Yunite with YuVerse00days00hrs00min00secRSVP
Talk to us
BlogBankingEducational GuideYuvoice

UAE PDPL: Consent Rules Every AI Calling Deployment Must Follow

Understand UAE PDPL consent rules for AI voice calling in banking: lawful bases, disclosure duties and DIFC/ADGM overlays. Deploy AI calling compliantly.

YT

YuVerse Team

Published August 15, 2026 · Updated August 20, 2026 · 9 min read

UAE PDPL: Consent Rules Every AI Calling Deployment Must Follow

The UAE PDPL — Federal Decree-Law 45/2021 — governs how a bank processes personal data when an AI voice agent places or receives a call. Before deploying AI calling, a lender must fix a lawful basis, disclose the AI processing, and honour data-subject rights alongside CBUAE consumer-protection conduct duties.


  • The law: UAE PDPL is Federal Decree-Law 45/2021, the federal personal-data protection framework administered by the UAE Data Office. Source: u.ae.
  • Consent is one basis, not the only one: processing may rest on consent or another lawful ground the law recognises; consent, where used, must be freely given and specific.
  • Conduct overlay: CBUAE Consumer Protection Regulation (Circular 8/2020) requires fair treatment, honest disclosure and no coercive collection pressure on calls.
  • Free-zone overlays: the DIFC (DFSA-regulated firms) applies DIFC Data Protection Law No. 5 of 2020; the ADGM applies its Data Protection Regulations 2021.
  • Automated decisions: DIFC DPL Article 10 sets specific rules where a decision is taken by autonomous or AI-based processing.

Voice calling in the UAE carries a data-protection profile that few other markets share. The customer base is majority-expatriate and multilingual, so a single AI calling campaign for a bank such as Emirates NBD or ADCB may switch between Arabic and English within one contact list, and personal data frequently crosses between an onshore mainland entity and a DIFC or ADGM booking centre. Salary-transfer lending ties a borrower's file to Wage Protection System (WPS) records and to an employer named on the residence visa, so the personal data an AI agent references on a collections or servicing call is unusually rich. That combination — cross-border data flows, sensitive financial context and a mobile expat population — is exactly why the UAE PDPL consent and disclosure rules deserve careful reading before any AI calling deployment goes live.


What is the UAE PDPL and who does it cover?

The UAE PDPL is Federal Decree-Law 45/2021, the country's federal personal-data protection law, overseen by the UAE Data Office. It applies to the processing of personal data of individuals inside the UAE, including by controllers and processors established in the UAE and, in defined circumstances, those outside it that process the data of people in the UAE.

For a bank running AI calling, three roles matter. The controller (the lender) decides why and how personal data is processed. The processor (often a technology vendor operating the voice platform) processes on the controller's instructions. The data subject is the customer being called. A licensed financial institution cannot outsource away its accountability: it remains the controller and must be able to demonstrate a lawful basis for every call.

The mainland PDPL does not apply inside the financial free zones, which run their own regimes — a distinction covered further below.


Not always — and this is the most common misconception. Consent is one lawful basis for processing personal data under the UAE PDPL, but the law recognises other grounds as well, such as processing necessary to perform a contract to which the data subject is a party, or to protect a legitimate interest, subject to conditions.

In practice, a servicing or collections call about a customer's own active loan will often rest on contractual necessity rather than fresh consent, because the processing is directly tied to the agreement the customer already signed. A purely promotional or cross-sell AI call to the same customer is a different matter and is far more likely to need consent — and to engage marketing and electronic-communications expectations set by the TDRA. The safe design rule is to separate the two purposes: never let a servicing call quietly become a marketing call without a basis for the second purpose.


Where consent is the chosen basis, it has to clear a bar. Under the UAE PDPL, consent should be a clear, freely given and specific indication of the data subject's agreement, the customer must be able to withdraw it as easily as it was given, and the controller must be able to prove it was obtained. Silence, pre-ticked boxes or consent bundled into unrelated terms do not meet the standard.

Requirement

What it means for an AI call

Weak practice to avoid

Freely given

The customer can decline without losing an unrelated service

Making a loan approval conditional on marketing consent

Specific

Consent names the actual purpose (e.g. collections vs promotions)

One blanket "we may contact you" clause

Informed

The customer is told who is calling and why before data is used

Starting the pitch before any disclosure

Withdrawable

Opt-out is offered on the call and is easy to action

Withdrawal buried in a portal the customer cannot reach

Demonstrable

The controller logs when, how and for what consent was captured

No auditable record tying consent to the call

For AI voice specifically, "informed" is the sharp edge: the customer should understand they are speaking with an automated system and what will happen to what they say.


What must an AI calling deployment disclose on the call?

