Web Development

Cookie Consent and Privacy Pages for UAE Websites (2026): What the Law Actually Says

SKIMBOX Team

Most UAE cookie banners were copied from Europe and never configured. Here is what UAE law confirms, what it does not, and why an unconfigured banner is worse than none.

Cookie Consent and Privacy Pages for UAE Websites (2026): What the Law Actually Says

Last updated: August 2026

Two things are true about most UAE business websites. There is a privacy policy that was copied from another site, sometimes with the original company name still buried in the third paragraph. And there is a cookie banner that somebody installed from a plugin directory and never configured, so the reject button does nothing at all.

Both come from the same mistake, and it is the most common mistake on this whole topic. Businesses import European practice and treat it as though it were UAE law. It is not. The UAE is not the EU, and the rules here are genuinely different in ways that matter for what you build.

This guide sets out what UAE sources actually confirm, what they do not, and what to do about the gap. We build websites, so this is written from the engineering side of the problem. We are not lawyers, and nothing here is legal advice. The wording of your policies is work for a qualified legal adviser.

The finding most articles get wrong

We went looking for a UAE cookie rule. Across the federal government portal, the DIFC Commissioner of Data Protection's own published guidance, and ADGM's data protection material, no UAE, DIFC or ADGM official source names cookies as a specifically regulated category [1][3][4]. We found no UAE equivalent of the European rule requiring prior consent before a non-essential cookie is set.

That is a finding, and it needs stating carefully. It is an absence of confirmation, not a permission slip. Two very different things.

What does exist is the general consent principle. The Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, has been in force since 2 January 2022 and applies to the processing of personal data, in full or in part, through electronic systems, inside or outside the country [1]. The government summary states the law prohibits processing personal data without the consent of its owner, except in some cases where processing is necessary to protect a public interest or to carry out legal procedures and rights [1].

Follow that through. A cookie that stores an IP address or a device identifier is processing personal data through an electronic system. So the consent principle reaches it, the same way it reaches a signup form. The obligation, where you have one, comes from the general rule about personal data. It does not come from a cookie-specific statute, because we could not find one.

What that does and does not mean for you

It means you can stop treating the European banner pattern as a legal requirement here. The pattern where nothing fires until a visitor clicks, the granular category toggles, the twelve month re-consent cycle: that is a European design solving a European rule.

It does not mean you can run whatever tracking you like. The consent principle still applies to the personal data your site collects. It also does not mean the question is settled forever. The PDPL's Executive Regulations have not been published, and detail that is currently open could close later.

And it does not mean nothing is enforceable today. Federal Law No. 15 of 2020 on Consumer Protection, as amended by Federal Decree-Law No. 5 of 2023, already requires suppliers to protect consumer privacy and data security and to refrain from using consumer data for promotional and marketing purposes without a proper basis [2]. That same law requires e-commerce sellers to disclose their licensing entity, Arabic language product and contract information, specifications, payment terms and warranty terms [2]. The official summary describes penalties reaching up to two million dirhams and imprisonment of up to two years for certain offences [2]. That is a published schedule with real numbers attached, which is more than the federal PDPL currently has.

Real talk: the law that is most likely to cause you a problem this year is consumer protection, not cookies. Most businesses have this backwards.

The banner that blocks nothing

This is the part worth your attention, because it is where we find the most damage on real sites.

A cookie banner does not control your tracking scripts. It is a piece of interface. Something has to connect the visitor's click to the tools that actually collect data, and on most sites nobody ever did that work.

Google says this outright in its own documentation. Consent mode does not provide a consent banner or widget, and instead interacts with your banner to obtain visitor consent [6]. Google also states that the site owner, not Google, is responsible for obtaining users' consent [5]. Consent mode governs distinct signals covering ad storage, analytics storage, ad personalisation and ad user data [5]. In basic mode, a denied consent blocks the tags and no data reaches Google at all. In advanced mode, tags still load with defaults set to denied and send cookieless pings carrying a timestamp, browser details, referrer and the consent state, used for statistical modelling [6].

None of that happens automatically because a banner exists. It happens because a developer wired the banner's events into consent mode.

Meta is the same story from a different angle. Meta's developer documentation describes what the pixel collects by default: HTTP header data including IP address, browser information, page location and referrer, plus the pixel ID and the Facebook cookie, button click data, and form field names, with field values excluded unless the site owner opts into advanced matching [7]. That is a defined set of data collected as standard. Nothing in that documentation gates it behind a consent banner. Gating it is the site owner's job.

