The Six-State Regulatory Map: Nine Data Protection Regimes Across the GCC
GCC Compliance & Implementation Track · Certified GCC Data Regulation Strategist
Six countries, nine distinct data protection regimes, four different regulators inside the UAE alone, and one state with no general statute at all. This course builds the map a CIO needs before making any architecture or sourcing decision in the Gulf. It is deliberately built on primary sources, because the GCC compliance content market is heavily contaminated with fabricated citations — the UAE Executive Regulations alone are variously reported as Cabinet Decision 111/2023, 33/2024, 33/2022 and "issued in 2026", when authoritative legal sources record that they have not been issued at all. Learners finish able to establish the actual legal position in any GCC state from the gazette and regulator, and to recognise when a vendor, consultant or article is citing an instrument that does not exist.
Learning objectives
- 01Map which of the nine GCC data protection regimes applies to each legal entity and activity
- 02Establish the actual current legal position in any GCC state from primary sources
- 03Detect fabricated or mis-cited regulatory instruments in vendor and advisory material
- 04Compare obligations across the six states on the dimensions that drive architecture
- 05Distinguish states that are actively enforcing from states that are not, and plan accordingly
- 06Brief a board on GCC regulatory exposure without overstating or understating it
15-module program
Full curriculum in preparation
This course is being written now by the ITHR editorial team. Join the waitlist and we'll notify you the moment the full syllabus, hands-on labs, and certification exam are live. No enrollment is accepted until publication.

