Your ERP holds more personal data than any other system: employees, customers, suppliers' contacts. Configure who can see it, where it is hosted and how long it stays.
UAE PDPL data protection for ERP is mostly configuration: role-based access to HR, payroll and customer records, field masking for Emirates ID and bank details, a documented hosting region, and retention schedules. The federal law is Federal Decree-Law No. 45 of 2021, overseen by the UAE Data Office. DIFC and ADGM companies follow their own data protection regimes instead.
A UAE PDPL data protection ERP review rarely needs new software. It needs decisions written into the system you already have: which roles can open a payroll record, which fields are masked, where the database is hosted, and when old records are anonymised or deleted. Those are the controls supervisors and auditors look for when they ask how personal data is protected.
Onshore, the main law is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, known as the PDPL. It sets rules on processing personal data, consent and its exceptions, data subject rights such as correction and restriction, security, and transfers outside the UAE. The UAE Data Office, established by Federal Decree-Law No. 44 of 2021, is the federal regulator. Check whether implementing regulations and any transition period are in force for your business, as their status affects deadlines.
Free zones with their own data protection laws are excluded from the PDPL. The best-known examples are DIFC, under DIFC Law No. 5 of 2020, and ADGM, under its Data Protection Regulations 2021. Companies licensed there follow those regimes instead. See our ERP for DIFC and ERP for ADGM pages for the free zone side.

A summary of the main regimes, offered as general information rather than legal advice. Ask your legal advisor which law applies to each entity, especially in groups with mainland and financial free zone companies.
Federal Decree-Law No. 45 of 2021 applies to processing of personal data inside or outside the UAE, subject to listed exclusions. It requires appropriate security measures and sets conditions for transferring personal data abroad.
The law excludes government data, data held by security and judicial authorities, health and banking data that have their own protection legislation, and companies in free zones that have their own data protection laws. Sector rules may add their own requirements.
DIFC Law No. 5 of 2020 is supervised by the DIFC Commissioner of Data Protection. Controllers and processors file a notification of processing that is kept current each year, and where a Data Protection Officer is required, an annual assessment is submitted to the Commissioner.
ADGM's Office of Data Protection keeps a register of data controllers. ADGM entities that process personal data register with it and renew annually.
Tax law requires many records to be kept for five or seven years, and AML guidance sets a five-year minimum for due diligence records. Data protection asks you not to keep personal data longer than needed, so your retention schedule should name the legal reason for each period.
General information, not tax or legal advice. Rules change; confirm current FTA, MOHRE and Ministry of Finance guidance with your advisor.
We use this list in ERP health checks. Most items are configuration and policy, not development.
Treat data protection as a cycle you repeat each year and after major changes, not a one-off project.
One shared database: every step updates stock, finance and reports in real time.
Each platform offers the building blocks; the protection comes from how they are configured. Hosting options depend on the vendor's current data centre regions and your plan, so confirm them before you sign.
| Zoho | Odoo | ERPNext | Dynamics 365 | |
|---|---|---|---|---|
| Access control | Roles, profiles and field-level permissions | Access groups and record rules | Role and user permissions, field permission levels | Security roles, permission sets, field security |
| Authentication | Two-factor and SAML single sign-on | Two-factor; SSO via OAuth or modules | Two-factor; SSO via OAuth or LDAP | Microsoft Entra ID with conditional access |
| Hosting choices | Zoho data centre regions, including a UAE data centre (confirm availability for your apps) | Odoo Online, Odoo.sh, or self-hosted on a cloud or local server | Frappe Cloud (check its current regions) or self-hosted with a cloud provider that has UAE regions | Microsoft cloud regions, including UAE regions for many services |
| Audit trail | Audit logs in most apps | Chatter history and audit modules | Version history and access logs | Change log and Microsoft audit features |
| Self-hosting option | Not for core apps | Yes | Yes | Business Central on-premises remains available |
Self-hosting gives full control of location, but your team then owns patching, backups and security monitoring.
Ranges for a mid-size company running one main ERP and a CRM. Groups with several entities and regimes take longer.
Durations are typical ranges; your plan is agreed after discovery.
We list modules, integrations and exports that hold personal data, and who uses each one.
We compare current roles, hosting and retention against your policy and your legal advisor's guidance.
Roles, masking, authentication, logging and archive jobs are adjusted and tested.
We document how to handle requests and new users, and train HR, finance and IT owners.
Data protection touches every system that holds people's details.
On-site workshops in Dubai, Abu Dhabi and Sharjah, and remote or on-site delivery across the Northern Emirates and free zones.
Official sources and references
Facts on this page were checked against these sources in October 2026. Rules change, so confirm current requirements before acting.
Still have a question? Our consultants are happy to help.
Ask an ExpertThe PDPL sets conditions for transferring personal data outside the UAE rather than a blanket rule that every system must be hosted locally. Some sectors and government contracts do require local hosting. Decide with your legal advisor, then choose a hosting region that fits and record the reason.
Companies in free zones with their own data protection law, such as DIFC and ADGM, are excluded from the PDPL and follow their own regime. A group with mainland and DIFC entities may need to apply both, entity by entity.
Retention periods required by law take priority for the records they cover. After that period, archive, anonymise or delete. Your retention schedule should name the law behind each period so you can show why data is still held.
It can help you find and export a person's data and correct it. Deletion needs care, because posted invoices and payroll records usually cannot be removed during the retention period. Log each request and the outcome.
Not necessarily. Major cloud vendors run security teams most companies cannot match, while self-hosting gives location control but moves patching and monitoring to you. The bigger risk in most reviews is weak user access, not the hosting model.
Related Solutions
Related Industries
Related ERP Platforms
Tell us which systems hold your personal data, and we will map the access, hosting and retention gaps.
Dubai, United Arab Emirates