WhatsApp and UAE data protection law: what a business message actually obliges you to do
A WhatsApp thread is personal data. The number identifies a person, the message body often carries far more, and the transcript lives in whatever system you connected. Federal Decree-Law No. 45 of 2021 has applied since 2 January 2022. This page sets out what that means for a business messaging customers in the UAE, in the order the decisions actually arise.
The short answer, in five lines
The short answer
You need a lawful basis before the first message, not after. Consent is the usual one for commercial messaging, and it has to be real rather than inferred from someone having your number.
People can ask you to correct or stop. The law gives a right to correction of inaccurate data and a right to restrict or stop processing. Your system has to be able to honour both.
Where the data goes is regulated. The law sets requirements for cross-border transfer. A model or a CRM hosted outside the UAE is a transfer.
Service and marketing are different purposes. Consumer protection law separately prohibits suppliers from using consumer data for marketing.
Free zones may differ. DIFC has its own regime, and health data carries an extra layer.
The instruments that apply
Federal Decree-Law No. 45 of 2021
The Personal Data Protection Law. In force since 2 January 2022. It covers the processing of personal data, in whole or in part, through electronic systems, inside or outside the country.
Processing requires the data subject's consent, except where it is necessary to protect a public interest or to carry out legal procedures and rights. Individuals may request correction of inaccurate personal data, and may request that processing be restricted or stopped. The law sets out requirements for cross-border transfer and sharing.
UAE Government portal, data protection laws, read 16 September 2026Federal Law No. 15 of 2020
Consumer Protection. Suppliers are prohibited from using consumer data for marketing purposes.
This is stricter than many businesses assume. A customer who messaged you about a delivery has not joined a marketing list by doing so.
UAE Government portal, consumer protection, read 16 September 2026Sectoral and free-zone regimes
DIFC Data Protection Law, DIFC Law No. 5 of 2020, for entities in that free zone. Federal Law No. 2 of 2019 on the use of information and communications technology in health fields, for anything clinical. Dubai Data Law (2015) for Dubai government data.
Check which applies to your licence before you design the data flow. It is much cheaper than rebuilding it.
UAE Government portal, data protection laws, read 16 September 2026What "personal data" covers in a WhatsApp thread
More than businesses expect, and the extra items are the ones that cause problems.
- The phone number
- An identifier on its own. Holding a list of numbers is processing.
- The display name
- Often a real name, supplied by the customer's own account.
- Message content
- Whatever they told you. Addresses, family details, symptoms, financial circumstances.
- Media
- Photographs and documents people send to explain a problem. Frequently the most sensitive item in the thread.
- Metadata
- Timestamps, read receipts, and the fact that a particular person contacted a particular business.
- Derived data
- Tags, scores and summaries your system attaches. Still personal data, and still correctable.
Getting consent that would survive being questioned
- Ask at the point of collectionOn the form, at the counter, in the booking flow. Not retrospectively by message.
- Say what for, specifically"Appointment reminders and service updates" is a purpose. "Marketing communications" is a different one, and needs its own tick.
- Record the evidence, not the intentionTimestamp, source, wording shown, and which boxes were ticked. Store it with the contact.
- Present it in the language of the conversationAn English-only consent shown to an Arabic-speaking customer is weak.
- Make withdrawal as easy as giving itA reply of STOP should work, and should take effect immediately.
- Re-check anything inheritedA list that came with an acquisition or from a third party is the highest-risk data you hold.
The rights you have to be able to honour
| Request | What it means operationally | What usually blocks it |
|---|---|---|
| Correct my data | Edit the stored record, including anything derived from it | A vendor system with no edit path, or data copied into three places |
| Stop processing | Suppress the contact across every send, immediately | Suppression that applies to one campaign tool but not the others |
| Restrict processing | Keep it, stop using it | Systems that only offer delete or nothing |
The practical test is not whether you would comply. It is whether you could, this week, without a developer. If the answer is no, that is the thing to fix before you scale sending.
Cross-border transfer, which almost everyone triggers
The law sets requirements for transferring personal data outside the country. Most WhatsApp automation stacks transfer something.
- The model. If the assistant runs on infrastructure outside the UAE, the message content goes there.
- The CRM. Most are hosted abroad.
- Analytics and logging. Often overlooked, and often the most complete copy of the conversation.
- Backups. A backup in another region is still a transfer.
We are describing where the question arises, not advising on how to satisfy it. The requirements are set out in the law and its executive regulations, and a business with significant volumes should take UAE legal advice rather than rely on a vendor's assurance.
Retention: decide it before you switch anything on
- Write down how long you keep a threadPick a period you can defend. "As long as the vendor keeps it" is not one.
- Separate the record from the conversationYou may need the booking for years and the chat for months.
- Delete the media firstPhotographs and documents are usually the most sensitive and the least needed.
- Apply it to every copyThe CRM, the analytics, the exports somebody made into a spreadsheet.
- Review it annuallyVolumes change, and so does what you are storing.
Who is responsible when you use a vendor
Most businesses do not build their own stack. They buy one, and then assume the obligation travels with the software. It does not.
- The business
- Decides why and how the data is processed. Answers to the customer, and to the regulator.
