/ Home / Blog / UAE data protection, plainly

You are collecting customer data. The UAE has a law about that now.

Every business that takes a name, a number, or an order is handling personal data, and the UAE now has a federal law about how that data is treated. It is not something only banks and hospitals need to think about. If you run a shop, a clinic, or a service and you keep customer details, this is about you, and it matters more once you start automating.

August 2026 ยท Marlow

What is the PDPL, in one paragraph?

The UAE Personal Data Protection Law, introduced as Federal Decree-Law No. 45 of 2021, is the country's general rule book for how businesses collect, use, store, and share the personal data of people in the UAE. It is overseen by the UAE Data Office, and enforcement has been getting more active, not less. The core idea is simple and reasonable: handle people's information with care, use it only for what you told them, keep it safe, and let them have a say over it. Everything else is detail built on that.

Does it really apply to my small business?

In most cases, yes. The law is about handling the personal data of people in the UAE, and it does not exempt you for being small. There are carve outs, for example government data and certain sectors, and businesses inside the DIFC and ADGM free zones follow their own separate data rules instead. But an ordinary mainland business keeping customer names, phone numbers, and order history sits squarely inside the general law. Being small changes how much you have to build, not whether the principles apply.

What does it actually ask you to do?

In plain terms: collect data with the person's awareness and for a clear purpose, use it only for that purpose, keep only what you genuinely need, store it securely, and be able to honour a request from someone to see or delete their information. That is the spirit of it. You do not need a legal department to respect those points, you need tidy habits: know what data you hold and why, do not keep old data you no longer use, protect access to it, and be able to answer a customer who asks what you have on them.

What changes when you add AI or a chatbot?

Automation moves data around faster and through more places, and that is exactly where care is needed. A chatbot that answers customers is collecting personal data. An automation that copies an order between systems is moving it. Anything that sends data to an outside tool is sharing it. So the questions become concrete: where does this information go, who can see it, is it protected on the way, and are we feeding sensitive details into a tool we should not be. A well built setup keeps a human in charge of anything sensitive and does not quietly pipe personal data somewhere it does not belong. A careless one can turn a helpful automation into a genuine risk.

How do you stay compliant without a legal department?

Start by writing down, in one page, what personal data you collect, why, where it lives, and who it is shared with. That single map answers most of the practical questions and shows you where the risk sits. Then apply common sense: least data, clear purpose, secure storage, and a way to handle deletion requests. When you automate, insist that whoever builds it can tell you exactly where data flows and can keep sensitive cases with a person. You do not need to become a privacy expert. You need to know what you hold, and to work with people who take it as seriously as you should.

This article is general information, not legal advice. Your obligations depend on your specific situation and can change as regulations develop. For guidance on your business, refer to the UAE Data Office or a qualified legal adviser.

Questions owners ask us

Do I need to appoint a Data Protection Officer?

Not every business does. A dedicated data protection officer is generally expected where processing is large scale or high risk, such as handling sensitive data at volume. A small business with ordinary customer records usually does not need a formal officer, but it does still need to follow the principles and keep its data in order.

Are DIFC and ADGM different?

Yes. The financial free zones DIFC and ADGM have their own data protection regimes that apply instead of the federal law for businesses established there. If you operate inside one of those zones, you follow their rules. Most mainland businesses fall under the federal PDPL.

Does this apply to WhatsApp messages and chatbots?

Yes. A phone number, a name, and the content of a conversation are personal data, whichever channel they arrive on. If you automate replies or store chat history, you are processing personal data and the same principles apply: clear purpose, security, and care with anything sensitive.

Adding automation and want it done without creating a data risk?

We build assistants and automations that keep a human in charge of sensitive cases and can tell you exactly where every piece of customer data goes. Tell us what you want to automate and we will show you how it handles data, in plain language you can actually check.

Start a conversation