BOOK A DEMO

HRMS security evaluation

HRMS security evaluation: the evidence to demand before implementation

A CIO’s guide to reading a vendor’s security artefacts, and to the employer obligations that actually bite in the United Arab Emirates, Saudi Arabia, Qatar, Kuwait, Bahrain and Oman.

The short answer

An HRMS security evaluation is a documentary exercise, not a questionnaire exercise. Ask for nine artefacts: the ISO/IEC 27001 certificate and its scope line, the Statement of Applicability version it names, a SOC 2 Type 2 report, the current editions of any cloud or privacy standards claimed, penetration test evidence, business continuity objectives, the sub-processor list, the data processing agreement with its breach clock, and written exit and deletion terms. Then read each one for what it does not cover.

The obligations these artefacts have to satisfy are yours as controller, and they differ in all six GCC states.

Why the questionnaire is the weakest part of the process

Most HRMS security evaluations run on a security questionnaire. The vendor answers two hundred questions, the answers come back overwhelmingly affirmative, and the evaluation closes. Nothing in that process is verified by anyone outside the vendor.

The alternative is not a longer questionnaire. It is a short list of documents that were produced by someone other than the vendor, each of which can be checked, dated and read for its limits. That list is the evidence pack, and this article is about how to read it.

The reason to do this before implementation rather than after is that an HR and payroll database is an unusually concentrated target. In a GCC deployment it holds national identity numbers, passport and residency data, bank account details and IBANs, the basic-versus-gross salary split that statutory calculations depend on, accrued end-of-service balances, social insurance registration numbers, dependants, sickness absence, disciplinary records and nationality classification used for localisation reporting. The wage file submitted through a wage protection channel carries a further concentration of the same data in one structured export. There is no meaningful sense in which this is low-risk data.

Accountability does not disappear when an HRMS is outsourced. The employer, as controller, remains responsible for complying with its own controller obligations, but vendors and processors may also have direct statutory duties. For example, UAE federal law requires a processor that becomes aware of a personal-data breach to notify the controller, while DIFC and ADGM impose their own processor notification duties. A contract can allocate operational responsibilities between the parties, but it cannot remove statutory duties that the applicable law places directly on either party.

The nine artefacts, and what each one does not prove

Table 1 is the working list. The last column is the question that separates a document from a claim.

Artefact What it establishes What it does not establish Ask for
ISO/IEC 27001 certificate An information security management system was audited against the standard, within a stated scope That the scope includes the product you are buying, or its hosting The certificate PDF. Read the scope line, the version and the expiry date before anything else
Statement of Applicability Which controls were included, which were excluded, and the justification for each That excluded controls are irrelevant to your deployment The specific SoA version named in the certification documents
SOC 2 Type 2 report That controls operated over a stated period, tested by a CPA firm Anything outside the Trust Services Criteria selected, or after the period ended The full report, not a summary. Read the period, the criteria in scope, the exceptions and the user entity controls
Cloud and privacy standards claimed Alignment to a published code of practice or, for ISO/IEC 27701, a management system Currency, if the vendor cites a superseded edition The edition year, and where those controls appear in the named SoA
Penetration test evidence That a defined scope was tested on a defined date by an identified tester Security today. The UK National Cyber Security Centre is explicit that a test validates against known issues on the day of the test Scope statement, test date, tester accreditation, risk ratings and the remediation status of each finding
Business continuity evidence That a continuity management system exists and was audited, where ISO 22301 is held Any particular recovery time or recovery point. Those are numbers the organisation sets for itself RTO and RPO as contractual commitments, plus the date and result of the last restoration test
Sub-processor list Who else will process your employee data, and where That those parties are covered by the vendor’s own assurance reports The list with locations, the notification period for changes, and each sub-processor’s own evidence
Data processing agreement The contractual allocation of duties between you as controller and the vendor as processor Compliance. Several GCC states prescribe no minimum contract content at all The breach notification clock to you, the audit right, and the assistance obligations
Exit and deletion terms What happens to the data when the contract ends That backups and archives are included, unless it says so Export format, retention window, deletion certificate, and whether backups are in scope

Table 1. The HRMS vendor security evidence pack. Sources for the standards positions are listed at the end of this article.

ISO/IEC 27001: read the scope line before the logo

ISO does not issue certificates. Its own guidance is unambiguous: “ISO does not perform certification or issue certificates, and it does not permit anyone to use the ISO logo in connection with certification.” A certificate comes from a certification body, and the certificate that carries weight comes from one accredited under ISO/IEC 17021-1 by an accreditation body recognised through the International Accreditation Forum.

Three checks take about four minutes.

