HomeGuidesPDPL Compliance (GCC)
GCC · Data Protection · WhatsApp API

PDPL compliance for WhatsApp messaging in UAE, Saudi, Oman & Jordan — the enterprise procurement guide.

Between 2022 and 2024, every major GCC economy passed a Personal Data Protection Law. Enterprise procurement teams now include “PDPL-compliant?” as a first-round filter for any communications vendor. This guide covers what each country’s PDPL requires for WhatsApp messaging specifically — the article-by-article consent rules, the DPA obligations on vendors, the data residency expectations, and what “compliant” actually looks like in a procurement audit.

✓ Signed DPA available on request ✓ Meta Business Partner · GCC data controls ✓ 1,500+ businesses across GCC + India + Europe
PDPL compliance for WhatsApp Business API across UAE, Saudi Arabia, Oman, Jordan, Bahrain, Qatar
TL;DR

Every GCC country now has a Personal Data Protection Law (PDPL) covering WhatsApp marketing. UAE PDPL, Saudi PDPL (SDAIA), Oman Royal Decree 6/2022, Jordan PDPL, Bahrain PDPL, and Qatar DPL each require explicit prior consent for marketing messages, define retention limits, and impose fines for non-compliance. Enterprise buyers now filter WhatsApp vendors on whether they sign a Data Processing Agreement (DPA) that maps to the local PDPL. Go4whatsup provides a signed DPA covering all 6 GCC PDPLs plus GDPR (for EU entities) and India DPDP Act.

Key facts
  • 6 GCC/near-GCC PDPLs in force as of 2026: UAE (2021), Saudi (2021, updated 2023), Oman Royal Decree 6/2022, Jordan (2023), Bahrain (2018), Qatar (2016 + 2023 revision)
  • All 6 require explicit opt-in for marketing communications — implied consent from a purchase alone is NOT sufficient
  • Maximum fines range from AED 1M (UAE) to SAR 5M (Saudi) per violation, with per-record penalties in Oman
  • Enterprise procurement requires: signed DPA, data residency disclosure, breach notification within 72 hours, documented retention limits

Quick answers

Q: Is WhatsApp Business API automatically PDPL-compliant? A: No. Meta’s WhatsApp Business API is the technical layer. PDPL compliance is a business obligation on the sender — you need explicit consent, retention limits, breach procedures, and a DPA with your vendor.
Q: Do I need explicit consent to send WhatsApp marketing in UAE? A: Yes. UAE PDPL (Federal Decree-Law No. 45 of 2021) requires prior, informed, specific consent for marketing. Purchase-time consent does NOT extend to marketing.
Q: Does Go4whatsup sign a DPA for GCC customers? A: Yes. Signed DPA available on request, covering all 6 GCC PDPLs plus GDPR (EU) and India DPDP Act. Typically returned within 48 hours.

Why PDPL suddenly matters for WhatsApp in GCC

Before 2020, GCC data protection was governed by patchwork sector rules — banking secrecy laws, telecom regulations, health data acts. Marketing on WhatsApp lived in a grey zone. Then between 2021 and 2024, every major GCC economy passed a comprehensive PDPL modelled loosely on GDPR. Enforcement lagged the passage by 12–18 months, so by 2024–2026 the first meaningful fines started appearing — Saudi SDAIA issued its first published penalty in 2024, UAE PDPL cases began proceeding in 2025.

The consequence for WhatsApp marketing: enterprise procurement teams now filter out non-compliant vendors in round one. If your CRM or WhatsApp platform can’t produce a DPA that references the local PDPL, you don’t make the shortlist. This isn’t new bureaucracy — it’s the same standard European enterprises have applied for years under GDPR, now landed in GCC.

UAE PDPL — what it says about WhatsApp marketing

🇦🇪 United Arab Emirates

Federal Decree-Law No. 45 of 2021 concerning the Protection of Personal Data
  • Consent (Article 6): Marketing requires prior, informed, specific, and unambiguous consent — separate from any transactional consent.
  • Withdrawal right: Users must be able to withdraw consent as easily as it was given. WhatsApp opt-out (STOP command) must be honoured within reasonable time.
  • Data controller obligations: Maintain a record of consent — timestamp, source, wording of the consent notice.
  • Data subject rights: Access, correction, deletion, portability.
  • Breach notification: 72 hours to the UAE Data Office, without undue delay to affected individuals if high risk.
Penalty: Up to AED 1M per violation; higher for repeat offenders or sensitive data breaches.

