Home/ Home/ Blog/ PDPL and Data Residency

UAE PDPL and Where Your Business Data Should Live

Federal Decree-Law 45 of 2021 changed the rules on how UAE businesses handle personal data. Here is what it means for your accounting, POS and ERP data, and how to decide between cloud, on-premise and offline-first.

Why this matters

The law changed. Most SMEs did not notice.

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data - the UAE PDPL - is the first federal, cross-sector data protection statute in the country. It sits alongside sector rules from the DIFC, ADGM, the Central Bank and the Dubai Health Authority, and it applies to almost every business that processes personal data of individuals inside the UAE. Your customer list is personal data. Your supplier contacts are personal data. The names and phone numbers on your invoices, delivery notes and POS receipts are personal data. That means the question of where your ERP database lives is no longer just an IT preference - it is a compliance question with a paper trail.

What the PDPL actually says

The PDPL sets out familiar principles: lawful basis for processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. It gives data subjects rights to access, correction, erasure, restriction of processing, portability and objection. It requires controllers to keep records of processing, to notify the UAE Data Office of certain breaches, and to appoint a Data Protection Officer in higher-risk cases. Crucially for ERP buyers, it also regulates cross-border transfer of personal data outside the UAE - transfers are only permitted to jurisdictions with an adequate level of protection, or under specified safeguards such as contractual clauses and explicit consent.

Six PDPL duties that touch your ERP

scale

Lawful basis

You must be able to justify why you hold each field - contract, legal obligation, legitimate interest or consent.

eye

Transparency

Customers can ask what you hold. Your system needs to answer, ideally by pulling a full profile in one click.

edit

Correction and erasure

You must be able to fix or remove personal data on request, subject to VAT record-retention obligations.

globe

Cross-border control

Sending personal data outside the UAE requires an adequacy finding or a defined safeguard.

shield

Security

Appropriate technical and organisational measures - encryption at rest and in transit, access control, backup.

alert

Breach notification

Notifiable incidents must reach the UAE Data Office within the timeframes set by the Executive Regulations.

The overlap with the FTA

UAE VAT law requires you to keep tax records for five years (fifteen for real estate). PDPL erasure rights do not override that obligation - you retain the invoice, but you may need to lock or minimise personal data beyond the retention window. An ERP with proper archival, not just delete, matters here.

Where your data actually sits: three architectures

Every UAE ERP falls into one of three shapes. A pure cloud SaaS keeps the master database in a vendor-run data centre, often outside the UAE. A hosted or private cloud puts a dedicated instance in a named region, sometimes inside the UAE, always dependent on a live connection. An offline-first, on-premise system installs a database engine on the customer's own PC or LAN server, and treats any cloud service as optional. Each shape has a different PDPL footprint, a different failure mode when the internet drops, and a different cost profile over five years.

Cloud SaaS vs hosted cloud vs offline-first

DimensionCloud SaaSHosted cloudOffline-first
Where the database livesVendor data centre, often outside UAENamed region, sometimes UAECustomer's own PC or LAN server
Cross-border transfer under PDPLAlmost always in scopeDepends on region and sub-processorsNot triggered if data stays on-premise
Works during an internet outageNoNoYes, indefinitely
Who holds the encryption keysVendorVendor or sharedCustomer, with optional cloud escrow
Exit and data portabilityExport files, then account closedSnapshot handoverYou already have the PostgreSQL database
Typical monthly cost patternPer user, foreverPer user plus infrastructureOne licence, hardware is yours

Cross-border transfer is the quiet trap

A UAE grocery using a cloud POS whose servers sit in a European region is transferring personal data outside the country every time it rings up a sale under a loyalty account. That transfer is lawful only if the destination is on the adequacy list published under the PDPL Executive Regulations, or if the vendor has put a compliant safeguard in place - typically standard contractual clauses, binding corporate rules or the customer's own explicit, informed consent. Many SME owners have never read the sub-processor list of their SaaS vendor. The obligation to know is theirs, not the vendor's.

A five-step data residency review for your business

1

List every system that touches personal data

Accounting, POS, e-commerce, WhatsApp Business, payroll, HR, CCTV, loyalty. Write down the vendor and the hosting country for each.

2

Classify the fields

Separate identifiers (name, Emirates ID, phone, email, address) from transaction data. Note anything sensitive - health, biometrics, minors.

3

Map the flows

For each system, mark whether data leaves the UAE, which sub-processors touch it, and where backups sit.

4

Check the legal basis and the safeguard

For every cross-border flow, confirm adequacy or a written safeguard. Where you rely on consent, make sure the consent is specific, informed and revocable.

5

Decide what to keep local

Books of account, invoice history, customer master, POS transactions and stock movements can all live on-premise. Ask why they would not.

