Guide · UAE data protection
UAE PDPL data protection when your developers are outside the UAE
On this page11 sections
Short answer: the UAE's Personal Data Protection Law (Federal Decree-Law No. 45 of 2021, the PDPL) reaches developers outside the UAE who work on your customers' data, and its definition of cross-border processing covers someone abroad simply viewing records on a UAE server. Put the Article 8 processor duties in your contract, rely on an Article 23 route for the transfer, and design the work so developers rarely need real personal data at all. The detailed Executive Regulations still aren't on any official source we could find.
From our side
Every UAE client asks some version of "so your team in India can see all our customers?" No. We work on a copy where the names and numbers are fake. The real database stays in their account, in the region they choose.
— Avi Singh, Founder
This guide is for UAE businesses (onshore, not in a financial free zone) that hire a development team in another country to build or maintain a system holding customer, staff or supplier data. We're one of those teams: our developers are in India, so we've written it from the side of the people asking for access.
First: which law covers you?
The PDPL isn't the only data protection regime in the UAE. Article 2(2) of the PDPL excludes several groups, and the government's data protection laws page lists the separate laws that cover them.
| Your situation | Main law to check | What it means for an offshore team |
|---|---|---|
| Onshore company (mainland licence) | PDPL, Federal Decree-Law No. 45 of 2021 | Articles 22–23 on transfers; Article 8 processor duties in your contract |
| Company in the DIFC | DIFC Data Protection Law No. 5 of 2020 | Transfers to a country not on the DIFC adequacy list need a safeguard such as DIFC standard contractual clauses |
| Company in ADGM | ADGM Data Protection Regulations 2021 | ADGM's own adequacy list and standard contractual clauses |
| Health data with its own legislation | Federal Law No. 2 of 2019 on ICT in health fields | Excluded from the PDPL by Article 2(2)(e); check the health law before any offshore work |
| Banking and credit data with its own legislation | Sector law and Central Bank rules | Excluded by Article 2(2)(f) |
| Government entities and government data | Not the PDPL | Excluded by Article 2(2)(a)–(b); follow the entity's own rules |
The free-zone exclusion in Article 2(2)(g) only covers free zones that have their own data protection legislation. A company in a free zone without one is under the PDPL like any mainland business.
Why remote access counts as a transfer
Many businesses assume that if the database stays on a UAE server, nothing leaves the country. The PDPL's definitions say otherwise. Cross-Border Processing in Article 1 means "dissemination, use, display, transmission, reception, retrieval, sharing or processing of Personal Data outside the State". A developer in another country opening an admin panel, running a query or reading an error log full of customer emails is displaying and retrieving that data outside the UAE.
ADGM's own guidance on data transfers gives the same reading for its regime: a software provider abroad that needs limited access to personal data on a platform, mainly for support, is treated as an export of data.
So the question isn't only "where is the server?" It's "who can see the data, and from where?"
The two routes the PDPL allows
| Article 22 | Article 23 | |
|---|---|---|
| When it applies | The destination has data protection law and a regulator, or the UAE has a data protection agreement with it, in cases approved by the Data Office | No adequate protection is available |
| Route that fits an offshore developer | Depends on an approved list we couldn't find published | 23(1)(a): a contract obliging the recipient to apply the PDPL's measures and controls |
| Other routes | — | Explicit consent of each person, contract necessity, legal claims, judicial cooperation, public interest |
| Detail still to come | Approval process | Article 23(2): the Executive Regulations set the controls for these transfers |
For a development contract, the practical route is Article 23(1)(a): a written contract that binds the developer to the PDPL's measures and controls. Asking every customer for explicit consent (23(1)(b)) to let a developer see their record isn't workable for most businesses, and consent can be withdrawn at any time under Article 6.
What the contract with your developer should cover
Article 8 lists what a processor must do. Each point becomes a contract clause:
| Article 8 duty | Contract clause to include |
|---|---|
| 8(1) Process only on the controller's instructions and the agreed scope | Written scope: which systems, which data categories, which people, for what purpose |
| 8(2) Protection measures from the design stage | Security requirements for the build: encryption, roles, logging |
| 8(3) Stay within the agreed period, or ask to extend | Fixed access period per project or support term |
| 8(4) Erase data at the end, or on handover | Deletion and return clause, with written confirmation |
| 8(5) No disclosure except as the law allows | Confidentiality covering every individual on the team |
| 8(6) Secure the devices and media used | Rules for laptops, storage, and no data on personal devices |
| 8(7) Keep a record of processing, including cross-border movement | The developer keeps a processing record and gives it to you on request |
| 8(8) Prove compliance when asked | Audit or evidence clause |
| 8(10) More than one processor | Written roles for any subcontractor, or both are jointly responsible |
Article 9(3) adds one more: the developer must tell you about any breach as soon as it becomes aware of it, and you then notify the Data Office. Write that into the contract with a named contact on both sides. Your own record under Article 7(4) must also show "any data related to the cross-border movement" of personal data, so list the offshore team there.
