UAE Outbound Calling Compliance: TDRA Rules Explained (2026)
A 2026 guide to UAE outbound compliance: TDRA rules, Do Not Call and consent, calling hours, caller ID, recording, PDPL, and emirate-level telemarketing permits.
Quick answer
Outbound calling in the UAE is regulated at the federal level by the TDRA and by the Personal Data Protection Law (Federal Decree-Law No. 45 of 2021), plus emirate-level telemarketing rules such as Dubai economic-department permits. Operators generally need prior consent, verified caller ID, defined calling windows, honored opt-outs, and lawful call recording. Confirm current rules with TDRA, the relevant emirate authority, and local counsel.
The United Arab Emirates is one of the most closely regulated markets in the region for outbound calling. Contact centers, BPOs, collections teams, and telecom resellers operating into the UAE face a layered rulebook: a federal telecom regulator, a national data protection law, emirate-specific telemarketing requirements, and separate regimes inside the major financial free zones. Getting this wrong is not just a fine risk; repeated violations can put a license or a client relationship in jeopardy.
This guide walks through the main categories of UAE outbound calling compliance as they generally stand in 2026, who enforces them, and how a compliance-supporting multilingual dialer helps operators keep pace. It is written for teams calling into the UAE from anywhere, as well as for domestic contact centers based in Dubai, Abu Dhabi, and the northern emirates. For the wider regional picture, see our MENA compliance guide.
Who Regulates Outbound Calling in the UAE?
The primary federal regulator is the TDRA — the Telecommunications and Digital Government Regulatory Authority. TDRA oversees the UAE telecom sector, licenses providers, and sets rules that touch how calls are originated, how caller identity is presented, and how marketing communications reach consumers. When you place outbound calls into UAE networks, TDRA's framework is the backdrop.
Alongside TDRA, the UAE has a federal Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021. The PDPL governs how personal data — including phone numbers, call recordings, and contact histories — is collected, processed, stored, and shared. Any outbound program that touches UAE residents' personal data has to consider both the telecom rules and the data protection rules together, because they overlap.
Two important nuances make the UAE different from a single-regulator market:
- Emirate-level rules. Individual emirates layer their own telemarketing requirements on top of federal law. In Dubai, for example, telemarketing activity is generally subject to permits and registered-number requirements administered through the emirate's economic department. Other emirates maintain their own approaches. A company licensed in one emirate cannot assume its telemarketing authorization automatically applies everywhere.
- Free-zone data regimes. The Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM) operate their own data protection regimes separate from the federal PDPL. If your entity — or your client's entity — is established in DIFC or ADGM, the applicable data protection rules may be the free-zone law rather than, or in addition to, the federal PDPL.
The practical takeaway: UAE outbound compliance is not one checklist. It depends on where the calling entity is licensed, where the person being called is, and what free zone (if any) is in scope. Our UAE region overview summarizes the market for outbound operators.
Consent and Do Not Call Rules
Consent is the foundation of lawful marketing calling in the UAE. As a general principle, unsolicited marketing calls to consumers require a lawful basis, and for direct-marketing purposes that basis is typically prior consent. Consent should be specific, informed, and demonstrable — meaning you can show when and how the person agreed to be contacted for marketing.
Good practice, and what regulators generally expect, includes:
- Capturing the source of consent (the form, campaign, or channel where it was collected).
- Recording a timestamp and, where relevant, technical evidence such as the URL, IP address, or channel identifier.
- Honoring opt-out and Do Not Call requests promptly and permanently across all campaigns and tenants.
- Respecting national and sector Do Not Call mechanisms where they apply.
The UAE distinguishes between marketing calls and other categories. Debt collection, transactional service calls, and existing-relationship contact are treated differently from cold marketing, but they are not unregulated — collections calling in particular is sensitive to harassment, timing, and disclosure rules, and to data protection obligations. Do not assume a "non-marketing" label removes compliance duties.
Calling Hours, Caller ID, and Recording
Three operational controls come up constantly in UAE enforcement and client audits: when you can call, what number you show, and how you handle recordings.
Calling hours. The UAE generally restricts marketing and telemarketing calls to reasonable daytime windows and typically prohibits calls during religious observances, public holidays, and rest periods. The exact permitted hours and excluded days can vary by rule set, emirate, and call category, and they change over time. Do not hard-code a specific window from a blog post as legal fact — configure your system so calling windows are adjustable and verify the current permitted hours with TDRA and the relevant emirate authority before launching a campaign.
Caller ID / CLI. The number you present must be a legitimate, verified number associated with the calling entity. Presenting misleading, masked, or spoofed caller identity is treated seriously, and Dubai's telemarketing framework, for example, generally expects marketing calls to originate from registered, identifiable numbers. Using unverified or foreign-appearing numbers to disguise a marketing call is a common source of complaints and penalties.
Call recording. Recording outbound calls is widely used for quality and dispute resolution, but under the PDPL a recording is personal data. That means you generally need a lawful basis for recording, appropriate notice to the person, defined retention periods, access controls, and secure storage. Blanket indefinite retention of recordings without a documented basis is a risk. Recordings involving free-zone entities may fall under DIFC or ADGM rules instead of, or alongside, the federal PDPL.
Data Protection: The UAE PDPL and Free Zones
The federal PDPL (Federal Decree-Law No. 45 of 2021) introduces obligations familiar to anyone who has worked with modern privacy law: a lawful basis for processing, purpose limitation, data-subject rights, security requirements, and constraints on cross-border transfers of personal data. For an outbound operation, the personal data in scope includes phone numbers, names, call outcomes, dispositions, notes, and recordings.
Key data protection themes for UAE outbound calling:
- Lawful basis. Marketing calling generally relies on consent; other processing may rely on contract, legal obligation, or legitimate interest depending on the activity. Document which basis you rely on.
- Data-subject rights. Individuals can request access, correction, and deletion, and can object to marketing. Your dialer and CRM need to action these requests reliably.
- Cross-border transfers. If your BPO or platform stores UAE personal data outside the UAE, transfer rules apply. Understand where your data physically sits.
- Free-zone divergence. DIFC and ADGM have their own, well-developed data protection regimes. An entity established in one of these zones should map its obligations to the zone's law rather than assuming the federal PDPL governs.
Summary of UAE Outbound Compliance Categories
| Category | Primary source | What operators generally need |
|---|---|---|
| Telecom / calling rules | TDRA (federal) | Verified caller ID, permitted calling windows, no spoofing |
| Telemarketing permits | Emirate authorities (e.g., Dubai economic department) | Permits and registered numbers where required, per emirate |
| Consent & Do Not Call | TDRA framework + PDPL | Demonstrable prior consent, honored opt-outs |
| Data protection | PDPL — Federal Decree-Law No. 45 of 2021 | Lawful basis, data-subject rights, secure storage, transfer rules |
| Free-zone data | DIFC / ADGM regimes | Apply the relevant free-zone law where the entity is established |
| Call recording | PDPL / free-zone rules | Notice, lawful basis, retention limits, access controls |
This table is a categorized starting point, not a definitive rulebook. Each row hides detail that varies by emirate, entity type, and call category, and the underlying rules are periodically updated.
Building a Compliant UAE Outbound Program
Regulators and enterprise clients increasingly expect operators to show their compliance posture, not just claim it. A defensible UAE outbound program generally includes: a documented lawful basis for each campaign, consent records you can retrieve on demand, a reliable suppression and opt-out process, configurable calling windows, verified caller ID, disciplined recording retention, and clear ownership of data-subject requests. Multi-tenant BPOs need to keep all of this separated cleanly per client so one campaign's rules never leak into another's.
Language matters too. The UAE workforce and customer base are highly multilingual, and calling in the right language — Arabic and beyond — is both a service quality and, in some contexts, a fairness and disclosure consideration. See our broader MENA solutions overview for how operators structure regional programs.
How DialerBee Supports Compliant Outbound in the UAE
DialerBee is built as a compliance-supporting multilingual AI outbound dialer, and several of its controls map directly onto the UAE requirements above. Operators can configure calling windows per campaign and per market so that outbound activity stays within the hours and days they have verified as permitted, and pause automatically outside them. Consent and opt-out state is tracked per contact and enforced across campaigns, which helps teams honor Do Not Call requests consistently and produce consent evidence when a client or auditor asks. Verified caller-ID configuration supports presenting registered, identifiable numbers rather than masked ones, and call recording can be managed with retention settings that fit a documented PDPL or free-zone basis instead of open-ended storage. For BPOs and telecom resellers running many clients, DialerBee's multi-tenant separation keeps each client's rules, suppression lists, numbers, and recordings isolated. And because it offers language-aware AI across 9 languages, including Arabic, teams can engage UAE contacts in the appropriate language. These are compliance-supporting controls that help operators implement their obligations — they do not replace legal review. You can read more on our compliance features page.
Frequently Asked Questions
Who regulates outbound calling in the UAE?
The primary federal telecom regulator is the TDRA — the Telecommunications and Digital Government Regulatory Authority. Data protection is governed by the federal PDPL (Federal Decree-Law No. 45 of 2021), while individual emirates add their own telemarketing rules and the DIFC and ADGM free zones have separate data protection regimes.
Do I need consent to make marketing calls in the UAE?
As a general rule, unsolicited marketing calls to UAE consumers require a lawful basis, and for direct marketing that basis is typically prior, demonstrable consent. You should record when and how consent was given and be able to produce that evidence. Confirm the exact requirements for your activity with TDRA, the relevant emirate authority, and local counsel.
What are the permitted calling hours in the UAE?
The UAE generally limits marketing calls to reasonable daytime windows and restricts calling during holidays and rest periods, but the exact hours and excluded days can vary by rule set, emirate, and call category, and they change over time. Configure adjustable calling windows and verify current permitted hours with TDRA and the relevant emirate authority before launching.
Are Dubai telemarketing permits required?
Telemarketing in Dubai is generally subject to emirate-level requirements administered through the economic department, which can include permits and registered-number obligations. Other emirates maintain their own approaches. A telemarketing authorization in one emirate does not automatically apply across the UAE, so check the rules for each emirate you operate in.
How does the UAE PDPL affect call recording?
Under the PDPL (Federal Decree-Law No. 45 of 2021), a call recording is personal data, so you generally need a lawful basis, appropriate notice, defined retention periods, and secure, access-controlled storage. Recordings tied to DIFC or ADGM entities may fall under those free-zone regimes instead of or alongside the federal PDPL.
How does DialerBee help with UAE compliance?
DialerBee provides compliance-supporting controls: configurable calling windows, per-contact consent and opt-out tracking, verified caller-ID configuration, managed recording retention, and multi-tenant separation for BPOs, plus language-aware AI across 9 languages including Arabic. These help operators implement their obligations but do not replace legal review or guarantee compliance.
This article is for general informational purposes and is not legal advice. UAE federal and emirate-level rules change and vary by jurisdiction and free zone — confirm current requirements with TDRA, the relevant emirate authority, and qualified local counsel.