Marketing

Marketing Messages in the UAE: The Rules on SMS, Calls and Email

SKIMBOX Team

Consent has to be storable, messages are permitted only between 7am and 9pm, every message needs a free unsubscribe, and there is a national Do Not Call Register. Most UAE marketing lists were built without any of that in mind.

Marketing Messages in the UAE: The Rules on SMS, Calls and Email

Most UAE marketing lists were assembled the same way: exhibition badge scans, business cards, a spreadsheet from a previous role, a form that never recorded when anybody submitted it, and an import from a source nobody can now identify.

Then a campaign goes out at eleven at night because the platform is scheduled in another timezone, from a short code nobody recognises, with an unsubscribe link that leads to a login page.

Every element of that is addressed by rules that already exist here and that most marketers have never read.

This article covers what the framework requires, why the commercial case for compliance is stronger than the compliance case, and how to repair a list built without any of it.

The rules, specifically

The telecoms regulator publishes a regulatory policy on unsolicited electronic communications and operates the national Do Not Call Register [1][2][3].

Consumers have a stated right not to receive unsolicited electronic communications, which is the principle underneath everything else [4].

Four requirements matter operationally:

Consent. Licensees must obtain the mobile customer's consent to receive marketing text messages, and that explicit consent is valid where it is written or electronic and storable [2].

Hours. Marketing messages are permitted only between 7am and 9pm UAE time [2].

Unsubscribe. Every marketing message should contain a free of charge unsubscribe option that customers can use to stop receiving such messages [2].

The register. The Do Not Call Register lets people opt out of marketing calls from specific sectors or from all sectors [1][3].

And there are penalties attached. Administrative violations and penalties are stated as ranging from ten thousand to one hundred and fifty thousand dirhams, depending on the type and nature of the violation [2].

The word that catches everybody: storable

Consent being valid where it is written or electronic and storable is the requirement that most businesses fail without knowing it.

It means you need a record you can produce, not a belief that somebody agreed at some point.

What satisfies it: a timestamped database entry showing who consented, when, through what mechanism, and to what.

What does not: a verbal yes at an exhibition. A business card. A conversation. A general sense that the relationship implies permission.

The test worth applying to your own list is simple. Could you produce the evidence if asked? A consent you cannot evidence is functionally identical to no consent, whatever actually happened at the time.

Which leads to the most common failure in this whole area. Businesses store the email address or the mobile number and nothing else. A year later they have a list and no way to demonstrate how any of it was obtained.

Capture four things at signup, stored together: the identifier you will message, an explicit affirmative action, what they are agreeing to receive, and a timestamp.

The hours window is an engineering problem

Seven in the morning to nine at night, UAE time.

That is a hard operational constraint, and it catches businesses in two specific ways.

Platforms scheduled in another timezone. Your marketing tool may be configured against a head office timezone, or against whatever the default was when somebody set it up. Check what it is actually doing rather than assuming.

Behaviour-triggered messaging. An abandoned-cart message that fires ninety minutes after the event will eventually fire at 2am, because customers abandon carts at 2am. The restriction is on the marketing message rather than on how it was triggered.

The fix is a queue that holds anything falling outside the window and releases it at seven the following morning, which also happens to be a better send time than the middle of the night was ever going to be. It is a small piece of engineering and it is frequently missing entirely, because nobody considered that an automated flow is still a marketing message.

Transactional messages are a different category. Order confirmations, delivery updates and password resets are operational rather than promotional, and should be cleanly separated in your systems.

Where businesses get into difficulty is bundling a promotion into a transactional message. A delivery notification that also advertises a sale has arguably become marketing, and it brings the rules into play for a message that was previously outside them. Keep the two streams genuinely separate rather than treating the transactional channel as free promotional real estate.

The Do Not Call Register changes your list

Its existence means something specific for any business doing outbound calling.

A number being in your database does not tell you whether you may call it. A person may have registered an objection you know nothing about, through a route that does not involve contacting you.

So a business calling at scale needs a process for reconciling against the register rather than treating its own list as authoritative. Ask your dialler provider how they handle it, and treat a vague answer as a finding.

