Telonic

PlatformSEP 30, 2026Anthony Ombrore

What a customer record has to hold when every channel writes to it

When calls, WhatsApp messages, texts, emails and web chats all feed one record, the record is only useful if it is built around issues, commitments and confirmed facts rather than a pile of messages. This article sets out what the evidence says a record needs, what it should deliberately leave out, and how we design for both.

On this page
  1. The situation
  2. What the evidence shows
  3. What that means
  4. How we design for it
  5. What we don't know yet
  6. Sources

The situation

A motor claim in Dubai rarely arrives through one door. The policyholder calls on Sunday night to report the accident. On Monday she sends photographs of the damage over WhatsApp. On Tuesday she emails from her work address to ask what happens next. On Wednesday her brother calls, because she is in a meeting and he has the police report in his hand. That report matters more than anything else in the file: in the UAE, the police report decides which insurer handles the claim, and until someone reads it nobody can tell her whether she is even in the right queue.

By Thursday there are four contacts in four systems. The telephony platform holds a recording. The WhatsApp inbox holds the photographs. The mailbox holds the email. The brother's call sits under a number the insurer has never seen. The handler who opens the email sees one message, not one claim, and asks for the photographs again. The same pattern runs through a property handover and a disrupted flight.

What the evidence shows

Repeating yourself is common, measured and costly

The best-known figures come from Salesforce's State of the Connected Customer, sixth edition, 2023 [1]. In a survey of 11,000 consumers and 3,300 business buyers across 25 countries, fielded May to July 2023, 56% of customers said they often have to repeat or re-explain information to different representatives, and 55% said it generally feels like they are communicating with separate departments, not one company. The UAE was in the sample, with 650 respondents; Saudi Arabia was not, and no UAE-only cut of those two figures was published. Treat it as a measure of how common the experience is, not of what it costs: the survey is a vendor's and the wording is self-report.

The cost shows up in official indices. The UK Customer Satisfaction Index, a survey of over 15,000 UK consumers covering 59,500 customer experiences, found in July 2025 that 26% of customers needed more than one channel to achieve their objective [2]. A 2020 Arizona State University study of a representative panel of 1,026 US households found people made nearly three contacts on average to resolve a problem, and that satisfaction with the outcome fell from 43% at one contact to 24% at six or more [3]. The foundational work is a 2010 Harvard Business Review study of more than 75,000 customers, in which 56% had to re-explain an issue and 62% had to contact the company repeatedly [4]; it is 16 years old and not peer reviewed, but it is where the idea of customer effort comes from.

The nearest Gulf evidence is KPMG's 2024 study of 1,612 UAE customers, which attributed part of a fall in experience scores to technology that "shepherded customers into low-cost and low-satisfaction channels" [5]: a warning about how channels are added, not against adding them. It is the closest regional figure there is. Everything else above comes from outside the Gulf, and we found no published UAE or Saudi figure for how often customers repeat themselves.

A match between channels is a probability, not a fact

Identity resolution is the job of deciding that a phone number, a WhatsApp account, an email address and a web session belong to the same person. The simplest way to do it is exact match: same number, same person. The evidence says that is not safe.

Start with WhatsApp itself. Meta's developer documentation states, twice, that "a WhatsApp user's ID and phone number may not always match" [6]. When a user changes number, the business receives a system notice and a new user ID [7]. Meta also issues an identity hash for each user, and tells businesses that if it changes they should "assume the customer's phone number can no longer be trusted" and verify identity through another channel [8]. The company that runs the channel is saying the number is not a permanent identity.

Numbers are also plural and reused. World Bank telecoms data, drawn from the International Telecommunication Union, puts mobile subscriptions at 203 per 100 people in the UAE and 160 per 100 in Saudi Arabia in 2024 [9]. The count includes business and machine connections, but it still means many people hold more than one number. In the US, the Federal Communications Commission estimated in 2018 that about 35 million numbers are disconnected and reassigned each year [10]; no Gulf regulator publishes an equivalent figure.