The version must read 2022

IAF Mandatory Document 26 set the transition from ISO/IEC 27001:2013 to the 2022 edition at 36 months from publication, expiring 31 October 2025, and states that certifications based on the 2013 edition “shall expire or be withdrawn at the end of the transition period”. Any certificate still citing the 2013 edition is no longer live. An accreditation body’s own checklist requires the current standard with the version indicated to appear on the certificate, so this is visible on the face of the document.

The scope line must contain the product and its hosting

A certificate names the “scope of certification (the product or service of the company to which the certificate was issued)”. A scope covering a head office and its corporate IT does not cover a multi-tenant payroll platform running in a cloud region. This is the single most common gap between what a certificate says and what a buyer assumes it says.

The certificate must be verifiable independently

The International Accreditation Forum runs IAF CertSearch, a global database of accredited management system certifications, and UKAS runs CertCheck for certificates issued by UKAS-accredited bodies. Where a certificate does not appear, the certification body will confirm status, standard, scope and geographic location on request. Certificate numbers are not standardised across bodies, so verification is by register lookup or direct confirmation rather than by number format.

The Statement of Applicability is where the substance sits

The SoA is a required output of the standard. An ISO/IEC JTC 1/SC 27 auditing practices note describes it as setting out an organisation’s necessary controls, the justification for including them, and whether they are implemented, together with the justification for excluding any Annex A control. The same note records that the SoA version is referenced in the certification documents.

That last detail is the useful one. It means you can ask for a named version rather than “your SoA”, and check that what you receive is the version the certificate was issued against. No standards body creates an entitlement to receive it, so this is a commercial ask rather than a right. A vendor that declines to share it during a procurement has told you something.

SOC 2: an examination over a period, not a certification

The American Institute of Certified Public Accountants describes SOC 2 throughout as an examination reported on under its attestation standards. Baker Tilly puts the consequence plainly: “SOC is not a certification. It is an audit opinion”. Nobody is SOC 2 certified. Four things inside the report decide what it is worth to you.

Type 1 or Type 2, and the period

A Type 1 addresses the design of controls at a point in time. A Type 2 addresses operating effectiveness over a period. Only the second tells you the controls worked. Read the period dates on the cover, and note that reports are typically issued some weeks after the period ends.

Which Trust Services Criteria are in scope

The AICPA’s five categories are security, availability, processing integrity, confidentiality and privacy. Crowe, Baker Tilly and RSM all describe only security, the common criteria, as required in every report, with the remaining four selected by management. For a system holding payroll and personal data, a report covering security alone does not opine on confidentiality, privacy or availability. That is a material limitation and it is stated on the cover page.

Complementary user entity controls

These are controls the report assumes you will operate. Wipfli describes them as “controls that your vendor has included within their system that they’re relying on you to implement”. If your side of the deployment does not operate them, the assurance in the report is incomplete by its own terms. In an HRMS this usually covers user provisioning and deprovisioning, approval of privileged access, review of access reports and configuration of authentication. Read this section during evaluation, because it is also the implementation work you are committing to.

Sub-service organisations, and the gap after the period ends

Under the carve-out method a sub-service organisation’s controls sit outside the report; under the inclusive method they are inside it and tested. Carve-out is common, and it means the hosting provider and any other critical supplier need their own evidence. For the gap between the end of the period and today, vendors offer a bridge letter. Wipfli notes that these letters are not the auditor’s responsibility to send. A bridge letter is a management representation, not assurance, and should be read as such.

No standards body publishes a rule that a report older than twelve months is stale. As a working rule of thumb, though, annual re-assurance is the observable norm: accredited certification requires annual surveillance audits, and the Cloud Security Alliance expires STAR attestation listings after one year unless updated. Treating anything beyond about twelve months as needing a bridge letter is consistent with how the assurance ecosystem behaves, and it should be presented as a buyer’s rule rather than a published standard.

Cloud and privacy standards: check the edition, not the number

Three of the standards most often quoted in HR software marketing have been revised recently, and a vendor citing the old edition is telling you when its evidence pack was last updated.

  • ISO/IEC 27017 moved to a second edition in July 2026, covering information security controls for cloud services. The 2015 edition was withdrawn on 27 July 2026.
  • ISO/IEC 27018 moved to a third edition in August 2025, covering protection of personally identifiable information in public clouds acting as PII processors.
  • ISO/IEC 27701 moved to a second edition in October 2025 and is now a standalone privacy information management system standard rather than an extension to ISO/IEC 27001. The certification body requirements for it, ISO/IEC 27706, were published in the same month, so accredited certification against the new edition is recent. A 27701 certificate may still be a 2019-edition extension certificate. Check which.

ISO publishes 27017 and 27018 as guidance and controls documents rather than requirements standards, and the certification body requirements that exist cover ISO/IEC 27001 and ISO/IEC 27701. The IAF multilateral arrangement scope list names ISO/IEC 27001 and does not name 27017 or 27018. The practical reading is that a vendor claiming alignment to those two should be able to show where those controls appear in the named Statement of Applicability.

ISO/IEC 42001:2023 is a management system standard for artificial intelligence governance. It says nothing about the accuracy or behaviour of any particular model, and like ISO/IEC 27001 it should be read scope first.

What the six GCC states require of you, not of the vendor

The evidence pack has to satisfy your obligations. Those obligations are not uniform across the Gulf Cooperation Council states, and in the United Arab Emirates they are not even uniform within one country. Table 2 sets out the position by jurisdiction.

Jurisdiction Instrument Breach notification to the regulator Cross-border mechanism General HR data localisation
United Arab Emirates
Mainland and free zones Federal Decree-Law No. 45 of 2021 No fixed period. Article 9 defers it to the Executive Regulations, which remain unpublished Articles 22 and 23. No adequacy list and no standard contractual clauses published None
DIFC DIFC Law No. 5 of 2020, as amended 2025 “As soon as practicable in the circumstances”, Article 41. Not 72 hours Own regime, separate from the federal law None
ADGM Data Protection Regulations 2021 Without undue delay and, where feasible, within 72 hours, section 32, unless the breach is unlikely to result in a risk to individuals’ rights ADGM publishes its own standard contractual clauses None. Annual data controller registration renewal is required, with appointed processors notified
Saudi Arabia PDPL, Royal Decree M/19 of 2021 as amended by M/148 of 2023 Maximum 72 hours from awareness where the incident may harm the data, or the data subject, or conflict with their rights or interests, Implementing Regulation Article 24. To the individual, “without undue delay” Transfer Regulation. Adequacy list not yet published, so safeguards under Article 4 are the practical route None generally. Sectoral rules exist
Qatar, State Law No. 13 of 2016 The statute sets no period. A 72-hour expectation appears in the regulator’s guidelines Article 15 restricts blocking cross-border flows rather than restricting the flows themselves None
Qatar, QFC QFC Data Protection Regulations 2021, version 3 Within 72 hours under Article 31, except where the controller determines the breach is unlikely to result in risk to the rights and legitimate interests of data subjects Own regime, separate from the State of Qatar law None
Kuwait No omnibus law. Electronic Transactions Law No. 20 of 2014 binds employers No general deadline for employers. CITRA-licensed service providers: 24 hours from awareness, Decision No. 26 of 2024 Transparency only. Name the destination countries and document the safeguards None. The tiered classification policy was repealed in February 2024
Bahrain Law No. 30 of 2018, with Ministry of Justice Orders 42, 43 and 46 of 2022 A 72-hour framework from discovery, Order 43 of 2022, Article 4, subject to the applicable threshold and exceptions Published adequacy list, or case-by-case authorisation. Criminal exposure if neither applies None. The control is on the destination, not the location
Oman Royal Decree No. 6 of 2022, with Executive Regulations issued in 2024 72 hours, from the Executive Regulations. The Law itself sets no period Consent plus an assessment of protection in the receiving jurisdiction. No separate approval for non-sensitive data; sensitive data stored or processed abroad needs Cyber Defence Centre approval None

Table 2. Employer obligations by jurisdiction, as at 17 September 2026. Sources are listed at the end of this article. Figures and deadlines change; confirm with the named authority before relying on any of them.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 was issued on 20 September 2021 and commenced on 2 January 2022. Article 20 requires controllers and processors to develop and take appropriate technical and regulatory measures, and lists encryption and pseudonymisation, continuous confidentiality and integrity of processing systems, timely retrieval of data after a failure, and testing and evaluation of the measures themselves. That last item is the statutory hook for asking a vendor about penetration testing and control testing.

Article 9 is the provision most often misquoted. It requires the controller to notify the Bureau at the time it becomes aware of a breach, but the period is set “in accordance with the measures and requirements set by the Executive Regulations”. Those regulations have still not been issued, a position corroborated in 2026 by Ashurst, Chambers and other named firms, though no official UAE source states it either way. There is therefore no federal 72-hour rule in the UAE. Anyone quoting one is importing it from elsewhere. Article 9(3) does bind the processor directly: on becoming aware of a breach it must notify the controller “as soon as it becomes aware of the same”.

The two financial free zones run separate regimes and diverge from each other on the point that matters most operationally. DIFC Law No. 5 of 2020 requires notification “as soon as practicable in the circumstances”. ADGM’s Data Protection Regulations 2021 set 72 hours where feasible, unless the breach is unlikely to result in a risk to individuals’ rights, and also require annual data controller registration renewal, with appointed processors notified. A group with entities in Dubai mainland, the DIFC and Abu Dhabi Global Market is running three different clocks inside one country.

