Frameworks · Middle East
DIFC Data Protection Law 2020
The Data Protection Law, DIFC Law No. 5 of 2020, as amended, governs how controllers and processors established in the Dubai International Financial Centre process personal data. The DIFC Commissioner of Data Protection administers it.
Who it applies to
Controllers and processors established in the DIFC, and entities that process personal data in the DIFC as part of stable arrangements, wherever the data subjects are. The federal UAE PDPL does not apply inside free zones that have their own data protection law. A DIFC entity therefore answers to this law, and Federal Decree-Law No. 45 of 2021 does not apply to it.
Main requirements
Lawful basis & accountability
Lawful grounds for processing, records of processing, a Data Protection Officer where required, and impact assessments for high-risk processing.
Data subject rights
Access, rectification, erasure, objection and portability requests answered within the statutory time limits.
Transfers
Transfers out of the DIFC based on adequacy or appropriate safeguards, recorded for each transfer.
Breach notification
Under Article 41, a breach that compromises confidentiality, security or privacy is notified to the Commissioner as soon as practicable in the circumstances. Affected individuals are notified where required.
How xmodo supports it
- 1
Articles are set up as controls with owners, evidence and a calculated readiness score, alongside your security frameworks.
- 2
The breach workflow starts when an incident is classified as a personal data breach. It records the assessment, the notification and the timestamps the Commissioner may ask for.
- 3
Processors are held in the third-party module with their contracts and assessments, so the processor register is backed by evidence.
- 4
Mapping to GDPR, UK GDPR and the UAE PDPL lets a group with DIFC, mainland and European entities run one privacy programme and report to each regime.
Related frameworks
DIFC Data Protection Law 2020 shares requirements with the frameworks below. Controls you already run for any of them count towards DIFC Data Protection Law 2020 as well.
Frequently asked questions
Is this "DIFC GDPR"?
No. It is the Data Protection Law, DIFC Law No. 5 of 2020, a DIFC statute with its own Commissioner, breach rule and transfer regime. It shares concepts with the GDPR, so mapping between the two saves work, but it is a separate law.
Does the federal UAE PDPL also apply to us in the DIFC?
Federal Decree-Law No. 45 of 2021 does not apply within free zones that have their own data protection law. A DIFC-established entity answers to the DIFC law. A group with mainland and DIFC entities follows both, and xmodo assigns each entity to the law that binds it.
What is the breach notification deadline?
The DIFC law requires notification to the Commissioner as soon as practicable in the circumstances, where the breach compromises confidentiality, security or privacy. It does not set a fixed number of hours. The timestamps on the incident record are your evidence that you acted as soon as practicable.