Saudi PDPL — the SDAIA-supervised regime

🇸🇦 Kingdom of Saudi Arabia

Personal Data Protection Law (2021, amended by Royal Decree M/148 of 2023); Regulator: SDAIA
  • Consent (Article 5): Explicit consent required for marketing. Consent for one purpose does not extend to another.
  • Data localisation: Personal data of Saudi residents must be processed within KSA unless SDAIA-approved cross-border transfer mechanism is in place.
  • DPO requirement: Businesses processing significant volumes must appoint a Data Protection Officer, notify SDAIA.
  • Data subject rights: Access, correction, deletion, restriction — implemented within 30 days of request.
  • Breach notification: To SDAIA within 72 hours; to affected individuals promptly if high risk.
Penalty: Up to SAR 5M per violation; 2 years imprisonment for wilful disclosure of sensitive data.

Oman PDPL (Royal Decree 6/2022)

🇴🇲 Sultanate of Oman

Royal Decree No. 6/2022 (Personal Data Protection Law)
  • Explicit consent: Required for marketing, must be documented, must include specific purposes.
  • Retention limits: Data may only be retained as long as necessary for the original purpose.
  • Cross-border transfer: Restricted; requires either adequacy decision or explicit consent.
  • Sensitive data: Health, religion, ethnicity — additional layer of protection, generally requires written consent.
Penalty: Fines calibrated per-record for large-scale violations; OMR 500,000 maximum for major breaches.

Jordan PDPL + TRC opt-in requirements

🇯🇴 Hashemite Kingdom of Jordan

Personal Data Protection Law No. 24 of 2023 + TRC (Telecommunications Regulatory Commission) opt-in rules
  • Two-layer consent regime: PDPL requires prior consent for processing; TRC additionally requires opt-in specifically for electronic marketing (SMS + WhatsApp + email).
  • Do-not-call registry: Jordan operates a national opt-out registry — vendors must scrub against it before marketing sends.
  • Breach notification: 72 hours to Jordan’s Data Protection Council.
Penalty: JOD 100,000+ per violation; TRC can also suspend a business’s telecom licence for repeated violations.

Bahrain PDPL — the earliest GCC regime

🇧🇭 Kingdom of Bahrain

Personal Data Protection Law No. 30 of 2018 (Bahrain was the first GCC country to pass a comprehensive PDPL)
  • Cross-border data transfer: Bahrain PDPL is unusually strict — requires either Personal Data Protection Authority approval or a specific legal basis.
  • Consent + purpose limitation: Standard opt-in; data cannot be used for a purpose outside what was consented to.
  • DPO for processors above threshold: Required if processing significant personal data volumes.
Penalty: BHD 20,000+ per violation; up to 1 year imprisonment for certain breaches.

Qatar DPL — sector-specific carve-outs

🇶🇦 State of Qatar

Personal Data Privacy Protection Law No. 13 of 2016 (updated 2023)
  • Consent required for processing personal data of special nature (including marketing behavioural data).
  • Notice-based model: Businesses must publish a privacy notice explaining what data is processed and why.
  • Sector-specific carve-outs: Financial services, healthcare, government have additional sectoral rules layered on top.
  • Breach notification: To Qatar’s Compliance and Data Protection Department (CDP).
Penalty: QAR 5M maximum for major breaches; smaller fines for procedural non-compliance.

What WhatsApp API vendors must provide (procurement checklist)

What GCC enterprise procurement teams look for during vendor evaluation:

Signed DPA / AVV

Data Processing Agreement mapping to the local PDPL. Signed by the vendor DPO. Countersigned by the customer’s legal counsel.

Data residency disclosure

Where personal data is stored, processed, and transferred. For KSA specifically — whether data stays in KSA or crosses borders under an SDAIA-approved mechanism.

Breach notification procedure

Vendor commits to notifying customer within 24-48 hours of any breach, so the customer can meet its own 72-hour regulator obligation.

