PHII Labs
2026-10-27Real Estate AI10 min read

PDPL-compliant AI CRM in the UAE: data flows that pass audit

How to build an AI CRM that survives a PDPL audit: data-flow maps, subprocessors, retention, consent, and Federal Decree-Law 45/2021 requirements

Sergei Suvorin · Co-founder, PHII Labs

PDPL-compliant AI CRM data-flow map for UAE businesses

An AI CRM passes a PDPL audit when you can show, hop by hop, where personal data goes: which processor touches it, in which country, for how long, and under which lawful basis of Federal Decree-Law 45/2021. That means a written data-flow map, a processing record, a deletion path that reaches backups, and a human-review path for automated decisions the data subject objects to

We are engineers, not lawyers. This post describes how we design and document systems so your counsel and your auditor have something concrete to check. It quotes the Decree-Law directly and does not replace legal advice

What does PDPL actually require of an AI CRM?

The UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, has been in force since 2 January 2022. For a CRM that ingests WhatsApp chats, portal leads and documents, five of its articles turn into engineering work.

ArticleWhat it says, paraphrasedWhat it means in the system
Art. 4Processing needs consent unless an exception applies, such as performing a contract the data subject asked for (Art. 4(9))Every record carries a lawful_basis field set at intake
Art. 5Collect for a specific purpose, keep only what is necessary, delete when the purpose is exhaustedField-level minimisation and a retention timer per data class
Art. 6You must be able to prove consent, and withdrawal must be easyConsent is an event row with timestamp, channel and wording version
Art. 7(4)The controller keeps a record of processing: categories, who has access, erasure mechanism, cross-border movement, security measuresA processing register generated from the same config the code reads
Art. 22-23Transfers outside the UAE need an adequate jurisdiction, a protective contract, explicit consent, or contractual necessityEvery LLM, OCR and storage vendor outside the UAE is a documented transfer

Two more articles bite hardest on AI features. Article 18 gives the data subject the right to object to decisions made by automated processing, and Article 18(4) requires a human to review such decisions on request. Article 15 gives a right to erasure, with exceptions where other laws require you to keep the record

Scope matters too. Article 2(2) excludes, among others, government data, health and banking data covered by their own legislation, and establishments in free zones that have their own data protection laws. A brokerage established in DIFC or ADGM is outside the federal PDPL and answers to that zone's regime. A mainland Dubai brokerage with a RERA-registered office answers to the federal law

Several details, including breach-notification timelines, the DPO volume threshold and transfer controls, are deferred to Executive Regulations (Art. 28) — still pending as of late 2026. Check their current status on uaelegislation.gov.ae before you trust any vendor who quotes you a specific number of hours. Note too that in June 2026 the federal government announced the Artificial Intelligence and Data Authority, which consolidates the Data Office's remit; it does not change the law's text, but it is where the regulator signals will come from.

Where does your data actually flow?

In a typical WhatsApp plus CRM plus retrieval stack, personal data crosses six or seven boundaries before an agent reads it, and at least two of them usually sit outside the UAE. We draw this map in the first week of a build, before any model is connected

Lead (UAE resident)
  |
  | 1. WhatsApp message / Property Finder or Bayut enquiry / web form
  v
[Channel processor]  Meta Cloud API, portal lead feed
  |
  | 2. webhook (TLS)
  v
[Inbox service]  your server, documented region
  |-- 3a. redacted prompt ------> [LLM provider]  cross-border
  |-- 3b. document image -------> [OCR service]  self-hosted or vendor
  |
  | 4. structured fields + lawful_basis + consent_id
  v
[CRM]  HubSpot / Zoho / Odoo / Salesforce / custom Postgres
  |
  | 5. files, embeddings, backups
  v
[Storage]  object store, vector index, encrypted backups
  |
  | 6. role-scoped views
  v
[Humans]  agents, team leads, back office; every read is logged

The table annotates each hop with the facts an auditor will ask for. The vendor names are examples of what sits at each position; your map lists your actual vendors