On hosting: there is no UAE requirement that an ordinary private-sector employer keep HR or payroll data inside the country. The three localisation rules that do exist are sectoral. Federal Law No. 2 of 2019 restricts offshore storage of health data held by health entities. The Central Bank’s Consumer Protection Standards require licensed financial institutions to hold consumer and transaction data in the UAE, and its Outsourcing Regulation for Banks requires the master system of record to be maintained in the UAE. None of these reaches an ordinary employer’s HR records. A UAE hosting requirement in a tender is a procurement preference, which is a legitimate thing to have, but it is not the same as a legal obligation and should not be described as one.

Saudi Arabia

The Personal Data Protection Law came into force on 14 September 2023, with a grace period to 14 September 2024 during which the competent authority did not apply penalties. The Saudi Data and AI Authority is the regulator, and both the Implementing Regulation and a separate Regulation on Personal Data Transfer Outside the Kingdom are in force.

Article 23 of the Implementing Regulation is the most useful provision in the region for an evidence pack, because it ties the required organisational, administrative and technical measures to the cybersecurity standards issued by the National Cybersecurity Authority or to international best practice. It converts a general security duty into a benchmark you can hold a vendor to.

Two points on those NCA frameworks are commonly out of date in vendor material. The Essential Cybersecurity Controls are now ECC-2:2024 and the Cloud Cybersecurity Controls are now CCC-2:2024, superseding the 2018 and 2020 editions respectively. More consequentially, the change log to CCC-2:2024 records that “Controls related to data localization have been transferred from the document to the National Data Management Office”. The in-Kingdom hosting subcontrol that a great deal of published material still quotes from CCC-1:2020 is superseded. Both frameworks bind government entities, their affiliates and private entities owning, operating or hosting critical national infrastructure. An ordinary private employer is not in scope directly, but is exposed through Article 23 and through contracting with entities that are.

On transfers, the Transfer Regulation provides for an adequacy list, but SDAIA has not published one. King & Spalding, writing in November 2025, continues to advise clients to limit transfers to jurisdictions the European Commission has deemed adequate. The practical route for a group hosting Saudi payroll centrally is therefore the Article 4 safeguards, with the transfer risk assessment that Article 7 makes mandatory for exemption-based transfers and for continuous or wide-scale transfers of sensitive data.

Penalties sit in two separate branches that should not be merged. Article 35 covers disclosure or publication of sensitive data with intent to harm or for personal benefit, and provides for imprisonment not exceeding two years and a fine not exceeding SAR 3,000,000. Article 36 covers other violations by a natural or private legal person, and provides for a warning or a fine not exceeding SAR 5,000,000, which may be doubled for a repeat offence. Article 36 starts at a warning, not at a fine.

Qatar

Law No. 13 of 2016 places the security duty on both controller and processor: each must take the precautions necessary to protect personal data against loss, damage, change, disclosure, access or inadvertent or illegal use, and those precautions must be commensurate with the nature and importance of the data. The processor must notify the controller of a breach forthwith.

Article 14 requires notification of the individual and the competent department where a breach may cause serious damage, but sets no deadline. The 72-hour figure widely attributed to Qatar comes from the regulator’s guidelines rather than the statute, and named firms describe those guidelines in different terms, one saying they clarify the deadline and another that they seek to introduce it. The honest position for a buyer is that Qatar’s 72 hours is a regulator expectation set out in guidance, not a statutory deadline of the kind Saudi Arabia has.

The supervisory position is also unsettled. The Compliance and Data Protection Department at the Ministry of Transport and Communications issued the guidelines in 2020 and 2021, they are now published by the National Cyber Security Agency, and a 2026 Chambers chapter records the NCSA as having clarified that the competent department has not yet been formally designated. A vendor claiming an established Qatari regulator relationship deserves a follow-up question.

Entities registered in the Qatar Financial Centre are in a different regime entirely. The QFC Data Protection Regulations 2021 set 72 hours under Article 31, except where the controller determines the breach is unlikely to result in risk to the rights and legitimate interests of data subjects. The QFC has also published a named enforcement notice following a data breach in October 2024, which makes it the jurisdiction in this group where the consequences are least theoretical.

Qatar’s National Information Assurance Policy is, in its own words, “mandatory for compliance by the government sector and strongly recommended for the critical sector organizations”. For a private employer it is a benchmark rather than an obligation. The same is true of the Cloud First Policy, which applies to government agencies. Note that an older NCSA cloud security policy directed at government agencies imposes a four-hour notification window for actual and suspected breaches, which is a useful contractual benchmark even where it does not bind you.

