.png)
.png)

DIFC Data Protection Law (Dubai)
Framework Name
DIFC Data Protection Law No. 5 of 2020
Type
Mandatory
Region / Jurisdiction
Dubai International Financial Centre (DIFC), a financial free zone within Dubai, UAE, with its own independent legal system separate from UAE federal law
Enforcing Body / Certifying Party
DIFC Commissioner of Data Protection, an independent regulator with full enforcement powers within the DIFC specifically
Penalty / Consequence of Non-Compliance
Administrative fines set out in the law's own schedule, ranging from $10,000 to $100,000 depending on the specific violation. Individuals also have a private right to go directly to court for compensation if they've suffered harm from a violation, not just a right to file a regulatory complaint
What It Is & Why It Matters
The DIFC Data Protection Law governs how any organization processing personal data within the DIFC handles that data, regardless of where the organization itself is incorporated. It's widely regarded as one of the most GDPR-aligned data protection frameworks outside the EU itself, and it also draws concepts from the CCPA. It was recently updated through an amendment effective July 2025, strengthening individual rights, cross-border transfer rules, and compliance obligations to keep pace with global practice.
It matters because DIFC was the first jurisdiction in the Gulf region to have any data protection law at all, dating back to 2004, and its current version remains a reference point for how a well-regarded international financial hub structures privacy regulation. For companies operating in or through DIFC specifically, banks, asset managers, fintechs, and other financial and professional services firms that make up the zone's tenant base, this is the actual governing law, not the UAE's broader federal privacy statute.
Who Needs It
- You operate a business registered in or processing personal data within the DIFC, regardless of where your parent company is incorporated
- You are a financial services, fintech, or professional services firm using DIFC as your regional base
- You need to transfer personal data out of the DIFC and must rely on the Commissioner's approved standard contractual clauses or binding corporate rules
- You want to compare DIFC's data protection standard against GDPR, since it was deliberately built to closely mirror it