What's still missing: Executive Regulations and fines
Article 28 told the Cabinet to issue Executive Regulations within six months of 20 September 2021. On 3 October 2026, the law's page on the federal legislation portal still showed its last update as 20 September 2021, and the government's data protection page (last updated 4 December 2025) mentions no regulations. That matters for three reasons:
- The compliance clock hasn't started. Article 29 gives businesses six months to regularise their status from the date the Executive Regulations are issued.
- Breach deadlines aren't set. Article 9 says the notification period comes from the regulations.
- Fines aren't in the law. Article 26 leaves violations and penalties to a Cabinet decision.
Several websites state that the regulations have been issued and quote fines. They disagree on the decision number and date, and none we checked linked an official text. We have left those claims out. If you see one, look for the decision on uaelegislation.gov.ae before acting on it.
None of this means the PDPL can be ignored. The law has been in force since 2 January 2022, and Article 24 already lets a customer complain to the Data Office. A processor contract and sensible access controls cost little now, and you won't be starting from zero when the regulations land.
If your developers are in India
India's Digital Personal Data Protection Act 2023 has a specific exemption in section 17(1)(d): most of its duties don't apply when a person in India processes personal data of people outside India under a contract with someone outside India. The section 8(5) duty to take reasonable security safeguards is one of the parts that stays.
In plain terms, Indian law won't do much of the protecting for your UAE customers' data. Your contract has to. That's also why the DIFC adequacy list, which the DIFC publishes and which does not include India, points DIFC firms to standard contractual clauses for Indian suppliers.
Build it so the developers don't need real data
The cheapest compliance is access nobody needs. Article 20 names encryption and pseudonymisation, and Article 5(3) limits data to what the purpose needs. For a development project that translates into a few design choices:
- Host in the region you need. Production stays on a cloud region you choose, in your own account.
- Give developers a masked copy. A staging database with names, phone numbers, emails and addresses replaced. Order history and stock levels can stay real; that's usually what bugs depend on.
- Keep production access for named people, for a period. Time-limited accounts, read-only where possible, every session logged.
- Scrub logs and error reports. Error trackers and AI coding tools are where personal data leaks abroad without anyone noticing. Strip personal fields before they're sent.
- Check every third-party service. Email, SMS, WhatsApp and AI model APIs each move data to another country. Add each one to your Article 7(4) record. Our AI automation builds list these as separate lines for that reason.
- Plan the exit. On handover, the developer deletes local copies and confirms it in writing, as Article 8(4) requires, and you keep the code and data.
A short check before you sign with an offshore team
- Do you know which regime covers you: PDPL, DIFC, ADGM or a sector law?
- Is the developer named as a processor, with the Article 8 duties in the contract?
- Does the contract give your Article 23 transfer basis in writing?
- Can the developers do their work on masked data?
- Who can reach production, from where, until when, and is it logged?
- Will the developer report a breach to a named person as soon as they know?
- Is the offshore team in your record of processing?
How we work on UAE projects
We're a software company founded in 2020 with our development team in India and no UAE office. We build custom systems, apps and AI automations, hosted in the region the client chooses, in accounts the client owns. On UAE projects we set up masked staging data, time-limited production access and a processing record from the start, and we sign a processor agreement your lawyer can review. We don't give legal advice. You get a fixed quote after a 20-minute call.
See what we build for UAE businesses, how we approach custom software development, or book a call. If you'd rather write first, use the enquiry form.
Sources
- UAE Legislation portal, Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data (official English translation; Articles 1, 2, 5–10, 20–29; page checked via the 3 October 2026 archive)
- UAE Legislation portal, PDPL full text download
- UAE Government portal, Data protection laws (last updated 4 December 2025)
- DIFC Commissioner of Data Protection, Data export and sharing, adequate jurisdictions and standard contractual clauses (accessed 7 October 2026)
- ADGM Office of Data Protection, Guidance on the DPR 2021, Part 6: transfers (version 2.0, 14 September 2021)
- Government of India, Digital Personal Data Protection Act 2023 (sections 8 and 17)
Last reviewed 7 October 2026. This guide explains published law and guidance and isn't legal advice. Check the current position with a UAE data protection lawyer before you sign.