HomeFrameworksDIFC DP Law
DIFC Commissioner of Data Protection · United Arab Emirates (DIFC)

Data Protection Law, DIFC Law No. 5 of 2020 compliance software

The DIFC's own data protection law, article by article — 79 obligations on controllers and processors across 11 domains, consolidated to the July 2025 amendments and the DP Regulations, with the Commissioner-facing duties tracked as their own indicator.

At a glance
  • RegulatorDIFC Commissioner of Data Protection
  • InstrumentsDIFC Law No. 5 of 2020 (consolidated July 2025) · Data Protection Regulations (in force 1 Sep 2023)
  • Structure11 domains, 79 controls, each citing its article and regulation
  • FinesSchedule 2: USD 25,000–100,000 per contravention, plus a general fine; Article 64A civil claims
DIFC DP LawAvailable
Overview

What DIFC DP Law requires

Who it applies to

  • Every controller and processor incorporated in the DIFC
  • Firms processing personal data in the DIFC through a branch or stable arrangement
  • DIFC Authorised Firms already assessed against DFSA GEN 5.5
  • Deployers and operators of AI systems under DP Regulation 10

DIFC Law No. 5 of 2020 is the data protection law of the Dubai International Financial Centre, in force since 1 July 2020 and administered by the Commissioner of Data Protection. It applies to every controller or processor incorporated in the DIFC wherever it processes, and to processing carried out in the DIFC by others. The federal PDPL does not apply inside the zone. The Law was amended by DIFC Law No. 2 of 2022 and DIFC Law No. 1 of 2025, and is supplemented by the Data Protection Regulations, whose Regulation 10 on autonomous and semi-autonomous systems is the first AI-specific privacy rule in the region.

Its obligations run from the processing principles and lawful bases (Articles 9–13) through accountability, registration and records (14–15), the DPO and Annual Assessment (16–19), DPIAs (20–21), processor and joint-controller agreements (23–25), transfers out of the DIFC (26–28), transparency (29–31), the data subject rights (32–40), security and breach notification (41–42), digital communications and AI systems (Regulations 9–10) and enforcement, including the Article 64A private right of action added in 2025. Schedule 2 fines run from USD 25,000 to USD 100,000 per contravention, with an unlimited general fine above them.

GRCLens transcribes the Law and Regulations article by article from DIFC's consolidated text, cites the article and regulation on every control, and reads beside the DFSA cyber catalogue for a DIFC Authorised Firm and beside the ADGM Data Protection Regulations for a group with entities in both zones.

In the platform

How GRCLens supports DIFC DP Law

DIFC DP Law runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.

What the Commissioner sees first

Registration, the DPO appointment and the Annual Assessment are filed with the Commissioner, so they are tracked as one readiness indicator: the duties that fail in public before anyone inspects.

AI systems under Regulation 10

Notice on first use, the register of system use cases, human-intervention safeguards and the deployer-as-controller rule are controls in the Marketing, Digital Communications and AI domain — the material most firms adopting AI tooling meet first.

Reads beside DFSA and ADGM

A DIFC Authorised Firm assesses GEN 5.5 cyber rules and the DP Law in one tenant; a group with a DIFC and an ADGM entity reads the same six privacy indicators for both zones.

Arabic and English

Every article-level obligation carries Arabic with the same enumerators as the English, so bilingual boards and regulators read the same sub-paragraphs.

Questions

DIFC DP Law frequently asked questions

Does the UAE federal PDPL apply to a DIFC company?

Not for processing inside the DIFC — the zone has its own law and Commissioner. A DIFC firm that also processes onshore may be subject to both; GRCLens carries them as separate frameworks on the same control model.

What changed in 2025?

DIFC Law No. 1 of 2025 (enacted 8 July 2025) added Article 64A, giving data subjects a direct right of action in the DIFC Courts for damage including distress, and revised Schedule 2 amounts. The catalogue is consolidated to that text.

Is there a fixed breach notification deadline?

No fixed hours. Article 41 requires notification 'as soon as practicable in the circumstances' and Regulation 8.1 'without undue delay' — the Commissioner judges the delay after the fact, which is why the breach indicator counts every unmet duty in the notification chain.

Talk to us about DIFC DP Law

Security Solution Consultants provides DIFC data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.