Teliyadu OralOS

Dental data protection across Africa, the Middle East, and HIPAA

One practical starting point for dental clinics evaluating Teliyadu OralOS across different legal and operational environments. It brings the existing HIPAA, Ethiopia, Kenya, Uganda, Tanzania, and Rwanda resources together and adds selected official frameworks from other African and Middle Eastern markets.

This resource is not legal advice or a compliance determination. Laws, regulations, regulator guidance, health-sector rules, and enforcement practices change. Product safeguards do not make a clinic automatically compliant. Obtain a country-specific legal assessment and confirm Teliyadu availability, contracting, hosting, and configuration before processing patient data in any market.

Last reviewed 21 July 2026 · English source edition

Use this as a due-diligence map, not a legal shortcut

Different markets, different rules

Africa and the Middle East are not single legal markets. Countries can differ on health-data classification, patient consent, regulator registration, breach notification, record retention, government access, data localization, and cross-border transfers. Free zones and healthcare regulators can add another layer.

Availability is a separate question

A law appearing in this guide does not mean Teliyadu OralOS is commercially launched, legally approved, locally hosted, integrated with public systems, or ready for patient data in that country. Those decisions require a market and deployment review.

The official links below are starting points. Clinics should verify the current law, implementing regulations, regulator decisions, healthcare rules, and authoritative language version with qualified local counsel.

What Teliyadu OralOS currently provides

Tenant separation

Each clinic's tenant-owned records are separated in a dedicated PostgreSQL schema. This is a technical isolation control, not a country compliance certificate.

Role-based access

Clinic access is separated across the current Admin, Dentist, Receptionist, and Nurse roles. The clinic still has to assign and review access appropriately.

Auditability

Patient-record reads and financial mutations are audit-logged. Local law and clinic policy determine how logs must be reviewed and retained.

Encryption and backups

The platform uses encrypted transport, encrypted AWS storage, and automated database backups. These safeguards are only part of a complete privacy and security program.

Hosting location

Production infrastructure is hosted in AWS eu-central-1 (Frankfurt). Teliyadu does not claim local hosting or local data residency in African or Middle Eastern countries.

Per-clinic patient identity

Patient mobile identity is scoped to one clinic rather than shared across clinics. This does not remove a clinic's obligations for identity verification and patient rights.

These statements describe current technical architecture at a high level. They do not promise offline operation, local data residency, every language or currency, insurer integration, government integration, or regulatory approval. Read the security architecture overview for more context.

Clinic data-protection readiness checklist

  • Identify the legal entity operating the clinic and the people whose data will be processed.
  • Map patient, staff, billing, imaging, document, messaging, and audit data from collection through deletion.
  • Determine which party is the controller, processor, operator, responsible party, or equivalent under local law; contract wording must match the jurisdiction.
  • Document a lawful basis and any additional condition required for health, biometric, child, or other sensitive data.
  • Prepare clear privacy notices and a process for access, correction, objection, restriction, portability, or deletion where applicable.
  • Set legally supportable medical-record and financial-record retention schedules instead of using one global period.
  • Confirm regulator registration, notification, licensing, data-protection officer, impact-assessment, and record-keeping requirements.
  • Review incident response and every applicable regulator or patient breach-notification deadline.
  • Assess international transfers, remote support access, subprocessors, backup locations, and data-residency restrictions.
  • Check separate healthcare, professional secrecy, electronic-record, tax, insurance, employment, consumer, and telecommunications rules.

A clinic normally controls why patient records are created and used, while a software provider may process data on its behalf. Those roles and instructions must be confirmed in the applicable contract; terminology and responsibility vary by country.

HIPAA: when a U.S. framework enters the discussion

HIPAA is a United States framework; it is not an African or Middle Eastern regional law. It may still matter when a U.S. covered entity, business associate, patient-data flow, contract, or other regulated relationship is involved. HHS distinguishes covered entities from business associates and requires written business-associate arrangements in relevant relationships.

The Privacy Rule, Security Rule, and Breach Notification Rule address different parts of handling protected health information. Encryption, access controls, tenant isolation, backups, and audit trails can support a security program, but technical features alone do not establish HIPAA compliance.

Teliyadu-specific boundary: do not assume Teliyadu is acting as a HIPAA business associate or that a Business Associate Agreement is available for a deployment. Contracting, configuration, risk analysis, incident procedures, and the intended data flow must be confirmed with Teliyadu before regulated U.S. protected health information is entered into the service.