Signs your current setup is drifting out of compliance

  • You cannot name the country where your accounting database is stored today.
  • Your POS stops trading when the fibre goes down, and you have no fallback.
  • You have never seen a sub-processor list or a Data Processing Agreement from your ERP vendor.
  • Customer data is emailed as spreadsheets between staff and outside accountants.
  • Backups are downloaded to a personal laptop or a free consumer cloud drive.
  • Nobody on the team can produce a single-page record of processing on request.
How Zeyto is designed

Offline-first as a PDPL posture, not a marketing line

Zeyto ships as one signed binary plus a .zlic licence. The operational database is PostgreSQL running on the customer's own PC or LAN server. Invoicing, POS, stock, VAT return preparation, printing and local backup all work with zero internet indefinitely. Zeyto Cloud is a separate service that only holds licence records, opt-in telemetry and encrypted backups if the customer chooses to use them. Nothing about the operational database leaves the premises unless the owner explicitly turns on encrypted cloud backup, and even then the encryption key stays with the customer. For a UAE SME, that means the default answer to 'where does our data live' is simple: on our own machine, inside the UAE.

What that gives an SME owner

lock

Data stays put

No cross-border transfer to argue about, because the database never leaves the premises.

wifi-off

No outage risk

A cut fibre, an ISP issue or a power dip on the vendor side does not stop you invoicing.

key

Keys you hold

Backup encryption keys are generated and held by the customer, not the vendor.

archive

Five-year records

Tax records stay complete and locally addressable for the FTA retention period.

users

Subject requests

A single customer or supplier record can be exported, corrected or archived in place.

file

Audit trail

Every posting, edit and login is timestamped in the local ledger, ready for review.

Offline-first is not anti-cloud

There are good uses for the cloud - remote access, multi-site sync, encrypted off-site backup, business portal. The point is that these should be opt-in additions to a system that already works locally, not the load-bearing foundation. Zeyto puts the cloud where it belongs: on the edge, under the customer's control, with encryption in the customer's hands.

What to ask any ERP vendor before you sign

Do not accept vague answers. Ask which country the primary database lives in, and which countries the backups and disaster-recovery copies live in. Ask for the sub-processor list and the Data Processing Agreement in writing. Ask what happens to your data on the day you cancel, and how long it takes to get a full, machine-readable export. Ask whether the system continues to function during an internet outage, and for how long. Ask who holds the encryption keys. A vendor that cannot answer these questions on the first call is not ready for the PDPL either.

FAQ

Straight answers

Does the UAE PDPL apply to a small trading LLC in Dubai?
Yes. The PDPL applies to controllers and processors established in the UAE that process personal data, regardless of size, and to entities outside the UAE that process personal data of individuals inside the country. A small trading LLC with a customer list, supplier contacts and POS receipts is a data controller under the law.
Can I keep using a cloud ERP whose servers are outside the UAE?
You can, but only if the destination country is recognised as providing an adequate level of protection under the PDPL Executive Regulations, or if the vendor has a specified safeguard in place - typically standard contractual clauses, binding corporate rules or explicit informed consent from each data subject. The obligation to verify this sits with you as the controller, not with the vendor.
Does the PDPL require me to delete customer data on request?
It gives customers a right to request erasure, but that right is not absolute. You can refuse or defer erasure where you are legally required to retain the record - for example, UAE VAT law requires tax records to be kept for five years, and fifteen for real estate. In practice you archive or minimise personal fields beyond the retention window rather than deleting the underlying invoice.
Is offline-first ERP allowed under the PDPL?
Yes, and it removes several categories of PDPL risk. When the database sits on the customer's own hardware inside the UAE, there is no cross-border transfer to justify and no third-party controller to audit. The controller still has to meet security, transparency and data-subject-rights duties, but the residency question answers itself.
What is a Data Processing Agreement and do I need one?
A Data Processing Agreement is a written contract between a controller and a processor that sets out how personal data will be handled, secured, sub-contracted and returned or deleted at the end of the relationship. If a vendor processes personal data on your behalf - a cloud ERP, an outsourced payroll bureau, a bulk-SMS provider - you should have one. Offline-first software installed on your own hardware is not processing on your behalf and does not require a DPA for the local database, though a DPA is still appropriate for any optional cloud services.
Where does Zeyto store my data?
Zeyto's operational database is PostgreSQL running on your own PC or LAN server. Invoicing, POS, stock, VAT return preparation, printing and local backup all work with zero internet. Zeyto Cloud is a separate service that only holds licence records, opt-in telemetry and encrypted backups if you turn them on. The encryption key for cloud backups stays with you.
What happens to my data if I stop paying for Zeyto?
The database is a standard PostgreSQL instance on your own machine, so it does not vanish when a subscription lapses. You keep the historical data, the backups you have made, and the ability to open the database with any PostgreSQL-compatible tool. New postings and licence-gated features stop working until the licence is renewed, but the record of past business remains yours.

Keep your books where UAE law expects them

Book a walkthrough, or start a 14-day trial on your own PC with your own data. No cloud lock-in, no data leaving your premises.