Most UAE marketing lists were assembled the same way: exhibition badge scans, business cards, a spreadsheet from a previous role, a form that never recorded when anybody submitted it, and an import from a source nobody can now identify.
Then a campaign goes out at eleven at night because the platform is scheduled in another timezone, from a short code nobody recognises, with an unsubscribe link that leads to a login page.
Every element of that is addressed by rules that already exist here and that most marketers have never read.
This article covers what the framework requires, why the commercial case for compliance is stronger than the compliance case, and how to repair a list built without any of it.
The rules, specifically
The telecoms regulator publishes a regulatory policy on unsolicited electronic communications and operates the national Do Not Call Register [1][2][3].
Consumers have a stated right not to receive unsolicited electronic communications, which is the principle underneath everything else [4].
Four requirements matter operationally:
Consent. Licensees must obtain the mobile customer's consent to receive marketing text messages, and that explicit consent is valid where it is written or electronic and storable [2].
Hours. Marketing messages are permitted only between 7am and 9pm UAE time [2].
Unsubscribe. Every marketing message should contain a free of charge unsubscribe option that customers can use to stop receiving such messages [2].
The register. The Do Not Call Register lets people opt out of marketing calls from specific sectors or from all sectors [1][3].
And there are penalties attached. Administrative violations and penalties are stated as ranging from ten thousand to one hundred and fifty thousand dirhams, depending on the type and nature of the violation [2].
The word that catches everybody: storable
Consent being valid where it is written or electronic and storable is the requirement that most businesses fail without knowing it.
It means you need a record you can produce, not a belief that somebody agreed at some point.
What satisfies it: a timestamped database entry showing who consented, when, through what mechanism, and to what.
What does not: a verbal yes at an exhibition. A business card. A conversation. A general sense that the relationship implies permission.
The test worth applying to your own list is simple. Could you produce the evidence if asked? A consent you cannot evidence is functionally identical to no consent, whatever actually happened at the time.
Which leads to the most common failure in this whole area. Businesses store the email address or the mobile number and nothing else. A year later they have a list and no way to demonstrate how any of it was obtained.
Capture four things at signup, stored together: the identifier you will message, an explicit affirmative action, what they are agreeing to receive, and a timestamp.
The hours window is an engineering problem
Seven in the morning to nine at night, UAE time.
That is a hard operational constraint, and it catches businesses in two specific ways.
Platforms scheduled in another timezone. Your marketing tool may be configured against a head office timezone, or against whatever the default was when somebody set it up. Check what it is actually doing rather than assuming.
Behaviour-triggered messaging. An abandoned-cart message that fires ninety minutes after the event will eventually fire at 2am, because customers abandon carts at 2am. The restriction is on the marketing message rather than on how it was triggered.
The fix is a queue that holds anything falling outside the window and releases it at seven the following morning, which also happens to be a better send time than the middle of the night was ever going to be. It is a small piece of engineering and it is frequently missing entirely, because nobody considered that an automated flow is still a marketing message.
Transactional messages are a different category. Order confirmations, delivery updates and password resets are operational rather than promotional, and should be cleanly separated in your systems.
Where businesses get into difficulty is bundling a promotion into a transactional message. A delivery notification that also advertises a sale has arguably become marketing, and it brings the rules into play for a message that was previously outside them. Keep the two streams genuinely separate rather than treating the transactional channel as free promotional real estate.
The Do Not Call Register changes your list
Its existence means something specific for any business doing outbound calling.
A number being in your database does not tell you whether you may call it. A person may have registered an objection you know nothing about, through a route that does not involve contacting you.
So a business calling at scale needs a process for reconciling against the register rather than treating its own list as authoritative. Ask your dialler provider how they handle it, and treat a vague answer as a finding.
The same logic applies to your sales team. Outbound calling is not outside scope because it feels like a conversation rather than a campaign, and any business calling at volume needs both the reconciliation and a record of where numbers came from.
The unsubscribe that does not work
Every marketing message needs a free unsubscribe. Two words there carry weight.
Free means no premium number, no charged reply, no cost to the person exercising a right.
Every means it is not sufficient to include it in the first message of a sequence and omit it thereafter.
Beyond the requirement, there are two failure modes that produce complaints from people who genuinely tried to leave.
The unsubscribe that requires a login. A link leading to a preference centre demanding account credentials the person does not have is functionally a refusal. Test your own flow from a phone, as an ordinary recipient, rather than assuming it works because somebody configured it.
Suppression at export rather than at send. Businesses running campaigns from an exported list send to a snapshot taken before the unsubscribe, so somebody who opted out on Monday receives Wednesday's campaign. That is precisely the complaint the mechanism exists to prevent.
Suppress at send time, not at export time.
