By Sagar Shankaran, Founder of CallSphere
Master Dubai and UAE calling compliance across DIFC, ADGM, and onshore regulations with this guide to recording, consent, and data residency rules.
Key takeaways
The United Arab Emirates presents a unique regulatory challenge for financial services firms: three distinct regulatory frameworks operate simultaneously, each with its own rules governing telephone communications, call recording, data protection, and consumer conduct.
Each framework has distinct data protection legislation, financial services regulations, and enforcement mechanisms. A financial institution operating across all three environments must comply with each applicable framework simultaneously.
In 2025, combined regulatory enforcement across these three frameworks totaled AED 187 million in fines, with communication compliance failures — particularly inadequate call recording and consent management — cited in 28% of enforcement actions.
The UAE's federal data protection law, effective since January 2022 with enforcement beginning in 2023, establishes the baseline for call recording consent:
flowchart LR
CALLER(["Client or Lead"])
subgraph TEL["Telephony"]
SIP["Twilio SIP and PSTN"]
end
subgraph BRAIN["Financial Services AI<br/>Agent"]
STT["Streaming STT<br/>Deepgram or Whisper"]
NLU{"Intent and<br/>Entity Extraction"}
TOOLS["Tool Calls"]
TTS["Streaming TTS<br/>ElevenLabs or Rime"]
end
subgraph DATA["Live Data Plane"]
CRM[("CRM and Notes")]
CAL[("Calendar and<br/>Schedule")]
KB[("Knowledge Base<br/>and Policies")]
end
subgraph OUT["Outcomes"]
O1(["KYC pre-fill done"])
O2(["Funding instructions sent"])
O3(["Compliance officer<br/>escalation"])
end
CALLER --> SIP --> STT --> NLU
NLU -->|Lookup| TOOLS
TOOLS <--> CRM
TOOLS <--> CAL
TOOLS <--> KB
NLU --> TTS --> SIP --> CALLER
NLU -->|Resolved| O1
NLU -->|Schedule| O2
NLU -->|Escalate| O3
style CALLER fill:#f1f5f9,stroke:#64748b,color:#0f172a
style NLU fill:#4f46e5,stroke:#4338ca,color:#fff
style O1 fill:#059669,stroke:#047857,color:#fff
style O2 fill:#0ea5e9,stroke:#0369a1,color:#fff
style O3 fill:#f59e0b,stroke:#d97706,color:#1f2937
Penalties: Up to AED 5 million per violation; repeat violations can result in doubled penalties.
The CBUAE's Consumer Protection Standards (effective 2023) impose specific requirements on telephone interactions:
The SCA regulates securities and commodities markets onshore. Key communication requirements:
The DFSA's Conduct of Business Module establishes comprehensive requirements for client communications:
COB Rule 3.2 — Communication with Clients:
Hear it before you finish reading
Talk to a live CallSphere AI voice agent for financial services in your browser — 60 seconds, no signup.
COB Rule 6.11 — Recording of Telephone Conversations:
The DIFC has its own data protection framework, modeled closely on GDPR:
Penalties: Up to USD $100,000 per violation by the Commissioner of Data Protection; DFSA can impose additional regulatory penalties.
In its 2024 thematic review of communication surveillance practices, the DFSA identified several common deficiencies:
The ADGM's FSRA imposes communication requirements similar to the DFSA but with specific ADGM nuances:
COBS Rule 3.3 — Recording of Telephone Communications:
COBS Rule 2.6 — Fair Treatment of Customers:
The ADGM data protection framework (separate from both onshore UAE and DIFC):
Penalties: Up to USD $28 million per violation by the ADGM Office of Data Protection.
A financial group operating in the UAE may simultaneously hold:
Each entity within the group is subject to its respective framework's call recording, data protection, and conduct requirements. Client calls may involve participants in different jurisdictions within the UAE itself.
Step 1: Unified Recording Standard Apply the most stringent recording requirement across all frameworks:
Still reading? Stop comparing — try CallSphere live.
See the financial services AI agent handle a real call — complete, industry-specific, and live in your browser. No signup.
