Home › Law library › DIFC DPL
AE
DIFC DPL
DIFC Data Protection Law, DIFC Law No. 5 of 2020 (as amended by DIFC Amendment Law No. 1 of 2025)
Sourced. Last verified 9 October 2026
Dubai International Financial Centre (UAE free zone) Privacy
- Status
- In force since 1 July 2020 (compliance grace period ended 1 October 2020); amendments in force 15 July 2025.
- Who it applies to
- DIFC-incorporated entities wherever they process data, plus any controller or processor processing personal data in the DIFC, whether or not it is incorporated there.
- Size thresholds
- No size threshold. Every DIFC entity files a data protection notification at incorporation and whenever its processing changes.
- Regulator
- Commissioner of Data Protection (DIFC)
- Breach or incident reporting
- Notify the Commissioner of breaches that compromise data subjects' rights, and notify affected individuals of high-risk breaches as soon as practicable. Use the DIFC Personal Data Breach Reporting Form.
- Deadline to answer personal data requests
- Being verified
- Data protection officer
- Required for controllers/processors regularly doing High Risk Processing (e.g., large-scale sensitive data, AI or new tech); the Commissioner can also require one. DPO normally UAE-resident; groups may use one abroad.
- Local representative
- Being verified
- Sending data abroad
- Allowed to DIFC-approved adequate jurisdictions, or with safeguards (SCCs, Commissioner-approved BCRs) or derogations. Since 2025, exporters must document an adequacy assessment of the recipient jurisdiction.
- Cookies and consent
- Being verified
- Maximum penalty
- Administrative fines of USD 20,000–100,000 per listed contravention (e.g., up to USD 50,000 for not appointing a required DPO), plus Commissioner general fines for serious breaches and court compensation.
Facts marked “Being verified” are still being confirmed and are not given as answers.
What you must do
- File and keep current your DIFC data protection notification with the Commissioner.
- Assess whether you do High Risk Processing; if so, appoint a DPO and run DPIAs.
- Report qualifying breaches to the Commissioner, and tell high-risk affected people as soon as practicable.
- Document an adequacy assessment before any transfer outside the DIFC.
- Prepare for direct claims: since July 2025 individuals can sue in the DIFC Courts.
- Keep records of processing and honour data subject rights requests.
Recent changes
Amendment Law No. 1 of 2025 (in force 15 July 2025) added a private right of action in the DIFC Courts, clarified extraterritorial reach, and required documented adequacy assessments for transfers.
Sources
- Primary source: https://www.difc.com/business/registrars-and-commissioners/commissioner-of-data-protection
- Second source: https://www.twobirds.com/en/insights/2025/united-arab-emirates/difc-enacts-amendments-to-data-protection-law
- Regulator: Commissioner of Data Protection (DIFC)
Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].