The DIFC Data Protection Law explained: GDPR-grade, with extras
The DIFC Data Protection Law, DIFC Law No. 5 of 2020, is the data-protection law of the Dubai International Financial Centre, a common-law financial free zone with its own courts and its own Commissioner of Data Protection. It was built to be GDPR-grade, and it largely is. If you run GDPR, the principles, the six lawful bases including legitimate interests, the rights and the controller and processor duties will all look familiar. The interesting part is what the DIFC adds on top.
The GDPR-grade baseline
You process on one of the six Article 10 bases, with legitimate interests available subject to the Article 13 conditions. Special categories (Article 11) are actually broader than GDPR, adding communal origin and criminal-record data. You keep records of processing, respond to data-subject requests within one month, run DPIAs for high-risk processing, and notify breaches. None of that will surprise a GDPR practitioner.
Registration and an annual fee
Here is the first thing GDPR does not have. Controllers and processors in the DIFC must register their processing with the Commissioner, pay a fee, and renew annually (Article 14). The register is public. A lapsed registration is a standing contravention in its own right, so the renewal date belongs on a calendar with a reminder, not in someone's memory.
The annual DPO assessment, and non-discrimination
Where a DPO is required, the DIFC expects an annual assessment of the organisation's processing to be carried out and filed with the Commissioner (Article 19), a recurring regulator filing with no GDPR equivalent. The law also gives data subjects an express right not to be discriminated against for exercising their rights (Article 39), which reads more like California than Europe.
A couple of other DIFC fingerprints: breaches are notified to the Commissioner as soon as practicable rather than on a fixed seventy-two-hour clock (Article 41), and online platforms must default to privacy (Article 14(4)).
Regulation 10: AI and autonomous systems
The DIFC was early to regulate automated processing. Regulation 10 sets duties for autonomous and semi-autonomous systems, with named roles, a Deployer, an Operator and an Autonomous Systems Officer, plus oversight and certification. If you process personal data through AI in the DIFC, this is a distinct body of rules on top of the Law itself.
The DIFC gives you GDPR you already understand, plus a registration desk, an annual homework assignment for your DPO, and an AI rulebook most countries have not written yet.
In Compliance One
The DIFC control library covers the Law and its Regulations across seventeen domains, including a dedicated Regulation 10 domain for autonomous systems. The shared privacy registers are configured for the DIFC's one-month rights clock and the Commissioner, and everything cross-maps to GDPR so a single evidence set counts across both. The registration renewal and the annual DPO assessment come with their own reminders so the DIFC-only deadlines do not slip.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.