United Arab Emirates
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
The national privacy law has been in force since January 2022, but the rules that make it work were never written, so almost none of it can be enforced. Meanwhile the industries that matter have hard walls: health records, payment data, insurance data and identity-check reports must stay inside the country. Two financial districts run their own separate privacy systems, and those regulators do issue penalties.
Eight questions about the United Arab Emirates
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do the United Arab Emirates' rules apply to my company?
Yes. The national privacy law reaches a company with no office in the country, as long as it handles the personal data of people inside the country. There is no revenue or headcount threshold to hide under. But the law carves out huge areas: government bodies, government data, health data, banking and credit data, and companies inside the financial free zones that have their own privacy laws.
Federal Decree-Law No. 45 of 2021, Article 2(1), applies to 'each Controller or Processor residing outside the State and carrying out the activities of processing Personal Data of Data Subjects inside the State'. Article 2(2) excludes government data, governmental entities that control or process personal data, security and judicial authority data, health data and banking/credit data that already have their own legislation, and companies established in free zones that have their own personal data protection legislation. A data protection officer is required under Article 10 only where processing is high risk, involves systematic assessment of sensitive data, or involves large volumes of sensitive data; the law does not on its face require that person to be resident in the country. No general in-country representative duty appears in the statute — that kind of detail was left to Executive Regulations that have not been issued.
Sources
- Official sourceUAE Legislation Portal, Ministry of JusticeFederal Decree-Law No. 45 of 2021 on the Protection of Personal Data — Articles 2, 7 and 10
uaelegislation.gov.ae
“Each Controller or Processor residing outside the State and carrying out the activities of processing Personal Data of Data Subjects inside the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 — official record: issued 20 September 2021, effective 2 January 2022, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
Can I store my users' data outside the United Arab Emirates?
It depends entirely on your industry. Under the national law data can leave once you have the right paperwork, and in practice nobody is checking. But four industries have real walls. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. And since April 2026 the national identity-check report may not be taken out of the country at all.
Headline rating: sectoral. Overrides, each with its own rating: - Health and social care — closed. Federal Law No. 2 of 2019, Article 13: health data generated by services provided inside the country may not be stored, processed, generated or transferred abroad unless the relevant health authority issues a decision in coordination with the Ministry. - Payments — closed. Central Bank Retail Payment Services and Card Schemes Regulation, Circular 15/2021, Article 14(22): personal and payment data shall be stored and maintained in the State. - Insurance — closed. Electronic Insurance Regulations 2020, Article 9(2): data protection must be delivered by measures including storing data inside the State and in the cloud. - Banking and identity checks — closed for one document. Cabinet Resolution No. 55 of 2026, Article 13: users must refrain from transferring the Know Your Customer report or any data in it outside the State. - Government and public sector — outside the national law entirely. Article 2(2) of the national law excludes government data and government entities, leaving residency to internal government policy that is not published as legislation. - Financial free zones (Dubai International Financial Centre and Abu Dhabi Global Market) — conditional. Each has its own privacy law with a European-style approved-destinations list. - Telecoms — no published localisation rule found on the regulator's own list of regulations, checked 18 August 2026. Secondary sources describe an Internet of Things policy requiring in-country storage; see the unconfirmed list. - Mapping and geospatial data — no federal localisation rule found, checked 18 August 2026, confidence medium.
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019 on the Use of Information and Communications Technology in Health Fields — Article 13
uaelegislation.gov.ae
“It is not permissible to store, process, generate or transform the health data and information outside State -which are related to the health services provided inside State- except in the case where a resolution is issued from the Health Authority in coordination with the Ministry.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation (Circular 15/2021), Article 14(22)
rulebook.centralbank.ae
“Personal and Payment Data shall be stored and maintained in the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Executive Regulations of the Know Your Customer Digital Platform law, Article 13
uaelegislation.gov.ae
“Refrain from transferring the 'Know Your Customer' Report or any data contained therein outside the State.”
Link checked 18 August 2026
What do I need in place before data leaves the United Arab Emirates?
