Practice · Telecommunications

Telecoms licensing in the UAE is federal, and no free zone sells you a way around it.

TDRA licensing and spectrum · interconnection and wholesale access · VoIP and OTT treatment · tower and passive-infrastructure deals · subsea cable landing and data centre interconnect · consumer-protection obligations · regulatory enforcement and disputes.

The structural fact most entrants get wrong

A commercial licence is not a telecoms licence.

Free zones issue commercial licences that permit a company to exist and to trade in a described activity. They do not authorise the operation of a public telecommunications network or the provision of public telecommunications services. That authority sits federally, with the Telecommunications and Digital Government Regulatory Authority, and it reaches into every emirate and every free zone — DIFC and ADGM included. Companies that build a product roadmap on the assumption that a free-zone activity code equals a right to carry traffic discover the gap late, usually when a bank, an operator or a customer asks to see the licence.

Where the commercial value actually sits

The licence perimeter, not the licence itself.

In a market with a small number of licensed public operators, the question that determines whether a business model works is rarely "can we obtain a licence?" It is "can this be structured so that a licence is not required, and if not, on whose licence do we ride?" Reseller, wholesale-capacity, managed-service and infrastructure-only structures each land differently. We advise on which side of the perimeter a given service falls, and design the contractual chain to keep it there.

2

Licensed public operators

e& (formerly Etisalat) and du (Emirates Integrated Telecommunications Company) supply public fixed and mobile services nationally, with significant state shareholding in both.

7

Emirates, one regulator

TDRA licenses and supervises the sector federally. There is no emirate-level telecoms licensing authority operating in parallel.

0

Free-zone carve-outs

No UAE free zone — including DIFC and ADGM — confers authority to operate a public telecommunications network or provide public telecoms services.

Who regulates the sector, and what that regulation actually reaches

The Telecommunications and Digital Government Regulatory Authority (TDRA) is the federal regulator of the UAE telecommunications sector. It issues and varies operator licences, manages the radio-frequency spectrum, administers numbering, approves telecommunications equipment for use in the country, sets technical and quality standards, supervises tariff and consumer-facing conduct, and enforces against unlicensed activity. Its remit was broadened when the authority took on the digital-government mandate, which is why the same regulator now sits behind both carrier licensing and federal digital-service policy.

Two consequences follow, and both are routinely misjudged by new entrants.

The first is reach. TDRA regulation is federal. It applies uniformly across all seven emirates and it applies inside the free zones. DIFC and ADGM are separate legal jurisdictions for civil and commercial law, company law, employment and data protection — they are not separate jurisdictions for telecommunications. An ADGM-incorporated company that wants to route voice traffic is in exactly the same regulatory position as a mainland Abu Dhabi company that wants to do the same thing.

The second is subject matter. Telecoms regulation attaches to the activity, not to the corporate form. Whether a company is a licensed operator, a technology vendor, a systems integrator or a foreign platform, the analysis starts with what the service does to traffic: does it carry it, terminate it, assign numbers to it, or merely sit on top of connectivity that someone else provides? That question, answered honestly at design stage, determines almost everything downstream.

The licensing perimeter: who needs authorisation, and for what

Under the UAE telecommunications regulatory framework, the operation of a public telecommunications network and the provision of public telecommunications services require a licence from TDRA. The licences held by the two public operators are broad, long-dated instruments covering fixed, mobile and international services. They are not products you apply for off the shelf.

Most commercial work therefore concerns the space around those licences rather than the licences themselves. The recurring structures are:

  • Reseller and branded arrangements. A commercial layer sitting on a licensed operator's network, with the operator retaining the regulatory relationship. The negotiation is about margin, exclusivity, subscriber ownership, brand control and — critically — who bears the cost of a regulatory instruction that changes the product.
  • Enterprise and managed services. Private networks, corporate connectivity, SD-WAN overlays and managed security. Whether these require authorisation depends on whether the service is offered to the public and whether the provider is carrying third-party traffic on its own account.
  • Wholesale capacity. Buying transmission or IP transit from a licensed operator and reselling it. Usually a contractual question sitting inside a regulatory constraint on who may sell what to whom.
  • Infrastructure-only. Owning ducts, towers, dark fibre or landing-station real estate without operating a service across it. This is where a great deal of recent capital has gone, precisely because the regulatory perimeter is narrower.