The same logic applies to your sales team. Outbound calling is not outside scope because it feels like a conversation rather than a campaign, and any business calling at volume needs both the reconciliation and a record of where numbers came from.

The unsubscribe that does not work

Every marketing message needs a free unsubscribe. Two words there carry weight.

Free means no premium number, no charged reply, no cost to the person exercising a right.

Every means it is not sufficient to include it in the first message of a sequence and omit it thereafter.

Beyond the requirement, there are two failure modes that produce complaints from people who genuinely tried to leave.

The unsubscribe that requires a login. A link leading to a preference centre demanding account credentials the person does not have is functionally a refusal. Test your own flow from a phone, as an ordinary recipient, rather than assuming it works because somebody configured it.

Suppression at export rather than at send. Businesses running campaigns from an exported list send to a snapshot taken before the unsubscribe, so somebody who opted out on Monday receives Wednesday's campaign. That is precisely the complaint the mechanism exists to prevent.

Suppress at send time, not at export time.

And keep a permanent suppression list rather than deleting people entirely. This surprises businesses who assume the point is removal, but if you delete somebody completely, the next list import can quietly re-add them. Retaining enough to ensure you never message them again is the whole purpose. Our guide on data retention covers the general principle, and suppression is one of the cases where retaining data is the protective choice.

What a compliant setup actually looks like

Rather than a list of prohibitions, here is the shape of a programme that satisfies the requirements and performs better commercially, which are the same programme.

At collection. An unticked checkbox, separate from any other agreement, stating plainly what the person will receive and roughly how often. The record stores the identifier, the affirmative action, the stated purpose and a timestamp, in one row you could produce on request.

In the database. Every contact carries its source and its consent date. Suppression is a permanent list rather than a deletion. Transactional and marketing streams are separate, with separate consent states, so somebody who opts out of promotions still gets their delivery notification.

At send time. The platform checks the suppression list at the moment of sending rather than at export. It holds anything scheduled outside the permitted window and releases it at seven. It reconciles outbound calling against the register. Sender identification matches the brand the person signed up to.

In every message. A free unsubscribe that works in one tap from a phone, without a login, and takes effect before the next send.

On a schedule. An engagement-based expiry that removes people who have not opened anything in a defined period, and a quarterly check that the four operational controls above still work after whatever platform changes have happened in the meantime.

None of that is elaborate. It is perhaps two days of configuration and one short conversation with whoever owns the list. What makes it rare is not difficulty but that no single person is usually accountable for all five layers at once.

Where lists actually go wrong

Four sources account for nearly all of it.

Purchased lists. Consent obtained by somebody else for their own purposes is unlikely to cover your messages. Beyond the exposure, purchased lists perform badly, damage sender reputation and raise complaint rates, so the commercial case is weak before compliance enters the conversation at all.

Business cards and badge scans. Somebody handing you a card at an event has not subscribed to a campaign. The card is an invitation to make contact, not a standing permission. This is one of the most widespread assumptions in the region and one of the least defensible.

Contacts brought from a previous role. A new marketing hire arriving with a spreadsheet is importing people who consented to hear from a different company entirely.

Undocumented imports. The single riskiest habit. A list appears, somebody uploads it, and nobody records where it came from. It is invisible until a complaint arrives.

The fix for all four is one process step: require a documented source for every import, recorded at the point of import rather than reconstructed afterwards, and give somebody authority to refuse one.

Two minutes per import. Businesses that adopt it are usually surprised how many proposed imports cannot answer the question, which is exactly the point of asking it. The imports that fail the test were the ones generating your complaints.

Specificity. Consent to receive an order update is not consent to a weekly promotional newsletter. A single line buried in terms and conditions is a weak basis for a marketing programme.

Separate checkboxes for separate purposes are more work at signup and considerably stronger afterwards, and they also produce better lists, because people who opted in specifically to the thing you send are people who want it.

Pre-ticked boxes record an absence of objection rather than an affirmative choice. They are a poor basis if anybody examines them, and they inflate your list with people who never wanted your messages, which drags engagement down and makes every subsequent send perform worse.

Unticked is both safer and commercially better, which is an unusually convenient alignment.

