Telemarketing Restrictions in the UAE: Why We Should Fight the Cause, Not the Effect
Spam and Internet fraud cannot be combatted without effective measures against data leaks. Lev Matveev, founder of SearchInform, explains why we get spam and fraudulent calls and how best to deal with this old but still pressing problem.
The UAE’s Digital Government Regulatory Authority (TDRA) encourages residents to report unwanted spam calls and messages from telemarketers promoting their products and services. Earlier, in mid-2024, new regulations came into effect banning the use of personal numbers for sales calls and introducing fines for violations like engaging in deceptive or misleading marketing practices over the phone. Now companies can face fines of up to AED 150,000 (more than $40,000) for breaching the new restrictions.
The measures came in response to rising complaints and the low effectiveness of previous telemarketing regulations in the UAE.
Why Do Telemarketers Call Us?
The problem of cold calls is long-standing for the UAE. Residents of the country are disturbed daily by offers to buy real estate, invest, get loans, mobile and Internet services, etc. According to the UAE Telecommunications Regulatory Authority, in 2013, about 82.3 million spam calls and messages were blocked; in 2015, 312.7 million (from inside and outside the country).
The UAE authorities tried to appeal to the conscience of telemarketers so that they would check consumer numbers on the DNC registry before calling. Since August 2023, this requirement has become mandatory, although it did not provide for any control or penalties.
As a result, the number of cold calls has not decreased. On the Reddit social network, users reported that adding a phone number to the DNC registry did not affect the number of agent offers they continued receiving, nor did filing complaints with regulators.
Some users connect telemarketers’ calls with their previous inquiries to local web resources. For example, after registering on the website of the Department of Economy and Tourism, one of the users began receiving calls from the Etisalat telecom operator offering Internet services. Another victim of spam on Reddit suggests that her phone number fell into the hands of real estate agents from the investment company Emaar. Now she is offered to buy a house 2-3 times a day.

Thus, UAE residents suffering from telemarketing have identified the root cause of the problem: their personal data, including phone numbers, are migrated from the databases of organizations to other companies.


Mostly, they are right. In addition, personal data from private and public companies is leaked not only to telemarketers but also to fraudsters. How does this happen? There are two reasons: hacker attacks on the data controllers and unprotected systems, and employees of these companies who steal and sell data.
Sometimes, there are entire groups of employees who use their official position for selfish purposes. They sell customer databases to third parties, data brokers, and cybercriminals. Unless special-purpose software is installed in the company to prevent the leak and identify the culprit, the crime will never be revealed.
To note, under UAE law, disclosure of confidential information obtained at work may result in imprisonment for up to 6 months and a fine of up to AED 1 million. Self-interest is considered an aggravating circumstance in this case.
In addition, there are many cases of robbery through telephone fraud, i.e., scam, in the UAE. According to media, over the past five years, more than 40,000 UAE residents have lost thousands of millions of dollars just by getting involved in fraudulent investment schemes. For example, last year an Abu Dhabi entrepreneur lost $20,000 investing in cryptocurrency after accepting an offer from his alleged former business partner.
Another illustrative case happened this summer when 8,300 citizens were tricked into handing over their data from the UAE PASS system.
Where do scammers get information about victims? Often from the same place as telemarketers, it is sold or leaked by insiders.
How to Effectively Deal with Database Leaks?
First, implement security software, in particular Data-Centric Audit and Protection (DCAP) and Data Loss Prevention (DLP) systems. Together, these two solutions provide comprehensive data protection from the inside, identifying threats and preventing the misuse of information carelessly or intentionally. In fact, the implementation of such systems is recommended by the UAE government.
However, for many companies, especially small and medium businesses, purchasing DCAP and DLP systems is a major expense, which is why they often neglect security software. Consequently, such companies lose data and money. For them, the most suitable solution for data protection is Managed Security Services. It works on a subscription basis: the client is provided with security software, so there is no need to purchase a license and equipment and hire an information security analyst to manage the system.
Secondly, educate your employees on how to handle data responsibly. Raise their level of information security awareness through trainings and webinars. If a protective solution is deployed, it should be brought to the attention of employees. This fact will also reinforce discipline in working with information.
Finally, organizations should be legally obliged to implement security solutions. The regulations should specify classes of systems companies need to use and, most importantly, control their use. For failure to comply with this and other data protection requirements, it is advisable to introduce turnover-based fines for companies, with the size of fine increasing with each repeated violation.
Then, most companies will take a more responsible approach to protection and implement truly effective solutions, significantly reducing the number of victims of Internet fraud, cold calls, and other negative consequences of information leaks.
Conclusion
The telemarketing restrictions adopted in the UAE this year are the right move. The sizeable fines will make agents think twice before making calls at unspecified hours or without checking the number through the DNCR. However, this measure is unlikely to stop scammers.
There is a catch. The newly introduced measures are aimed at mitigating the consequences of the problem, in other words, “symptoms of the disease,” not its root cause, so the effect of their implementation may be limited. Without requiring organizations to prevent data leaks themselves, the side effects of data exposure, such as spam, and scams will continue to threaten the safety and well-being of people.
Therefore, it is paramount to take measures to combat data breaches by implementing specialized solutions and raising security awareness. This is the only way to tackle all the challenges associated with information loss.
