If you've deployed a chatbot or AI agent on your UAE website, the cookie-and-contact-form privacy policy sitting in your footer isn't enough. An AI agent processes personal data in ways a static policy never contemplated, and Federal Decree-Law No. 45 of 2021 (the PDPL) sets specific disclosure obligations for how you tell users about it.
This guide walks through what your notice must say, clause by clause, for a business operating in Dubai or anywhere else in the Emirates.
Key Takeaways
- A generic privacy policy fails PDPL requirements — An AI agent needs a dedicated privacy notice that names the agent, states the lawful basis for each data category, and identifies the third-party LLM it calls.
- Federal Decree-Law No. 45 of 2021 applies — This is the UAE's federal PDPL baseline. DIFC- and ADGM-registered businesses must layer their own free-zone data-protection regime on top of it.
- Chat messages and inferences count as personal data — Typed messages, uploaded files, and any inferences the model draws are personal data under the PDPL, and each needs its own stated purpose and lawful basis.
- Notices need a minimum age and deletion process — If children under 13 can reach the agent, state a minimum age of 13, confirm you don't knowingly collect their data, and describe how a parent can request deletion.
- Material changes require an updated notice first — Switching LLM provider, adding voice input, or extending retention all require a notice update and an active in-agent re-notification before the change goes live, not after.
Why a Generic Website Privacy Policy Falls Short for an AI Agent
A standard website policy was written for cookies, contact forms, and newsletter sign-ups. An AI agent does something different: it collects, infers, and processes personal data in real time through open conversation.
Under Federal Decree-Law No. 45 of 2021, any entity processing personal data in the UAE must give data subjects clear, specific notice at or before the point of collection. A chatbot widget that opens over your site with no reference to what it stores fails that test.
So does burying the AI disclosure in paragraph 14 of a policy no user opens. The third-party LLM your agent calls is a sub-processor, and the API request carrying the user's message to it is often a cross-border transfer. Both need disclosure in language the user can find.
The UAE government publishes a plain-English summary of the data protection laws that applies across the federal jurisdiction and the financial free zones.
The Mandatory Elements UAE's PDPL Requires in Every AI Privacy Notice

Photo: https://kaboompics.com/ on Pexels
Treat this as your checklist. Every AI privacy notice for a UAE-deployed agent needs at least these disclosures on the face of the document.
Controller identity. The full legal name and contact details of the UAE company deploying the agent, plus a Data Protection Officer contact where one is appointed. A dpo@ mailbox is the norm.
Categories of personal data collected. Break this out honestly: typed messages, voice input if supported, uploaded files, IP address and session metadata, and any inferences the model draws. Grouping everything under "information you provide" is not specific enough.
Purpose and lawful basis, per category. State the purpose for each data category, and state the lawful basis, whether consent, contractual necessity, or legitimate interest. You cannot rely on a single blanket basis for everything the agent does.
Data subject rights. Access, correction, deletion, objection to automated decision-making, and the identity of the supervisory authority. In the UAE that is the Data Office, established under Federal Decree-Law No. 44 of 2021, and users can complain to it directly.
Miss any of these four and the notice is defective on its face.
Six Clauses the Template Must Contain That Competitors' Notices Skip
The elements above are the baseline. These six clauses separate an AI-specific notice from a repurposed website policy.
1. Automated processing clause. State plainly that responses are generated by an AI model, that no human reviews every output, and what the agent is and is not authorised to decide on the company's behalf. If the agent can quote prices, book meetings, or issue refunds, say so.
If it cannot, say that too, because users will assume it can.
2. Third-party model and sub-processor clause. Name the AI provider your agent calls. State where their servers are located.
Describe the cross-border transfer safeguards you rely on under the PDPL, whether that is a standard contract, adequacy, or explicit user consent. The UK government's own AI tools notice is a useful shape reference for how a public body discloses this kind of processing.
3. Conversation retention clause. Say exactly how long chat logs are stored. Say who inside your company can access them.
Say whether they are used to train or fine-tune any model, yours or the provider's. Vague retention language ("as long as reasonably necessary") reads as evasive and does not meet the specificity the PDPL expects.
4. Withdrawal and deletion clause. Explain how a user requests deletion of their conversation, the channel they use (email, in-agent command, a form), and the timeframe you commit to. A specific number of days beats "we will act promptly."
Get the deletion path working before you publish the notice. If you'd like a second set of eyes, Lenoo AI runs a free 30-minute review.
5. Complaints and supervisory authority clause. Point users to the UAE Data Office and give them a route to raise a complaint with your DPO first. Free-zone operators name the free-zone regulator here as well.
6. Notice version and effective date. Put the version number and effective date at the top of the notice, not in the footer. Users and regulators both check this first.
Each clause covers a distinct disclosure, and a notice missing one is easy to spot.
Licensed financial institutions work to the Central Bank of the UAE rulebook, which covers outsourcing, model risk and how customer data may be handled.
| Clause | What It Must State |
|---|---|
| Automated processing | Whether AI or a human generates the response, and what the agent may decide |
| Third-party model and sub-processor | Provider name, server location, cross-border transfer safeguard used |
| Conversation retention | Storage duration, who can access logs, whether used for training |
| Withdrawal and deletion | How to request deletion, the channel, and the committed timeframe |
| Complaints and supervisory authority | Route to the UAE Data Office, DPO contact, free-zone regulator if applicable |
| Notice version and effective date | Version number and effective date shown at the top, not the footer |
Sensitive Data, Children Under 13, and DIFC or ADGM Overlays

Photo: Julia M Cameron on Pexels
Some deployments carry higher-tier obligations. The notice has to reflect them or the whole document fails.
Sensitive personal data. If your agent touches health, financial, biometric, religious, or other sensitive categories, the PDPL requires explicit consent as the lawful basis, and you must describe the additional safeguards you apply. That means separate consent language for those flows, not a single tick-box at the start of a conversation.
Children under 13. If your agent can be reached by minors, state a minimum age of 13, confirm you do not knowingly collect personal information from children under 13, and specify that any such data identified will be deleted. Say how a parent or guardian can contact you to request deletion, and name your verification mechanism, even if the mechanism is "we act on any credible report."
DIFC and ADGM overlays. Businesses registered in the DIFC or ADGM operate under data-protection regimes that sit on top of the federal PDPL. A single notice can address both tiers, but many operators find it cleaner to maintain two: one for the mainland deployment, one for the free-zone entity.
Keeping Your AI Privacy Notice Accurate as the Agent Evolves
A privacy notice is not a "set it and forget it" document. The PDPL's notice obligation is continuing, not one-off.
Material change triggers. Switching LLM provider, adding voice input, accepting document uploads for the first time, extending retention from 30 days to 12 months, or sharing conversation data with a new analytics vendor all require a notice update before the change goes live. Not after.
Not in the next quarterly review. Before.
Re-notification. Silently editing the policy page is not enough for a material change. The PDPL expects data subjects to be informed, and for a conversational agent that means an active in-agent notification at the user's next session.
Version control. Date-stamp every revision on the face of the notice. Keep prior versions accessible at a stable URL.
Tie legal review to the sprint, not the calendar. An annual review cycle lags months behind the product. If your development team is shipping changes to how the agent handles data, the notice check belongs in that sprint's definition of done.
If you've already gone live, our earlier piece on getting started with AI in Dubai covers where a review usually sits in a first deployment.
Related reading
- UAE PDPL AI Compliance
- Consent for AI Data Collection in the UAE
- Cross Border Data Transfer UAE Rules
FAQ
Does a UAE business need a separate AI privacy notice or can it simply add a clause to the existing website policy?
You can do it either way legally, but a bolt-on clause almost always fails the specificity test the PDPL requires. A separate, dedicated notice linked from the agent itself is the cleaner and safer route.
What does the UAE PDPL require a data controller to disclose about automated decision-making?
You must tell users when responses are produced by an AI model with no human in the loop, describe the categories of decision the agent can make on your behalf, and give users the right to object to fully automated decisions that affect them.
Do I have to name the LLM provider my AI agent calls in the privacy notice?
Yes. The provider is a sub-processor under the PDPL, and their identity, server location, and the safeguards covering the cross-border transfer must be disclosed. Naming "a third-party AI provider" without saying which one does not meet the standard.
Does the notice need to be written in Arabic as well as English?
For any consumer-facing agent in the UAE, an Arabic version is expected practice and, in the free zones, effectively required. English-only notices for a UAE consumer product invite a complaint.
What data rights must UAE users have over their AI agent conversation history?
Access, correction, deletion, portability where technically feasible, and the right to object to automated decision-making. The notice must state each right and the channel to exercise it.
If my agent can be accessed by someone under 13, what must the notice say?
State the minimum age, confirm you do not knowingly collect personal information from children under 13, describe what happens if you discover you have, and give a contact channel for parents or guardians to request deletion.
How quickly must I act when a user requests deletion of their conversation data?
The PDPL does not fix a single number of days, but the practical benchmark most UAE operators commit to is 30 days from a verified request, with an interim acknowledgement inside 72 hours. Whatever number you publish, meet it.
If you're not sure whether your current notice covers the six clauses above, book a free 30-minute review with Lenoo AI. You'll get an honest assessment and a clear next step.