L O A D I N G
Data protection

UAE PDPL Data Protection ERP Setup for Mainland and Free Zone Firms

Your ERP holds more personal data than any other system: employees, customers, suppliers' contacts. Configure who can see it, where it is hosted and how long it stays.

Free consultation

Get a Free ERP Consultation

Tell us a little about your business. A consultant will reach out within one business day.

  • No obligation
  • Vendor-neutral advice
  • Your data stays private
Quick answer Updated October 2026 · Reviewed by UAE ERP Experts consultants

How should an ERP be configured to comply with the UAE PDPL data protection law?

UAE PDPL data protection for ERP is mostly configuration: role-based access to HR, payroll and customer records, field masking for Emirates ID and bank details, a documented hosting region, and retention schedules. The federal law is Federal Decree-Law No. 45 of 2021, overseen by the UAE Data Office. DIFC and ADGM companies follow their own data protection regimes instead.

  • The PDPL sets conditions for transferring data abroad rather than requiring all ERP data hosted locally.
  • DIFC follows DIFC Law No. 5 of 2020; ADGM follows its Data Protection Regulations 2021.
  • Legally required tax retention periods take priority over deletion requests for the records they cover.
  • A typical ERP data protection review includes a data map, gap review and two to four weeks of configuration.

Personal data protection is mostly configuration

A UAE PDPL data protection ERP review rarely needs new software. It needs decisions written into the system you already have: which roles can open a payroll record, which fields are masked, where the database is hosted, and when old records are anonymised or deleted. Those are the controls supervisors and auditors look for when they ask how personal data is protected.

Onshore, the main law is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, known as the PDPL. It sets rules on processing personal data, consent and its exceptions, data subject rights such as correction and restriction, security, and transfers outside the UAE. The UAE Data Office, established by Federal Decree-Law No. 44 of 2021, is the federal regulator. Check whether implementing regulations and any transition period are in force for your business, as their status affects deadlines.

Free zones with their own data protection laws are excluded from the PDPL. The best-known examples are DIFC, under DIFC Law No. 5 of 2020, and ADGM, under its Data Protection Regulations 2021. Companies licensed there follow those regimes instead. See our ERP for DIFC and ERP for ADGM pages for the free zone side.

Personal data protection is mostly configuration
  • Role-based access to HR, payroll and customer records
  • Hosting region chosen and documented for each system
  • Retention schedule that balances tax, AML and privacy rules
  • A process for access, correction and deletion requests
UAE Compliance

Which data protection regime applies to your ERP

A summary of the main regimes, offered as general information rather than legal advice. Ask your legal advisor which law applies to each entity, especially in groups with mainland and financial free zone companies.

Federal PDPL (mainland and most free zones)

Federal Decree-Law No. 45 of 2021 applies to processing of personal data inside or outside the UAE, subject to listed exclusions. It requires appropriate security measures and sets conditions for transferring personal data abroad.

Exclusions from the PDPL

The law excludes government data, data held by security and judicial authorities, health and banking data that have their own protection legislation, and companies in free zones that have their own data protection laws. Sector rules may add their own requirements.

DIFC Data Protection Law

DIFC Law No. 5 of 2020 is supervised by the DIFC Commissioner of Data Protection. Controllers and processors file a notification of processing that is kept current each year, and where a Data Protection Officer is required, an annual assessment is submitted to the Commissioner.

ADGM Data Protection Regulations 2021

ADGM's Office of Data Protection keeps a register of data controllers. ADGM entities that process personal data register with it and renew annually.

Retention rules from other laws

Tax law requires many records to be kept for five or seven years, and AML guidance sets a five-year minimum for due diligence records. Data protection asks you not to keep personal data longer than needed, so your retention schedule should name the legal reason for each period.

General information, not tax or legal advice. Rules change; confirm current FTA, MOHRE and Ministry of Finance guidance with your advisor.

Data protection settings to review in your ERP

We use this list in ERP health checks. Most items are configuration and policy, not development.

  • A data map showing which modules hold personal data: HR, payroll, CRM, helpdesk, POS, supplier contacts
  • Roles defined by job, with payroll, medical and passport data restricted to named HR users
  • Field-level masking for bank account numbers, Emirates ID and passport numbers where the platform supports it
  • Single sign-on and two-factor authentication for all users, and prompt removal of leavers
  • Hosting region and backup location documented for each system, with the contract terms that apply
  • Audit logging switched on for views and changes of sensitive records where available
  • A retention schedule by record type, with archiving or anonymisation jobs for expired data
  • A logged process for data subject requests: access, correction, restriction and deletion
  • Data processing terms in place with the ERP vendor, hosting provider and integration partners
  • Test and training databases built from anonymised copies, not live personal data
ERP Workflow

A practical data protection cycle for ERP owners

Treat data protection as a cycle you repeat each year and after major changes, not a one-off project.

  1. 1Map personal data
  2. 2Set access roles
  3. 3Choose hosting
  4. 4Define retention
  5. 5Handle requests
  6. 6Review logs
  7. 7Annual review

One shared database: every step updates stock, finance and reports in real time.

How each platform supports data protection controls

Each platform offers the building blocks; the protection comes from how they are configured. Hosting options depend on the vendor's current data centre regions and your plan, so confirm them before you sign.

How each platform supports data protection controls
ZohoOdooERPNextDynamics 365
Access controlRoles, profiles and field-level permissionsAccess groups and record rulesRole and user permissions, field permission levelsSecurity roles, permission sets, field security
AuthenticationTwo-factor and SAML single sign-onTwo-factor; SSO via OAuth or modulesTwo-factor; SSO via OAuth or LDAPMicrosoft Entra ID with conditional access
Hosting choicesZoho data centre regions, including a UAE data centre (confirm availability for your apps)Odoo Online, Odoo.sh, or self-hosted on a cloud or local serverFrappe Cloud (check its current regions) or self-hosted with a cloud provider that has UAE regionsMicrosoft cloud regions, including UAE regions for many services
Audit trailAudit logs in most appsChatter history and audit modulesVersion history and access logsChange log and Microsoft audit features
Self-hosting optionNot for core appsYesYesBusiness Central on-premises remains available

Self-hosting gives full control of location, but your team then owns patching, backups and security monitoring.

Implementation Timeline

A typical data protection review

Ranges for a mid-size company running one main ERP and a CRM. Groups with several entities and regimes take longer.

Durations are typical ranges; your plan is agreed after discovery.

  1. Data map

    1-2 weeks

    We list modules, integrations and exports that hold personal data, and who uses each one.

  2. Gap review

    1 week

    We compare current roles, hosting and retention against your policy and your legal advisor's guidance.

  3. Configuration changes

    2-4 weeks

    Roles, masking, authentication, logging and archive jobs are adjusted and tested.

  4. Process and training

    1 week

    We document how to handle requests and new users, and train HR, finance and IT owners.

Serving the UAE

UAE PDPL Data Protection ERP across all seven emirates

On-site workshops in Dubai, Abu Dhabi and Sharjah, and remote or on-site delivery across the Northern Emirates and free zones.

Official sources and references

Facts on this page were checked against these sources in October 2026. Rules change, so confirm current requirements before acting.

FAQs

PDPL and ERP data protection questions

Still have a question? Our consultants are happy to help.

Ask an Expert
Does the PDPL require ERP data to be hosted in the UAE?

The PDPL sets conditions for transferring personal data outside the UAE rather than a blanket rule that every system must be hosted locally. Some sectors and government contracts do require local hosting. Decide with your legal advisor, then choose a hosting region that fits and record the reason.

We are a DIFC company. Does the federal PDPL apply to us?

Companies in free zones with their own data protection law, such as DIFC and ADGM, are excluded from the PDPL and follow their own regime. A group with mainland and DIFC entities may need to apply both, entity by entity.

How do we delete personal data when tax law says keep records?

Retention periods required by law take priority for the records they cover. After that period, archive, anonymise or delete. Your retention schedule should name the law behind each period so you can show why data is still held.

Can the ERP handle data subject requests?

It can help you find and export a person's data and correct it. Deletion needs care, because posted invoices and payroll records usually cannot be removed during the retention period. Log each request and the outcome.

Is cloud ERP less secure than on-premises?

Not necessarily. Major cloud vendors run security teams most companies cannot match, while self-hosting gives location control but moves patching and monitoring to you. The bigger risk in most reviews is weak user access, not the hosting model.

Free Consultation

Book an ERP data protection review

Tell us which systems hold your personal data, and we will map the access, hosting and retention gaps.

Location

Dubai, United Arab Emirates

Free consultation

Send us your requirements

  • No obligation
  • Vendor-neutral advice
  • Your data stays private
Chat with an ERP expert