Skip to content

Data

DIFC Data Protection Law

DIFC Law No. 5 of 2020, with the Data Protection Regulations

In short

Every DIFC entity that processes personal data has to notify the Commissioner of Data Protection and renew that notification each year. The Law closely tracks the GDPR in structure, with lawful bases, data subject rights, transfer restrictions and breach reporting. A Data Protection Officer is required where processing is high risk, and the Commissioner has fining powers that are used.

Instrument
DIFC Law No. 5 of 2020, with the Data Protection Regulations
In force
1 July 2020, enforcement from 1 October 2020
Regulator
DIFC Commissioner of Data Protection
Applies to
Every controller or processor incorporated in the DIFC, and any entity processing personal data in the Centre as part of stable arrangements, regardless of where the data subject is.

What it requires

ObligationWhat it means in practice
Notify the CommissionerFile a notification of processing operations on incorporation and renew it annually with the fee.
Appoint a DPO where requiredMandatory for high risk processing, and the appointment is notified to the Commissioner.
Maintain records of processingA written record of processing activities, purposes, categories and retention periods.
Honour data subject rightsAccess, rectification, erasure, restriction, portability and objection, within one month.
Report personal data breachesTo the Commissioner without undue delay where there is a risk to the data subject, and to affected individuals where the risk is high.
Control transfers out of the CentreOnly to jurisdictions with adequate protection, or under appropriate safeguards, or on a permitted derogation.

Deadlines

ItemWhen
Initial notificationOn incorporation, before processing begins
Annual notification renewalEach year, with the fee
Data subject request responseWithin 1 month, extendable in limited cases
Breach notification to the CommissionerWithout undue delay once aware

If you get it wrong

The Commissioner can issue directions, impose administrative fines set out in the Regulations, and publish enforcement outcomes. Data subjects also have a direct right to compensation in the DIFC Courts. Failing to notify, or letting the annual renewal lapse, is the most common and most avoidable contravention.

Notification is the obligation most firms miss

The Law requires a notification to the Commissioner describing the entity's processing operations. It is filed on incorporation and renewed annually with a fee. It is a small administrative step and it is skipped constantly, usually because nobody was told it existed.

A lapsed notification shows up at licence renewal and in due diligence. Put the renewal in the same calendar as the licence renewal and the problem disappears.

When you need a Data Protection Officer

A DPO is mandatory where the entity carries out high risk processing activities. That includes large scale processing of special categories of data, systematic monitoring of individuals on a significant scale, and processing that is likely to result in high risk to data subjects. The Law also brings in any processing of sensitive personal data as a core activity.

The DPO can be an employee or an external appointment, and does not have to be resident in the DIFC, although the Commissioner expects genuine availability. The appointment is notified to the Commissioner and the DPO must have real independence, which means no instruction on how to carry out the role and no dismissal for doing it properly.

Transferring data out of the DIFC

The DIFC maintains its own list of jurisdictions with an adequate level of protection, which includes the EEA and a number of other countries. Transfers to those places need no further mechanism. Everywhere else needs appropriate safeguards, most commonly standard contractual clauses, binding corporate rules or a legally binding instrument between public authorities.

The point that surprises groups is that a transfer to the parent company in another emirate is a transfer out of the DIFC. The Centre is treated as a separate jurisdiction for this purpose, so an intra-group data flow to a Dubai mainland affiliate needs the same analysis as a flow to Singapore.

Article 28 and requests from authorities

The Law contains a specific regime for disclosing personal data to a public authority, including a foreign one. Before handing anything over, the controller has to assess the request, satisfy itself of the legal basis, apply a proportionality test and keep a record of the assessment.

This matters for regulated firms receiving requests from overseas regulators and for any DIFC entity served with a foreign court order. Complying without doing the assessment is itself a contravention, even where the underlying disclosure would have been permitted.

Common questions

Does every DIFC company need to register for data protection?

Every entity that processes personal data, which in practice means every entity with employees, has to notify the Commissioner and renew that notification annually. The fee is modest. The exposure from not filing is not.

Is DIFC data protection the same as GDPR?

It is closely modelled on the GDPR and uses the same architecture of lawful bases, data subject rights and transfer restrictions. It is not identical. The DIFC has its own adequacy list, its own notification regime, and specific provisions such as the Article 28 assessment for disclosures to authorities that have no direct GDPR equivalent.

Is sending data to a Dubai mainland company an international transfer?

Yes. The DIFC is treated as a separate jurisdiction, so transferring personal data to an affiliate outside the Centre, including elsewhere in the UAE, requires an adequacy finding, appropriate safeguards or a derogation.

Check the source

This page summarises the position as at September 2026. Laws and regulations change. The authoritative text is published by the regulator: DIFC data protection. Nothing here is legal advice.

Compliance is a calendar, not a project

Six recurring obligations across four different bodies, and nobody sends a reminder. We track them for DIFC entities so renewal is never the moment you discover a gap.