Deal-making · Compliance

A few years ago, a security questionnaire was a formality you filled in after the deal was agreed. Today it arrives before the deal, and a weak answer kills it. If you sell to larger companies in the Gulf, Brazil, or Europe, your compliance posture is no longer a back-office concern. It’s a line item in their procurement, and increasingly it’s the line that decides whether you make the shortlist.

Key facts

  • Security questionnaires now arrive before pricing, not after.
  • Relevant regimes: UAE PDPL, Brazil's LGPD, EU's NIS2/GDPR.
  • A weak compliance answer now kills deals outright, not just slows them.

That last phrase, prove on demand, is the whole game. Buyers don’t want to hear that you take security seriously. They want a document, a policy, a control they can point to. Most mid-market companies have some of the substance and almost none of the evidence. Closing that gap is faster and cheaper than people fear.

What’s actually changed in each market

The Gulf (UAE-led). The federal Personal Data Protection Law has been in force since 2022, and the Information Assurance Standard, now 188 controls extended to cloud, AI, IoT, and supply-chain risk, became mandatory this year for government, semi-government, and critical-infrastructure entities. PDPL penalties run from AED 100K to 1M; critical-infrastructure harm reaches AED 3M. And there’s a trap most firms miss: the ADGM and DIFC free zones run their own data-protection regimes.

Brazil (LGPD). The national data authority has gone from “moderately active” to genuinely aggressive, with roughly BRL 98M in fines over the last two years. The detail that catches exporters: the grace period for Brazil’s standard contractual clauses ended in 2025, so any cross-border data flow. Brazil to the Gulf, Brazil to Europe, now needs a formal transfer mechanism you can show on paper.

Europe (NIS2). If you supply European customers, you’re likely in scope even if you don’t think you are. NIS2’s supply-chain clause pulls in mid-market vendors below the size threshold because their large customers are obligated to vet them. The incident clock is unforgiving: 24-hour early warning, 72-hour full report, one-month final report. And the directive creates personal liability for board members.

The mistake that costs the deal

The expensive error isn’t non-compliance. It’s gold-plating, spending on a maximal security programme when your buyer needed three specific things, or discovering mid-sales-cycle that you can’t answer a questionnaire you could have prepared for in a fortnight.

What works is the opposite: figure out which regimes genuinely apply, map the handful of controls your buyers and regulators actually ask about, and build the evidence pack before you need it.

The bottom line

Compliance has quietly become a commercial function. The companies winning enterprise and public-sector contracts in these markets aren’t the most secure on paper, they’re the ones who can prove a proportionate posture the moment a buyer asks.


The Tek Atelier builds proportionate, board-ready compliance programmes across the Gulf, Latin America, and Europe. Get in touch.

// About the author

Mario Pucciarelli is the founder of The Tek Atelier. 25 years in enterprise technology, 12 of them living and working in the Gulf as the in-region presence for US and European multinationals across cybersecurity, identity, AI, IT, and telco. CISSP, Aeronautical Engineer, Executive MBA (University of Bologna). Works in English, Italian, Spanish, and Portuguese.

More about the practice →

Have questions on how this affects your business?

Book a call