HopPersonal dataProcessor (example)LocationRetentionPDPL basis to document
1. ChannelPhone number, name, message text, voice notesMeta (WhatsApp Cloud API)Meta data centresUp to 30 days for messages, per Meta's Cloud API data privacy pageConsent at opt-in, or Art. 4(9) when the lead asked to be contacted
1. Portal leadName, phone, email, listing referenceProperty Finder, Bayut, Dubizzle feedsPortal's systemsPortal's own policyLead submitted the enquiry; record the source
2. InboxFull conversation, mediaYour app serverRegion you choose and write downConversation log: e.g. 24 months, then anonymiseSame as hop 1
3a. LLMMessage text with phone, Emirates ID number and email maskedOpenAI, Anthropic, GoogleUsually outside UAEPer vendor API terms; turn on zero-retention options where offeredArt. 23 transfer: contract terms plus notice to the lead
3b. OCRPassport, Emirates ID, Ejari, SPA, title deed imagesSelf-hosted OCR, or a vendorYour region if self-hostedImage deleted after extraction unless a deal file needs itArt. 4(9) contract performance
4. CRMContact, budget, preferences, deal stageCRM vendorVendor's regionLife of the client relationship plus legal holdContract or consent, stored per record
5. StorageDocuments, embeddings, backupsObject storage, vector DBDocumented regionBackups rotate on a fixed cycle, e.g. 35 daysArt. 20 security measures: encryption at rest
6. HumansWhatever their role allowsYour staffOffice and remoteAccess log kept 12 monthsArt. 7(4) record of who can access

The retention numbers in the Inbox, Storage and Humans rows are defaults we propose; you set yours with counsel. The one value an auditor must never see is "unknown"

Meta describes itself as a data processor for Cloud API and keeps messages for a maximum of 30 days to support retransmission. So one WhatsApp conversation exists in at least three places (Meta, your inbox, your CRM), and each copy needs its own row

Diagram: channel inputs flowing through a compliance shield into storage and archive nodes

Which data needs extra protection?

Emirates ID copies, passport scans and anything that reveals religion, health or family status need tighter handling than a phone number. Article 1 defines Sensitive Personal Data to include religious beliefs, family details, health and biometric data. A scanned passport carries a photo and an ID number. If you run face matching on it, the output is biometric data

Dubai real estate deal files collect these by default. An SPA names the buyer and their passport number, an Ejari tenancy record carries the tenant's Emirates ID, and a developer NOC application may include both parties' documents. Our Ejari, SPA and NOC pipeline post covers extraction. For compliance, the image lives in one encrypted bucket with a short retention timer, and only the extracted fields the workflow needs travel downstream

Identity documents arrive on the first screen of some products. Our UAE Visa Platform starts every application with a passport scan, which is why GovTech builds force these storage decisions early instead of after launch

What does a redacted record lifecycle look like?

A lifecycle table answers the deletion question before anyone asks it. For each data class you write down where it lives, how long it stays, and the code path that removes it. Here is a redacted template for a real estate CRM

Data classPrimary storageCopiesRetention triggerDeletion pathLogged as
Lead contact (name, phone, email)CRM contactInbox, Meta (30 days)No reply in 12 months, or erasure requestCRM delete job anonymises contact, inbox thread purgederasure.contact
Chat transcriptInbox DBMeta (30 days), LLM vendor per terms24 months after last messageNightly job replaces text with a hash and keeps metadataretention.chat
Emirates ID / passport imageEncrypted bucketNone by designDeal closed plus legal hold periodObject lifecycle rule, then bucket auditretention.id_doc
Extracted ID fieldsCRM deal recordBackupsSame as deal recordDeleted with the deal record; backups age outerasure.deal
Ejari / SPA / NOC PDFDeal folderBackupsLegal hold period set by counselFolder delete plus backup rotationretention.deal_doc
Embeddings of documentsVector indexNoneSource document deletedDelete by source_id, then reindexerasure.vector
Consent eventsConsent tableBackupsKept as proof for the life of the relationshipRemoved last, after all dependent dataconsent.closed

The vector index row is the one most teams miss. If a contract was chunked and embedded for retrieval, deleting the PDF leaves its text recoverable from the index. Every chunk needs a source_id so one call removes it

Backups are the other gap. You cannot surgically edit an encrypted backup, so the accurate answer to "is it deleted?" is "it is deleted from live systems now and ages out of backups within 35 days." Write that sentence in your privacy notice and your processing record

What does an auditor ask for?

