An assistant based outside the UAE can legally handle your business data, including personal information about customers and staff, but only if a few things are set up properly first. UAE data protection law doesn’t ban sending personal data abroad. It just puts conditions on how you do it.
There’s one big exception worth flagging up front. Health data runs under a completely separate law, one that starts from the opposite assumption: it generally can’t leave the UAE at all. If you run a clinic, a medical centre, or anything that touches patient records, jump ahead to that section before reading the rest. It changes the answer.
Everything else here is about setting things up the right way, not about whether it’s allowed.
UAE data protection: which rulebook applies to you
First, work out which regime actually applies to you. The UAE runs several data protection frameworks side by side, and they’re not interchangeable.
| Your situation | Which law governs your data |
|---|---|
| Mainland UAE company | Federal PDPL — Federal Decree-Law No. 45 of 2021 |
| Commercial free zone with no data protection law of its own | Federal PDPL |
| Registered in DIFC | DIFC Data Protection Law No. 5 of 2020 — its own regime |
| Registered in ADGM | ADGM Data Protection Regulations 2021 — its own regime |
| Dubai Healthcare City | Its own free zone rules, preserved separately |
| You handle patient or health data | Federal Law No. 2 of 2019 on ICT in health fields — see below |
| You handle banking or credit data | Sector-specific rules, outside the PDPL |
Most businesses reading this — a consultancy, an agency, a logistics company, a real estate brokerage, an online store — fall under the federal PDPL. If you’re set up in DIFC or ADGM, a lot of the thinking below still applies in spirit, but the actual rules differ, so work from your own regime rather than this one.
One thing that trips people up: just being in a free zone doesn’t get you out of the federal law. The exemption only applies to free zones that have their own data protection rules, and in practice that means the financial free zones. If you’re in an ordinary commercial free zone, you’re still inside the federal PDPL.
Your assistant is covered too, wherever they’re based
The federal PDPL has applied since 2 January 2022, and its reach is broad by design. It covers any controller or processor inside the UAE, no matter where the person whose data it is happens to live. It also covers controllers and processors outside the UAE, as long as they’re processing the personal data of people inside the UAE.
That second part is the one that matters here. An assistant working from Manila on your Dubai customer list isn’t outside the law just because they’re outside the country. Neither is the company employing them.
That’s actually good news, not bad news. It means the law was written with this exact setup in mind, rather than leaving it as a grey area for someone to close later.
Delegating the work doesn’t delegate the responsibility
This is the part most businesses get wrong.
If you’re the one deciding what data gets collected and why, you’re the controller. Anyone processing it on your instructions, whether that’s your assistant, the company employing them, or your CRM provider, is a processor. Handing the work to a processor doesn’t hand over the obligation with it. The duty to protect that data is still yours.
The PDPL is explicit that this sits with the controller: you’re expected to satisfy yourself that any processor you use can actually deliver appropriate technical and organisational safeguards, on top of the separate obligations that bind the processor directly. “Our assistant handles that” isn’t an answer to a data protection question. Choosing who you hand data to is itself a decision you’re accountable for.
Which means the vetting you do on a provider isn’t a nice-to-have, it’s part of your compliance position. It’s also the clearest argument for a managed arrangement over an anonymous marketplace contractor. Our managed VA versus marketplace comparison goes into the broader differences, but the data angle alone is worth noting: with a managed provider, you’re contracting with an identifiable legal entity that’s already done the vetting, working with a named person under supervision. Hire through a platform instead, and that vetting is yours to do yourself, and the accountability chain is a lot shorter than most buyers assume.
What’s actually allowed when data leaves the UAE
The PDPL gives you two ways to do this legally.
One is sending data to a country the UAE Data Office recognises as offering an adequate level of protection, generally somewhere with its own data protection law or that’s signed up to the relevant international agreements.
