Creuto is now an OpenAI Select Partner Read More

Software Architecture & Technical

UAE data residency: what actually has to stay in-country

UAE data residency, checked against the law: the PDPL restricts transfers but mandates nothing. No adequacy list, no UAE standard clauses, and who is exempt.

UAE data residency: what actually has to stay in-country

UAE data residency is not one rule, and the federal privacy law everyone cites for it does not require your data to stay in the country. Federal Decree-Law 45 of 2021 restricts transfers abroad; it never mandates in-country storage. The hard localisation sits in banking and health rules the same law explicitly carves out.

That distinction decides your architecture. If you are a SaaS company, a marketplace or an e-commerce platform serving UAE customers, the federal law gives you transfer conditions to satisfy, not a region to deploy into. If you process bank customer data or health data from services delivered in the UAE, a different instrument applies and the answer is in-country, with a fine attached.

Here is the shape of it, checked on 8 October 2026:

InstrumentWhat it doesWho it binds
Federal Decree-Law 45/2021 (PDPL)Conditions on transferring personal data outside the UAE. No localisation requirement.Controllers and processors inside and outside the UAE handling data of people in the UAE — with wide exclusions
CBUAE Outsourcing Regulation C 14/2021Master system of record must be stored in the UAE; confidential customer data needs approval and consent to leaveBanks operating in the UAE
Federal Law 2/2019 (ICT in health fields)Health data from services provided in the UAE may not be stored, processed, generated or transferred abroad without a decision permitting itAnyone using ICT in health fields in the UAE, including the free zones
DIFC Law 5/2020, ADGM Regulations 2021Their own transfer regimes, with a published adequacy list and standard clausesEntities in those financial free zones

What the PDPL actually restricts, and when it came into force

The PDPL has two cross-border articles and neither is a residency rule. Article 22 permits transfer where the destination state or province has personal data protection legislation covering the substantive protections and has a judicial or regulatory authority able to impose measures on the controller or processor, or where the UAE has joined a bilateral or multilateral data protection agreement with it. Article 23 then says that notwithstanding Article 22, data may still go out under a contract obliging the receiving company to adopt the measures and controls the PDPL sets out, or on the data subject's explicit consent, or where the transfer is necessary for a contract, for judicial proceedings, for international judicial cooperation, or to protect the public interest.

Read together, that is a GDPR-shaped transfer regime: adequacy first, contractual safeguards and consent as fallbacks. Nothing in it says a copy must remain in the UAE.

One date in circulation is wrong. Coverage routinely gives the PDPL an effective date of September 2023. The official legislation portal records it as issued 20 September 2021, published in Official Gazette 712 on 26 September 2021, and in force as of 2 January 2022 — which is also what the UAE government portal says. September 2023 looks like a guess at when the compliance clock would run out, and that clock works differently.

Why there is still no adequacy list and no UAE standard contractual clauses

Article 23(2) of the PDPL hands the detail of the contractual route to Executive Regulations. Article 28 required the Council of Ministers to issue those regulations within six months of the decree-law being promulgated — so by around March 2022. Article 29 then gives controllers and processors six months from the issuance of the Executive Regulations to regularise their status.

As of 8 October 2026 we could not find those regulations published. The legislation portal's entry for the decree-law states that the last update to it was listed on 20 September 2021 and lists no related legislation, with the site itself timestamped 2 October 2026. Chambers' UAE data protection guide, last updated 10 March 2026, says the implementing regulations have yet to be issued. DLA Piper's guide, current as of 6 January 2025, says the same and notes that further detail on transfers is awaited from the regulator.

Three consequences follow:

  1. No adequacy list. Article 22 assumes an approved set of destinations. We found none published, which means nobody can rely on Article 22 by pointing at a list.
  2. No UAE standard contractual clauses. There is no federal template to sign. Article 23(1)(a) still works — it is a self-executing condition, not a form-filling exercise — but you are drafting the clauses yourself against the measures in the law, without a safe harbour to quote.
  3. The Article 29 transition has not demonstrably started. The law has applied since January 2022; the six-month regularisation window keyed to the regulations has not opened.

