Digital Marketing Services

UAE PDPL and email marketing: consent, exceptions and your email platform

What Federal Decree by Law No. 45 of 2021 means for email marketing in Dubai and the UAE: whether it covers your business, when consent is needed, the rights subscribers hold, and what it says about platforms that store data abroad.

Hands in a pink sleeve typing on a silver laptop at a dark desk beside a potted plant

Under the UAE Personal Data Protection Law, the PDPL, Federal Decree by Law No. 45 of 2021, a business generally needs the subscriber’s consent to send marketing emails to a named person, and it must be able to prove that consent and let people withdraw it easily. The law’s exceptions, such as performing a contract, fit order and service emails far better than promotions.

Read together, these are the UAE PDPL rules that shape email marketing. The law does not cover everyone. Government data, certain health and banking data, and companies in free zones with their own data protection laws are excluded. For businesses it does cover, the law also brings rules on purpose, retention, subscriber rights and sending data to email platforms hosted outside the UAE. This guide reads those provisions as they apply to email marketing, as of September 2026.

Key points

  • The law reaches controllers inside the UAE and controllers abroad that process data of people in the UAE.
  • Free zone companies with their own data protection legislation, such as those in DIFC, are outside its scope.
  • Consent must be specific, clear and unambiguous, provable, and include an easy right to withdraw.
  • People can object to direct marketing at any time and ask for their data to be erased after withdrawing consent.
  • Using an overseas email platform is a cross border transfer, which the law allows only in listed cases.

This is a practical reading of the published English translation of the law as of 14 September 2026, not legal advice. The Arabic text prevails in any conflict. The law leaves many details to Executive Regulations, so take advice on your specific licence and data.

Does the UAE PDPL apply to your business?

Under the UAE PDPL, scope decides whether your email marketing needs consent at all. Article 2 sets the scope. The law applies to the processing of personal data, by automated or other means, relating to data subjects who reside or have a place of business in the UAE, by controllers or processors located in the UAE whether their data subjects are inside or outside the country, and by controllers or processors abroad that process the personal data of people inside the UAE.

The same article lists exclusions. For marketers the relevant ones are:

  • Free zones with their own law. Companies located in free zones that have special legislation on personal data protection are excluded. The UAE Government portal refers to the DIFC Data Protection Law No. 5 of 2020 as one such regime. A DIFC firm’s email marketing is governed by that law instead.
  • Health data with its own legislation. Personal health data covered by its own protection rules is excluded, which moves many clinic and hospital marketing questions into a separate framework.
  • Banking and credit data with its own legislation. Banks and finance companies should look first to the rules of their own regulator.

Not every free zone has its own data law, so a free zone licence alone does not settle the question. Check which regime covers your specific licence before building consent wording.

Article 3 lets the UAE Data Office exempt establishments that do not process a large volume of personal data from some or all requirements, under standards set by the Executive Regulations. Until such an exemption is confirmed for your business, do not plan around it.

Valid consent is where UAE PDPL email marketing rules bite hardest. The law’s definition of consent requires authorisation that shows in a specific, clear and unambiguous way that the person accepts the processing, through a clear positive statement or action. Article 6 then says consent only counts if three things are true: the controller can prove it, it was requested in a clear, simple, unambiguous and easily accessible way, in writing or electronically, and it includes the right to withdraw easily. Withdrawal does not make earlier processing unlawful.

Translated into a sign up form for a Dubai business, those words rule out several common designs:

Common designProblem under the PDPL wordingBetter approach
Marketing box already tickedNo positive action by the personUnticked box the person selects
Consent folded into accepting terms and conditionsNot specific to marketingA separate choice just for marketing emails
Wording such as “we may contact you with relevant information”Not clear or unambiguous about marketingName the brand and say it will send offers and news by email
Form in English only for an Arabic speaking audienceHard to show the request was clear and accessible to that personArabic and English versions of the form and the consent text
Unsubscribe only by writing to a postal addressWithdrawal is not easyA one click link in every email
No log of when or where the person signed upConsent cannot be provenTimestamp, source and consent wording stored in the platform

Article 4(5) of the Consumer Protection Law points the same way, listing among consumer rights the protection of their privacy and data and not using that data for promotion and marketing.

