Call recording laws in the UAE: onshore, DIFC, and ADGM rules for call centres

By Adnan Bassem — Founder, InfoDriven (Dubai). Building Arabic-first speech recognition for GCC call centers.Published June 10, 2026

ComplianceLast updated: June 10, 2026

Is it legal to record customer calls in the UAE?

Yes, for legitimate business purposes with proper disclosure. UAE contact centres routinely record calls, and for licensed telecom operators the TDRA actually mandates it on key interactions. The compliance question is jurisdictional: a voice recording that identifies a natural person is personal data, and which data-protection law governs it depends on where the controller is established — onshore mainland, the Dubai International Financial Centre (DIFC), or Abu Dhabi Global Market (ADGM).

Two cautions frame everything else. First, UAE law has historically treated covert recording of private conversations seriously — the safe and standard posture for any call centre is an explicit recording notice to all participants at the start of every recorded call, never silent recording. Second, the "may be recorded" notice is the floor, not the ceiling: the lawful basis, purpose limitation, retention, and transfer obligations under the applicable data-protection regime all still apply after the beep. Where a use case goes beyond quality assurance and dispute resolution — biometric voice analysis, AI training, marketing profiling — get specific advice before relying on the standard notice.

Which law applies — federal PDPL, DIFC, or ADGM?

The federal Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) was issued on 26 September 2021 and entered into force on 2 January 2022, with the UAE Data Office established to oversee controllers and processors. It applies to onshore-mainland processing and to processors handling onshore data. It requires a lawful basis for processing, data-subject rights (access, rectification, erasure, restriction, portability), breach notification, and DPIAs for high-risk processing — and large-scale call recording is high-risk processing.

The DIFC Data Protection Law No. 5 of 2020 is GDPR-aligned and operates inside the DIFC free zone with its own Commissioner of Data Protection; it applies independently of the federal PDPL for DIFC-established controllers. The ADGM Data Protection Regulations 2021 similarly operate inside Abu Dhabi Global Market with an independent Office of Data Protection. A UAE group can easily be subject to two or all three regimes at once — a mainland-licensed contact centre serving a DIFC-registered fintech parent, for example — so map each legal entity that controls call recordings to its regime before writing the compliance policy. Both DIFC and ADGM treat EU jurisdictions as adequate for cross-border transfer in most cases, and the federal PDPL accepts transfers with appropriate contractual safeguards, which is why an EU-hosted processing posture with a solid DPA is the common-denominator arrangement.

What do TDRA rules require from licensed operators?

The Telecommunications and Digital Government Regulatory Authority (TDRA, formerly TRA) Telecommunications Consumer Protection Regulations (Version 3.0, 2022) require licensed operators to record customer-care calls relating to service activation, contractual changes, and complaints, with retention of at least one year for general calls and longer for disputed transactions. That is a recording mandate, not just a permission — the operator must be able to retrieve the call when a billing or contract dispute lands.

Even for non-operators, the TDRA baseline is a useful design pattern: record the transactional and complaint interactions, keep them at least a year, keep disputed-transaction calls longer, and make retrieval fast. CallScribe sits downstream of this infrastructure as the transcription and search layer — recordings stay in your TDRA-compliant recording platform, and full-text-searchable transcripts make the "retrieve the disputed call from last March" exercise a seconds-long search rather than a manual trawl.

What extra retention rules apply to financial firms? DFSA, FSRA, and CBUAE

Financial-services firms carry the heaviest overlays. DFSA Conduct of Business module COB Rule 3.4.6 requires authorised firms to record and retain telephone communications relating to client orders for a minimum of six years; similar windows apply under FSRA conduct rules in ADGM. The Central Bank of the UAE (CBUAE) adds consumer-protection and telephone-marketing recording obligations for its licensees onshore.

The practical consequences: per-category retention (a DIFC brokerage keeps client-order calls six years even if general support calls are kept one year), strict access controls with audit logs regulators can inspect after the fact, and prompt retrieval for investigations. Mis-selling and suitability reviews also depend on the recordings being analysable — a six-year archive of Arabic-English code-switched sales calls is only useful to compliance if it is searchable, which is precisely the transcription use case.

What are the penalties for getting call recording wrong in the UAE?

Exposure comes from several directions at once. Under the federal PDPL, administrative penalties are set through the executive-regulation framework overseen by the UAE Data Office; the DIFC Commissioner of Data Protection and the ADGM Office of Data Protection each have their own fining and direction powers under their respective laws, and both have shown willingness to use them. TDRA can act against licensed operators on consumer-protection grounds, and DFSA / FSRA enforcement against record-keeping failures is a standing feature of financial-services supervision.

