UAE PDPL: Consent Rules Every AI Calling Deployment Must Follow
The UAE PDPL — Federal Decree-Law 45/2021 — governs how a bank processes personal data when an AI voice agent places or receives a call. Before deploying AI calling, a lender must fix a lawful basis, disclose the AI processing, and honour data-subject rights alongside CBUAE consumer-protection conduct duties.
- The law: UAE PDPL is Federal Decree-Law 45/2021, the federal personal-data protection framework administered by the UAE Data Office. Source: u.ae.
- Consent is one basis, not the only one: processing may rest on consent or another lawful ground the law recognises; consent, where used, must be freely given and specific.
- Conduct overlay: CBUAE Consumer Protection Regulation (Circular 8/2020) requires fair treatment, honest disclosure and no coercive collection pressure on calls.
- Free-zone overlays: the DIFC (DFSA-regulated firms) applies DIFC Data Protection Law No. 5 of 2020; the ADGM applies its Data Protection Regulations 2021.
- Automated decisions: DIFC DPL Article 10 sets specific rules where a decision is taken by autonomous or AI-based processing.
Voice calling in the UAE carries a data-protection profile that few other markets share. The customer base is majority-expatriate and multilingual, so a single AI calling campaign for a bank such as Emirates NBD or ADCB may switch between Arabic and English within one contact list, and personal data frequently crosses between an onshore mainland entity and a DIFC or ADGM booking centre. Salary-transfer lending ties a borrower's file to Wage Protection System (WPS) records and to an employer named on the residence visa, so the personal data an AI agent references on a collections or servicing call is unusually rich. That combination — cross-border data flows, sensitive financial context and a mobile expat population — is exactly why the UAE PDPL consent and disclosure rules deserve careful reading before any AI calling deployment goes live.
What is the UAE PDPL and who does it cover?
The UAE PDPL is Federal Decree-Law 45/2021, the country's federal personal-data protection law, overseen by the UAE Data Office. It applies to the processing of personal data of individuals inside the UAE, including by controllers and processors established in the UAE and, in defined circumstances, those outside it that process the data of people in the UAE.
For a bank running AI calling, three roles matter. The controller (the lender) decides why and how personal data is processed. The processor (often a technology vendor operating the voice platform) processes on the controller's instructions. The data subject is the customer being called. A licensed financial institution cannot outsource away its accountability: it remains the controller and must be able to demonstrate a lawful basis for every call.
The mainland PDPL does not apply inside the financial free zones, which run their own regimes — a distinction covered further below.
Does the UAE PDPL require consent for AI calling?
Not always — and this is the most common misconception. Consent is one lawful basis for processing personal data under the UAE PDPL, but the law recognises other grounds as well, such as processing necessary to perform a contract to which the data subject is a party, or to protect a legitimate interest, subject to conditions.
In practice, a servicing or collections call about a customer's own active loan will often rest on contractual necessity rather than fresh consent, because the processing is directly tied to the agreement the customer already signed. A purely promotional or cross-sell AI call to the same customer is a different matter and is far more likely to need consent — and to engage marketing and electronic-communications expectations set by the TDRA. The safe design rule is to separate the two purposes: never let a servicing call quietly become a marketing call without a basis for the second purpose.
What counts as valid consent under the UAE PDPL?
Where consent is the chosen basis, it has to clear a bar. Under the UAE PDPL, consent should be a clear, freely given and specific indication of the data subject's agreement, the customer must be able to withdraw it as easily as it was given, and the controller must be able to prove it was obtained. Silence, pre-ticked boxes or consent bundled into unrelated terms do not meet the standard.
Requirement | What it means for an AI call | Weak practice to avoid |
|---|---|---|
Freely given | The customer can decline without losing an unrelated service | Making a loan approval conditional on marketing consent |
Specific | Consent names the actual purpose (e.g. collections vs promotions) | One blanket "we may contact you" clause |
Informed | The customer is told who is calling and why before data is used | Starting the pitch before any disclosure |
Withdrawable | Opt-out is offered on the call and is easy to action | Withdrawal buried in a portal the customer cannot reach |
Demonstrable | The controller logs when, how and for what consent was captured | No auditable record tying consent to the call |
For AI voice specifically, "informed" is the sharp edge: the customer should understand they are speaking with an automated system and what will happen to what they say.
What must an AI calling deployment disclose on the call?
Two rulebooks meet on a single call. The UAE PDPL drives transparency about the processing; the CBUAE Consumer Protection Regulation (Circular 8/2020) and its Standards drive conduct.