Age of consent is worth a policy. There is no single stated shelf life, and consent obtained five years ago from somebody who has never engaged since is weak on both compliance and deliverability grounds. An engagement-based expiry addresses both at once.

The commercial case is stronger than the compliance case

This is the argument to use internally when somebody resists cleaning the list.

Deliverability depends heavily on engagement. A list full of people who never open drags down whether your messages reach anybody at all, including the people who actually want them.

So a smaller engaged list frequently produces more revenue than a larger disengaged one. The compliance benefit arrives as a side effect of doing the commercially correct thing.

Re-permissioning is how you get there from a list built without any of this. Send one message explaining what you send and asking people to confirm they want to keep receiving it. Keep only those who confirm.

It is painful, and the list shrinks more than anybody expects, which is exactly why it keeps being postponed.

We are not going to give you a survival percentage, because the figures in circulation come from email platform vendors with an interest in the number. What is reliably true is that the people who confirm are largely the ones who were going to buy anyway, and the ones who do not confirm were suppressing your metrics and your deliverability the whole time.

The cost of getting it wrong, in order of likelihood

Businesses assess this by imagining a regulator. That is the least likely consequence and the least expensive one.

Deliverability decay is the most likely by a wide margin, and it is entirely invisible in your reporting. Complaints and low engagement damage your sender reputation with networks and inbox providers, so a growing share of your messages stop arriving. Your open rate falls, you conclude the creative is tired, and you send more, which makes it worse. Nobody ever sees a bounce for this.

Wasted spend follows. Sending to people who never consented costs money per message and produces nothing. On a large list that is a continuing line item nobody examines, because the cost per message is small enough to escape scrutiny while the total is not.

Customer damage is next. Somebody who receives a message they did not ask for at eleven at night forms a view about your business that no campaign afterwards corrects, and a proportion of them were customers.

Platform action is a real risk for messaging apps in particular, where the platform enforces its own rules more actively than any regulator and can remove your access with limited recourse. Losing a channel you built a programme around is considerably more disruptive than a fine.

Regulatory penalties sit at the end, with a stated administrative range of ten thousand to one hundred and fifty thousand dirhams depending on the violation.

Read that ordering and the argument changes. The case for fixing this is commercial and immediate rather than legal and hypothetical, which is also the argument most likely to succeed internally.

Three frameworks, one email address

Worth mapping, because businesses satisfy one and assume the rest.

Telecoms rules govern unsolicited electronic communications: consent, hours, unsubscribe, the register [1][2].

Consumer protection law obliges suppliers to protect consumer data and refrain from using it for promotional and marketing purposes [5], which is a constraint many businesses have never encountered because it sits in an unexpected place. Our guide on consumer protection for online sellers covers it.

Data protection law governs the processing of that personal data generally. Our guide on PDPL compliance covers the framework.

Three sets of obligations attaching to one contact record. They do not substitute for each other, and the safe position across all three is explicit, evidenced, specific consent.

On messaging apps: business messaging carries the platform's own rules on top of whatever applies locally, and platform rules are frequently stricter and more actively enforced than anything a regulator does. Our guide on the WhatsApp Business API covers those requirements.

On business-to-business: the framework concerns electronic communications to recipients rather than turning solely on the recipient being a consumer, and the boundary is a question for your adviser. The practical point is that a mobile number and a personal work email address belong to an individual regardless of who pays their salary. Treating business contacts as unrestricted is a weaker assumption than it appears.

If an agency sends for you

Your position does not transfer.

The marketing is yours and the customer relationship is yours. An agency handling the sending is doing so on your behalf.

There is also a practical trap. An agency sending from its own platform may hold the consent records, which means you cannot evidence consent for your own list without asking them. Ask where those records live, confirm you can obtain them, and confirm you would still have them if the relationship ended. Our guide on getting your data out covers testing that rather than assuming.

Questions for an SMS provider, in writing: how do you handle the permitted hours window; do you reconcile against the Do Not Call Register; what consent records do you store and can I export them; how are unsubscribes processed and suppressed; and what sender identification appears?

A provider who cannot answer the first two quickly is not operating with the local rules in mind, which tells you what you need to know.

