Data Protection

Cross-Border Data Transfer Assessment

The UAE has three data protection regimes and they do not treat each other as equivalent. Moving personal data from a DIFC company to its own mainland sister company is a **restricted transfer** requiring safeguards, because the mainland is not on the DIFC adequacy list. Groups do this daily without documenting it.

Download as Word6 pages24 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

Cross-Border Data Transfer Assessment

Moving personal data between UAE regimes and abroad

The UAE has three data protection regimes and they do not treat each other as equivalent. Moving personal data from a DIFC company to its own mainland sister company is a restricted transfer requiring safeguards, because the mainland is not on the DIFC adequacy list. Groups do this daily without documenting it.

ItemDetail
Transferring entity[NAME]
Its jurisdiction[Mainland / Free zone — name it / DIFC / ADGM]
Receiving entity[NAME]
Its jurisdiction or country[DETAIL]
Relationship[Group company / Processor / Independent controller / Cloud provider]
Data transferred[CATEGORIES]
Special or sensitive categories?[Y/N — identify]
Volume and frequency[DETAIL]
Purpose of the transfer[DESCRIBE]
Mechanism relied on[Adequacy / Contractual safeguards / Derogation]
Assessed by[NAME] on [DATE]
Review due[DATE]

1. Establish Which Regime Governs the Transfer

1.1The rules that apply are those of the exporting entity’s jurisdiction. Establish that first.

Exporting entityGoverning lawRegulator
UAE mainlandFederal Decree-Law 45/2021 (PDPL)UAE Data Office
Free zone without its own data lawFederal PDPLUAE Data Office
DIFCDIFC Data Protection Law 5/2020DIFC Commissioner
ADGMADGM Data Protection Regulations 2021ADGM Office of Data Protection

1.2Where data moves in both directions between two entities, there are two transfers and each is assessed under its own exporting regime. They may reach different answers.

Generated from www.helionerp.com1

5 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

The exporting jurisdiction sets the rules

It is the law of the entity sending the data that governs the transfer, not the law of the recipient. In a group with mainland, free zone and DIFC entities, the same flow can be unrestricted in one direction and restricted in the other.

DIFC to mainland is the one that catches groups

The UAE mainland is not on the DIFC adequacy list. A DIFC company sending personal data to its own mainland affiliate, to a mainland payroll provider, or to a mainland bank is making a restricted transfer that needs contractual safeguards or a derogation. This happens constantly and is almost never documented.

The three adequacy lists do not match

Each regime maintains its own list. A country adequate for DIFC purposes may not be treated the same way under the federal regime, and ADGM maintains its own position again. Check the list for the exporting jurisdiction and record the date checked, because the lists change.

Remote access is a transfer

Personal data does not have to be copied to be transferred. An engineer, support agent or administrator outside the UAE who can view or access the data is receiving it. Support arrangements and follow-the-sun helpdesks are transfers even where the data never leaves the UAE server.

Consent is a weak basis for routine flows

Explicit consent works for a one-off transfer where the individual genuinely has a choice. It is a poor foundation for systematic operational flows, because it can be withdrawn at any time and the flow then has no basis. Use contractual safeguards for anything recurring.

Signing the clauses is not the whole job

Standard contractual clauses require an assessment of whether law in the destination — particularly government access powers — would prevent the recipient honouring them. Where it might, supplementary measures such as encryption with keys held locally may be needed.

Follow the onward transfers

A vendor in an adequate country using a sub-processor elsewhere creates a second transfer. Cloud services in particular distribute processing across regions. Ask where the data actually sits and who can reach it, not where the vendor is incorporated.

Assess necessity before mechanism

Question 6 asks whether the transfer is necessary at all, and whether less data would achieve the purpose. Aggregated or pseudonymised data frequently serves group reporting perfectly well and removes the problem entirely.

Tell people in the privacy notice

Transparency is a separate obligation from lawfulness. A transfer with perfect safeguards that was never disclosed in the privacy notice still breaches the transparency requirement.

Keep the register current

The transfer register is what allows a regulator question to be answered in an afternoon rather than a fortnight. It also surfaces the flows nobody authorised — a new SaaS tool adopted by one team is usually discovered through the register rather than through a review.

Review on change, not only on a calendar

A new vendor, a changed cloud region, a group restructuring, or a change to an adequacy list all invalidate the assessment. Tie the review to those events as well as to an annual date.

Sector rules may add restrictions

Banking, healthcare and telecoms data are subject to sector legislation that may restrict transfer independently of the data protection regime. Compliance with the data protection analysis alone is not sufficient in a regulated sector.

Document the reasoning, not just the conclusion

A register entry saying "SCCs" is less useful than one recording what was assessed, what risks were identified and what measures were applied. The reasoning is what demonstrates accountability.

Federal position is unsettled in part

Aspects of the federal transfer regime depend on the PDPL Executive Regulations, whose status is reported inconsistently. Where the federal analysis is uncertain, apply contractual safeguards and document the approach rather than relying on an unconfirmed adequacy position.

Current as of

Reflects UAE, DIFC and ADGM positions current as of {{DATE OF USE}}. Adequacy lists, transfer mechanisms and the status of the federal PDPL Executive Regulations all change — verify the current position for the exporting jurisdiction with the relevant regulator or a UAE data protection adviser before relying on this assessment.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.