HomeBlogWhatsApp marketing rules in the UAE: what actually applies
🛡️ Compliance

WhatsApp marketing rules in the UAE: what actually applies

Most of what is written about this online applies to SMS. Here is what governs a WhatsApp message sent to someone in Dubai — and what you have to do about it.

A Dubai retailer asked us last month whether they needed a registered sender ID and an AD- prefix for their WhatsApp broadcasts. They did not — those rules belong to SMS. But while they were solving a problem they did not have, they were sending marketing to a list of numbers collected from a supplier, with no consent record and no working opt-out. That is the real exposure, and it is the one nobody writes about.

Search for WhatsApp compliance in the UAE and you will find a lot of pages promising "TDRA-compliant WhatsApp marketing", usually with a checklist about sender IDs and the AD- prefix. Almost all of it is wrong, and wrong in a specific way: it takes the rules written for SMS and applies them to a channel they were never written for.

That matters, because while people are busy worrying about the wrong regulation, the one that does apply to them — the UAE's Personal Data Protection Law — gets ignored. This is an attempt to lay out what actually governs a WhatsApp message sent to someone in the UAE, and what a business has to do about it.

⚡ Short answer

Three things govern your WhatsApp messaging in the UAE, and only three: the PDPL (because you are processing personal data), Meta's own Business Messaging Policy (because it is their platform and they enforce it hard), and your customer's patience (because block rates are the thing that actually shuts accounts down). TDRA's marketing SMS rules are about SMS.

The TDRA myth, cleared up

The Telecommunications and Digital Government Regulatory Authority regulates telecom services in the UAE. Its policy on unsolicited electronic communications and its marketing SMS initiative govern messages sent through licensed telecom operators — Etisalat, du, Virgin Mobile. That is where the familiar requirements come from: registered sender IDs capped at eleven characters, the mandatory AD- prefix on promotional messages, restricted sending hours, the Do Not Call Registry.

WhatsApp does not travel over that network. It is an over-the-top service — your message goes over the internet to Meta's servers and down to the recipient's app. TDRA's SMS framework, read plainly, is scoped to licensees and SMS. There is no AD- prefix on WhatsApp. There is no sender ID to register. A provider selling you a "TDRA-approved WhatsApp sender ID" is selling you something that does not exist.

None of which means you can do as you like. It means the constraints come from somewhere else.

🧭 Worth borrowing anyway

TDRA restricts marketing SMS to daytime hours. That rule doesn't bind WhatsApp — but a promotional message landing on a Dubai phone at 11pm will get you blocked regardless of what any regulator says. The rule is a good description of what UAE consumers already expect. Sending between roughly 7am and 9pm Gulf time is simply good practice.

What the PDPL actually requires

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data — the PDPL — came into force on 2 January 2022. It is channel-agnostic. It does not care whether you reach someone by email, SMS, phone call or WhatsApp; it cares that you are processing personal data about an identifiable person, and a mobile number attached to a name and a purchase history is exactly that.

The core of it, as the UAE government describes it, is that the law prohibits processing personal data without the consent of its owner, save for a narrow set of exceptions such as legal obligations or protecting a public interest. For marketing, no exception saves you. Consent is the basis, and the burden of proving it sits with you.

In practice that translates into four obligations that are easy to state and, in our experience, rarely implemented:

  • Collect consent that is specific and demonstrable. Not "they bought from us so they're a customer". A clear, unambiguous action where the person agreed to receive messages from you.
  • Keep the record. When they consented, through what — a checkout checkbox, a QR code scan, a WhatsApp opt-in reply — and against which number. If you cannot produce it, you did not have it.
  • Honour withdrawal. Consent can be pulled at any time, and it has to be as easy to withdraw as it was to give. On WhatsApp that means STOP works, immediately, permanently.
  • Support the other rights. Access, correction, deletion, restriction of processing. Someone can ask what you hold about them and ask you to remove it.

Two further points that catch UAE businesses out. If your customer data leaves the country — and it does, the moment you use a platform hosted abroad — cross-border transfer rules apply, and you should know where your provider stores data. And if you are set up in DIFC or ADGM, those free zones have their own data protection regimes that operate alongside the federal law, generally with stricter and more detailed obligations.

We are describing the shape of the law, not giving legal advice. If you process data at scale, or handle anything sensitive such as health records, have a UAE lawyer look at your specific setup.

Meta's rules, which bite faster than any regulator

Here is the uncomfortable truth: the thing most likely to stop your WhatsApp messaging is not a fine. It is Meta switching you off.

Meta requires opt-in before you send a template message to anyone, and it requires that the person understood what they were agreeing to and from which business. It reviews every marketing template before it can be used. And it watches, continuously, how people react to you.

That last part runs on a quality rating. Blocks and "report" taps push it down. Drop far enough and your messaging tier falls — the cap on how many unique customers you may message in 24 hours — and in a bad case the number is restricted outright. There is no appeal queue that gets you a same-day answer. We have watched businesses lose a number that had years of customer history on it, and the cause was almost always the same: a bought list, or a broadcast to people who had no idea who was writing.