On paper the model is an approved-destinations list. The regulator is supposed to name countries whose protection is good enough, and no list has ever been published. So in practice everyone uses the fallback route: a contract with the recipient promising equivalent protection, or the person's explicit consent, or a narrow necessity exception. No government permission is needed and no filing is made, because the rules that would create those steps were never written.
Federal Decree-Law No. 45 of 2021, Article 22, permits transfer where the destination has data protection legislation covering privacy, confidentiality and data subject rights, with judicial oversight of controllers and processors. Article 23 permits transfer to countries without such legislation where the recipient gives binding contractual undertakings of equivalent protection, or on the data subject's explicit consent (where there is no security concern), or where necessary for a contract, legal proceedings, judicial cooperation or public interest. Critically, the approved-destinations list is empty: no adequacy instrument has been published, so Article 22 is a dead letter and Article 23 carries all real-world traffic. Because there is no penalty schedule either, there is presently nothing to fine you with. Sector rules displace all of this: health, payments, insurance and the identity-check report have no transfer route at all except, for health, a specific decision from the health authority.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 — Articles 22 and 23 (cross-border transfer)
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceThe United Arab Emirates' Government portalData protection laws — official government portal description of the law and the UAE Data Office (page updated 4 December 2025)
u.ae
Link checked 18 August 2026
Who enforces the rules in the United Arab Emirates, and what can they do?
On paper the UAE Data Office. In practice it has never enforced anything: it has no public website, it has published no approved-destinations list, and the government decision that would set the fines has not been made. The regulators that really bite are elsewhere — the central bank fined a foreign bank branch about 5.4 million dollars in June 2026, and the data protection commissioner in the Abu Dhabi financial district has issued published penalty notices.
The UAE Data Office was created by Federal Decree-Law No. 44 of 2021 and is described on the government portal as the federal data regulator responsible for policies, standards, complaints systems and guidance. We could not find a website of its own (dataoffice.gov.ae and uaedataoffice.gov.ae do not resolve, checked 18 August 2026), any published register, any guidance document or any decision. Article 26 of the privacy law leaves violations and penalties to be set by a Cabinet decision, and none was found — without it there is no fine to impose. Contrast the sector regulators: the Central Bank of the UAE published financial sanctions of 20,000,000 dirhams (about $5.4m) on 24 June 2026 and 1,820,000 dirhams (about $495,000) on 6 July 2026 against foreign bank branches. The Abu Dhabi Global Market Office of Data Protection has published a penalty notice against Okadoc Technologies Limited (21 May 2024) and a direction against VentureRock Global Limited (23 June 2023) under its own 2021 regulations. Overall rating 'waking': the national regime is dormant, the sector and free-zone regimes are active.
Sources
- Official sourceThe United Arab Emirates' Government portalUAE Data Office — role and establishing law (Federal Decree-Law No. 44 of 2021), government portal, updated 4 December 2025
u.ae
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank of the UAE — 2026 news: financial sanction of AED 20,000,000 (24 June 2026) and AED 1,820,000 (6 July 2026) on foreign bank branches
centralbank.ae
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — published regulatory actions (Okadoc Technologies penalty notice, 21 May 2024; VentureRock Global direction, 23 June 2023)
adgm.com
Link checked 18 August 2026
How long do I have to keep the data?
The floors are long and they are set by industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deletion deadline, because the detailed rules that would set one were never issued.
Floors verified on government sources: 25 years from the last health procedure (Federal Law No. 2 of 2019, Article 20); 5 years for personal and payment data held by payment service providers, plus a secure backup in a separate location (Circular 15/2021, Article 10(10) and Article 14(22)); 5 years for identity-check reports, requests for them and records of provision (Cabinet Resolution No. 55 of 2026, Articles 10, 12 and 13). Ceiling: the privacy law's own minimisation and deletion detail was left to Executive Regulations that do not exist, so there is no enforceable national delete-by date today — confidence medium on that negative. Conflict resolution is unusually clean here and works in favour of the floors: the privacy law expressly does not apply to health data or to banking and credit data that have their own legislation, so a sector retention minimum cannot be overridden by a privacy-law erasure right.
