xmodoxmodo

Frameworks · Middle East

DIFC Data Protection Law 2020

The Data Protection Law, DIFC Law No. 5 of 2020, as amended, governs how controllers and processors established in the Dubai International Financial Centre process personal data. The DIFC Commissioner of Data Protection administers it.

Who it applies to

Controllers and processors established in the DIFC, and entities that process personal data in the DIFC as part of stable arrangements, wherever the data subjects are. The federal UAE PDPL does not apply inside free zones that have their own data protection law. A DIFC entity therefore answers to this law, and Federal Decree-Law No. 45 of 2021 does not apply to it.

Main requirements

Lawful basis & accountability

Lawful grounds for processing, records of processing, a Data Protection Officer where required, and impact assessments for high-risk processing.

Data subject rights

Access, rectification, erasure, objection and portability requests answered within the statutory time limits.

Transfers

Transfers out of the DIFC based on adequacy or appropriate safeguards, recorded for each transfer.

Breach notification

Under Article 41, a breach that compromises confidentiality, security or privacy is notified to the Commissioner as soon as practicable in the circumstances. Affected individuals are notified where required.

How xmodo supports it

  • 1

    Articles are set up as controls with owners, evidence and a calculated readiness score, alongside your security frameworks.

  • 2

    The breach workflow starts when an incident is classified as a personal data breach. It records the assessment, the notification and the timestamps the Commissioner may ask for.

  • 3

    Processors are held in the third-party module with their contracts and assessments, so the processor register is backed by evidence.

  • 4

    Mapping to GDPR, UK GDPR and the UAE PDPL lets a group with DIFC, mainland and European entities run one privacy programme and report to each regime.

Related frameworks

DIFC Data Protection Law 2020 shares requirements with the frameworks below. Controls you already run for any of them count towards DIFC Data Protection Law 2020 as well.

Frequently asked questions

Is this "DIFC GDPR"?

No. It is the Data Protection Law, DIFC Law No. 5 of 2020, a DIFC statute with its own Commissioner, breach rule and transfer regime. It shares concepts with the GDPR, so mapping between the two saves work, but it is a separate law.

Does the federal UAE PDPL also apply to us in the DIFC?

Federal Decree-Law No. 45 of 2021 does not apply within free zones that have their own data protection law. A DIFC-established entity answers to the DIFC law. A group with mainland and DIFC entities follows both, and xmodo assigns each entity to the law that binds it.

What is the breach notification deadline?

The DIFC law requires notification to the Commissioner as soon as practicable in the circumstances, where the breach compromises confidentiality, security or privacy. It does not set a fixed number of hours. The timestamps on the incident record are your evidence that you acted as soon as practicable.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo