Article 11 of Ministerial Decision No. 243 of 2025 addresses storage: "Any Person subject to the Electronic Invoicing System shall store all Electronic Invoices, Electronic Credit Notes, and any associated data within the State in accordance with the timeline prescribed under the Tax Procedures Law." Two obligations: geographic — data within the UAE — and temporal — retained for the Tax Procedures Law period. Both have significant infrastructure and commercial consequences for businesses operating through cloud, shared service, or group treasury models.
The Data Residency Requirement
"Within the State" means within the UAE. Electronic Invoice data, Electronic Credit Note data, and any associated data must be stored in UAE territory. The Decision does not elaborate on what "within the State" means for cloud infrastructure — whether data centres physically located in the UAE satisfy the requirement where the cloud provider's architecture replicates data across multiple geographies. The UAE Electronic Invoicing Guidelines V1.1 do not resolve this question further at the time of writing.
For businesses operating on global cloud ERP platforms — SAP S/4HANA Cloud, Oracle Fusion Cloud, Microsoft Dynamics 365 — the default data residency settings of those platforms may not satisfy the Article 11 requirement without explicit configuration. Many global cloud deployments route UAE entity data through European or US-based data centres. Businesses on these platforms need to verify with their cloud ERP vendor whether UAE-specific data residency can be configured for the electronic invoicing data set, and whether that configuration carries a commercial cost or a contractual change.
For ASP-maintained archives — where the Accredited Service Provider holds a copy of all transmitted invoices — the ASP's data storage location is within scope of this requirement. ASP selection due diligence should explicitly confirm that the provider's archive infrastructure is located within the UAE. A Peppol-accredited ASP based entirely outside the UAE does not satisfy Article 11 for the storage obligation, even if it satisfies the accreditation requirement for the exchange and transmission functions.
The Tax Procedures Law Retention Period
Article 11 delegates the retention timeline to the Tax Procedures Law — specifically Federal Decree-Law No. 28 of 2022 and its Executive Regulation, Cabinet Decision No. 74 of 2023. Under Article 3 of Cabinet Decision No. 74 of 2023, the retention period for records supporting tax obligations is five years following the relevant Tax Period. For VAT Registrants, the Tax Period is the quarterly (or monthly) VAT return period. A VAT return for Q4 2027 has a retention period running to the end of Q4 2032.
The five-year baseline is extended in three circumstances: where a Tax Assessment is raised, where a voluntary disclosure is filed, or where a tax dispute is pending. In those cases, retention continues until the matter is finally resolved — which in complex disputes can extend the practical retention period significantly beyond five years. Businesses building their e-invoicing archive should design for a minimum five-year retention period with an extension mechanism that can hold specific documents beyond the standard window when triggered by a tax event.
"Associated Data" — What Else Must Be Stored
Article 11 covers not just the Electronic Invoices and Electronic Credit Notes themselves but "any associated data." The PINT-AE transmission process generates several categories of associated data beyond the invoice XML document itself: the transmission acknowledgement from the ASP, the processing confirmation from the Recipient's ASP, the UUID assigned to the document at transmission, the timestamp of the transmission event, and error messages or rejection notices where a document fails validation. All of this associated data is part of the documentary trail that establishes when an invoice was issued, whether it was successfully transmitted, and whether it was received and processed by the Recipient. Each of these data points may be relevant in an FTA audit or dispute. The Article 11 storage obligation covers this entire associated data set, not just the XML invoice payload.
Implications for Shared Service Centre Models
For corporate groups that process UAE entity transactions through a centralised shared service model — whether the centre is in the UAE or abroad — Article 11 creates a specific architectural requirement. Where the shared service model involves routing UAE invoice data through systems located outside the UAE, the data residency requirement is not satisfied. The shared service centre model does not remove the UAE data residency obligation from the UAE entity; it raises the question of how to satisfy that obligation while maintaining the economies of scale the shared service model provides.
Several architectural responses are possible: dedicated UAE-based storage for UAE electronic invoice data maintained alongside the shared service infrastructure; ASP-maintained UAE archives as the primary record, with the shared service system holding a non-primary copy; or migration of UAE entity processing to a UAE-based cloud instance of the ERP. None of these options is cost-free. The compliance implications of existing shared service models for UAE entities is one of the most substantive infrastructure decisions in the e-invoicing implementation programme for multinationals.
The Archive and the Audit Trail
Article 11 connects directly to Article 10. The FTA's access power under Article 10(1) covers data "processed, received and stored" under the Electronic Invoicing System. The Article 11 storage obligation ensures that the stored data the FTA can access is the full transaction record, not just the transmitted payload. An e-invoicing archive built to satisfy Article 11 is simultaneously the documentary foundation for responding to an FTA information request or audit under Article 10. The design of the archive — the data elements stored, the retention period, the geographic location, the accessibility and reproducibility on demand — is therefore a tax risk management decision as well as an infrastructure one.
