Skip to content
The Algorithm
Vision 2030UAE PDPLSAMANCANEOMDIFCADGMNESASDAIA

Vision 2030 / UAE PDPL /
SAMA-aligned AI and cloud
engineering for banks,
governments, energy,
and healthcare.

Concrete engineering patterns — not slogans. SAMA-compliant cloud data platforms. NCA-ready government infrastructure. UAE PDPL-aligned AI systems. ADNOC-scale IoT pipelines.

Covering Saudi Arabia, UAE, Qatar, Bahrain, and Oman — in one place, at the depth Gulf enterprise technology leaders actually need.

Gulf entity establishing 2026. Engineering delivery from our India center — staffed by engineers trained on SAMA, NCA, UAE PDPL, DIFC, and NESA. Gulf business week. Arabic/English bilingual delivery.

Start the ConversationالعربيةRegulatory Deep Dive →
By Jurisdiction

Saudi Arabia. UAE. Qatar.
Bahrain. Oman. Covered
in one practice.

Most technology vendors cover one country. Gulf enterprises operating across multiple jurisdictions face compliance requirements that do not stop at borders. We cover the GCC as a single practice — with jurisdiction-specific depth in each market.

Saudi Arabia
المملكة العربية السعودية
Programs
Vision 2030NEOMQiddiyaRed Sea ProjectSDAIASaudi Sovereign Cloud
Frameworks
SAMA Cybersecurity FrameworkNCA Essential Controls (ECC)SDAIA AI Ethics PrinciplesSaudi PDPLCITC Telecom RegulationsSaudi Central Bank Open Banking Framework

Saudi Arabia's Vision 2030 is the largest government-directed technology investment program in the world — $3T+ in national transformation spending across energy, financial services, healthcare, government, and new cities. NEOM alone represents $500B in infrastructure requiring engineering teams with the depth to build at sovereignty-grade standards. SAMA's Cybersecurity Framework and the NCA's Essential Cybersecurity Controls apply to every financial institution and critical infrastructure operator. SDAIA's AI governance principles govern AI systems deployed in Saudi-regulated environments. The window for establishing a credible presence before Vision 2030 programs reach peak execution is narrowing.

SAMA cybersecurity assessments are annual. NCA ECC compliance is mandatory for critical sectors. SDAIA AI governance applies to any AI system touching government or regulated data.
UAE
الإمارات العربية المتحدة
Programs
UAE Centennial 2071Dubai 2040 Urban Master PlanAbu Dhabi Economic VisionADNOC Digital TransformationDIFC Innovation HubADGM FinTech
Frameworks
UAE Federal PDPL (Federal Decree No. 45/2021)DIFC Data Protection Law (Law No. 5/2020)ADGM Data Protection Regulations 2021NESA National Information Assurance FrameworkCBUAE Technology Risk ManagementTDRA Telecom Regulations

The UAE operates three parallel data protection regimes — federal UAE PDPL, DIFC, and ADGM — that apply simultaneously to organisations with presences across the mainland and both financial free zones. Entities serving the DIFC fintech ecosystem face GDPR-equivalent requirements enforced by the DIFC Commissioner of Data Protection. ADNOC's digital transformation program — spanning upstream field operations, refining, and distribution — requires engineering teams who can work at OT/IT convergence with data sovereignty requirements built into the architecture. The CBUAE's technology risk management guidelines impose prescriptive requirements on UAE-licensed financial institutions.

UAE PDPL enforcement is active. DIFC Commissioner has levied enforcement actions. CBUAE technology risk assessments are ongoing.
Qatar · Bahrain · Oman
قطر · البحرين · عُمان
Programs
Qatar National Vision 2030Bahrain Economic Vision 2030Oman Vision 2040QFC FinTechBahrain FinTech BayOIA Sovereign Fund
Frameworks
Qatar PDPLQCB Cybersecurity FrameworkBahrain PDPLCBB Technology Risk ModuleOman PDPLCBO Cybersecurity Guidelines

Qatar, Bahrain, and Oman have each passed data protection legislation aligned structurally with GDPR, creating compliance requirements for organisations operating across the GCC. Bahrain's Central Bank Technology Risk Module is among the most prescriptive banking cybersecurity frameworks in the region. Qatar's Financial Centre operates under QFC rules that maintain standards closely aligned with UK FCA frameworks — creating natural opportunity for firms with UK regulatory depth. Oman Vision 2040 is driving technology investment in energy, logistics, and financial services with engineering requirements that exceed the capability of regional generalist vendors.

