Ask a UAE agency which data protection rules govern its lead forms and WhatsApp campaigns and you often get a confident answer about the federal law. The reality is more uneven. The federal law exists but has no fines yet. The rules with teeth are the 2024 telemarketing regulations, the SMS policy and the financial free zones' own laws.
The federal law, and the gap
- Federal Decree-Law 45 of 2021 on Personal Data Protection came into force on 2 January 2022.
- Its executive regulations were due within six months. On 3 October 2026 the UAE legislation portal listed no regulations for it, and law firms including BSA and Ashurst say they are still pending.
- Businesses get six months from their issue to comply, extendable once, and the violations and penalties are left to a separate Cabinet decision that has not appeared. There are no PDPL fine amounts yet, whatever some blogs say.
- The UAE Data Office, the regulator named in the law, was merged into a new Artificial Intelligence and Data Authority announced in June 2026.
What the law says, for when it bites
- Consent must be specific, clear and unambiguous, given by a clear positive statement or action, provable and easy to withdraw.
- There is no legitimate interests basis. Processing without consent is allowed only in listed cases, such as performing a contract.
- People can object to direct marketing, including profiling for it.
- Processors act on the controller's instructions under a written contract that sets the scope, purpose and type of data, and keep a processing record.
- It applies to data on UAE residents, by controllers and processors inside or outside the UAE.
Penalties that already exist
The Cybercrime Decree-Law punishes collecting or processing residents' personal data in violation of the legislation in force with imprisonment and/or a fine of AED 50,000 to 500,000 (Article 13).
DIFC and ADGM
Companies in free zones with their own data protection laws sit outside the federal law. DIFC's Data Protection Law of 2020 caps listed contraventions at USD 100,000 each but allows a general fine beyond that, and its commissioner issued 717 preliminary and 273 decision notices in 2025. ADGM's regulations allow fines of up to USD 28 million.
WhatsApp, calls and SMS
Cabinet Resolution 56 of 2024, in force since 27 August 2024, regulates telemarketing, defined to include marketing text messages and marketing messages through social media apps. It applies to licensed companies, including those in free zones.
- Get prior approval from the competent authority, and use local numbers registered to your trade licence.
- Market only to consumers who came through your opt-in channel, and never to numbers on the national Do Not Call Register.
- Identify the company and the purpose at the start, and call only between 9am and 6pm.
- Do not disclose or trade consumer data without consent.
Fines under Cabinet Resolution 57 of 2024 rise with each offence: AED 75,000, 100,000 and 150,000 for operating without approval; AED 50,000, 75,000 and 150,000 for calling numbers on the register or trading consumer data; and AED 10,000, 25,000 and 50,000 for calling outside hours. For SMS, the TDRA's policy requires recorded opt-in consent, a free opt-out in every message, no marketing messages between 9pm and 7am, and a sender name starting with AD-.
What agencies should do now
- Record consent as if the federal law were fully in force: when, how and with what wording.
- Put a processing contract in place with each client whose leads you handle.
- For WhatsApp or SMS campaigns, check who holds the telemarketing approval and whose registered numbers are used. We could not confirm whether an agency sending for a client needs its own approval.
- Send only to people who opted in, and honour opt-outs immediately.
- For DIFC or ADGM clients, follow their own law.
Our guide to Saudi Arabia's data protection law covers the rules for campaigns across the border.