Then there is who is speaking. Saudi Arabia's 2022 census put non-Saudis at 41.6% of the population [11]. The International Labour Organization estimated 3.7 million domestic workers in Saudi Arabia in 2019 and about 890,000 in the UAE in 2018, and notes that in most Gulf states domestic work is a fifth to a quarter of the labour force [12]. Drivers, household staff, personal assistants and family members contact businesses on other people's behalf every day, and the Central Bank of the UAE's Consumer Protection Standards allow a financial institution to disclose a customer's information, apart from under a legal order, only with the customer's express consent or "through a representative nominated by the Consumer" [13]. The brother with the police report is a common case and a legally distinct one. Names do not rescue the match: a 2006 MITRE study found a single Arabic name maps to many Latin spellings, and plain string matching performed poorly until rebuilt to allow one-to-many mappings [14].

The discipline that handles this is record linkage, and its foundational paper is from 1969 [15]. Its central idea is that a match carries a score. Each field that agrees adds to the score, and rarer agreements count for more: a full email address counts for a lot, a first name like Mohammed for very little. The total is compared against two thresholds. Above the upper one, link. Below the lower one, do not. Between them, a person checks. The UK Office for National Statistics describes the two errors this trades off: a missed match, which creates a duplicate profile, and a false match, which joins two people's records [16]. The false match is the expensive one. In 2025 Australia's privacy commissioner ordered a government agency to pay AUD 10,000 to a man whose health records had been repeatedly merged with those of another person with the same name and date of birth [17], and in the UK, sending personal data to the wrong recipient is a reportable breach and among the most common incidents reported to the regulator [18].

A transcript is not a record

ISO 15489, the international standard on records management, defines a record as information kept "as evidence and as an asset ... in the transaction of business", and says an authoritative record must be authentic, reliable, complete and unaltered, and usable [19]. A transcript on its own fails that test three ways.

First, it can be wrong. Speech-to-text systems are measured by word error rate, the share of words they get wrong. In a 2023 benchmark, a leading open model reached 12% to 19% on formal Arabic read aloud, 35% on broadcast speech that was mostly formal, 44% on Egyptian dialect and 83% on Moroccan [20]. A 2025 study of Emirati dialect, on a small set of four hours of recordings, found error rates of 86% to 93% for general-purpose models used as they come, and about 41% for the best model after training on the dialect [21]. Arabic-English code-switching, where a speaker moves between languages mid-sentence, produced rates from 23% to 65% depending on the system in a 2021 study [22]. Service calls will score differently from research recordings, and results vary widely by system, but nobody should treat a raw transcript of a Gulf Arabic call as the truth about what the customer said.

Second, its timestamps disagree. Each channel keeps its own clock. A webhook is the notification a platform sends to another system when something happens, and Meta's documentation says the time on a webhook is "when the Event Notification was sent (not when the change that triggered the notification occurred)", that the message inside carries its own separate timestamp, and that duplicates can arrive [23]. The email standard says the Date header is the time the sender's software declared, not the time of delivery [24]. This is the problem Leslie Lamport set out in 1978: when separate systems each keep their own clock there is no single true order of events, only the order you choose to impose [25]. A record has to hold the channel's time and the time we received the event, and say which it is using.

Third, messages do not arrive threaded, that is, grouped into the exchange they belong to. Email carries reply headers that let a system group a thread. WhatsApp carries a reply pointer only when the customer uses the reply function, and SMS carries nothing. WhatsApp's own "conversation" object was a 24-hour billing unit, not an issue; Meta stopped charging by it in July 2025, while the 24-hour window that governs when a business may message remains [26]. Working out which messages belong to which issue is a research problem in its own right. On the standard 2019 test set, the best published model grouped messages into exactly the right conversations only 38% of the time, and in the 2008 study that started the field, two people doing the same task by hand agreed only about half the time [27]. An issue cannot be inferred from message flow. It has to be opened, named and closed as an act of record.

