UAE
The UAE's federal regulations on personal data do not provide for a separate list of jurisdictions with adequate protection. However, federal regulation provides for a caveat: under Article 28 of the UAE Personal Data Protection Law, the Council of Ministers was to adopt implementing regulations for the law; however, no such document has yet been issued. Therefore, even though the law took effect back in 2022, it is not actually being enforced, and companies are trying to use the regulations of other regions, including the GDPR, as a reference. At the same time, certain sector-specific regulations impose their own restrictions on cross-border data transfers and data localisation. For example, in banking and insurance, personal data may not be transferred as part of an outsourcing arrangement to a jurisdiction that does not provide a level of protection comparable to that of the UAE. For medical data, there is a specific list of cases in which the transfer or storage of data abroad is permitted.Separate regulations governing personal data are being actively developed and implemented in two free economic zones: the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM). The DIFC maintains a list of 50 jurisdictions with adequate protection, which includes European countries, the state of California, Canada, South Korea, Japan, the Qatar Financial Centre, and some others. At the ADGM, the list differs in some respects, as the regulator of this free economic zone recognises adequate protection of personal data in Israel, as well as in companies that have joined the EU-US Data Privacy Framework, but does not recognise Colombia, Singapore and California as jurisdictions with adequate protection. Russia is not included on the list of jurisdictions with adequate protection in either the DIFC or the ADGM. It is interesting to note that both freezones recognise each other as jurisdictions with adequate protection, but deny this status to the rest of the UAE. Accordingly, when auditing cross-border transfers of personal data, it is not enough to simply verify that the counterparty’s servers are located in the UAE; rather, it is important to confirm whether they are located in the DIFC or the ADGM.
Georgia
Article 38 of Georgia’s Law on the Protection of Personal Data provides for an official list of countries with adequate protection, which must be reviewed every three years or more frequently. The current list was approved on 14 April 2026 by Order No. 007 and includes 49 countries, including the EEA member states, North Macedonia, Bosnia and Herzegovina, Albania and Uruguay (Russia is not included on the list).A transfer to a country that is not on the list is permitted on other grounds, including the data subject’s written consent, the protection of the data subject’s vital interests, and the public interest. It is also possible to use a contract, which is a regional equivalent of Standard Contractual Clauses (SCC), but in that case, the cross-border transfer will need to be approved by the regulator. This ground implies an authorisation-based procedure, and the controller (operator) is prohibited from transferring data until an authorisation is obtained. Documents must be drawn up in Georgian, or a notarised translation must be attached to them. An application for authorisation to transfer data may be filed through a representative. During the procedure, the regulator may invite the controller to oral hearings, which may be held either in person or remotely. If the controller fails to appear at these hearings, the body will discontinue considering the application. The maximum approval period (including any extensions and excluding suspensions) must not exceed three months.
Uzbekistan
Uzbekistan's Personal Data Law provides for the creation of a list of states with adequate protection of personal data. It is approved by the Cabinet of Ministers pursuant to Article 271 of the Law. The up-to-date list (covering 49 jurisdictions) was approved by the Cabinet of Ministers in Resolution No. 415 of 29 July 2026. The list of jurisdictions with adequate protection that became effective on 3 August 2026, includes, for example, European countries, Russia, Singapore, Hong Kong and Brazil, while the UAE and Georgia are not included on the list. For the United States, Uzbekistan recognises transfers to companies participating in the EU-US Data Privacy Framework.If, however, the counterparty’s state is not included on the list of states ensuring adequate protection, local equivalents of the SCCs and BCRs (Binding Corporate Rules), the requirements for which must be approved by November 2026, or international standards may be used for processing personal data outside Uzbekistan. At the same time, Article 15 of the Law formally continues to authorise cross-border transfers to jurisdictions with inadequate protection, in particular, with the consent of the data subject.