Last updated: August 2026
Two things are true about most UAE business websites. There is a privacy policy that was copied from another site, sometimes with the original company name still buried in the third paragraph. And there is a cookie banner that somebody installed from a plugin directory and never configured, so the reject button does nothing at all.
Both come from the same mistake, and it is the most common mistake on this whole topic. Businesses import European practice and treat it as though it were UAE law. It is not. The UAE is not the EU, and the rules here are genuinely different in ways that matter for what you build.
This guide sets out what UAE sources actually confirm, what they do not, and what to do about the gap. We build websites, so this is written from the engineering side of the problem. We are not lawyers, and nothing here is legal advice. The wording of your policies is work for a qualified legal adviser.
The finding most articles get wrong
We went looking for a UAE cookie rule. Across the federal government portal, the DIFC Commissioner of Data Protection's own published guidance, and ADGM's data protection material, no UAE, DIFC or ADGM official source names cookies as a specifically regulated category [1][3][4]. We found no UAE equivalent of the European rule requiring prior consent before a non-essential cookie is set.
That is a finding, and it needs stating carefully. It is an absence of confirmation, not a permission slip. Two very different things.
What does exist is the general consent principle. The Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, has been in force since 2 January 2022 and applies to the processing of personal data, in full or in part, through electronic systems, inside or outside the country [1]. The government summary states the law prohibits processing personal data without the consent of its owner, except in some cases where processing is necessary to protect a public interest or to carry out legal procedures and rights [1].
Follow that through. A cookie that stores an IP address or a device identifier is processing personal data through an electronic system. So the consent principle reaches it, the same way it reaches a signup form. The obligation, where you have one, comes from the general rule about personal data. It does not come from a cookie-specific statute, because we could not find one.
What that does and does not mean for you
It means you can stop treating the European banner pattern as a legal requirement here. The pattern where nothing fires until a visitor clicks, the granular category toggles, the twelve month re-consent cycle: that is a European design solving a European rule.
It does not mean you can run whatever tracking you like. The consent principle still applies to the personal data your site collects. It also does not mean the question is settled forever. The PDPL's Executive Regulations have not been published, and detail that is currently open could close later.
And it does not mean nothing is enforceable today. Federal Law No. 15 of 2020 on Consumer Protection, as amended by Federal Decree-Law No. 5 of 2023, already requires suppliers to protect consumer privacy and data security and to refrain from using consumer data for promotional and marketing purposes without a proper basis [2]. That same law requires e-commerce sellers to disclose their licensing entity, Arabic language product and contract information, specifications, payment terms and warranty terms [2]. The official summary describes penalties reaching up to two million dirhams and imprisonment of up to two years for certain offences [2]. That is a published schedule with real numbers attached, which is more than the federal PDPL currently has.
Real talk: the law that is most likely to cause you a problem this year is consumer protection, not cookies. Most businesses have this backwards.
The banner that blocks nothing
This is the part worth your attention, because it is where we find the most damage on real sites.
A cookie banner does not control your tracking scripts. It is a piece of interface. Something has to connect the visitor's click to the tools that actually collect data, and on most sites nobody ever did that work.
Google says this outright in its own documentation. Consent mode does not provide a consent banner or widget, and instead interacts with your banner to obtain visitor consent [6]. Google also states that the site owner, not Google, is responsible for obtaining users' consent [5]. Consent mode governs distinct signals covering ad storage, analytics storage, ad personalisation and ad user data [5]. In basic mode, a denied consent blocks the tags and no data reaches Google at all. In advanced mode, tags still load with defaults set to denied and send cookieless pings carrying a timestamp, browser details, referrer and the consent state, used for statistical modelling [6].
None of that happens automatically because a banner exists. It happens because a developer wired the banner's events into consent mode.
Meta is the same story from a different angle. Meta's developer documentation describes what the pixel collects by default: HTTP header data including IP address, browser information, page location and referrer, plus the pixel ID and the Facebook cookie, button click data, and form field names, with field values excluded unless the site owner opts into advanced matching [7]. That is a defined set of data collected as standard. Nothing in that documentation gates it behind a consent banner. Gating it is the site owner's job.
So here is the honest position. A banner that was installed and never configured does not satisfy any confirmed UAE requirement, because we could not confirm one exists. And it displays a working control to your visitors that does not work. Anyone who opens their browser tools after clicking reject can see the same requests firing.