So here is the honest position. A banner that was installed and never configured does not satisfy any confirmed UAE requirement, because we could not confirm one exists. And it displays a working control to your visitors that does not work. Anyone who opens their browser tools after clicking reject can see the same requests firing.

That reasoning is practical, not legal. We are not saying an unconfigured banner breaks a UAE law. We are saying it is the worst of both worlds: no legal benefit, and a visible false claim about what your site does. No banner at all is at least honest.

Why the copied European policy fails here

The copied policy fails for a structural reason, not a cosmetic one.

European policies are built around a set of legal bases that lets a business justify processing without consent in many situations. UAE law is written the other way around, prohibiting processing without consent except in named cases [1]. A policy whose justification section is built on the European model is explaining the wrong thing.

Then there are the rights. The official government summary of the PDPL confirms two rights by name: the right to request corrections of inaccurate personal data, and the right to restrict or stop processing [1]. Those two we will state. A right to receive a copy of your own data could not be confirmed on that official page, so we are not going to claim it. That is not a statement that the right does not exist somewhere in the full statute. It is a statement about what we could verify. Take the complete rights list to a qualified legal adviser and to the full text on the official legislation portal before you publish a list of your own [9].

DIFC is a useful contrast here, and a common source of confusion. DIFC's own law does explicitly confirm a right to obtain a copy of the data held about a person, alongside rectification, erasure, objection, restriction and portability [3]. But DIFC is a separate regime. It applies to DIFC establishments, meaning entities established, licensed, registered or authorised to operate or conduct activity within or through the DIFC [3]. If your licence is not in DIFC, DIFC's rights list is not your rights list, and copying it into your policy promises visitors something UAE federal law has not been confirmed to give them.

Finally, a copied policy names the wrong regulator, points visitors at a complaints route that does not exist for them, and describes data flows that belong to somebody else's business. That last one is the reason to write your own. The policy should describe what your site actually does, which means somebody has to find out.

Which law applies to you

Three routes, and your licence decides.

  • Mainland or a standard free zone such as DMCC, JAFZA, IFZA or Dubai Internet City: the federal PDPL [1].
  • DIFC: DIFC Law No. 5 of 2020, with its own Commissioner of Data Protection [3].
  • ADGM: the ADGM Data Protection Regulations 2021, which replaced the 2015 regulations and established an independent Office of Data Protection headed by a Commissioner. ADGM states the regulations apply to entities established in ADGM that process personal data, or that process in the context of the activities of an ADGM establishment [4].

Both DIFC and ADGM publish their own penalty structures, which is a real difference from the federal position where the schedule is still pending. We are not printing specific figures for either zone here, because we could not re-verify current numbers directly with those authorities this time and these schedules get revised. If you are licensed in either zone, get the current figures from the relevant authority.

On the federal side, two things stay true. The PDPL uses the word immediately for breach notification rather than a number of hours, and the Executive Regulations that would fix a precise deadline are still pending [10]. And no federal fine schedule has been published, so any dirham figure you see quoted for a federal PDPL breach is somebody's estimate [10]. Our PDPL compliance guide goes through the regulator, the Executive Regulations and the compliance window in detail.

When European law actually reaches you

This one gets sold hard to UAE small businesses, so it is worth being precise.

The GDPR describes its own territorial reach in Article 3. It applies to a controller or processor not established in the EU where the processing relates to offering goods or services to people who are in the EU, or to monitoring their behaviour so far as that behaviour takes place within the Union [8]. That is EU law describing how far it reaches. It is not something UAE law does to you.

So when are you genuinely in scope? If you price in euros, ship to EU addresses, translate for EU markets, or run advertising tracking against visitors who are physically in the EU, the trigger is live and you should take advice.

When are you not? A Dubai dental clinic with an all-UAE patient base, dirham pricing and no EU targeting is not in scope because three people in Berlin found the site through search. Traffic alone is not the test. Plenty of UAE businesses are sold a GDPR programme they do not need, usually by someone selling the programme.

A sensible order of work

If you are starting from a copied policy and a dead banner, do it in this order.