Africa: continental context and reviewed national frameworks

African Union context

The African Union Convention on Cyber Security and Personal Data Protection (often called the Malabo Convention) provides continental context. It does not replace each country's laws, ratification status, regulator rules, healthcare obligations, or transfer requirements.

Ethiopia

Personal Data Protection Proclamation No. 1321/2024

The Proclamation establishes a national framework for processing personal data, including sensitive personal data. A dental clinic should review its lawful basis, notices, patient-rights process, processor arrangements, security measures, retention, and any transfer of data outside Ethiopia.

Deployment check: Confirm the current regulator, registration or notification steps, rules for health data, and whether Frankfurt hosting requires a transfer assessment or authorization.

Kenya

Data Protection Act, 2019

Kenya's framework regulates controllers and processors, gives individuals data rights, and treats health information as sensitive personal data. The Office of the Data Protection Commissioner publishes health-sector and registration guidance.

Deployment check: Determine the clinic's registration duties, document the controller-processor relationship, and assess health-data and cross-border transfer requirements before rollout.

Uganda

Data Protection and Privacy Act, 2019

Uganda's Act regulates the collection, processing, use, and disclosure of personal data and sets responsibilities for data collectors, processors, and controllers. The Personal Data Protection Office oversees the framework.

Deployment check: Confirm registration, health-data handling, retention, breach response, and international transfer requirements with the PDPO or local counsel.

Tanzania

Personal Data Protection Act, 2022

The Act establishes data-protection principles, rights, controller and processor duties, and the Personal Data Protection Commission. Its application across Mainland Tanzania and Zanzibar includes qualifications that need local interpretation.

Deployment check: Verify registration, sensitive health-data conditions, patient-rights workflows, and transfer requirements for the clinic's exact location and operating model.

Rwanda

Law No. 058/2021 relating to the protection of personal data and privacy

Rwanda's law covers controllers and processors inside Rwanda and can also reach processing of data about people located in Rwanda. It expressly includes health status and medical records within sensitive personal data.

Deployment check: Review controller and processor registration, any data-protection officer requirement, breach duties, retention, and authorization for transfers or storage outside Rwanda.

Nigeria

Nigeria Data Protection Act, 2023

The Act created the Nigeria Data Protection Commission and regulates the processing of personal data. Clinics should treat patient records as high-risk information and examine the Act together with current Commission guidance.

Deployment check: Confirm whether the clinic or its vendors qualify for registration or additional obligations, and review lawful basis, impact assessment, processor, breach, and cross-border transfer requirements.

Ghana

Data Protection Act, 2012 (Act 843)

Ghana's Act is administered by the Data Protection Commission and establishes rules for organizations processing personal data and rights for individuals.

Deployment check: Check registration, treatment of medical information, security and retention duties, processor contracts, and any conditions on storing or accessing data abroad.

South Africa

Protection of Personal Information Act 4 of 2013 (POPIA)

POPIA sets conditions for lawful processing by public and private bodies and is overseen by South Africa's Information Regulator. Health information requires careful handling under the applicable special-personal-information rules.

Deployment check: Assess the responsible-party and operator relationship, information-officer duties, security-compromise response, health-data grounds, retention, and transborder data flows.

Morocco

Law No. 09-08 on personal-data processing

Law No. 09-08 regulates processing of personal data and established the CNDP. The CNDP publishes formalities for processing and transfers, and its primary materials are available in French and Arabic.

Deployment check: Obtain local advice on notification or authorization, sensitive medical data, patient notices, processor use, and transfers to infrastructure outside Morocco.

Egypt

Personal Data Protection Law No. 151 of 2020

Egypt has a national personal-data protection framework. Its current implementation, licensing, executive rules, and interaction with health-sector requirements should be checked at the time of deployment.

Deployment check: Confirm the competent authority's current procedures, licensing or permit requirements, treatment of health data, processor terms, and conditions for international hosting or access.

Middle East: reviewed national and special-zone frameworks

There is no single Middle Eastern data-protection regime. Federal laws, healthcare laws, free-zone rules, professional confidentiality, cybersecurity rules, and data-localization measures can overlap. Arabic may be the controlling legal text even where an English translation is published.

United Arab Emirates

Federal Decree-Law No. 45 of 2021 and health-sector rules

The UAE has a federal personal-data law, separate health-information legislation, and distinct regimes in financial free zones such as DIFC and ADGM. The applicable rules depend on the clinic, license, location, data, and processing activity.