All three jurisdictions have active data protection enforcement. CBB and QCB compliance assessments run on annual cycles.
Reference Architectures

What SAMA-compliant
actually means in code.

These are engineering decision lists — the specific controls, choices, and implementation patterns that distinguish a system that passes Gulf regulatory examination from one that creates findings. Not slogans. Not framework name-drops. Actual architecture decisions.

SAMA-Compliant Cloud Data Platform
Saudi Financial Services
SAMA SCF + NCA ECC
01

Data residency enforcement — all data classified as Confidential or above remains within KSA sovereign boundary; no cross-border transfer without explicit SAMA notification

02

SAMA SCF Tier 1–3 controls mapped to infrastructure layer at design time — not audited after deployment

03

Privileged Access Management with just-in-time access provisioning; no standing privileged credentials

04

Immutable audit log pipeline with 7-year retention — SAMA SCF requirement, chain-of-custody preserved across all data access events

05

Incident response runbooks aligned to SAMA Cyber Incident Management Framework; 72-hour notification SLA built into alerting architecture

06

Annual SAMA cybersecurity assessment readiness package produced continuously during build — not assembled pre-audit

07

NCA ECC controls mapped and evidenced at commit — compliance posture visible in CI/CD dashboard, not in a spreadsheet

UAE PDPL-Aligned AI Platform
UAE Financial Services / Healthcare
UAE PDPL + DIFC DPL + CBUAE
01

Dual-regime architecture for entities with both mainland and DIFC presence — PDPL and DIFC DPL requirements implemented as separate, coexisting control sets in the same platform

02

Consent management engine with purpose limitation enforcement — processing is blocked at the data layer if consent scope is exceeded

03

Data subject rights API: access, rectification, erasure, and portability requests resolved within PDPL-mandated timeframes with automated fulfilment where possible

04

Breach detection and notification pipeline with automated TDRA notification trigger at 72-hour threshold

05

Cross-border transfer controls — standard contractual clause generation, adequacy decision tracking, and transfer impact assessment documentation maintained in real time

06

AI model governance: training data provenance logging, bias audit trail, and model decision explainability for AI systems touching UAE PDPL-regulated personal data

07

CBUAE technology risk evidence package: system dependency mapping, recovery time objectives tested against CBUAE definitions of critical business services

NCA-Ready Government Infrastructure
Saudi Government / Critical Infrastructure
NCA ECC + NCA CCC + CSP
01

NCA Essential Cybersecurity Controls (ECC-1:2018) implemented at infrastructure layer — 114 controls mapped to IaC modules, not documented in a Word file

02

Cloud Cybersecurity Controls (CCC-1:2020) for government cloud deployments — each CCC control has a corresponding Terraform/Pulumi module that enforces it at provision time

03

Critical Systems Protection (CSP) framework for OT/ICS environments: IEC 62443 security levels mapped to network segmentation architecture

04

Data classification enforcement — NCA's four-tier classification (Top Secret, Secret, Confidential, Public) enforced at the storage and transit layer, not as a labelling exercise

05

Penetration testing cadence and red team program designed to NCA requirements — findings fed back into IaC and remediation evidenced before next assessment cycle

06

Supply chain security controls for third-party components — NCA SCM requirements implemented through dependency scanning and vendor risk scoring in CI/CD pipeline

ADNOC-Scale IoT and Data Pipeline
UAE Energy / OT-IT Convergence
IEC 62443 + UAE PDPL + NESA
01

OT/IT convergence architecture with network segmentation: Purdue model levels 0–4 enforced through infrastructure design, not firewall rules alone

02

ISA-99 / IEC 62443 security levels applied to upstream field instrumentation, DCS, and SCADA integration layers

03

Edge computing for upstream field operations — local processing of sensor data with selective sync to central data lake; no raw OT data traverses untrusted networks

04

Data lake with chain-of-custody logging from field sensor to analytics layer — NESA information assurance requirements satisfied for critical infrastructure operators

05

Real-time analytics pipeline with SCADA integration: historian data ingested, normalised, and made available to AI/ML models without breaking OT network isolation

06

ADNOC digital transformation alignment: architecture designed to support ADNOC's IIoT roadmap requirements including OSDU data standard for subsurface data

Industries

Four sectors. Each one
with a distinct
compliance architecture.

