Data
Residence, movement and egress.
UNITED ARAB EMIRATES
Technology choices change. Customer authority should remain explicit. Twelve customer controls govern data, access, models and assurance across the agreed production system.
Residence, movement and egress.
Approved storage and processing locations.
Cloud, sovereign or on-premises infrastructure.
Users, service identities and permission boundaries.
Key custody, use and revocation.
Named authority before defined actions.
Versions, endpoints and routing.
Permitted actions and operational limits.
A controlled route to stop the system.
Evidence against agreed acceptance criteria.
Protected records of access, outputs and actions.
Portability, migration and substitution.
01 / OPERATING EVIDENCE
For each control, the implementation identifies the owner, the technical mechanism and the evidence used to accept it. Portability depends on the agreed interfaces, formats and supplier terms. It is tested and documented, not assumed.
Customer data is not authorised for supplier model training merely because it is used to provide the service. Processing purposes, retention, support access and any permitted reuse belong in the agreement.
View the reference architecture02 / UAE DEPLOYMENT REQUIREMENTS
The federal Personal Data Protection Law, DIFC law and ADGM regulations have different scopes. Identify the applicable regime and any exclusions before agreeing the processing design.
UAE Government: data protectionLocal hosting is not a complete data-flow assessment. Review inference, storage, logs, support access and backups. Transfer conditions, sector rules and customer approvals affect the design.
ADGM: data protectionGovernment classification, financial-sector controls and health-data requirements need a use-case-specific review. For banks, CBUAE rules include UAE record-location and offshore-sharing conditions within their scope.
CBUAE: outsourcing outside the UAEDefine the people authorised to review, approve and stop consequential actions. DIFC Regulation 10 includes requirements for personal data processed through autonomous and semi-autonomous systems within its scope.
DIFC: Regulation 10General deployment information, reviewed against the cited public sources on 8 September 2026. It is not legal advice or a compliance certification. Confirm the applicable rules and final architecture with your legal, privacy and security owners before production.
CONTACT
Tell us the requirement, the environment and the decision you need to make.