Don’t do SECURITY. Do business SECURELY.

New DIFC data protection law comes into force

The Dubai International Financial Centre’s new GDPR-style Data Protection Law No. 5 of 2020 takes effect.

The DIFC Data Protection Law No. 5 of 2020 comes into force today in the Dubai International Financial Centre, replacing the 2007 law with a modern, GDPR-style regime.

Key points

  • Controller and processor obligations, including DPIAs for high-risk processing.
  • Appropriate security measures and breach notification to the Commissioner.
  • Restrictions on transfers outside the DIFC.
  • A three-month period before enforcement begins on 1 October 2020.

Many UK financial services firms operate in the DIFC or serve clients there, so should review their privacy notices, transfer arrangements and incident procedures.

Source: DIFC Data Protection Law No. 5 of 2020 (DIFC)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights