Compliance Node Overview
The Dubai International Financial Centre (DIFC) Data Protection Law 2020 (DIFC Law No. 5 of 2020), enacted on 1 July 2020 and commencing on 1 October 2020, is the data protection framework governing personal data processing within the DIFC, which is a designated free zone in Dubai with its own independent legal and regulatory system based on common law principles. DIFC Law No. 5 of 2020 replaced the earlier DIFC Data Protection Law 2007 (DIFC Law No. 1 of 2007) and is specifically designed to align with the EU General Data Protection Regulation (GDPR) framework, making the DIFC one of the most GDPR-compatible jurisdictions in the Middle East and Africa region. The DIFC is a major international financial centre - home to over 5,000 registered companies including many of the world's largest banks, asset managers, law firms, and professional services firms. The enforcement authority for the DIFC Data Protection Law 2020 is the Commissioner of Data Protection (CDP), who is appointed by the DIFC Authority (DIFCA). The Commissioner investigates complaints, conducts audits, issues enforcement notices, and imposes fines. Key features of DIFC Law No. 5 of 2020: (1) Controllers and processors - GDPR-aligned controller/processor framework; (2) Six lawful bases for processing: consent, contract, legal obligation, vital interests, public task, and legitimate interests; (3) Special categories of personal data: race or ethnic origin, political opinion, religious or philosophical belief, trade union membership, physical or mental health, sexual life or orientation, biometric data used for identification, criminal convictions or allegations - processed only with explicit consent or in limited exceptions; (4) Data subject rights: access, rectification, erasure, portability, restriction, objection, and rights related to automated decision-making - aligned with GDPR Arts. 15-22; (5) Data Protection Officer (DPO): required where processing poses high risk to data subjects - controllers must assess DPO need based on processing profile; (6) Personal data breach notification: notify the CDP within 72 hours; notify affected data subjects without undue delay for high-risk breaches; (7) Data Protection Impact Assessment (DPIA): required for high-risk processing; (8) Cross-border data transfer: transfers only to adequate jurisdictions or with appropriate safeguards; the DIFC CDP maintains a list of adequate jurisdictions; (9) Fines: up to USD 100,000 per violation; (10) Privacy notices must be provided before collection in English (and Arabic where appropriate). The DIFC is a separate legal jurisdiction from mainland UAE - DIFC law applies to entities registered in the DIFC; mainland UAE entities are subject to the UAE Federal Decree-Law No. 45 of 2021 on Personal Data Protection (Federal PDPL). DIFC entities transferring data to mainland UAE entities must consider both DIFC and Federal PDPL requirements.
Pillar: Cybersecurity · Authority: Commissioner of Data Protection (CDP), Dubai International Financial Centre (DIFC) · Version: 1.0.0 · Last updated:
Primary source: https://www.difc.ae/
SHA-256 integrity: 2b805424da3834f501906bf1b2aa73ac5bf0f2aa13f92539ebd79cbc3efb41c0
Primary Citations — 6 traced to source
- DIFC Data Protection Law 2020 (DIFC Law No. 5 of 2020) - enacted 1 July 2020; commenced 1 October 2020; GDPR-aligned framework for DIFC; six lawful bases: consent, contract, legal obligation, vital interests, public task, legitimate interests; special categories: race/ethnic origin, political opinion, religious/philosophical belief, trade union membership, health, sexual life/orientation, biometric data, criminal convictions; 72-hour CDP breach notification; DPO required for high-risk processing; DPIA mandatory for high-risk processing; USD 100,000 per violation fines; data subject rights aligned with GDPR Arts. 15-22
- Commissioner of Data Protection (CDP, DIFC) - appointed by DIFC Authority; independent enforcement authority; investigates complaints; conducts audits; issues enforcement notices; maintains CDP adequacy country list; receives DPO registrations; publishes DIFC DP Law 2020 guidance, DPIA templates, and SCC templates at difc.ae; active in reviewing breach notifications and compliance audits of DIFC-registered entities
+ 4 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access