Financial Services
SAMA · NCA · CBUAE · DIFC · CBB · QCB

SAMA's Cybersecurity Framework requires Saudi banks and fintechs to implement specific controls across governance, protection, detection, response, and recovery — assessed annually with findings escalated to SAMA board level. The CBUAE's technology risk management requirements apply to UAE-licensed institutions with equal prescriptiveness. DIFC and ADGM fintech firms face GDPR-equivalent data protection obligations enforced by their respective commissioners. Open banking mandates across Saudi Arabia and Bahrain require API compliance architectures that most regional technology vendors cannot build to regulatory standard.

What we deliver
SAMA SCF-aligned core banking infrastructure
CBUAE technology risk evidence packages
DIFC / ADGM GDPR-equivalent data protection architecture
Open banking API compliance — SAMA and Bahrain CBB frameworks
AML/KYC platform engineering with FATF-aligned controls
RegTech platforms for real-time regulatory change detection
Government & Public Sector
NCA · SDAIA · UAE TRA · MOTEI

NCA's Essential Cybersecurity Controls are mandatory for Saudi government entities and operators of critical national infrastructure. SDAIA's AI governance framework applies to AI systems deployed by or for government — with requirements around explainability, bias assessment, and data sovereignty that most AI vendors have not designed for. UAE government digital transformation programs — Hayya, Smart Dubai, Abu Dhabi's digital government initiatives — require engineering teams who can deliver within the NESA information assurance framework and the UAE TRA's data localisation requirements for government data.

What we deliver
NCA ECC-compliant government cloud infrastructure
SDAIA AI governance framework implementation
NESA-aligned e-government platform engineering
GovCloud architecture for Saudi sovereign cloud
Digital identity and authentication systems for government services
Citizen data platform with PDPL compliance built in
Energy & NEOM-Scale Infrastructure
ARAMCO · ADNOC · NEOM · IEC 62443

Saudi ARAMCO's Cybersecurity Compliance and Vendor Security programs impose requirements on technology partners that exceed what most enterprise security frameworks demand. ADNOC's digital transformation program spans upstream OT environments, refining operations, and distribution infrastructure — requiring engineering teams who can work at the intersection of IT architecture and OT security. NEOM's The Line, Oxagon, and Trojena programs represent infrastructure-at-scale engineering with AI, smart city, and IoT requirements that will define the next generation of urban technology architecture.

What we deliver
IEC 62443-aligned OT/IT convergence architecture
ARAMCO supplier cybersecurity compliance programs
NEOM smart infrastructure data platform engineering
AI-enabled predictive maintenance for energy assets
SCADA integration and real-time analytics pipelines
Carbon accounting and sustainability data platforms for Vision 2030 targets
Healthcare
MOH Saudi · DOH Abu Dhabi · DHA Dubai · ABDM

Saudi Arabia's Healthcare Vision 2030 targets include digitising 70% of health services and building a national health data exchange. MOH's Seha Virtual Hospital and the National Health Laboratory require interoperability infrastructure aligned to HL7 FHIR and Saudi-specific data standards. Abu Dhabi's Department of Health and Dubai's DHA each operate distinct health data platforms with their own regulatory requirements — creating multi-regime compliance challenges for healthcare technology operators across the UAE. Clinical AI deployed in Gulf healthcare environments requires validation against both local health authority standards and the same robustness requirements applied in FDA and MHRA-regulated markets.

What we deliver
MOH-compliant health data exchange platforms
HL7 FHIR interoperability for Gulf health systems
Clinical AI platforms validated for UAE DOH and DHA environments
PDPL-compliant patient data architecture
Telehealth infrastructure with cross-emirate and cross-border compliance
AI-enabled diagnostic support with explainability for Gulf regulatory review
GCC for GCC

Gulf Cooperation Council
enterprises building
Global Capability Centers
in India.

Saudi and UAE enterprises running large engineering programs are increasingly establishing India engineering hubs — for cost structure, talent depth, and time zone coverage of Gulf operating hours. Most lack a partner who can set up the India center and also deliver the Gulf-side compliance engineering under one commercial relationship.

DTT India is the India anchor. The Algorithm Gulf is the regional compliance engineering practice. Engineers in Indore are trained on SAMA, UAE PDPL, and NESA before they work on Gulf client infrastructure. One relationship. Two geographies.

