Guide

UAE PDPL & Your Website: Privacy, Cookies and Enquiry Forms

Signed documents on a desk — the kind of personal data a UAE website form collects

The UAE Personal Data Protection Law is not a reason to paste a 4,000-word GDPR template onto your site. It is a reason to stop collecting Emirates ID copies you never needed, to write a privacy page that matches what the form actually does, and to stop dropping five ad pixels before the visitor has said hello.

I am not your lawyer. If you process health data, children’s data, or run a large marketplace, get proper counsel. What I am is the person who builds the forms, the booking widgets and the WhatsApp buttons. Most PDPL pain I see on UAE sites is sloppy implementation, not a missing 40-page policy.

What a normal business site actually collects

A clinic, contractor or consultancy site typically picks up:

  • Name, mobile, email from an enquiry form
  • A WhatsApp pre-filled message (still a phone number plus intent)
  • Sometimes a file upload: trade licence, floor plan, lab result
  • Analytics: pages viewed, device, rough location
  • Marketing cookies if you run Meta or Google ads

That is personal data. Treat it like a client file, not like a lead list you dump into a shared Excel on someone’s laptop. If you needed a rebuild after a hack, read security and maintenance as well — a leaked enquiry inbox is both a trust problem and a legal one.

Forms: collect less, say more

Every extra field is a reason to abandon the form on mobile. It is also more data you must protect. For a first enquiry I usually ask: name, mobile, a one-line “what do you need?” Optional email. That is enough to reply on WhatsApp the same afternoon.

Do not ask for Emirates ID, passport or full address until you actually need it for a contract. Do not use an open file upload that accepts .exe. Do not email form contents to a personal Gmail with no access control.

On the form itself, one plain sentence is better than a fake tick-box: “We use this to reply about your project. We do not sell it.” Link the privacy page. Never pre-tick consent.

Planning notes and a laptop — mapping what a website form collects before it goes live
Write down what each field is for before you build the form. If you cannot explain a field, delete it.

Cookies: the banner that blocks your own leads

EU-style cookie walls got copied onto Dubai sites that only have a contact form and Google Analytics. The visitor has to play whack-a-mole before they can tap WhatsApp. That is a conversion tax you invented for yourself.

A practical split:

  • Essential: hosting session, security, form token. No theatre required.
  • Analytics: say so on the privacy page. Prefer a privacy-respecting setup; do not send extra identifiers you do not use.
  • Ads / remarketing: this is the one that deserves a real choice. If you retarget people around Dubai, tell them.

If the first thing on your homepage is a dark overlay, you have already failed the five-second homepage test.

WhatsApp is still data

Click-to-chat is how the UAE works. Keep it. Just do not pretend it is anonymous. Use a business number, decide who in the team sees new chats, and do not forward medical or legal attachments into a family group. Mention on the contact page that the conversation may continue on WhatsApp. That is honesty, not a scare notice.

The privacy page people will actually read

Write it in the same voice as the rest of the site. In English, and in Arabic if the site is bilingual. Cover:

  1. Who you are (trade name, city, email / phone)
  2. What you collect and why
  3. Who you share it with (hosting, email, payment, WhatsApp)
  4. How long you keep enquiries
  5. How someone asks you to delete or correct their details

If you copied a UK template that talks about the ICO and “our offices in London,” take it down. It tells a careful client you did not read your own legal page — the same amateur signal as a privacy policy that still says Copyright 2019.

Free-zone companies (DIFC, ADGM) can sit under different rules. Do not assume a mainland PDPL paragraph covers a DIFC entity. That is a lawyer question. My job is to make sure the website does not contradict whatever they draft.

Need forms, hosting and a privacy page that match how you actually work?

Talk through it on WhatsApp

What I implement on a typical ITZ build

HTTPS everywhere. Forms that go to a mailbox you control, not a random plugin account. No mystery scripts from abandoned chat tools. A short privacy page in your brand language. Cookie use that matches the ads you actually run. And a launch checklist that includes “delete the old test form that stored 200 fake leads.”

That is not legal advice. It is the difference between a site that looks grown-up and a site that collects too much, explains nothing, and then wonders why serious clients hesitate.

Frequently asked questions

Does a small UAE website need a privacy policy?

If you collect names, numbers or files, yes — a short honest page. A copied EU novel is worse than a clear half-page.

Do I need a cookie banner?

Not a blocking EU wall for essential cookies. If you run ad pixels, explain them and offer a real choice.

Is WhatsApp a PDPL issue?

It is personal data leaving the site. Use a business number, limit who sees chats, and say that enquiries may continue on WhatsApp.

I’ll build the form and the page so they match each other.

WhatsApp +971 52 486 7767
ITZ
ITZ Web Development

Freelance web design & development in the UAE with 10+ years of hands-on experience building fast, SEO-friendly sites that win customers.