Kuwait

Kuwait does not have a single omnibus personal data protection law equivalent to the UAE, Saudi, Bahrain or Oman regimes. For ordinary employers, Chapter Seven of Law No. 20 of 2014 on Electronic Transactions provides the principal general protections for personal information held in electronic records. Article 32 expressly applies to companies and non-governmental entities and regulates unauthorised access, disclosure and publication of personal information, as well as purpose limitation. Law No. 20 of 2014 was amended by Decree-Law No. 148 of 2025, although that amendment changed Articles 2 and 3 rather than replacing the Chapter Seven privacy provisions.

CITRA’s Data Privacy Protection Regulation is a separate sector-specific regime. The current instrument is Decision No. 26 of 2024 and applies to service providers licensed by CITRA. Article 6 requires an in-scope service provider to notify CITRA of a personal-data breach within 24 hours after becoming aware of it. The 24-hour CITRA rule should therefore not be presented as a general deadline for every private employer in Kuwait.

For an HRMS evaluation, first determine whether the employer or vendor is itself within CITRA’s licensing scope. If not, do not import the CITRA 24-hour rule into the employer’s statutory obligations merely because data is processed electronically.

Bahrain

Law No. 30 of 2018 came into effect on 1 August 2019. The Personal Data Protection Authority exists in the law, but its duties are exercised by the Ministry of Justice, Islamic Affairs and Waqf under Royal Decree No. 78 of 2019, which is where correspondence and registrations go.

Bahrain has the most prescriptive security regulation in the region, and it is the most directly useful text a CIO can cite. Ministry of Justice Order No. 43 of 2022 requires privacy by design, password protection, anti-virus and firewalls, regulated retention and disposal, continuity plans and periodic vulnerability assessment and penetration testing. Periodic testing is a legal requirement in Bahrain, not a good practice, which means asking a vendor for current penetration test evidence has a statutory basis rather than a commercial one.

The same Order provides a 72-hour breach-notification framework from discovery, subject to the applicable threshold and exceptions, and in Article 4(3)(a) it removes the duty to notify affected individuals where the breached data is “unintelligible to any person who is not authorised to access it, such as encryption”. That is a concrete, citable reason to require encryption at rest from an HRMS vendor rather than a general preference.

Transfers are the sharp edge. Articles 12 and 13 prohibit transfer outside Bahrain except to countries on a published list or under case-by-case authorisation, and Ministry of Justice Order No. 42 of 2022 published that list. Getting this wrong is a criminal matter: Article 58(1) provides for imprisonment of up to one year and a fine, with Article 59 doubling the minimum and maximum for legal entities where the offence results from board action or gross negligence. Two details are worth checking directly against the Official Gazette before you rely on them, because the Order dates from March 2022: whether the list has changed, and whether Qatar remains absent from it. On the March 2022 list, Saudi Arabia, Kuwait, Oman and the United Arab Emirates appear and Qatar does not, which matters for any GCC group routing data between entities.

One helpful provision: Article 14 exempts an employer from the general notification requirement for processing employee data to the extent necessary to perform its duties, and separately exempts controllers who appoint a Data Protection Guardian. The employee-data exemption is narrow and self-assessed, and it will not cover HRMS processing that goes beyond necessity, such as analytics, profiling or wellness modules.

Oman

Oman’s Personal Data Protection Law, Royal Decree No. 6 of 2022, operates together with its Executive Regulations issued under Ministerial Decision No. 34 of 2024. A controller must notify the Ministry within 72 hours of becoming aware of a personal-data breach where the breach threatens the rights of data subjects. Where the breach causes serious harm or presents a high risk to the data subject, notification to the affected data subject is also required within 72 hours.

Cross-border transfers require more than a simple statement that there is “no approval”. MTCIT states that, as a general rule, the controller must obtain the data subject’s consent and assess the protection offered in the receiving jurisdiction. For non-sensitive personal data, no separate authority approval is generally required where the applicable safeguards are met. Sensitive personal data that will be stored or processed outside Oman requires approval from the Cyber Defence Centre.

Royal Decree No. 68 of 2026 was published in Official Gazette No. 1664 on 6 September 2026 and took effect on 7 September 2026. The amendment added Article 5bis, which expressly permits the controller to process personal data of its workers without the Article 5 permit where the processing is within the controller’s internal operations, complies with the law and the data is not disclosed to third parties without the employee’s written consent. It also added Article 10bis, introducing additional grounds for processing without explicit consent, including compliance with a legal obligation and performance of a contract.

The employee-processing exception should not be read as automatically removing separate cross-border controls. In particular, the MTCIT’s current guidance still requires Cyber Defence Centre approval where sensitive personal data is to be stored or processed outside Oman.