Two rulebooks meet on a single call. The UAE PDPL drives transparency about the processing; the CBUAE Consumer Protection Regulation (Circular 8/2020) and its Standards drive conduct.

A defensible AI calling script for a UAE bank typically opens by identifying the institution and the reason for the call, makes clear that the customer is interacting with an automated agent, and gives a route to a human. It avoids coercive language on collections calls, does not disclose debt details to third parties, and respects reasonable contact hours. Where the call is recorded, the customer is told. Because the UAE weekend is Saturday–Sunday, calling-time policies should be built around the local working week rather than an imported calendar.

None of this is optional. The consumer-protection conduct rules and the PDPL transparency duties both bite on the same interaction, and the CBUAE's February 2026 guidance on the use of AI and machine learning by licensed financial institutions adds expectations on governance, explainability and human oversight.


How do the DIFC and ADGM change AI calling in the free zones?

If the customer relationship sits inside a financial free zone, a different data-protection law applies. Firms regulated in the DIFC follow DIFC Data Protection Law No. 5 of 2020; firms in the ADGM follow the ADGM Data Protection Regulations 2021. A group that books some customers onshore and some in a free zone may therefore run the same AI calling technology under two regimes at once.

Regime

Applies to

AI-relevant feature

UAE PDPL (Federal Decree-Law 45/2021)

Onshore/mainland processing

Consent standard, data-subject rights, cross-border transfer rules

DIFC DPL No. 5 of 2020

DIFC-based (DFSA-regulated) entities

Article 10 addresses autonomous/AI-based decision-making

ADGM Data Protection Regulations 2021

ADGM-based (FSRA-regulated) entities

Standalone consent, transparency and transfer requirements

The design implication is practical: map each contact list to the entity that owns the relationship, then apply that entity's regime. Do not assume one privacy notice covers all three.


Does an AI call trigger extra rules on automated decisions?

It can. Where a call feeds an automated decision that materially affects the customer — an AI-driven eligibility or collections-treatment decision, say — DIFC DPL Article 10 sets specific conditions for decisions based solely on autonomous or AI-based processing, and the CBUAE's 2026 AI/ML guidance reinforces human oversight and explainability. The safe pattern is to keep a human in the loop for consequential outcomes and to be able to explain, in plain terms, how the AI reached a result.


How AI helps: compliant voice at scale

Meeting these rules by hand across thousands of calls is where teams struggle — consistent disclosures, correct language selection, honest collections conduct and an auditable record of what was said and when. This is the practical case for a purpose-built voice platform. YuVoice runs Arabic and English AI voice agents that can deliver the same compliant opening on every call, capture and time-stamp consent and opt-outs, and hand off to a human when a customer asks — so a bank's disclosure and conduct policy is applied uniformly rather than left to script drift. The qualitative outcome banks care about: consistent, defensible calls at a volume manual teams cannot match, with the evidence trail regulators expect.


FAQ

Do I need consent to make an AI collections call in the UAE? Often the call rests on contractual necessity rather than fresh consent, because it concerns the customer's own active agreement. Consent is more likely to be required for promotional calls. Confirm the lawful basis for each purpose before dialling.

Does the UAE PDPL apply inside the DIFC and ADGM? No. The mainland UAE PDPL (Federal Decree-Law 45/2021) does not apply within the financial free zones. The DIFC applies its own Data Protection Law No. 5 of 2020 and the ADGM its Data Protection Regulations 2021.

Must I tell customers they are speaking to an AI agent? Transparency is central to the UAE PDPL and to CBUAE conduct expectations, so a defensible deployment makes clear the customer is interacting with an automated system and offers a route to a human.

Can a customer withdraw consent given on a call? Yes. Where processing rests on consent, it must be as easy to withdraw as to give, so an AI calling deployment should offer an opt-out on the call and action it reliably.

Which regulator oversees the UAE PDPL? The UAE PDPL is administered federally by the UAE Data Office. For banks, the CBUAE Consumer Protection Regulation adds conduct duties that apply on the same customer calls.

Does recording an AI call raise separate obligations? Recording is itself processing of personal data, so customers should be informed, the recording should serve a stated purpose, and retention should be limited — all consistent with UAE PDPL transparency principles.


Building AI calling for a UAE lender? Start with the compliance essentials on the YuVerse UAE hub.

This is a general explainer, not legal advice.

References

Stay Updated

Get the latest AI insights delivered to your inbox.

Product Brochure

A complete overview of YuVerse products, use cases, and capabilities.

Topics

UAE PDPL consentAI calling consent UAEFederal Decree-Law 45/2021PDPL AI voice agentsdata protection AI calling UAECBUAE consumer protection calling