CBUAE Regulatory Alignment
For financial institutions operating in the United Arab Emirates, alignment with Central Bank of the UAE (CBUAE) requirements is fundamental. DocChat is built to help licensed institutions move customer document collection off consumer messaging apps and onto a secure, auditable channel—directly supporting the requirements of CBUAE Circular CBUAE/MCS/2026/2058.
The Messaging-App Prohibition (CBUAE/MCS/2026/2058)
On 17 April 2026, the CBUAE issued Circular CBUAE/MCS/2026/2058, instructing all licensed financial institutions—including banks, insurers, exchange houses, and finance companies—to stop using instant-messaging platforms such as WhatsApp and Telegram for customer communication and data handling. Institutions were required to confirm compliance by 30 April 2026.
Under this directive, institutions are prohibited from using messaging apps to:
- Request or share customer data
- Initiate or confirm transactions
- Send authentication credentials such as one-time passwords (OTPs), PINs, or passwords
- Exchange documents containing personal or financial information
The CBUAE has stated that the use of VPNs or similar tools does not exempt institutions from these requirements. Institutions are directed to migrate customers to approved, controlled channels—such as official mobile apps, online portals, staffed contact centres, and branches.
How DocChat Supports This Requirement
DocChat replaces consumer messaging channels with a managed, institutionally controlled document-collection workflow. Specifically, DocChat helps your institution:
- Eliminate messaging-app document exchange: Customers receive a secure, time-limited link via email or SMS and upload through a branded web portal, not through WhatsApp or Telegram.
- Keep document handling on controlled infrastructure: Uploads are encrypted in transit, stored in the Azure UAE North region, and malware-scanned on receipt.
- Evidence every interaction: Each request, upload, and review decision is recorded to a tamper-evident, cryptographically chained audit log available for inspection.
- Control access: Role-based access controls and branch-level isolation limit who can view and act on customer documents.
Supporting Your Broader Data-Protection Obligations
Beyond the messaging-app circular, UAE financial institutions operate under broader data-protection frameworks, including the UAE Personal Data Protection Law (Federal Decree-Law No. 45 of 2021) and, for DIFC-based entities, the DIFC Data Protection Law (Law No. 5 of 2020). DocChat is designed to support your obligations under these frameworks by:
- Storing customer documents and records in the UAE North region
- Providing data-minimisation controls (only requested documents are collected)
- Supporting configurable retention and deletion policies
- Enabling data-subject-rights workflows operated by your institution as the data controller
DocChat does not replace your compliance programme. We provide technical controls that help you demonstrate the controls expected of a regulated institution.
Partner with a Secure Vendor
We welcome due diligence from your risk and information security teams. Contact us to discuss how DocChat supports your CBUAE/MCS/2026/2058 compliance, or read our Security Overview.