Step 2: Jurisdiction-Aware Consent Management Tailor consent notifications based on the regulatory framework applicable to the specific interaction:
Step 3: Centralized Recording Infrastructure with Logical Separation Maintain a single recording platform with logical separation by regulatory entity:
CallSphere provides multi-entity, multi-jurisdiction recording infrastructure that supports the UAE's unique regulatory landscape, with configurable consent flows, retention policies, and access controls per regulatory framework.
The UAE's federal data protection law does not impose strict data localization, but several practical considerations apply:
Major cloud providers have established UAE data center regions:
These local cloud regions enable firms to satisfy data residency preferences while leveraging cloud scalability and compliance certifications.
The UAE's consumer protection framework requires that financial communications be available in both Arabic and English:
CallSphere's platform supports Arabic language processing with Gulf Arabic dialect optimization, enabling accurate transcription and compliance monitoring for Arabic-language calls.
The applicable regulator depends on your license and the location of your operations. If you hold a CBUAE or SCA license, onshore UAE rules apply. If you operate from the DIFC, the DFSA framework applies. If you operate from the ADGM, the FSRA framework applies. Many financial groups hold multiple licenses and must comply with each applicable framework for the respective entity's activities.
The minimum retention period varies by regulator: SCA requires 5 years, DFSA requires 6 years, and FSRA requires 6 years. If you operate under multiple frameworks, apply the longest applicable period (6 years). Some firms voluntarily retain for 7 years to provide an additional margin of safety.
There is no absolute legal requirement for data localization in the UAE, but strong regulatory preferences favor domestic storage. The CBUAE has expressed preference for customer data remaining in the UAE. The DIFC and ADGM allow cross-border transfers with appropriate safeguards. Given the availability of UAE-based cloud regions from major providers, domestic storage is both practical and advisable.
Yes, but the system must support logical separation between regulatory entities, with separate access controls, audit trails, and potentially different retention policies per entity. Each regulator may request recordings only for the entity it supervises, and your system must be able to isolate and produce recordings on a per-entity basis. CallSphere supports multi-entity deployments with configurable separation and unified administration.
For onshore operations, consent notification must be provided in both Arabic and English. For DIFC and ADGM operations, English is sufficient but Arabic availability is recommended for retail clients. The notification should clearly state that the call is being recorded, the purposes of recording, the retention period, and the data subject's rights regarding the recording.
Written by
Sagar Shankaran· Founder, CallSphere
Sagar Shankaran is the founder of CallSphere, where he builds production AI voice and chat agents deployed across healthcare, hospitality, real estate, and home services. He writes about agentic AI, LLM engineering, and shipping voice agents that handle real calls in production.
See how AI voice agents work for your industry. Live demo available -- no signup required.
Memory stores live in regions, and that matters for GDPR, UK GDPR, and Schrems II compliance posture. The residency architecture for EU agent deployments built right.
Texas SB 1188 requires US-resident EHRs from January 1, 2026; Nevada's consumer-health-data law constrains health data; Colorado AI Act takes effect June 30, 2026. AI voice agents must architect for state-by-state data localization.
Claude Opus 4.6 introduces data residency controls, zero-data-retention options, and regional processing to meet enterprise compliance requirements globally.
A 2026 market read on financial services and fintech SMBs across Singapore, Malaysia, the Philippines, and Indonesia — and how CallSphere AI voice and chat agents deliver multilingual, compliant, 24/7 customer conversations.
Liechtenstein private banks, trustees and wealth advisers use CallSphere AI voice and chat agents for discreet, GDPR-grade client handling in German and English around the clock, priced in CHF.
Seychelles corporate service providers, law firms, and accountants use CallSphere AI voice and chat agents to answer international client enquiries 24/7, qualify leads, and comply with the Data Protection Act.
© 2026 CallSphere LLC. All rights reserved.
Made within New York
Watch how CallSphere handles real customer calls, schedules appointments, and processes payments — live.
Try Live DemoBook a DemoCalculate Your ROI