What a UAE business is actually exposed to online — with the amount, the instrument behind it, and a link to the source for every line.
The result is not the one most people expect. The data protection law has been in force since 2022 and still has no published penalty schedule, while the named amounts sit in advertising and in messaging — which is where nobody looks.
In short
Per violation, reported, for marketing without provable consent
Advertising without the permit, first offence. AED 40,000 on repeat
Published data-protection penalties. The schedule is still outstanding
Anyone publishing advertising content online from within the UAE holds an Advertiser Permit from the UAE Media Council.
Federal Media Law No. 55 of 2023 and Cabinet Resolution No. 42 of 2025, in force from 1 February 2026
Operating without a licence: AED 10,000 for a first offence, AED 40,000 for a repeat
The obligation reaches further than most brands assume. It applies to citizens, residents and visitors alike, to websites and blogs as well as social platforms, and — the part that catches people — to unpaid promotion as well as paid.
A personal account promoting its owner's own products or services is exempt. That exemption is exactly where the commercial risk sits: the moment a company pays or gifts a creator to promote it, the creator is advertising something that is not their own, and the arrangement is inside the regime.
The practical consequence for a business buying influencer placements is that the permit status of every creator on the campaign is now a procurement question, verified before the contract rather than after the post.
Source: Gulf News, 1 February 2026
Advertising content complies with the content rules attached to the permit regime.
Federal Media Law No. 55 of 2023 and Cabinet Resolution No. 42 of 2025
Content breaches: AED 5,000 to AED 1,000,000. Breaches affecting state interests or national security: AED 50,000 to AED 500,000
The upper bound is the reason this belongs on a checklist rather than in a policy document. A single campaign can carry an exposure two orders of magnitude above its media budget.
Source: Gulf News, 1 February 2026
Advertising does not carry false or misleading information.
Federal Media Law No. 55 of 2023 and Cabinet Resolution No. 42 of 2025
AED 5,000 to AED 10,000
A modest figure next to the others, and worth reading alongside them rather than alone: the same campaign that carries a misleading claim usually also carries the permit question, and the two are assessed together.
Source: Gulf News, 1 February 2026
The permit is current and used by the party it was issued to.
Federal Media Law No. 55 of 2023 and Cabinet Resolution No. 42 of 2025
Expired licence: AED 150 per day, capped at AED 3,000. Misuse of a licence: AED 20,000
The daily accrual is the mechanism worth understanding: an expiry nobody noticed is not a single event but a running total, and it stops only when it is renewed or the cap is reached.
Source: Gulf News, 1 February 2026
Marketing messages are sent only to recipients whose consent was obtained, clearly and verifiably, before the first message.
TDRA Regulatory Policy on Unsolicited Electronic Communications
Up to AED 400,000 per violation
Consent has to be demonstrable after the fact, which means a record of when it was given, by whom, and to what. A tick box with no log is the same as no consent when it is examined.
This is the clause that makes a purchased database indefensible rather than merely risky. Nobody on that list consented to hear from you, so every message is a violation at the moment it is sent — there is no volume at which it becomes compliant, and no wording that repairs it.
The same reasoning applies to a list acquired with a business, scraped from a directory, or exported from a previous employer. The question is never where the numbers came from; it is whether the person on the other end agreed, to you, before you wrote.
Source: TDRA, Regulatory Policy on Unsolicited Electronic Communications
Marketing SMS carries the required sender prefix and a working opt-out, and is sent inside the permitted hours.
TDRA marketing SMS rules
Enforced under the same policy; up to AED 400,000 per violation
Promotional traffic is identified as such — the `AD-` prefix — and carries the published opt-out code. Classifying a promotional message as transactional to avoid the prefix is itself the violation, and it is visible to the operator carrying it.
Opt-outs are processed promptly rather than at the next campaign. A person who unsubscribed and received another message is the standard origin of a complaint.
Personal data is processed on a lawful basis, with the data subject rights the law grants, and cross-border transfers meet its conditions.
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, in force 2 January 2022
No penalty schedule has been published. The executive regulations that would set the amounts remain outstanding.
This is the finding rather than a gap in the research. The law has been in force since January 2022, and the executive regulations that were to specify administrative penalties had still not been issued as of reporting in early 2025. Any source quoting a specific PDPL fine is quoting something that has not been published.
An obligation without a published number is not an absence of obligation. It is an exposure whose size is not yet known, which is a worse planning position rather than a better one — and it can be set retrospectively in the sense that conduct today is judged against the law as it stands today.
The practical response is unchanged by the uncertainty: know what personal data you hold, why you are allowed to hold it, who can reach it, and how someone asks for it to be corrected or removed. None of that becomes cheaper by waiting for the number.
Personal information is not published, intercepted or disclosed without authorisation through an information system.
Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, in force 2 January 2022
Privacy violation through information technology: AED 150,000 to AED 500,000 and/or imprisonment from six months. Disclosure of confidential information obtained through work: imprisonment from six months and/or AED 200,000 to AED 1,000,000
Where the data protection law has no published penalties, this one does — and it is the instrument under which misuse of personal information is actually prosecuted today. It applies to individuals as well as companies, including employees acting on their own initiative.