  1. Inventory what actually runs. Open your site and list every tag, pixel and script. Most teams find tools nobody remembers adding, still firing.
  2. Decide what you actually need. The cheapest privacy fix is removing a tool you stopped using two years ago.
  3. Wire the consent mechanism properly, or remove it. Either connect the banner to consent mode and to your other tags, or take it off the site. A decorative banner is the one option with no upside.
  4. Write the privacy notice around reality. What you collect, why, who sees it, how long you keep it, and how someone asks you to correct or restrict their data.
  5. Get the wording reviewed by a qualified legal adviser. This step is not optional and it is not ours to do.
  6. Check the consumer-facing pages if you sell online. Licensing entity, Arabic contract information, payment and warranty terms [2]. Our e-commerce build guide and VAT-compliant e-commerce guide cover the commercial side, and the Saudi selling guide covers what changes across that border.

Real client stories

Situations from our own work. Details changed for privacy.

A Dubai retail brand with a banner that blocked nothing. The site had a full consent banner with category toggles, installed by a previous agency. We clicked reject and watched the network tab. Every analytics and advertising request fired exactly as before, because the banner had never been connected to anything [5][6]. The founder's reaction was the useful part. He had assumed the banner was the compliance work, and had never checked. We disconnected the unused tools, wired the rest properly, and the banner finally meant something.

A mainland clinic sold a GDPR programme. An all-UAE patient base, dirham pricing, no EU marketing, and a proposal to build a GDPR compliance programme because the site had European visitors. Read against Article 3, offering goods or services to people in the EU or monitoring their behaviour there, the clinic did not meet the trigger [8]. We told them so and pointed the budget at the federal PDPL work that did apply to them.

A free zone SaaS company using someone else's policy. The privacy policy promised a right to download a copy of all personal data. Nobody had built that, and the right was not one we could confirm on the official government summary of the federal PDPL [1]. It had been inherited from a European template. The policy was promising a feature the product did not have, under a law that had not been checked. That is a support ticket and an awkward conversation waiting to happen.

How SKIMBOX approaches this

We handle the engineering half of this problem, and we are clear about where our half ends.

That means auditing what your site actually loads, removing tools you no longer use, wiring consent controls into the tags they are supposed to control so a reject click does something real, and building the pages themselves. If you are rebuilding anyway, our website cost guide sets out what a focused business site costs, starting from around AED 3,500 [10]. Final pricing depends on scope.

The related work usually sits nearby. Sites that depend on tracking for conversion measurement need landing page and CRO work that survives a properly configured consent setup. Businesses reporting on customer data across systems should read our analytics and BI guide. Anything with a customer login and stored records is closer to a web portal build than a brochure site, and the data questions get heavier accordingly.

What we do not do is write your legal wording or tell you what your policy must say. We are not lawyers and this article is not legal advice. Take the drafting to a qualified adviser, and take the current penalty figures for your zone to the authority that publishes them.

If you want the technical side looked at properly, see our web development services or our business consulting services, or contact us.

References

[1] The UAE Government Portal - Data protection laws, Federal Decree-Law No. 45 of 2021, scope, the consent requirement, and the rights to rectification and to restrict processing. u.ae [2] The UAE Government Portal - Consumer protection, Federal Law No. 15 of 2020 as amended by Federal Decree-Law No. 5 of 2023, supplier duties on consumer data, e-commerce disclosure requirements, and penalties. u.ae [3] DIFC Commissioner of Data Protection - Overview of DIFC Data Protection Law and Regulations, covering DIFC Law No. 5 of 2020, the definition of DIFC establishments, and the data subject rights list. difc.com [4] ADGM - Data Protection Regulations 2021 announcement and Office of Data Protection guidance, covering the new regulations, the Commissioner, and scope. adgm.com [5] Google for Developers - Consent mode overview, the consent signals it governs, and the statement that the site owner is responsible for obtaining consent. developers.google.com [6] Google Ads Help - About consent mode, confirming that consent mode does not provide a banner, and the difference between basic and advanced behaviour when consent is denied. support.google.com [7] Meta for Developers - Meta Pixel documentation, covering the data the pixel collects by default and the advanced matching opt-in. developers.facebook.com [8] EUR-Lex - Regulation (EU) 2016/679, Article 3, on territorial scope for controllers and processors not established in the European Union. eur-lex.europa.eu [9] UAE Legislation Portal - Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the official source for the full statute text. uaelegislation.gov.ae [10] SKIMBOX - Our published PDPL compliance guidance on the federal breach-notification wording, the pending Executive Regulations and fine schedule, and our own website build pricing for UAE clients, 2026. skimbox.co

Frequently asked questions

  • Does my UAE website legally need a cookie banner?

