Affinitas AI Advisory

AI in Practice — First Issue

AI Data Retention in the UAE — What the PDPL Means for Your ChatGPT Usage

September 2026 · 5-minute read

Ask a room of UAE executives whether their staff use ChatGPT, Claude, or Gemini for client work, and most hands go up. Ask whether that usage sits inside a documented retention and deletion policy, and the hands go down. That gap is no longer a theoretical compliance exposure. It is becoming an enforcement question.

The law already applies

The UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) has been in force since January 2022. It covers electronic processing of personal data — inside or outside the country — grants data-subject rights, and regulates cross-border transfers. When an employee pastes a client's contract, payroll file, or correspondence into a public AI tool, that is processing under the PDPL. If the tool's provider retains prompts for model training, or stores them outside the UAE, two further obligations are engaged: purpose limitation and transfer controls.

What has been missing, until now, is an enforcer. The PDPL's Executive Regulations — the operational detail — remain unpublished. Most firms have treated this as a reason to wait.

What changed this summer

Two developments ended the waiting logic. In June 2026, the UAE established a dedicated federal authority for artificial intelligence and data, consolidating the AI Office, the Emirates Data Office, and digital-government functions. For the first time, a single body holds a genuine private-sector enforcement mandate — and authorities are typically established ahead of the regulations they will enforce, not after. Separately, Dubai has set a two-year horizon for private-sector adoption of agentic AI, backed at Crown-Prince level. Firms are being told to deploy AI — into a regulatory perimeter that is hardening at the same time.

For entities in the DIFC, the perimeter is already hard: Regulation 10, covering personal-data processing through autonomous and semi-autonomous systems, is in full enforcement, and a 2026 consultation proposes formalising an accountable "Autonomous Systems Officer" role.

What most firms are getting wrong

The failure pattern we see is consistent: a generic "AI acceptable use" paragraph in an HR policy, no inventory of which tools touch which data, no enterprise agreements with no-training and deletion clauses, and no retention schedule for prompts and outputs. Policy without inventory is decoration. When the Executive Regulations arrive, the compliance runway will be short — and "we were waiting for the regulations" is not a control.

The practical sequence

This briefing is operational governance commentary, not legal advice. Where a formal legal position is required, we work with qualified counsel.

Affinitas AI Advisory's Agentic AI Readiness & Governance Audit begins with exactly this inventory — and ends with a retention and governance framework your board can sign.

← Back to Affinitas AI Advisory