The one HR domain where nationals and expatriates are treated identically

In GCC payroll, the distinction between nationals and expatriates organises almost everything. Expatriates in most of the region accrue end-of-service benefits, nationals are on social insurance schemes run by their own state’s authority, GCC nationals working outside their home state sit on a third track under the unified insurance arrangements, and the DIFC replaces gratuity with a funded scheme altogether. Nationality is the first branch in nearly every statutory calculation.

Data protection is the exception. None of the six states distinguishes nationals from expatriates in its personal data regime. Bahrain’s connecting factor is residence in Bahrain and place of business in Bahrain. Oman’s law applies to personal data that is processed, with no nationality qualifier. The same holds across the others. An expatriate employee’s record attracts identical protection to a national’s.

This matters at design time. Teams carry the payroll instinct into data architecture and segregate populations by nationality, sometimes placing expatriate records under lighter controls or in different hosting arrangements on the assumption that the obligations differ. They do not. Segmenting HR data by nationality is a legitimate thing to do for statutory calculation purposes. It is not a basis for differentiating security controls.

gulfHR expert view

A single 72-hour vendor breach-notification clause is not suitable for a multi-country GCC HRMS contract. The regulatory clocks are different and many are subject to risk or harm thresholds. UAE federal law does not state a fixed number of hours in Article 9; DIFC requires notification as soon as practicable; ADGM, Saudi Arabia, Bahrain, Oman and the QFC operate 72-hour regimes subject to their respective notification thresholds; Qatar’s statute does not specify a deadline, although NCSA guidance uses 72 hours for qualifying breaches; and Kuwait’s current CITRA regulation requires a 24-hour notification for CITRA-licensed service providers.

The vendor’s contractual notification obligation should therefore be materially shorter than the shortest regulatory period applicable to the customer and should begin when the vendor becomes aware of the incident, rather than only when its investigation is complete. The contract should also permit information to be provided in stages so that an initial notification is not delayed while every fact is being confirmed.

Six vendor claims that do not mean what they sound like

The claim What it actually means
“We are SOC 2 certified” There is no such thing. SOC 2 is an examination reported on under the AICPA’s attestation standards. Ask which type, which period and which criteria
“We are ISO 27001 certified” True or not depending on the scope line and the edition. A 2013-edition certificate expired on 31 October 2025
“We are listed on the CSA STAR registry” Level 1 is a self-assessment the provider submits itself. Only Level 2 involves a third-party audit. Check the level on the entry
“We comply with Kuwait’s data classification requirements” Kuwait’s tiered classification policy was repealed in February 2024
“Our Saudi hosting satisfies the NCA in-Kingdom requirement” The localisation subcontrols were removed from the Cloud Cybersecurity Controls in the 2024 edition and moved to the National Data Management Office
“Bahrain’s data embassy law protects your data” Legislative Decree No. 56 of 2018 governs foreign parties storing data in Bahraini data centres under their own home law. It does not exempt a Bahraini controller from the PDPL

Table 3. Claims that survive a questionnaire and fail a document review.

Where gulfHR fits

gulfHR is an enterprise HR and payroll platform built for complex GCC workforces, and it holds itself to the evaluation described above rather than standing outside it. Table 4 applies this article’s own nine-artefact test to gulfHR.

Artefact gulfHR position Reviewed with you during scoping
ISO/IEC 27001 certificate Held. Certificates are in place for gulfHR and for OPS, the connected payroll operation within Gulf Solutions Group. The certificate itself, and its scope statement. Read the scope line as you would for any vendor.
Statement of Applicability Version 5.0, dated 31 March 2026. That version by name, and confirmation that it is the version the certificate was issued against.
SOC 2 Type 2 report gulfHR’s platform assurance is its ISO/IEC 27001 certification. The hosting layer carries Microsoft Azure’s SOC 2 Type 2. The two layers are evidenced separately, as the carve-out method above describes: the ISO/IEC 27001 certificate and Statement of Applicability for the platform, Azure’s SOC 2 Type 2 for the infrastructure beneath it.
Cloud and privacy standards A privacy information standard is being implemented, and ISO/IEC 42001 certification is in progress. The standard being adopted, its current stage, and where those controls sit in the named Statement of Applicability.
Penetration test evidence The most recent test was conducted on 20 August 2026. The scope statement, the tester’s accreditation, the risk ratings and the remediation status of each finding.
Business continuity evidence In place. RTO and RPO as contractual commitments, plus the date and result of the last restoration test.
Sub-processor list Maintained. The list with locations, and the notification period for changes.
Data processing agreement In place. The breach notification clock to you, the audit right and the assistance obligations.
Exit and deletion terms In place. Export format, retention window, deletion certificate, and whether backups are in scope.

Table 4. This article’s nine-artefact test applied to gulfHR. Positions confirmed internally on 17 September 2026 by gulfHR’s ISO standards, governance and risk function.