India GCC Practice →
India engineers trained on Gulf frameworks

SAMA SCF, NCA ECC, UAE PDPL, DIFC DPL, and NESA controls trained into the Indore engineering team before they touch Gulf client infrastructure. Your India center runs to Gulf compliance standards from day one.

Gulf business week alignment

Sunday–Thursday operating schedule for India teams supporting Gulf engagements. Overlap hours maximised for Saudi (GMT+3) and UAE (GMT+4) working patterns.

Arabic/English bilingual coordination

Bilingual project leads for Saudi and UAE engagements where Arabic-language stakeholder communication is required. Documentation in both languages where needed.

Data sovereignty across both jurisdictions

DPDPA compliance for the India entity. SAMA/PDPL compliance for Gulf-side data handling. Cross-border transfer mechanisms between India and Gulf jurisdictions documented and maintained.

BOT model for Gulf enterprises

Build-Operate-Transfer for Gulf enterprises establishing India engineering centers. We build the team to your standards, operate the center through the ramp phase, and transfer it as a captive. IP transfers with the team. Transfer is contractual.

Common Questions

What Gulf technology leaders
ask before engaging.

Do you have a physical presence in Saudi Arabia or UAE?

We are establishing our Gulf entity in 2026. In the interim, Gulf engagements are delivered by our India engineering center — staffed by engineers trained on SAMA, NCA, UAE PDPL, DIFC, and NESA frameworks — with engagement leadership available in-region. We work on the Gulf business week (Sunday–Thursday), provide Arabic/English bilingual coordination for Saudi and UAE stakeholders, and have structured our India center specifically to support Gulf-market delivery. Our 2026 entity registration is a commitment, not an aspiration — it is funded and planned.

Can you guarantee data sovereignty — that our data will not leave the Kingdom or the UAE?

Yes, and we design this at the architecture level. Data residency enforcement is not a policy document — it is a combination of cloud region selection (AWS Riyadh, Microsoft Azure UAE North/UAE Central, Google Cloud ME West 1), network egress controls, encryption key management in-country, and continuous monitoring for data exfiltration. We produce data flow diagrams showing every data residency control, which we provide to SAMA, NCA, or TDRA as part of regulatory documentation.

Do you actually understand SAMA, NCA, and SDAIA — or are you reading the same PDFs we are?

Our engineers are trained on SAMA SCF control implementation — not just the framework document. We map controls to infrastructure modules, produce evidence packages for annual SAMA assessments, and design systems so that NCA ECC compliance is visible in the CI/CD pipeline, not assembled pre-audit. We can discuss specific controls (SCF domains, ECC control families, SDAIA AI ethics principles) at the engineering decision level. If your team wants to test our knowledge before engaging, that conversation happens in the first meeting.

How do you handle Arabic-speaking stakeholders and Gulf working patterns?

Our Gulf delivery team includes Arabic/English bilingual engineers and project leads. We work on the Gulf business week where engagements require it. We understand that Gulf government and enterprise decision-making involves stakeholder layers and relationship cycles that differ from Western project cadences — and we structure engagement timelines accordingly. We do not parachute in a Western-model delivery team and expect Gulf clients to adapt to it.

We are evaluating partners for a multi-year Vision 2030 program. How do we know you will still be here?

Three registered entities operating since 2015 — US, UK, and India. A 2026 Gulf entity planned and funded. We do not enter markets to win a project and leave. Our business model is long-term program delivery: the same compliance standards applied across engagements, building institutional knowledge in the client's environment that compounds over time. We can provide references from US and UK clients on multi-year programs. The Gulf market is a strategic commitment, not a business development experiment.

We need a partner for both our Saudi operations and our India engineering center. Can one firm handle both?

Yes — and this is a natural combination for Gulf enterprises. We operate the India engineering center (Design Thinking Technologies India, Indore) that Gulf companies use for their GCC build-operate-transfer engagements, and we are establishing the Gulf practice as the compliance engineering arm. Engineers in the India center are trained on SAMA, UAE PDPL, and NESA frameworks. One relationship covers Saudi/UAE compliance engineering and India GCC setup. See our India practice page.

Gulf & Middle East Practice

SAMA. NCA. UAE PDPL.
DIFC. NEOM.
We build to these standards.

Conversations start with engineering leadership who will work on your engagement. Gulf business week. Arabic/English bilingual. Fixed-price proposals within two weeks.

Start the ConversationالعربيةRegulatory Deep Dive →
Engage Us