On sender identification: recipients should be able to tell who is messaging them. Messages from an unrecognisable short code asking people to click a link are indistinguishable from fraud, and are increasingly treated as such by recipients and by platforms. Use an identity matching the brand the person actually signed up to.

The afternoon audit

Four checks. Between them they cover most of the exposure.

Where did every contact come from, and can you evidence it? If the honest answer for a large share is that nobody knows, you have found the main problem and re-permissioning is the answer.

Does your platform respect the 7am to 9pm window, including for automated and triggered messages?

Do unsubscribes suppress at send time rather than at export time?

Does your unsubscribe link work from a phone without a login? Test it yourself as a recipient.

Do all four in one sitting rather than as a project, because each is a check rather than a change, and the changes that follow are mostly configuration.

Give the whole thing an owner in marketing, with a written process, since marketing controls the sends and owns the list. The failure mode is that compliance is nominally somebody else's function while the actual decisions, which list to send to and when, get made by whoever is running a campaign that week.

Enforcement is real: the regulator states that it monitors compliance through regular reporting and takes action against entities sending without prior consent [2]. But the more immediate consequence for most businesses is quieter. Complaints damage sender reputation with networks and platforms, which reduces how many of your messages arrive at all, including to the people who wanted them.

For the current rules, go to the telecoms regulator directly [1][2][3]. Requirements are revised, and a business acting on a stale summary carries the consequence rather than whoever wrote it.

If you want help, reviewing where your list came from and whether consent is evidenced, checking your platform against the hours and unsubscribe requirements, and building suppression and source-tracking into your systems starts from around AED 2,500 with us. Final pricing depends on scope, and these are our own figures rather than a market survey.

References

  1. TDRA, marketing short message service
  2. TDRA, regulatory policy on unsolicited electronic communications
  3. TDRA, consumer affairs
  4. TDRA, know your rights and responsibilities consumer guide
  5. UAE Government, consumer protection
  6. SKIMBOX, consumer protection for online sellers in the UAE
  7. SKIMBOX, PDPL compliance in the UAE
  8. SKIMBOX, WhatsApp Business API cost and setup in the UAE
  9. SKIMBOX, email deliverability, SPF, DKIM and DMARC
  10. SKIMBOX, data retention for a UAE business
  11. SKIMBOX, getting your data out

Requirements summarised here are published by the telecoms regulator and are revised over time; confirm the current position directly. This article is not legal advice, and questions about how the framework applies to a specific programme should go to a qualified adviser.

Frequently asked questions

  • Are there actual rules on marketing messages in the UAE?

    Yes, and they are more specific than most marketers expect. The telecoms regulator publishes a regulatory policy on unsolicited electronic communications, operates a national Do Not Call Register, and sets requirements covering consent, permitted hours and unsubscribe mechanisms. Consumers have a stated right not to receive unsolicited electronic communications, which is the principle the whole framework rests on. Consumers have a stated right not to receive unsolicited electronic communications, which is the underlying principle.

  • What consent do we need to send marketing SMS?

    Licensees must obtain the mobile customer's consent to receive marketing text messages, and that explicit consent is valid where it is written or electronic and storable. The storable requirement is the operative word for most businesses, because it means you need a record you can produce rather than a belief that somebody agreed at some point in the past. The storable requirement is the operative word, because it means a record you can produce rather than a belief.

  • What does storable consent look like in practice?

    A record showing who consented, when, through what mechanism, and to what. A timestamped database entry from a form submission satisfies that. A verbal yes at an exhibition does not, unless somebody captured it in a form. The test worth applying is whether you could produce the evidence if asked, because a consent you cannot evidence is functionally the same as no consent. A consent you cannot evidence is functionally identical to no consent, whatever actually happened at the time.

  • Are there permitted hours for marketing messages?

    Marketing messages are permitted only between 7am and 9pm UAE time. That is a hard operational constraint rather than a courtesy, and it catches out businesses running automated campaigns scheduled in another timezone or triggered by events at any hour. Check what your platform is actually configured to do rather than assuming it respects a local window. Check what your platform is actually configured to do rather than assuming it respects a local window.

  • Does the time window apply to automated messages too?

