The UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection came into force in January 2022. Yet the majority of enterprise AI vendor contracts signed since then contain clauses that conflict with its requirements, and most procurement teams do not know what to look for.
The Training Data Problem
The most common issue is model training. Many AI vendors include clauses, sometimes buried in appendices, permitting them to use client data to train or improve their models. Under UAE PDPL Article 11, processing personal data for purposes beyond those originally specified requires fresh consent or a legitimate interest assessment.
If your AI vendor processes UAE personal data, names, IDs, health records, financial transactions, using your data to train their models without explicit written consent from your organisation (and potentially from data subjects) creates legal exposure. Not for the vendor. For you, as the data controller.
Under UAE PDPL, you are the data controller. The vendor is a data processor. Their compliance failures are your regulatory liability.
The Residency Question
PDPL Article 26 restricts cross-border data transfers to jurisdictions with equivalent protection or where appropriate safeguards exist. Sending UAE personal data to a US or EU cloud for AI processing requires documented safeguards, Standard Contractual Clauses, Binding Corporate Rules, or an adequacy decision.
Most cloud AI vendors do not operate UAE-resident infrastructure. Processing happens in their global regions, US East, EU West, Asia Pacific. The adequacy framework between UAE and these jurisdictions is still developing. Until it is settled, the prudent position is to keep UAE personal data in UAE infrastructure.
Five Contract Clauses to Review
- Model training rights: does the vendor claim any right to use your data for training? Insist this is explicitly excluded or requires separate written consent.
- Data residency: where does processing physically occur? Get a jurisdiction commitment, not just a contractual assurance.
- Sub-processor disclosure: who does the vendor share data with? PDPL requires you to know your sub-processors.
- Retention after termination: how long does the vendor retain your data after contract end? PDPL requires deletion.
- Breach notification: what are the vendor's obligations if your data is compromised? PDPL requires notification within 72 hours.
The On-Premises Alternative
The cleanest compliance position is on-premises AI deployment, no data leaves your infrastructure, no sub-processors, no cross-border transfer questions. This is architecturally more demanding, but for regulated entities processing sensitive UAE personal data, it eliminates an entire class of compliance risk.
This is one reason Varaisys built DetraCore and FluxNode as on-premises-first platforms. Zero data egress is not a selling point, it is the correct architecture for the UAE enterprise context.