Beyond fines, the operational risks are concrete: recordings made without proper notice may be challenged when offered in a dispute; a breach involving voice data triggers notification obligations; and covert recording of private conversations can carry criminal exposure under UAE law. We deliberately avoid quoting specific fine amounts here — they differ by regime and are revised over time — so treat penalty sizing as a question for counsel, and treat the architecture (notice, lawful basis, retention, access logs) as the part you control.

UAE call-recording compliance checklist

A starting inventory for auditing an existing UAE call-recording operation across onshore, DIFC, and ADGM entities. Practitioner checklist, not legal advice.

  • Map every legal entity that controls recordings to its regime: federal PDPL, DIFC DP Law 5/2020, ADGM DP Regulations 2021 — or a combination
  • Recording notice plays to all participants before the agent connects, in Arabic and English, naming the purposes
  • Lawful basis documented per call category; DPIA completed for large-scale recording and AI analytics
  • TDRA retention baseline met where applicable: one year minimum for general operator calls, longer for disputed transactions
  • DFSA COB 3.4.6 / FSRA six-year windows configured for client-order calls at regulated entities
  • Cross-border transfer mechanism documented for any storage or processing outside the UAE (EU adequacy under DIFC/ADGM rules; contractual safeguards under federal PDPL)
  • Processor DPAs signed with transcription and analytics vendors, with sub-processor disclosure and breach-notification terms
  • Health-data exception checked: UAE Federal Law No. 2 of 2019 generally requires in-UAE processing for health data — different architecture
  • Transcript access logged append-only; PII redacted from searchable transcripts
  • Data-subject rights workflow tested end-to-end: access, export, erasure of a named caller's recordings and transcripts

Sources

  1. UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data; UAE Data Office
  2. DIFC Data Protection Law No. 5 of 2020; Commissioner of Data Protection
  3. ADGM Data Protection Regulations 2021; Office of Data Protection
  4. UAE TDRA Telecommunications Consumer Protection Regulations, Version 3.0 (2022)
  5. DFSA Rulebook, COB module, Rule 3.4.6 (six-year retention for client-order calls)
  6. UAE Federal Law No. 2 of 2019 on the Use of ICT in Health Fields (in-UAE storage for health data)

Frequently asked questions

Is the UAE a one-party or two-party consent jurisdiction for call recording?

Neither framing maps cleanly. UAE practice is notification-driven: announce the recording to all participants at the start of the call and establish a lawful basis under the applicable data-protection regime. Covert recording of private conversations carries legal risk under UAE law, so all-participant disclosure is the only sensible operating posture for a call centre.

My company is in the DIFC — does the federal PDPL still apply?

For processing carried out by the DIFC-established controller, the DIFC Data Protection Law No. 5 of 2020 applies with its own Commissioner, independently of the federal PDPL. But group structures rarely stay inside one regime — a mainland operating entity or an ADGM affiliate brings its own law with it. Map entity by entity rather than assuming one regime covers the group.

How long do UAE call centres need to keep recordings?

TDRA rules set at least one year for licensed-operator customer-care calls, longer for disputed transactions. DFSA COB 3.4.6 requires six years for client-order calls at DIFC-authorised firms, with FSRA equivalents in ADGM and CBUAE obligations onshore. Non-regulated businesses should set a defensible window tied to purpose — commonly one to two years for QA — and document it.

Can UAE call recordings be processed on EU servers?

In most cases yes. DIFC and ADGM both treat EU jurisdictions as adequate for cross-border transfer in most cases, and the federal PDPL accepts transfers with appropriate contractual safeguards in a DPA. The main exception is health data under Federal Law No. 2 of 2019, which generally requires in-UAE storage, and government procurements that mandate in-region processing — for those, GCC-resident worker nodes or in-UAE enterprise deployment is the answer.

Does a "this call may be recorded" IVR message satisfy the UAE PDPL by itself?

It satisfies the notification element, not the whole law. You still need a documented lawful basis, purpose limitation (do not reuse QA recordings for unrelated purposes without revisiting the basis), retention limits, transfer safeguards, processor contracts, and a working data-subject rights process. The notice is the visible 10% of the compliance posture.

Test it on your own Arabic calls

Dialect-aware transcription with diarization and sentiment — built for GCC call centers.

Try CallScribe free →

5 min/mo free · No credit card