UAE PDPL sets out rules for how organisations collect, process, store, and transfer personal data, including requirements to obtain a legal basis for processing, keep data reasonably secure, and inform individuals about how their data is used. It requires organisations to put formal data processing agreements in place with any third-party vendor that processes personal data on their behalf, and it restricts transferring personal data outside the UAE unless adequate safeguards or an approved mechanism are in place.
For an AI concierge platform handling banking, healthcare, and government customer conversations, UAE PDPL compliance directly shapes where conversation data can be hosted and which vendors can be used, since sensitive personal data such as account details or medical information may be exchanged through WhatsApp or web chat. Data processing agreements and data residency arrangements are not optional extras in these sectors, but a baseline requirement for a vendor to be considered for deployment at all.
In Eshal: Eshal provides a PDPL-compliant data processing agreement to all UAE customers and processes data on OVHcloud Dubai to satisfy data residency requirements under the law. This combination lets banking, healthcare, and government customers deploy Eshal's AI concierge on WhatsApp and web chat while meeting their own PDPL obligations around third-party processors and cross-border data transfer restrictions.