Compliance

What are the UAE rules on messaging patients about appointments?

Last reviewed 18 September 2026

Short answer

UAE clinics are responsible for the lawful handling of patient health data and for the consent behind any message they send. Health data rules are set federally and by health authorities in each emirate, including DHA in Dubai and DoH in Abu Dhabi. Automating messaging does not transfer that responsibility to the software vendor.

Who is responsible
The clinic, as the data controller
Regulators
Federal law plus emirate health authorities (e.g. DHA, DoH)
Consent
Recorded, and withdrawable by the patient
Retention
Defined period with a way to delete on request

This is a summary, not legal advice

Health data rules in the UAE sit across federal legislation and emirate-level health authority requirements, and free zones such as DHCC add their own. Clinics should confirm their specific obligations with their own counsel or compliance advisor.

What follows is the practical checklist clinics tend to work through when they automate messaging.

The practical checklist

  • Record consent for messaging per patient, with the date and channel, and honour withdrawal.
  • Keep automated messages administrative — appointments, deposits, availability — rather than clinical advice.
  • Limit who on the team can see conversations, and log staff actions.
  • Set a retention period for conversations and be able to delete a patient's records on request.
  • Know where patient data is stored and which sub-processors are involved.
  • Have a documented process for a patient asking what you hold about them.

Questions to put to any vendor

  • Can consent be recorded and enforced before outbound messaging?
  • Is there a configurable retention period and a purge?
  • Are staff and AI actions logged separately?
  • Which sub-processors handle messages, AI generation and voice?

How VeaDesk supports this

VeaDesk records messaging consent per patient, can restrict outbound messaging to consented patients, lets each clinic set a retention period and run a purge, keeps an audit log of AI and staff actions, and lists its sub-processors in the privacy notice. The clinic remains the data controller throughout.

Frequently asked

Can we send appointment reminders without explicit consent?

Clinics generally treat administrative messages about an existing booking differently from marketing, but the lawful basis should be confirmed with your own advisor rather than assumed.

Where is patient data stored?

Ask every vendor directly and get it in writing. VeaDesk documents its infrastructure and sub-processors in its privacy notice.

Does using AI change our obligations?

The obligations stay with the clinic. What changes is that you also need to know how the AI provider handles the content it processes.

Want this handled for your clinic?

VeaDesk answers enquiries in Arabic and English when your team can't, sends deposit links on your own payment account, helps refill cancelled slots and shows which marketing led to each paid booking.

Related guides