Creuto is now an OpenAI Select Partner Read More
UAE data residency, checked against the law: the PDPL restricts transfers but mandates nothing. No adequacy list, no UAE standard clauses, and who is exempt.

UAE data residency is not one rule, and the federal privacy law everyone cites for it does not require your data to stay in the country. Federal Decree-Law 45 of 2021 restricts transfers abroad; it never mandates in-country storage. The hard localisation sits in banking and health rules the same law explicitly carves out.
That distinction decides your architecture. If you are a SaaS company, a marketplace or an e-commerce platform serving UAE customers, the federal law gives you transfer conditions to satisfy, not a region to deploy into. If you process bank customer data or health data from services delivered in the UAE, a different instrument applies and the answer is in-country, with a fine attached.
Here is the shape of it, checked on 8 October 2026:
| Instrument | What it does | Who it binds |
|---|---|---|
| Federal Decree-Law 45/2021 (PDPL) | Conditions on transferring personal data outside the UAE. No localisation requirement. | Controllers and processors inside and outside the UAE handling data of people in the UAE — with wide exclusions |
| CBUAE Outsourcing Regulation C 14/2021 | Master system of record must be stored in the UAE; confidential customer data needs approval and consent to leave | Banks operating in the UAE |
| Federal Law 2/2019 (ICT in health fields) | Health data from services provided in the UAE may not be stored, processed, generated or transferred abroad without a decision permitting it | Anyone using ICT in health fields in the UAE, including the free zones |
| DIFC Law 5/2020, ADGM Regulations 2021 | Their own transfer regimes, with a published adequacy list and standard clauses | Entities in those financial free zones |
The PDPL has two cross-border articles and neither is a residency rule. Article 22 permits transfer where the destination state or province has personal data protection legislation covering the substantive protections and has a judicial or regulatory authority able to impose measures on the controller or processor, or where the UAE has joined a bilateral or multilateral data protection agreement with it. Article 23 then says that notwithstanding Article 22, data may still go out under a contract obliging the receiving company to adopt the measures and controls the PDPL sets out, or on the data subject's explicit consent, or where the transfer is necessary for a contract, for judicial proceedings, for international judicial cooperation, or to protect the public interest.
Read together, that is a GDPR-shaped transfer regime: adequacy first, contractual safeguards and consent as fallbacks. Nothing in it says a copy must remain in the UAE.
One date in circulation is wrong. Coverage routinely gives the PDPL an effective date of September 2023. The official legislation portal records it as issued 20 September 2021, published in Official Gazette 712 on 26 September 2021, and in force as of 2 January 2022 — which is also what the UAE government portal says. September 2023 looks like a guess at when the compliance clock would run out, and that clock works differently.
Article 23(2) of the PDPL hands the detail of the contractual route to Executive Regulations. Article 28 required the Council of Ministers to issue those regulations within six months of the decree-law being promulgated — so by around March 2022. Article 29 then gives controllers and processors six months from the issuance of the Executive Regulations to regularise their status.
As of 8 October 2026 we could not find those regulations published. The legislation portal's entry for the decree-law states that the last update to it was listed on 20 September 2021 and lists no related legislation, with the site itself timestamped 2 October 2026. Chambers' UAE data protection guide, last updated 10 March 2026, says the implementing regulations have yet to be issued. DLA Piper's guide, current as of 6 January 2025, says the same and notes that further detail on transfers is awaited from the regulator.
Three consequences follow:
The contrast with the financial free zones is sharp. The DIFC Commissioner of Data Protection publishes a List of Adequate Data Protection Regimes naming the EU and EEA states, the UK, Japan, Singapore, South Korea, Canada, Switzerland, California, ADGM and the QFC among others, plus its own standard contractual clauses based on the European and UK models. If you are inside the DIFC you have the compliance path the mainland lacks. If you are outside it, you improvise.
This is where most coverage goes wrong, and it goes wrong in the direction of selling you more compliance than you need. Article 2(2) of the decree-law excludes, in terms: government data; governmental entities that control or process personal data; personal data held by the security and judicial authorities; a person processing their own data for personal purposes; personal health data that has legislation regulating its protection and processing; personal banking and credit data that have legislation regulating their protection and processing; and companies and establishments located in UAE free zones that have their own special personal data protection legislation.
So the two sectors with real in-country mandates are the two the PDPL does not govern. A hospital group's patient records are not a PDPL cross-border problem; they are a Federal Law 2/2019 problem. A bank's customer accounts are not a PDPL cross-border problem; they are a Central Bank problem. Writing "PDPL compliance" on a hosting decision for either one is a category error, and a DIFC or ADGM entity that has been told the PDPL binds it has been told something the statute says it does not.
What is caught is everything else with a UAE-resident user base: Article 2(1)(c) reaches a controller or processor resident outside the UAE that processes personal data of data subjects inside it. That extraterritorial hook is in the text. Whether it has been used is a separate question — we found no published enforcement decision under the PDPL naming a company, a date or an amount, and we are not going to assert a willingness to enforce that we cannot show.
For banks, the binding text is the Central Bank's Outsourcing Regulation for Banks, C 14/2021, effective 15 July 2021. Article 6.1 requires that the Master System of Record — defined in Article 1.8 as the collection of all data, including confidential data, required to conduct all core activities of the bank — be "continuously maintained and stored within the UAE". Branches of foreign banks may, with Central Bank approval, satisfy this by keeping a copy inside the UAE updated at least daily (6.2). Separately, customer confidential data must not be shared outside the UAE without Central Bank approval and the customer's prior written consent, including a written acknowledgement that the data may be accessed under legal proceedings abroad (6.3). Article 6.6 bars storing data in any jurisdiction whose secrecy or other laws would limit supervisory access.