An auditor asks for evidence: the processing record, the transfer list, consent proof for a sample of records, and a demonstrated deletion. This is the checklist we prepare before a client's review

The auditor asksWhat you showArticle
What personal data do you process and why?Processing register, one row per data class, with purposeArt. 5, 7(4)
Who has access?Role matrix exported from the app, plus access logsArt. 7(4)
Which vendors process data for you?Processor list with contract, location, retentionArt. 7(5), 8
Does any data leave the UAE?Transfer list: vendor, country, mechanism under Art. 22 or 23Art. 22-23
Prove this person consentedConsent event: timestamp, channel, wording version, withdrawal statusArt. 6
Show me an erasure request handled end to endRequest ticket, deletion job output, log entries per systemArt. 15
Can a customer contest an AI decision?Approval queue and the named reviewer for each decision typeArt. 18
How is data secured?Encryption at rest and in transit, key ownership, restore test resultsArt. 20
Did you assess the AI processing before launch?Impact assessment covering profiling and sensitive data volumeArt. 21
What happens in a breach?Runbook: who detects, who notifies, which systems are isolatedArt. 9

If the register is a spreadsheet maintained by hand, it drifts from the code within a quarter. We generate it from the same retention and vendor config the deletion jobs read, so the document and the system cannot disagree

Which CRM changes make a system compliant?

You do not need a new CRM. HubSpot, Zoho, Odoo or Salesforce all work, because PDPL governs how data moves between systems rather than which product holds it. The changes go in four places

  1. Add schema fields. Each contact and deal gets lawful_basis, consent_id, source_channel and retention_class. Intake refuses to create a record without them
  2. Mask before the model. Phone numbers, Emirates ID numbers, passport numbers and emails get replaced with tokens before text goes to an LLM, and re-inserted on the way back. The model gets the context it needs to qualify a lead without the identifiers
  3. Put humans in front of consequential actions. We use approval queues for low-confidence classifications, high-value lead routing and any outbound message that commits to price or availability. On our 8,000-unit inventory CRM the AI assistant proposes status changes and a person approves them; the system took status accuracy from about 60% to about 98%
  4. Build erasure as one command. A job walks CRM, inbox, vector index and object storage by subject ID and writes a log line per system

Human review still leaves room for heavy automation: on a property-management platform, about 60% of tenant chats are handled by AI. Pick the ratio by risk and write it into the processing record

On the a property-management platform build, about 60% of tenant chats are handled by AI before a person steps in. We choose that ratio by risk, and we write it into the processing record so an auditor can see the human stays in front of the consequential actions.
Sergei Suvorin · Co-founder, PHII Labs

Two decisions belong to you and your counsel: the retention periods, and whether marketing messages rely on consent. Meta's Business Messaging Policy separately requires opt-in before you message someone on WhatsApp; our WhatsApp Business API guide covers opt-in flows and templates.

When comparing vendors, ask each one for a filled-in hop table from a past project. That question is on our list for choosing an AI automation agency in Dubai, and the AI real estate systems page shows how we scope these builds

The takeaway

PDPL compliance for an AI CRM comes down to documents that match the code: a hop-by-hop data-flow map, a processing register, a lifecycle table with real deletion paths, and approval queues where automated decisions affect people. Draw the map before you connect the LLM, and an audit becomes a review of evidence you already have

Book a free audit and we will map your current lead and document flows against Federal Decree-Law 45/2021 and show you which hops are undocumented

FAQ

Is AI automation in the UAE PDPL compliant?

Compliance comes from the architecture: a documented data-flow map, named subprocessors, retention and deletion paths, and a lawful basis per Federal Decree-Law 45/2021

Where is customer and Emirates ID data stored?

In a compliant build, primary storage sits in a documented region with named subprocessors. Emirates ID copies need extra protection and defined retention

Can a human approve AI replies, document actions and high-value lead routing?

Approval queues keep a person in the loop: low-confidence classifications and all external-facing actions wait for a named reviewer

Does it work with our existing HubSpot, Salesforce, Zoho or Odoo setup?

Yes. PDPL compliance depends on how data flows between systems, whichever CRM you run. The audit documents each hop and its legal basis

What happens to personal data when a customer asks for deletion?

A compliant system locates the record across CRM, chat history and backups, deletes or anonymizes it, and logs the action for audit

Sources

Want systems like this?

We build and ship AI systems for real operations