This is why the compliance question and the marketing-performance question are the same question in the UAE. A list you did not earn will cost you the number.

Consent, opt-out and sending hours, built in

QuickWA keeps a consent log against every contact, handles STOP automatically and permanently, and ships with a sending window so scheduled broadcasts only go out during UAE-appropriate hours. Billed in AED, from AED 99/month.

Start free trial →

Getting opt-in right in a UAE context

Opt-in does not have to be a legal form. The good ones are practical and barely noticeable:

  • Checkout. A checkbox at the point of purchase — "Send me my order updates and offers on WhatsApp" — with the number and the fact you'll message clearly stated. Pre-ticked boxes do not count.
  • The customer messages first. A QR code on a receipt, a chat button on your site, a Click-to-WhatsApp ad. When someone starts the conversation, intent is unambiguous and you have a 24-hour window to be useful in.
  • In-chat confirmation. Ask once, plainly: "Would you like offers and new arrivals on WhatsApp? Reply YES." Store the reply. It is the cleanest record you will ever have.
  • Walk-in. A card at the till with a QR code and one line of explanation works better in a Dubai shop than any form.

What does not count, whatever a lead vendor tells you: a purchased database, numbers scraped from Google Maps or property portals, a list inherited when you bought the business, or every number that ever called your landline. In the UAE market these lists are sold constantly and cheaply. They are the fastest way to lose a WhatsApp number.

Arabic, and the bit people forget

If you are messaging Arabic-speaking customers, the opt-out has to work in Arabic too. Telling someone to "reply STOP" in an Arabic message is a poor experience and arguably not a genuine mechanism. Accept the Arabic equivalents, publish the instruction in the language of the message, and make sure your platform actually processes it rather than filing it as an unread chat.

The same goes for your privacy notice. If you market in Arabic, the explanation of what you do with someone's data should be available in Arabic. It is a small thing that signals you are a local business rather than a foreign list-buyer, which in this market is worth more than the compliance points it earns.

A practical checklist

  • Every number on your list can be traced to a moment of consent you can produce.
  • STOP — and its Arabic equivalent — is honoured immediately and permanently, not just marked read.
  • Marketing goes out between about 7am and 9pm Gulf time. Transactional messages can go whenever they are genuinely useful.
  • Utility templates are written as utility: specific, transactional, no offer bolted onto the end.
  • You know where your customer data is stored, and whether it leaves the UAE.
  • Someone in your team watches the quality rating weekly, not after something breaks.
  • Your privacy notice exists, is reachable, and is in the languages you market in.
  • If you are in DIFC or ADGM, someone has checked the free-zone regime as well as the federal one.

The bottom line

The regulation that governs your WhatsApp messaging in the UAE is the PDPL, not TDRA's SMS framework — and the enforcement you will feel first is Meta's, not any regulator's. Both point the same direction: message people who asked to hear from you, let them leave easily, and keep the receipts. Businesses that treat that as a constraint find WhatsApp expensive and fragile. Businesses that treat it as the operating model end up with a channel their customers actually read.

Frequently asked questions

Do TDRA rules apply to WhatsApp marketing in the UAE? +
Not in the way most articles claim. TDRA's marketing SMS framework — registered sender IDs, the AD- prefix, the Do Not Call Registry — governs messages sent through licensed UAE telecom operators. WhatsApp is an over-the-top service that does not use that network, so there is no sender ID to register and no prefix to add. What does apply to WhatsApp is the PDPL, because you are processing personal data, and Meta's own messaging policy.
Is the UAE PDPL relevant to WhatsApp messages? +
Yes. Federal Decree-Law No. 45 of 2021 came into force on 2 January 2022 and is channel-agnostic — it governs the processing of personal data regardless of how you reach the person. A mobile number tied to a name and purchase history is personal data. In practice that means consent before marketing, a record you can produce, an easy way to withdraw, and support for access and deletion requests.
Can I message a list I bought from a data vendor? +
No, and it is the single fastest way to lose your number. Those contacts never consented to hear from you, which fails the PDPL test, and it also breaches Meta's opt-in requirement. What actually happens is mechanical: people block and report, your quality rating falls, your messaging tier drops, and eventually the number is restricted. Businesses in the UAE lose numbers this way regularly.
What time can I send WhatsApp marketing in the UAE? +
No regulation sets WhatsApp hours the way TDRA sets them for SMS. But the practical answer is roughly 7am to 9pm Gulf time. A promotional message at 11pm will be blocked and reported at a much higher rate whatever the law permits, and blocks are what cost you the account. Transactional messages — a delivery update, an appointment reminder — are judged differently and can go when they are genuinely useful.
Does my customer data have to stay in the UAE? +
The PDPL does not require it in all cases, but it does place conditions on transferring personal data outside the country, and you are expected to know where your data goes. Most WhatsApp platforms are hosted abroad, so ask your provider where data is stored and processed before you sign. Businesses licensed in DIFC or ADGM should also check the free-zone regime, which sits alongside the federal law.