Skip to the content
Global Data RulesData governance rules, country by country

United Arab Emirates

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in the United Arab Emirates — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Waking up

Your industry decides the answer here. The national privacy law started in January 2022. But the detailed rules that make it work were never written. So almost none of it can be enforced. Four kinds of data must stay inside the country: health records, payment data, insurance data and identity-check reports. Two financial districts run their own separate privacy systems. Those regulators do issue fines.

Data governance in the United Arab Emirates

The eight things that decide how you handle data about people in the United Arab Emirates. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The national privacy law applies even if you have no office in the country. It catches you if you handle personal data about people inside the country. There is no revenue or staff-size cut-off to fall below. But the law leaves out large areas. It does not cover government bodies, government data, health data, or banking and credit data. It also does not cover companies inside the financial free zones that have their own privacy laws.

What you have to do here:
Appoint a data protection officer

Where the data is allowed to live

It depends on your industry. Under the national law you can send data abroad once you have the right paperwork. Nobody is checking. But four industries have real bans. Health records may not be stored or sent abroad at all. Payment data must be stored inside the country. Insurance data must be stored inside the country. Since April 2026 the national identity-check report may not be taken out of the country at all.

What to do: Plan for a database inside United Arab Emirates: this data is not allowed to leave.

Sending data out of the country

On paper, you may only send data to countries the regulator has approved. The regulator has never published that list. So everyone uses the backup route instead. That means a contract where the recipient promises the same level of protection. Or the person's explicit consent. Or a narrow necessity exception. You need no government permission and you file nothing. The rules that would have created those steps were never written.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Explicit consent · Needed for a contract

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

On paper, the UAE Data Office. It has never enforced anything. It has no public website. It has published no list of approved countries. The government decision that would set the fines has not been made. The regulators that act are elsewhere. The central bank fined a foreign bank branch about 5.4 million US dollars in June 2026. The data protection commissioner in the Abu Dhabi financial district has published penalty notices.

Not fully verified — see “What we're not sure about” below.

How long you must keep it — and when to delete it

How long you must keep data is set by your industry, not by the privacy law. Health records must be kept for at least 25 years after the last treatment. Payment data must be kept for 5 years, with a separate backup. Identity-check reports must be kept for at least 5 years. There is no working national deadline to delete data. The detailed rules that would set one were never issued.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep records of how you use data

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There is no national deadline in hours today. The privacy law says you must tell the regulator as soon as you find a breach. It leaves the exact timing and the wording of the notice to detailed rules that were never issued. So the deadlines that really run come from your own regulator. That means the central bank for financial firms, and the separate data protection offices in the two financial districts. The national cyber incident reporting service is aimed at government bodies, not private companies.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things catch people out. One: the national privacy law does not cover health data, banking data, government data, or companies in the financial free zones. Most regulated firms are not governed by it at all. Two: health data may not leave the country, ever, and the fine goes up to about 190 thousand US dollars. Three: since April 2026 the national identity-check report may not be sent abroad. Four: a child is anyone under 18, but you only need a parent's consent for children under 13. Five: two extra legal systems run inside the country, and their regulators do issue penalties.

What you have to do here:
Get a parent's consent for children · Register or notify · Keep the data in the country
What it costs if you get it wrong:
Fixed maximum fine · Loss of your licence

What's changing next

The biggest change could land on any day. When the government publishes the detailed rules under the privacy law, every company gets six months to comply. The law then becomes enforceable. Nothing tells us when that will happen. Meanwhile the new child safety law still needs its schedule of fines. And the national identity-check platform is being rolled out across banks.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Health and social care

Health and social care data must stay in the country

Official name: Federal Law No. (2) of 2019 Concerning the Use of the Information and Communications Technology in Health Fields · Federal Law No. 2 of 2019, Articles 13, 20, 24 and 25 · Act of parliament

In forceNo — it stays put

Health data created by health services inside the country may not be stored, used, generated or moved abroad at all. The only exception is a specific decision from the relevant health authority. Records must be kept for at least 25 years after the last treatment. This is the country's strictest data rule. Breaking it costs up to about 191,000 US dollars, and you can lose your licence.