- The vendor
- Processes on your instructions. Their compliance is evidence, not a substitute for yours.
- The platform
- Meta operates the messaging channel under its own terms. That is a third relationship, not a replacement for either of the above.
- The model provider
- If the assistant sends message content to a model, that provider is in your data flow. Know who they are and where they run.
The uncomfortable version: a customer who is unhappy about what you did with their data will come to you, and "our supplier handles that" is not an answer they will accept.
Eight questions to ask before you sign
- Where is the data stored, by regionName the country. "The cloud" is not an answer.
- Which sub-processors touch the message contentIncluding the model provider, the analytics tool and any translation service.
- Can I edit a stored contact record myselfWithout a support ticket, and including derived fields.
- How does suppression work across every send pathOne switch, or one per tool.
- What is the retention default, and can I change itAsk for the number, not the policy page.
- How do I export everything about one personThen ask them to demonstrate it.
- What happens to the data if I leaveDeletion timetable, and proof.
- Who at your company can read my customers' messagesA real answer here tells you a lot about the rest.
These are procurement questions, not legal ones. A vendor who answers all eight crisply is not necessarily compliant, but a vendor who cannot answer them is telling you something useful.
Terms worth being precise about
- Personal data
- Data relating to an identified or identifiable person. A phone number qualifies on its own.
- Processing
- Almost anything you do with it: collecting, storing, using, sharing, deleting.
- Controller
- The party deciding why and how data is processed. For your customer conversations, you.
- Processor
- A party processing on the controller's instructions, such as a software vendor.
- Cross-border transfer
- Moving personal data outside the country, including by hosting it there.
- Purpose
- What you collected the data for. Consent attaches to a purpose, so a new purpose needs new consent.
- Retention period
- How long you keep it before deletion. A decision you make, not a setting you inherit.
The grey zone
Safe and effective
- Replying to a customer who messaged you first, about the thing they asked.
- Appointment reminders where the booking itself established the expectation.
- Storing a transcript with a stated retention period and a way to correct it.
Moves with a consequence
- Marketing to a service list. Consumer protection law addresses this directly.
- Uploading a customer list you did not collect yourself.
- Pasting customer messages into a general consumer assistant to draft a reply.
Borderline, and businesses do it anyway
- Treating an inbound enquiry as consent to market. Common, and it is exactly the conflation the consumer protection rule addresses.
- Keeping everything forever because storage is cheap. Cheap to store, expensive the day someone asks what you hold.
Frequently asked questions
Does UAE data protection law apply to WhatsApp messages?
Yes. Federal Decree-Law No. 45 of 2021 covers processing of personal data through electronic systems,
and a WhatsApp thread is personal data.
Do I need consent to message a customer on WhatsApp?
For business-initiated messaging, yes in practice. The law requires consent to process personal data
apart from narrow exceptions, and Meta separately requires opt-in for business-initiated messages.
Can I market to customers who contacted me for support?
Treat that as a separate purpose needing separate consent. Federal Law No. 15 of 2020 prohibits
suppliers from using consumer data for marketing purposes.
What if my CRM or AI model is hosted outside the UAE?
That is a cross-border transfer, and the law sets requirements for it. Establish where every copy of
the conversation lives before you scale.
How long can I keep WhatsApp conversations?
The law does not publish a number. Set a defensible period, write it down, and apply it to every copy
including backups and exports.
Does this apply if I am in DIFC or ADGM?
Those free zones have their own data protection regimes. DIFC operates under DIFC Law No. 5 of 2020.
Check which applies to your licence.
How we checked this, and what we could not settle
Checked: Federal Decree-Law No. 45 of 2021, Federal Law No. 15 of 2020, DIFC Law No. 5 of 2020 and Federal Law No. 2 of 2019, as summarised on the UAE Government portal and read on 16 September 2026. Meta's own documentation for opt-in and the customer service window.
Not settled: this page is commercial information, not legal advice. We have read the government summaries rather than litigated the executive regulations, and the detail of what satisfies the cross-border transfer requirement is exactly the kind of question that needs a UAE lawyer rather than a web page. We have not seen published enforcement decisions that would let us tell you where the practical threshold sits.
Want the messaging built so these questions have answers?
We build WhatsApp assistants with consent captured at the point of collection, purposes kept separate, a stated retention period, and an escalation path to a named human.
Sources
- LawUAE Government portal, data protection laws, Federal Decree-Law 45/2021, DIFC Law 5/2020, Federal Law 2/2019 on ICT in health, Dubai Data Law
- LawUAE Government portal, consumer protection, Federal Law 15/2020
- LawUAE Government portal, justice, safety and the law, legal framework overview
- PlatformMeta, Cloud API send-messages guide, the 24-hour customer service window and templates
- PlatformWhatsApp Business Messaging Policy, what business accounts may and may not do
- PlatformWhatsApp Business Solution Terms, platform terms
- RegulatorTDRA internet guidelines and permitted VoIP application list, read 16 September 2026
Written by Edmund Gay, Learnmind.ai, Dubai. This page is commercial information about a market we operate in, not legal advice. Regulation and vendor rates on this page carry the date we checked them, and both change.