What a record needs instead is spelled out in ISO 10002, the standard for complaints handling: a unique identifier, a description of the issue, the remedy requested, a due date for a response, and tracking from receipt to closure [28]. The Central Bank of the UAE requires the same of regulated firms, with a unique service request number for every complaint and retention of complaint records for at least five years from closure [29].

Untracked promises are where complaints come from

The clearest evidence is ombudsman data, and it is not from the Gulf. In 2025/26 the Legal Ombudsman for England and Wales accepted 8,412 complaints. Poor communication (24%) and delay and failure to progress (22%) were the two largest categories, together 46% of complaint types, and poor communication was the single largest category among upheld complaints [30]. Australia's Telecommunications Industry Ombudsman received 57,592 complaints in 2024-25; the largest issue by far, recorded on 34,770 of them, was "no or delayed action by a provider", and its coding scheme includes "agreed resolution not actioned" as a formal category [31].

Individual decisions show what happens when the promise is not in the record. In one 2023 case a bank was ordered to pay compensation after "the call handler also promised Mr M a call back and this didn't happen" [32]. In another, the ombudsman wrote that where there is no record of a call, "it's one word against another" [33]. In a third, the firm won because it held a note written at the time of the call, which the customer's recollection could not overturn [34]. The record protects both sides, but only if it exists.

Experimental research explains why broken promises bite harder than other failures. A 2014 study found people penalise a broken promise heavily but give almost no extra credit for a promise exceeded [35]. A 2016 study in the Journal of Service Research found that a failed recovery after a failure, which the literature calls a double deviation, deepens the loss of trust, and that a credible promise restored more trust than financial compensation [36]. The lesson is to promise carefully and then do exactly what was promised, which is only possible if the promise was written down. The same data adds a caution: the Legal Ombudsman notes that delay complaints often arise because "consumers' expectations for updates may differ from what service providers can reasonably offer" [30], so the record has to hold what was said about timing, not only what was done. Saudi Arabia's civil aviation authority publishes the closest Gulf equivalent, a monthly index that logged 2,313 airline complaints in August 2025, ranked by flights, baggage and tickets; it has no category for broken commitments, and no Gulf regulator we checked publishes one [37].

What the law requires

The UAE Personal Data Protection Law, Federal Decree-Law 45 of 2021, requires personal data to be "sufficient and limited to what is necessary" for the stated purpose, and says it "shall not be kept after the purpose of its processing has been exhausted" unless anonymised, meaning stripped of anything that identifies the person [38]. Consent must be clear and unambiguous and can be withdrawn at any time; processing without consent is allowed where it is necessary to perform a contract with the customer, among other grounds. A processor, the company handling data on an enterprise's instructions, must erase the data or hand it back when the processing period ends. Personal data is defined to include a person's voice and any electronic identifier, so a call recording and a WhatsApp ID are both in scope. The Executive Regulations that will set breach deadlines and penalty amounts had not been issued as of March 2026 [39]. Separately, the UAE cybercrime law makes recording a conversation through an electronic network or system without consent an offence carrying at least six months' imprisonment and/or a fine of AED 150,000 to 500,000 [40].

Saudi Arabia's Personal Data Protection Law, in force since September 2023 with enforcement from September 2024, requires collection to be "limited to the minimum amount necessary", requires data to be destroyed once no longer needed unless another law requires retention, lets the individual withdraw consent at any time, and treats health data as sensitive, which means explicit consent and no marketing use [41]. A 2023 amendment added a legitimate-interest ground, which lets a company process data for its own reasonable purposes without consent, but not for sensitive data; fines for most violations run up to SAR 5 million [42]. For an enterprise in the Dubai International Financial Centre, Regulation 10 adds a duty to tell a person "in clear and explicit terms upon the initial use" that they are dealing with an automated system [43].

What that means

The working hypothesis was that a useful record is organised around issues and commitments rather than messages, links identities with a stated level of confidence, and holds only what is needed for as long as policy allows. The evidence supports it, with three refinements.