That reasoning is practical, not legal. We are not saying an unconfigured banner breaks a UAE law. We are saying it is the worst of both worlds: no legal benefit, and a visible false claim about what your site does. No banner at all is at least honest.
Why the copied European policy fails here
The copied policy fails for a structural reason, not a cosmetic one.
European policies are built around a set of legal bases that lets a business justify processing without consent in many situations. UAE law is written the other way around, prohibiting processing without consent except in named cases [1]. A policy whose justification section is built on the European model is explaining the wrong thing.
Then there are the rights. The official government summary of the PDPL confirms two rights by name: the right to request corrections of inaccurate personal data, and the right to restrict or stop processing [1]. Those two we will state. A right to receive a copy of your own data could not be confirmed on that official page, so we are not going to claim it. That is not a statement that the right does not exist somewhere in the full statute. It is a statement about what we could verify. Take the complete rights list to a qualified legal adviser and to the full text on the official legislation portal before you publish a list of your own [9].
DIFC is a useful contrast here, and a common source of confusion. DIFC's own law does explicitly confirm a right to obtain a copy of the data held about a person, alongside rectification, erasure, objection, restriction and portability [3]. But DIFC is a separate regime. It applies to DIFC establishments, meaning entities established, licensed, registered or authorised to operate or conduct activity within or through the DIFC [3]. If your licence is not in DIFC, DIFC's rights list is not your rights list, and copying it into your policy promises visitors something UAE federal law has not been confirmed to give them.
Finally, a copied policy names the wrong regulator, points visitors at a complaints route that does not exist for them, and describes data flows that belong to somebody else's business. That last one is the reason to write your own. The policy should describe what your site actually does, which means somebody has to find out.
Which law applies to you
Three routes, and your licence decides.
- Mainland or a standard free zone such as DMCC, JAFZA, IFZA or Dubai Internet City: the federal PDPL [1].
- DIFC: DIFC Law No. 5 of 2020, with its own Commissioner of Data Protection [3].
- ADGM: the ADGM Data Protection Regulations 2021, which replaced the 2015 regulations and established an independent Office of Data Protection headed by a Commissioner. ADGM states the regulations apply to entities established in ADGM that process personal data, or that process in the context of the activities of an ADGM establishment [4].
Both DIFC and ADGM publish their own penalty structures, which is a real difference from the federal position where the schedule is still pending. We are not printing specific figures for either zone here, because we could not re-verify current numbers directly with those authorities this time and these schedules get revised. If you are licensed in either zone, get the current figures from the relevant authority.
On the federal side, two things stay true. The PDPL uses the word immediately for breach notification rather than a number of hours, and the Executive Regulations that would fix a precise deadline are still pending [10]. And no federal fine schedule has been published, so any dirham figure you see quoted for a federal PDPL breach is somebody's estimate [10]. Our PDPL compliance guide goes through the regulator, the Executive Regulations and the compliance window in detail.
When European law actually reaches you
This one gets sold hard to UAE small businesses, so it is worth being precise.
The GDPR describes its own territorial reach in Article 3. It applies to a controller or processor not established in the EU where the processing relates to offering goods or services to people who are in the EU, or to monitoring their behaviour so far as that behaviour takes place within the Union [8]. That is EU law describing how far it reaches. It is not something UAE law does to you.
So when are you genuinely in scope? If you price in euros, ship to EU addresses, translate for EU markets, or run advertising tracking against visitors who are physically in the EU, the trigger is live and you should take advice.
When are you not? A Dubai dental clinic with an all-UAE patient base, dirham pricing and no EU targeting is not in scope because three people in Berlin found the site through search. Traffic alone is not the test. Plenty of UAE businesses are sold a GDPR programme they do not need, usually by someone selling the programme.
A sensible order of work
If you are starting from a copied policy and a dead banner, do it in this order.
- Inventory what actually runs. Open your site and list every tag, pixel and script. Most teams find tools nobody remembers adding, still firing.
- Decide what you actually need. The cheapest privacy fix is removing a tool you stopped using two years ago.
- Wire the consent mechanism properly, or remove it. Either connect the banner to consent mode and to your other tags, or take it off the site. A decorative banner is the one option with no upside.
