Last updated: Wednesday 16th September 2026

WhatsApp and UAE data protection law: what a business message actually obliges you to do

A WhatsApp thread is personal data. The number identifies a person, the message body often carries far more, and the transcript lives in whatever system you connected. Federal Decree-Law No. 45 of 2021 has applied since 2 January 2022. This page sets out what that means for a business messaging customers in the UAE, in the order the decisions actually arise.

The short answer, in five lines

The short answer

You need a lawful basis before the first message, not after. Consent is the usual one for commercial messaging, and it has to be real rather than inferred from someone having your number.

People can ask you to correct or stop. The law gives a right to correction of inaccurate data and a right to restrict or stop processing. Your system has to be able to honour both.

Where the data goes is regulated. The law sets requirements for cross-border transfer. A model or a CRM hosted outside the UAE is a transfer.

Service and marketing are different purposes. Consumer protection law separately prohibits suppliers from using consumer data for marketing.

Free zones may differ. DIFC has its own regime, and health data carries an extra layer.

The instruments that apply

Federal Decree-Law No. 45 of 2021

The Personal Data Protection Law. In force since 2 January 2022. It covers the processing of personal data, in whole or in part, through electronic systems, inside or outside the country.

Processing requires the data subject's consent, except where it is necessary to protect a public interest or to carry out legal procedures and rights. Individuals may request correction of inaccurate personal data, and may request that processing be restricted or stopped. The law sets out requirements for cross-border transfer and sharing.

UAE Government portal, data protection laws, read 16 September 2026

Federal Law No. 15 of 2020

Consumer Protection. Suppliers are prohibited from using consumer data for marketing purposes.

This is stricter than many businesses assume. A customer who messaged you about a delivery has not joined a marketing list by doing so.

UAE Government portal, consumer protection, read 16 September 2026

Sectoral and free-zone regimes

DIFC Data Protection Law, DIFC Law No. 5 of 2020, for entities in that free zone. Federal Law No. 2 of 2019 on the use of information and communications technology in health fields, for anything clinical. Dubai Data Law (2015) for Dubai government data.

Check which applies to your licence before you design the data flow. It is much cheaper than rebuilding it.

UAE Government portal, data protection laws, read 16 September 2026

What "personal data" covers in a WhatsApp thread

More than businesses expect, and the extra items are the ones that cause problems.

The phone number
An identifier on its own. Holding a list of numbers is processing.
The display name
Often a real name, supplied by the customer's own account.
Message content
Whatever they told you. Addresses, family details, symptoms, financial circumstances.
Media
Photographs and documents people send to explain a problem. Frequently the most sensitive item in the thread.
Metadata
Timestamps, read receipts, and the fact that a particular person contacted a particular business.
Derived data
Tags, scores and summaries your system attaches. Still personal data, and still correctable.

Getting consent that would survive being questioned

  1. Ask at the point of collectionOn the form, at the counter, in the booking flow. Not retrospectively by message.
  2. Say what for, specifically"Appointment reminders and service updates" is a purpose. "Marketing communications" is a different one, and needs its own tick.
  3. Record the evidence, not the intentionTimestamp, source, wording shown, and which boxes were ticked. Store it with the contact.
  4. Present it in the language of the conversationAn English-only consent shown to an Arabic-speaking customer is weak.
  5. Make withdrawal as easy as giving itA reply of STOP should work, and should take effect immediately.
  6. Re-check anything inheritedA list that came with an acquisition or from a third party is the highest-risk data you hold.

The rights you have to be able to honour

RequestWhat it means operationallyWhat usually blocks it
Correct my dataEdit the stored record, including anything derived from itA vendor system with no edit path, or data copied into three places
Stop processingSuppress the contact across every send, immediatelySuppression that applies to one campaign tool but not the others
Restrict processingKeep it, stop using itSystems that only offer delete or nothing

The practical test is not whether you would comply. It is whether you could, this week, without a developer. If the answer is no, that is the thing to fix before you scale sending.

Cross-border transfer, which almost everyone triggers

The law sets requirements for transferring personal data outside the country. Most WhatsApp automation stacks transfer something.

We are describing where the question arises, not advising on how to satisfy it. The requirements are set out in the law and its executive regulations, and a business with significant volumes should take UAE legal advice rather than rely on a vendor's assurance.