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019, Article 20 — health records kept not less than 25 years from the last health procedure
uaelegislation.gov.ae
“the keeping period shall not be less than (25) twenty-five years from the last date of the health procedure.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation (Circular 15/2021), Article 10(10) — five-year record keeping
rulebook.centralbank.ae
“Payment Service Providers shall keep all necessary records on Personal and Payment Data for a period of (5) years from the date of receipt of such data”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Articles 10, 12 and 13, five-year retention of identity-check reports
uaelegislation.gov.ae
Link checked 18 August 2026
What happens if there is a breach?
There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you discover a breach, and leaves the actual timing and the wording of the notice to detailed rules that were never issued. So the clocks that really run are the ones set by your own regulator: the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not at private companies.
Federal Decree-Law No. 45 of 2021, Article 9, requires the controller to notify the Bureau on discovering a breach affecting the privacy, confidentiality or security of data, with content including the nature and causes of the breach, the approximate number of records, the contact details of the appointed officer, expected impacts and corrective measures. The deadline for telling affected individuals is expressly left to the Executive Regulations. A processor that discovers a breach must tell the controller immediately. Because the Executive Regulations do not exist and the penalty decision under Article 26 does not exist, there is no enforceable national hour-count. The telecoms and digital government regulator operates a cyber incident reporting service whose stated audience is the government sector, and its published service description sets a 3 to 90 working day response window rather than a reporting duty on private firms. Firms in the Dubai International Financial Centre and the Abu Dhabi Global Market are on their own regulators' clocks.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 9 — breach notification, timing left to Executive Regulations
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceTelecommunications and Digital Government Regulatory AuthorityReport a cyber incident — service description, audience stated as the government sector
tdra.gov.ae
Link checked 18 August 2026
- Official sourceUAE Cyber Security CouncilUAE Cyber Security Council — national incident response framework; no public reporting deadline published
csc.gov.ae
Link checked 18 August 2026
What trips people up in the United Arab Emirates?
Five things that cost people their weekend. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones, so most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine is up to about 190 thousand dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but the parental consent line is drawn at 13. Five: there are two extra legal systems inside the country, and their regulators actually issue penalties.
(1) Federal Decree-Law No. 45 of 2021, Article 2(2), excludes government data, government entities, security and judicial data, health data and banking and credit data already covered by their own legislation, and free-zone companies with their own privacy legislation. A compliance programme built only on the national law will miss the rule that binds you. (2) Federal Law No. 2 of 2019, Article 24, sets a fine of not less than 500,000 dirhams (about $136,000) and not more than 700,000 dirhams (about $191,000) for storing or transferring health data abroad, and Article 25 allows health authorities to impose sanctions up to 1,000,000 dirhams (about $272,000) and to cancel a licence. (3) Cabinet Resolution No. 55 of 2026, in force since 21 April 2026, bars users of the national Know Your Customer platform from moving the report or any data in it out of the country — a new hard export ban that predates most published guidance. (4) Federal Decree-Law No. 26 of 2025 on Child Digital Safety defines a child as anyone under 18 but requires documented, verifiable caregiver consent for those under 13, with highest-privacy default settings and easy consent withdrawal. Its penalties are left to a future Cabinet decision, so the duties are live while the sanctions are not. (5) The Dubai International Financial Centre and the Abu Dhabi Global Market are separate legal jurisdictions with their own privacy laws, their own registration duties and their own commissioners. The Abu Dhabi commissioner requires every entity processing personal data to register as a data controller and publishes its enforcement notices.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 2(2) — exclusions for government data, health data, banking data and free-zone companies
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 26 of 2025 on Child Digital Safety — Articles 7, 10 and 11
uaelegislation.gov.ae
“Any human being who has not completed the age of eighteen (18) Gregorian years.”
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — registration of data controllers, adequate jurisdictions approach, regulatory actions
adgm.com
Link checked 18 August 2026
What is changing soon in the United Arab Emirates?
The single biggest thing is a rule that could appear on any Tuesday. When the government finally publishes the detailed rules under the privacy law, every company gets six months to comply and the law switches from decorative to real. Nothing signals when that will happen. In the meantime the new child safety law needs its penalty schedule, and the national identity-check platform is being rolled out across banks.
Dormant switches — powers already held that can change the picture with no consultation: 1. The Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021. They were due within six months of September 2021 and are still not published, nearly five years late. Article 29 gives controllers and processors no more than six months from their issuance to regularise their position, so publication starts a hard six-month clock for every company in the country. 2. The Cabinet decision under Article 26 setting out violations and penalties. Until it exists there is no fine; the day it exists the national law becomes enforceable. 3. The approved-destinations list under Article 22. It has never been populated. Populating it would define, and by implication restrict, lawful destinations. 4. The health authority's power under Article 13 of Federal Law No. 2 of 2019 to permit, or refuse, offshore storage of health data by individual decision. 5. The penalties regulation under Article 16 of the 2025 Child Digital Safety law. Known in-flight items: the national Know Your Customer digital platform, whose Executive Regulations took effect on 21 April 2026 and whose administrative violations regulation is Cabinet Resolution No. 56 of 2026; and the renaming of the securities regulator to the Capital Market Authority, which now publishes its rulebook at a new address.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Articles 26, 28 and 29 — penalties by Cabinet decision, Executive Regulations, six-month compliance window
uaelegislation.gov.ae
“The Controller and the Processor shall regularize their status in compliance with the provisions of this Decree by Law within a period of no more than six (6) months”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalRelated legislation for Federal Decree-Law No. 45 of 2021 — no Cabinet Resolution issuing Executive Regulations listed as at 18 August 2026
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Capital Market AuthorityCapital Market Authority regulations listing — the securities regulator's site now redirects from sca.gov.ae to uaecma.gov.ae
uaecma.gov.ae
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
2 rules here
Layer 2
State or provincial rule
Made by a state or province. Only binds you for people in that state.
1 rule here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
4 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules2 rules
Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data
Act of parliament · Federal Decree-Law No. 45 of 2021, Official Gazette No. 712, 26 September 2021
The national privacy law. It reaches foreign companies that handle the data of people inside the country, and allows transfers abroad on a contract, consent or an approved-destination basis. In practice it is close to unenforceable: the detailed rules required by Article 28 have never been published, the penalty schedule under Article 26 has never been made, and the approved-destinations list is empty. It also does not apply to government data, health data, banking and credit data, or free-zone companies with their own privacy laws.
Enforced by UAE Data Office — not yet operational
Transfer model: Allowlist (the list is currently empty) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Legal claims, Important public interest
What it makes you do
- Get consent
- Tell people what you do
- Keep records of processingArticle 7(4): a special record of personal data covering the controller, the data protection officer, categories of data, authorised personnel, processing times and security measures.
- Secure the data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Report breaches to the regulatorArticle 9: notify on discovery. No hour count in the statute; the timing was left to Executive Regulations that have not been issued.
- Tell affected peopleTimeframe expressly deferred to the Executive Regulations.
- Appoint a data protection officer — applies at: High-risk processing, systematic assessment of sensitive data, or large volumes of sensitive data (Article 10).
- Put a transfer safeguard in place
- Written vendor contract
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data — full text
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 20 September 2021, effective 2 January 2022, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Secondary sourceDLA PiperData Protection Laws of the World — United Arab Emirates (page last modified 27 January 2025): Executive Regulations still unpublished
dlapiperdataprotection.com
Link checked 18 August 2026
Federal Decree-Law No. (26) of 2025 Regarding Child Digital Safety
Act of parliament · Federal Decree-Law No. 26 of 2025, Articles 7, 10, 11 and 16 · Social media and online platforms
A new law in force since 1 January 2026. Online platforms must default children's accounts to the strongest privacy settings, offer parental controls and reporting tools, and get documented, verifiable consent from a caregiver for anyone under 13. A child is anyone under 18. The fines have not been set yet — they were left to a future government decision — so the duties are live while the sanctions are not.