In force since 14 May 2019

Enforced by Ministry of Health and Prevention

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Payments

Payments data must stay in the country

Official name: Retail Payment Services and Card Schemes Regulation · Circular No. C 15/2021 · Directly binding regulation

In forceNo — it stays put

If you are licensed to provide retail payment services, personal and payment data must stay inside the country. You also need a separate secure backup, and you must keep the data for five years. The regulation gives no route for sending data abroad. It says nothing about whether an extra copy may sit overseas, so firms treat it as a total ban.

In force since 6 June 2021

Enforced by Central Bank of the United Arab Emirates

How this country controls where data goes: Not allowed

Insurance

Insurance data must stay in the country

Official name: Insurance Authority Board of Directors' Resolution No. (18) of 2020 Concerning the Electronic Insurance Regulations · Board Resolution No. 18 of 2020, Article 9 · Directly binding regulation

In forceNo — it stays put

If you sell or service insurance policies online, you must protect customer information held electronically. That includes storing the data inside the country. Confidentiality never expires. You may only hand data over under a court or security order. Supervision moved from the Insurance Authority to the central bank when the two merged.

In force since 28 April 2020

Enforced by Central Bank of the United Arab Emirates

How this country controls where data goes: Not allowed

Applies to every company2 rules

These bind you whatever business you are in, once the country's rules reach you.

Banking rules

Official name: Federal Decree-Law No. (45) of 2021 Concerning the Protection of Personal Data · Federal Decree-Law No. 45 of 2021, Official Gazette No. 712, 26 September 2021 · Act of parliament

Partly in forceYes, with paperwork

The national privacy law. It reaches foreign companies that handle data about people inside the country. You may send data abroad using a contract, consent, or an approved destination. Today it is close to unenforceable. The detailed rules required by Article 28 have never been published. The schedule of fines under Article 26 has never been made. The list of approved destinations is empty. The law also does not apply to government data, health data, banking and credit data, or free-zone companies with their own privacy laws.

In force since 2 January 2022

Enforced by UAE Data Office — not yet operational

How this country controls where data goes: Only approved countries (no country is on the approved list yet) · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent, Needed for a contract, Legal claims, Important public interest

Social media and online platforms

Children's data rules

Official name: Federal Decree-Law No. (26) of 2025 Regarding Child Digital Safety · Federal Decree-Law No. 26 of 2025, Articles 7, 10, 11 and 16 · Act of parliament

Partly in forceYes — store it anywhere

A new law in force since 1 January 2026. Online platforms must set children's accounts to the strongest privacy settings by default. They must offer parental controls and reporting tools. For anyone under 13 they need documented, checkable consent from a caregiver. A child is anyone under 18. The fines have not been set yet. They were left to a future government decision. So the duties apply now, but there are no penalties.

In force since 1 January 2026

Enforced by Telecommunications and Digital Government Regulatory Authority

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies only in certain states1 rule

Made by a state or province. It only binds you for the people living there.

Rules for sending data abroad

Official name: ADGM Data Protection Regulations 2021 · Data Protection Regulations 2021, Abu Dhabi Global Market · Directly binding regulation

In forceYes, with paperwork

Two financial districts sit outside the national privacy law and run their own systems. The Abu Dhabi Global Market uses its 2021 regulations. The Dubai International Financial Centre uses its own 2020 law. The Abu Dhabi office keeps a public register. It follows a European-style list of approved destinations. It has published penalty notices and directions. It is one of the few privacy regulators in the country that actually works.