The record needs a layer of confirmed facts. Because transcripts are lossy and timestamps disagree, the reliable content of a conversation is what was extracted and confirmed with the customer: the claim number, the unit, the amount, the date, the promise. The transcript and the recording are evidence attached to the record. They are not the record.

Who is speaking and whom it is about are different fields. The brother is contacting the insurer about his sister's claim. The record must be about her, hold his call as an event, and carry what authority he had to discuss it. Collapsing the two is how one person's data ends up in another's file.

Minimisation is about content, not about the record itself. Regulators require complaint records to be kept for years; the data protection laws require personal data to go when its purpose ends. Both hold at once, because they apply to different things. The structured record of issues, commitments and outcomes has a long life set by regulation and the enterprise's policy. The raw content has a short one: the audio, the identity document in a photograph, the card number read aloud. Some of it should never be stored at all.

That gives the list of what the record should deliberately not hold. Not inferences about the customer. A 2019 study in the Journal of Consumer Research, in an advertising setting, found people react badly when a company uses information it inferred rather than information they stated, or gathered in one context and used in another [44]. The 70% of customers who told Salesforce they expect every representative to have the same information about them were talking about what they said, not what was guessed [1]. Not sensitive data in plain text. Not the caller's own personal data when the caller is not the customer. And not anything without a stated purpose, because both laws make the purpose the test.

The trade-off is real. Set the identity threshold high and customers are asked to confirm who they are more often, which is the friction the record was meant to remove. Set it low and the record will, sooner or later, put someone else's photographs in front of a handler. Because the harm from a false match is a disclosure and the harm from a missed match is a question, the threshold belongs on the cautious side, with uncertain cases sent to a person.

How we design for it

Issues, not messages. Our agents treat an exchange of messages as one customer issue that opens on first contact and closes on resolution, and keep an email thread as one issue across replies. Each issue carries its outcome: resolved, unresolved or escalated.

Confirmed facts alongside the transcript. Names, dates, amounts, reference numbers and addresses are extracted during the conversation and held as structured fields, so what a handler reads is what the customer confirmed, not what the speech recogniser heard.

Commitments as entries in their own right. Every promise made to a customer is logged with what was promised, to whom, by when, and whether it was delivered. That is the entry an ombudsman asks for, and the entry that makes a chasing call unnecessary.

One timeline across channels. A returning customer is recognised and their previous conversations are known. A call, a WhatsApp message and an email from the same customer are one continuous history, written to a single relationship timeline that can answer what was said to this customer and when, including what the enterprise's own staff said.

Identity as a claim with a confidence level. On the web, the cleanest identity is the customer's own login, passed to the agent by the enterprise. Elsewhere, the design rule is that a link between a channel identifier and a customer is held with its evidence and a confidence level, that the speaker is recorded separately from the subject of the conversation, and that an uncertain match goes to a person rather than being assumed.

Retention the enterprise controls. The retention window for conversation history is set per deployment, so the enterprise's data policy and its regulator's minimum both apply. Where a client's policy forbids retention, memory can be disabled or held in the client's own storage.

Nothing without permission. Call recording proceeds only when consent has been requested and recorded against the interaction, and consent state is held per customer and checked before any outbound message.

Sensitive data masked before it travels. Card numbers, identity documents and similar sensitive information are identified and masked in transcripts so they do not leave the deployment in plain text, and data can be kept inside a chosen country where that is required.

What we don't know yet

There is no published Gulf figure for how often customers have to repeat themselves, and no UAE or Saudi study of how customers feel about being remembered across channels. The regional surveys that exist are vendors' and ask about privacy in general.

There is no evidence that tracking promises reduces complaints. The evidence shows that unkept promises cause complaints and that firms with records win disputes. Whether logging a promise changes whether it is kept is untested.

No Gulf regulator publishes statistics on number reassignment, SIMs per person or shared phone use, so the real rate of identity error in this market is unknown.