    No UAE source we could find names cookies as a separately regulated category, and no UAE rule requiring prior consent before a cookie fires was found. That is not the same as saying anything goes. The general rule under the PDPL is that processing personal data needs consent, so if a cookie collects an identifier or an IP address, the consent principle reaches it. The obligation flows from that general rule, not from a cookie-specific law.

  • I copied a cookie banner script from another site and never configured it. Is that a problem?

    It is a practical problem rather than a confirmed legal one. An unconfigured banner does not satisfy any UAE rule we could confirm, because no cookie-specific rule was found. It also shows visitors an accept or reject choice that changes nothing behind the scenes. Google and Meta both require deliberate developer work before their tags respect a reject click. So the banner promises control the site does not deliver.

  • Can I copy a European privacy policy and change the company name?

    You should not. A European policy is written around legal bases, rights and regulators that come from EU law. The UAE PDPL is built around consent and does not offer the same broad fallback bases. A copied policy will also name an EU supervisory authority that has no role here, and promise rights in wording that may not match UAE law. Write the notice around what your site actually does, then have a qualified adviser check it.

  • What is the UAE PDPL and when did it start?

    The Personal Data Protection Law is Federal Decree-Law No. 45 of 2021, and the government portal states it has been in force since 2 January 2022. It applies to the processing of personal data, in full or in part, through electronic systems, inside or outside the country. That last phrase matters for websites, because almost everything a website does with visitor data is processing through an electronic system.

  • What counts as personal data under the PDPL?

    Information that can identify a person. Names, phone numbers, email addresses and account details are the obvious cases. For a website the less obvious cases matter more, because analytics and advertising tools routinely collect IP addresses and device or browser identifiers. If a cookie or a script stores something that can be tied back to an individual, treat it as personal data and treat the consent principle as applying to it.

  • Is consent the main legal basis under the PDPL?

    Consent is central. The government summary states the law prohibits processing personal data without the consent of its owner, except in some cases where processing is necessary to protect a public interest or to carry out legal procedures and rights. There is no broad legitimate interests fallback of the kind some businesses lean on elsewhere. That is why a copied European policy tends to justify processing in a way that does not translate here.

  • Which PDPL rights are confirmed on the official government page?

    Two are named there directly. The right to request corrections of inaccurate personal data, which is rectification, and the right to restrict or stop the processing of personal data. Those two we can point to on the government portal. The full statute may contain more, but we are not going to assert rights we could not confirm on an official page. Take the complete rights list to a qualified legal adviser before you publish it.

  • Do I have a right to receive a copy of my data under UAE law?

    We could not confirm that right on the official government summary of the federal PDPL, which names only rectification and restriction. That is an absence of confirmation, not proof the right does not exist in the full statute. DIFC is different. DIFC data protection law explicitly gives a right to obtain a copy of the data held about you, but DIFC law applies only to companies licensed in DIFC, not to UAE businesses generally.

  • How many hours do I have to report a data breach?

    No fixed number of hours is set in the federal law. The PDPL uses the word immediately, and the Executive Regulations that would fix a precise deadline have not been published. So if you read a confident seventy-two hour figure for the federal PDPL, treat it as imported from elsewhere. The practical answer is to build a breach process that can move within a day, because a tight deadline is the likely outcome.

  • What is the fine for breaching the federal PDPL?

    No federal fine schedule has been published. The penalties are due to come through a separate Cabinet decision, and as of 2026 that schedule is still pending. Any specific dirham figure you see quoted for a federal PDPL breach is somebody's estimate rather than an official number. The absence of a published fine is not the same as the absence of a legal duty, though. The law itself is in force.

  • Does having a cookie banner make me PDPL compliant?

    No. A banner touches one narrow slice of one issue. It says nothing about whether your privacy notice is accurate, whether you can actually honour a correction or restriction request, how long you keep data, who inside your business can see it, or what happens when there is a breach. Plenty of sites with a banner would fail on every one of those points. The banner is the smallest part of the work.

  • Do I need separate consent for Google Analytics and Meta Pixel?

    You need your consent mechanism to actually control both, which is not the same as showing one banner. They are separate tools with separate implementations. Google offers a consent mode that your banner has to be wired into. Meta Pixel documentation describes what the pixel collects but leaves consent handling to the site owner. Wiring one and forgetting the other is a common outcome, and it is easy to miss because nothing visibly breaks.