The other is relying on safeguards when the destination doesn’t have that recognition. The law still permits the transfer through routes including:
- a contract that binds the recipient to PDPL-level protections (the standard contractual clauses approach)
- the data subject’s own express consent to the transfer
- cases where the transfer is necessary to carry out a contract involving them, or a contract with a third party that’s in their interest
- international judicial cooperation, or where it’s necessary in the public interest
For most businesses hiring a provider whose assistants are based somewhere without that adequacy recognition, the contract route is the practical one: a written agreement that obliges the provider and their staff to handle your data to PDPL standards. This is ordinary commercial practice, not some exotic legal manoeuvre. Any provider worth using should already have one, or be willing to sign yours.
One caveat: the Data Office hasn’t published a public list of approved countries, so don’t assume any particular one qualifies. Put the contractual safeguards in place regardless. That route doesn’t depend on a list that may not exist yet.
The hard stop: health data
If your business handles health data, most of the above doesn’t matter. A different law takes over, and it’s much stricter.
Federal Law No. 2 of 2019 covers the use of information and communication technology in health fields, and it applies across the UAE, free zones included. The provision that matters is Article 13: health information and data tied to health services provided in the UAE can’t be stored, processed, generated, or transferred outside the UAE, except in cases the relevant health authority has specifically approved.
That’s the opposite structure from the PDPL. Instead of permitted-with-conditions, it’s prohibited-with-narrow-exceptions.
The definition of health data is also wider than most people assume. The law defines it as data characterised by a health feature, whether that relates to health or insurance bodies or to the person receiving the service. Legal commentary on the law reads that as covering patient names, information from consultations, diagnosis and treatment records, patient ID numbers, medical images, and lab results.
If you run a clinic, that has a consequence that’s easy to miss. A list of patient names and appointment times counts as health data too. Not just the clinical notes. The booking calendar itself.
None of the exceptions cover outsourced admin work. Ministerial Resolution 51/2021, from August 2021, lists ten categories where health data is allowed to leave the country: things like overseas medical treatment, lab samples sent abroad, approved scientific research, claims data for UAE-licensed insurers, pharmacovigilance, some telemedicine arrangements, and transfers the patient has specifically requested. Most come with conditions attached: written patient consent, strong encryption, anonymisation where it applies, and a copy kept inside the UAE.
There’s no category on that list for general back-office admin. An offshore admin arrangement that touches patient data doesn’t fit into any of the ten.
The penalties are serious enough to notice: breaching Article 13 carries a fine of AED 500,000 to AED 700,000.
If you run a healthcare business in the UAE and the work touches patient data in any form, including the appointment book, an assistant outside the country is the wrong tool for it, and no contract fixes that. Work that truly doesn’t touch patient data might be a different conversation, but that line needs a qualified adviser to draw it, not a guess.
We’d rather say that clearly and lose the enquiry than place an assistant into an arrangement that could cost a client a six-figure fine.
What’s still unsettled, and why it doesn’t change what you should do
The PDPL’s Executive Regulations are the implementing detail that would spell out the adequacy list, breach notification timelines, and the penalty regime, and their status has genuinely been unclear. They were originally due within six months of the law being issued in September 2021. Established legal trackers have reported them as still unpublished well past that point. A few secondary sources say they were issued by Cabinet decision sometime in 2026. The official legislation portal doesn’t clearly reflect either version. Once they’re issued, organisations get another six months to bring their operations into line.
The PDPL itself doesn’t spell out penalties on its face; those are left to a future Cabinet decision. Separately, the Cyber Crime Law (Federal Decree-Law No. 34 of 2021) already provides for detention and fines between AED 50,000 and AED 500,000 for breaching data protection legislation.
None of that is a reason to wait. The obligations in the main law are already in force, the direction is clear enough, and every control in the next section is something you’d need under any version of the regulations that eventually lands. Put the mechanics in place now and you’re not betting on how the details shake out.
What to actually put in place
A practical list for engaging any provider whose assistants work outside the UAE:
1. Work out which regime applies to you. Mainland, commercial free zone, DIFC, ADGM, or a sector-specific law. Everything else follows from this one decision.
