MENA Compliance Guide for Outbound Calling Teams
A practical guide to outbound calling regulations across the UAE, Saudi Arabia, Egypt, and Jordan.
Outbound calling compliance in the Middle East is fragmented, evolving, and often poorly documented. Each country has its own regulator, its own Do Not Call rules, its own calling hours, and its own consent requirements. This guide covers what you need to know to stay compliant across the four major MENA markets.
UAE — TDRA (Telecommunications and Digital Government Regulatory Authority)
The UAE is the most mature regulatory environment in the MENA region for outbound calling.
Calling hours: Sunday through Thursday, 9:00 AM to 6:00 PM local time. No calls on Fridays, Saturdays, or public holidays unless the customer has explicitly opted in to weekend contact.
Do Not Call (DNC): TDRA maintains a national DNC registry. Numbers on this list must not be called. The registry is updated regularly — your system must sync at least daily.
Consent: Prior consent is required for all outbound marketing calls. Consent has a maximum validity of 2 years under TDRA guidelines. Consent must be recorded with proof: URL where consent was given, IP address, user-agent, and timestamp.
Caller ID: CLI (Calling Line Identification) must be a verified number owned by the calling entity. CLI spoofing is illegal and aggressively enforced.
Penalties: Violations can result in fines up to AED 10 million and license revocation.
Saudi Arabia — CITC (Communications, Space & Technology Commission)
Calling hours: Sunday through Thursday, 9:00 AM to 9:00 PM local time. Slightly longer window than UAE.
Do Not Call: CITC maintains a DNC registry. Additionally, under Saudi data protection law (PDPL), individuals have the right to opt out of marketing communications at any time.
Consent: Explicit, informed consent is required under PDPL. The consent mechanism must clearly state the purpose of data collection and the types of communications the individual will receive.
Language: Marketing materials and disclosures must be available in Arabic. If the call is conducted in Arabic, all compliance disclosures must also be in Arabic.
Egypt — NTRA (National Telecom Regulatory Authority)
Calling hours: Sunday through Thursday, 9:00 AM to 9:00 PM local time. Egypt also restricts calling during Ramadan: no outbound marketing calls during fasting hours.
Do Not Call: NTRA maintains a DNC registry. Registration is free for consumers. Companies must check the registry before every campaign.
Consent: Prior consent is required. NTRA requires that the consent be verifiable and that the consumer can withdraw consent at any time through a simple mechanism (e.g., pressing a key during the call or replying to an SMS).
Jordan — TRC (Telecommunications Regulatory Commission)
Calling hours: Sunday through Thursday, 9:00 AM to 8:00 PM local time.
Do Not Call: TRC maintains a registry, though enforcement has historically been less aggressive than UAE or KSA. This is changing as the regulatory environment matures.
Consent: Required for marketing calls. Jordan's data protection law requires clear, specific consent.
Cross-Border Considerations
If your team operates across multiple MENA countries, you face compounded complexity:
- Time zone management: UAE (GMT+4), KSA (GMT+3), Egypt (GMT+2), Jordan (GMT+3). A single campaign targeting all four markets must respect four different calling windows.
- DNC aggregation: You need to check every number against every relevant DNC registry. A UAE-based number might appear on the TDRA registry even if the campaign is KSA-focused.
- Consent jurisdiction: Consent obtained in one country may not be valid in another. If a customer signed up on a UAE website but has a KSA phone number, which consent rules apply?
How DialerBee Handles This
DialerBee's compliance engine is built for this exact complexity. Every outbound dial goes through a compliance check that evaluates:
- DNC status — checked against all relevant registries for the destination number
- Calling hours — jurisdiction-aware, respects the destination's local time
- Consent validity — checks that consent exists, hasn't expired, and covers the campaign type
- CLI ownership — verifies the caller ID is owned and verified for that tenant and jurisdiction
The system can be configured as default-deny. If a configured check fails — or if there's an error, a timeout, or an unknown rule version — the call can be blocked and logged.
Compliance decisions can be recorded with rule version, audit reference, and context where audit logging is configured. If a regulator asks "why did you call this number at this time?", you have the answer.
Compliance isn't a feature. It's a requirement. Build it in from day one, or pay for it later.