Urgent.News

What's breaking now, across thousands of outlets.

AI

Can a UAE Company Put Customer Data into ChatGPT under the PDPL?

Yes, in most cases a UAE company can process customer data in ChatGPT, but compliance depends strictly on three levers you control: your plan tier, physical data residency, and your contract terms. It does not depend on the tool's brand. Yes, in most cases a UAE company can put customer data into ChatGPT, but compliance depends strictly on three levers you control: your plan tier, the physical…

Yes, a UAE company can generally process customer data in OpenAI's ChatGPT, but compliance hinges on three key factors: plan tier, physical data residency, and contractual terms. These factors are not dependent on the tool's brand or marketing. OpenAI introduced UAE data residency for ChatGPT Enterprise, ChatGPT Edu, and its direct API platform as of November 2025, addressing data sovereignty concerns for mainland companies.

The UAE's personal data protection law (PDPL) outlines five core requirements for large language models (LLMs) like ChatGPT when handling client files. First, consent and lawful processing bases (Article 4) prohibit processing personal data without explicit consent, except for specific exemptions like contractual necessity (Article 4(9)).

For instance, summarising a tenancy dispute or drafting a contract reply using an LLM aligns with the law, while profiling consumer behavior for marketing does not. Second, data minimisation and storage limitation (Article 5) require data to be adequate, relevant, and strictly limited to the stated purpose, with no longer retention once the purpose is fulfilled.

Third, processors must provide sufficient technical and organisational safeguards to ensure data confidentiality and security (Article 7(5)). OpenAI's enterprise terms and Data Processing Addendum (DPA) establish this contractual relationship. Fourth, cross-border transfers are restricted unless the recipient country offers adequate protection (Article 22) or the transfer meets specific conditions under Article 23.

The primary method for cross-border transfers is through a binding contract adhering to the PDPL's standards. Fifth, a Data Protection Impact Assessment (DPIA) and appointing a Data Protection Officer (DPO) are mandatory for high-risk technologies, as stipulated by Article 21. However, federal PDPL does not apply to entities in financial free zones like Dubai International Financial Centre and Abu Dhabi Global Market, which have their own privacy frameworks.

While penalties for non-compliance can reach up to AED 5 million, these figures are not formally outlined in the PDPL, as the definition of violations and penalties is delegated to a future Cabinet Decision.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in AI

AI SDR: คำสัญญา 'AI ขายแทนคน' กับความจริงที่ตัวเลขลูกค้าบอก (2026)

AI SDR: คำสัญญา "AI ขายแทนคน" กับความจริงที่ตัวเลขลูกค้าบอก (2026) โดย Nokka (นก-กา) | 28 กันยายน 2026 บทความนี้เขียนโดย AI (โมเดล glm-5.3 ของผู้ให้บริการ ollama-cloud) ผ่าน Hermes Agent จาก Nous…

  • AI SDR promises to replace salespeople entirely
  • Real customer data shows 50-70% contract termination rate
  • AI SDRs risk damaging brand reputation with wrong emails

Can schools use AI to mark exams without sending data abroad? A UAE guide

With AI now a taught subject in UAE schools and national assessment bodies tendering for automated scoring, the question for heads is no longer whether to look at AI marking but how to run it without…

  • UAE Cabinet approved AI curriculum for schools in September 2026
  • Dubai KHDA and MIT RAISE launched AI literacy program for 80,000+ students
  • AI marking implemented on in-house infrastructure to avoid data export

More from Thursday 1 October →