How to Choose a Web Design Company in Dubai
What to ask a Dubai web design company, what a proposal must contain, who owns what, and how to verify reviews and a trade licence.
Read the guideCompliance
What the UAE's personal data law means for your contact forms, tracking tags, privacy policy, hosting and breach plans, checked against the official text.
Under the UAE’s personal data law, a business website must collect only the personal data it needs, get clear consent that can be proved and withdrawn (unless another legal basis applies), tell visitors why their data is collected and who it is shared with, keep it secure, and be ready to report a breach. Companies in the DIFC and ADGM follow their own free zone data protection rules instead.
In short:
This article is general information about UAE data protection rules as they apply to websites. It is not legal advice. Check your own position with a qualified adviser.
The law is Federal Decree by Law No. (45) of 2021 Concerning the Protection of Personal Data, usually called the PDPL. According to the UAE’s official legislation portal, it was issued on 20 September 2021, published in the Official Gazette on 26 September 2021, and came into effect on 2 January 2022. The portal notes that its English version is a translation and the Arabic text prevails in case of conflict.
Several of its definitions matter for websites. Personal data covers anything that identifies a person directly or indirectly, with examples including name, image, identification number, electronic identifier and geographical location. Consent must be specific, clear and unambiguous, given through a clear positive statement or action, which a pre ticked box is not.
Article 2 sets the scope. It covers data subjects in the UAE, controllers and processors in the UAE processing data of people inside or outside the country, and controllers and processors abroad processing data of people in the UAE. It then excludes, among others:
The two best known free zone regimes are in the financial centres. The DIFC Commissioner of Data Protection supervises and enforces the Data Protection Law, DIFC Law No. 5 of 2020, which DIFC says was enacted in May 2020. DIFC entities must submit a data protection notification at incorporation and when there are changes, and DIFC provides a personal data breach reporting form.
In Abu Dhabi, ADGM issued its Data Protection Regulations 2021 on 14 February 2021, replacing the 2015 regulations. Its Office of Data Protection maintains the register of data controllers, enforces their obligations and handles data breach notifications.
The UAE Government’s data protection page also lists Federal Law No. 2 of 2019 on the use of information and communication technology in health fields, among other laws. For a clinic or pharmacy, patient data may fall under health legislation, a question for a lawyer rather than a web agency.
| Your business | Main regime to check | Official source |
|---|---|---|
| Mainland company in Dubai or elsewhere in the UAE | Federal Decree by Law No. 45 of 2021 (PDPL) | uaelegislation.gov.ae |
| Company registered in DIFC | DIFC Data Protection Law No. 5 of 2020 | difc.com |
| Company registered in ADGM | ADGM Data Protection Regulations 2021 | adgm.com |
| Company in another free zone | Depends on whether that zone has its own data protection legislation | Your free zone authority |
| Healthcare provider | Health sector legislation may apply to patient data | Your regulator and adviser |
Online guides disagree here, so this is only what the official sources show. Article 28 required the Council of Ministers to issue executive regulations within six months of the decree. Article 29 gives controllers and processors up to six months from the date those regulations are issued to bring themselves into compliance, extendable once. Article 26 says violations and administrative penalties will be set by a Council of Ministers decision.
When we checked on 13 September 2026, the official legislation portal’s related legislation list for the PDPL did not include executive regulations or a penalties decision, and the UAE Government’s data protection page, last updated in December 2025, did not mention them either. Some commercial websites say the regulations have been issued; we could not confirm that officially.
The honest position: the decree is in force, but the detail on timings, exemptions and penalties hangs on regulations we could not find on an official source. Build good practice now rather than waiting for a deadline.
The breach notification period, the exemption criteria and the transfer conditions all depend on those regulations, so check the current status with your adviser before relying on any timeline. The principles in Articles 5, 6 and 20 are already in the decree.
