What UAE law asks for before you record a conversation
Recording a private conversation without consent is a criminal offence in the UAE, not a policy matter. Here is what that means for a team that wants conversation analytics.
Most conversations in a restaurant, a pharmacy, or a showroom are never reviewed. Nobody listens to a shift. The work of a manager is guesswork built on the two or three moments they happened to witness. Analytics fixes that — but only if the recording behind it is lawful.
In the UAE the rule is stricter than most teams expect, and it sits in criminal law rather than in a data policy.
Recording without consent is a crime, not a violation
Federal Decree-Law 34/2021 makes recording a private conversation without the consent of the people in it a cybercrime. The penalty runs to a fine of AED 150,000–500,000 and up to two years. There is no business-purpose exemption to fall back on: a manager cannot authorize it, and an employment contract cannot waive it on a customer’s behalf.
So the first question is never technical. It is who is in the room, and what each of them has agreed to.
Two consents, not one
- The employee. Recording at a workstation is part of the role, and it belongs in the contract or an annex to it — written, specific about what is recorded and what it is used for.
- The guest or customer. They need notice before the conversation, not after. A sign at the counter, a line in the booking confirmation, a short notice at the start of a call.
Notice and consent are not the same thing. Notice tells a person that recording happens; consent is their agreement to it. In a customer-facing space the practical form is visible notice plus the freedom to ask for the recording to stop.
What Decree-Law 45/2021 adds
Federal Decree-Law 45/2021 governs personal data itself: how it is collected, how long it is kept, and who may see it. Two consequences matter for conversation analytics.
- Data has to stay where it belongs. Recordings, transcripts, and analytics for a UAE business should sit on infrastructure inside the region rather than travelling to whatever cloud the vendor happens to use.
- Retention is a decision, not a default. How long audio lives, when it is deleted, and who can pull it back are settings someone has to own.
Anonymization is the part that does the real work
The strongest answer to all of this is to stop carrying personal data into the analysis at all. Names, phone numbers, addresses, and card numbers can be found in the transcript and masked before any model reads it. What remains is a conversation about service, with no way back to a specific customer.
That is how Lansy is built: the transcript is anonymized first, and the language model only ever sees the masked version. It is also what makes the rest of the conversation about analytics easy — a manager reviewing a shift is looking at service quality, not at a customer’s file.
A short checklist
- Written consent from employees, specific about what is recorded and why.
- Visible notice for guests before the conversation starts.
- Personal data masked in the transcript before analysis.
- Data stored in-region, with a named retention period.
- One person who can delete a recording on request.
None of this is exotic. It is the same discipline any UAE business already applies to CCTV and to customer records — applied to the conversation, which is where most of the service actually happens.