Skip to main content
Nexa Tech

Cloud Services

Which UAE data protection law applies to you

Nexa Tech5 min read

The question sounds administrative and is architectural. It decides where data may sit, what a transfer requires, who a breach is reported to and how quickly, and those answers change the design rather than the paperwork.

The UAE does not have one data protection regime. It has a federal law, separate regimes inside the financial free zones, and sector rules that sit above both.

The three layers

Federal Decree-Law No. 45 of 2021 governs the protection of personal data at federal level and is the default position for an entity licensed on the mainland or in a non-financial free zone.

The Dubai International Financial Centre and Abu Dhabi Global Market are different. Each operates its own data protection law with its own regulator and its own notification requirements, closer in structure to European practice. An entity licensed in DIFC answers to the DIFC regime and its Commissioner, not to the federal law, and an entity licensed in ADGM answers to ADGM's regulations.

Sector rules then sit above all of it. In health the effect is decisive: federal law restricts health data generated in the state from being stored or processed outside it, which removes options that would otherwise be available under a general reading of the data protection position alone.

Why groups get this wrong

Because the licence decides, not the address. A group can run a mainland trading entity, a DIFC holding company and a free zone operations arm from adjacent buildings and be subject to two or three regimes simultaneously. The systems those entities share, and they usually share several, then sit across a boundary that nobody drew on the network diagram.

The shared systems are where it surfaces. One HR platform serving all entities. One CRM. One backup target. One identity provider. Each of those is now processing personal data under more than one regime, with different transfer rules and different notification clocks, and the design has to accommodate the strictest applicable position or separate the data.

The second recurring error is treating a free zone as a jurisdiction for this purpose when it is not one. Most free zones in the country are not financial free zones and do not have their own data protection law, so entities licensed in them fall under the federal regime. DIFC and ADGM are the exceptions, and assuming otherwise in either direction produces a design built to the wrong rules.

What this changes in the architecture

Residency, transfer basis and support access are the three that move. Where a workload may run, what makes an export lawful, and whether an engineer outside the country may open a console and read records are decided by the applicable regime, and a support model that is fine for one entity may not be fine for another in the same group.

Notification timescales matter for the same reason. If a regime requires notification within a defined window, logging and detection have to be capable of establishing what happened inside that window. That is a monitoring design requirement, not a legal one, and it is cheap at design and expensive after an incident.

What to establish before designing

  • The licensing jurisdiction of every entity whose data the system will hold, not the office location.
  • Which systems are shared across entities, and therefore across regimes.
  • The permitted processing and storage locations for each dataset, sector rules included.
  • Every route by which someone outside the country could read the data, named and justified or removed.
  • The notification window that applies, and whether detection and logging can actually meet it.

Establish those five and the residency and support decisions become obvious. Leave them until the platform is chosen and one entity in the group usually has to be carved back out of it.

Next step

Bring the complete environment into one conversation.

Tell us what you are planning, replacing, integrating or trying to stabilise. We will help define the right next step.