And keep a permanent suppression list rather than deleting people entirely. This surprises businesses who assume the point is removal, but if you delete somebody completely, the next list import can quietly re-add them. Retaining enough to ensure you never message them again is the whole purpose. Our guide on data retention covers the general principle, and suppression is one of the cases where retaining data is the protective choice.
What a compliant setup actually looks like
Rather than a list of prohibitions, here is the shape of a programme that satisfies the requirements and performs better commercially, which are the same programme.
At collection. An unticked checkbox, separate from any other agreement, stating plainly what the person will receive and roughly how often. The record stores the identifier, the affirmative action, the stated purpose and a timestamp, in one row you could produce on request.
In the database. Every contact carries its source and its consent date. Suppression is a permanent list rather than a deletion. Transactional and marketing streams are separate, with separate consent states, so somebody who opts out of promotions still gets their delivery notification.
At send time. The platform checks the suppression list at the moment of sending rather than at export. It holds anything scheduled outside the permitted window and releases it at seven. It reconciles outbound calling against the register. Sender identification matches the brand the person signed up to.
In every message. A free unsubscribe that works in one tap from a phone, without a login, and takes effect before the next send.
On a schedule. An engagement-based expiry that removes people who have not opened anything in a defined period, and a quarterly check that the four operational controls above still work after whatever platform changes have happened in the meantime.
None of that is elaborate. It is perhaps two days of configuration and one short conversation with whoever owns the list. What makes it rare is not difficulty but that no single person is usually accountable for all five layers at once.
Where lists actually go wrong
Four sources account for nearly all of it.
Purchased lists. Consent obtained by somebody else for their own purposes is unlikely to cover your messages. Beyond the exposure, purchased lists perform badly, damage sender reputation and raise complaint rates, so the commercial case is weak before compliance enters the conversation at all.
Business cards and badge scans. Somebody handing you a card at an event has not subscribed to a campaign. The card is an invitation to make contact, not a standing permission. This is one of the most widespread assumptions in the region and one of the least defensible.
Contacts brought from a previous role. A new marketing hire arriving with a spreadsheet is importing people who consented to hear from a different company entirely.
Undocumented imports. The single riskiest habit. A list appears, somebody uploads it, and nobody records where it came from. It is invisible until a complaint arrives.
The fix for all four is one process step: require a documented source for every import, recorded at the point of import rather than reconstructed afterwards, and give somebody authority to refuse one.
Two minutes per import. Businesses that adopt it are usually surprised how many proposed imports cannot answer the question, which is exactly the point of asking it. The imports that fail the test were the ones generating your complaints.
Consent has to be specific, and unticked
Specificity. Consent to receive an order update is not consent to a weekly promotional newsletter. A single line buried in terms and conditions is a weak basis for a marketing programme.
Separate checkboxes for separate purposes are more work at signup and considerably stronger afterwards, and they also produce better lists, because people who opted in specifically to the thing you send are people who want it.
Pre-ticked boxes record an absence of objection rather than an affirmative choice. They are a poor basis if anybody examines them, and they inflate your list with people who never wanted your messages, which drags engagement down and makes every subsequent send perform worse.
Unticked is both safer and commercially better, which is an unusually convenient alignment.
Age of consent is worth a policy. There is no single stated shelf life, and consent obtained five years ago from somebody who has never engaged since is weak on both compliance and deliverability grounds. An engagement-based expiry addresses both at once.
The commercial case is stronger than the compliance case
This is the argument to use internally when somebody resists cleaning the list.
Deliverability depends heavily on engagement. A list full of people who never open drags down whether your messages reach anybody at all, including the people who actually want them.
So a smaller engaged list frequently produces more revenue than a larger disengaged one. The compliance benefit arrives as a side effect of doing the commercially correct thing.
Re-permissioning is how you get there from a list built without any of this. Send one message explaining what you send and asking people to confirm they want to keep receiving it. Keep only those who confirm.
It is painful, and the list shrinks more than anybody expects, which is exactly why it keeps being postponed.
We are not going to give you a survival percentage, because the figures in circulation come from email platform vendors with an interest in the number. What is reliably true is that the people who confirm are largely the ones who were going to buy anyway, and the ones who do not confirm were suppressing your metrics and your deliverability the whole time.
The cost of getting it wrong, in order of likelihood
Businesses assess this by imagining a regulator. That is the least likely consequence and the least expensive one.
Deliverability decay is the most likely by a wide margin, and it is entirely invisible in your reporting. Complaints and low engagement damage your sender reputation with networks and inbox providers, so a growing share of your messages stop arriving. Your open rate falls, you conclude the creative is tired, and you send more, which makes it worse. Nobody ever sees a bounce for this.
Wasted spend follows. Sending to people who never consented costs money per message and produces nothing. On a large list that is a continuing line item nobody examines, because the cost per message is small enough to escape scrutiny while the total is not.
