27 July 2026 · 8 minute read

Cross-border transfer under UAE PDPL: what appropriate safeguards means in practice

UAE PDPL permits personal data to leave the country where safeguards are in place. The obligation is to evidence those safeguards, and that is where most programmes have real work to do.

Almost every organisation operating in the United Arab Emirates transfers personal data outside it. Cloud infrastructure, a group parent, a payroll provider, a support desk in another time zone: each of these is a cross-border transfer, whether or not anyone has described it that way internally.

The UAE Personal Data Protection Law permits this. It does not permit doing it without addressing it, and the difference between those two positions is where most privacy programmes in the region have genuine work remaining.

The obligation is evidential

The law does not require personal data to remain in the country. It requires that where data leaves, appropriate safeguards apply and that the transfer rests on a proper basis. The practical consequence is that the obligation is evidential: you must be able to show what left, where it went, why that was lawful, and what protects it once it arrives.

That is a different task from choosing a hosting region, and it is frequently confused with it. Selecting a data centre answers one question. It does not answer where the support engineer connects from, where the backup replicates to, or which group entity can query the record.

Discovery comes before safeguards

Most organisations cannot complete this exercise at the point they begin, because they cannot yet state what personal data they hold or where it moves. Until that is established, a transfer policy is a statement of intent rather than a control.

The discovery that actually matters is narrower than a full data inventory, and it is worth scoping tightly:

  • Which processing activities involve personal data, described as the business would describe them rather than as systems.
  • For each, which third parties touch that data, including those reached through another supplier.
  • Where each of those parties processes and stores it, including support access and backup replication, not only the primary region.
  • What contractual and technical protection currently applies to each route.

The fourth item is usually where the gaps appear, and they are rarely evenly distributed. A well-negotiated contract with a major cloud provider sits alongside an arrangement with a small supplier that was agreed by email.

What safeguards look like when they are real

A safeguard that exists only in a policy document is not a safeguard. What holds up under examination tends to share three characteristics. It is contractual, so an obligation binds the receiving party. It is specific, naming the data, the purpose and the limits rather than gesturing at compliance generally. And it is verifiable, meaning someone can check that the receiving party is doing what was agreed rather than assuming it.

The third characteristic is the one most often missing. An organisation can produce signed agreements covering every processor and still have no mechanism by which a breach of those agreements would ever come to light.

Where regimes differ, and where they do not

Organisations that have completed a serious programme under the European General Data Protection Regulation usually find themselves well positioned, because the regional privacy regimes are drafted against a similar structure. The reverse is less reliable. GDPR sets a higher bar on accountability, requiring an organisation to demonstrate compliance rather than achieve it, and a programme built only to satisfy a regional regime may not carry that evidential weight.

For organisations operating across several Gulf states, the efficient approach is to treat the regional privacy regimes as one programme with local variations rather than as separate projects. The common core is substantial. The differences are specific, and they are manageable once they have been identified rather than assumed.

The question to start with

If a regulator asked today which of your suppliers can read your customers' personal data, and from which country, how long would it take you to answer with evidence?

For most organisations the honest answer is measured in weeks, and it involves asking people rather than consulting a record. Closing that distance is the substance of the work, and it is worth beginning before a regulator or a customer's due diligence team asks the question first.

Apply this to your own position

An assessment turns these questions into a documented answer for your organisation, with the gaps ordered by what to address first.

Establish your position →

More insights