Connect Point Dubai
ENG

Code Of Conduct & Information Security (COCIS)

Last updated: April 2026

This document is an operational policy (COCIS) for One Stop Shop. It is designed to support personal data security requirements and organisational measures under UAE PDPL, and must be reviewed by a UAE lawyer before final adoption. We do not build an open marketplace. We build a controlled process with traceability and documentation. Data is processed purpose-driven and secured with technical and organisational measures in accordance with UAE PDPL.

01

1. Scope

COCIS applies to all employees, contracted consultants, admin users and partners who access the One Stop Shop portal or customer data, including subcontractors processing data on behalf of One Stop Shop.

02

2. Ethical Standards And Conduct

One Stop Shop does not tolerate corruption, informal side agreements outside the platform, or pressure to circumvent public procedures. All delivery must be traceable, documented and through the portal.

03

3. Confidentiality And Need-To-Know

Access to customer data and documents is granted only when needed to deliver services. Personal data must be limited to what is necessary for the purpose (PDPL requirement).

04

4. Information Security - Minimum Requirements

Encryption of stored data and encrypted transport (TLS)

Role-based access (RBAC), MFA for admin, and logging of all actions on sensitive objects

Pseudonymisation where appropriate (e.g. in internal datasets/test environments)

Separation of environments (prod/stage/dev) and prohibition of real customer data in test without approval

Regular testing of security measures and recovery procedures

05

5. Data Classification

Public: Marketing, general texts

Internal: Operational data without personal information

Confidential: Customer profiles, contracts, payment status

Sensitive: ID documents, signed legal documents, police clearance (if collected)

06

6. Retention And Deletion

Data must not be retained longer than necessary for the purpose, unless anonymised or needed for legal claims.

Signed contracts + signing evidence: 7 years after case closure

Invoices, receipts, payment logs: 7 years after tax period

Passport/ID copies: 2 years after case closure (+ legal hold for disputes)

Reference check notes: 5 years after partnership ends

Police clearance: 12 months or until assignment ends

Customer support/complaints: 3 years after closure

Cookie consent log: 24 months

Marketing consent: 5 years after last contact

07

7. Incident Handling And Breaches

In case of suspected data breach, unauthorised access or leakage:

Secure evidence, stop further damage, activate incident process

Notify relevant internal owner (Security/Privacy) immediately

Assess notification obligation to Bureau/Office (PDPL art. 9)

Document the incident, including expected impact and corrective measures

08

8. Data Protection Officer (DPO)

One Stop Shop shall assess whether there is an obligation to appoint a DPO (e.g. for large-scale sensitive data processing or high-risk technology).

09

9. Vendor Management

All vendors processing data must have a written agreement covering instructions, security, sub-processors, logging and deletion.

010

10. Audit And Discipline

One Stop Shop reserves the right to audit access, logs and compliance, and to suspend/terminate access for breaches.