I agreed, but did I consent?
As AI agents increasingly act on behalf of consumers, UAE’s Personal Data Protection Law must confront what meaningful consent really means in agentic commerce. This article has been authored by Vaibhavi Tadwalkar, with guidance and contributions from Arjun Uppal.
“Hey Agent, book me a table for dinner and surprise me.”
In the emerging world of agentic commerce, this single instruction can set in motion a sequence of autonomous decisions no conventional booking flow could. The AI agent scans the user’s location, reviews dining history, infers dietary preferences, books a restaurant, processes a payment, and shares a guest count with the venue. The dinner is booked. But across that cascade of automated acts, what did the user consent to, and how far does that consent extend?
This question sits at the heart of the tension between agentic commerce and the UAE’s federal data protection regime: Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (the PDPL).
THE UAE’S DATA PROTECTION REGIME AND THE AGENTIC ARCHITECTURE
The PDPL came into effect on January 2, 2022, establishing a unified federal standard for the collection, processing, storage and transfer of personal data across mainland UAE. It applies regardless of where the controller or processor is established, provided personal data belonging to UAE-based individuals is being processed. It does not extend to free zones with their own data protection regimes, notably the DIFC and the ADGM, nor to government entities or data governed by separate sectoral legislation. Since its enactment, the PDPL has formed part of a broader programme of institutional reform aimed at strengthening the UAE’s data governance framework. Most recently, on June 14, 2026, the UAE established the Federal Authority for Artificial Intelligence and Data, consolidating the former Emirates Data Office, the UAE Artificial Intelligence Office, and the digital government functions of the Telecommunications and Digital Government Regulatory Authority (TDRA) into a single authority reporting directly to the Cabinet. The Authority is responsible for shaping national AI and data policy, proposing legislation, setting compliance standards, and overseeing enforcement of the PDPL. This institutional consolidation closes a longstanding gap in the UAE’s data protection landscape by providing a dedicated supervisory authority capable of operationalising and enforcing the federal regime. While the Executive Regulations remain outstanding, including the anticipated schedule of administrative penalties, detailed compliance thresholds, and rules governing matters such as cross-border transfers, businesses are nonetheless required to comply with the PDPL as enacted. The regulatory trajectory is therefore increasingly one of implementation and enforcement rather than framework-building.
The PDPL provides a range of lawful bases for processing, including consent, contract performance, legal obligation, vital interests and public interest. In agentic commerce environments, where processing is dynamic, multi-party and frequently opaque at the point of instruction, consent remains the most practically appropriate basis for most commercial data processing. The other bases are either too narrow or too fact-specific to sustain what an AI agent undertakes across a multi-merchant transaction. It is therefore the PDPL’s requirements for valid consent that become the principal point of legal tension, and the architecture of agentic systems is precisely what those requirements were not designed to accommodate.
WHAT THE PDPL REQUIRES OF CONSENT
The PDPL defines consent as a specific, informed and unambiguous indication of the data subject’s agreement to the processing of their personal data, given by a statement or clear affirmative action. Under Article 6, consent must be given in a clear, simple and easily accessible manner, whether in writing or electronic form. The controller bears the evidentiary burden of proving that consent was properly obtained. The data subject may withdraw consent at any time, easily, and withdrawal does not affect the legality of prior processing.
Article 5 reinforces these requirements through processing controls that apply regardless of the legal basis relied upon. Personal data must be collected for a specific and clear purpose and not processed incompatibly with it. It must be limited to what is necessary for that purpose, kept accurate, and not retained after the purpose is fulfilled unless anonymised. These controls assume a defined, bounded processing activity. Agentic commerce operates on precisely the opposite model.
THE AGENTIC TENSION
A single instruction, multiple controllers
In conventional e-commerce, the data subject is present at each step: they search, select, confirm, and pay. In an agentic system, a single instruction, whether “book my dinner” or “plan my trip to Abu Dhabi”, triggers execution across time, platforms, and independent commercial parties without further input. The restaurant receives the user’s name, contact details, and dietary notes. The payment platform processes financial data. A third-party table management system holds the booking record. Each may independently qualify as a controller under the PDPL, each responsible for establishing its own lawful basis for processing and, where consent is relied upon, each required to demonstrate compliance with Article 6.
The PDPL’s controller-processor model assumes documented terms when a controller engages a processor, specifying scope, purpose, and security obligations. In a multi-agent environment, where systems transact at machine speed, the orderly documentation of these relationships is structurally difficult to maintain. Counterparty systems may engage sub-processors, log behavioural data for analytics, or retain transaction records under their own retention policies, none of which may have been disclosed to the user at the point of instruction.
