International Data Transfer Agreement Template for the United Arab Emirates
Generate a bespoke document
What is a International Data Transfer Agreement?
This International Data Transfer Agreement is essential for organizations transferring personal data from the UAE to other countries. It is designed to comply with UAE's Federal Decree-Law No. 45/2021 and related regulations, including specific requirements from free zones like DIFC and ADGM. The document should be used whenever personal data is transferred outside the UAE, whether within a corporate group or to third parties. It contains detailed provisions on data protection obligations, security measures, breach notification procedures, and data subject rights. The agreement is particularly important given the UAE's strict data protection requirements and its position as a global business hub, requiring careful consideration of both local and international data protection standards.
Trusted by high-performance teams
About the International Data Transfer Agreement
An International Data Transfer Agreement is a legally binding contract that governs the transfer of personal data from the United Arab Emirates to recipients in other countries. This document ensures compliance with UAE's Federal Decree-Law No. 45/2021, the primary data protection legislation, while establishing clear obligations and safeguards for cross-border data processing activities.
When do you need this document?
You need this agreement whenever your UAE-based organization transfers personal data to entities outside the UAE's borders. This includes transfers to parent companies, subsidiaries, or third-party service providers located in other countries. The agreement is essential for multinational corporations with UAE operations, companies outsourcing services to international vendors, and organizations using cloud services hosted outside the UAE. It's particularly critical when transferring employee data for HR purposes, customer information for business operations, or any sensitive personal data that requires enhanced protection under UAE law.
Key legal considerations
The agreement must establish adequate safeguards for personal data protection, including technical and organizational security measures that meet UAE standards. You must clearly define the roles and responsibilities of both the data exporter and importer, specify the categories of data being transferred, and outline the purposes for processing. The document should include provisions for data subject rights, breach notification procedures, and regular compliance monitoring. Consider including clauses for data retention limits, onward transfer restrictions, and termination procedures. If your organization operates within DIFC or ADGM free zones, additional specific requirements may apply. The agreement must also address potential conflicts between UAE law and the data importer's local regulations.
Legal requirements in United Arab Emirates
Federal Decree-Law No. 45/2021 requires that international data transfers only occur when adequate protection is ensured for personal data. The law mandates that you obtain explicit consent from data subjects or rely on other legal bases for transfer, such as contractual necessity or legitimate interests. If you're operating within the Dubai International Financial Centre, you must also comply with DIFC Data Protection Law No. 5 of 2020, which may impose additional transfer requirements. For Abu Dhabi Global Market entities, the ADGM Data Protection Regulations 2021 apply. Healthcare organizations must consider Federal Law No. 2 of 2019 on ICT in Healthcare when transferring medical data. The UAE Data Office may require notification or approval for certain types of transfers, particularly those involving large volumes of sensitive data or transfers to countries without adequate protection levels.
GOVERNING LAW
Applicable law
This International Data Transfer Agreement is drafted to comply with United Arab Emirates law. Key legislation includes:
DIFC Data Protection Law No. 5 of 2020: Specific data protection regulations for the Dubai International Financial Centre, which may apply if any party is based in DIFC
ADGM Data Protection Regulations 2021: Abu Dhabi Global Market's data protection regulations, relevant if any party is based in ADGM
Federal Law No. 2 of 2019 on the Use of ICT in Healthcare: Specific regulations for health data transfer and processing, relevant if medical data is involved in the transfer
Federal Law No. 5 of 2012 on Combating Cyber Crimes: Cybersecurity law that includes provisions relevant to data security during transfer and storage
UAE Cabinet Resolution No. 21 of 2013: Regulations concerning the security of government data and information systems, relevant if government entities are involved
Explore 208,390+ legal templates
Explore 208,390+ legal templates
Genie's Security Promise
Genie is the safest place to draft. Here's how we prioritise your privacy and security.
Your data is private:
We do not train on your data; Genie's AI improves independently
All data stored on Genie is private to your organisation
Your documents are protected:
Your documents are protected by ultra-secure 256-bit encryption
We are ISO27001 certified, so your data is secure
Organizational security:
You retain IP ownership of your documents and their information
You have full control over your data and who gets to see it