Retention: decide it before you switch anything on

  1. Write down how long you keep a threadPick a period you can defend. "As long as the vendor keeps it" is not one.
  2. Separate the record from the conversationYou may need the booking for years and the chat for months.
  3. Delete the media firstPhotographs and documents are usually the most sensitive and the least needed.
  4. Apply it to every copyThe CRM, the analytics, the exports somebody made into a spreadsheet.
  5. Review it annuallyVolumes change, and so does what you are storing.

Who is responsible when you use a vendor

Most businesses do not build their own stack. They buy one, and then assume the obligation travels with the software. It does not.

The business
Decides why and how the data is processed. Answers to the customer, and to the regulator.
The vendor
Processes on your instructions. Their compliance is evidence, not a substitute for yours.
The platform
Meta operates the messaging channel under its own terms. That is a third relationship, not a replacement for either of the above.
The model provider
If the assistant sends message content to a model, that provider is in your data flow. Know who they are and where they run.

The uncomfortable version: a customer who is unhappy about what you did with their data will come to you, and "our supplier handles that" is not an answer they will accept.

Eight questions to ask before you sign

  1. Where is the data stored, by regionName the country. "The cloud" is not an answer.
  2. Which sub-processors touch the message contentIncluding the model provider, the analytics tool and any translation service.
  3. Can I edit a stored contact record myselfWithout a support ticket, and including derived fields.
  4. How does suppression work across every send pathOne switch, or one per tool.
  5. What is the retention default, and can I change itAsk for the number, not the policy page.
  6. How do I export everything about one personThen ask them to demonstrate it.
  7. What happens to the data if I leaveDeletion timetable, and proof.
  8. Who at your company can read my customers' messagesA real answer here tells you a lot about the rest.

These are procurement questions, not legal ones. A vendor who answers all eight crisply is not necessarily compliant, but a vendor who cannot answer them is telling you something useful.

Terms worth being precise about

Personal data
Data relating to an identified or identifiable person. A phone number qualifies on its own.
Processing
Almost anything you do with it: collecting, storing, using, sharing, deleting.
Controller
The party deciding why and how data is processed. For your customer conversations, you.
Processor
A party processing on the controller's instructions, such as a software vendor.
Cross-border transfer
Moving personal data outside the country, including by hosting it there.
Purpose
What you collected the data for. Consent attaches to a purpose, so a new purpose needs new consent.
Retention period
How long you keep it before deletion. A decision you make, not a setting you inherit.

The grey zone

Safe and effective

Moves with a consequence

Borderline, and businesses do it anyway

Frequently asked questions

Does UAE data protection law apply to WhatsApp messages?
Yes. Federal Decree-Law No. 45 of 2021 covers processing of personal data through electronic systems, and a WhatsApp thread is personal data.

Do I need consent to message a customer on WhatsApp?
For business-initiated messaging, yes in practice. The law requires consent to process personal data apart from narrow exceptions, and Meta separately requires opt-in for business-initiated messages.

Can I market to customers who contacted me for support?
Treat that as a separate purpose needing separate consent. Federal Law No. 15 of 2020 prohibits suppliers from using consumer data for marketing purposes.

What if my CRM or AI model is hosted outside the UAE?
That is a cross-border transfer, and the law sets requirements for it. Establish where every copy of the conversation lives before you scale.

How long can I keep WhatsApp conversations?
The law does not publish a number. Set a defensible period, write it down, and apply it to every copy including backups and exports.

Does this apply if I am in DIFC or ADGM?
Those free zones have their own data protection regimes. DIFC operates under DIFC Law No. 5 of 2020. Check which applies to your licence.

How we checked this, and what we could not settle

Checked: Federal Decree-Law No. 45 of 2021, Federal Law No. 15 of 2020, DIFC Law No. 5 of 2020 and Federal Law No. 2 of 2019, as summarised on the UAE Government portal and read on 16 September 2026. Meta's own documentation for opt-in and the customer service window.

Not settled: this page is commercial information, not legal advice. We have read the government summaries rather than litigated the executive regulations, and the detail of what satisfies the cross-border transfer requirement is exactly the kind of question that needs a UAE lawyer rather than a web page. We have not seen published enforcement decisions that would let us tell you where the practical threshold sits.

Want the messaging built so these questions have answers?

We build WhatsApp assistants with consent captured at the point of collection, purposes kept separate, a stated retention period, and an escalation path to a named human.

Sources

Written by Edmund Gay, Learnmind.ai, Dubai. This page is commercial information about a market we operate in, not legal advice. Regulation and vendor rates on this page carry the date we checked them, and both change.