Informed consent and the problem of runtime disclosure
The PDPL requires consent to be informed: the data subject must understand, before or at the point of giving consent, what personal data will be processed and for what purpose. In an agentic system, these matters may not be determinable at the point of instruction. An AI agent that infers a preference for Japanese cuisine from past transaction history, and uses that inference to select and book a restaurant, is processing personal data for a purpose, behavioural profiling for preference inference, that may never have been disclosed to the user. Article 5 requires that personal data be collected for a specific and clear purpose and not processed incompatibly with it. Where purposes expand as execution unfolds, the conditions for informed consent become structurally difficult to satisfy.
The right to withdraw and the collapsed window
Article 6 gives data subjects the right to withdraw consent at any time, and the procedure must be as easy as giving it. In an agentic context, this right is structurally undermined. By the time a data subject seeks withdrawal in respect of a particular transaction, the agent may already have confirmed a booking, committed to a cancellation policy, shared personal data with multiple merchants, and processed a payment. The gap between instruction and consequence is compressed to the point where meaningful withdrawal is not practically available. Article 6(2) preserves the legal position of controllers in respect of prior processing, but does not cure the absence of a meaningful withdrawal window, nor does it resolve what obligations arise in respect of data retained by controllers the user never knew were involved.
Automated processing and profiling
Article 18 of the PDPL gives data subjects the right to object to decisions arising from automated processing that have legal consequences or seriously affect them, including profiling. That right does not apply where the automated processing is included in the terms of a contract, required by applicable legislation, or where prior consent has been given under Article 6. In each case, the controller must apply appropriate measures to protect the data subject’s privacy. An AI agent that builds a behavioural profile through accumulated interaction data and uses it to shape choices, rank options, and set defaults may be engaged in profiling in the sense Article 18 contemplates. Whether consent obtained in such an environment constitutes a specific, informed and unambiguous indication of the data subject’s agreement is an open question the PDPL has not yet answered.
Towards a workable framework
The most defensible position available to businesses deploying agentic systems is a comprehensive privacy notice capturing the categories of data the system may process, the classes of controller it may engage, and the types of processing and purposes it may undertake. Consent is obtained once, against a fully articulated perimeter. This anticipatory disclosure model can be reinforced through layered consent structures, where higher-risk processing, such as sharing sensitive preference data with third-party merchants, requires a confirmatory step, and through contextual visibility tools such as activity logs that maintain the data subject’s awareness without requiring repeated interruption.
A well-conducted data protection impact assessment, completed before deployment and mapping the categories of processing, the controllers likely to be involved, and the risks to data subjects, provides both a compliance record and a design discipline. It forces businesses to confront, before going live, whether consent can genuinely be informed and specific, and whether processing is genuinely limited to what is necessary.
The unresolved question
The dinner was booked. Multiple controllers processed personal data. Preference inferences were drawn. A payment was taken. Across that sequence, was there consent of the standard the PDPL requires? The honest answer is: not necessarily in a form the law was designed to recognise. That uncertainty is heightened by the fact that some aspects of the PDPL remains to be operationalised through the Executive Regulations, leaving businesses to apply a binding legal framework to technologies that evolve considerably faster than regulatory guidance.
CONCLUSION
None of this renders agentic commerce impermissible. Businesses that engage seriously with the PDPL through comprehensive privacy notices, layered consent structures, pre-deployment impact assessments and documented governance arrangements are plainly better positioned than those that do not. Equally, the UAE’s data governance framework continues to mature. The strengthening of its institutional architecture, the development of dedicated supervisory functions and the continued refinement of the PDPL framework all point towards a regulatory environment that is becoming progressively more structured and capable of supporting emerging technologies. What the PDPL has not yet done, and may need to do, is address the agentic model directly. Standards for purpose-bound authorisation in automated systems, accountability frameworks for multi-controller chains, and guidance on Articles 6 and 18 in the context of modern AI deployments would meaningfully reduce the legal uncertainty that currently sits at the centre of this space. As the UAE continues to strengthen its institutional framework for AI and data governance, these are precisely the areas in which regulatory guidance and supervisory practice will become increasingly important. The law is reaching for a moving target, and the gap between its consent architecture and the realities of agentic systems is not a compliance detail. It is a structural question about what consent means when a system acts, learns, as well as decides, on your behalf.
Text by:

- Vaibhavi Tadwalkar, senior associate, KARM Legal
- Arjun Uppal, partner, KARM Legal







































































































