    The restriction is on marketing messages rather than on how they were triggered, so an automated campaign firing at 2am is exactly the case to design against. Businesses running behaviour-triggered messaging need a queue that holds anything falling outside the window and releases it in the morning, which is a small piece of engineering that is frequently missing. A queue that holds out-of-hours messages and releases them at seven is a small piece of engineering that is frequently missing.

  • What about transactional messages?

    Order confirmations, delivery updates, password resets and similar operational messages are a different category from marketing, and the sensible position is to keep them cleanly separated in your systems. Where businesses get into difficulty is bundling a promotion into a transactional message, which arguably converts it into marketing and brings the rules into play. Keep the two streams genuinely separate rather than treating the transactional channel as free promotional space.

  • Must every message carry an unsubscribe option?

    Every marketing message should contain a free of charge unsubscribe option that customers can use to stop receiving such messages. Two words in that requirement matter: free, so no premium number or charged reply, and every, so it is not sufficient to include it in the first message of a campaign and omit it thereafter. It is not sufficient to include it in the first message of a sequence and omit it from the rest.

  • What is the Do Not Call Register?

    A national register operated by the telecoms regulator that lets people opt out of receiving marketing calls, either from specific sectors or from all sectors. It exists precisely so consumers have a route that does not depend on contacting each business individually, and its existence means an opt-out is enforceable outside your own systems as well as inside them. Its existence means an opt-out is enforceable outside your own systems as well as inside them.

  • How does the register affect our calling list?

    It means a number being in your database does not tell you whether you may call it, because a person may have registered an objection you know nothing about. Any business doing outbound calling at scale needs a process for reconciling against the register rather than treating its own list as authoritative. Ask your dialler provider how they handle this. Ask your dialler provider how they handle it, and treat a vague answer as a finding in itself.

  • What are the penalties?

    Administrative violations and penalties are stated as ranging from ten thousand to one hundred and fifty thousand dirhams depending on the type and nature of the violation. Those are per-violation administrative penalties rather than a single ceiling for a campaign, which is worth understanding before deciding the risk is tolerable. Those are per-violation administrative penalties rather than a single ceiling for an entire campaign. A record you could produce on request is the standard rather than a recollection of the conversation.

  • Do these rules apply to email as well as SMS?

    The framework is about unsolicited electronic communications generally rather than SMS alone, and email marketing sits within that. Separately, consumer protection law obliges suppliers to protect consumer data and refrain from using it for promotional and marketing purposes, which is a constraint many businesses have never encountered. Both apply, and treating email as unregulated is a mistake. Treating email as unregulated is a mistake, and three frameworks attach to the same contact record.

  • What about WhatsApp and messaging apps?

    Business messaging on those platforms carries the platform's own rules on top of whatever applies locally, and the platform rules are frequently stricter and more actively enforced. Our guide on the WhatsApp Business API covers the platform requirements, and the practical answer is that you need consent for the same reasons and to a similar standard. Platform rules are frequently stricter and more actively enforced than anything a regulator does.

  • Can we buy a marketing list?

    Purchased lists are the clearest way to end up sending to people who never consented to hear from you, and consent obtained by somebody else for their own purposes is unlikely to cover your messages. Beyond the regulatory exposure, purchased lists perform badly, damage sender reputation and increase complaint rates, so the commercial case is weak even setting compliance aside. The commercial case against purchased lists is weak before compliance enters the conversation at all.

  • What about people who gave us a business card?

    Somebody handing you a card at an event has not consented to a marketing campaign, and treating that as permission is one of the most common assumptions in the region. The card is an invitation to make contact rather than a subscription. If you want to market to them, ask them to opt in and record it. The card is an invitation to make contact rather than a subscription to a campaign.

  • Does consent expire?

    There is no single stated shelf life, and consent obtained five years ago from somebody who has never engaged since is a weak position to defend, both as a matter of compliance and as a matter of deliverability. Setting an engagement-based expiry on your list addresses both at once, and our data retention guide covers the reasoning. An engagement-based expiry addresses both the compliance and the deliverability problem at once.

  • How specific does consent need to be?