Retention + deletion controls

Documented retention periods, mechanism for customer-initiated deletion of contact records, audit log of deletion actions.

Access + correction API

Ability for customer to fulfil data subject access requests (DSARs) programmatically or via support ticket within regulator SLA.

Sub-processor list

Named list of every sub-processor with access to customer data (typically Meta, hosting provider, analytics). Change notification when the list updates.

Consent language template (GCC-ready, English + Arabic)

Use this as the opt-in wording for marketing WhatsApp lists. Meets UAE PDPL, Saudi PDPL, Oman PDPL, Jordan PDPL requirements simultaneously.

What Go4whatsup provides out-of-box for GCC compliance

  • Signed DPA on request covering UAE PDPL, Saudi PDPL, Bahrain PDPL, Oman PDPL (Royal Decree 6/2022), Qatar DPL, Jordan PDPL — plus GDPR for EU entities and DPDP Act for India.
  • Documented data residency: Primary data centres and sub-processors listed in the DPA. Cross-border transfer mechanism spelled out for KSA and Oman.
  • 24-hour breach notification SLA to the customer, faster than any regulator’s 72-hour requirement.
  • Configurable retention controls: Set contact retention limits per country. Auto-delete on customer request. Full audit log.
  • DSAR support: Data Subject Access Requests fulfilled within 15 business days (well inside Saudi’s 30-day requirement).
  • Consent management: Opt-in and opt-out logged with timestamp, source, and exact consent wording. Auditable for regulator inspection.
  • Do-not-contact list scrubbing: Automatic exclusion of contacts once they’ve opted out. Jordan TRC do-not-call registry integration on request.
  • Sub-processor transparency: Named list of all third parties with access. Notification when the list changes.

Get our GCC PDPL compliance packet + signed DPA

We’ll send our DPA, sub-processor list, data residency disclosure, and consent template — all mapped to the 6 GCC PDPLs. Signed DPA typically returned within 48 hours.

Frequently asked questions

Is WhatsApp Business API automatically PDPL-compliant?

No. Meta’s WhatsApp Business API is the message transport layer. PDPL compliance is a business obligation on the sender — you need explicit consent, retention limits, breach procedures, and a DPA with your vendor.

Do I need explicit consent to send WhatsApp marketing in UAE?

Yes. UAE PDPL (Federal Decree-Law No. 45 of 2021) requires prior, informed, specific consent. Consent obtained during a purchase for transactional messages does not extend to marketing.

Does Go4whatsup sign a DPA for GCC customers?

Yes. Signed DPA available on request, covering all 6 GCC PDPLs plus GDPR (EU) and India DPDP Act. Typically returned within 48 hours.

Where is customer data stored — is it in the GCC or outside?

Depends on customer tier and country. For KSA-specific requirements, we can process Saudi customer data within KSA via SDAIA-approved mechanisms. Sub-processor list documented in the DPA.

What is the difference between UAE PDPL and Saudi PDPL for WhatsApp?

Both require explicit consent and 72-hour breach notification. Saudi enforces data localisation; UAE is more permissive on cross-border transfers. Saudi DPO thresholds lower.

Can I be fined for non-PDPL WhatsApp campaigns in Oman?

Yes. Oman’s Royal Decree 6/2022 imposes per-record penalties for large-scale marketing without consent. OMR 500,000 maximum for major breaches. Enforcement active since 2024.

Do I need a separate opt-in for Jordan on top of consent?

Yes. Jordan operates a two-layer regime: PDPL (2023) requires prior consent for processing; TRC additionally requires opt-in specifically for electronic marketing. Vendors must scrub against Jordan’s national do-not-call registry.

Is this legal advice?

No. This guide is a plain-language summary of the PDPL landscape as we understand it in 2026. For binding compliance decisions, consult qualified legal counsel in the applicable jurisdiction.

Legal disclaimer. This guide is provided for informational purposes only and does not constitute legal advice. Go4whatsup is a Meta Business Partner and WhatsApp API software vendor, not a law firm. PDPL laws change; regulators issue new guidance; every business’s obligations depend on its specific facts. For binding compliance decisions, consult qualified legal counsel in the applicable jurisdiction. Article numbers and penalty ranges cited are as of publication (September 2026) and may have changed.