Every artefact in that list exists and can be walked through in a scoping session. The right-hand column is the detail a security reviewer will want alongside each document, and it is the same detail this article asks you to require of any vendor, including this one. A buyer who works through Table 1 with gulfHR gets the same answers set out here.

Three further points sit outside the artefact list. The gulfHR managed cloud is hosted on Microsoft Azure with enterprise-grade security, and the specific region and residency arrangement are confirmed during scoping rather than assumed. gulfHR-managed cloud, customer-managed cloud and on-premises deployment are all available, and the choice moves the shared responsibility boundary, so that boundary should be documented during solution design rather than inferred. Role-based access and audit trail are core to how the platform is built, and exactly which controls apply to your configuration, and which statutory calculations are native rather than configured in each country, should be confirmed during scoping.

If you are building an evidence pack, the related reading is our HRMS evaluation checklist for the weighted scoring instrument, the ten questions to ask before buying an HRMS for the demonstration requests, and cloud HR software in Dubai for hosting and data residency in the UAE specifically. Once a vendor is selected, implementation readiness covers the decisions to settle before kickoff, and running one HRMS across six countries covers what the multi-country operating model has to hold together.

Take the evidence pack into your next vendor session

Speak to gulfHR about your HR and payroll security and compliance requirements across the GCC. We will work through the same nine artefacts, on our platform and on any other you are assessing.

Speak to gulfHR  →

Frequently asked questions

What documents should I ask an HRMS vendor for before implementation?

Nine: the ISO/IEC 27001 certificate, the Statement of Applicability version it names, a SOC 2 Type 2 report, the editions of any cloud or privacy standards claimed, penetration test evidence with scope and remediation status, business continuity objectives with the last test date, the sub-processor list with locations, the data processing agreement with its breach notification clock, and written exit and deletion terms including whether backups are in scope.

Is ISO 27001 certification enough on its own?

No, because a certificate attests to a management system within a defined scope, not to the security of a specific product. Read the scope line to confirm it covers the platform and its hosting, confirm the edition is 2022, and ask for the Statement of Applicability version named in the certification documents to see which controls were excluded and why.

Does UAE law require HR data to be hosted in the UAE?

Not for an ordinary private-sector employer. Federal Decree-Law No. 45 of 2021 regulates the conditions of cross-border transfer rather than the location of storage. The UAE localisation rules that do exist are sectoral and cover health data held by health entities and consumer and transaction data held by licensed financial institutions.

Is there a single GCC breach notification deadline?

No. The rules differ by jurisdiction and many depend on the risk or harm caused by the breach. Saudi Arabia requires notification to the competent authority within 72 hours where the statutory harm or rights threshold is met. Bahrain and Oman also operate 72-hour regimes subject to their applicable thresholds. ADGM and the QFC require notification within 72 hours unless the relevant low-risk exception applies. DIFC requires notification as soon as practicable in the circumstances. Qatar’s Law No. 13 of 2016 does not prescribe a numerical deadline, although NCSA guidance states 72 hours for qualifying breaches. UAE federal Article 9 does not itself prescribe a fixed number of hours. Kuwait has no single general breach-notification deadline for all private employers under the Electronic Transactions Law, while CITRA-licensed service providers are subject to a 24-hour requirement under Decision No. 26 of 2024.

What is a complementary user entity control and why does it matter to HR?

It is a control the vendor’s SOC 2 report assumes the customer operates, so the opinion depends on work you do. In an HRMS this typically covers user provisioning and deprovisioning, approval of privileged access, periodic access review and authentication configuration. Reading this section during evaluation tells you what your own team is committing to at go-live.

Do GCC data protection rules treat nationals and expatriates differently?

No. Unlike end-of-service and social insurance rules, which branch on nationality in every GCC state, the personal data regimes do not distinguish nationals from expatriates. Bahrain keys on residence and place of business, Oman on the fact of processing, and the others likewise. Security controls should not be differentiated by employee nationality.

