Registration is mandatory
Unlike GDPR, DIFC entities must register their processing with the Commissioner, pay a fee and renew every year. A lapsed registration is itself an enforcement risk.
The GDPR-grade law of the Dubai International Financial Centre.
The DIFC Data Protection Law (DIFC Law No. 5 of 2020), in force since 1 July 2020 and kept current by its Data Protection Regulations through 2025, is the data-protection law of the Dubai International Financial Centre, a common-law financial free zone with its own courts and its own Commissioner of Data Protection. It is GDPR-grade: six lawful bases including legitimate interests, the full set of principles and individual rights, records of processing, security and privacy by design, breach notification, a Data Protection Officer, impact assessments for high-risk processing, and adequacy-based cross-border transfers. On top of GDPR it layers a handful of DIFC-specific duties, chief among them a mandatory registration and annual renewal with the Commissioner, an annual assessment that high-risk processors file to the Commissioner, and a dedicated regime for autonomous and AI systems.
The standard
DIFC Data Protection Law, DIFC Law No. 5 of 2020 (+ Data Protection Regulations, incl. Regulation 10)
Who needs it
Any entity registered in or operating from the DIFC that processes personal data, from financial firms and their service providers to the professional and corporate services clustered in the Centre. Businesses in mainland UAE follow the federal PDPL instead, and those in Abu Dhabi Global Market follow the ADGM regulations, so a group spanning all three runs them side by side on one UAE track.
65
Articles + Regulations, mapped
The basics
The DIFC DPL applies to controllers and processors established in the DIFC and to the processing of personal data in the context of DIFC activities. It mirrors the GDPR structure: the processing principles, six lawful bases in Article 10 (including legitimate interests, subject to a balancing test under Article 13), broader special categories in Article 11 (which include communal origin and criminal-record data), the rights to access, rectification, erasure, restriction, portability and objection in Articles 32 to 40, and the controller and processor duties for records, security, breach, the DPO and impact assessments.
What makes it DIFC rather than GDPR is the extra machinery. Controllers and processors must register with the Commissioner, pay a fee and renew annually (Article 14). High-risk processors carry out an annual assessment and file it with the Commissioner (Article 19). There is an express non-discrimination right (Article 39), privacy by default built into platforms (Article 14(4)), a breach standard of 'as soon as practicable' rather than a fixed 72 hours (Article 41), an Article 28 regime for data-sharing and government-access requests, and Regulation 10 governing autonomous and semi-autonomous processing systems, with a Deployer, an Operator and an Autonomous Systems Officer.
Why it matters
Unlike GDPR, DIFC entities must register their processing with the Commissioner, pay a fee and renew every year. A lapsed registration is itself an enforcement risk.
High-risk processors must perform an annual assessment and file it with the Commissioner under Article 19, a recurring obligation GDPR does not impose.
Regulation 10 sets duties for AI and autonomous processing, with named roles and oversight, ahead of most data-protection laws worldwide.
The Commissioner can impose an uncapped general fine under Article 62(3), and the 2025 reforms added a private right of action for individuals.
The processing principles and the six Article 10 bases, including legitimate interests subject to the Article 13 balancing test.
Fair-processing notices (Articles 29 to 30) and the Record of Processing under Article 15, provided to the Commissioner on request.
Access, rectification, erasure, restriction, portability, objection and automated-decision rights, plus non-discrimination (Articles 32 to 40).
Appropriate measures and privacy by design and default (Article 14), with breach notification to the Commissioner as soon as practicable (Articles 41 to 42).
A DPO (Articles 16 to 18), the annual Article 19 assessment, DPIAs for high-risk processing (Article 20), and registration and renewal with the Commissioner (Article 14).
Adequacy and Article 27 safeguards for cross-border transfers, the Article 28 data-sharing regime, and Regulation 10 for autonomous and AI systems.
Firms assume their GDPR programme drops straight into the DIFC, then miss the DIFC-only duties: the mandatory registration and annual renewal, the Article 19 filing to the Commissioner, the autonomous-systems regime, and a breach standard worded differently from the GDPR clock. Tracking those by hand, while a group also runs the federal PDPL and the ADGM regulations, is where things slip.
Do it once, reuse it everywhere. Evidence you collect for DIFC DPL is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps DIFC DPL to your environment in a 30-minute walkthrough — and how much of it we handle for you.