---
title: "Moving Personal Data Abroad: Cross-Border Data Transfers Under UAE Law"
date: 2026-08-11
author: "ABS Partners"
url: https://abspartners.ae/cross-border-data-transfers-uae-pdpl/
---

# Moving Personal Data Abroad: Cross-Border Data Transfers Under UAE Law

Posted On - 11 August, 2026 • By - [Ayush A Haq](https://abspartners.ae/people/ayush-a-haq/)

![UAE cross-border data transfers under data protection law](https://abspartners.ae/wp-content/uploads/uae-cross-border-data-transfers-data-protection-law.jpg)

For multinational groups operating in the UAE, one question comes up constantly: can we transfer employee, customer, or business data from our UAE entity to a parent company, shared services hub, or affiliate in another country? The answer sits in UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), the UAE’s first comprehensive federal [data protection](https://abspartners.ae/practice-areas/data-privacy/) statute, in force since 2 January 2022. This article sets out what the PDPL actually says about cross-border transfers, how intra-group transfers are treated, where DIFC and ADGM diverge from the federal regime, and what remains unsettled while the law’s executive regulations are still pending.

The Federal Framework: Articles 22 and 23  
The PDPL’s cross-border transfer regime is built around two core provisions, Articles 22 and 23. Together, they set out a general rule and a set of exceptions.  
The general rule is that personal data may only be transferred outside the UAE to a jurisdiction that offers an “adequate” level of protection for personal data; broadly, protection comparable to what the PDPL itself provides. Adequacy is intended to be determined centrally by the UAE Data Office, the federal regulator established alongside the PDPL, which is expected to maintain a list of approved countries and territories.  
Where the destination country has not been confirmed as adequate, the PDPL contemplates alternative lawful bases for transfer, broadly consistent with international practice, including:  
• Appropriate safeguards, such as approved standard contractual clauses (SCCs) or binding corporate rules (BCRs) that impose PDPL-equivalent obligations on the receiving entity  
• A specific derogation, most importantly explicit consent from the data subject to the particular transfer, after they have been informed of the risks  
• Necessity for the performance of a contract with the data subject, or for pre-contractual steps taken at their request  
• Necessity to protect the vital interests of the data subject, where consent cannot practically be obtained  
• Necessity for the establishment, exercise, or defense of [legal claims](https://abspartners.ae/practice-areas/litigation/)  
This structure will look familiar to anyone versed in GDPR, and the PDPL was deliberately drafted with international frameworks in mind. The categories of safeguard, the approval mechanics for SCCs and BCRs, and the adequacy list itself are all meant to be defined in more granular detail through the law’s executive regulations.  
Why This Matters for Intra-Group Data Transfers  
Cross-border rules are not just a concern for arm’s-length vendor relationships. They apply squarely to transfers between related companies, i.e. a UAE subsidiary sending HR data to a regional headquarters, a UAE branch feeding customer data into a global CRM hosted abroad, or a shared finance function processing payroll data outside the country. Corporate affiliation does not exempt a transfer from the PDPL; “group company” is not itself a lawful basis.  
For groups with recurring, structural data flows between entities, the PDPL’s safeguard mechanisms point toward two practical tools:  
Binding Corporate Rules (BCRs): internal, group-wide data protection policies that bind every entity in the corporate group to PDPL-equivalent standards, regardless of where they sit. BCRs are the natural fit for groups with frequent, high-volume intra-group data flows, since they avoid the need to paper every transfer with a separate contract.  
Intra-group data transfer agreements / standard contractual clauses: contractual commitments between the UAE entity and the receiving affiliate, imposing UAE-equivalent protections, audit rights, and breach notification obligations on the recipient.  
Until the UAE Data Office publishes an approved adequacy list, approved SCC templates, and a formal BCR approval process, groups are largely operating on the text of the Decree-Law and general principles rather than a settled procedural framework. In practice, well-advised groups are already documenting their intra-group flows, mapping which entities receive UAE-originated personal data, and putting contractual safeguards in place now, rather than waiting for the executive regulations to catch up.  
DIFC and ADGM: A Materially Different Regime  
This is where many groups get tripped up. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) are financial free zones with their own independent legal systems, and each has its own standalone data protection law; the DIFC Data Protection Law (DIFC Law No. 5 of 2020) and the ADGM Data Protection Regulations 2021. These are not simply “local implementations” of the federal PDPL; they are separate legislative regimes, closely modeled on the EU GDPR, complete with their own regulators, their own adequacy determinations, and their own approved SCC and BCR frameworks.  
Two consequences follow that are easy to miss in group structuring:  
First, a transfer of personal data from the UAE mainland into DIFC or ADGM or between DIFC/ADGM and a foreign jurisdiction is treated as a cross-border transfer in its own right, governed by that free zone’s law, not the federal PDPL. A group with a mainland trading entity and a DIFC-based holding or treasury function needs to treat the flow between them as an international transfer requiring its own lawful basis, even though both entities are technically within the UAE.  
Second, DIFC’s and ADGM’s adequacy lists are generally more developed than the federal regime’s, since both were built with direct reference to the EU’s own adequacy decisions. A jurisdiction recognized as adequate by DIFC is not automatically recognized as adequate under the federal PDPL, and vice versa: group data maps that assume a single “UAE adequacy standard” will be wrong in practice.  
For any group with entities spread across mainland UAE and one or both free zones, this means running, in effect, up to three parallel compliance analyses for what looks internally like a single data flow.  
The Open Question: Executive Regulations  
The PDPL itself anticipated that executive regulations would follow to operationalize the law’s high-level provisions, originally expected within six months of the Decree-Law’s issuance. As of the time of writing, the status of those executive regulations, including the promised adequacy list, approved SCC templates, and formal BCR approval mechanism, has not been consistently or reliably confirmed through primary sources, and reporting on this point across secondary commentary is inconsistent. Businesses should treat the precise regulatory status and any claimed Cabinet Decision numbering as unconfirmed pending direct verification against the UAE Legislation Portal or Official Gazette, rather than rely on it from commentary alone.  
Practically, this means the core obligations in Articles 22 and 23 are in force and bind controllers and processors now, but the detailed procedural infrastructure that would normally make compliance straightforward; a published adequacy list, pre-approved contractual clause templates, and a formal BCR filing process has not been reliably confirmed as available. Groups are, in effect, expected to comply with a principle-based standard ahead of the machinery that would make compliance mechanical.