Speech recognition results for Gulf dialects come from small research corpora, not service calls. The right number for any deployment can only come from measuring on the enterprise's own calls.

The UAE law's Executive Regulations are still to come, and Saudi Arabia consulted on amendments to its implementing regulations in 2025 [45]. What each finally requires on retention periods and breach reporting will shape the record's lifetime.

Sources

  1. 1.Salesforce Research, State of the Connected Customer, sixth edition, 2023, p. 20 (chart "Consistency Does Not Match Expectations") and p. 28 (methodology). Mirror copy:⁠https://event.hbrturkiye.com/storage/uploads/state-of-the-connected-customer-655b114557dfa.pdf. UAE sample of 650: https://www.zawya.com/en/press-release/research-and-studies/85-of-customers-in-uae-want-to-know-if-theyre-communicating-with-ai-or-a-human-salesforce-report-tabg3mwr
  2. 2.Institute of Customer Service, UK Customer Satisfaction Index, July 2025.⁠https://www.instituteofcustomerservice.com/product/ukcsi-jul-25/
  3. 3.Arizona State University W. P. Carey School of Business and Customer Care Measurement & Consulting, 2020 National Customer Rage Study, p. 14.⁠https://research.wpcarey.asu.edu/services-leadership/wp-content/uploads/2020/06/2020-RageStudyUPDATEDFINALFORRELEASE.pdf
  4. 4.Dixon, M., Freeman, K. and Toman, N., "Stop Trying to Delight Your Customers", Harvard Business Review, July–August 2010.⁠https://hbr.org/2010/07/stop-trying-to-delight-your-customers
  5. 5.KPMG, Customer Experience Excellence Report 2023–24: UAE, 2024, pp. 3 and 10.⁠https://assets.kpmg.com/content/dam/kpmg/ae/pdf-2024/05/uae-cee-report-2023-24.pdf
  6. 6.Meta for Developers, WhatsApp Business Platform, "Text messages" webhook reference.⁠https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/messages/text
  7. 7.Meta for Developers, WhatsApp Business Platform, "System messages" webhook reference.⁠https://developers.facebook.com/documentation/business-messaging/whatsapp/webhooks/reference/messages/system
  8. 8.Meta for Developers, WhatsApp Business Platform, "Business phone numbers", identity change check.⁠https://developers.facebook.com/documentation/business-messaging/whatsapp/business-phone-numbers/phone-numbers
  9. 9.World Bank, World Development Indicators (ITU data), mobile cellular subscriptions per 100 people, 2024. UAE:⁠https://fred.stlouisfed.org/series/ITCELSETSP2ARE. Saudi Arabia: https://fred.stlouisfed.org/series/ITCELSETSP2SAU
  10. 10.US Federal Communications Commission, Advanced Methods to Target and Eliminate Unlawful Robocalls, Second Further Notice of Proposed Rulemaking, CG Docket 17-59, Federal Register, 23 April 2018.⁠https://www.federalregister.gov/documents/2018/04/23/2018-08376/advanced-methods-to-target-and-eliminate-unlawful-robocalls
  11. 11.General Authority for Statistics (Saudi Arabia), 2022 Census results, via Saudi Press Agency, 31 May 2023.⁠https://www.spa.gov.sa/w1911463
  12. 12.International Labour Organization, Making decent work a reality for domestic workers in the Middle East, 2021, figure 1 and table p. 3; and ILO, "Domestic workers in the Arab States".⁠https://www.ilo.org/media/378326/download and https://www.ilo.org/regions-and-countries/arab-states/domestic-workers-arab-states
  13. 13.Central Bank of the UAE, Consumer Protection Standards, Article 6, clause 6.1.1.5.⁠https://rulebook.centralbank.ae/en/rulebook/article-6-protection-consumer-data-and-assets