2. Put a data processing agreement in writing. Name the parties, define what’s being processed and why, bind the provider to PDPL-standard protections, cover onward transfers and sub-processors, set out security measures and breach notification, and say what happens to the data once the engagement ends. This is what makes a transfer to a non-adequate country defensible.
3. Only give access to what the task needs. The best data protection control is simply not handing over data someone doesn’t need — an assistant running your calendar has no reason to be in the finance folder. Our guide on scoping what to delegate is useful here: define the task, then grant the access it actually requires, in that order.
4. Keep data in systems, not on personal devices. Give access through your CRM, shared drive, or helpdesk, tied to named accounts, rather than letting working files pile up on someone’s personal laptop overseas. That way access can be revoked, checked, and contained.
5. Know who’s actually doing the work. You should be able to name the person handling your data. If a provider can’t tell you who that is, you can’t really assess anything else they’re telling you about vetting.
6. Get breach notification into the contract. You’re the one who has to tell the Data Office if something goes wrong, and you can’t do that if your provider sits on the news for a week.
7. Plan the offboarding, not just the onboarding. Access revoked, accounts closed, working copies deleted, confirmed in writing. Agree this up front, while it’s a clause, rather than at the end, when it’s a scramble.
8. Revisit this once the regulations land. Put a reminder in your calendar. When the Executive Regulations are confirmed, read your agreement against them and adjust anything that needs it.
When we’d tell you not to
A few situations where the honest answer is “don’t”:
- Health data, as covered above. Not a contract problem, a legal one. The exceptions don’t stretch to cover general admin support.
- Banking and credit data, which sit outside the PDPL under their own rules and need advice from someone who specialises in that, not a general answer.
- Work where the entire value is in data you couldn’t lawfully share in the first place. The arrangement stops making sense once access is scoped properly.
- Nobody internally owns this. If no one on your side can sign off on a processing agreement or say what access is appropriate, sort that out before adding a processor, not after.
Where Desert VA fits
We run a managed model. We recruit, vet, employ, and supervise the assistant; you direct the day-to-day work. For data protection purposes, that means you’re contracting with one identifiable UAE-registered entity, working with a named person we employ and supervise, instead of assembling that accountability chain yourself.
Ask us, and ask anyone else you’re evaluating, five concrete questions: will you sign a data processing agreement, where exactly are your assistants based, who specifically will be working on our data, what happens to their access once the engagement ends, and how fast will you tell us if something goes wrong. Those five questions are a decent filter for who’s actually thought about this.
If a scoping call turns up work involving data that shouldn’t leave the country, we’ll say so rather than propose a workaround. Book a consultation if you want to talk it through, or see what our assistants actually handle on the services page first.
And if the bigger question is which hiring model fits at all, our UAE hiring decision guide walks through employee, freelancer, marketplace, and managed options, including work permits, statutory costs, and legal exposure.
Frequently asked questions
Can a virtual assistant outside the UAE legally access my customer data? Generally, yes, under the federal PDPL, as long as the transfer meets the law’s conditions: either the destination is recognised as offering adequate protection, or you’ve got contractual safeguards binding the recipient to PDPL-level protections. Health data is the big exception, and it runs under a separate law that starts from a prohibition rather than a permission.
Do I need a data processing agreement with a VA provider? For a transfer to a country without UAE adequacy recognition, yes, in practice. A contract imposing PDPL-standard obligations is one of the main permitted routes, and it’s also how you show the diligence the law expects from you as the controller.
Does the PDPL apply if my company is in a free zone? It depends which one. DIFC and ADGM run their own data protection regimes and sit outside the federal law, and so does Dubai Healthcare City. An ordinary commercial free zone without its own data protection law falls under the federal PDPL.