Contact, quote and booking forms are where most small UAE websites collect personal data. Article 4 prohibits processing without consent, with exceptions, one of which is processing necessary to take steps at the data subject’s request with the aim of concluding a contract. Replying to someone who asked you for a quote arguably fits that. Adding them to a marketing list does not, and Article 17 gives people the right to object to processing for direct marketing.
Article 6 sets the conditions for valid consent: the controller must be able to prove it, it must be clear, simple and easily accessible, and it must include the right to withdraw it easily.
Article 5 requires personal data to be collected for a specific and clear purpose, and to be sufficient and limited to what is necessary for that purpose. It also says data should not be kept after the purpose has been exhausted, unless anonymised.
One issue we often see is the quote form that grew over years of marketing requests: date of birth, nationality, budget, a file upload, three phone fields. Every field is data you must secure, explain and eventually delete. For most service businesses, a first enquiry needs a name, one contact method and the question. Shorter forms also tend to be easier to complete on a phone, which matters for the landing pages behind paid campaigns.| Field | Keep, drop or make optional | Reason |
|---|---|---|
| Name | Keep | Needed to reply |
| Phone or email | Keep at least one | Needed to reply; let the visitor choose |
| Message or service required | Keep | The purpose of the enquiry |
| Date of birth, nationality, Emirates ID | Drop | Rarely needed for a first enquiry; identification numbers are named in the definition of personal data |
| Health details on a clinic form | Drop from open forms | Health data is sensitive personal data under the decree; collect it through the clinical system instead |
| File upload | Only if essential | Uploads often contain far more personal data than intended |
Set a retention rule too. Decide how long unconverted leads stay in the CRM and delete or anonymise them after that.
The PDPL does not mention cookies by name. It does, however, include electronic identifiers and location in its definition of personal data, and advertising pixels and analytics cookies work by setting or reading identifiers. The cautious approach for a UAE website is to hold non essential tags until the visitor agrees, and to offer a genuine choice to decline.
Google’s consent mode lets tags adjust their behaviour to the visitor’s choice, using consent types including ad_storage, analytics_storage, ad_user_data and ad_personalization. In basic consent mode, Google says no data is sent before a user consents. In advanced consent mode, tags load with consent denied by default and send cookieless measurements when consent is denied. Choose deliberately and write the choice into your privacy policy.
Two GA4 settings are worth checking. Google states that IP addresses are not logged or stored in GA4. And standard GA4 properties let you set data retention for user level and event level data to 2 months or 14 months. Pick the shorter period unless you genuinely analyse older data.
Meta documents a consent control for the pixel: calling fbq('consent', 'revoke') pauses pixel fires, and fbq('consent', 'grant') resumes them once the visitor agrees. Also check whether advanced matching is on. Meta’s documentation shows it can send details such as email, phone number, name and city with conversion events, and that values passed through the base code are hashed automatically by the pixel using SHA 256. Hashed data is still derived from personal data, so disclose it.
Check the tag manager and page source for analytics, advertising, chat and heatmap scripts, including old ones.
Strictly necessary, analytics or advertising.
Hold analytics and advertising tags behind a consent tool, using consent mode for Google and revoke and grant for Meta.
Decline in a fresh browser and confirm in the network panel that the tags behave as chosen.
Article 13 gives people the right to request information including the types of data processed, the purposes, automated decisions, who data is shared with inside and outside the UAE, retention standards, how to correct or erase data, cross border protections, breach measures and how to complain to the UAE Data Office. It also says that before processing starts, the controller must provide the purposes, the sectors or establishments the data is shared with, and the protections for cross border processing. A website privacy policy is the natural place to do that.
Do not copy another business’s policy. One that lists tools you do not use, or omits those you do, is not transparent.
Many UAE websites are hosted in Europe or the United States, and the CRM, email platform and form tools often sit elsewhere again. The decree defines cross border processing as including storage, transmission and processing of personal data outside the State. Article 22 allows transfers, in cases approved by the UAE Data Office, where the destination has adequate data protection legislation or an agreement with the UAE applies. Article 23 adds other routes, including a contract imposing the decree’s protections, the data subject’s explicit consent, or necessity for a contract with the data subject.
Questions to put to your web team and each provider:
Online stores add payment and shipping integrations, so map those before an ecommerce website launches.
Article 9 requires the controller to notify the UAE Data Office of a breach within the period set by the executive regulations, describing the breach, its likely effects and the corrective measures. Affected data subjects must also be told, and processors must tell the controller as soon as they become aware. Article 20 requires appropriate technical and organisational security, including encryption and pseudonymisation, and the ability to restore access to data after a failure.
For a typical company website, readiness looks like this:
If you run a healthcare practice, the stakes are higher because health data is sensitive personal data under the decree. Our notes on clinic website design cover how to keep booking forms light.
Mainland PDPL, DIFC, ADGM, another free zone, or a sector law.
Every form, tag and integration, and where each sends data.
Remove unneeded form fields and set a retention period for leads.
Unticked marketing consent, stored proof, easy withdrawal, tags held until agreement.
Accurate to your real tools, recipients and locations, in every site language.
Locations, processing agreements and the basis for any transfer abroad.
Security basics, tested backups and a one page breach plan.
After every new plugin or integration, and when the executive regulations appear officially.
Much of this is web work rather than legal work. When Codeeo launches a site, conversion tracking is part of the launch, and we set it up with the consent choices agreed with you. If your current site has years of forms and tags nobody fully understands, a website redesign can be the cleanest point to reset it. To talk through your site, contact our Dubai team for a fixed written quote, scoped to you, and bring your adviser’s view on which law applies.
Straight answers
The decree applies to controllers and processors in the UAE that process personal data, and a contact form that collects names and phone numbers is processing. Article 3 lets the UAE Data Office exempt some establishments that do not process a large volume of personal data, but only under standards set by the executive regulations. Until you have confirmed an exemption applies to you, plan as if the law does.
The PDPL excludes companies in free zones that have their own personal data protection legislation. DIFC has its own Data Protection Law and ADGM has its own Data Protection Regulations. Other free zones need checking individually, because the exclusion depends on whether the zone has its own data protection rules. Ask your free zone authority or legal adviser.
The PDPL does not mention cookies by name. It does define personal data to include electronic identifiers and location, and it prohibits processing without consent unless an exception applies. If your tags use identifiers to track or advertise to visitors, asking for consent first is the cautious approach, and it is also what many overseas visitors will expect.
Hosting abroad means personal data is processed outside the State, which the decree treats as cross border transfer. Articles 22 and 23 set the conditions, such as the destination having data protection legislation, a contract imposing equivalent protections, or the explicit consent of the data subject. Confirm which basis you rely on before choosing a host.
Article 10 requires one where processing causes a high risk because of new technologies or data volume, involves systematic assessment of sensitive personal data including profiling, or covers a large volume of sensitive personal data. A clinic or a business handling health or biometric data should look at this closely. A typical company brochure site usually will not meet those triggers, but take advice.
Article 26 says the Council of Ministers will issue a decision setting out the violations and administrative penalties. We could not find that decision published on the official UAE legislation portal when this article was checked on 13 September 2026, so we do not quote any penalty figures. Check the current position with a legal adviser.
Sources
Photo: Yourusernamewillbepublic2, CC0, via Wikimedia Commons
Fixed price, in writing
Got it. Your quote is being written now.
In business hours you will have it within 45 minutes. Check your inbox for the confirmation.
Keep reading

What to ask a Dubai web design company, what a proposal must contain, who owns what, and how to verify reviews and a trade licence.
Read the guide
LCP, INP and CLS explained for UAE business owners, with Google's thresholds and the speed fixes that matter most, in priority order.
Read the guide
Right to left layout, Arabic fonts, hreflang, transcreation and CMS setup: what a proper Arabic and English website in the UAE needs.
Read the guide