Enforced by Telecommunications and Digital Government Regulatory Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get a parent's consent for children — applies at: Under 13 (a child is anyone under 18), from 1 January 2026Consent must be explicit, documented and verifiable, with an easy and always-available way to withdraw it.
- Secure the data — from 1 January 2026Default and initial privacy settings must be set to the highest level of privacy.
- Tell people what you do — from 1 January 2026Clear, user-friendly reporting tools and parental control tools.
Sources
- Official sourceUAE Legislation PortalFederal Decree-Law No. 26 of 2025 Regarding Child Digital Safety — full text
uaelegislation.gov.ae
“explicit, documented, and verifiable”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 1 October 2025, effective 1 January 2026, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
State or provincial rule1 rule
ADGM Data Protection Regulations 2021
Directly binding regulation · Data Protection Regulations 2021, Abu Dhabi Global Market
Two financial districts sit outside the national privacy law and run their own systems: the Abu Dhabi Global Market under its 2021 regulations, and the Dubai International Financial Centre under its own 2020 law. The Abu Dhabi office keeps a public register, follows a European-style approved-destinations list, and has issued published penalty notices and directions — making it one of the few genuinely operational privacy regulators in the country.
Enforced by Abu Dhabi Global Market Office of Data Protection
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent
What it makes you do
- Register or notifyEvery entity processing personal data must register as a data controller with the Office of Data Protection and pay a fee.
- Report breaches to the regulator
- Put a transfer safeguard in place
- Let people see their data
- Secure the data
What it costs if you get it wrong
- Fixed maximum fineContravention of the 2021 Regulations — penalty notices issued under section 55(1)
- Order to stopDirections issued under section 54(1)
Sources
- Official sourceAbu Dhabi Global MarketADGM Office of Data Protection — Data Protection Regulations 2021, controller registration, adequate jurisdictions (page updated 31 July 2024)
adgm.com
Link checked 18 August 2026
- Official sourceAbu Dhabi Global MarketADGM regulatory actions — penalty notice against Okadoc Technologies Limited (21 May 2024) and direction against VentureRock Global Limited (23 June 2023)
adgm.com
Link checked 18 August 2026
- Official sourceUAE Legislation PortalFederal Decree-Law No. 45 of 2021, Article 2(2) — free-zone companies with their own data protection legislation are excluded from the national law
uaelegislation.gov.ae
Link checked 18 August 2026
Industry rules4 rules
Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields
Act of parliament · Federal Law No. 2 of 2019, Articles 13, 20, 24 and 25 · Health and social care
Health data generated by health services provided inside the country may not be stored, processed, generated or moved abroad at all, unless the relevant health authority issues a specific decision. Records must be kept for at least 25 years after the last treatment. This is the country's hardest data wall and it carries fines of up to about $191,000 plus licence loss.
Enforced by Ministry of Health and Prevention
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryStoring, processing, generating or transforming health data abroad is prohibited unless the health authority issues a decision in coordination with the Ministry.
- Keep data for a minimum period — 25 yearsNot less than 25 years from the date of the last health procedure.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: AED 700,000 — about $191 thousandStoring, processing or transferring health data outside the country (minimum AED 500,000, about $136,000)
- Fixed maximum fine: AED 1,000,000 — about $272 thousandDisciplinary sanctions imposed by health authorities
- Loss of your licenceRepeated or serious breach
Sources
- Official sourceUAE Legislation PortalFederal Law No. 2 of 2019 — full text, Articles 13, 20, 24, 25
uaelegislation.gov.ae
“It is not permissible to store, process, generate or transform the health data and information outside State -which are related to the health services provided inside State- except in the case where a resolution is issued from the Health Authority in coordination with the Ministry.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 6 February 2019, effective 14 May 2019, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceThe United Arab Emirates' Government portalHealth policies and laws — official index listing Federal Law No. 2 of 2019 on ICT in health fields
u.ae
Link checked 18 August 2026
Retail Payment Services and Card Schemes Regulation
Directly binding regulation · Circular No. C 15/2021 · Payments
Anyone licensed to provide retail payment services must keep personal and payment data inside the country, with a separate secure backup, for five years. The regulation gives no route for sending it abroad and is silent on whether an additional copy may sit overseas, so firms treat it as a hard wall.
