Middle East Privacy

How we meet health data and privacy law in the six Gulf states: where data is kept, the standards we follow, and the rights you have.

Last updated

01Who this page is for#

This page explains how Modulon Health meets health data and privacy law for clinics in the six Gulf states: the United Arab Emirates, Qatar, Saudi Arabia, Kuwait, Bahrain and Oman, and for their patients and staff. It adds to our Privacy Policy; where the two differ for people in the region, this page applies.

The clinic decides how its patients' information is used. Modulon handles it only on the clinic's instructions, under our Data Processing Agreement, which includes the regional terms described here.

02Where data is kept#

Clinic inData stored in
United Arab EmiratesDubai, UAE
QatarDoha, Qatar
Saudi ArabiaRiyadh, Saudi Arabia
KuwaitKuwait
BahrainDubai, UAE
OmanDubai, UAE

The UAE, Qatar, Saudi Arabia and Kuwait require health data to stay in the country, and it does. Bahrain and Oman allow it to be kept abroad with safeguards, so their clinics are hosted in the UAE under the transfer conditions their laws set, which our Data Processing Agreement includes.

AI processing runs where the data is kept, under agreements that forbid our providers from keeping the data or using it to train their models. The providers in each country are listed on our subprocessors page. Our team gives remote support only when a clinic asks, without copying data out of the country, and only as local law allows.

03United Arab Emirates#

Health data law

Health data in the UAE is governed by Federal Law No. 2 of 2019 on the Use of Information and Communication Technology in Health Fields and its implementing regulations. We meet its requirements as they apply to our role:

  • Health data is stored and processed inside the UAE, and leaves it only in the cases the law allows.
  • It is kept confidential, used only for the clinic's health services, and protected against unauthorized access, change or loss.
  • Every access and change is recorded, so the clinic can show who saw or did what, and when.
  • The law requires health records to be kept for at least 25 years. The clinic's medical record system remains the record, and when a clinic leaves Modulon we return its data before deleting anything, so the clinic can meet that duty.

Health authority standards

We align with the standards of the authority that licenses each clinic: the Department of Health Abu Dhabi's Healthcare Information and Cyber Security Standard (ADHICS), the Dubai Health Authority's policies on health information and on artificial intelligence, and the Ministry of Health and Prevention's requirements for the Northern Emirates. We help clinics meet their own obligations, including connections to health information exchanges such as Malaffi, NABIDH and Riayati.

Personal data law

Other personal data, such as clinic staff accounts and website enquiries, is protected under Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.

Free zones

For clinics established in a free zone with its own data protection law, we also meet the obligations it sets for processors: the DIFC Data Protection Law of 2020, including its rules on autonomous and AI systems; the Dubai Healthcare City Health Data Protection Regulation; and the ADGM Data Protection Regulations of 2021.

04Qatar#

Personal data law

Personal data in Qatar is protected by Law No. 13 of 2016 on the Protection of Personal Data Privacy, overseen by the National Data Privacy Office. Health information is personal data of a special nature under that law, and we protect it accordingly:

  • Health data is stored and processed in Qatar.
  • We process it only on the clinic's instructions, with the safeguards described on our Security page and the National Data Privacy Office's guidelines.
  • We give the clinic the information it needs for any permit or approval it requires to process personal data of a special nature.
  • We notify the clinic of a breach within 48 hours, so it can meet its own duty to notify the National Data Privacy Office and the people affected.

Health sector

We meet the requirements of the Ministry of Public Health that apply to our role, and support clinics in meeting theirs.

Qatar Financial Centre

For clinics established in the Qatar Financial Centre, we also meet the processor obligations of the QFC Data Protection Regulations of 2021.