    Specific enough that the person understood what they were agreeing to receive. Consent to receive an order update is not consent to a weekly promotional newsletter. A single pre-ticked box buried in terms and conditions is a weak basis. Separate checkboxes for separate purposes are more work at signup and considerably stronger afterwards. Separate checkboxes for separate purposes are more work at signup and considerably stronger afterwards.

  • Should the checkbox be pre-ticked?

    No. A pre-ticked box records an absence of objection rather than an affirmative choice, and it is a poor basis to rely on if anybody examines it. It also inflates your list with people who never wanted your messages, which drags engagement rates down and makes every subsequent send perform worse. Unticked is both safer and commercially better. Unticked is both safer and commercially better, which is an unusually convenient alignment and worth pointing out to whoever is arguing for the pre-ticked version on volume grounds.

  • What should our signup form actually capture?

    The identifier you will message, an explicit affirmative action, what they are agreeing to receive, and a timestamp. Store all four together. The most common failure is storing the email address and nothing else, so a year later the business has a list and no way to demonstrate how any of it was obtained. The most common failure is storing the address and nothing else, leaving you with a list and no provenance.

  • How do we fix a list built without any of this?

    Re-permission it. Send one message to the existing list explaining what you send and asking people to confirm they want to keep receiving it, then keep only those who confirm. It is painful, the list shrinks dramatically, and the remainder is both defensible and considerably more responsive than what you had. The remainder is both defensible and considerably more responsive than what you had before.

  • How much of a list typically survives re-permissioning?

    Less than owners expect, which is exactly why it gets postponed. We are not going to give you a percentage, because the figures in circulation come from email platform vendors. What is reliably true is that the people who confirm are the ones who were going to buy anyway, and the ones who do not confirm were suppressing your metrics. The people who confirm are largely the ones who were going to buy anyway.

  • Is a smaller list actually better?

    Commercially, usually yes. Deliverability depends heavily on engagement, so a list full of people who never open drags down whether your messages reach anybody at all, including the people who want them. A smaller engaged list frequently produces more revenue than a larger disengaged one, before any compliance argument enters the conversation. The compliance benefit arrives as a side effect of doing the commercially correct thing.

  • What does an unsubscribe need to do?

    Actually unsubscribe them, promptly, without requiring a login or a reply that costs money. The failure mode is a link that leads to a preference centre requiring account credentials the person does not have, which is functionally a refusal. Test your own unsubscribe flow from a phone as an ordinary recipient rather than assuming it works. Test your own unsubscribe flow from a phone as an ordinary recipient rather than assuming it works.

  • How quickly must we honour an unsubscribe?

    Promptly, and the practical standard is that somebody who unsubscribes should not receive the next send. Businesses running campaigns from an exported list frequently send to a snapshot taken before the unsubscribe, which produces exactly the complaint the mechanism exists to prevent. Suppress at send time rather than at export time. Suppress at send time rather than at export time, which is where most of these complaints originate.

  • Do we need to keep a record of unsubscribes?

    Yes, and permanently, which surprises people who assume the point is deletion. You need to retain enough to ensure you never message that person again, which means a suppression list rather than removing them entirely. Deleting somebody completely means the next list import can quietly re-add them, which is a recurring cause of complaints. Deleting somebody completely means the next import can quietly re-add them, which is a recurring cause of complaints.

  • Who is responsible if our agency sends the messages?

    You are, in substance, because the marketing is yours and the customer relationship is yours. An agency handling the sending does not transfer your position, and an agency using its own platform may leave you unable to evidence consent because the records sit with them. Ask where consent records live and confirm you can obtain them. Ask where consent records live and confirm you could still obtain them if the relationship ended.

  • What should we ask an SMS provider?

    How they handle the permitted hours window, whether they reconcile against the Do Not Call Register, what consent records they store and whether you can export them, how unsubscribes are processed and suppressed, and what sender identification appears. A provider who cannot answer the first two quickly is not operating with the local rules in mind. A provider who cannot answer the first two quickly is not operating with the local rules in mind.

  • What about sender identification?