Deployment check: Teliyadu's production infrastructure is in Frankfurt, not the UAE. Federal health-information rules include restrictions on storing or processing UAE health information abroad, so deployment must not proceed without confirming an applicable approval, exception, and configuration. DIFC or ADGM status does not automatically resolve health-sector rules.

Saudi Arabia

Personal Data Protection Law (PDPL) and implementing regulations

Saudi Arabia's PDPL regulates personal-data processing, including sensitive data, and is supplemented by implementing and transfer regulations and official guidance from SDAIA.

Deployment check: Review health-sector rules, lawful basis, privacy notices, records, processor contracts, breach duties, data-protection officer criteria, and the transfer regulation before using non-Saudi hosting.

Bahrain

Personal Data Protection Law No. 30 of 2018

Bahrain's law regulates personal-data processing and identifies health information as sensitive personal data. The Personal Data Protection Authority publishes the law and related decisions.

Deployment check: Confirm the lawful condition for medical data, notification or authorization steps, processor terms, patient rights, breach response, and any conditions for transfers outside Bahrain.

Oman

Personal Data Protection Law, Royal Decree 6/2022

Oman's Personal Data Protection Law is supplemented by executive regulations issued under Ministerial Decision 34/2024. Both should be read together for a current deployment assessment.

Deployment check: Verify the conditions for health data, consent or other grounds, controller and processor records, breach handling, data-subject requests, and transfer of data outside Oman.

Qatar

Personal Data Privacy Protection Law No. 13 of 2016

Qatar's law establishes a national personal-data privacy framework, with official guidance published for regulated entities and individuals. Sector-specific healthcare requirements may add obligations.

Deployment check: Confirm regulator expectations for sensitive health data, privacy notices, consent or other grounds, processors, direct marketing, breach management, and data hosted outside Qatar.

Jordan

Personal Data Protection Law No. 24 of 2023

Jordan's law took effect in 2024 and created a national framework administered through the Ministry of Digital Economy and Entrepreneurship's data-protection bodies.

Deployment check: Check current regulations, licensing or permit procedures, special rules for health data, processor terms, patient rights, and cross-border storage or access before launch.

All-market index for regional assessment

This index ensures the expansion review does not stop at the countries summarized above. It is a planning scope, not a list of launched or supported countries. Markets without a detailed summary require fresh country-specific legal assessment before a deployment decision. Regional groupings are for navigation and may differ from other geographic conventions.

Africa

North Africa

Algeria, Egypt, Libya, Morocco, Sudan, and Tunisia

West Africa

Benin, Burkina Faso, Cabo Verde, Côte d'Ivoire, The Gambia, Ghana, Guinea, Guinea-Bissau, Liberia, Mali, Mauritania, Niger, Nigeria, Senegal, Sierra Leone, and Togo

Central Africa

Angola, Cameroon, Central African Republic, Chad, Democratic Republic of the Congo, Equatorial Guinea, Gabon, Republic of the Congo, and São Tomé and Príncipe

East Africa

Burundi, Comoros, Djibouti, Eritrea, Ethiopia, Kenya, Madagascar, Malawi, Mauritius, Mozambique, Rwanda, Seychelles, Somalia, South Sudan, Tanzania, Uganda, Zambia, and Zimbabwe

Southern Africa

Botswana, Eswatini, Lesotho, Namibia, and South Africa

Middle East

Gulf markets

Bahrain, Kuwait, Oman, Qatar, Saudi Arabia, and the United Arab Emirates

Levant markets

Israel, Jordan, Lebanon, the Palestinian territories, and Syria

Other commonly included Middle Eastern markets

Egypt, Iran, Iraq, Turkey, and Yemen

Definitions of the Middle East vary. Egypt is included in both North Africa and the Middle East planning view. Cyprus is not included in this working market list; Turkey is included for expansion assessment. Neither choice states availability.

Before a clinic goes live in a new market

Bring a concrete deployment profile

Share the clinic country, legal entity, number of locations, intended users, patient-data categories, messaging and payment workflows, required integrations, retention needs, and any local-hosting requirement. Teliyadu can then confirm which product, contract, and configuration questions can be answered and which require local legal or regulatory advice.

No assumption of availability

Contact us to confirm market availability and configuration. A demo or discussion does not authorize processing patient data or establish compliance.

Discuss your market