TelonicDocs
English

Legal and compliance

Data protection in the UAE and Saudi Arabia

What the UAE and Saudi personal data laws expect of an organisation using Telonic, who is responsible for what, and what the product does to support you.

On this page
  1. Who is responsible for what
  2. What the UAE law expects
  3. What the Saudi law expects
  4. What the law expects, and what the product does to support you
  5. The networks your customers use
  6. Consent in conversations
  7. In practice
  8. What your team controls
  9. Related

Every conversation the agent holds involves personal data: a name, a phone number, a unit, a booking, a claim. Both the UAE and Saudi Arabia have personal data protection laws that set out how that data may be collected, used, kept and moved. Your organisation decides why and how your customers' data is used, and Telonic processes it on your instruction. This page describes what the laws expect in plain terms, how responsibility is divided, and what the product does to support your organisation in meeting its obligations.

Note

This page is general information about the law, not legal advice. Laws and regulations in both countries continue to develop, and how they apply depends on your organisation, your sector and your customers. Your organisation is responsible for its own compliance and should take its own legal advice. We will walk your legal team through exactly how the product handles each point.

Who is responsible for what

Data protection law divides responsibility between two roles. The controller decides why personal data is processed and how. The processor handles the data on the controller's behalf and on its instructions.

When you deploy Telonic, your organisation is the controller of your customers' data, and Telonic acts as your processor. You decide which conversations the agent holds, what it may look up, what is stored and for how long. Telonic processes the data only to provide the service, on your documented instructions, under data processing terms that form part of your agreement. See Contracts and data processing terms.

What the UAE law expects

The UAE's Federal Decree-Law on the Protection of Personal Data applies to the processing of personal data of people in the UAE, and to organisations established in the UAE that process personal data. In plain terms, it expects an organisation to:

  • Have a lawful basis. Consent is the main basis, with specific exceptions, such as processing needed to perform a contract with the person or to meet another legal obligation.
  • Use data only for its stated purpose, collect only what that purpose needs, and keep it accurate and no longer than needed.
  • Respect the rights of the people the data is about, including the rights to access their data, correct it, have it erased, restrict or stop processing, and object to decisions made only by automated means.
  • Keep data secure, with technical and organisational measures suited to the risk.
  • Report breaches of personal data to the regulator, and in some cases to the people affected.
  • Transfer data outside the UAE only under the conditions the law sets, for example to countries recognised as giving adequate protection, or with the safeguards the law allows.
  • Keep a record of processing, and in some cases appoint a data protection officer.
  • Put a contract in place with any processor, requiring it to act only on instructions and to protect the data.

The law is supported by executive regulations, and detailed rules continue to be issued. Some sectors, such as health and financial services, carry additional rules of their own, including on where certain data may be held.

The financial free zones have their own laws. The Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) each have their own data protection law and their own regulator. If your organisation is established in one of them, that law applies to it, and your legal team will tell you how it interacts with the federal law for your business.

What the Saudi law expects

Saudi Arabia's Personal Data Protection Law is overseen by the Saudi Data and Artificial Intelligence Authority (SDAIA), and supported by implementing regulations and regulations on transferring personal data outside the Kingdom. It applies to the processing of personal data of people in Saudi Arabia, including processing by organisations outside the Kingdom. If you hold data belonging to Saudi residents, it applies to that data wherever it is processed.

Its expectations follow the same shape as the UAE law: a lawful basis, with consent as the primary one; use limited to the stated purpose; rights for the people the data is about, including to be informed, to access, to correct and to have their data destroyed; appropriate security; records of processing; and, in some cases, a data protection officer. Breaches must be notified to SDAIA within a short, fixed period set in the regulations, and to the people affected where they are at risk. Transfers outside the Kingdom are allowed only under the conditions the transfer regulations set. SDAIA continues to issue guidance, and your legal team should check the current position.

