1. Scope
COCIS applies to all employees, contracted consultants, admin users and partners who access the One Stop Shop portal or customer data, including subcontractors processing data on behalf of One Stop Shop.
Last updated: April 2026
This document is an operational policy (COCIS) for One Stop Shop. It is designed to support personal data security requirements and organisational measures under UAE PDPL, and must be reviewed by a UAE lawyer before final adoption. We do not build an open marketplace. We build a controlled process with traceability and documentation. Data is processed purpose-driven and secured with technical and organisational measures in accordance with UAE PDPL.
COCIS applies to all employees, contracted consultants, admin users and partners who access the One Stop Shop portal or customer data, including subcontractors processing data on behalf of One Stop Shop.
One Stop Shop does not tolerate corruption, informal side agreements outside the platform, or pressure to circumvent public procedures. All delivery must be traceable, documented and through the portal.
Access to customer data and documents is granted only when needed to deliver services. Personal data must be limited to what is necessary for the purpose (PDPL requirement).
Encryption of stored data and encrypted transport (TLS)
Role-based access (RBAC), MFA for admin, and logging of all actions on sensitive objects
Pseudonymisation where appropriate (e.g. in internal datasets/test environments)
Separation of environments (prod/stage/dev) and prohibition of real customer data in test without approval
Regular testing of security measures and recovery procedures
Public: Marketing, general texts
Internal: Operational data without personal information
Confidential: Customer profiles, contracts, payment status
Sensitive: ID documents, signed legal documents, police clearance (if collected)
Data must not be retained longer than necessary for the purpose, unless anonymised or needed for legal claims.
Signed contracts + signing evidence: 7 years after case closure
Invoices, receipts, payment logs: 7 years after tax period
Passport/ID copies: 2 years after case closure (+ legal hold for disputes)
Reference check notes: 5 years after partnership ends
Police clearance: 12 months or until assignment ends
Customer support/complaints: 3 years after closure
Cookie consent log: 24 months
Marketing consent: 5 years after last contact
In case of suspected data breach, unauthorised access or leakage:
Secure evidence, stop further damage, activate incident process
Notify relevant internal owner (Security/Privacy) immediately
Assess notification obligation to Bureau/Office (PDPL art. 9)
Document the incident, including expected impact and corrective measures
One Stop Shop shall assess whether there is an obligation to appoint a DPO (e.g. for large-scale sensitive data processing or high-risk technology).
All vendors processing data must have a written agreement covering instructions, security, sub-processors, logging and deletion.
One Stop Shop reserves the right to audit access, logs and compliance, and to suspend/terminate access for breaches.