UAE and Dubai Cookie Consent Under PDPL, DIFC and ADGM
How UAE Federal PDPL, DIFC and ADGM rules affect cookie consent for Dubai websites, plus a bilingual implementation checklist.
In short
Under the UAE's Federal PDPL (Federal Decree-Law No. 45 of 2021), overseen by the UAE Data Office, non-essential cookies and trackers generally need clear notice and the visitor's free, informed consent before they run; strictly necessary cookies do not. Businesses registered in DIFC or ADGM free zones also need to check the DIFC Data Protection Law and the ADGM Data Protection Regulations, which run alongside Federal PDPL. For a UAE and Dubai audience, the notice and consent banner should be geo-targeted with Arabic (RTL) shown by default and English as a secondary option, and cross-border transfers of related data need a documented legal basis. Cookietrace supports these consent flows alongside GDPR/ePrivacy, CCPA, LGPD and KVKK, with bilingual Arabic/English geo-targeted banners, automated scanning, IAB TCF v2.2, Google Consent Mode v2 and timestamped, integrity-proofed consent records kept 3+ years. This is general information, not legal advice.
- Cookietrace Privacy Engineering Team — Published 2026-09-15 · 8 min read
What does UAE PDPL mean for cookies on Dubai websites?
The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), overseen by the UAE Data Office, treats persistent identifiers such as cookies, mobile ad IDs and tracking pixels as personal data whenever they can be linked to an identifiable individual. A website operated from or targeting visitors in Dubai and the wider UAE mainland needs a documented lawful basis, a clear notice, and in most cases prior consent before non-essential cookies run.
Consent and lawful basis under PDPL
Strictly necessary cookies (session, security, load-balancing) generally do not need consent because they are required to deliver the service the visitor requested. Analytics, advertising and social-media cookies almost always require the visitor's free, specific and informed consent, collected before the cookie fires, with an equally easy way to withdraw it.
- Consent must be an affirmative, unambiguous action — pre-ticked boxes or continued browsing are not valid consent
- The visitor must be able to reject non-essential categories as easily as accepting them
- Consent choices must be logged with a timestamp so they can be reproduced on request
- Withdrawal must be as simple as giving consent, e.g. a persistent 'privacy settings' link
Mainland UAE vs DIFC vs ADGM: which rules apply?
The UAE has three overlapping data protection regimes. Federal PDPL applies to mainland UAE entities and most Dubai-based businesses outside the financial free zones. The Dubai International Financial Centre (DIFC) has its own DIFC Data Protection Law, enforced by the DIFC Commissioner of Data Protection, for entities registered in that free zone. Abu Dhabi Global Market (ADGM) applies its own ADGM Data Protection Regulations, modelled closely on GDPR, to ADGM-registered entities. A business should confirm which free zone, if any, it is registered in before assuming Federal PDPL is the only law in scope.
Notice and transparency obligations
All three regimes require a clear, accessible privacy notice describing what data is collected, the purpose, retention period and any third parties involved, in language the data subject understands. For a UAE and Dubai audience this means the notice and consent banner should be available in Arabic, not only in English, since Arabic is the official language and English is widely used in business but does not replace the transparency expectation for Arabic-speaking visitors.
Cross-border data transfer considerations
PDPL, the DIFC law and the ADGM regulations all restrict transferring personal data — including consent logs and analytics data tied to UAE visitors — outside the country or free zone unless an adequate level of protection is demonstrated or another legal transfer mechanism applies. Businesses using overseas analytics, advertising or CMP vendors should review this together with local counsel before relying on it, since guidance from the UAE Data Office, the DIFC Commissioner and the ADGM continues to evolve.
Arabic and English geo-targeted consent banners
Because Modern Standard Arabic (MSA) is the official language and the primary language for a large share of consumers in the UAE, a consent banner shown only in English does not meet the transparency expectations of PDPL, the DIFC law or the ADGM regulations for a UAE audience. An effective setup geo-targets UAE and Gulf visitors with an Arabic-first banner by default, offers English as a secondary option, and correctly renders right-to-left (RTL) layout. The same platform should still show an English or other-language banner to visitors from outside the region.
