Short answer. The UAE personal data law has applied since January 2022 and reaches anyone processing the data of people in the country, wherever that processor sits. Articles 22 and 23 allow transfers out of the country only where the destination offers adequate protection or where contractual safeguards are in place. No list of adequate destinations has been published. Full compliance is required by 1 January 2027.
One caveat first: this is not legal advice. Deadlines, the status of the regulations and anything that turns on your particular structure belong with a lawyer.
An employee exported the client list and pasted it into a chat window to sort it by visa date. That list holds passport copies, Emirates ID numbers and details of company shareholders.
Which law are you under?
The federal personal data law. And you almost certainly are under it.
It is Federal Decree-Law No. 45 of 2021, in force since 2 January 2022, and the UAE Data Office enforces it. The law reaches beyond the borders: a company with no office here still falls under it if it processes the data of people located in the UAE. Registering somewhere else will not exempt you.
Some categories sit outside it and live under their own rules: government data, data held by security and judicial bodies, and health and banking records. For a corporate services firm that changes little. Passport copies, visa details and shareholder contacts stay inside the law's reach.
Full compliance is required by 1 January 2027. That is under eighteen months away.
Here is a genuine area of uncertainty worth knowing before you talk to a lawyer. Sources disagree on whether the executive regulations have been issued: some cite Cabinet Resolution No. 33 of 2024, others as recently as September 2026 state there are none. The transfer mechanics and the penalty schedule both depend on them, which is why we quote no figures here. Either way your conclusion is the same: build the inventory now, and check the deadlines with a lawyer.
What counts as a transfer abroad?
More than you would expect. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) free zones count as abroad too.
Articles 22 and 23 give two lawful routes. First, the UAE Data Office has recognised that the destination offers adequate protection. Second, contractual safeguards or the person's explicit consent is in place. No final list of adequate destinations has been published. In practice companies rely on the second route.
Then comes the part almost nobody considers. The mainland, DIFC and ADGM are separate jurisdictions, so moving data between them counts as a cross-border transfer. According to the 2026 Chambers review, the mechanics of that particular transfer are still being finalised, which does not change its status.
| What the employee does | Where the data goes | Covered by Articles 22 and 23 |
|---|---|---|
| Pastes a list into a public chat | the vendor's servers, usually outside the UAE | yes |
| Connects an extension to work mail | the same, plus standing access | yes |
| Sends a file to a partner in DIFC | into another jurisdiction | yes |
| Uploads to a service hosted in the UAE | stays in the country | no |
That last row explains the regional appetite for local hosting. It is not a push for data sovereignty. It is the one row that needs no lawful basis at all.
What does using AI change?
It adds two obligations that did not exist while the data sat in a folder.
First, a person has the right to object to a decision produced by automated processing without human involvement. If your system rejects applications on its own, ranks clients by priority or scores risk, that right is already live. So you need somebody the affected person can appeal to, and a clear route to reach them.
Second, high-risk processing calls for an impact assessment, and new technologies are named among the grounds for treating processing as high risk. There is no separate list saying "this counts as high risk", which is another question for the lawyer.
The DIFC has had Regulation 10 in force since January 2026, written for autonomous and semi-autonomous systems. It is the first instrument in the region aimed at those systems specifically. If you sit outside the DIFC, it does not apply to you. Reading it still pays: it shows how a regulator here interprets autonomy, and federal regulators will likely move the same way.
What should you do before January 2027?
Four steps, all doable without a lawyer on staff.
- Build the inventory. What personal data you hold, where it sits, who has access. Nothing after this counts without it, and a lawyer will start the conversation at exactly this point.
- Split the data in two. What can go out once anonymised, and what cannot go out at all. Passport copies and Emirates ID numbers belong in the second category.
- Check the service settings. Most vendors let you switch off training on your data in a business plan, and offer no such switch on a free one. That is the difference between a breach and no breach, and it takes checking a single box.
- Find what is already connected. Extensions in the work inbox, personal subscriptions, automation set up without your knowledge. How to look for it is in our piece on who has already connected AI to your data.
This is where a lawyer becomes necessary: once you know what leaves and where it goes, the remaining questions are about consent wording, contractual safeguards and group structure. That is their work, and arriving with a finished inventory costs a fraction of arriving without one.
We covered consent for campaigns targeting an existing database separately. It is a related question under the same law.
We set up intake and request handling so client data does not leave the perimeter without a person deciding it should. How that works is on the AI intake page. Start with the inventory rather than with us: it takes an evening, and it makes the conversation with a lawyer short.
Danil Ivanov
Founder, KAIVIX
Builds AI systems for companies in the UAE and beyond.