Article 4 exceptions and why they rarely fit promotions

UAE PDPL email marketing questions often start here. Article 4 prohibits processing personal data without consent and then lists cases excluded from that prohibition. Marketers often look for a way round consent in this list, so it is worth reading the two that are cited most.

Performing a contract. Article 4(9) covers processing necessary to perform a contract the person is party to, or to take steps they requested to enter, amend or end one. A receipt, a delivery update, a booking confirmation or a password reset fits. A newsletter with new arrivals does not, because the contract can be performed without it.

Data made public by the person. Article 4(2) covers personal data that has become available and known to all by an act of the data subject. It is sometimes used to justify collecting emails from LinkedIn profiles or company websites. The wording concerns the lawfulness of processing, but it does not remove the separate right to object to direct marketing under Article 17, nor the purpose limits in Article 5. Cold email programmes built on scraped addresses should be reviewed by a lawyer before launch.

Other exceptions, such as protecting the public interest, legal claims and health purposes, have little to do with ordinary marketing. The list also ends with “any other cases set out in the Executive Regulations”, which is one reason this area may change.

Purpose, data minimisation and retention

List hygiene for UAE PDPL email marketing runs on these controls. Article 5 sets processing controls that affect list building as much as consent does. Personal data must be collected for a specific and clear purpose and not processed later in a way that is incompatible with it, although the law allows processing for a purpose that is similar or close to the original one. Data must be limited to what is necessary, kept accurate and updated, and not kept after the purpose is exhausted unless it has been anonymised.

For email programmes this means:

  • Ask only for the fields you will use. A newsletter form rarely needs a date of birth or nationality.
  • Do not quietly move addresses collected for a warranty registration, a job application or a support ticket into a promotional list.
  • Remove or anonymise subscribers who withdrew consent and have no other relationship with you, rather than keeping them indefinitely.
  • Correct bounced and mistyped addresses, since Article 5 requires accuracy as well as security.

Article 7(4) also requires controllers to keep a record of personal data processing, covering categories of data, who can access it, processing purposes, cross border transfers and security measures, and to provide it to the Data Office on request. Your email programme should appear in that record.

Subscriber rights your UAE email marketing programme must support

UAE PDPL email marketing has to support these rights in the platform itself: the law gives data subjects several rights that turn into features in an email platform.

  • Information before processing. Article 13(2) requires the controller to tell the person, before processing starts, the purposes of processing, the sectors or establishments the data will be shared with inside and outside the UAE, and the protection measures for cross border processing. A privacy notice linked beside the sign up box is the usual way to do that.
  • Objecting to direct marketing. Article 17 lets the person object to and stop processing for direct marketing, including profiling related to it.
  • Erasure. Article 15 allows a request for erasure where consent is withdrawn, where the person objects, or where the data is no longer needed, subject to exceptions.
  • Correction and restriction. Articles 15 and 16 cover correcting inaccurate data and restricting processing while accuracy is checked.
  • Access and portability. Articles 13 and 14 allow requests for information on the data held and, where processing is based on consent and automated, for a machine readable copy.
  • A way to reach you. Article 19 requires clear and appropriate ways for people to contact the controller about their rights, and Article 24 lets them complain to the Data Office.

UAE PDPL email marketing programmes handle these differently. An objection and an erasure request are not the same thing. If you delete someone completely after they object, a later list import can add them back. Most platforms keep a suppression entry that stops future emails, and you should record why that entry exists.

Your UAE email marketing platform, processors and cross border transfers

This is where UAE PDPL email marketing meets vendor choice. Most email tools used in Dubai store data on servers outside the UAE. Under the law, the platform is usually a processor acting for you as controller. Article 7(5) requires controllers to appoint processors with sufficient safeguards to implement the technical and organisational measures the law demands, and Article 8 requires processors to act on the controller’s instructions and contracts that set out the scope, purpose and type of data.

Moving subscriber data abroad is cross border processing. Article 22 allows transfers to countries with personal data protection legislation that meets the law’s standards, or under relevant agreements the UAE has joined, in cases approved by the Data Office. Article 23 then lists alternatives where that level of protection is not available, including a contract binding the recipient to the law’s requirements and the person’s explicit consent to the transfer.

The practical steps are to read your platform’s data processing terms, note where subscriber data is stored, record the transfer in your processing record, and mention cross border processing in the privacy notice shown at sign up. Where the legal basis for a transfer is uncertain, take advice before migrating a large list to a new tool.

Executive Regulations and the timeline

UAE PDPL email marketing rules will keep evolving here. The law came into force on 2 January 2022. Article 28 asked for Executive Regulations within six months, and Article 29 gives controllers and processors six months from the issue of those regulations to regularise their position, a period the Cabinet may extend. When we searched the UAE Legislation portal on 14 September 2026 we did not find the Executive Regulations for this law listed. Several important details, including breach notification periods and the small business exemption standards, depend on them.

That gap is not a reason to wait on UAE PDPL email marketing basics. Consent that is specific, provable and easy to withdraw is required by the law’s own articles, and it is also what keeps complaint rates low and lists healthy. Businesses that build it now will have little to change when the regulations appear.

A consent audit of an existing list usually runs in this order:

  1. Confirm which data protection regime applies to your licence.
  2. Trace each segment of the list to its collection point and the wording shown at the time.
  3. Separate contacts with provable marketing consent from customers held only for orders or support.
  4. Pause promotional sends to segments without proof, and plan a clear permission request through a channel the law allows.
  5. Update forms, privacy notice and processing record, including the platform’s storage location.
  6. Set suppression and retention rules so withdrawn and inactive contacts are handled consistently.

How Digital Marketing Dubai can help

Our team works with UAE PDPL email marketing rules every day. We set up and run email marketing for businesses in Dubai and across the UAE, starting with consent capture and list hygiene, and our email copywriting team writes permission requests and campaigns in Arabic and English. Sign up forms and preference pages can be built into your site through website development, and web analytics measures what subscribers do after they click.

We are a marketing agency, not a law firm, so we work alongside your legal adviser on the points above. If WhatsApp or SMS is part of your programme, the same consent thinking applies; see our guide to promotional SMS rules in the UAE. Send a brief for a written fixed price proposal, usually within 45 minutes during business hours.

Straight answers

Frequently asked questions

Are business email addresses like sales@company.ae covered?

The law protects data relating to an identified or identifiable natural person. A generic role address that identifies no individual is less clearly personal data, while an address such as a named person's work email identifies that person. Many B2B lists mix both, so apply the same consent standard to the whole list unless you have advice otherwise.

Does the PDPL apply to an overseas company emailing people in Dubai?

Article 2 extends the law to controllers and processors outside the UAE that process the personal data of data subjects inside the country. A foreign brand that markets to UAE residents by email should assume the law is relevant to it, subject to its own legal advice.

Can we keep emailing customers who withdraw consent but still buy from us?

You can keep sending messages needed to perform their contract, such as receipts and delivery updates, because that is a separate ground under Article 4. Promotional emails based on consent must stop once consent is withdrawn, and the person can also object to direct marketing under Article 17.

Do we need a Data Protection Officer to run email campaigns?

Article 10 requires one where processing creates a high risk through new technology or data volume, involves systematic assessment of sensitive personal data including profiling, or covers a large volume of sensitive data. Most ordinary newsletter programmes do not fall into those categories, but health, finance and heavy profiling cases should be reviewed with an adviser.

Is double opt in required by UAE law?

The law does not name double opt in. It does require that you can prove consent, and a confirmation click that is logged with a timestamp is one practical way to build that proof, as well as a way to keep mistyped and fake addresses off your list.

Fixed price, in writing

Send your brief. Get a scope and a price within 45 minutes.

  • One fixed number, agreed in writing before work starts
  • No obligation, and no pressure to sign
  • English and Arabic work, with proper right to left layout
  • One team for design, marketing, web, media and copy

Get your fixed price quote

Written scope and price within 45 minutes in business hours. No obligation.

By sending this you agree to be contacted about your enquiry. Privacy policy

Keep reading

More articles for UAE businesses

All articles
Call WhatsApp Get a quote