All frameworks
DIFDIFC Law 5/2020 · in force 1 Jul 2020 · regulated by the DIFC Commissioner of Data Protection

DIFC DPL compliance

The GDPR-grade law of the Dubai International Financial Centre.

The DIFC Data Protection Law (DIFC Law No. 5 of 2020), in force since 1 July 2020 and kept current by its Data Protection Regulations through 2025, is the data-protection law of the Dubai International Financial Centre, a common-law financial free zone with its own courts and its own Commissioner of Data Protection. It is GDPR-grade: six lawful bases including legitimate interests, the full set of principles and individual rights, records of processing, security and privacy by design, breach notification, a Data Protection Officer, impact assessments for high-risk processing, and adequacy-based cross-border transfers. On top of GDPR it layers a handful of DIFC-specific duties, chief among them a mandatory registration and annual renewal with the Commissioner, an annual assessment that high-risk processors file to the Commissioner, and a dedicated regime for autonomous and AI systems.

Start from the basics

The standard

DIFC Data Protection Law, DIFC Law No. 5 of 2020 (+ Data Protection Regulations, incl. Regulation 10)

Who needs it

Any entity registered in or operating from the DIFC that processes personal data, from financial firms and their service providers to the professional and corporate services clustered in the Centre. Businesses in mainland UAE follow the federal PDPL instead, and those in Abu Dhabi Global Market follow the ADGM regulations, so a group spanning all three runs them side by side on one UAE track.

65

Articles + Regulations, mapped

The basics

What is DIFC DPL?

The DIFC DPL applies to controllers and processors established in the DIFC and to the processing of personal data in the context of DIFC activities. It mirrors the GDPR structure: the processing principles, six lawful bases in Article 10 (including legitimate interests, subject to a balancing test under Article 13), broader special categories in Article 11 (which include communal origin and criminal-record data), the rights to access, rectification, erasure, restriction, portability and objection in Articles 32 to 40, and the controller and processor duties for records, security, breach, the DPO and impact assessments.

What makes it DIFC rather than GDPR is the extra machinery. Controllers and processors must register with the Commissioner, pay a fee and renew annually (Article 14). High-risk processors carry out an annual assessment and file it with the Commissioner (Article 19). There is an express non-discrimination right (Article 39), privacy by default built into platforms (Article 14(4)), a breach standard of 'as soon as practicable' rather than a fixed 72 hours (Article 41), an Article 28 regime for data-sharing and government-access requests, and Regulation 10 governing autonomous and semi-autonomous processing systems, with a Deployer, an Operator and an Autonomous Systems Officer.

Why it matters

What DIFC DPL does for your business

Registration is mandatory

Unlike GDPR, DIFC entities must register their processing with the Commissioner, pay a fee and renew every year. A lapsed registration is itself an enforcement risk.

An annual filing to the regulator

High-risk processors must perform an annual assessment and file it with the Commissioner under Article 19, a recurring obligation GDPR does not impose.

Autonomous systems are regulated

Regulation 10 sets duties for AI and autonomous processing, with named roles and oversight, ahead of most data-protection laws worldwide.

Real teeth

The Commissioner can impose an uncapped general fine under Article 62(3), and the 2025 reforms added a private right of action for individuals.

What it covers

Principles & lawful basis

The processing principles and the six Article 10 bases, including legitimate interests subject to the Article 13 balancing test.

Transparency & records

Fair-processing notices (Articles 29 to 30) and the Record of Processing under Article 15, provided to the Commissioner on request.

Individual rights

Access, rectification, erasure, restriction, portability, objection and automated-decision rights, plus non-discrimination (Articles 32 to 40).

Security & breach

Appropriate measures and privacy by design and default (Article 14), with breach notification to the Commissioner as soon as practicable (Articles 41 to 42).

DPO, DPIA & registration

A DPO (Articles 16 to 18), the annual Article 19 assessment, DPIAs for high-risk processing (Article 20), and registration and renewal with the Commissioner (Article 14).

Transfers & autonomous systems

Adequacy and Article 27 safeguards for cross-border transfers, the Article 28 data-sharing regime, and Regulation 10 for autonomous and AI systems.

The hard way

Firms assume their GDPR programme drops straight into the DIFC, then miss the DIFC-only duties: the mandatory registration and annual renewal, the Article 19 filing to the Commissioner, the autonomous-systems regime, and a breach standard worded differently from the GDPR clock. Tracking those by hand, while a group also runs the federal PDPL and the ADGM regulations, is where things slip.

The easier way, with Compliance One

  • A ready control library covering the DIFC Law and its Regulations across 17 domains, including a dedicated Regulation 10 autonomous-systems domain, so you implement the GDPR-grade baseline and the DIFC-specific duties together.
  • The shared privacy registers, records of processing, consent, rights requests, DPIAs, breach, transfers, retention, configured for the DIFC's vocabulary and the Commissioner of Data Protection.
  • Cross-mapping to GDPR so a single evidence set counts across both, with the federal PDPL and ADGM on the same UAE track for groups that span onshore and the free zones.
  • Reminders for the DIFC-only deadlines, the annual registration renewal and the Article 19 assessment, alongside breach, DPO and DPIA triggers and a cross-border transfer assessment.

Do it once, reuse it everywhere. Evidence you collect for DIFC DPL is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

How is the DIFC law different from the UAE federal PDPL?
The DIFC is a separate common-law free zone with its own Commissioner. Its law is GDPR-grade with legitimate interests as a lawful basis, where the federal PDPL is consent-first. DIFC entities are carved out of the federal PDPL, and we cover both, plus ADGM, on one UAE track.
Do we really have to register with the Commissioner?
Yes. Registration and an annual renewal with a fee are mandatory under Article 14 for controllers and processors in the DIFC, and a lapsed registration is an enforcement risk in its own right.
What is Regulation 10?
A dedicated DIFC regime for autonomous and semi-autonomous processing systems, with defined roles (Deployer, Operator, Autonomous Systems Officer) and oversight and certification duties. We provide a Regulation 10 control domain and policy template.
What is the breach deadline?
The DIFC standard is to notify the Commissioner 'as soon as practicable in the circumstances' where a breach compromises a data subject's confidentiality, security or privacy (Article 41), not a fixed 72-hour clock, with communication to affected individuals where the risk is high.

Ready to tackle DIFC DPL?

See exactly how Compliance One maps DIFC DPL to your environment in a 30-minute walkthrough — and how much of it we handle for you.