Sources

  1. Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, Articles 8, 9, 10, 20, 22, 23 and 26. UAE Legislation Portal
  2. Data protection laws. UAE Government portal
  3. Data Protection Law, DIFC Law No. 5 of 2020, consolidated July 2025, Articles 14, 16, 24 and 41. Dubai International Financial Centre
  4. Data breach notifications, Data Protection Regulations 2021, sections 24, 26, 30, 32 and 35. Abu Dhabi Global Market
  5. Consumer Protection Standards, Article 6, and Outsourcing Regulation for Banks C 14/2021, Article 6. Central Bank of the UAE Rulebook
  6. Federal Law No. 2 of 2019 on the Use of ICT in Health Fields, Articles 2 and 13. UAE Legislation Portal
  7. Personal Data Protection Law, Implementing Regulation and Regulation on Personal Data Transfer Outside the Kingdom. Saudi Data and AI Authority, National Data Governance Platform
  8. Essential Cybersecurity Controls ECC-2:2024 and Cloud Cybersecurity Controls CCC-2:2024. National Cybersecurity Authority, Saudi Arabia
  9. International personal data transfers under Saudi Arabia’s data protection law, 17 November 2025. King & Spalding
  10. Cloud Computing Services Provisioning Regulations, Decision No. 506/1445. Communications, Space and Technology Commission, Saudi Arabia
  11. Law No. 13 of 2016 on Personal Data Privacy Protection, Articles 13, 14 and 15; guidelines released 31 January 2021. Ministry of Transport and Communications, Qatar
  12. Cyber Security Guidelines for Defining NIAP Scope Statements and National Information Assurance Policy v2.0. National Cyber Security Agency, Qatar
  13. Data protection, and Personal Data Breach Reporting Form citing Article 31. Qatar Financial Centre
  14. Cloud First Policy, Reference P005, version 1.0.0, April 2024. Hukoomi, Qatar
  15. Resolution No. 42 of 2021 on the Data Privacy Protection Regulation. Communication and Information Technology Regulatory Authority, Kuwait
  16. Kuwait data privacy protection regulations, February 2024. Al Tamimi & Company
  17. Law No. 30 of 2018 on the Protection of Personal Data, Articles 8, 10, 12, 13, 14, 55, 58 and 59. Personal Data Protection Authority, Bahrain
  18. Ministerial Order No. 43 of 2022 on technical and organisational measures, Articles 2, 3 and 4, and Order No. 42 of 2022 listing countries with adequate protection. Ministry of Justice, Islamic Affairs and Waqf, Bahrain
  19. Diplomatic immunity for data: Bahrain’s data embassy law, on Legislative Decree No. 56 of 2018. Al Tamimi & Company
  20. Personal Data Protection Law, Royal Decree No. 6 of 2022, and Executive Regulations, Ministerial Decision No. 34 of 2024. Ministry of Transport, Communications and Information Technology, Oman
  21. Oman updates its Personal Data Protection Law, on Royal Decree No. 68 of 2026. CMS
  22. ISO/IEC 27001:2022, ISO/IEC 27017:2026, ISO/IEC 27018:2025, ISO/IEC 27701:2025, ISO/IEC 27706:2025, ISO/IEC 42001:2023 and ISO 22301:2019, and the Certification page. International Organization for Standardization
  23. IAF MD 26:2023, Transition Requirements for ISO/IEC 27001:2022, and IAF MD 5:2019 on audit time. International Accreditation Forum
  24. Auditing Practices Note on the Statement of Applicability, N3298, 10 September 2022. ISO/IEC JTC 1/SC 27/WG 1
  25. What to look for on a certificate. ANSI National Accreditation Board
  26. Description Criteria for a SOC 2 report and the SOC 2 reporting guide. AICPA & CIMA
  27. SOC FAQ, and the five trust service criteria of a SOC 2 audit. Baker Tilly
  28. How to read a SOC report, and bridge letters. Wipfli
  29. STAR Registry and STAR Attestation. Cloud Security Alliance
  30. Penetration testing: how to get the most from penetration testing. National Cyber Security Centre, United Kingdom
  31. Cloud security shared responsibility model. National Cyber Security Centre, United Kingdom
  32. NIST SP 800-34 Rev. 1, definitions of recovery time objective and recovery point objective. National Institute of Standards and Technology
  33. Data Bytes 67, on the status of the UAE PDPL Executive Regulations, 17 July 2026. Ashurst Perkins Coie
  34. Data Protection & Privacy 2026, UAE, Qatar and Kuwait chapters. Chambers and Partners

This article is general guidance on evaluating vendor security evidence and is not legal advice; statutory deadlines, penalties and transfer mechanisms change, so confirm any figure or requirement with the named authority before relying on it.

ABOUT gulfHR

gulfHR is a trusted provider of robust enterprise-grade HR and payroll software, serving customers in the Middle East for over 20 years. GulfHR has been purpose-built to manage complex, multi-entity and multi-region, workforces operations across the UAE, GCC, and wider MENA region.

With a focus on automation, centralised control, regulatory compliance, and operational governance, gulfHR delivers structured solutions for:

  • Multi-entity payroll and WPS compliance
  • Time, attendance, and shift management
  • Leave and workforce policy management
  • Onboarding and employee lifecycle management
  • Performance tracking and consolidated reporting

Built for complex organisational structures, gulfHR ensures accuracy, audit-readiness, and integrations with ERP, biometric, and banking tools, enabling executive and finance teams to maintain  visibility and operational control.