  • What does Google Analytics collect if a visitor clicks reject?

    It depends entirely on whether your site is wired into Google Consent Mode. If it is not, a reject click usually changes nothing, because the tag fires the way it always did. Google states plainly that consent mode does not provide a consent banner or widget, and that it interacts with your banner instead. Someone has to connect the two. Installing a banner plugin on its own does not do it.

  • What is Google Consent Mode?

    It is Google's mechanism for telling Google tags how to behave based on a visitor's consent choice, using signals such as ad storage, analytics storage, ad personalisation and ad user data. In basic mode, a denied consent blocks the tags and no data reaches Google at all. In advanced mode, tags still load with defaults set to denied and send cookieless pings carrying a timestamp, browser details, referrer and the consent state.

  • What does the Meta Pixel actually track?

    Meta's own developer documentation describes HTTP header data including IP address, browser information, page location and referrer, plus the pixel ID and the Facebook cookie, button click data covering which buttons were clicked on which pages, and form field names. Field values are not sent unless the site owner explicitly opts into advanced matching. That is a defined set of data collected by default, which is worth knowing before you argue your site collects nothing.

  • I have no privacy policy at all. How exposed am I?

    There is no published federal PDPL fine to point at, so nobody can hand you a number. Your exposure is more practical. You have nothing to show a visitor, a partner or a corporate buyer who asks how you handle data, and enterprise procurement teams increasingly ask. Consumer protection law also already places duties on suppliers around consumer data and disclosure, and that law is live and enforceable today.

  • What does the UAE Consumer Protection Law require from an online store?

    Federal Law No. 15 of 2020 on Consumer Protection, as amended by Federal Decree-Law No. 5 of 2023, requires suppliers to protect consumer privacy and data security and to refrain from using consumer data for promotional and marketing purposes without a proper basis. For e-commerce it also requires disclosure of the licensing entity, Arabic language product and contract information, specifications, payment terms and warranty terms. That is a present duty, not a future one.

  • What are the penalties under the Consumer Protection Law?

    The official government summary describes fines reaching up to two million dirhams and imprisonment of up to two years for certain offences, including misleading pricing, providing false information, and failing to repair or replace a defective product. That is a published schedule, unlike the federal PDPL position. If your store leans on vague claims or hides its return terms, this is the law that has teeth right now.

  • My company is in DIFC. Does the federal PDPL apply to me?

    No. DIFC has its own regime under DIFC Law No. 5 of 2020, supervised by the DIFC Commissioner of Data Protection. It applies to DIFC establishments, meaning entities established, licensed, registered or authorised to operate or conduct activity within or through the DIFC. If your licence is in DIFC, that is your law, and building your policy around the federal PDPL means you are compliant with the wrong statute.

  • My company is in ADGM. Same question.

    Same answer, different zone. ADGM enacted its Data Protection Regulations 2021, replacing the 2015 regulations, and set up an independent Office of Data Protection headed by a Commissioner of Data Protection. ADGM states the regulations apply to entities established in ADGM that process personal data, or that process in the context of the activities of an ADGM establishment. So an ADGM licence means ADGM rules, not the federal PDPL.

  • My company is in DMCC or IFZA or JAFZA. Which law applies?

    The federal PDPL. Only DIFC and ADGM operate their own separate data protection regimes with their own regulators. Every other free zone, along with mainland companies, sits under the federal law. This trips people up because free zone marketing often blurs the difference. The check is simple. Look at the licence, and if it does not say DIFC or ADGM, plan around the federal PDPL.

  • Do DIFC and ADGM publish their own penalties?

    Yes, both zones publish their own penalty structures, unlike the federal PDPL where the schedule is still pending. We are not quoting specific figures here because we could not re-verify current numbers directly with either authority in this round of research, and these schedules do get updated. If you are licensed in DIFC or ADGM, get the current figures from the relevant authority rather than from a blog.

  • I have visitors from Europe. Does GDPR apply to my Dubai business?

    It can, under the GDPR's own territorial scope rule. Article 3 reaches a controller or processor not established in the EU where processing relates to offering goods or services to people in the EU, or to monitoring their behaviour while that behaviour takes place in the Union. Ad tracking against EU visitors can count as monitoring. This is EU law describing its own reach, not something UAE law imposes on you.