What the law expects, and what the product does to support you

What the law expectsWhat the product does to support you
Know where data is processed, and control transfers abroadYou choose where your deployment runs: a UAE region, a Saudi Arabian region, your own cloud account or your own premises. All processing for your deployment runs in the region you choose, unless you explicitly choose a language model provider outside it. See Hosting and data residency
Limit what leaves your controlPersonal information is redacted before data leaves your deployment for anywhere other than your own systems and your own customers, including any provider outside your region and reports and exports. See Personal information redaction
Keep data only as long as neededNothing is stored without your permission, and you set how long each kind of content is kept. With content storage off, only a content-free audit record is kept, for the period you set
Keep data secureEncryption in transit with TLS (Transport Layer Security) 1.2 or higher, and at rest with AES-256 (the Advanced Encryption Standard with 256-bit keys). Each customer's data kept separate from every other customer's. See Encryption
Limit who can see dataSingle sign-on (one company login for many applications) through your identity provider, with multi-factor authentication (a second check beyond a password). Each person sees only what their role needs. See Access control and single sign-on
Be able to show what happenedAccess and changes are logged, and every conversation carries a record of what the agent looked up, did and why. See Audit trail and decision records
Respond to requests from the people the data is aboutYour team can find the conversations held about a person through search and the customer record. Telonic assists you with access, correction and deletion requests, as set out in your data processing terms
Delete data when it is no longer neededData is deleted at the end of the retention period you set. At the end of your agreement, your data is returned in a standard format, then deleted from live systems and from backups as they expire, with written confirmation
Report breaches promptlyPersonal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data, with ongoing updates. See Incident response
Control who else processes dataThe list of sub-processors (other companies Telonic uses to provide the service) is part of the data processing terms and available on request. You receive 30 days' notice of any change, with the right to object. See Sub-processors
Have a processor contractData processing terms form part of every agreement. See Contracts and data processing terms
Important

Personal data breaches are notified to your named contacts without undue delay, and within 24 hours of becoming aware of a breach affecting your data. Where your regulator sets a short deadline of its own, as the Saudi rules do, your legal team should plan how the two timings fit together. Tell us who your named contacts are and how to reach them out of hours, so no time is lost.

The networks your customers use

Your customers reach you through networks that carry the conversation to your deployment. Your carrier carries calls, and Meta's WhatsApp platform carries WhatsApp messages. Meta receives, processes and briefly stores WhatsApp messages on its own infrastructure before they reach your deployment, under its own terms, as it does for every business using WhatsApp.

Your legal team should take this into account when assessing the WhatsApp channel. See WhatsApp: overview.

Where consent is your lawful basis, the agent can capture it in the conversation and record it against the customer. Calls are recorded only once the caller has consented, and outbound WhatsApp messages are sent only to customers whose opt-in is on record. See Call recording and consent and Contact rules for outbound messages and calls.

In practice

A Dubai property developer sells units to buyers in the UAE and Saudi Arabia.

  1. Its legal team confirms that UAE law applies to its UAE buyers' data, and that Saudi law applies to data belonging to buyers resident in the Kingdom, wherever it is processed.
  2. After taking advice, the developer chooses the UAE region for its deployment, and records in its transfer assessment how Saudi buyers' data is handled. It chooses no provider outside the region.
  3. It sets retention: transcripts for the life of the sale plus the period its policy specifies, and call recordings for a shorter period.
  4. Khalid, a buyer in Riyadh, asks for a copy of what the developer holds about him. The data protection officer finds Khalid's conversations through search and his customer record, and provides him with a copy.
  5. The developer's named contacts for breach notices include an out-of-hours number, recorded in its data processing terms.

What your team controls

  • The hosting option and region, and whether any provider outside it may be used.
  • What is stored, and for how long.
  • Who in your organisation can see personal data.
  • Your lawful basis and consent wording.
  • Your named contacts for breach notices.

Product names and logos are trademarks of their owners. Their mention shows systems Telonic connects to and does not imply partnership or endorsement.