UAE PDPL & Your Website: Privacy, Cookies and Enquiry Forms
The UAE Personal Data Protection Law is not a reason to paste a 4,000-word GDPR template onto your site. It is a reason to stop collecting Emirates ID copies you never needed, to write a privacy page that matches what the form actually does, and to stop dropping five ad pixels before the visitor has said hello.
I am not your lawyer. If you process health data, children’s data, or run a large marketplace, get proper counsel. What I am is the person who builds the forms, the booking widgets and the WhatsApp buttons. Most PDPL pain I see on UAE sites is sloppy implementation, not a missing 40-page policy.
What a normal business site actually collects
A clinic, contractor or consultancy site typically picks up:
- Name, mobile, email from an enquiry form
- A WhatsApp pre-filled message (still a phone number plus intent)
- Sometimes a file upload: trade licence, floor plan, lab result
- Analytics: pages viewed, device, rough location
- Marketing cookies if you run Meta or Google ads
That is personal data. Treat it like a client file, not like a lead list you dump into a shared Excel on someone’s laptop. If you needed a rebuild after a hack, read security and maintenance as well — a leaked enquiry inbox is both a trust problem and a legal one.
Forms: collect less, say more
Every extra field is a reason to abandon the form on mobile. It is also more data you must protect. For a first enquiry I usually ask: name, mobile, a one-line “what do you need?” Optional email. That is enough to reply on WhatsApp the same afternoon.
Do not ask for Emirates ID, passport or full address until you actually need it for a contract. Do not use an open file upload that accepts .exe. Do not email form contents to a personal Gmail with no access control.
On the form itself, one plain sentence is better than a fake tick-box: “We use this to reply about your project. We do not sell it.” Link the privacy page. Never pre-tick consent.
Cookies: the banner that blocks your own leads
EU-style cookie walls got copied onto Dubai sites that only have a contact form and Google Analytics. The visitor has to play whack-a-mole before they can tap WhatsApp. That is a conversion tax you invented for yourself.
A practical split:
- Essential: hosting session, security, form token. No theatre required.
- Analytics: say so on the privacy page. Prefer a privacy-respecting setup; do not send extra identifiers you do not use.
- Ads / remarketing: this is the one that deserves a real choice. If you retarget people around Dubai, tell them.
If the first thing on your homepage is a dark overlay, you have already failed the five-second homepage test.
WhatsApp is still data
Click-to-chat is how the UAE works. Keep it. Just do not pretend it is anonymous. Use a business number, decide who in the team sees new chats, and do not forward medical or legal attachments into a family group. Mention on the contact page that the conversation may continue on WhatsApp. That is honesty, not a scare notice.
The privacy page people will actually read
Write it in the same voice as the rest of the site. In English, and in Arabic if the site is bilingual. Cover:
- Who you are (trade name, city, email / phone)
- What you collect and why
- Who you share it with (hosting, email, payment, WhatsApp)
- How long you keep enquiries
- How someone asks you to delete or correct their details
If you copied a UK template that talks about the ICO and “our offices in London,” take it down. It tells a careful client you did not read your own legal page — the same amateur signal as a privacy policy that still says Copyright 2019.
Free-zone companies (DIFC, ADGM) can sit under different rules. Do not assume a mainland PDPL paragraph covers a DIFC entity. That is a lawyer question. My job is to make sure the website does not contradict whatever they draft.
Need forms, hosting and a privacy page that match how you actually work?
Talk through it on WhatsAppWhat I implement on a typical ITZ build
HTTPS everywhere. Forms that go to a mailbox you control, not a random plugin account. No mystery scripts from abandoned chat tools. A short privacy page in your brand language. Cookie use that matches the ads you actually run. And a launch checklist that includes “delete the old test form that stored 200 fake leads.”
That is not legal advice. It is the difference between a site that looks grown-up and a site that collects too much, explains nothing, and then wonders why serious clients hesitate.
Frequently asked questions
Does a small UAE website need a privacy policy?
If you collect names, numbers or files, yes — a short honest page. A copied EU novel is worse than a clear half-page.
Do I need a cookie banner?
Not a blocking EU wall for essential cookies. If you run ad pixels, explain them and offer a real choice.
Is WhatsApp a PDPL issue?
It is personal data leaving the site. Use a business number, limit who sees chats, and say that enquiries may continue on WhatsApp.
I’ll build the form and the page so they match each other.
WhatsApp +971 52 486 7767