Skip to the content
Global Data RulesData governance rules, country by country

United Arab Emirates

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Waking up

The national privacy law has been in force since January 2022, but the rules that make it work were never written, so almost none of it can be enforced. Meanwhile the industries that matter have hard walls: health records, payment data, insurance data and identity-check reports must stay inside the country. Two financial districts run their own separate privacy systems, and those regulators do issue penalties.

Eight questions about the United Arab Emirates

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do the United Arab Emirates' rules apply to my company?

Yes. The national privacy law reaches a company with no office in the country, as long as it handles the personal data of people inside the country. There is no revenue or headcount threshold to hide under. But the law carves out huge areas: government bodies, government data, health data, banking and credit data, and companies inside the financial free zones that have their own privacy laws.

High confidenceNational rulesAppoint a data protection officer

Can I store my users' data outside the United Arab Emirates?

It depends entirely on your industry. Under the national law data can leave once you have the right paperwork, and in practice nobody is checking. But four industries have real walls. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. And since April 2026 the national identity-check report may not be taken out of the country at all.

High confidenceDepends on your industryNo — it stays putAllowlist

What do I need in place before data leaves the United Arab Emirates?

On paper the model is an approved-destinations list. The regulator is supposed to name countries whose protection is good enough, and no list has ever been published. So in practice everyone uses the fallback route: a contract with the recipient promising equivalent protection, or the person's explicit consent, or a narrow necessity exception. No government permission is needed and no filing is made, because the rules that would create those steps were never written.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesExplicit consentNeeded for a contract

Who enforces the rules in the United Arab Emirates, and what can they do?

On paper the UAE Data Office. In practice it has never enforced anything: it has no public website, it has published no approved-destinations list, and the government decision that would set the fines has not been made. The regulators that really bite are elsewhere — the central bank fined a foreign bank branch about 5.4 million dollars in June 2026, and the data protection commissioner in the Abu Dhabi financial district has issued published penalty notices.

Medium confidenceWaking upActive

How long do I have to keep the data?

The floors are long and they are set by industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deletion deadline, because the detailed rules that would set one were never issued.

High confidenceKeep data for a minimum periodDelete data after a periodKeep records of processing

What happens if there is a breach?

There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you discover a breach, and leaves the actual timing and the wording of the notice to detailed rules that were never issued. So the clocks that really run are the ones set by your own regulator: the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not at private companies.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in the United Arab Emirates?

Five things that cost people their weekend. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones, so most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine is up to about 190 thousand dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but the parental consent line is drawn at 13. Five: there are two extra legal systems inside the country, and their regulators actually issue penalties.

High confidenceGet a parent's consent for childrenRegister or notifyKeep the data in the countryFixed maximum fineLoss of your licence

What is changing soon in the United Arab Emirates?

The single biggest thing is a rule that could appear on any Tuesday. When the government finally publishes the detailed rules under the privacy law, every company gets six months to comply and the law switches from decorative to real. Nothing signals when that will happen. In the meantime the new child safety law needs its penalty schedule, and the national identity-check platform is being rolled out across banks.

Medium confidencePartly in forceDirectly binding regulation

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    2 rules here

  2. Layer 2

    State or provincial rule

    Made by a state or province. Only binds you for people in that state.

    1 rule here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    4 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules2 rules

Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data

Act of parliament · Federal Decree-Law No. 45 of 2021, Official Gazette No. 712, 26 September 2021

Partly in forceYes, with paperwork

The national privacy law. It reaches foreign companies that handle the data of people inside the country, and allows transfers abroad on a contract, consent or an approved-destination basis. In practice it is close to unenforceable: the detailed rules required by Article 28 have never been published, the penalty schedule under Article 26 has never been made, and the approved-destinations list is empty. It also does not apply to government data, health data, banking and credit data, or free-zone companies with their own privacy laws.

In force since 2 January 2022

Enforced by UAE Data Office — not yet operational

Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Legal claims, Important public interest

High confidence

Federal Decree-Law No. (26) of 2025 Regarding Child Digital Safety

Act of parliament · Federal Decree-Law No. 26 of 2025, Articles 7, 10, 11 and 16 · Social media and online platforms

Partly in forceYes — store it anywhere

A new law in force since 1 January 2026. Online platforms must default children's accounts to the strongest privacy settings, offer parental controls and reporting tools, and get documented, verifiable consent from a caregiver for anyone under 13. A child is anyone under 18. The fines have not been set yet — they were left to a future government decision — so the duties are live while the sanctions are not.

In force since 1 January 2026

Enforced by Telecommunications and Digital Government Regulatory Authority

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

State or provincial rule1 rule

ADGM Data Protection Regulations 2021

Directly binding regulation · Data Protection Regulations 2021, Abu Dhabi Global Market

In forceYes, with paperwork

Two financial districts sit outside the national privacy law and run their own systems: the Abu Dhabi Global Market under its 2021 regulations, and the Dubai International Financial Centre under its own 2020 law. The Abu Dhabi office keeps a public register, follows a European-style approved-destinations list, and has issued published penalty notices and directions — making it one of the few genuinely operational privacy regulators in the country.

In force since 14 February 2021

Enforced by Abu Dhabi Global Market Office of Data Protection

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent

Medium confidence

Industry rules4 rules

Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields

Act of parliament · Federal Law No. 2 of 2019, Articles 13, 20, 24 and 25 · Health and social care

In forceNo — it stays put

Health data generated by health services provided inside the country may not be stored, processed, generated or moved abroad at all, unless the relevant health authority issues a specific decision. Records must be kept for at least 25 years after the last treatment. This is the country's hardest data wall and it carries fines of up to about $191,000 plus licence loss.