Can an offshore assistant handle patient data for a UAE clinic? Almost certainly not. Federal Law No. 2 of 2019 generally prohibits storing, processing, or transferring health data outside the UAE, and the narrow exceptions in Ministerial Resolution 51/2021 don’t include outsourced admin support. Breaches carry fines of AED 500,000 to AED 700,000, so get specific advice before assuming any part of the work falls outside the definition.
Who is liable if a virtual assistant mishandles our data — us or the provider? As controller, the obligation to protect the data stays with you, including the duty to pick a processor that can actually deliver on it. The processor has its own obligations too, and your contract sets the commercial terms between you. Handing off the task doesn’t hand off the responsibility.
Is the UAE PDPL fully in force? The law itself has applied since 2 January 2022. The Executive Regulations that would fill in the implementing detail have had an unclear published status, and once they land, organisations get six months to comply. Either way, the core obligations apply right now.
Sources and methodology
Researched and written: September 2026. Next review due: March 2027, or sooner if the PDPL Executive Regulations are confirmed published.
Data protection law in the UAE is still moving, and one input here, the status of the PDPL’s Executive Regulations, is reported inconsistently even across reliable sources. Where that’s true, this article says so rather than picking whichever version reads more cleanly. Article numbers are given only where the instrument and provision could be identified consistently across sources; see the note below the table.
| Claim | Source |
|---|---|
| PDPL is Federal Decree-Law No. 45 of 2021; in force 2 January 2022; scope covers controllers/processors outside the UAE processing data of individuals inside it | UAE Government Portal — Data protection laws · DLA Piper Data Protection Laws of the World — UAE |
| DIFC, ADGM and Dubai Healthcare City preserved under their own regimes; commercial free zones without their own law fall under the federal PDPL; health, banking and credit data governed separately | DLA Piper — UAE |
| Cross-border transfer permitted to destinations recognised as adequate, or otherwise via contractual clauses, express consent, contractual necessity, judicial cooperation or public interest | Securiti — Overview of the UAE PDPL · International Trade Administration — UAE cross-border data flows |
| Controller must engage processors providing sufficient guarantees; separate obligations bind processors | Securiti — Overview of the UAE PDPL |
| PDPL specifies no penalties on its face; Cyber Crime Law (Federal Decree-Law No. 34 of 2021) provides AED 50,000–500,000 for breaching data protection legislation | DLA Piper — UAE |
| Executive Regulations status unclear; six months to comply from issuance | DLA Piper — UAE · Chambers Global Practice Guides — Data Protection & Privacy 2026, UAE |
| Federal Law No. 2 of 2019 applies across the UAE including free zones; Article 13 generally prohibits storing, processing, generating or transferring UAE health data abroad except as defined by health authority decision | UAE Legislation Portal — Federal Law No. 2 of 2019 · DLA Piper — UAE |
| Health data definition read as reaching patient names, consultation data, diagnosis and treatment records, patient identifiers, medical images and lab results | Taylor Wessing — Health data in the UAE · BSA Law — The New UAE Health Data Law |
| Ministerial Resolution 51/2021 (August 2021) sets ten exception categories, with conditions including written patient consent, encryption, anonymisation and a copy retained in the UAE | Hogan Lovells — The UAE’s Health Data Law |
| Article 13 breach carries a fine of AED 500,000–700,000 | Global Compliance News — UAE: New Health Data Law |
A note on article numbers. Sources disagree on which PDPL article covers cross-border transfer: DLA Piper points to Article 10, other summaries cite Articles 22 and 23. The official English translation is for reference only, and the Arabic text prevails. Since that conflict couldn’t be resolved against the primary Arabic text, this article describes the cross-border mechanisms without putting a number on them. Article 13 of Federal Law No. 2 of 2019 is cited by number because every independent source identifies it the same way.
Nothing here is legal advice. It’s a practical summary built from published law and reputable legal commentary. Your position depends on your licence, jurisdiction, sector, and the specific data involved, so get qualified UAE legal advice before relying on any of it.