A defensible AI calling script for a UAE bank typically opens by identifying the institution and the reason for the call, makes clear that the customer is interacting with an automated agent, and gives a route to a human. It avoids coercive language on collections calls, does not disclose debt details to third parties, and respects reasonable contact hours. Where the call is recorded, the customer is told. Because the UAE weekend is Saturday–Sunday, calling-time policies should be built around the local working week rather than an imported calendar.
None of this is optional. The consumer-protection conduct rules and the PDPL transparency duties both bite on the same interaction, and the CBUAE's February 2026 guidance on the use of AI and machine learning by licensed financial institutions adds expectations on governance, explainability and human oversight.
How do the DIFC and ADGM change AI calling in the free zones?
If the customer relationship sits inside a financial free zone, a different data-protection law applies. Firms regulated in the DIFC follow DIFC Data Protection Law No. 5 of 2020; firms in the ADGM follow the ADGM Data Protection Regulations 2021. A group that books some customers onshore and some in a free zone may therefore run the same AI calling technology under two regimes at once.
Regime | Applies to | AI-relevant feature |
|---|---|---|
UAE PDPL (Federal Decree-Law 45/2021) | Onshore/mainland processing | Consent standard, data-subject rights, cross-border transfer rules |
DIFC DPL No. 5 of 2020 | DIFC-based (DFSA-regulated) entities | Article 10 addresses autonomous/AI-based decision-making |
ADGM Data Protection Regulations 2021 | ADGM-based (FSRA-regulated) entities | Standalone consent, transparency and transfer requirements |
The design implication is practical: map each contact list to the entity that owns the relationship, then apply that entity's regime. Do not assume one privacy notice covers all three.
Does an AI call trigger extra rules on automated decisions?
It can. Where a call feeds an automated decision that materially affects the customer — an AI-driven eligibility or collections-treatment decision, say — DIFC DPL Article 10 sets specific conditions for decisions based solely on autonomous or AI-based processing, and the CBUAE's 2026 AI/ML guidance reinforces human oversight and explainability. The safe pattern is to keep a human in the loop for consequential outcomes and to be able to explain, in plain terms, how the AI reached a result.
How AI helps: compliant voice at scale
Meeting these rules by hand across thousands of calls is where teams struggle — consistent disclosures, correct language selection, honest collections conduct and an auditable record of what was said and when. This is the practical case for a purpose-built voice platform. YuVoice runs Arabic and English AI voice agents that can deliver the same compliant opening on every call, capture and time-stamp consent and opt-outs, and hand off to a human when a customer asks — so a bank's disclosure and conduct policy is applied uniformly rather than left to script drift. The qualitative outcome banks care about: consistent, defensible calls at a volume manual teams cannot match, with the evidence trail regulators expect.
FAQ
Do I need consent to make an AI collections call in the UAE? Often the call rests on contractual necessity rather than fresh consent, because it concerns the customer's own active agreement. Consent is more likely to be required for promotional calls. Confirm the lawful basis for each purpose before dialling.
Does the UAE PDPL apply inside the DIFC and ADGM? No. The mainland UAE PDPL (Federal Decree-Law 45/2021) does not apply within the financial free zones. The DIFC applies its own Data Protection Law No. 5 of 2020 and the ADGM its Data Protection Regulations 2021.
Must I tell customers they are speaking to an AI agent? Transparency is central to the UAE PDPL and to CBUAE conduct expectations, so a defensible deployment makes clear the customer is interacting with an automated system and offers a route to a human.
Can a customer withdraw consent given on a call? Yes. Where processing rests on consent, it must be as easy to withdraw as to give, so an AI calling deployment should offer an opt-out on the call and action it reliably.
Which regulator oversees the UAE PDPL? The UAE PDPL is administered federally by the UAE Data Office. For banks, the CBUAE Consumer Protection Regulation adds conduct duties that apply on the same customer calls.
Does recording an AI call raise separate obligations? Recording is itself processing of personal data, so customers should be informed, the recording should serve a stated purpose, and retention should be limited — all consistent with UAE PDPL transparency principles.
Building AI calling for a UAE lender? Start with the compliance essentials on the YuVerse UAE hub.
This is a general explainer, not legal advice.
References
- UAE Government — UAE Personal Data Protection Law (Federal Decree-Law 45/2021): https://u.ae/
- CBUAE Rulebook — Consumer Protection Regulation (Circular 8/2020): https://rulebook.centralbank.ae/en/rulebook/consumer-protection-regulation
- CBUAE Rulebook — Consumer Protection Standards: https://rulebook.centralbank.ae/en/rulebook/consumer-protection-standards
- CBUAE Rulebook (AI/ML guidance for licensed financial institutions): https://rulebook.centralbank.ae/
- DIFC — Data Protection Law No. 5 of 2020 (Article 10, autonomous decision-making): https://www.difc.com/