Requirements
What the regulation expects

Federal personal data protection since January 2022
Applies to processing of personal data through electronic systems inside or outside the country.
Security measures
Controllers need technical and organisational measures that actually protect personal data. Encryption with keys you govern is one of them.
Cross-border transfer
Keeping keys in the UAE while ciphertext sits in a global cloud is a common pattern. Supply location attestation to counsel; do not treat it as automatic compliance.
Alignment with sector rules
Healthcare (ADHICS), finance (CBUAE) and Dubai DESC often apply in parallel. Key architecture should satisfy the strictest applicable instrument.
Solutions
How DuoKey supports the framework
OpenBAO + DuoKey SD-HSM
On-premise or in-country vault with tamper-evident trail of every key access.
Learn moreMicrosoft 365 DKE
Outer key held under entity control so the SaaS host cannot unilaterally decrypt.
Learn moreKey themes
Where independent key control fits
Quote operative articles from the official text. Product mappings stop at architecture and evidence.
Security measures for personal data
Encryption with customer-held keys, enforced access control and a tamper-evident trail of access to key material.
Cross-border transfer architecture
Key location attestation and deployment topology supplied to the customer's legal transfer assessment. Not a substitute for that assessment.
Discuss the decisions that matter most to your security programme.
Tell us where control is difficult today. We will help you identify a practical next step.
