Saudi PDPL and UAE PDPL share roughly 75% of their control base with GDPR. easyPII derives many regulatory outputs from one control base, which makes the Gulf a mapping exercise, not a rebuild.
Hall H7, Stand H7-C170.1 · 16–18 September 2026 · Dubai World Trade Centre
Gulf organisations are being brought into scope of data protection obligation quickly and at scale, frequently without an existing compliance function. The incumbent response is manual consultancy at high day rates, producing point-in-time documents that decay on delivery.
easyPII replaces the day rate with a control base. The same scan that certifies against UK frameworks produces the PDPL evidence, continuously and signed.
20+ paid pilots and a 100% audit pass rate under UK Cyber Essentials and IASME certification, applied against Gulf frameworks from the same engine.
Agentless discovery across your IT network. Nothing installed, ever. OT/SCADA visibility is in active development; talk to us if you need it as a design partner.
Cryptographically signed evidence packs produced as the estate changes, not an annual document exercise.
Twenty years implementing regulatory frameworks inside Barclays, HSBC, IBM, HPE and DWP. CISSP, CISA, CEH, ISO 27001 Lead Auditor, Cyber Essentials Assessor, CCIE Security.
OT/SCADA visibility and a fully air-gapped, zero-connectivity deployment mode are both in active design, built passive-only from day one, to meet the same safety constraints your ICS and OT engineers already work under. If your organisation needs either of these (critical infrastructure, defence, government, or anywhere a hard data-localisation mandate applies), talk to us. We're recruiting a small number of design partners to help shape both before general release.
Talk to us about OT / air-gapped deploymentOne control base,
many regulatory outputs.
Because the Compliance Knowledge Graph links each regulatory control to each live asset, adding a jurisdiction is a mapping exercise against controls the platform already scans.
For the customer that means one scan, one remediation pass, and evidence produced against UK GDPR and PDPL together. For an organisation operating in both the UK and the Gulf, it removes the second tool and the second consultant entirely.
Market entry is being structured through a majority-held Saudi joint venture, with all intellectual property retained by iSoft PVT Ltd in the United Kingdom and licensed to the joint venture on a royalty basis.
We say “being structured” because that is what it is. Legal instruments precede company registration, and we would rather tell you the true stage than describe a company that does not yet exist.
easyPII is available across the GCC on a white-label and revenue-share basis. Compliance work you currently deliver as chargeable manual labour becomes a platform you deliver at margin.
You keep the client relationship and the brand. We provide the engine, the evidence and the multi-jurisdiction output.
We reply within one working day. Which frameworks are you accountable for, and what is forcing the timeline?
Frameworks
Book a 30-minute walkthrough with our team — we'll tailor it to what you're trying to solve.
Book a DemoNo commitment · Pick any time that works
We scan a representative environment, show you what is non-compliant against PDPL, and deploy the fix live.