In force since 14 May 2019

Enforced by Ministry of Health and Prevention

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Retail Payment Services and Card Schemes Regulation

Directly binding regulation · Circular No. C 15/2021 · Payments

In forceNo — it stays put

Anyone licensed to provide retail payment services must keep personal and payment data inside the country, with a separate secure backup, for five years. The regulation gives no route for sending it abroad and is silent on whether an additional copy may sit overseas, so firms treat it as a hard wall.

In force since 6 June 2021

Enforced by Central Bank of the United Arab Emirates

Transfer model: Not allowed

High confidence

Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations

Directly binding regulation · Board Resolution No. 18 of 2020, Article 9 · Insurance

In forceNo — it stays put

Insurers selling or servicing policies online must protect electronic customer information by measures that include storing the data inside the country. Confidentiality is permanent, and disclosure is allowed only under a judicial or security order. Supervision passed from the Insurance Authority to the central bank when the two merged.

In force since 28 April 2020

Enforced by Central Bank of the United Arab Emirates

Transfer model: Not allowed

High confidence

Who you would hear from

  • UAE Data Office

    Not yet live

    مكتب الإمارات للبيانات

    Federal data protection regulator under Federal Decree-Law No. 44 of 2021

    Created in law in 2021 and described on the government portal as the federal data regulator. As at 18 August 2026 we could find no website of its own (dataoffice.gov.ae and uaedataoffice.gov.ae do not resolve), no published guidance, no register, no approved-destinations list and no decisions. The Cabinet decision that would set penalties under Article 26 of the privacy law has not been located either, so there is nothing for it to impose.

  • مصرف الإمارات العربية المتحدة المركزي

    Banking, payments, insurance, exchange houses, the national customer identity-check platform

    Publishes financial sanctions regularly, including AED 20,000,000 (about $5.4m) on 24 June 2026 and AED 1,820,000 (about $495,000) on 6 July 2026 against foreign bank branches.

  • Health data, jointly with the emirate-level health authorities in Abu Dhabi and Dubai

    Holds the power under Article 13 of Federal Law No. 2 of 2019 to permit offshore storage of health data by decision, in coordination with the emirate health authority.

  • Telecoms, digital government, cyber incident reporting for the government sector

  • National cyber security strategy, critical infrastructure protection, national incident response

    Established by the Cabinet in November 2020. Operates a national security operations centre, but publishes no general incident reporting deadline for private companies.

  • هيئة الأوراق المالية والسلع

    Securities and commodities markets

    The former Securities and Commodities Authority site (sca.gov.ae) now redirects to uaecma.gov.ae, indicating a rename. We did not locate a securities data-localisation rule.

  • Personal data in the Abu Dhabi Global Market financial free zone

    Maintains a data controller register and publishes enforcement notices; issued a penalty notice on 21 May 2024 and a direction on 23 June 2023.

  • Personal data in the Dubai International Financial Centre financial free zone

    Widely reported as active, but the Centre's website blocked automated access on 18 August 2026, so we could not verify its current law text, adequacy list or enforcement record from its own site. Treated as medium confidence.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021 have still not been issued as at 18 August 2026

    We can show that the official legislation portal lists no Cabinet Resolution issuing them among the law's related legislation, and a professional source dated 27 January 2025 states they were unpublished. The portal's free-text search timed out repeatedly, so we cannot exhaustively prove a negative for the period since January 2025. This is the single most important claim in the record and should be re-checked first at every refresh.

  • That no Cabinet decision setting violations and penalties under Article 26 of the privacy law exists

    Not found on the legislation portal, but the portal search was unavailable. Asserted as 'no rule found, checked 18 August 2026', not as fact.

  • A telecoms or Internet-of-Things rule requiring data to be stored inside the country

    The regulator's own regulations page lists an Internet of Things category with no documents published under it, checked 18 August 2026. Secondary commentary describes an Internet of Things regulatory policy with in-country storage requirements; we could not obtain a government copy, so no such rule is asserted here.

  • The current text, adequacy list and enforcement record of the Dubai International Financial Centre data protection law

    The Centre's website (difc.com and dp.difc.ae) returned bot-protection challenges and 403 errors to every fetch attempt on 18 August 2026. The free-zone rule in this record is backed by the Abu Dhabi regulator's own site instead, and the Dubai position is flagged medium confidence.

  • Whether any health authority decision has been issued permitting offshore storage of health data under Article 13 of Federal Law No. 2 of 2019, and how wide it is

    The exemption power is explicit in the statute, but we could not locate any published decision using it. Health ministry pages blocked automated access.

  • The data residency policy that applies to government bodies and government data

    The national privacy law expressly excludes government data and government entities, so a separate policy must exist. We could not locate a published federal instrument setting it. Emirate-level material on the Dubai digital government and legislation portals was rendered by scripts we could not read.

  • Any mapping or geospatial data localisation rule

    No rule found, checked 18 August 2026, confidence medium. Search of the federal legislation portal was hampered by timeouts.

  • That the 2026 central bank sanctions were for data or privacy breaches

    The published headlines record financial sanctions for regulatory violations without stating the subject matter; they are cited only as evidence that the regulator is operational and imposes large penalties.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.