  • When does GDPR not apply to a UAE business?

    Random traffic from an EU IP address does not put you in scope on its own. The Article 3 trigger is about offering goods or services to people in the EU or monitoring their behaviour there. A Dubai clinic serving UAE residents, priced in dirhams, with no EU targeting and no EU tracking, is a long way from that trigger. Plenty of UAE small businesses are sold GDPR compliance they do not need.

  • Do I need a cookie policy as a separate page?

    No UAE rule we found mandates a cookie policy at all, let alone as a separate page. Many sites publish one anyway, and there is a good reason to. Writing down every tool you run and what it collects forces someone to actually check, which is how unconfigured banners and forgotten tracking scripts get found. Treat it as a transparency and housekeeping exercise rather than a statutory checkbox.

  • What should a privacy notice tell a UAE website visitor?

    In plain language: what personal data you collect, why you collect it, who you share it with, roughly how long you keep it, and how someone contacts you to have inaccurate data corrected or to ask you to restrict processing. Those last two map to the rights confirmed on the official government page. Write it around what your site genuinely does, then have a qualified adviser review the wording before it goes live.

  • What should my terms of use cover?

    There is no UAE statutory template we found for terms of use. Whatever you write has to sit consistently with consumer protection law, which means accurate representations, terms you can actually enforce, and Arabic availability of contract information for consumers on an e-commerce site. A copied set of terms from a foreign site tends to fail on all three. This is drafting work for a qualified legal adviser, not something to generate.

  • My Google Ads account warns me about consent signals. What is that?

    That is Google's own platform requirement, not a UAE legal one. Google is telling you that your site is not sending it clear consent signals from a properly wired banner. Ignoring it affects your measurement quality and your standing with the ad platform. It is worth fixing on its own terms, but do not let anyone convert a Google product notice into a claim that UAE law requires a banner.

  • Is no banner better than a broken banner?

    Neither maps to a confirmed UAE cookie violation, so this is about honesty rather than law. No banner is at least a truthful state. Nothing on the page claims to give the visitor a choice. A banner that was never configured displays a working control that does not exist, and anyone who checks what fires after a reject click can see the gap. That is the worse position to be in.

  • I am selling into Saudi Arabia. Does that change things?

    It adds a separate set of questions rather than changing your UAE position. Saudi Arabia has its own data protection law and its own e-commerce and consumer protection regime, and Saudi VAT sits at fifteen percent against the UAE's five. Our Saudi guide covers the commercial and consumer side. If you process Saudi residents' data at any scale, treat Saudi data protection as its own review with its own adviser.

  • Can a foreign company with no UAE office be caught by the PDPL?

    The stated scope covers processing of personal data, in full or in part, through electronic systems, inside or outside the country. On that wording a foreign online store selling to UAE shoppers is within reach even with no local office. This is the mirror image of the GDPR question. Every serious data protection law now claims some reach beyond its own borders, which is why location alone settles very little.

  • Who enforces the PDPL day to day?

    The UAE Data Office was the original federal regulator, established under Federal Decree-Law No. 44 of 2021. In June 2026 it was brought into a new Federal Authority for Artificial Intelligence and Data, which is expected to publish the pending Executive Regulations and take enforcement forward. Our PDPL compliance guide covers the regulator, the Executive Regulations timeline and the six month compliance window in more depth.

  • Does ISO 27001 certification satisfy my PDPL obligations?

    It covers the security side well, because the PDPL expects appropriate technical and organisational measures and an information security management system gives you documented evidence of exactly that. It does not cover the rest. Consent, privacy notices, handling correction and restriction requests, and breach reporting are legal duties that no security certification addresses. Treat the certification as a strong foundation rather than a finished compliance programme.

  • What is the most common mistake with UAE privacy pages?

    Two, and they usually appear together. The first is a European style privacy policy pasted in whole, promising rights and naming regulators that do not apply here. The second is a consent tool installed and never connected to the tags it is meant to control, so the reject button is decorative. Both come from the same root cause, which is treating this as a page to install rather than a decision to make.

  • How much does this cost to sort out?

    The engineering side is normal website work. A focused business site build starts from around AED 3,500, and wiring an existing banner into your tags properly is usually a small piece of work on top of an existing site. Final pricing depends on scope. Drafting the policy wording itself is a legal question for a qualified adviser rather than something we sell, and we will say so rather than pretend otherwise.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading