Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
Residency, sovereignty and localisation are three different requirements, and UAE rules apply them differently across federal law, the financial free zones and sector regulators. Residency concerns where data is stored, sovereignty concerns whose law governs access to it, and localisation is a legal duty to keep data in the country. This guide maps each regime's position, explains the control plane problem and transfer mechanisms, and shows how to design an estate that meets them.
Testing a vendor against these five points shows quickly whether a UAE compliance claim holds up.
The UAE has no single data location law. Federal personal data law, the two financial free zone regimes, health data law, financial sector rules and government regulations each take their own position, and one organisation can fall under several at once. This guide stays in the security and architecture lane, so it describes what each regime requires of your design and does not interpret the law, and our cloud security services guide covers the wider service categories that sit around these decisions.
Security operations raise the question as often as cloud hosting does. A monitoring service ingests logs that can contain personal data, and where those logs sit is a residency decision in its own right, as our SOC as a service guide explains for log data. You see, the earlier an enterprise maps these flows, the fewer surprises appear at contract signature.
Data localisation is a legal requirement to keep certain data inside the country. It is the strictest of the three because it comes from a rule and not from a vendor promise, and it can reach backups, replicas and processing as well as main storage. A vendor can truthfully claim UAE data residency while remaining subject to foreign access powers, and neither claim satisfies a localisation rule that also covers support access or telemetry.
Sovereignty in practice turns on three questions: who operates the platform, who can log in and who holds the encryption keys. Customer-held keys that the provider cannot use on its own limit what any party can read, even where legal pressure is applied to the provider, and our end-to-end encryption guide explains the mechanics. A claim that does not answer all three questions is a residency claim presented as a sovereignty claim.
| Regime | Residency position | Cross-border transfer permitted when | Applies to |
| Federal PDPL | It sets no blanket requirement to store personal data in the UAE and regulates transfers abroad instead. | A transfer is permitted to a jurisdiction the UAE Data Office treats as adequate, or otherwise through binding contractual measures, explicit consent or listed necessity grounds. | It applies to personal data processed by mainland entities and by entities abroad that process UAE residents' data. |
| DIFC | It regulates transfers by adequacy and safeguards and sets no blanket local storage rule. | A transfer is permitted to a jurisdiction recognised as adequate or where appropriate safeguards are in place. | It applies to entities licensed in the Dubai International Financial Centre. |
| ADGM | It regulates transfers by adequacy and safeguards under its own regulations and sets no blanket local storage rule. | A transfer is permitted to a jurisdiction recognised as adequate or where appropriate safeguards are in place. | It applies to entities licensed in Abu Dhabi Global Market. |
| NESA / UAE IAS | Public descriptions of the standard focus on security controls and third-party security for cloud-hosted services, so hosting expectations usually arrive through the entity's regulator, contracts and sector rules. | Entities confirm permitted transfers with their authority and with the data protection law that applies to the data. | It applies to government entities, critical infrastructure operators and, through third-party controls, the suppliers that serve them. |
| ADHICS and the health data law | Federal Law No. 2 of 2019 prohibits storing, processing, generating or transferring health data related to services provided in the UAE outside the country by default. | A transfer is permitted only within the exceptions listed in Ministerial Resolution 51 of 2021, which sets out ten circumstances. | It applies to health data relating to healthcare services provided in the UAE, and ADHICS applies to Abu Dhabi health entities. |
| DESC ISR | Version 3 prevents storing or processing critical government information outside the UAE and extends that to cloud services. | Entities should confirm any permitted exception with DESC before moving such information abroad. | It applies to Dubai Government entities and, through contracts, their suppliers. |
| Central Bank of the UAE | Consumer protection rules require licensed financial institutions to store customer and transaction data in the UAE, and payment rules require personal and payment data to be stored and maintained in the UAE. | The outsourcing regulation for banks requires data needed for core activities to be maintained and stored in the UAE, so offshore processing needs Central Bank engagement and a no-objection notice before outsourcing. | It applies to institutions licensed by the Central Bank of the UAE, including banks, insurers and payment service providers. |
When an entity falls under more than one regime, design to the most restrictive applicable position and document the differences. A bank with a health insurance arm, or a mainland company with a DIFC subsidiary, can meet several positions at once. One 2026 legal analysis even advises treating transfers between a mainland entity and a free zone entity as cross-border transfers that need contractual protection, which shows how finely these boundaries are drawn.
