Cloud & Infrastructure
Data Residency in the UAE: Why Your Data Must Stay in the Country
Jul 01, 2026
Introduction
Data residency in the UAE is no longer optional. Under Federal Decree-Law No. 45 of 2021 (PDPL), any entity processing personal data of UAE residents must comply with strict storage and transfer rules . The National Cloud Security Policy further mandates that cloud service providers storing data classified above "Open" must ensure all consumer data is stored strictly within UAE borders .
The Problem: Offshore Storage Creates Compliance Risk
The UAE has three parallel data protection regimes—federal PDPL, DIFC, and ADGM—and they don't fully align . Processing data outside the UAE can violate PDPL, and the UAE Data Office has not yet published an adequacy list for cross-border transfers, creating genuine compliance uncertainty . Health data must stay in the UAE absent health authority approval, and Central Bank rules require financial institutions to store customer data locally . In April 2026, the Central Bank banned banks from using WhatsApp for customer data due to data residency concerns .
The Solution: Local Hosting with Sovereign Controls
The UAE's National Cloud Security Policy sets security and sovereignty requirements across three tiers. For data classified as "Confidential/Restricted," CSPs must store all consumer data strictly within UAE borders . For highly critical data, even metadata storage and processing must remain in-country . Sovereign solutions like e&'s UAE Sovereign Launchpad, endorsed by the UAE Cybersecurity Council, ensure data residency, governance, and compliance within the UAE .
Real Numbers: The Cost of Non-Compliance
DIFC and ADGM have demonstrated willingness to enforce data protection rules, with fines reaching up to AED 370 million imposed on financial institutions since early 2025 . Financial institutions face supervisory action for non-compliance, and health sector violations carry fines under Federal Law No. 2 of 2019 .
UAE-Specific Security Considerations
The PDPL applies to any entity processing personal data of UAE residents, even if located outside the country . Healthcare data generally cannot leave the UAE without health authority approval . Financial institutions must obtain Central Bank approval for cross-border transfers . Organizations operating in both mainland and DIFC/ADGM must treat transfers between these jurisdictions as cross-border transfers requiring contractual protections .
Why FortyFi
FortyFi helps UAE businesses achieve data residency compliance with PDPL, sectoral rules, and the National Cloud Security Policy.
FAQ
What data must stay in the UAE? Personal data of UAE residents under PDPL, health data under Federal Law No. 2 of 2019, and financial customer data under Central Bank rules must stay in-country or require approval to transfer . Do DIFC and ADGM follow the same rules? No. They have their own data protection regimes, and transferring data from DIFC to mainland UAE requires appropriate safeguards like SCCs . What happens if I store UAE citizen data offshore? You risk regulatory action, fines, and criminal penalties under the Cybercrime Law .
Assess Your Data Residency Compliance
Message FortyFi on WhatsApp for a free compliance review.