In force since 14 February 2021

Enforced by Abu Dhabi Global Market Office of Data Protection

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • UAE Data Office

    Not yet live

    مكتب الإمارات للبيانات

    Federal data protection regulator under Federal Decree-Law No. 44 of 2021

    Set up in law in 2021. The government portal describes it as the federal data regulator. As at 18 August 2026 we could find no website of its own. Two addresses, dataoffice.gov.ae and uaedataoffice.gov.ae, do not work. We found no published guidance, no register, no list of approved destinations and no decisions. We also could not find the Cabinet decision that would set fines under Article 26 of the privacy law. So it has nothing to impose.

  • مصرف الإمارات العربية المتحدة المركزي

    Banking, payments, insurance, exchange houses, the national customer identity-check platform

    Publishes financial penalties regularly. These include 20,000,000 dirhams (about 5.4 million US dollars) on 24 June 2026. They also include 1,820,000 dirhams (about 495,000 US dollars) on 6 July 2026. Both were against foreign bank branches.

  • Health data, jointly with the emirate-level health authorities in Abu Dhabi and Dubai

    Article 13 of Federal Law No. 2 of 2019 gives it the power to allow health data to be stored abroad. It does this by decision, working with the emirate health authority.

  • Telecoms, digital government, cyber incident reporting for the government sector

  • National cyber security strategy, critical infrastructure protection, national incident response

    Set up by the Cabinet in November 2020. It runs a national security operations centre. It publishes no general deadline for private companies to report incidents.

  • هيئة الأوراق المالية والسلع

    Securities and commodities markets

    The former Securities and Commodities Authority site (sca.gov.ae) now redirects to uaecma.gov.ae, which points to a rename. We did not find a securities rule requiring data to stay in the country.

  • Personal data in the Abu Dhabi Global Market financial free zone

    Keeps a register of companies that use personal data, and publishes enforcement notices. It issued a penalty notice on 21 May 2024 and a direction on 23 June 2023.

  • Personal data in the Dubai International Financial Centre financial free zone

    Widely reported as active. We could not open its own website, so we could not check its current law text, its list of approved destinations or its enforcement record. Treat this as medium confidence.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the Executive Regulations under Article 28 of Federal Decree-Law No. 45 of 2021 have still not been issued as at 18 August 2026

    The official legislation portal lists no Cabinet Resolution issuing them. A professional source dated 27 January 2025 says they were still unpublished. We could not fully confirm the position for the period since January 2025. This is the most important claim in this record. Check it first before you rely on it.

  • That no Cabinet decision setting violations and penalties under Article 26 of the privacy law exists

    We found no such decision on the legislation portal, and we could not confirm it against a full government search. Ask the regulator before you rely on there being no fines.

  • A telecoms or Internet-of-Things rule requiring data to be stored inside the country

    The regulator's own regulations page has an Internet of Things section with no documents in it, checked 18 August 2026. Other sources describe an Internet of Things policy that requires storage inside the country. We could not get a government copy, so we do not state it as a rule. If you work in telecoms, check before you rely on this.

  • The current text, adequacy list and enforcement record of the Dubai International Financial Centre data protection law

    We could not open the Centre's own website, so we could not confirm its current law, its approved destinations or its enforcement record. The free-zone rule in this record is based on the Abu Dhabi regulator's own site instead. Treat the Dubai position as medium confidence.

  • Whether any health authority decision has been issued permitting offshore storage of health data under Article 13 of Federal Law No. 2 of 2019, and how wide it is

    The power to grant an exemption is written into the law. We could not find any published decision using it. If you need to store health data abroad, ask the health ministry directly.

  • The where data has to be stored policy that applies to government bodies and government data

    The national privacy law leaves out government data and government bodies, so a separate policy must exist. We could not find a published federal rule setting it out. If this affects you, ask the government body you deal with.

  • Any mapping or geospatial keeping data in the country rule

    We found no such rule, and we could not confirm it against a full government search. Medium confidence. If you handle mapping data, check before you rely on it.

  • That the 2026 central bank sanctions were for data or privacy breaches

    The published notices record financial penalties for breaking the rules. They do not say what the breaches were about. We cite them only to show that the regulator is active and imposes large fines.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.