Lawful basis
You must be able to justify why you hold each field - contract, legal obligation, legitimate interest or consent.
Federal Decree-Law 45 of 2021 changed the rules on how UAE businesses handle personal data. Here is what it means for your accounting, POS and ERP data, and how to decide between cloud, on-premise and offline-first.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data - the UAE PDPL - is the first federal, cross-sector data protection statute in the country. It sits alongside sector rules from the DIFC, ADGM, the Central Bank and the Dubai Health Authority, and it applies to almost every business that processes personal data of individuals inside the UAE. Your customer list is personal data. Your supplier contacts are personal data. The names and phone numbers on your invoices, delivery notes and POS receipts are personal data. That means the question of where your ERP database lives is no longer just an IT preference - it is a compliance question with a paper trail.
The PDPL sets out familiar principles: lawful basis for processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. It gives data subjects rights to access, correction, erasure, restriction of processing, portability and objection. It requires controllers to keep records of processing, to notify the UAE Data Office of certain breaches, and to appoint a Data Protection Officer in higher-risk cases. Crucially for ERP buyers, it also regulates cross-border transfer of personal data outside the UAE - transfers are only permitted to jurisdictions with an adequate level of protection, or under specified safeguards such as contractual clauses and explicit consent.
You must be able to justify why you hold each field - contract, legal obligation, legitimate interest or consent.
Customers can ask what you hold. Your system needs to answer, ideally by pulling a full profile in one click.
You must be able to fix or remove personal data on request, subject to VAT record-retention obligations.
Sending personal data outside the UAE requires an adequacy finding or a defined safeguard.
Appropriate technical and organisational measures - encryption at rest and in transit, access control, backup.
Notifiable incidents must reach the UAE Data Office within the timeframes set by the Executive Regulations.
UAE VAT law requires you to keep tax records for five years (fifteen for real estate). PDPL erasure rights do not override that obligation - you retain the invoice, but you may need to lock or minimise personal data beyond the retention window. An ERP with proper archival, not just delete, matters here.
Every UAE ERP falls into one of three shapes. A pure cloud SaaS keeps the master database in a vendor-run data centre, often outside the UAE. A hosted or private cloud puts a dedicated instance in a named region, sometimes inside the UAE, always dependent on a live connection. An offline-first, on-premise system installs a database engine on the customer's own PC or LAN server, and treats any cloud service as optional. Each shape has a different PDPL footprint, a different failure mode when the internet drops, and a different cost profile over five years.
| Dimension | Cloud SaaS | Hosted cloud | Offline-first |
|---|---|---|---|
| Where the database lives | Vendor data centre, often outside UAE | Named region, sometimes UAE | Customer's own PC or LAN server |
| Cross-border transfer under PDPL | Almost always in scope | Depends on region and sub-processors | Not triggered if data stays on-premise |
| Works during an internet outage | No | No | Yes, indefinitely |
| Who holds the encryption keys | Vendor | Vendor or shared | Customer, with optional cloud escrow |
| Exit and data portability | Export files, then account closed | Snapshot handover | You already have the PostgreSQL database |
| Typical monthly cost pattern | Per user, forever | Per user plus infrastructure | One licence, hardware is yours |
A UAE grocery using a cloud POS whose servers sit in a European region is transferring personal data outside the country every time it rings up a sale under a loyalty account. That transfer is lawful only if the destination is on the adequacy list published under the PDPL Executive Regulations, or if the vendor has put a compliant safeguard in place - typically standard contractual clauses, binding corporate rules or the customer's own explicit, informed consent. Many SME owners have never read the sub-processor list of their SaaS vendor. The obligation to know is theirs, not the vendor's.
Accounting, POS, e-commerce, WhatsApp Business, payroll, HR, CCTV, loyalty. Write down the vendor and the hosting country for each.
Separate identifiers (name, Emirates ID, phone, email, address) from transaction data. Note anything sensitive - health, biometrics, minors.
For each system, mark whether data leaves the UAE, which sub-processors touch it, and where backups sit.
For every cross-border flow, confirm adequacy or a written safeguard. Where you rely on consent, make sure the consent is specific, informed and revocable.
Books of account, invoice history, customer master, POS transactions and stock movements can all live on-premise. Ask why they would not.
Zeyto ships as one signed binary plus a .zlic licence. The operational database is PostgreSQL running on the customer's own PC or LAN server. Invoicing, POS, stock, VAT return preparation, printing and local backup all work with zero internet indefinitely. Zeyto Cloud is a separate service that only holds licence records, opt-in telemetry and encrypted backups if the customer chooses to use them. Nothing about the operational database leaves the premises unless the owner explicitly turns on encrypted cloud backup, and even then the encryption key stays with the customer. For a UAE SME, that means the default answer to 'where does our data live' is simple: on our own machine, inside the UAE.
No cross-border transfer to argue about, because the database never leaves the premises.
A cut fibre, an ISP issue or a power dip on the vendor side does not stop you invoicing.
Backup encryption keys are generated and held by the customer, not the vendor.
Tax records stay complete and locally addressable for the FTA retention period.
A single customer or supplier record can be exported, corrected or archived in place.
Every posting, edit and login is timestamped in the local ledger, ready for review.
There are good uses for the cloud - remote access, multi-site sync, encrypted off-site backup, business portal. The point is that these should be opt-in additions to a system that already works locally, not the load-bearing foundation. Zeyto puts the cloud where it belongs: on the edge, under the customer's control, with encryption in the customer's hands.
Do not accept vague answers. Ask which country the primary database lives in, and which countries the backups and disaster-recovery copies live in. Ask for the sub-processor list and the Data Processing Agreement in writing. Ask what happens to your data on the day you cancel, and how long it takes to get a full, machine-readable export. Ask whether the system continues to function during an internet outage, and for how long. Ask who holds the encryption keys. A vendor that cannot answer these questions on the first call is not ready for the PDPL either.
Book a walkthrough, or start a 14-day trial on your own PC with your own data. No cloud lock-in, no data leaving your premises.