PDPL and UAE Decree-Law 45: The Compliance Checklist Before You Switch On an AI Voice Agent

TL;DR
Before launch, settle six things: a lawful basis and recorded consent, a spoken recording notice, where audio is processed and stored, how long transcripts are kept, a signed processing agreement with your vendor, and clear limits for sensitive sectors such as healthcare.
Why this is a data question, not an IT question
A voice agent is not a phone system with a nicer greeting. It captures audio, converts it to text, extracts personal details, writes them into a CRM and often triggers follow-up messages.
That means every call creates personal data about an identifiable individual. In Saudi Arabia that falls under the Personal Data Protection Law, supervised by SDAIA. In the UAE it falls under Federal Decree-Law 45 of 2021, with sector rules on top in free zones such as the DIFC and ADGM. Both frameworks rest on the same ideas: a lawful basis, transparency, purpose limitation, minimisation, retention limits and accountability for whoever processes on your behalf.
The good news: a well-designed voice agent is usually easier to evidence than a human call centre, because every interaction is logged, consistent and auditable.
1. Lawful basis and consent you can produce on request
Decide, in writing, why you process each type of data and on what basis.
- Booking an appointment a customer requested is straightforward, and generally rests on performing the service.
- Recording the call, keeping the transcript, and later marketing to that person are separate purposes that usually need their own consent.
- Consent must be informed, specific and withdrawable, and you must be able to show when and how it was given.
Practical implementation: capture consent at the point of contact — the web form, the click-to-WhatsApp ad, the in-clinic form — with a timestamp stored against the contact record, and a one-word opt-out that works permanently.
2. A recording notice the caller actually hears
If calls are recorded, say so at the start, in the caller's language, before anything sensitive is discussed. Two rules we apply by default:
- The notice is the first thing in the greeting, in Arabic and English, not buried after a menu.
- If the caller objects, the agent can continue without retaining the recording, or hand over to a human.
A transcript with no notice is a liability. A transcript with a clear notice is an asset — it is how you prove what was promised on a call.
3. Where the audio is processed and stored
This is the question most vendors answer vaguely, and the one regulators and enterprise buyers ask first.
Ask for it in writing: in which country is speech recognised, where is the audio stored, where do transcripts live, which subprocessors touch the data, and does anything leave the country. For customers in the Kingdom and the UAE we process voice calls, recordings and transcripts on infrastructure inside the respective country, and keep CRM and automation data in encrypted cloud infrastructure under approved transfer safeguards. The full description is on our Data Security page.
If a vendor cannot draw you that map on one page, treat the answer as no.
4. Minimisation and retention, decided before launch
Two settings prevent most future problems.
Collect less. For nearly every business, the agent needs a name, a contact number, an email, and what the customer wants. It does not need Emirates ID or Iqama numbers, card details, or clinical history — so configure it never to ask, and to redact if a caller volunteers them.
Keep it for a defined period. Set an explicit retention window for audio and a separate one for transcripts and CRM notes, tied to a business reason such as dispute handling or accounting. Then automate deletion. "We keep everything forever, just in case" is the most common finding in any audit — and the least defensible.
5. Contracts with whoever processes for you
You remain the controller of your customers' data. The vendor is a processor, and that relationship must be documented:
- A data processing agreement covering purpose, scope, security measures, subprocessors, breach notification timelines, audit rights and deletion on termination.
- Standard contractual clauses or an equivalent safeguard for any cross-border flow.
- A named contact for data subject requests — access, correction, deletion — and an internal service level for answering them.
Ask for these before signing, not after your first incident.
6. Sensitive sectors need a harder boundary
Healthcare is where most projects go wrong, and where the fix is simple: separate acquisition from records.
Use the AI agent to capture new patient enquiries, confirm identity minimally, book and remind. Keep clinical data in the hospital or clinic's own EMR or EHR, and do not mirror it into the marketing stack. Diagnoses, results and treatment history stay inside the medical system.
Similar logic applies in finance and legal services: the agent qualifies, schedules and routes; the regulated record stays in the regulated system. Our Industries pages describe how this split is configured per sector.
The pre-launch checklist
Print this and tick it before your agent takes a live call.
- Documented purposes and lawful basis for each data type
- Consent captured with timestamp, and a working opt-out
- Recording notice in the greeting, in Arabic and English
- Written map of processing and storage locations, plus subprocessors
- Fields the agent must never collect, with redaction configured
- Retention windows set for audio, transcripts and CRM notes, with automated deletion
- Signed data processing agreement and transfer safeguards
- Named owner for data subject requests, with a response deadline
- Breach process, including who is informed and how fast
- Sensitive-sector boundary defined, especially separation from EMR or EHR
None of this slows a launch by more than a few days. It does decide whether your AI channel survives its first serious question from a regulator, a hospital procurement team, or a customer who simply asks where their recording went.
This is guidance, not legal advice
Regulations evolve and sector rules differ, particularly inside financial free zones and in healthcare. Use this checklist to structure the conversation with your own legal counsel and with any vendor you are evaluating — including us.
If you want to see how the controls are implemented in practice, read our Data Security page or ask us for the processing map for your country before you commit to anything.