UAE Data Protection & AI
DIFC: a financial free zone in Dubai
What it is, and where
A financial free zone, effectively one business district in Dubai, with its own courts and its own body of law separate from the rest of the UAE. Its data law binds only companies registered there. Though it occupies only a small district, the DIFC is one of the world's leading financial centres, home to thousands of registered companies including many of the region's banks, funds and international firms, so its rules reach a great deal of significant activity.
Does it apply to me?
Only if your entity is established in the DIFC. If not, this law does not apply, though the UAE's national law may.
What it asks of you
A familiar GDPR-style set: a lawful basis, transparency, data-subject rights (with a one-month deadline to answer access requests), security, breach handling, a data protection officer where required, and safeguards for transfers out of the zone.
The AI angle — what's distinctive about DIFC
A dedicated rulebook for AI, "Regulation 10", which makes the business deploying an AI system accountable for what the system does. It introduces specific roles ("Deployer" and "Operator"), requires a register of AI processing, expects privacy by design, and created a named oversight role, the Autonomous Systems Officer. Proposed 2026 changes would add "safety" as a design principle, detail the Officer's duties, and create an ASO certification. Those changes are proposed, not yet law: the consultation closed in July 2026 and the results are awaited.
Where to start
If you deploy AI that touches personal data in the DIFC, work out whether it is "high-risk", keep a record of it, and check whether you need an Autonomous Systems Officer.