  14. 14.Freeman, A., Condon, S. and Ackerman, C., "Cross Linguistic Name Matching in English and Arabic", HLT-NAACL, 2006.⁠https://aclanthology.org/N06-1060.pdf
  15. 15.Fellegi, I. P. and Sunter, A. B., "A Theory for Record Linkage", Journal of the American Statistical Association, 64(328), 1969.⁠https://www.tandfonline.com/doi/abs/10.1080/01621459.1969.10501049
  16. 16.Office for National Statistics, Developing standard tools for data linkage, February 2021.⁠https://www.ons.gov.uk/methodology/methodologicalpublications/generalmethodology/onsworkingpaperseries/developingstandardtoolsfordatalinkagefebruary2021
  17. 17.Office of the Australian Information Commissioner, "Beware: the digital doppelganger", 3 February 2025, on 'ATQ' and CEO of Services Australia [2025] AICmr 19.⁠https://www.oaic.gov.au/news/blog/beware-the-digital-doppelganger
  18. 18.Information Commissioner's Office, Personal data breaches: a guide; and ICO data security incident trends.⁠https://ico.org.uk/for-organisations/report-a-breach/personal-data-breach/personal-data-breaches-a-guide/ and https://ico.org.uk/action-weve-taken/data-security-incident-trends/
  19. 19.ISO 15489-1:2016, Information and documentation, Records management, Part 1: Concepts and principles, clauses 3.14 and 5.2.2.⁠https://www.iso.org/standard/62542.html
  20. 20.Talafha, B., Waheed, A. and Abdul-Mageed, M., "N-Shot Benchmarking of Whisper on Diverse Arabic Speech Recognition", Interspeech, 2023.⁠https://www.isca-archive.org/interspeech_2023/talafha23_interspeech.pdf
  21. 21.AlBlooki, Inui and Shehata, "ASR Models for Traditional Emirati Arabic", ICNLSP, 2025.⁠https://aclanthology.org/2025.icnlsp-1.5.pdf
  22. 22.Ali, A., Chowdhury, S., Hussein, A. and Hifny, Y., "Arabic Code-Switching Speech Recognition using Monolingual Data", Interspeech, 2021.⁠https://www.isca-archive.org/interspeech_2021/ali21b_interspeech.pdf
  23. 23.Meta for Developers, Graph API Webhooks, "Getting started"; and WhatsApp Cloud API, "Webhooks".⁠https://developers.facebook.com/docs/graph-api/webhooks/getting-started and https://developers.facebook.com/docs/whatsapp/cloud-api/webhooks
  24. 24.IETF, RFC 5322, Internet Message Format, 2008, sections 3.6.1 and 3.6.7.⁠https://www.rfc-editor.org/rfc/rfc5322.html
  25. 25.Lamport, L., "Time, Clocks, and the Ordering of Events in a Distributed System", Communications of the ACM, 21(7), 1978.⁠https://lamport.azurewebsites.net/pubs/time-clocks.pdf
  26. 26.Meta for Developers, WhatsApp Business Platform, "Send messages" (customer service window) and "Pricing" (conversation-based pricing deprecated 1 July 2025).⁠https://developers.facebook.com/documentation/business-messaging/whatsapp/messages/send-messages and https://developers.facebook.com/docs/whatsapp/pricing
  27. 27.Kummerfeld, J. K. et al., "A Large-Scale Corpus for Conversation Disentanglement", ACL, 2019; and Elsner, M. and Charniak, E., "You Talking to Me? A Corpus and Algorithm for Conversation Disentanglement", ACL, 2008.⁠https://aclanthology.org/P19-1374.pdf and https://aclanthology.org/P08-1095.pdf
  28. 28.ISO 10002:2018, Quality management, Customer satisfaction, Guidelines for complaints handling in organizations, clauses 7.2 and 7.3.⁠https://www.iso.org/standard/71580.html
  29. 29.Central Bank of the UAE, Consumer Protection Standards, Article 8, clauses 8.1.1.4, 8.1.2.2 and 8.2.3.1.⁠https://rulebook.centralbank.ae/en/rulebook/article-8-complaint-management-and-complaint-resolution