The point of the exercise is not to find a loophole. It is to identify, before commercial commitments are made, whether the business as designed sits inside or outside the licensed perimeter — and if inside, to structure the operator relationship so that the licensed party's obligations do not become the unlicensed party's uncontrolled liability.

The licensing perimeter: what the service does to the traffic Operating a public telecommunications network or providing public telecommunications services requires federal authorisation. The question is not what the business calls itself but what the service does to traffic, and whether it is offered to the public. Inside the perimeter Federal authorisation required Carrying or terminating public trafficProviding connectivity to the publicAssigning numbers to end usersDelivering content over managednetworks Structurable outside it Rides on a licensed operator Reseller on an operator's networkEnterprise managed services notoffered to the publicWholesale capacity resaleInfrastructure only — ducts,towers, dark fibre
No free zone confers telecoms authority, DIFC and ADGM included. Establish which side a feature sits on before it is contracted into the market, not after.
LayerJurisdictionGovernsDoes not govern
TDRA telecommunications regulationUAE Federal — all emirates, all free zonesOperator licensing, spectrum, numbering, type approval, network and service standards, telecoms consumer conductCorporate form, contract law, employment, general data protection
Federal Personal Data Protection LawUAE Federal (onshore)Processing of personal data by onshore controllers and processors, administered by the UAE Data OfficeWhether you may operate a network or sell telecoms services
DIFC Data Protection Law 2020DIFC onlyData processing by DIFC-domiciled entities; GDPR-aligned regime with its own CommissionerTelecoms licensing — DIFC confers no authority to carry public traffic
ADGM Data Protection Regulations 2021ADGM onlyData processing by ADGM-domiciled entities; GDPR-aligned regime with its own regulatorTelecoms licensing — ADGM confers no authority to carry public traffic
Free-zone / mainland commercial licensingEmirate-level or free-zone authorityRight to incorporate and to trade in a described commercial activityAny sector authorisation for telecommunications networks or public telecoms services
Virtual-asset and financial-services regulationVARA (Dubai), FSRA (ADGM), DFSA (DIFC)Virtual-asset and regulated financial activity conducted in the relevant jurisdictionConnectivity, spectrum or the carriage of communications traffic

Spectrum, numbering and equipment approval

Spectrum in the UAE is a state resource assigned by TDRA. It is not sold, traded freely or held as property. Assignments come with conditions — coverage, technical parameters, interference management, and in practice an expectation of use. Any transaction involving a spectrum-holding entity therefore needs its diligence framed around whether the assignment survives the transaction, on what terms, and whether regulatory consent is required for the change of control that carries it.

This matters far beyond mobile operators. Satellite ground segment, private industrial networks in ports and logistics, oil and gas telemetry, broadcast links and short-range devices all touch spectrum. Deployments planned on the assumption that a frequency plan used in another jurisdiction will simply work here are a common and expensive error.

Numbering is administered federally. Numbers are allocated, not owned. Businesses that build customer relationships around a number — contact centres, messaging platforms, emergency and alerting services — should understand that the allocation sits with a licensed party and that continuity depends on that party's position, not on the commercial contract alone.

Type approval applies to telecommunications and radio equipment placed on the UAE market or connected to networks. Importers, device manufacturers, IoT vendors and industrial-equipment suppliers all encounter it, frequently at the point of customs clearance rather than at product-planning stage. The remedial cost is disproportionate: stranded inventory, missed installation windows, and contractual delay claims that the supply agreement never allocated.

