DIFC and ADGM

DIFC Data Protection Policy

The DIFC regime is closer to European data protection law than the federal UAE law is, and it is administered by its own Commissioner with its own courts. Two consequences matter most: **legitimate interests is available as a lawful basis**, and **the UAE mainland is not on the DIFC adequacy list** — so sending data to a mainland affiliate is a restricted transfer requiring safeguards.

Download as Word7 pages21 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

DIFC Data Protection Policy

DIFC Data Protection Law No. 5 of 2020 — [COMPANY NAME]

The DIFC regime is closer to European data protection law than the federal UAE law is, and it is administered by its own Commissioner with its own courts. Two consequences matter most: legitimate interests is available as a lawful basis, and the UAE mainland is not on the DIFC adequacy list — so sending data to a mainland affiliate is a restricted transfer requiring safeguards.

ItemDetail
Entity[COMPANY NAME], DIFC registration [NUMBER]
Role[Controller / Processor / Both]
Data Protection Officer[NAME — or "not appointed"; see Section 6]
DPO appointment notified to the Commissioner[DATE / Not applicable]
Annual notification to the Commissioner filed[DATE]
High risk processing activities?[Y/N — see Section 6]
Approved by[NAME], [DESIGNATION], on [DATE]
ReviewAnnually, and on any material change to processing

1. Scope

1.1This policy applies to the processing of personal data by [COMPANY NAME] as an entity established in the Dubai International Financial Centre.

1.2The governing law is DIFC Data Protection Law No. 5 of 2020, as amended, together with the DIFC Data Protection Regulations. The regulator is the DIFC Commissioner of Data Protection.

1.3The federal UAE Personal Data Protection Law does not apply to processing by a DIFC entity within the DIFC. Where the Company also operates a mainland or other free zone entity, that entity is separately subject to the federal PDPL.

1.4Group structures frequently run both regimes simultaneously. Mapping is per entity and per dataset.

2. Principles

PrincipleWhat it requires
Lawfulness, fairness and transparencyProcess lawfully and tell people what you are doing
Purpose limitationCollect for specified, explicit, legitimate purposes
Data minimisationAdequate, relevant and limited to what is necessary
AccuracyAccurate and kept up to date
Storage limitationKept no longer than necessary
Integrity and confidentialityAppropriate security
AccountabilityDemonstrate compliance — records, assessments, governance

3. Lawful Basis

3.1The Company processes personal data on one of the following bases, recorded for each activity:

Generated from www.helionerp.com1

6 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

This regime is separate from the federal law

A DIFC entity is governed by DIFC Data Protection Law No. 5 of 2020 and regulated by the DIFC Commissioner, not by the federal PDPL or the UAE Data Office. Applying a federal PDPL policy to a DIFC entity produces a document that references the wrong law, the wrong regulator and the wrong rights.

Mainland is not adequate — the point most groups miss

The DIFC maintains its own list of adequate jurisdictions and the UAE mainland is not on it. Sending personal data from a DIFC entity to a mainland affiliate, service provider or bank is a restricted transfer requiring standard contractual clauses, binding corporate rules or a derogation. Groups move data between their own entities constantly without treating it as a transfer at all.

Legitimate interests is available here

Unlike the federal regime, which leans heavily on consent, DIFC recognises legitimate interests as a lawful basis. That is genuinely useful — but it requires a documented balancing assessment. An assertion of legitimate interests with no assessment behind it is weaker than consent properly obtained.

Do not carry analysis across jurisdictions

A legitimate-interests assessment prepared for a DIFC entity does not support the same processing by a mainland affiliate under the federal law. Each entity needs its own analysis under its own regime.

The annual notification is a real obligation

DIFC entities file an annual notification with the Commissioner and update it on material change. It is administrative, it is easy, and it is the kind of thing that lapses quietly when the person who filed it last year has left.

DPO appointment turns on high risk processing

The trigger is the nature of the processing, not headcount. Large-scale special category processing, systematic monitoring, and automated evaluation with significant effects all point towards appointment. Where in doubt, appoint and notify.

One month for data subject requests

The DIFC response period is one month, extendable for complex requests provided the data subject is told of the extension and the reason. That is a shorter and more definite timeline than the federal position, and it needs a process behind it rather than good intentions.

Direct marketing objections are absolute

An objection to direct marketing must be honoured without a balancing exercise. Marketing suppression lists need to be central and applied across every campaign and channel.

Portability is a real right here

Data portability applies in DIFC. For a business holding structured customer data, the practical question is whether the systems can actually export it in a machine-readable format on request — usually discovered at the first request rather than in advance.

AI and automated systems carry additional obligations

DIFC introduced specific requirements for autonomous and semi-autonomous systems processing personal data, including impact assessment and transparency about automated decision-making. This area is developing quickly; confirm the current scope rather than relying on a policy drafted before it.

Report breaches first, assess second

Clause 7.2 instructs staff to report immediately without attempting to assess or fix. The most damaging delays come from a well-intentioned attempt to resolve something quietly, which loses containment time and often destroys the logs needed to establish scope.

Record why a breach was not notified

Entities document notified breaches and record nothing about those assessed and dismissed. If challenged, an absent record is indistinguishable from no assessment. Clause 7.4 requires the reasoning either way.

Employee data is in scope and includes sensitive categories

Passport and visa records, medical testing results and health insurance data all pass through a UAE employer. Much of it is special category data requiring an additional condition. Issue an employee privacy notice at onboarding.

The Commissioner has real enforcement powers

The DIFC regime includes fines and directions, and the Commissioner publishes guidance and takes enforcement action. This is not a light-touch jurisdiction on data protection.

Current as of

Reflects DIFC law current as of {{DATE OF USE}}. DIFC Data Protection Law No. 5 of 2020 was amended with effect from July 2025, and additional requirements for autonomous and semi-autonomous systems took effect from January 2026 — confirm the current text, the adequacy list and the notification requirements with the DIFC Commissioner or a DIFC data protection adviser before relying on this policy.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.