Lawful basis
You must be able to justify why you hold each field - contract, legal obligation, legitimate interest or consent.
Federal Decree-Law 45 of 2021 changed the rules on how UAE businesses handle personal data. Here is what it means for your accounting, POS and ERP data, and how to decide between cloud, on-premise and internet-resilient.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data - the UAE PDPL - is the first federal, cross-sector data protection statute in the country. It sits alongside sector rules from the DIFC, ADGM, the Central Bank and the Dubai Health Authority, and it applies to almost every business that processes personal data of individuals inside the UAE. Your customer list is personal data. Your supplier contacts are personal data. The names and phone numbers on your invoices, delivery notes and POS receipts are personal data. That means the question of where your ERP database lives is no longer just an IT preference - it is a compliance question with a paper trail.
The PDPL sets out familiar principles: lawful basis for processing, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality, and accountability. It gives data subjects rights to access, correction, erasure, restriction of processing, portability and objection. It requires controllers to keep records of processing, to notify the UAE Data Office of certain breaches, and to appoint a Data Protection Officer in higher-risk cases. Crucially for ERP buyers, it also regulates cross-border transfer of personal data outside the UAE - transfers are only permitted to jurisdictions with an adequate level of protection, or under specified safeguards such as contractual clauses and explicit consent.
You must be able to justify why you hold each field - contract, legal obligation, legitimate interest or consent.
Customers can ask what you hold. Your system needs to answer, ideally by pulling a full profile in one click.
You must be able to fix or remove personal data on request, subject to VAT record-retention obligations.
Sending personal data outside the UAE requires an adequacy finding or a defined safeguard.
Appropriate technical and organisational measures - encryption at rest and in transit, access control, backup.
Notifiable incidents must reach the UAE Data Office within the timeframes set by the Executive Regulations.
UAE VAT law requires you to keep tax records for five years (fifteen for real estate). PDPL erasure rights do not override that obligation - you retain the invoice, but you may need to lock or minimise personal data beyond the retention window. An ERP with proper archival, not just delete, matters here.
Every UAE ERP falls into one of three shapes. A pure cloud SaaS keeps the master database in a software provider-run data centre, often outside the UAE. A hosted or private cloud puts a dedicated instance in a named region, sometimes inside the UAE, always dependent on a live connection. A internet-resilient, on-premise system installs a database engine on the customer's own server, LAN server or private cloud, and treats any cloud service as optional. Each shape has a different PDPL footprint, a different failure mode when the internet drops, and a different cost profile over five years.
A UAE grocery using a cloud POS whose servers sit in a European region is transferring personal data outside the country every time it rings up a sale under a loyalty account. That transfer is lawful only if the destination is on the adequacy list published under the PDPL Executive Regulations, or if the software provider has put a compliant safeguard in place - typically standard contractual clauses, binding corporate rules or the customer's own explicit, informed consent. Many business owners have never read the sub-processor list of their SaaS software provider. The obligation to know is theirs, not the software provider's.
Separate identifiers (name, Emirates ID, phone, email, address) from transaction data. Note anything sensitive - health, biometrics, minors.
For each system, mark whether data leaves the UAE, which sub-processors touch it, and where backups sit.
For every cross-border flow, confirm adequacy or a written safeguard. Where you rely on consent, make sure the consent is specific, informed and revocable.
Books of account, invoice history, customer master, POS transactions and stock movements can all live on-premise. Ask why they would not.
Zeyto ships as one signed application plus a signed licence. The operational database is local database running on the customer's own server, LAN server or private cloud. Invoicing, POS, stock, VAT return preparation, printing and local backup all work during internet outages indefinitely. Zeyto Cloud is a separate service that only holds licence records, opt-in telemetry and encrypted backups if the customer chooses to use them. Nothing about the operational database leaves the premises unless the owner explicitly turns on encrypted cloud backup, and even then the encryption key stays with the customer. For a UAE business, that means the default answer to 'where does our data live' is simple: on our own server or private cloud, inside the UAE.
No cross-border transfer to argue about, because the database never leaves the premises.
A cut fibre, an ISP issue or a power dip on the software provider side does not stop you invoicing.
Backup encryption keys are generated and held by the customer, not the software provider.
Tax records stay complete and locally addressable for the FTA retention period.
A single customer or supplier record can be exported, corrected or archived in place.
Every posting, edit and login is timestamped in the local ledger, ready for review.
There are good uses for the cloud - remote access, multi-site sync, encrypted off-site backup, business portal. The point is that these should be opt-in additions to a system that already works locally, not the load-bearing foundation. Zeyto puts the cloud where it belongs: on the edge, under the customer's control, with encryption in the customer's hands.
Do not accept vague answers. Ask which country the primary database lives in, and which countries the backups and disaster-recovery copies live in. Ask for the sub-processor list and the Data Processing Agreement in writing. Ask what happens to your data on the day you cancel, and how long it takes to get a full, machine-readable export. Ask whether the system continues to function during an internet outage, and for how long. Ask who holds the encryption keys. A software provider that cannot answer these questions on the first call is not ready for the PDPL either.
Open the public demo, install the Windows trial, or talk to the Zeyto team about your exact workflow, branches, users and reporting needs.
Explore the hosted ERP without installing anything. Use the public demo login below.
Demo data refreshes nightly to keep the sample company clean.
Run Zeyto in your preferred deployment: cloud, private cloud, on-premise, local server, desktop shell, browser access and mobile app.
Send your industry, branch count, users, devices and reporting needs. We route you to sales, support or partner onboarding.
Zeyto is an ERP for UAE businesses. Your data lives on your own server or private cloud, backups are encrypted with your key, and the cloud is optional. Sold and supported by local IT partners.