[HEADER — replace with your organisation’s letterhead, if used]
Cross-Border Data Transfer Assessment
Moving personal data between UAE regimes and abroad
The UAE has three data protection regimes and they do not treat each other as equivalent. Moving personal data from a DIFC company to its own mainland sister company is a restricted transfer requiring safeguards, because the mainland is not on the DIFC adequacy list. Groups do this daily without documenting it.
| Item | Detail |
|---|
| Transferring entity | [NAME] |
| Its jurisdiction | [Mainland / Free zone — name it / DIFC / ADGM] |
| Receiving entity | [NAME] |
| Its jurisdiction or country | [DETAIL] |
| Relationship | [Group company / Processor / Independent controller / Cloud provider] |
| Data transferred | [CATEGORIES] |
| Special or sensitive categories? | [Y/N — identify] |
| Volume and frequency | [DETAIL] |
| Purpose of the transfer | [DESCRIBE] |
| Mechanism relied on | [Adequacy / Contractual safeguards / Derogation] |
| Assessed by | [NAME] on [DATE] |
| Review due | [DATE] |
1. Establish Which Regime Governs the Transfer
1.1The rules that apply are those of the exporting entity’s jurisdiction. Establish that first.
| Exporting entity | Governing law | Regulator |
|---|
| UAE mainland | Federal Decree-Law 45/2021 (PDPL) | UAE Data Office |
| Free zone without its own data law | Federal PDPL | UAE Data Office |
| DIFC | DIFC Data Protection Law 5/2020 | DIFC Commissioner |
| ADGM | ADGM Data Protection Regulations 2021 | ADGM Office of Data Protection |
1.2Where data moves in both directions between two entities, there are two transfers and each is assessed under its own exporting regime. They may reach different answers.