UAE Health Data Law: Localisation Rules for Clinics

UAE Federal Law No. 2 of 2019 keeps health data in the country, sets 25-year retention and allows limited exceptions. What clinics and doctors must do.

UAE Health Data Law: Localisation Rules for Clinics

The UAE was one of the first countries in the region to adopt a law specific to health data. Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields, often called the ICT Health Law, applies to hospitals, clinics, pharmacies, insurers and technology providers that handle UAE patients' health information. Its best-known feature is a strict data localisation rule. That rule matters more now that clinics use cloud platforms, teleconsultation and AI tools.

  • Federal Law No. 2 of 2019 sets the principles: confidentiality, data quality, retention, localisation and sanctions.
  • Cabinet Decision No. 32 of 2020, issued in April 2020, is the implementing regulation. It contains much of the operational detail.
  • Ministerial Resolution No. 51 of 2021 from the Ministry of Health and Prevention (MOHAP) lists exceptions to the localisation rule. It was issued on 28 April 2021 and took effect on 16 May 2021.
  • Health data that is governed by its own legislation falls outside the general federal data protection law (Federal Decree-Law No. 45 of 2021), so the ICT Health Law is the main reference. Some free zones, such as Dubai Healthcare City, have their own patient-data rules.

Article 13: health data stays in the UAE

Under Article 13, health data relating to health services provided in the UAE may not be stored, processed, generated or transferred outside the country unless a health authority approves it in coordination with MOHAP. This is stricter than most general privacy laws, which allow transfers with safeguards.

The 2021 exceptions

Resolution No. 51 of 2021 created a closed list of situations in which data may leave the country. Legal analyses list them as including:

  • scientific research
  • pharmacovigilance and safety reporting
  • insurance claims administration
  • wearables and remote monitoring devices
  • some remote and cross-border consultation scenarios

Each exception comes with conditions, such as written patient consent, time limits for remote consultations and reporting duties. As Baker McKenzie notes, fitting an activity within an exception is only the first step. The organisation must also be able to meet the conditions attached to it. The resolution also confirms that the law covers health data of UAE patients that relates to services provided in the UAE.

Retention: at least 25 years

Article 20 requires health data to be kept for at least 25 years from the date of the last health procedure performed on the patient. Longer retention is allowed where needed. This affects archiving budgets, EMR migrations and the decommissioning of old systems. Records must stay readable, complete and confidential for the whole period.

Sanctions

The law provides for fines, warnings and the suspension or cancellation of an entity's licence. Published analyses differ on the exact fine amounts for each article, so check the official Arabic text or ask counsel. Whatever the amount, a licence suspension is the real risk for a clinic.

What clinics should do

1. Map where patient data physically lives

List every system that holds or processes patient information: EMR, PACS, lab interfaces, billing, appointment apps, WhatsApp-type messaging, email, backups and AI or transcription services. For each, record the country where the data is stored and processed.

2. Check every foreign service against Article 13

A cloud EMR hosted abroad, a foreign teleradiology reader or an online AI assistant that receives patient notes may count as a transfer outside the UAE. Either the activity fits a 2021 exception and you meet its conditions, or you need a UAE-hosted or on-premise alternative.

3. Build retention into contracts

Make sure vendor contracts guarantee data return and readable export formats for the 25-year retention period. This matters most when you change systems.

4. Align with your emirate's health authority

Licensing, exchange connections (Malaffi, NABIDH, Riayati) and audits run through the Department of Health Abu Dhabi, the Dubai Health Authority or MOHAP. Their circulars add requirements on top of the federal law.

5. Train staff on everyday leaks

Most localisation breaches are informal: a photo of a report sent through a foreign messaging app, or a dictated letter processed by an online service. Clear rules and approved tools work better than bans.

Key takeaways

  • Federal Law No. 2 of 2019 and Cabinet Decision No. 32 of 2020 govern UAE health data, and the general PDPL largely gives way to them.
  • Article 13 bans storage or processing abroad unless approved or covered by a Resolution 51/2021 exception, each with conditions.
  • Keep records for at least 25 years after the patient's last procedure.
  • Check cloud, teleradiology, messaging and AI tools for hidden transfers abroad.
  • Tools that process data locally on the clinic's own computers remove the localisation question altogether.

General information only, not legal advice.

Frequently asked questions

Can a UAE clinic use a cloud EMR hosted abroad?

Only if the processing is approved by the health authority or fits an exception under MOHAP Resolution No. 51 of 2021, with its conditions met. Otherwise, health data must stay in the UAE.

How long must medical records be kept in the UAE?

Article 20 of Federal Law No. 2 of 2019 requires at least 25 years from the date of the patient's last health procedure.

Does the UAE PDPL apply to health data?

Health data governed by its own legislation, such as the ICT Health Law, falls outside Federal Decree-Law No. 45 of 2021, so the sector law applies.

Sources

  1. Federal Law No. (2) of 2019 Concerning the Use of ICT in Health Fields — official text (EHS)
  2. Al Tamimi & Co — Health data transfers outside the UAE
  3. Baker McKenzie — UAE Health Data Law: Permitted Transfers of Health Data
  4. Al Tamimi & Co — Implementing regulations on the Federal law regulating ICT in the UAE healthcare sector
  5. Baker McKenzie Global Data and Cyber Handbook — UAE key data and cybersecurity laws
Dictate your reports, nothing leaves your computer

Nabady Whisper transcribes your voice offline in English, French or Arabic, with report templates for every specialty.

General information, checked at the publication date; it is neither medical nor legal advice.

Share LinkedIn WhatsApp X