Federal personal data obligations, including the conditions on transfers, sit in our UAE PDPL compliance guide. That guide maps each obligation to the control that satisfies it.
The free zone regimes have their own regulators and rules, which our DIFC and ADGM data protection guide compares in detail. Firms operating in both zones should read it alongside this page.
Health entities in Abu Dhabi should read the residency position alongside the wider control framework in our ADHICS compliance guide. The Department of Health has reportedly indicated that processing and storing health data in a UAE-hosted cloud does not need an exception, though each entity remains responsible for confirming its own position.
The management layer deserves particular attention. In a standard public cloud, the control plane that provisions and configures resources often runs in the provider's main regions, so configuration data, metadata and telemetry can flow to a global platform even when customer data stays local. Legal commentary on Central Bank rules also notes that a backup stored abroad can be treated as data leaving the country, regardless of where the original sits.
A residency commitment that covers only data at rest leaves most of this unaddressed. Ask where each of these sits: main storage, replicas and backups, processing, logs and telemetry, the control plane and support access. Entities under frameworks such as NESA face the same questions through third-party security controls for cloud-hosted services, as our NESA compliance guide explains for covered entities.
Three questions surface most gaps. Can the provider's staff outside the UAE access your data, and under whose approval? Are the encryption keys held in the UAE and controlled by you? Does any telemetry, support traffic or backup leave the country? Written answers to those questions are worth more than a residency badge.
A controller should retain evidence for each transfer: which route applies, the contract or consent record, the assessment of the recipient's protections and a note of where the data goes afterwards. Encryption with keys held in the UAE can reduce exposure where a transfer route is uncertain, and our data security solutions page covers the controls involved. These records are what a regulator or auditor asks for first.
In the UAE, the major hyperscalers operate regions in the country, and the Central Bank has launched a sovereign financial cloud with a UAE cloud operator for licensed financial institutions. That suggests regulators and industry treat sovereign options as a distinct tier above a standard in-country region. Offerings change quickly, so confirm current availability before building a design around one.
The trade-offs are practical. Sovereign offerings can run with smaller service catalogues than the provider's flagship regions, and some services take time to reach parity. Buyers gain stronger control over who operates the platform and who holds the keys, and they may give up some managed services, so match the tier to the sensitivity of each workload and not to the whole estate. Our modern enterprise cloud security solutions guide covers how a secure architecture is designed across tiers.
Test any sovereignty claim with the same questions: who operates the control plane, who holds the keys, which law governs the operator and how you exit. A badge on a region answers none of them by itself. Neutral questions applied equally to every provider give a fair comparison.
Review the file whenever a provider adds a region, changes a subprocessor or launches a service, since residency positions drift with provider changes. This design process can help reduce the risk of an unexpected data flow, though it cannot remove the need to confirm obligations against the current rules. This article offers general guidance and does not constitute legal advice.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cloud Security | 07/10/2026
Cloud Security | 07/10/2026
Cyber Threats | 07/10/2026
Does UAE law require data to be stored in the UAE?
Not for all data. Health data, some financial data and government information face localisation duties.What is the difference between data residency and data sovereignty?
Residency is where data is stored. Sovereignty is whose law governs access, and it depends on who operates the platform and holds the keys.Can we use a cloud region outside the UAE?
For some data, yes, with a lawful transfer route. See our cloud security services guide for provider questions.What is sovereign cloud?
A cloud model with stronger control over operators, keys and governing law than a standard region, in several forms.Does the PDPL restrict cross-border transfers?
It regulates them through adequacy, safeguards, consent or listed exceptions. See our PDPL compliance guide.Do healthcare entities have stricter residency rules?
Yes. Health data from UAE services cannot leave the country except in listed cases. See our ADHICS compliance guide.Does data residency cover backups and logs?
It can. Confirm where backups, replicas, logs and telemetry sit, since a residency claim may cover only main storage.