05Saudi Arabia#

Personal data law

Personal data in Saudi Arabia is protected by the Personal Data Protection Law and its implementing regulations, overseen by the Saudi Data and AI Authority (SDAIA). Health data is sensitive data under that law, and we protect it accordingly:

  • Health data is stored and processed in the Kingdom.
  • It leaves the Kingdom only as the Regulation on Personal Data Transfer outside the Kingdom allows, and never for storage.
  • We notify the clinic of a breach within 48 hours, so it can notify SDAIA within the 72 hours the law sets, and the people affected where required.
  • We support the records of processing and impact assessments the law asks clinics to keep.

Health and cybersecurity rules

We meet the Ministry of Health's requirements and the National Health Information Center's standards that apply to our role, and the National Cybersecurity Authority's Essential Cybersecurity Controls and Cloud Cybersecurity Controls. Clinics can connect Modulon to NPHIES, the national insurance platform, for eligibility and claims.

06Kuwait#

Personal data in Kuwait is protected by the Data Privacy Protection Regulation issued by the Communication and Information Technology Regulatory Authority (CITRA). We meet it as a processor for the clinic:

  • Health data is stored and processed in Kuwait, as CITRA's Cloud Computing Regulatory Framework requires for data of its sensitivity.
  • We process it only on the clinic's instructions, with the consent and notices the clinic provides.
  • We notify the clinic of a breach within 48 hours, so it can notify CITRA and the people affected within the time the regulation sets.

We also meet the Ministry of Health's requirements that apply to our role.

07Bahrain#

Personal data in Bahrain is protected by Law No. 30 of 2018 on the Protection of Personal Data, overseen by the Personal Data Protection Authority. Health data is sensitive personal data under that law:

  • Data for clinics in Bahrain is kept in the UAE, which Bahrain's law allows with the safeguards and any authorization it requires. We provide the contract terms and information the clinic needs for that transfer.
  • We process health data only on the clinic's instructions, for the clinic's health services.
  • We notify the clinic of a breach within 48 hours.

We also meet the National Health Regulatory Authority's requirements that apply to our role.

08Oman#

Personal data in Oman is protected by the Personal Data Protection Law issued by Royal Decree No. 6 of 2022 and its executive regulations, overseen by the Ministry of Transport, Communications and Information Technology. Health data may be processed only with the ministry's permit:

  • The clinic holds the permit to process health data, and we give it the information it needs to obtain it.
  • Data for clinics in Oman is kept in the UAE, under the cross-border transfer conditions the executive regulations set.
  • We notify the clinic of a breach within 48 hours, so it can notify the ministry and the people affected.

We also meet the Ministry of Health's requirements that apply to our role.

09Calls, texts and recordings#

  • Calls and texts are carried by licensed telecommunications operators in the clinic's country, and texts are sent from the clinic's registered sender name.
  • Callers are told at the start that they are speaking with an automated assistant and that the call is recorded, and can ask for a person at any time.
  • The AI note taker records a visit only after the patient agrees. Visit audio is deleted once the provider signs the note, unless the clinic chooses to keep it.
  • Texts are about the patient's own care and account, respect the quiet hours the clinic sets, and stop when the patient asks.

10Arabic and English#

Patients can be served in Arabic or English, by phone, by text and on booking, intake and payment pages, which are laid out right to left in Arabic. Where we translate a legal document, the English text controls unless local law requires otherwise.

11AI in healthcare#

Our AI follows the principles set by the region's health authorities: it is transparent with patients about being automated, acts only within rules the clinic sets, leaves clinical decisions to licensed professionals, and keeps a record of every action and the rule that allowed it. Nothing clinical reaches a patient without a clinician's approval.

12Your rights#

Depending on the law that applies to you, you may have the right to know how your data is used, to get a copy of it, to have it corrected or erased, to object to or restrict its use, and to withdraw consent.

If you are a patient, make requests about your health information to your clinic; if you send them to us, we will pass them on within five business days and help the clinic respond. For anything else, write to hello@modulonhealth.com. You may also complain to the data protection authority in your country.

Questions about this page? Write to hello@modulonhealth.com.