Customer damage is next. Somebody who receives a message they did not ask for at eleven at night forms a view about your business that no campaign afterwards corrects, and a proportion of them were customers.
Platform action is a real risk for messaging apps in particular, where the platform enforces its own rules more actively than any regulator and can remove your access with limited recourse. Losing a channel you built a programme around is considerably more disruptive than a fine.
Regulatory penalties sit at the end, with a stated administrative range of ten thousand to one hundred and fifty thousand dirhams depending on the violation.
Read that ordering and the argument changes. The case for fixing this is commercial and immediate rather than legal and hypothetical, which is also the argument most likely to succeed internally.
Three frameworks, one email address
Worth mapping, because businesses satisfy one and assume the rest.
Telecoms rules govern unsolicited electronic communications: consent, hours, unsubscribe, the register [1][2].
Consumer protection law obliges suppliers to protect consumer data and refrain from using it for promotional and marketing purposes [5], which is a constraint many businesses have never encountered because it sits in an unexpected place. Our guide on consumer protection for online sellers covers it.
Data protection law governs the processing of that personal data generally. Our guide on PDPL compliance covers the framework.
Three sets of obligations attaching to one contact record. They do not substitute for each other, and the safe position across all three is explicit, evidenced, specific consent.
On messaging apps: business messaging carries the platform's own rules on top of whatever applies locally, and platform rules are frequently stricter and more actively enforced than anything a regulator does. Our guide on the WhatsApp Business API covers those requirements.
On business-to-business: the framework concerns electronic communications to recipients rather than turning solely on the recipient being a consumer, and the boundary is a question for your adviser. The practical point is that a mobile number and a personal work email address belong to an individual regardless of who pays their salary. Treating business contacts as unrestricted is a weaker assumption than it appears.
If an agency sends for you
Your position does not transfer.
The marketing is yours and the customer relationship is yours. An agency handling the sending is doing so on your behalf.
There is also a practical trap. An agency sending from its own platform may hold the consent records, which means you cannot evidence consent for your own list without asking them. Ask where those records live, confirm you can obtain them, and confirm you would still have them if the relationship ended. Our guide on getting your data out covers testing that rather than assuming.
Questions for an SMS provider, in writing: how do you handle the permitted hours window; do you reconcile against the Do Not Call Register; what consent records do you store and can I export them; how are unsubscribes processed and suppressed; and what sender identification appears?
A provider who cannot answer the first two quickly is not operating with the local rules in mind, which tells you what you need to know.
On sender identification: recipients should be able to tell who is messaging them. Messages from an unrecognisable short code asking people to click a link are indistinguishable from fraud, and are increasingly treated as such by recipients and by platforms. Use an identity matching the brand the person actually signed up to.
The afternoon audit
Four checks. Between them they cover most of the exposure.
Where did every contact come from, and can you evidence it? If the honest answer for a large share is that nobody knows, you have found the main problem and re-permissioning is the answer.
Does your platform respect the 7am to 9pm window, including for automated and triggered messages?
Do unsubscribes suppress at send time rather than at export time?
Does your unsubscribe link work from a phone without a login? Test it yourself as a recipient.
Do all four in one sitting rather than as a project, because each is a check rather than a change, and the changes that follow are mostly configuration.
Give the whole thing an owner in marketing, with a written process, since marketing controls the sends and owns the list. The failure mode is that compliance is nominally somebody else's function while the actual decisions, which list to send to and when, get made by whoever is running a campaign that week.
Enforcement is real: the regulator states that it monitors compliance through regular reporting and takes action against entities sending without prior consent [2]. But the more immediate consequence for most businesses is quieter. Complaints damage sender reputation with networks and platforms, which reduces how many of your messages arrive at all, including to the people who wanted them.
For the current rules, go to the telecoms regulator directly [1][2][3]. Requirements are revised, and a business acting on a stale summary carries the consequence rather than whoever wrote it.
If you want help, reviewing where your list came from and whether consent is evidenced, checking your platform against the hours and unsubscribe requirements, and building suppression and source-tracking into your systems starts from around AED 2,500 with us. Final pricing depends on scope, and these are our own figures rather than a market survey.
References
- TDRA, marketing short message service
- TDRA, regulatory policy on unsolicited electronic communications
- TDRA, consumer affairs
- TDRA, know your rights and responsibilities consumer guide
- UAE Government, consumer protection
- SKIMBOX, consumer protection for online sellers in the UAE
- SKIMBOX, PDPL compliance in the UAE
- SKIMBOX, WhatsApp Business API cost and setup in the UAE
- SKIMBOX, email deliverability, SPF, DKIM and DMARC
- SKIMBOX, data retention for a UAE business
- SKIMBOX, getting your data out
Requirements summarised here are published by the telecoms regulator and are revised over time; confirm the current position directly. This article is not legal advice, and questions about how the framework applies to a specific programme should go to a qualified adviser.