Its reported overall range runs from AED 20,000 to AED 3,000,000 across the offences it defines.
Source: Baker McKenzie, Global Data and Cyber Handbook — UAE
The site identifies the legal entity behind it — the licensed name, the licensing authority and the licence number.
Trade licensing practice; requirements differ by emirate and by free zone
Set by the licensing authority rather than federally; verify against your own licence
Verify this one against your own licence and your own authority rather than against a general article, because the requirement and its wording differ between the mainland departments of economic development and the free zones, and between free zones.
It is worth doing beyond compliance. A site that names its entity and its licence number is publishing the only claim on it a reader can independently check, and search engines and assistants resolve an entity far more reliably when the identifiers are stated.
The domain, the advertising accounts, the analytics and the social profiles are registered to the company rather than to an individual or a supplier.
Not a regulatory requirement. A commercial one.
No fine. The cost is the asset itself, and it is usually discovered during a dispute.
Included on a compliance checklist deliberately, because it is the item that costs the most and carries no penalty at all. A domain registered to a former contractor is not yours in any sense that survives a disagreement, and no regulator will help.
The check is a single question per row of the register: whose name is on the account. Not who paid for it, and not who uses it.
Access is revoked on the last working day, ownership of what the person holds is transferred first, and shared credentials are rotated.
Not a regulatory requirement, and interacts with employment and visa timing in the GCC.
No fine. The exposure is unauthorised access after departure, which is prosecutable under the cybercrimes law.
The administrative side of a departure in the GCC runs on its own schedule — notice, visa cancellation, final settlement — and technical revocation should not wait for any of it.
Transfer before you revoke. A sole administrator removed from a business account can leave that account with no administrator at all, and recovering it is a support case measured in weeks.
Source: Glossary — offboarding
Repetition changes the tier
Operating without the advertising permit is AED 10,000 the first time and AED 40,000 the second. The escalation is written into the schedule, so the second campaign run the same way is not a repeat of the first cost.
Some of it runs daily
An expired permit accrues at AED 150 a day to a cap of AED 3,000. Nobody decides to incur it; it is what a renewal nobody was watching costs while it is not being watched.
Messaging is counted per violation
The reported ceiling for unsolicited electronic communications is per violation rather than per campaign. A purchased list is not one decision with one exposure — it is a quantity of them.
One breach is rarely alone
The campaign that used an unpermitted creator is usually the campaign that also carried the unverified claim, and both are assessed against the same activity rather than in isolation.
- What is the largest named fine a UAE business faces for its online marketing?
- Under the advertising permit regime introduced by Federal Media Law No. 55 of 2023 and Cabinet Resolution No. 42 of 2025, content breaches carry AED 5,000 to AED 1,000,000, and breaches affecting state interests or national security AED 50,000 to AED 500,000. Operating without the required Advertiser Permit is AED 10,000 for a first offence and AED 40,000 for a repeat.
- Can a UAE business send marketing messages to a purchased list of phone numbers?
- No. The TDRA Regulatory Policy on Unsolicited Electronic Communications requires clear, verifiable consent obtained before the first marketing message, with penalties reported at up to AED 400,000 per violation. Nobody on a purchased list consented to hear from the buyer, so every message is a violation at the moment it is sent.
- What is the fine for breaching the UAE Personal Data Protection Law?
- There is no published schedule. Federal Decree-Law No. 45 of 2021 has been in force since 2 January 2022, but the executive regulations that were to specify administrative penalties had still not been issued as of reporting in early 2025. Misuse of personal information is prosecuted today under the cybercrimes law instead, where privacy violation through information technology carries AED 150,000 to AED 500,000 and imprisonment from six months.
- Does a UAE website need a cookie consent banner?
- We could not identify a UAE instrument equivalent to the EU ePrivacy consent rule. The data protection law still applies to any personal data a cookie or tag collects, so the notice describing it has to be truthful. A banner copied from a European template usually describes a regime the site is not in and lists processing it does not perform, which is a false statement published on your own domain.
- Does the advertiser permit apply to a company advertising its own products?
- A personal account promoting its owner's own products or services is exempt. The exemption is where the commercial risk sits: as soon as a company pays or gifts a creator to promote it, the creator is advertising something that is not their own and the arrangement is inside the regime, which makes the creator's permit status a procurement question for the brand.
Every figure above is attributed and dated, and the review was carried out on 4 August 2026. 7 of the 12 lines carry a named amount; the rest state honestly that none is published, or that the item is a commercial risk rather than a regulated one.
Three things are deliberately absent. We did not identify the specific article of the cybercrimes law that governs unsolicited commercial messaging, so it is not cited. We excluded the fine figures circulating in business-setup blogs — they are marketing content rather than primary sources, and several disagree with each other. And the statement that the UAE has no cookie-consent requirement is an absence rather than a finding: we could not identify such an instrument, which is not the same as establishing that none exists.
We hold an LL.M in International Business Law and read these instruments as part of the work. That is a reason to take the page seriously and not a substitute for counsel on your own facts — particularly on licensing, which differs by emirate and by free zone.