Enforced by Central Bank of the United Arab Emirates
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryPersonal and payment data must be stored and maintained in the country, with a secure backup in a separate location.
- Keep data for a minimum period — 5 years
- Get consentExplicit consent required before processing personal data of a payment service user.
- Secure the data
Sources
- Official sourceCentral Bank of the UAE RulebookRetail Payment Services and Card Schemes Regulation, Article 14(22) — storage in the State
rulebook.centralbank.ae
“Personal and Payment Data shall be stored and maintained in the State. Payment Service Providers must also establish a safe and secure backup of all Personal and Payment Data in a separate location for the required period of retention of (5) years.”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAE RulebookRegulation contents page — Circular C 15/2021, effective 6 June 2021, status In-Force
rulebook.centralbank.ae
Link checked 18 August 2026
Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations
Directly binding regulation · Board Resolution No. 18 of 2020, Article 9 · Insurance
Insurers selling or servicing policies online must protect electronic customer information by measures that include storing the data inside the country. Confidentiality is permanent, and disclosure is allowed only under a judicial or security order. Supervision passed from the Insurance Authority to the central bank when the two merged.
Enforced by Central Bank of the United Arab Emirates
Transfer model: Not allowed
What it makes you do
- Keep the data in the countryData protection measures must include storing data inside the State and in the cloud.
- Secure the dataLayered supervision, minimum security measures, disaster protocols, backups and website restoration procedures.
- Get consentNo unsolicited marketing messages without prior consent.
Sources
- Official sourceCentral Bank of the UAE RulebookElectronic Insurance Regulations, Article 9 — Information Security and Integrity, effective 28 April 2020, status In-Force
rulebook.centralbank.ae
“storing data inside the State and in the cloud”
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank legislation index — Federal Decree-Law No. 6 of 2025 on the Central Bank, financial institutions and insurance business
centralbank.ae
Link checked 18 August 2026
Cabinet Resolution No. (55) of 2026 Promulgating the Executive Regulations of Federal Decree-Law No. (30) of 2024 Regarding the "Know Your Customer" Digital Platform
Directly binding regulation · Cabinet Resolution No. 55 of 2026, Articles 10, 12 and 13 · Banking
The national customer identity-check platform came fully into effect on 21 April 2026. Businesses using it must not move the identity report, or any data inside it, out of the country, and must keep copies for at least five years. This is the newest hard export ban in the country and it post-dates most published compliance guidance.
Enforced by Central Bank of the United Arab Emirates
Transfer model: Not allowed
What it makes you do
- Keep the data in the country — from 21 April 2026Users must not transfer the customer identity report, or any data in it, outside the country.
- Keep data for a minimum period — 5 years, from 21 April 2026
- Keep records of processing
Sources
- Official sourceUAE Legislation PortalCabinet Resolution No. 55 of 2026 — Executive Regulations of the Know Your Customer Digital Platform law, Article 13
uaelegislation.gov.ae
“Refrain from transferring the 'Know Your Customer' Report or any data contained therein outside the State.”
Link checked 18 August 2026
- Official sourceUAE Legislation PortalOfficial record: issued 20 April 2026, effective 21 April 2026, status Active
uaelegislation.gov.ae
Link checked 18 August 2026
- Official sourceCentral Bank of the UAECentral Bank legislation index linking Federal Decree-Law No. 30 of 2024 and Cabinet Resolutions No. 55 and 56 of 2026
centralbank.ae
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021 have still not been issued as at 18 August 2026
We can show that the official legislation portal lists no Cabinet Resolution issuing them among the law's related legislation, and a professional source dated 27 January 2025 states they were unpublished. The portal's free-text search timed out repeatedly, so we cannot exhaustively prove a negative for the period since January 2025. This is the single most important claim in the record and should be re-checked first at every refresh.
