Alsuwaidi & Company

UAE KYC Digital Platform: Key Requirements Under Cabinet Resolutions No. 55 and 56 of 2026

The UAE has introduced the operational and enforcement framework for its national “Know Your Customer” (KYC) Digital Platform. Cabinet Resolution No. 55 of 2026 issues the Executive Regulations of Federal Decree-Law No. 30 of 2024, while Cabinet Resolution No. 56 of 2026 establishes the related administrative violations and sanctions.

Together, the Resolutions regulate the collection, retention, protection, exchange and use of KYC data and reports under the oversight of the Central Bank of the UAE. They apply broadly to persons handling KYC data or issuing KYC Reports.

Consent and Access to KYC Reports

A User requesting a KYC Report must generally identify the Customer, state the purpose for obtaining the Report and provide evidence of the Customer’s consent. The Company operating the Platform must verify that consent before issuing the Report. A limited exception permits a Report concerning a person indebted to the User to be obtained without consent where the request is supported by an order issued by the judge of urgent matters.

Key Responsibilities

Data Providers must verify the source, validity, accuracy and currency of KYC data before submitting it to the Platform. They must maintain secure transmission systems and promptly address correction or update requests.

The Company must manage the Platform, maintain required electronic links, verify applicants, ensure Reports match the information received, retain requests for at least five years and assess Report quality and accuracy.

Users may use a KYC Report only for the stated purpose and must inform the Customer of that purpose. They must maintain confidentiality, comply with UAE data protection legislation and submit to compliance audits or reviews.

Data Localisation, Retention and Security

Users must not transfer KYC Reports or their data outside the UAE or share them with an overseas entity. This is particularly relevant to businesses using overseas compliance teams, shared-service centres or cross-border cloud environments.

KYC Reports must be retained for at least five years and provided to competent authorities upon request. After the purpose is fulfilled and the retention period expires, they must be securely disposed of. Any unlawful use must be reported immediately to the Company, competent authorities and the Customer.

KYC systems must support encryption, restricted access, logging, monitoring, periodic reviews, security audits, business continuity and incident handling.

AML Obligations Remain

The Platform is a compliance tool, not a substitute for existing AML/CFT duties. Regulated entities remain responsible for risk assessment, enhanced due diligence, ongoing monitoring and reporting.

Administrative Sanctions

Cabinet Resolution No. 56 of 2026 prescribes administrative fines generally ranging from AED 10,000 to AED 100,000 and permits the Central Bank to suspend dealings with a person or entity that commits a listed violation.

  • transferring KYC Reports or data outside the UAE: AED 100,000;
  • using a Report for a purpose other than that stated in the request: AED 100,000;
  • breaching confidentiality or improperly disclosing or using Report data: AED 100,000;
  • failing to retain Reports for at least five years: AED 50,000; and
  • refusing an audit or failing to comply with personal data protection requirements: AED 50,000.

Before imposing a sanction, the Central Bank may issue a written notice allowing up to thirty days to rectify the violation. Rectification does not automatically prevent a sanction. A grievance may be submitted within thirty days after notification of the sanction decision.

Practical Priorities for Businesses

Businesses should review consent and purpose-recording processes, data-localisation controls, retention and disposal procedures, data quality, cybersecurity, incident reporting, contracts, staff training and audit readiness.

Conclusion

The framework may improve customer verification but also imposes obligations concerning consent, purpose limitation, data localisation, accuracy, retention, security, audit and enforcement. Implementation should involve legal, compliance, privacy, cybersecurity and operational teams, not only IT.

For advice on preparing for the UAE’s KYC Digital Platform framework, please contact Suneer Kumar at suneer@alsuwaidi.ae, Vida Grace Serrano at vida@alsuwaidi.ae or Mamdouh Tawfik at m.tawfik@alsuwaidi.ae.