What This Means in Practice  
For groups structuring or reviewing cross-border data flows involving a UAE entity, three things are worth doing now, independent of when the executive regulations land:  
• Map the flows: Identify every regular transfer of personal data out of the UAE entity: to group affiliates, cloud providers, or outsourced processors and note the receiving jurisdiction and legal basis relied upon.  
• Distinguish mainland from free zone: Treat DIFC and ADGM entities as separate jurisdictions for data transfer purposes, not as extensions of the mainland entity, and apply the correct law to each leg of the flow.  
• Put contractual safeguards in place: Rather than waiting for an approved SCC template or BCR process, use current best-practice contractual language: data processing agreements with UAE-specific obligations layered in as an interim safeguard that can be updated once the regulatory framework is confirmed.

The direction of travel is clear: the UAE is building a cross-border data transfer regime broadly aligned with international standards. What remains open is the procedural detail, and until that detail is confirmed through primary legislative sources, groups moving data in and out of the UAE should build compliance programs on the statutory text itself, kept current as the position develops.

[Data Privacy](https://abspartners.ae/practice-areas/data-privacy/)

---

## About ABS Partners

> ABS Partners is a top-tier legal consultancy firm specializing in corporate, regulatory, and advisory services, delivering expert solutions for complex legal disputes with excellence and integrity.

---

## Important Links

**Column 1**

- [People](https://abspartners.ae/people/)
- [Services](https://abspartners.ae/practice-areas/)
- [Industries](https://abspartners.ae/practice-areas/)
- [Insights](https://abspartners.ae/insights/)

**Column 2**

- [About Us](https://abspartners.ae/about/)
- [Updates](https://abspartners.ae/news/)
- [Careers](https://abspartners.ae/careers/)
- [Contact Us](https://abspartners.ae/contact-us/)

---

## Follow Us

- [LinkedIn](https://www.linkedin.com/company/100311808/)
- [Facebook](https://www.facebook.com/profile.php?id=61552819263833/)
- [Instagram](https://www.instagram.com/abs.partners/)
- [YouTube](https://www.youtube.com/channel/UCepnubj-V_jSapMmZEtnWAw)

---