Note what 6.1 does not say. It does not forbid processing elsewhere — 6.3 to 6.6 govern that, through approval, consent and jurisdiction tests. A bank can run a cross-border analytics pipeline; it cannot hold its system of record abroad, and it cannot move confidential data without two approvals.
For health, Article 13 of Federal Law 2 of 2019 on the use of ICT in health fields is blunter: health information and data related to health services provided in the UAE "may not be stored, processed, generated or transferred outside the State, unless in the cases defined by virtue of a decision issued by the Health Authority in coordination with the Ministry." Article 2 applies the law to all ICT uses in health fields in the UAE "including the Free Zones". Article 24 makes a breach of Article 13 punishable by a fine of not less than AED 500,000 and not more than AED 700,000. That is a statutory criminal fine with a published range — unlike the PDPL. A companion post covers the hosting specifics for health workloads; the point here is that the instrument is different and the consequence is concrete.
Article 26 of the PDPL does not set fines. It says the Council of Ministers, on the proposal of the Bureau's General Director, shall issue a decision defining the acts that constitute violations and the administrative penalties to be imposed. We could not find that Cabinet decision published. The AED 5 million ceiling that circulates in compliance marketing does not trace to it, and the USD 10,000–100,000 range that appears in some guides is the DIFC's Schedule 2, a free-zone instrument, not a federal one. We are cutting the number rather than repeating it: as of 8 October 2026 there is no published federal penalty schedule under the PDPL that we could verify. That is a weaker position for the regulator and a worse one for your legal team, because unquantified exposure is harder to budget than a known maximum.
The regulator has also changed, and most coverage has not caught up. Nearly every guide names the UAE Data Office, established by Federal Decree-Law 44 of 2021, as the enforcer. On 14 June 2026 the UAE Cabinet announced the Artificial Intelligence and Data Authority, "the single national body responsible for data, artificial intelligence and digital government in the UAE, reporting directly to the Cabinet", chaired by Omar Sultan Al Olama. The announcement states the Authority brings together under one mandate the functions previously held by three entities, naming the UAE Data Office as one of them. The decree-law's own text still refers to "the Bureau". If you are negotiating a data processing agreement that names the UAE Data Office as the supervisory authority, that clause now points at a body whose functions have moved.
Assume you have decided, for sector reasons or commercial ones, that your data stays in the UAE. The commitment is made at five layers, and it is the third and fourth that quietly stop being true.
Two readings of ours, offered as readings rather than rules. First, a CDN edge presence in Dubai is not residency. Caching and terminating TLS in-country does not change where the record of truth lives, and CBUAE 6.1 is about where data is maintained and stored, not where it is served from. Verify which region holds the primary and the backups, not which city has a point of presence. Second, if you are going to make a contractual residency commitment, make it name the four things that actually leak: the data, the metadata, the backups and the analytics copies. A clause that says "customer data is stored in the UAE" and is silent on backups is a clause your own architecture will breach in week three.
We should be plain about our standing here. Creuto has no delivery record in the UAE — we are reading the published law, the Central Bank rulebook and the Cabinet's own announcements, not reporting on projects we have shipped there. Our cloud and DevOps engineering work is where this intersects our practice, and if you are planning a build for the UAE market the residency decision belongs upstream of the architecture, not downstream of it.
The next decision is narrower than "do we need a UAE region". It is: name the sector instrument that binds you, or establish that none does. If it is the Central Bank or the health law, the answer is in-country and the engineering follows. If it is only the PDPL, you have a contract to draft and a transfer basis to document — and no list and no template to do it with, which is a drafting problem rather than a deployment one. Those are different budgets, and conflating them is how teams end up paying for a sovereign region they were never required to buy.
Federal Decree-Law 45 of 2021 does not require personal data to stay in the UAE. It sets conditions on transferring data abroad. In-country storage is mandated separately for bank records by the Central Bank's Outsourcing Regulation and for health data by Federal Law 2 of 2019.
As of 8 October 2026 we found no UAE standard contractual clauses published at federal level, and no list of adequate jurisdictions. The PDPL's contractual route in Article 23 still applies, but teams draft the clauses themselves against the measures the law sets out.
A CDN edge in Dubai is not data residency, in our reading. Caching and terminating connections in-country does not change where the record of truth lives. The Central Bank rule is about where data is maintained and stored, so check the primary and backup regions instead.
Banking and health are the two with hard localisation. Banks must keep the master system of record inside the UAE under Central Bank Regulation C 14/2021. Health data from services provided in the UAE may not be stored or transferred abroad without an authority decision permitting it.
The PDPL sets no fine amounts. Article 26 leaves administrative penalties to a Cabinet decision, which we could not find published as of 8 October 2026. The UAE Data Office's own functions moved to the Artificial Intelligence and Data Authority on 14 June 2026.
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.
11th Floor, O-Hub, Chandaka Industrial Estate, Infocity, Bhubaneswar, Odisha 751024
Level 4, 11 York Street Sydney Startup Hub Sydney, NSW – 2000
30 N. Đinh Nghệ, Phước Mỹ Sơn Trà, Đà Nẵng / Da Nang City – 550000
Level 25, AIDP Business Tower, Dubai Marina, United Arab Emirates
50 Beauchamp Street, Wellington, WGN 5028, New Zealand