  30. 30.Legal Ombudsman (England and Wales), 2025/26 annual complaints data and insight.⁠https://www.legalombudsman.org.uk/information-centre/data-centre/complaints-data/legal-ombudsman-202526-annual-complaints-data-and-insight/
  31. 31.Telecommunications Industry Ombudsman (Australia), Annual Report 2024-25; and "Complaint issues and keywords".⁠https://www.tio.com.au/reports/annual-report-2024-25 and https://www.tio.com.au/data-hive/complaint-issues-and-keywords
  32. 32.Financial Ombudsman Service (UK), decision DRN-4427583, 2023.⁠https://www.financial-ombudsman.org.uk/decision/DRN-4427583.pdf
  33. 33.Financial Ombudsman Service (UK), decision DRN-3969972, 2023.⁠https://www.financial-ombudsman.org.uk/decision/DRN-3969972.pdf
  34. 34.Financial Ombudsman Service (UK), decision DRN-4924309, 2024.⁠https://www.financial-ombudsman.org.uk/decision/DRN-4924309.pdf
  35. 35.Gneezy, A. and Epley, N., "Worth Keeping but Not Exceeding: Asymmetric Consequences of Breaking Versus Exceeding Promises", Social Psychological and Personality Science, 2014. Summary:⁠https://www.eurekalert.org/news-releases/823463
  36. 36.Basso, K. and Pizzutti, C., "Trust Recovery Following a Double Deviation", Journal of Service Research, 2016.⁠https://ppgad.ufms.br/files/2021/04/JSR-paper.pdf
  37. 37.General Authority of Civil Aviation (Saudi Arabia), airlines and airports performance report, August 2025, published 8 October 2025.⁠https://gaca.gov.sa/en/News/airlines-airports-performance-august-2025
  38. 38.UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, Articles 1, 4, 5, 6 and 8.⁠https://uaelegislation.gov.ae/en/legislations/1972/download
  39. 39.Chambers and Partners, Data Protection & Privacy 2026: UAE, 10 March 2026 (status of the Executive Regulations).⁠https://practiceguides.chambers.com/practice-guides/data-protection-privacy-2026/uae
  40. 40.UAE Federal Decree-Law No. 34 of 2021 on Countering Rumours and Cybercrimes, Article 44.⁠https://uaelegislation.gov.ae/en/legislations/1526/download
  41. 41.Saudi Data and Artificial Intelligence Authority, Guide to the Personal Data Protection Law for controllers and processors (Data Governance Platform), on Articles 4, 5, 6, 11 and 18 of the Personal Data Protection Law, Royal Decree M/19 of 2021 as amended by M/148 of 2023.⁠https://dgp.sdaia.gov.sa
  42. 42.Cleary Gottlieb, "Saudi Arabia's Data Protection Law and Regulations Come into Effect", January 2024 (secondary source for Articles 6, 35 and 36; the official English text was not reachable).⁠https://www.clearycyberwatch.com/2024/01/saudi-arabias-data-protection-law-and-regulations-come-into-effect/
  43. 43.Dubai International Financial Centre, Data Protection Regulations, Regulation 10, clause 10.2.2, 2023.⁠https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection/regulation-10
  44. 44.Kim, T., Barasz, K. and John, L. K., "Why Am I Seeing This Ad? The Effect of Ad Transparency on Ad Effectiveness", Journal of Consumer Research, 45(5), 2019.⁠https://academic.oup.com/jcr/article/45/5/906/4995525
  45. 45.Bird & Bird, "Saudi Arabia: public consultation on draft changes to the data protection regulations", 2025 (consultation open 27 April to 27 May 2025).⁠https://www.twobirds.com/en/insights/2025/saudi-arabia-public-consultation-on-draft-changes-to-the-data-protection-regulations

Get new research as it's published

Occasional emails when we publish.

Subscribe

Read next