    Recipients should be able to tell who is messaging them, which is both a regulatory expectation and basic practice. Messages from an unidentifiable short code asking people to click a link are indistinguishable from fraud, and increasingly get treated as such by recipients and by platforms. Use a sender identity that matches the brand the person actually signed up to. Use a sender identity matching the brand the person actually signed up to rather than an anonymous code.

  • Does this interact with data protection law?

    Directly. Marketing to somebody involves processing their personal data, so your obligations under the data protection framework apply alongside the telecoms rules and the consumer protection provision on promotional use. Our PDPL guide covers that framework, and the practical position is that three sets of obligations attach to one email address. The practical position is that three sets of obligations attach to a single email address.

  • What is the single riskiest thing most businesses do?

    Import a list from a source they cannot document. It happens at exhibitions, after acquisitions, when a salesperson leaves a spreadsheet behind, and when a new marketing hire brings contacts from a previous role. Each import adds people who never agreed to hear from you, and it is invisible until somebody complains. It happens at exhibitions, after acquisitions, and when a new hire arrives with contacts from a previous role.

  • How do we prevent unsourced imports?

    Require a documented source for every import, recorded at the point of import rather than reconstructed later, and give somebody authority to refuse one. That is a two-minute step that prevents the most common problem in this area, and businesses that adopt it are usually surprised how many proposed imports cannot answer the question. Businesses adopting it are usually surprised how many proposed imports cannot answer the question.

  • What should we audit right now?

    Four things. Where every contact on your list came from and whether you can evidence it. Whether your platform respects the permitted hours window. Whether unsubscribes suppress at send time. And whether your unsubscribe link works from a phone without a login. That is an afternoon and it covers most of the exposure. That is an afternoon of work and it covers the great majority of the exposure.

  • Is any of this actually enforced?

    The regulator states that it monitors compliance through regular reporting and mandates strict action against entities sending messages without prior consent, and it publishes an administrative penalty range. Beyond enforcement, complaints damage sender reputation with the platforms and networks, which quietly reduces how many of your messages arrive at all. Complaints also damage sender reputation, which quietly reduces how many messages arrive at all. The restriction attaches to the message being marketing, not to how it happened to be triggered.

  • Who should own this internally?

    Marketing, with a written process, since marketing controls the sends and owns the list. The failure mode is that compliance is treated as somebody else's function while the actual decisions, which list to send to and when, are made by whoever is running a campaign that week. One owner and one documented process removes most of it. One owner and one documented process removes most of the exposure at almost no cost.

  • What about our sales team calling prospects?

    Outbound calling engages the Do Not Call Register and the wider framework, so it is not outside scope because it feels like a conversation rather than a campaign. Any business calling at scale needs a reconciliation process and a record of where numbers came from, on the same basis as messaging. Any business calling at volume needs a reconciliation process and a record of where numbers came from.

  • Does business-to-business marketing have different rules?

    The framework concerns electronic communications to recipients rather than turning solely on the recipient being a consumer, and the boundary is a question for your adviser. The practical position is that mobile numbers and personal work email addresses belong to individuals regardless of who pays their salary, and treating business contacts as unrestricted is a weaker assumption than it looks. Treating business contacts as unrestricted is a weaker assumption than it appears at first.

  • Can you help with this?

    On the technical side, yes. Reviewing where your list came from and whether consent is evidenced, checking your platform against the permitted hours and unsubscribe requirements, and building suppression and source-tracking into your systems starts from around AED 2,500 with us. Final pricing depends on scope, and these are our own figures rather than a market survey. Final pricing depends on scope and these are our own figures rather than a market survey.

  • Where should we check the current rules?

    The telecoms regulator publishes the unsolicited electronic communications regulatory policy and material on the Do Not Call Register directly, and those are the authoritative version rather than any summary including this one. Requirements are revised, and a business acting on stale guidance carries the consequence rather than whoever wrote the summary. A business acting on stale guidance carries the consequence rather than whoever wrote the summary.

SKIMBOX Team

Tech Consultancy

Get fresh writing in your inbox

One email a fortnight. No filler.

By subscribing, you agree to our privacy policy.

Want us to build something?

We work with teams across MENA, UK, USA, and India to build products, run programs, and grow.

Get in touch

Continue reading