Interconnection, wholesale access and a concentrated market

The UAE public market is served by two licensed operators. Concentration of that degree changes the character of the legal work. In a market with a dozen operators, interconnection disputes are commercial. In a market with two, they are structural, and they are resolved with the regulator in the room.

Interconnection arrangements determine how traffic passes between networks, what is paid for termination, how capacity is ordered and provisioned, how faults are escalated, and how billing disputes are settled. For an enterprise customer these look like background plumbing until a service-affecting fault sits at the boundary between two networks and each side attributes it to the other. The contractual question is whether the customer's agreement gives it any effective remedy where the failure is not within its counterparty's sole control — and in standard operator terms, frequently it does not.

Related access questions run alongside: duct and pole access, in-building infrastructure in mixed-use developments, wayleaves across master-developer land, and the practical monopoly a developer or facilities manager can exert over which operator serves a building. Those disputes are often not telecoms disputes at all in form. They arrive as property, construction or facilities-management claims, and they are lost by parties who did not secure connectivity rights at the development-agreement stage.

Where a wholesale or interconnect relationship is genuinely one-sided, the realistic levers are regulatory engagement, contractual escalation and occasionally a competition-adjacent argument. Each requires contemporaneous evidence. Complaints reconstructed later from recollection rarely survive contact with a regulator.

VoIP, OTT services and the voice perimeter

Voice is the most tightly held part of the UAE telecoms perimeter, and the treatment of internet-based voice has been the sector's most persistently misunderstood topic.

The starting position is that the provision of voice services to the public is a licensed activity. Applications offering voice or video calling over the internet have historically been treated as engaging that perimeter, with access to certain services restricted at network level and operator-affiliated calling applications offered as the sanctioned route. Access policy has been adjusted over time, including in favour of business collaboration and conferencing tools, and continues to be adjusted. Current position should therefore be confirmed rather than assumed.

The consequences are commercial rather than abstract:

  • Product and SaaS vendors selling into the UAE need to know whether an embedded calling feature changes the regulatory characterisation of their whole product, and whether it can be disabled or regionalised cleanly.
  • Enterprises standardising on a global unified-communications platform need to know whether their UAE offices can actually use it, before the rollout is contracted globally.
  • Contracts need to allocate the risk of a change in access policy. A supplier warranting uninterrupted availability of a service whose accessibility is not within its control has assumed a risk it cannot manage.

The disciplined approach is to characterise the service accurately, confirm the position with the regulator or through the licensed operator where the answer is material, and draft on the basis that access policy is a variable rather than a constant.

Towers, subsea cable and data centre interconnect

The most active transactional work in the sector concerns passive infrastructure rather than services, for a straightforward reason: infrastructure carries predictable, contracted, long-dated revenue and sits in a narrower part of the regulatory perimeter.

Tower and passive-infrastructure transactions separate the physical estate from the operating business — typically a sale or carve-out of tower assets with a long-term master lease back to the operator. The legal work is in the detail that determines whether the deal is financeable: what precisely transfers, given that towers sit on land held under a patchwork of leases, municipal permissions and utility arrangements; how the master services agreement prices escalation and co-location; who carries the risk of a site lacking clean title or permitting; and what happens on decommissioning or technology change. Regulatory consent and change-of-control analysis must be scoped early, because a licensed operator's obligations do not transfer with the steel.

Subsea cable touches the UAE as both a landing jurisdiction and a transit corridor between Europe, the Gulf and Asia. Landing arrangements engage a licensed party, landing-station access, permitting for the marine and terrestrial route, and coordination with port, maritime and environmental authorities. The recurring disputes concern repair obligations and outage risk, capacity indefeasible-rights-of-use terms, and what happens when a fault outside UAE waters degrades a service sold on a UAE-law contract.

Data centres and interconnect sit at the junction of telecoms, real estate, energy and data protection. A hyperscale or colocation project needs power and cooling arrangements, land and build contracts, carrier access on non-discriminatory terms, and a data-residency architecture aligned to the federal Personal Data Protection Law or to the DIFC and ADGM regimes depending on where the controlling entity sits. Run those workstreams together; sequenced separately, they contradict each other.