How automated cookie scanning and categorisation works
A compliant setup starts with an automated scan of the site that discovers every cookie, tag and tracking pixel actually firing, then groups them into categories (necessary, functional, analytics, advertising) so the banner can offer real per-category choices rather than a single accept/reject toggle. Cookietrace runs this scan on a recurring schedule, since a new pixel added by a marketing team can silently break compliance between manual reviews.
Prior Blocking: stopping trackers before consent
With Cookietrace's Prior Blocking setting enabled, non-essential cookies and trackers detected by the scan — whether loaded via GTM or embedded directly in the page — are not executed until the visitor makes a choice; if the visitor rejects, they never run, and if they accept, only the accepted categories load.
Implementation checklist for Dubai e-commerce and corporate sites
Use this checklist as a starting point; it does not replace a legal review of your specific data flows, entity registration and free-zone status.
- Confirm whether your entity falls under Federal PDPL, the DIFC Data Protection Law, or the ADGM Data Protection Regulations
- Run an automated scan and categorise every cookie/tracker found on the site
- Publish an Arabic-first, RTL-aware privacy notice alongside the English version
- Deploy a bilingual, geo-targeted consent banner with granular accept/reject per category
- Enable Prior Blocking so non-essential scripts wait for a visitor decision
- Keep timestamped, exportable consent records for at least 3 years
- Review cross-border transfer arrangements with counsel if data leaves the UAE or the relevant free zone
- If you also serve EU visitors, layer GDPR/ePrivacy consent logic on top
- If you run on Shopify, WooCommerce, Magento, Salla or Zid, confirm the CMP script or GTM tag loads on every storefront template and checkout step
Frequently asked questions
Under the UAE's Federal PDPL (Federal Decree-Law No. 45 of 2021), overseen by the UAE Data Office, non-essential cookies and trackers generally need clear notice and the visitor's free, informed consent before they run; strictly necessary cookies do not. Businesses registered in DIFC or ADGM free zones also need to check the DIFC Data Protection Law and the ADGM Data Protection Regulations, which run alongside Federal PDPL. For a UAE and Dubai audience, the notice and consent banner should be geo-targeted with Arabic (RTL) shown by default and English as a secondary option, and cross-border transfers of related data need a documented legal basis. Cookietrace supports these consent flows alongside GDPR/ePrivacy, CCPA, LGPD and KVKK, with bilingual Arabic/English geo-targeted banners, automated scanning, IAB TCF v2.2, Google Consent Mode v2 and timestamped, integrity-proofed consent records kept 3+ years. This is general information, not legal advice.
Does UAE PDPL apply to cookies on my Dubai website?
Yes. PDPL, overseen by the UAE Data Office, treats cookies and similar identifiers as personal data when they can be linked to an identifiable person, so the usual notice and consent rules apply to non-essential cookies for a Dubai or wider UAE audience.
Do DIFC and ADGM have their own cookie rules, or does Federal PDPL cover everything?
Entities registered in the DIFC or ADGM free zones are generally subject to the DIFC Data Protection Law or the ADGM Data Protection Regulations rather than, or in addition to, Federal PDPL. Confirm your entity's registration status before assuming one law applies.
Should the consent banner be in Arabic for UAE visitors?
Yes. For a UAE and Dubai audience, showing the notice and consent choices in Arabic (rendered RTL) by default, with English as a secondary option, better meets the transparency expectations of PDPL, the DIFC law and the ADGM regulations than an English-only banner.
Can I send UAE visitor data to an analytics tool hosted abroad?
PDPL, the DIFC law and the ADGM regulations restrict cross-border transfers unless an adequate level of protection is shown or another lawful transfer mechanism applies; review your specific vendor and data flow with local counsel.
Does Cookietrace store data in the UAE or the Gulf?
No. Cookietrace hosts data in the EU by default, with a Türkiye hosting option; it does not offer UAE or Gulf data residency, so cross-border transfer requirements should be assessed separately.
How does Prior Blocking help with PDPL, DIFC or ADGM compliance?
With Prior Blocking enabled, non-essential cookies and trackers found by the scan do not run until the visitor chooses; if they reject, the scripts never fire, which supports a 'consent before tracking' approach across all three UAE regimes.
Sources
Official sources cited in this guide.
Who should read it
Website owners, marketing teams and developers responsible for cookie consent, analytics tagging and privacy documentation.
Cookietrace
Written and reviewed by the Cookietrace Privacy Engineering Team. (8 min — regulations)