Scality Blog | Object storage, AI data infrastructure & cyber resilience

UAE Data Residency Rules: How Organizations Comply

Written by Joshua Silvia | Oct 5, 2026, 8:46:27 PM

A hospital group in Abu Dhabi is modernizing its imaging archive. A bank in Dubai is replacing its backup infrastructure. A government entity is building a private cloud for citizen services. All of them face the same early question: which UAE data residency rules apply, and what do they mean for where and how data is stored?

The UAE has built a layered data protection landscape over the past few years: a federal personal data protection law, sector-specific rules that in some cases require data to stay in the country, separate regimes in financial free zones and emirate-level requirements for government entities. This article explains that landscape at a practical level and what it means for storage design. It is general information, not legal advice; organizations should confirm obligations with their legal and compliance teams. It is part of our data sovereignty series; see also sovereign cloud architecture.

The federal personal data protection law

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, which entered into force in January 2022, is the UAE's main federal framework for personal data. It sets rules on lawful processing, consent, data subject rights, security and cross-border transfers. Certain categories of data that are governed by their own specific legislation, and entities in free zones with their own data protection laws, fall outside its scope, so organizations need to identify which regime applies to each data set.

For storage, the federal law means personal data must be protected with appropriate security measures, processed lawfully and transferred abroad only under the conditions the law allows.

Health data: stored in the UAE

The health sector has some of the clearest localization rules. Federal Law No. 2 of 2019 on the use of information and communication technology in health fields generally requires health data and information to be stored and processed inside the UAE, with exceptions only in cases defined by the competent authorities. Emirate-level health regulators add their own standards. For hospitals, clinics, laboratories, insurers handling health claims and health technology providers, this typically means electronic health records, imaging archives, laboratory data and their backups must stay in UAE data centers.

Financial free zones

The Dubai International Financial Centre and Abu Dhabi Global Market operate their own data protection regimes, DIFC Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021, modeled on international standards. Firms in these free zones follow their free zone's rules for personal data, including transfer restrictions, alongside financial regulatory requirements.

Sector regulators

Banks, insurers and other regulated entities also follow requirements from their regulators on outsourcing, cloud use, resilience and data location. In practice, many financial institutions keep core customer data, transaction records and backups in the UAE and seek regulatory approval or notification for outsourcing arrangements. Telecommunications and critical infrastructure operators face similar sector expectations.

Government entities

Federal and emirate-level government entities follow national and local information security standards and cloud policies. Dubai and Abu Dhabi each have frameworks governing government data and the security of cloud services used by government entities. These commonly require government data to be hosted in the UAE, on infrastructure that meets defined security requirements.

What this means for storage design

Keep data and every copy in the UAE

For health data, government data and much regulated financial data, primary storage, replicas, backups and archives should all be in UAE data centers. Disaster recovery sites should also be within the country.

Watch metadata, logs and telemetry

Residency applies to more than primary data. Indexes, logs, monitoring data and support bundles can contain personal or sensitive information. Make sure storage platforms do not send these abroad.

Control administrative and support access

Remote vendor support from outside the country can count as access to data. Prefer models where remote access is disabled by default, approved case by case and logged.

Encrypt with locally held keys

Encrypt data at rest and in transit, with keys managed in the UAE under the organization's control.

Classify data by regime

Map each data set to the rules that apply: federal PDPL, health law, free zone law, sector regulation or government standards. Store data with different obligations in separate buckets or accounts, with policies to match.

Plan for growth locally

Imaging archives, video surveillance, smart city platforms and AI initiatives are driving rapid data growth in the UAE. Storage must scale within in-country facilities without forcing data abroad for capacity.

Cloud and on-premises options

Major cloud providers and local providers operate data centers in the UAE, and national cloud offerings serve government and regulated sectors. Many organizations also run private infrastructure for their most sensitive data. On-premises object storage is often used for imaging archives, backups, video and data lakes that must stay in-country, sometimes alongside local cloud services for other workloads.

Practical steps

  • Inventory data sets and identify the applicable legal regime for each.
  • Identify data that must stay in the UAE, including backups and DR copies.
  • Choose storage locations and providers that keep all copies in-country.
  • Review telemetry, logging and support arrangements for each platform.
  • Encrypt data and keep keys under local control.
  • Document data flows and controls for regulators and auditors.
  • Review obligations regularly as regulations and guidance evolve.

Workload examples

Healthcare imaging and records

Hospitals and diagnostic centers generate large imaging archives that must stay in the UAE under health data rules. Object storage behind PACS and VNA platforms provides scalable, in-country capacity, with replication between two UAE data centers for resilience.

Banking backups and archives

Banks keep backups, regulatory archives and communications records for years. In-country object storage with compliance-mode object lock protects these copies against ransomware while satisfying regulator expectations on location and resilience.

Government and smart city platforms

Government entities and smart city programs collect video, sensor data and citizen service records. Large volumes of video surveillance and Internet of Things data need scalable storage inside national facilities, often with strict access logging.

AI and analytics

National AI initiatives and enterprise analytics projects need large datasets close to GPU infrastructure in the UAE. A sovereign data lake on in-country object storage keeps training data and derived models under local control.

Common mistakes

  • Backups or DR copies replicated to a region outside the UAE by default.
  • Support tools that upload logs or diagnostic bundles to servers abroad.
  • Keys managed by a foreign service, even when data is stored locally.
  • Treating free zone and onshore data the same, when different laws apply.
  • Assuming one rule fits all data, rather than mapping each data set to its regime.

Working with regulators and auditors

Regulators and auditors will ask where data is stored, who can access it, how it is protected and how it is recovered. Prepare architecture diagrams showing data locations and flows, access control and logging arrangements, encryption and key management details, backup and DR designs and vendor support procedures. Keeping this documentation current makes approvals, inspections and audits much easier.

How Scality fits

Scality RING and ARTESCA run on infrastructure chosen by the organization, in its own data centers or with local partners, with no dependence on foreign cloud services. They provide S3-compatible object storage with erasure coding, multi-site deployment within the country, compliance-mode object lock, encryption and role-based administration with audit logging. That makes them suitable for in-country imaging archives, backups, video and data lakes in the UAE.

Putting it together

UAE data residency is shaped by a federal personal data law, strict localization for health data, separate regimes in financial free zones, sector regulators and government standards. For storage, the common thread is keeping sensitive data, and every copy of it, in the UAE under the organization's control, with metadata, logs and support access treated as carefully as the data itself. Map data to its regime, choose in-country storage and document controls for regulators.

Frequently asked questions

Does the UAE have a data protection law?

Yes. Federal Decree-Law No. 45 of 2021 is the federal framework for personal data, in force since January 2022, with separate regimes in free zones such as DIFC and ADGM.

Must health data be stored in the UAE?

Federal Law No. 2 of 2019 generally requires health data to be stored and processed inside the UAE, with limited exceptions defined by authorities.

Do DIFC and ADGM follow the federal law?

They have their own data protection laws: DIFC Law No. 5 of 2020 and the ADGM Data Protection Regulations 2021.

Do backups count for data residency?

Yes. Backups and disaster recovery copies of data that must stay in the UAE should also be stored in the country.

Can cloud services be used for regulated data in the UAE?

Often yes, using in-country data centers and meeting sector requirements, though many organizations keep the most sensitive data on private infrastructure.

Further reading

Related reading