Consumer protection, content and cyber obligations

Licensed operators, and increasingly the businesses sitting on top of them, carry conduct obligations under the UAE telecommunications regulatory framework: transparency of tariffs and terms, billing accuracy, fair treatment on renewal and termination, complaint handling, service quality, and controls on unsolicited marketing communications.

The marketing-communications point is where non-telecoms businesses collide with telecoms regulation most often. A retailer, a clinic or a property brokerage running an SMS or automated-call campaign is engaging rules on unsolicited commercial communication, alongside the consent and lawful-basis requirements of the applicable data-protection regime. The two frameworks overlap but are not identical, and satisfying one does not discharge the other.

Content and conduct obligations sit alongside. The UAE has an established federal cybercrimes framework addressing, among other things, unlawful access to systems, misuse of information technology and online content offences. Media and publishing activity engages a separate media-regulatory layer. A digital platform operating in the UAE can therefore find itself answerable to a telecoms regulator, a media regulator, a data-protection authority and the criminal law simultaneously — four different regimes, four different escalation paths, and no single clearing house.

The practical output for a client is a mapped obligation register: which regime bites on which part of the service, who inside the business owns each obligation, and what the notification path looks like when something fails at three in the morning.

Where this goes wrong

The failure modes in this sector are consistent enough to list. Each of the following has cost clients materially more than the advice that would have prevented it.

  • Treating a free-zone licence as regulatory authority. An activity description on a trade licence is not a telecoms authorisation. This surfaces at the worst possible moment — during investor diligence, at bank onboarding, or when a licensed operator declines to interconnect with a counterparty it cannot verify.
  • Contracting first, characterising later. Signing enterprise customers or a distribution agreement before establishing whether the service requires authorisation. Once revenue is booked and customers are live, the remediation options narrow to the expensive ones.
  • Assuming DIFC or ADGM domicile changes the telecoms analysis. It changes the governing law of the contract, the courts, the data-protection regime and the corporate law. It does not change who licenses telecommunications.
  • Ignoring type approval until customs. Device and IoT programmes planned to a launch date, with equipment approval treated as a formality, and inventory then stranded at the border.
  • Warranting availability of something outside your control. Suppliers accepting uptime or accessibility warranties for services whose availability depends on network-level access policy or on a third-party operator.
  • Tower and infrastructure deals diligenced as pure real estate. Site title and permitting matter, but so do the regulatory obligations attached to the operator and the change-of-control consents. A deal signed on a real-estate template will find the gap at completion.
  • Building the data-residency architecture after the product. Retrofitting residency and cross-border transfer controls into a live platform is an order of magnitude more expensive than designing for them, and it usually forces a renegotiation with customers who were promised something else.
  • Letting a regulatory correspondence thread run without counsel. Early informal responses to a regulator become the record. Positions taken casually in an email are difficult to move later.

Enforcement and disputes: where they actually land

Telecoms disputes in the UAE rarely present as a single clean claim in a single forum. They fragment, and the first strategic decision is usually about sequencing rather than merits.

Regulatory enforcement — unlicensed activity, breach of licence conditions, equipment non-compliance, consumer-conduct failures — proceeds through the regulator, with its own investigation, response and appeal pathway. The most valuable work here is early: the shape of the first written response frequently determines whether a matter is resolved administratively or escalates.

Commercial claims — interconnect and wholesale disputes, service-level and outage claims, infrastructure and construction claims on tower or landing-station projects, distribution and reseller terminations — go where the contract sends them: onshore courts, DIFC or ADGM courts, or arbitration under DIAC, arbitrateAD or another institution. Vendor and operator standard terms frequently specify a forum the customer never considered, and that choice is often more consequential than the substantive terms around it.

