Can a UAE Company Put Customer Data into ChatGPT under the PDPL?
Yes, in most cases a UAE company can process customer data in ChatGPT, but compliance depends strictly on three levers you control: your plan tier, physical data residency, and your contract terms. It does not depend on the tool's brand. Yes, in most cases a UAE company can put customer data into ChatGPT, but compliance depends strictly on three levers you control: your plan tier, the physical…
Yes, a UAE company can generally process customer data in OpenAI's ChatGPT, but compliance hinges on three key factors: plan tier, physical data residency, and contractual terms. These factors are not dependent on the tool's brand or marketing. OpenAI introduced UAE data residency for ChatGPT Enterprise, ChatGPT Edu, and its direct API platform as of November 2025, addressing data sovereignty concerns for mainland companies.
The UAE's personal data protection law (PDPL) outlines five core requirements for large language models (LLMs) like ChatGPT when handling client files. First, consent and lawful processing bases (Article 4) prohibit processing personal data without explicit consent, except for specific exemptions like contractual necessity (Article 4(9)).
For instance, summarising a tenancy dispute or drafting a contract reply using an LLM aligns with the law, while profiling consumer behavior for marketing does not. Second, data minimisation and storage limitation (Article 5) require data to be adequate, relevant, and strictly limited to the stated purpose, with no longer retention once the purpose is fulfilled.
Third, processors must provide sufficient technical and organisational safeguards to ensure data confidentiality and security (Article 7(5)). OpenAI's enterprise terms and Data Processing Addendum (DPA) establish this contractual relationship. Fourth, cross-border transfers are restricted unless the recipient country offers adequate protection (Article 22) or the transfer meets specific conditions under Article 23.
The primary method for cross-border transfers is through a binding contract adhering to the PDPL's standards. Fifth, a Data Protection Impact Assessment (DPIA) and appointing a Data Protection Officer (DPO) are mandatory for high-risk technologies, as stipulated by Article 21. However, federal PDPL does not apply to entities in financial free zones like Dubai International Financial Centre and Abu Dhabi Global Market, which have their own privacy frameworks.
While penalties for non-compliance can reach up to AED 5 million, these figures are not formally outlined in the PDPL, as the definition of violations and penalties is delegated to a future Cabinet Decision.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.