Appendix 4 of the UAE Electronic Invoicing Guidelines V1.1 provides specific clarification on storage and retention obligations under Article 11 of Ministerial Decision No. 243 of 2025. It draws a distinction that matters in practice: the difference between the ASP's technical logging obligation and the business's legal obligation to retain the invoice document itself. Confusing the two leads either to over-reliance on ASP storage without adequate contractual protections, or to unnecessary duplication of retention architecture.
The Person's Obligation
Article 11 places the primary retention obligation on the Person subject to the Electronic Invoicing System. Any Person must retain all Electronic Invoices, Electronic Credit Notes, and associated data for the period defined in the Tax Procedures Law, and must ensure those records can be produced to the Authority on request. The obligation to produce records sits with the business regardless of how the storage is physically arranged.
The Appendix is clear that delegating storage to an ASP is permissible, but does not transfer this legal obligation. A contractual arrangement under which the ASP stores invoices on the business's behalf is operationally valid. However, if the ASP fails to retain the data, or if the ASP ceases operations, the legal liability for non-production remains with the business. Delegation is a convenience arrangement, not a liability transfer.
The ASP's Transactional Log Obligation
ASPs carry a separate and distinct logging obligation. They are required to retain transactional logs for each transaction — logs that are technically distinct from the invoice content. These logs must include unique transaction identifiers and cover the end-to-end cycle: transmission statuses, routing information, and confirmation events. The Appendix specifies that this technical transmission data forms part of the ASP's operational and compliance obligations under its Peppol Service Provider Agreement and the UAE Peppol Authority Specific Requirements (PASR). It does not constitute business document data that the Person is required to retain under Article 11.
The distinction matters when an enterprise is designing its records architecture. The ASP's logs are Peppol-level audit trails — they document that a message moved through the network from Corner 2 to Corner 5 (or Corner 3 to Corner 4) and that confirmations were received. They are not a substitute for the invoice document itself, and the retention period and access controls that apply to them are defined by the Peppol framework rather than the Tax Procedures Law.
Storage Location and Architecture
The Appendix resolves a question that frequently arises in ERP integration discussions: is there a requirement that invoice data be stored at a specific system layer — specifically at Corner 1 (the supplier's system) or Corner 4 (the buyer's system)? The answer is no. Any compliant storage arrangement is acceptable provided three conditions are met: the data is retained for the required period; data integrity and security are preserved; and the records can be made available to the Authority upon request.
This flexibility has architectural consequences. A business that routes all invoice data through its ASP and relies on ASP-managed cloud storage is not in breach of Article 11, provided the contractual arrangements with the ASP are explicit about retention obligations, the retention period covers the statutory requirement, and access for regulatory purposes is guaranteed. These are the three conditions that should appear in any ASP contract review or renewal.
Transmission Confirmation
ASPs are required to inform businesses, on an event-driven basis and without undue delay, that Electronic Invoices and Tax Data Documents have been successfully transmitted to the Authority. This is not just a customer service obligation — it is a compliance mechanism. A business that has sent data to its ASP cannot assume that data reached Corner 5 without receiving a confirmation event. The absence of a confirmation is itself a signal that requires action, and the governance model agreed between business and ASP before go-live should define the process for handling delayed or missing confirmations.
Read alongside the business's own retention obligation, the confirmation requirement means that a complete Article 11 compliance posture involves three elements: the invoice document retained for the statutory period; a contractual arrangement with the ASP specifying how and where it stores data on the business's behalf; and a record of transmission confirmations demonstrating that each invoice was successfully reported to Corner 5. The third element is what closes the gap between "we sent it" and "it was received and acknowledged."
