[HEADER — replace with your organisation’s letterhead, if used]
DIFC Data Protection Policy
DIFC Data Protection Law No. 5 of 2020 — [COMPANY NAME]
The DIFC regime is closer to European data protection law than the federal UAE law is, and it is administered by its own Commissioner with its own courts. Two consequences matter most: legitimate interests is available as a lawful basis, and the UAE mainland is not on the DIFC adequacy list — so sending data to a mainland affiliate is a restricted transfer requiring safeguards.
| Item | Detail |
|---|
| Entity | [COMPANY NAME], DIFC registration [NUMBER] |
| Role | [Controller / Processor / Both] |
| Data Protection Officer | [NAME — or "not appointed"; see Section 6] |
| DPO appointment notified to the Commissioner | [DATE / Not applicable] |
| Annual notification to the Commissioner filed | [DATE] |
| High risk processing activities? | [Y/N — see Section 6] |
| Approved by | [NAME], [DESIGNATION], on [DATE] |
| Review | Annually, and on any material change to processing |
1. Scope
1.1This policy applies to the processing of personal data by [COMPANY NAME] as an entity established in the Dubai International Financial Centre.
1.2The governing law is DIFC Data Protection Law No. 5 of 2020, as amended, together with the DIFC Data Protection Regulations. The regulator is the DIFC Commissioner of Data Protection.
1.3The federal UAE Personal Data Protection Law does not apply to processing by a DIFC entity within the DIFC. Where the Company also operates a mainland or other free zone entity, that entity is separately subject to the federal PDPL.
1.4Group structures frequently run both regimes simultaneously. Mapping is per entity and per dataset.
2. Principles
| Principle | What it requires |
|---|
| Lawfulness, fairness and transparency | Process lawfully and tell people what you are doing |
| Purpose limitation | Collect for specified, explicit, legitimate purposes |
| Data minimisation | Adequate, relevant and limited to what is necessary |
| Accuracy | Accurate and kept up to date |
| Storage limitation | Kept no longer than necessary |
| Integrity and confidentiality | Appropriate security |
| Accountability | Demonstrate compliance — records, assessments, governance |
3. Lawful Basis
3.1The Company processes personal data on one of the following bases, recorded for each activity: