The UAE Personal Data Protection Law is not a reason to paste a 4,000-word GDPR template onto the site. It is a reason to stop collecting Emirates ID copies you never needed, write a privacy page that matches the form, and stop dropping five ad pixels before the visitor has said hello.

ITZ is not your lawyer. If you process health data, children’s data, or run a large marketplace, get counsel. ITZ is the team that builds the forms, booking widgets and WhatsApp buttons. Most PDPL pain on UAE sites is sloppy implementation, not a missing 40-page policy. The legal page for this site is at privacy. The build work sits on web development.

What a normal business site actually collects

A clinic, contractor or consultancy typically picks up name, mobile, email, a short note, and sometimes a file. That is personal data. Treat it like a client file, not a lead list dumped into a shared spreadsheet. A leaked enquiry inbox is a trust problem and a legal one. If you already had a breach, read security and maintenance.

Forms: collect less, say more

Every field needs a reason you can say out loud. If you cannot explain why you need a date of birth on a fit-out enquiry, delete it. Put a short note under the button: what you use the data for, and a link to the privacy page. Do not hide a pre-ticked marketing box. Form UX is covered in forms UAE visitors complete.

Planning notes and a laptop — mapping what a website form collects before it is built
Write down what each field is for before you build the form. If you cannot explain a field, it should not be there.

Cookies: the banner that blocks your own leads

If you are not running analytics or ads, you do not need a cookie wall that covers WhatsApp. If you do run GA4 or a pixel, say so, and do not fire marketing tags before consent where the law and your own policy require it. A banner copied from an EU theme that blocks the first screen is how you lose the chat you came to collect.

WhatsApp is still data

A wa.me click sends the visitor into Meta’s app. That is still a conversation with personal details. Use a business number you control. Do not scrape chats into a marketing list. Do not pre-fill the chat with data the visitor did not type. ITZ wires WhatsApp as a lead path, then documents it on the privacy page.

The privacy page people will actually read

Name the company, what you collect, why, how long, how to ask for deletion, and the WhatsApp / email to use. Match the live form. A pasted GDPR novel that mentions a DPO in Dublin and cookies you do not set is worse than a short honest page.

What ITZ implements on a typical build

  • Only the fields the job needs
  • A privacy page that describes this site, not a template
  • No marketing pixels unless you asked for them
  • WhatsApp and forms named in the policy
  • Admin logins that are not shared on a sticky note

Frequently asked questions

Does a small UAE website need a privacy policy?

If you collect names, numbers or emails — including via WhatsApp from the site — you should say so in plain language. Size of company is not a loophole. Keep it short and accurate.

Do I need a cookie banner?

Not as decoration. If you only use essential hosting logs, say that and skip the wall. If you drop analytics or ads, explain them and do not pretend you do not.

Is WhatsApp a PDPL issue?

It is personal data in a chat. Use a number you control, do not scrape it for marketing, and mention it on the privacy page. The app itself is Meta’s service once the visitor leaves your site.