- Write the privacy notice around reality. What you collect, why, who sees it, how long you keep it, and how someone asks you to correct or restrict their data.
- Get the wording reviewed by a qualified legal adviser. This step is not optional and it is not ours to do.
- Check the consumer-facing pages if you sell online. Licensing entity, Arabic contract information, payment and warranty terms [2]. Our e-commerce build guide and VAT-compliant e-commerce guide cover the commercial side, and the Saudi selling guide covers what changes across that border.
Real client stories
Situations from our own work. Details changed for privacy.
A Dubai retail brand with a banner that blocked nothing. The site had a full consent banner with category toggles, installed by a previous agency. We clicked reject and watched the network tab. Every analytics and advertising request fired exactly as before, because the banner had never been connected to anything [5][6]. The founder's reaction was the useful part. He had assumed the banner was the compliance work, and had never checked. We disconnected the unused tools, wired the rest properly, and the banner finally meant something.
A mainland clinic sold a GDPR programme. An all-UAE patient base, dirham pricing, no EU marketing, and a proposal to build a GDPR compliance programme because the site had European visitors. Read against Article 3, offering goods or services to people in the EU or monitoring their behaviour there, the clinic did not meet the trigger [8]. We told them so and pointed the budget at the federal PDPL work that did apply to them.
A free zone SaaS company using someone else's policy. The privacy policy promised a right to download a copy of all personal data. Nobody had built that, and the right was not one we could confirm on the official government summary of the federal PDPL [1]. It had been inherited from a European template. The policy was promising a feature the product did not have, under a law that had not been checked. That is a support ticket and an awkward conversation waiting to happen.
How SKIMBOX approaches this
We handle the engineering half of this problem, and we are clear about where our half ends.
That means auditing what your site actually loads, removing tools you no longer use, wiring consent controls into the tags they are supposed to control so a reject click does something real, and building the pages themselves. If you are rebuilding anyway, our website cost guide sets out what a focused business site costs, starting from around AED 3,500 [10]. Final pricing depends on scope.
The related work usually sits nearby. Sites that depend on tracking for conversion measurement need landing page and CRO work that survives a properly configured consent setup. Businesses reporting on customer data across systems should read our analytics and BI guide. Anything with a customer login and stored records is closer to a web portal build than a brochure site, and the data questions get heavier accordingly.
What we do not do is write your legal wording or tell you what your policy must say. We are not lawyers and this article is not legal advice. Take the drafting to a qualified adviser, and take the current penalty figures for your zone to the authority that publishes them.
If you want the technical side looked at properly, see our web development services or our business consulting services, or contact us.
References
[1] The UAE Government Portal - Data protection laws, Federal Decree-Law No. 45 of 2021, scope, the consent requirement, and the rights to rectification and to restrict processing. u.ae [2] The UAE Government Portal - Consumer protection, Federal Law No. 15 of 2020 as amended by Federal Decree-Law No. 5 of 2023, supplier duties on consumer data, e-commerce disclosure requirements, and penalties. u.ae [3] DIFC Commissioner of Data Protection - Overview of DIFC Data Protection Law and Regulations, covering DIFC Law No. 5 of 2020, the definition of DIFC establishments, and the data subject rights list. difc.com [4] ADGM - Data Protection Regulations 2021 announcement and Office of Data Protection guidance, covering the new regulations, the Commissioner, and scope. adgm.com [5] Google for Developers - Consent mode overview, the consent signals it governs, and the statement that the site owner is responsible for obtaining consent. developers.google.com [6] Google Ads Help - About consent mode, confirming that consent mode does not provide a banner, and the difference between basic and advanced behaviour when consent is denied. support.google.com [7] Meta for Developers - Meta Pixel documentation, covering the data the pixel collects by default and the advanced matching opt-in. developers.facebook.com [8] EUR-Lex - Regulation (EU) 2016/679, Article 3, on territorial scope for controllers and processors not established in the European Union. eur-lex.europa.eu [9] UAE Legislation Portal - Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, the official source for the full statute text. uaelegislation.gov.ae [10] SKIMBOX - Our published PDPL compliance guidance on the federal breach-notification wording, the pending Executive Regulations and fine schedule, and our own website build pricing for UAE clients, 2026. skimbox.co



