Article 11 of Ministerial Decision No. 243 of 2025 establishes a storage obligation that is both specific and consequential for multinationals: all Electronic Invoices, Electronic Credit Notes, and associated data generated under the UAE Electronic Invoicing System must be stored within the UAE. The obligation is territorial, not just temporal. It does not say data must be retained for five years (though the Tax Procedures Law's retention requirement applies). It says the data must be held in the UAE. For organisations whose data architecture routes invoice data to servers in Frankfurt, London, Singapore, or Mumbai — which describes most multinationals with UAE operations — this obligation requires an explicit architecture decision before go-live.
The Legal Basis and What It Covers
Article 11 of MD 243 provides that the Issuer and Recipient are each obligated to store Electronic Invoices and Electronic Credit Notes, and the data associated with them, within the UAE. The scope of "associated data" extends beyond the invoice XML itself: it includes the schematron validation results, the transmission confirmation data from the ASP, the Corner 5 reporting acknowledgements, and the document metadata generated through the exchange process. The full electronic record of the invoice lifecycle — from generation through transmission through reporting — falls within the Article 11 scope.
The retention period is governed by the Tax Procedures Law, which requires taxpayer records to be retained for five years from the end of the relevant tax period. For electronic invoices, this means invoices issued from 1 January 2027 must be retained until at least 31 December 2031. Invoices generated during a voluntary implementation period before the mandatory date carry the same retention obligation from the date of generation.
Delegated Storage Through the ASP
Article 11 and Appendix 4 of the UAE E-Invoicing Guidelines V1.1 permit the storage obligation to be delegated to the appointed ASP. Where the ASP provides a delegated storage service — agreed in writing and subject to the conditions set out in Appendix 4 — the Issuer's or Recipient's obligation is fulfilled by the ASP maintaining the required data on its behalf within the UAE. The delegation does not transfer the legal responsibility for compliance — if the ASP fails to maintain the data or stores it outside the UAE, the compliance failure belongs to the business, not the ASP.
For this reason, the delegated storage arrangement must be documented in the ASP contract with explicit provisions: that the storage service covers all data within the Article 11 scope, that the storage occurs within UAE borders at all times, that the business retains the right to access and retrieve its stored data throughout the retention period, and that the ASP maintains the data for the full five-year period even if the business terminates its ASP relationship. The last point is critical — an ASP contract that allows the ASP to delete stored data upon contract termination creates a retention gap if the business switches ASP before the five-year period has elapsed.
What Delegated Storage Does Not Cover
The ASP's delegated storage service covers the electronic invoice data that flows through the ASP — the PINT-AE XML, the transmission records, and the Corner 5 reporting data. It does not automatically cover the invoice data held in the business's own ERP. Where the ERP stores UAE invoice data — as it necessarily does for AR and AP processing purposes — that ERP data is also within the Article 11 scope. If the ERP stores that data on servers outside the UAE (for example, in a European or Indian data centre), the business has an Article 11 compliance gap regardless of whether the ASP's delegated storage is in place.
This is the storage architecture challenge for multinationals: the ASP covers one copy of the data (the transmitted exchange copy), but the ERP holds another copy (the source record and the accounting record), and both copies must be stored within the UAE under Article 11. Where the ERP is a global cloud instance with data centres outside the UAE, the business must assess whether UAE invoice data can be directed to a UAE-based data centre or a UAE region within the cloud provider's infrastructure.
Cloud ERP and UAE Data Residency
For businesses running cloud ERP systems — SAP S/4HANA Cloud, Oracle Fusion Cloud, Microsoft Dynamics 365, or similar — the data residency architecture depends on the cloud provider's data centre locations and the business's contractual data residency settings. The major cloud ERP providers have UAE-based data centres (typically in Abu Dhabi or Dubai), and most provide data residency configuration options that direct data to a specified geographic region.
However, enabling UAE data residency for a specific tenant or entity within a global cloud ERP typically requires a contractual change and a technical configuration that the global IT function must execute. For multinationals managed from a UK or European headquarters, this change requires a governance decision at the global IT level — not just a local UAE team request. The UAE tax team must escalate the Article 11 requirement into the global IT and data governance processes well in advance of go-live, because the lead time for data residency configuration changes in enterprise cloud platforms is measured in months, not days.
On-Premise ERP With Central Data Centres
For businesses running on-premise ERP systems where the central servers are located outside the UAE — a common configuration for multinationals with centralised data centres in Europe or Asia — the Article 11 obligation requires a more fundamental architecture decision. Options include: routing UAE invoice data to a UAE-based server or storage layer that maintains the in-country copy, replicating UAE invoice data to a UAE-hosted storage environment with appropriate access controls, or migrating UAE entity data to UAE-based infrastructure. None of these options is trivial to implement, and all require engagement with the global IT architecture team.
Practitioner Insight: Article 11 is the obligation that most multinational IT functions are least prepared for, because it constrains their freedom to locate data based on cost, performance, or operational convenience. A European shared service centre that manages UAE entity invoices through a Frankfurt data centre is not compliant with Article 11 regardless of any other e-invoicing preparation steps it has taken. This is a board-level data governance decision with legal compliance implications, and it must be treated as such — not delegated to the UAE local IT team to resolve with a workaround.
The ASP Transition Storage Obligation
Where a business transitions from one ASP to another during the five-year retention period, the outgoing ASP's storage obligation for historical invoice data must be explicitly addressed. The Appendix 4 delegated storage conditions require that the storage arrangement survives ASP contract termination for the remainder of the retention period. In practice, this means either the outgoing ASP continues to hold the historical data under a reduced-service storage agreement after the primary contract ends, or the historical data is migrated to the new ASP's storage service before the transition is completed.
For Phase 1 businesses that are selecting their first ASP now, the storage transition provisions may seem remote. But the five-year retention period from 1 January 2027 runs to the end of 2031, and ASP relationships do not always remain stable over that period. Building the storage transition provisions into the initial ASP contract — before the relationship starts — is far easier than negotiating them when the business has already decided to change providers.
Practical Steps Before Go-Live
Before 1 January 2027, Phase 1 businesses should complete three storage-related governance tasks. The first is a data flow map that traces every copy of UAE electronic invoice data from generation through the ERP, through the ASP, through Corner 5 reporting, and through any analytics or reporting systems — and identifies the location of each data store. The second is a storage compliance assessment against Article 11 for each identified data store: is this copy of UAE invoice data held within the UAE? If not, what is the remediation path? The third is a review of the ASP contract against the Appendix 4 delegated storage conditions to confirm that the storage obligation is properly delegated, the data remains in the UAE, and the storage arrangement survives contract termination.