The contrast with the financial free zones is sharp. The DIFC Commissioner of Data Protection publishes a List of Adequate Data Protection Regimes naming the EU and EEA states, the UK, Japan, Singapore, South Korea, Canada, Switzerland, California, ADGM and the QFC among others, plus its own standard contractual clauses based on the European and UK models. If you are inside the DIFC you have the compliance path the mainland lacks. If you are outside it, you improvise.

Who the PDPL does not catch

This is where most coverage goes wrong, and it goes wrong in the direction of selling you more compliance than you need. Article 2(2) of the decree-law excludes, in terms: government data; governmental entities that control or process personal data; personal data held by the security and judicial authorities; a person processing their own data for personal purposes; personal health data that has legislation regulating its protection and processing; personal banking and credit data that have legislation regulating their protection and processing; and companies and establishments located in UAE free zones that have their own special personal data protection legislation.

So the two sectors with real in-country mandates are the two the PDPL does not govern. A hospital group's patient records are not a PDPL cross-border problem; they are a Federal Law 2/2019 problem. A bank's customer accounts are not a PDPL cross-border problem; they are a Central Bank problem. Writing "PDPL compliance" on a hosting decision for either one is a category error, and a DIFC or ADGM entity that has been told the PDPL binds it has been told something the statute says it does not.

What is caught is everything else with a UAE-resident user base: Article 2(1)(c) reaches a controller or processor resident outside the UAE that processes personal data of data subjects inside it. That extraterritorial hook is in the text. Whether it has been used is a separate question — we found no published enforcement decision under the PDPL naming a company, a date or an amount, and we are not going to assert a willingness to enforce that we cannot show.

The sector rules that do mandate in-country data

For banks, the binding text is the Central Bank's Outsourcing Regulation for Banks, C 14/2021, effective 15 July 2021. Article 6.1 requires that the Master System of Record — defined in Article 1.8 as the collection of all data, including confidential data, required to conduct all core activities of the bank — be "continuously maintained and stored within the UAE". Branches of foreign banks may, with Central Bank approval, satisfy this by keeping a copy inside the UAE updated at least daily (6.2). Separately, customer confidential data must not be shared outside the UAE without Central Bank approval and the customer's prior written consent, including a written acknowledgement that the data may be accessed under legal proceedings abroad (6.3). Article 6.6 bars storing data in any jurisdiction whose secrecy or other laws would limit supervisory access.

Note what 6.1 does not say. It does not forbid processing elsewhere — 6.3 to 6.6 govern that, through approval, consent and jurisdiction tests. A bank can run a cross-border analytics pipeline; it cannot hold its system of record abroad, and it cannot move confidential data without two approvals.

For health, Article 13 of Federal Law 2 of 2019 on the use of ICT in health fields is blunter: health information and data related to health services provided in the UAE "may not be stored, processed, generated or transferred outside the State, unless in the cases defined by virtue of a decision issued by the Health Authority in coordination with the Ministry." Article 2 applies the law to all ICT uses in health fields in the UAE "including the Free Zones". Article 24 makes a breach of Article 13 punishable by a fine of not less than AED 500,000 and not more than AED 700,000. That is a statutory criminal fine with a published range — unlike the PDPL. A companion post covers the hosting specifics for health workloads; the point here is that the instrument is different and the consequence is concrete.

The penalty figure you have read is not a published figure

Article 26 of the PDPL does not set fines. It says the Council of Ministers, on the proposal of the Bureau's General Director, shall issue a decision defining the acts that constitute violations and the administrative penalties to be imposed. We could not find that Cabinet decision published. The AED 5 million ceiling that circulates in compliance marketing does not trace to it, and the USD 10,000–100,000 range that appears in some guides is the DIFC's Schedule 2, a free-zone instrument, not a federal one. We are cutting the number rather than repeating it: as of 8 October 2026 there is no published federal penalty schedule under the PDPL that we could verify. That is a weaker position for the regulator and a worse one for your legal team, because unquantified exposure is harder to budget than a known maximum.

