The DIFC Data Protection Law No. 5 of 2020 comes into force today in the Dubai International Financial Centre, replacing the 2007 law with a modern, GDPR-style regime.
Key points
- Controller and processor obligations, including DPIAs for high-risk processing.
- Appropriate security measures and breach notification to the Commissioner.
- Restrictions on transfers outside the DIFC.
- A three-month period before enforcement begins on 1 October 2020.
Many UK financial services firms operate in the DIFC or serve clients there, so should review their privacy notices, transfer arrangements and incident procedures.
Source: DIFC Data Protection Law No. 5 of 2020 (DIFC)
Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.