The Central Bank of the UAE has ordered all licensed banks and financial institutions to immediately stop using instant messaging platforms such as WhatsApp to communicate with customers or handle sensitive data. In the directive issued on April 22, 2026, the regulator prohibited requesting or sharing customer information, executing transactions, sending verification codes or transmitting documents containing personal or financial details through unregulated apps. The Central Bank of the UAE stated that these platforms do not comply with required standards for data security and consumer protection, mandating the exclusive use of approved secure channels instead. Non-compliance with the order will result in sanctions, according to the regulatory notice.
This prohibition aligns with the Central Bank of the UAE’s broader consumer protection framework, which requires secure notification methods for all account transactions. Gulf News reported that the move addresses growing concerns over fraud and data breaches associated with consumer messaging applications. The directive applies across all licensed entities including insurers and exchange houses operating in the country.
According to a Pinsent Masons analysis, financial institutions were given until April 30, 2026, to fully discontinue such practices or face enforcement measures. The Central Bank of the UAE’s rulebook emphasises protection against digital attacks and the integrity of customer data as core requirements for licensed operators. This step reinforces existing guidelines on how banks must manage customer interactions in an increasingly digital environment.
The regulation complements Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data, a Chambers and Partners 2026 guide noted as criminalising unauthorised handling of banking information with stricter penalties for sensitive data. The Central Bank of the UAE works alongside other authorities to oversee compliance in the financial services sector. Data from the regulator highlights the need for robust governance to maintain the security of the UAE’s banking system.
In parallel, the Central Bank of the UAE has been advancing other authentication reforms, including the phase-out of SMS and email one-time passwords as covered in a March 2026 Gulf Business article. These initiatives reflect a comprehensive approach to mitigating risks in digital banking channels. The consumer protection standards outlined in the Central Bank of the UAE’s publications require free and secure transaction alerts to customers.
Analyses from firms such as Securiti have indicated that such measures ensure financial data stays within regulated environments that meet national data residency requirements. The Central Bank of the UAE has stressed that all customer data must remain protected in line with national data residency and privacy laws, according to its published standards. This directive forms part of ongoing supervisory expectations for risk management in the sector, the regulator’s rulebook shows.
ع