Deploying an AI tutor, an adaptive assessment platform, or a behaviour-monitoring dashboard in a UAE private school is not a KHDA-only question. Three regulators sit in the room at once: KHDA for the licence and inspection, ADEK in Abu Dhabi if the group operates there, and the UAE Data Office under Federal Decree-Law No. 45 of 2021.
Miss any one of them and the liability lands on the school, not the vendor. Most operators only think about the first. That is where the KHDA AI schools compliance gap starts, and it is what this article closes.
Key Takeaways
- KHDA and ADEK don't cover data protection law — Federal Decree-Law No. 45 of 2021 governs student and parent data nationwide. KHDA licenses and inspects Dubai schools, ADEK does the same in Abu Dhabi, but neither displaces the federal law when AI tools process that data.
- The school is the data controller — Under the PDPL, ed-tech vendors are data processors acting on the school's instructions. The controller carries primary liability, so the school is accountable for what an AI platform does with student data regardless of whose software it is.
- Enrolment consent doesn't cover AI tools — The PDPL's purpose-limitation principle means consent for "administration of the child's education" doesn't authorise profiling, predictive risk scores, or feeding data into a vendor's model. Schools need a separate consent notice per tool, in Arabic and English, recorded before it goes live.
- Vendor contracts need specific PDPL terms — A data processing agreement must spell out the lawful purpose of processing, retention periods per data category, breach notification timelines the school can meet, and confirmed deletion of student data at contract end.
- A data incident is a double risk — KHDA and ADEK both weigh governance quality in their inspection judgements, and an incident tied to a school-deployed AI tool is visible to parents through published reports before any formal finding from the UAE Data Office, the federal enforcement body.
What KHDA Actually Governs When a Dubai Private School Deploys AI
KHDA is the licensing and inspection authority for Dubai's private schools and learning institutions. It sets terms, inspects, publishes ratings, and can sanction operators whose governance falls short.
What KHDA is not is a data protection regulator. That distinction is where most compliance failures start.
When a school deploys an AI adaptive learning platform or a proctoring tool, KHDA's inspection framework will still examine data handling, safeguarding, and governance. Weak controls surface as findings even though KHDA is not enforcing a data protection statute directly. A poor rating follows the school into next year's parent enrolment cycle.
Where does KHDA's remit end? At the point where student and parent records become "personal data" under the federal PDPL. From there, a separate federal law and regulator take over.
KHDA sits alongside sector-specific authorities that all interact with AI in their own way; the wider map is covered in our overview of UAE sector regulators and AI. Clearing a KHDA inspection does not clear you under the PDPL.
The Telecommunications and Digital Government Regulatory Authority is the body that licenses telecom services in the UAE and sets the rules for unsolicited marketing contact.
ADEK's Role in Abu Dhabi: A Parallel Framework, Not the Same Rules

Photo: Adnan Uddin on Pexels
Abu Dhabi's private schools answer to the Department of Education and Knowledge, ADEK, not KHDA. ADEK licences and inspects on its own timelines, with its own thresholds and reporting cycles. Group operators who assume that KHDA compliance covers them across the border find out otherwise at the first inspection.
The practical difference for AI tooling is real. ADEK and KHDA publish guidance on different clocks and phrase expectations differently on acceptable-use policies, safeguarding, and reporting. A single AI vendor rollout across campuses in both emirates means two sets of paperwork and two consent flows.
Neither authority displaces the federal law. ADEK and KHDA sit on top of the PDPL, not in place of it. A school in Abu Dhabi that satisfies ADEK's guidance still has to satisfy Federal Decree-Law No. 45 of 2021 for the personal data those tools process.
The three layers of oversight a school actually answers to look like this:
| Regulator | What It Governs | Relationship to the PDPL |
|---|---|---|
| KHDA | Dubai private school licensing, inspection, and ratings | Does not replace the PDPL |
| ADEK | Abu Dhabi private school licensing and inspection, own timelines and thresholds | Does not replace the PDPL |
| UAE Data Office | Federal enforcement of personal data protection nationwide | Sits on top of both KHDA and ADEK |
The Federal PDPL and Student Data: Who Is Actually the Data Controller
Federal Decree-Law No. 45 of 2021 applies to personal data processed in the UAE. That includes student records, parent contact details, assessment results, behavioural notes, and learning analytics generated by AI platforms. If your AI tool holds any of it, the PDPL applies.
The next question decides who is on the hook. Under the PDPL, the school is the data controller. The ed-tech vendor is a data processor acting on the school's instructions.
Controllers carry primary liability under UAE law. When a school signs a purchase order for an AI platform, it is legally accountable for what that platform does with student data, regardless of whose name is on the software.
Cross-border transfers add another layer. If the vendor processes UAE student data on servers outside the country, the transfer must be lawful under the PDPL. Free-zone regimes complicate this further: vendors in the DIFC or ADGM operate under those authorities' own data protection laws, adding a third compliance layer.
Parent Consent for AI Tools: What Schools Consistently Get Wrong
The single most common failure is treating the annual enrolment consent form as if it covers everything the school will ever plug in. It does not. The PDPL's purpose-limitation principle requires that consent be tied to a specific processing purpose.
Consent given at enrolment for "administration of the child's education" does not authorise a third-party AI platform to profile behaviour, generate predictive risk scores, or feed learning analytics into a vendor's model.
Purpose limitation cuts sharp. Consent for adaptive learning does not carry over to behavioural profiling, and profiling consent does not carry over to marketing. Each use case needs its own lawful basis, documented before the tool touches a student's data.
Parents have rights the school must honour. Under the PDPL, they can request access to their child's data, correct it, or ask for erasure from a third-party AI platform. The school, as controller, must facilitate that request against the vendor.
Without a workable deletion mechanism in the vendor contract, the school cannot answer the parent. The practical fix is granular: one consent notice per tool, in Arabic and English, recorded before the tool goes live. This is the audit trail showing a lawful basis exists for each processing activity.
Before You Deploy: Vendor Due Diligence and Data Processing Agreements

Photo: https://kaboompics.com/ on Pexels
The pre-deployment work is where the compliance gap closes. Start with the vendor's data flows: where is the data stored, where is it processed, and does that route touch jurisdictions that trigger additional PDPL transfer obligations? A vendor who cannot answer this in writing is a vendor you cannot sign.
The DPA carries the weight after that. Under the PDPL, a DPA with an ed-tech vendor must spell out the lawful purpose of processing, retention periods for each data category, breach notification timelines the school can meet, and confirmed deletion of student data at contract end. "The vendor will act in accordance with applicable law" is not a DPA; it is a signature waiting to become a liability.
Internal governance runs in parallel. Before go-live, the school needs an acceptable-use policy for AI tools, a data register mapping every AI tool to its legal basis and data categories, and staff training on handling parent requests and incidents.
For groups running AI across finance and admin, the same discipline extends into the back office; our note on corporate tax, VAT and AI bookkeeping picks up where automation stops. The national policy backdrop is worth reading in our piece on the UAE AI Charter and what it means for private companies.
What Happens If You Get This Wrong, and How to Close the Gap
Regulatory exposure under the PDPL is real. The UAE Data Office is the federal enforcement body, and a school that deploys AI tools without lawful basis, adequate vendor contract, or proper consent is exposed to enforcement action regardless of KHDA or ADEK's view of the rest of the file.
Then there is the inspection layer, the more visible risk day to day. KHDA and ADEK both weigh governance quality in their judgements. A data incident tied to a school-deployed AI tool is visible in that process, and to parents through published reports long before a formal regulatory finding lands.
The remediation path is straightforward once you accept the scope. Map the data flows for every AI tool in use, then draft or renegotiate DPAs for each vendor. Revise parent communications and reissue consent, in Arabic and English, per tool.
Train the staff who administer the tools and handle parent requests. None of this requires building custom AI or replacing platforms. Schools using AI-driven voice or outbound outreach should also read our note on TDRA rules for voice agents and automated calls, because the telemarketing regime applies to school marketing.
For a candid read on where your school sits against these obligations, book a free 30-minute consultation with Lenoo AI.
FAQ
Does KHDA require Dubai private schools to disclose which AI tools they use with students?
KHDA does not publish a standalone AI tools disclosure register, but its inspection framework examines governance and data handling. Any AI tool touching student data is in scope.
Does the federal PDPL apply to a private school in Dubai, or does KHDA compliance cover data protection?
Federal Decree-Law No. 45 of 2021 applies to personal data processed in the UAE, including student and parent data at a Dubai private school. KHDA compliance does not replace PDPL compliance.
Can parents legally demand that a school delete their child's data from a third-party AI platform?
Under the PDPL, parents can request erasure of their child's personal data subject to the law's conditions and exemptions. The school, as controller, must be able to action that request against the vendor.
What is the practical difference between KHDA and ADEK obligations when a school deploys an AI tool?
KHDA regulates Dubai private schools; ADEK regulates them in Abu Dhabi, each with its own guidance, inspection cycle, and reporting expectations. A group operating in both emirates has to satisfy both authorities separately, and both on top of the federal PDPL.
If an ed-tech vendor suffers a data breach, who is liable, the school or the vendor?
Primary controller liability under the PDPL sits with the school. The vendor may be contractually liable, but the regulator's first port of call is the institution that collected the data.
Does a UAE private school need a designated Data Protection Officer under the federal PDPL?
The PDPL requires a DPO in defined circumstances, including processing of sensitive personal data or systematic large-scale processing. Schools using AI tools with student data should assess against those triggers.
Can a UAE private school use an AI platform that stores student data on servers outside the UAE?
Yes, provided the transfer satisfies the PDPL's cross-border requirements. That usually means checking whether the destination jurisdiction offers adequate protection, or putting contractual safeguards in place before data leaves the country.