That no Cabinet decision setting violations and penalties under Article 26 of the privacy law exists
Not found on the legislation portal, but the portal search was unavailable. Asserted as 'no rule found, checked 18 August 2026', not as fact.
A telecoms or Internet-of-Things rule requiring data to be stored inside the country
The regulator's own regulations page lists an Internet of Things category with no documents published under it, checked 18 August 2026. Secondary commentary describes an Internet of Things regulatory policy with in-country storage requirements; we could not obtain a government copy, so no such rule is asserted here.
The current text, adequacy list and enforcement record of the Dubai International Financial Centre data protection law
The Centre's website (difc.com and dp.difc.ae) returned bot-protection challenges and 403 errors to every fetch attempt on 18 August 2026. The free-zone rule in this record is backed by the Abu Dhabi regulator's own site instead, and the Dubai position is flagged medium confidence.
Whether any health authority decision has been issued permitting offshore storage of health data under Article 13 of Federal Law No. 2 of 2019, and how wide it is
The exemption power is explicit in the statute, but we could not locate any published decision using it. Health ministry pages blocked automated access.
The data residency policy that applies to government bodies and government data
The national privacy law expressly excludes government data and government entities, so a separate policy must exist. We could not locate a published federal instrument setting it. Emirate-level material on the Dubai digital government and legislation portals was rendered by scripts we could not read.
Any mapping or geospatial data localisation rule
No rule found, checked 18 August 2026, confidence medium. Search of the federal legislation portal was hampered by timeouts.
That the 2026 central bank sanctions were for data or privacy breaches
The published headlines record financial sanctions for regulatory violations without stating the subject matter; they are cited only as evidence that the regulator is operational and imposes large penalties.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- United Arab Emirates versus Argentina
- United Arab Emirates versus Armenia
- United Arab Emirates versus Australia
- United Arab Emirates versus Austria
- United Arab Emirates versus Azerbaijan
- United Arab Emirates versus Brazil
- United Arab Emirates versus Bulgaria
- United Arab Emirates versus Cambodia
- United Arab Emirates versus Canada
- United Arab Emirates versus China
- United Arab Emirates versus Croatia
- United Arab Emirates versus Cyprus
- United Arab Emirates versus Estonia
- United Arab Emirates versus France
- United Arab Emirates versus Georgia
- United Arab Emirates versus Germany
- United Arab Emirates versus Greece
- United Arab Emirates versus Hong Kong SAR
- United Arab Emirates versus Hungary
- United Arab Emirates versus Iceland
- United Arab Emirates versus India
- United Arab Emirates versus Indonesia
- United Arab Emirates versus Ireland
- United Arab Emirates versus Israel
- United Arab Emirates versus Italy
- United Arab Emirates versus Japan
- United Arab Emirates versus Latvia
- United Arab Emirates versus Lithuania
- United Arab Emirates versus Luxembourg
- United Arab Emirates versus Malta
- United Arab Emirates versus Mexico
- United Arab Emirates versus Mongolia
- United Arab Emirates versus Nepal
- United Arab Emirates versus Netherlands
- United Arab Emirates versus Poland
- United Arab Emirates versus Russia
- United Arab Emirates versus Saudi Arabia
- United Arab Emirates versus Serbia
- United Arab Emirates versus Singapore
- United Arab Emirates versus Slovakia
- United Arab Emirates versus Slovenia
- United Arab Emirates versus South Korea
- United Arab Emirates versus Spain
- United Arab Emirates versus Sri Lanka
- United Arab Emirates versus Sweden
- United Arab Emirates versus Switzerland
- United Arab Emirates versus Taiwan
- United Arab Emirates versus Thailand
- United Arab Emirates versus Turkey
- United Arab Emirates versus Ukraine
- United Arab Emirates versus United Kingdom
- United Arab Emirates versus United States
- United Arab Emirates versus Uzbekistan