MyGatePass crosses 10 million verified entries · Read the milestone
Blog Security & Compliance
Security & Compliance

PII, residency and the GCC: what facility teams need to know

a adil.bouhouch · Compliance · 27 April 2026 · 8 min read

When a visitor checks in, they hand over their name, their identity number, sometimes a photograph and a vehicle plate. That is personal data — and in the GCC it sits under a tightening web of regulation. Facility teams are increasingly accountable for how it is stored, for how long, and where.

Residency is not optional

Under the UAE’s Federal Decree-Law No. 45 of 2021 and equivalent frameworks in Saudi Arabia and Qatar, personal data carries residency and processing expectations. For visitor data specifically, the safest posture is in-country storage, processing and audit — with cross-border replication only on explicit consent.

Retention and the right to be forgotten

A logbook keeps everything forever; a compliant system keeps only what it needs, for only as long as it must. Configurable retention windows and automatic redaction are no longer nice-to-haves — they are how you stay defensible.

The audit team asked for two years of entry data. We exported it, redacted to policy, in six minutes.

The shift facility teams need to make is from “capture and store” to “verify and minimise.” The lobby should hold the least data necessary to prove a verified entry happened — and nothing more.

See it run on a live gate

A 30-minute walkthrough tailored to your facility.

Request a demo
Get started

Turn every arrival into a verified moment.

Pilot MyGatePass on one gate. We’re on-site within 5 business days anywhere in the UAE — and online for the rest of the GCC.