Federal Law No. 2 of 2019 Concerning the Use of ICT in Health Fields compliance software
The federal law behind every UAE health data programme — 44 duties from Federal Law No. 2 of 2019, its Executive Regulation (Cabinet Resolution 32/2020) and the localisation exceptions in Ministerial Resolution 51/2021, each citing its article.
- RegulatorMOHAP and the health authorities (DoH Abu Dhabi, DHA, EHS)
- InstrumentsFederal Law 2/2019 (in force 14 May 2019) · Cabinet Resolution 32/2020 · Ministerial Resolution 51/2021
- Structure9 domains, 44 duties, each citing its article
- SanctionsArticle 25: notice, warning, AED 1,000–1,000,000 fine, Central System permit suspension or cancellation
What UAE ICT Health Law requires
Who it applies to
- Every UAE entity providing health services, health insurance or health IT
- Entities connected to Malaffi, NABIDH, Riayati or another Central System
- Cloud, analytics and support vendors handling UAE health data
- Medical tourism and telehealth providers relying on MR 51/2021 exceptions
Federal Law No. 2 of 2019 governs every use of information and communication technology in health fields in the UAE. It applies to every entity providing health services, health insurance or health IT, and to anyone who handles patient information. Its best-known provision, Article 13, prohibits storing, processing, generating or transferring health data outside the State except in cases the health authority approves — and Ministerial Resolution No. 51 of 2021 lists those ten cases with their conditions.
The Law also requires confidentiality and integrity of health data (Article 4), written consent for any use beyond health purposes (Article 16), a minimum 25-year retention from the last health procedure (Article 20), the ID number on every transaction (Article 21), and connection to and controlled access of the Central System (Articles 7, 8, 15). Cabinet Resolution No. 32 of 2020, the Executive Regulation, adds the conditions for circulating and storing data and for authorising Central System users. Article 25 sanctions range from a written notice to a fine of up to AED 1,000,000 and cancellation of the Central System permit.
GRCLens transcribes the obligations article by article from the official texts on uaelegislation.gov.ae and the Arabic original of MR 51/2021, distinguishing the Law, the Executive Regulation and the Ministerial Resolution in every code and reference. It is the legal layer beneath ADHICS in Abu Dhabi and the DHA and MOHAP standards elsewhere.
How GRCLens supports UAE ICT Health Law
UAE ICT Health Law runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Localisation, with its exceptions
Article 13 and all ten MR 51/2021 cases with their conditions — remote services, medical tourism, research, insurance, approved transfers — so an offshore cloud or support arrangement is assessed against the exception it actually relies on.
Three instruments, never confused
Codes distinguish the Law, the Executive Regulation (ER) and the Ministerial Resolution (R), and every reference names the instrument and article.
The 25-year rule
Retention runs from the last health procedure per patient. The retention indicator tracks the duties purge jobs, vendor exit terms and decommissioning plans most often break.
Arabic and English
The Arabic follows the official text's terminology, so legal, compliance and the health authority read the same words.
UAE ICT Health Law frequently asked questions
Is Ministerial Resolution 51/2021 the Law's Executive Regulation?
No. The Executive Regulation is Cabinet Resolution No. 32 of 2020. MR 51/2021 is MOHAP's instrument under Article 13 listing the cases in which health data may be stored or transferred outside the State. Both are in the catalogue and are coded separately.
Does this replace ADHICS or the DHA standards?
No. This is the federal legal duty; ADHICS (Abu Dhabi) and the DHA and MOHAP standards are how each authority requires it to be implemented. GRCLens carries them as separate frameworks so the legal register and the technical assessment stay distinct.
Can we host health data in a UAE region of a global cloud?
Article 13 concerns where the data is stored, processed and accessed, not who owns the data centre. In-country hosting with in-country support satisfies the rule; offshore backup, DR, analytics or remote support does not unless an MR 51/2021 case applies and its conditions are met.
One platform, many obligations

Talk to us about UAE ICT Health Law
Security Solution Consultants provides UAE health data law advisory alongside the platform, so you can combine tooling with hands-on expertise.