The regulator has also changed, and most coverage has not caught up. Nearly every guide names the UAE Data Office, established by Federal Decree-Law 44 of 2021, as the enforcer. On 14 June 2026 the UAE Cabinet announced the Artificial Intelligence and Data Authority, "the single national body responsible for data, artificial intelligence and digital government in the UAE, reporting directly to the Cabinet", chaired by Omar Sultan Al Olama. The announcement states the Authority brings together under one mandate the functions previously held by three entities, naming the UAE Data Office as one of them. The decree-law's own text still refers to "the Bureau". If you are negotiating a data processing agreement that names the UAE Data Office as the supervisory authority, that clause now points at a body whose functions have moved.

Where UAE data residency commitments usually break

Assume you have decided, for sector reasons or commercial ones, that your data stays in the UAE. The commitment is made at five layers, and it is the third and fourth that quietly stop being true.

  • Application tier. Easy. Containers in a UAE region, done.
  • Primary database. Easy, and the thing everyone checks.
  • Backups and snapshots. Cross-region replication is a default in many managed services and a standard disaster-recovery recommendation. A backup in Ireland is data outside the UAE. If you need the disaster recovery story for UAE workloads to survive both a regional failure and a residency clause, that is a design problem, not a checkbox — and it is worth knowing whether the backup you have never restored is even where you think it is.
  • Analytics and the warehouse. The product analytics SDK, the BI warehouse, the error tracker and the session replay tool each take a copy, and their default regions are rarely the Gulf.
  • Third-party processors. Payments, email, SMS, support desk, and now model inference. What stays local when a vendor offers UAE data residency is a contractual question with a different answer per vendor.

Two readings of ours, offered as readings rather than rules. First, a CDN edge presence in Dubai is not residency. Caching and terminating TLS in-country does not change where the record of truth lives, and CBUAE 6.1 is about where data is maintained and stored, not where it is served from. Verify which region holds the primary and the backups, not which city has a point of presence. Second, if you are going to make a contractual residency commitment, make it name the four things that actually leak: the data, the metadata, the backups and the analytics copies. A clause that says "customer data is stored in the UAE" and is silent on backups is a clause your own architecture will breach in week three.

We should be plain about our standing here. Creuto has no delivery record in the UAE — we are reading the published law, the Central Bank rulebook and the Cabinet's own announcements, not reporting on projects we have shipped there. Our cloud and DevOps engineering work is where this intersects our practice, and if you are planning a build for the UAE market the residency decision belongs upstream of the architecture, not downstream of it.

The next decision is narrower than "do we need a UAE region". It is: name the sector instrument that binds you, or establish that none does. If it is the Central Bank or the health law, the answer is in-country and the engineering follows. If it is only the PDPL, you have a contract to draft and a transfer basis to document — and no list and no template to do it with, which is a drafting problem rather than a deployment one. Those are different budgets, and conflating them is how teams end up paying for a sovereign region they were never required to buy.

Frequently asked questions

Federal Decree-Law 45 of 2021 does not require personal data to stay in the UAE. It sets conditions on transferring data abroad. In-country storage is mandated separately for bank records by the Central Bank's Outsourcing Regulation and for health data by Federal Law 2 of 2019.

As of 8 October 2026 we found no UAE standard contractual clauses published at federal level, and no list of adequate jurisdictions. The PDPL's contractual route in Article 23 still applies, but teams draft the clauses themselves against the measures the law sets out.

A CDN edge in Dubai is not data residency, in our reading. Caching and terminating connections in-country does not change where the record of truth lives. The Central Bank rule is about where data is maintained and stored, so check the primary and backup regions instead.

Banking and health are the two with hard localisation. Banks must keep the master system of record inside the UAE under Central Bank Regulation C 14/2021. Health data from services provided in the UAE may not be stored or transferred abroad without an authority decision permitting it.

The PDPL sets no fine amounts. Article 26 leaves administrative penalties to a Cabinet decision, which we could not find published as of 8 October 2026. The UAE Data Office's own functions moved to the Artificial Intelligence and Data Authority on 14 June 2026.

Written by

Akash Mohapatra

Akash Mohapatra

Co Founder & Director

8 Oct 2026

·

12 min read

Share

LET'S CONNECT

Connect with Creuto!

Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.

We don't just aim to fit in – we strive to stand out. Experience the perfect blend of innovation, excellence, and trust that makes us truly unforgettable. Discover the difference with Creuto.

© 2026 Creuto All Rights Reserved