Data and cyber incidents run as a third, parallel track on a much shorter clock — regulatory notification, customer communication, and evidence preservation. Decisions taken in the first forty-eight hours, usually by people who are not lawyers, define the defensible position for the next two years.

Running these tracks as one coordinated matter, rather than three unconnected ones, is the difference between a manageable problem and a compounding one. See Litigation & Arbitration for the contentious side, and Data Protection for the incident track.

Frequently asked questions

Do I need a TDRA licence, or is my free-zone licence enough?

They answer different questions. A free-zone or mainland commercial licence permits the company to exist and to trade in a described activity. Operating a public telecommunications network or providing public telecommunications services requires authorisation from TDRA, which is federal and applies inside every free zone including DIFC and ADGM. The real analysis is whether your service falls inside the licensed perimeter at all — many enterprise, software and managed-service models can be structured so that it does not, but that has to be established before customers are signed, not afterwards.

Does incorporating in DIFC or ADGM change the telecoms position?

No. DIFC and ADGM are separate jurisdictions for company law, contract law, employment and data protection, and they have their own courts. Telecommunications licensing is federal and is unaffected by which of those jurisdictions you incorporate in. Domicile does change the data-protection regime that applies to your processing, and the forum for contractual disputes — both material choices, but neither of them a route around TDRA.

How is VoIP treated in the UAE?

Provision of voice services to the public is a licensed activity, and internet-based voice has historically been treated as engaging that perimeter, with access to some applications restricted at network level and operator-affiliated calling applications offered as the sanctioned alternative. Access policy has been adjusted over time, including in favour of business collaboration tools, and it continues to change. Because the position moves, we confirm it for the specific service rather than working from a general assumption — and we draft contracts so that a change in access policy is an allocated risk rather than a breach.

Can spectrum be bought, sold or transferred with a business?

Spectrum is a state resource assigned by TDRA on conditions, not property that trades freely. In any transaction involving a spectrum-holding entity the questions are whether the assignment survives the deal, whether the change of control requires regulatory consent, and what conditions attach on the other side. This is scoped at the start of diligence, because the answer can change the structure — and, occasionally, the price.

What actually needs to be diligenced in a UAE tower or passive-infrastructure deal?

Beyond the asset schedule: site-by-site land tenure and permitting, because towers typically sit on a mix of leases, municipal permissions and utility arrangements; the master services agreement terms on escalation, co-location and decommissioning; which regulatory obligations remain with the licensed operator and cannot transfer; and the change-of-control consents required. Deals diligenced on a pure real-estate template consistently find the regulatory gap at completion rather than at signing.

Our SaaS product includes a calling feature. Does that make us a telecoms provider?

Not automatically, but it is the question that determines your regulatory characterisation, and it deserves a considered answer rather than an assumption. What matters is what the feature does to traffic, whether it is offered to the public, and whether it can be regionalised or disabled cleanly for the UAE. Establishing this before the product is contracted into the market is materially cheaper than restructuring a live service.

We are running an SMS marketing campaign. Which rules apply?

Two frameworks, and satisfying one does not discharge the other. Controls on unsolicited commercial communications sit within the telecoms regulatory framework, and the consent and lawful-basis requirements sit within the applicable data-protection regime — the federal PDPL for onshore controllers, or the DIFC or ADGM regime if the controlling entity is domiciled there. Campaigns are frequently designed against one and then challenged under the other.

A regulator has written to us. What should we do first?

Before responding on the merits: establish exactly what is being asked and under which power, preserve the relevant records, and identify who inside the business may speak to it. The shape of a first written response frequently determines whether a matter resolves administratively or escalates, and informal early correspondence becomes part of the record that later positions have to be consistent with. Contact us before the reply goes out, not after.

Related practices

Tell us what the service does to the traffic. We will tell you which side of the licence it sits on.

Most of the value in this practice is delivered before anything is built or signed — characterising the service, confirming the position where it is material, and structuring the operator and customer contracts around the answer. If a regulator has already written to you, send that first.

Speak with a partner