If your business processes personal data connected to the Dubai International Financial Centre, whether that means customers, employees or contacts based there, you need to understand the DIFC Data Protection Law. It applies to DIFC registered entities and, since a set of amendments made in 2025, to a wider group of businesses than many assume. The law is closely modelled on the UK and EU General Data Protection Regulation, which makes it more familiar to UK businesses than some other data protection regimes in the region. This guide sets out what the law covers, who it applies to, and what changed most recently.

What Is the DIFC Data Protection Law?

The DIFC Data Protection Law, formally DIFC Law No. 5 of 2020, came into effect on 1 July 2020, with enforcement beginning on 1 October 2020. It replaced an earlier 2007 law and was designed to bring the DIFC data protection regime closer to international standards, particularly the EU General Data Protection Regulation. The law is overseen by the DIFC Commissioner of Data Protection, an independent office responsible for its supervision and enforcement, and it is accompanied by a further set of DIFC Data Protection Regulations that add detail to how the law applies in practice.

Who Does the Law Apply To?

Following amendments made in July 2025, the DIFC Data Protection Law applies to any controller or processor incorporated in the DIFC, regardless of where it actually carries out its data processing. It also applies separately to the processing of personal data within the DIFC, including transfers made outside it, by any controller or processor as part of stable arrangements, even where that entity is not itself incorporated in the DIFC. This is a wider scope than many businesses assume, and it means a UK company with a genuine DIFC presence may be caught by the law even if most of its actual data processing happens outside Dubai.

What the Law Requires

The DIFC Data Protection Law sets out rights for data subjects that will be familiar from GDPR, including the right to access personal data held about them and to have inaccurate data corrected. Controllers processing higher risk categories of data may be required to appoint a Data Protection Officer, and businesses are expected to carry out an annual assessment of whether that requirement applies to them. Before undertaking higher risk processing activities, a data protection impact assessment may also be required, along with appropriate safeguards where personal data is transferred outside the DIFC.

What Changed in the 2025 Amendments

In July 2025, the DIFC Data Protection Law was amended to introduce a new private right of action, meaning data subjects can now apply directly to court for compensation where a breach of the law causes them financial or non-financial loss, rather than having to raise a complaint with the Commissioner first. Financial penalties were also increased significantly. Failing to complete the annual Data Protection Officer assessment can now attract a fine of up to USD 25,000, the maximum fine for failing to carry out a required impact assessment rose from USD 20,000 to USD 50,000, and penalties relating to disclosing personal data to a public authority rose from USD 10,000 to USD 50,000. Businesses already compliant with the previous version of the law should not assume that compliance still holds good, since both the scope and the consequences of getting it wrong have moved.

Need a hand right now?

Contact us now for more information on how MAR Legal can help with DIFC Data Protection Law compliance, or book a consultation to discuss your obligations.

How MAR Legal Can Help

Our solicitors, advise UK businesses with a DIFC connection on what the Data Protection Law requires of them, including whether the law applies to their activities following the 2025 changes, what a Data Protection Officer assessment involves, and how to review data processing practices against the law’s current requirements.

This sits alongside our wider legal services in Dubai for UK businesses with a DIFC connection.

We also advise on employment law in the DIFC, for businesses handling employee data alongside wider workforce compliance in the region.

Frequently Asked Questions

It can. Following the 2025 amendments, the law applies to any business incorporated in the DIFC, and separately to the processing of personal data within the DIFC by any controller or processor, even one not incorporated there, where that processing is part of stable arrangements. A UK company with a genuine DIFC presence should check whether either test applies to it.

The two laws are closely aligned, since the DIFC law was deliberately modelled on GDPR. The main practical differences lie in enforcement, since the DIFC has its own Commissioner and its own penalty regime, and in scope, since the DIFC law applies specifically to processing connected to the DIFC free zone rather than the EU or UK more broadly.

Since the 2025 amendments, a business can face financial penalties issued by the Commissioner and a direct compensation claim from an affected data subject through the DIFC Courts, without the data subject needing to raise a complaint with the Commissioner first. Penalties can reach USD 50,000 for the most serious categories of breach.

It depends on the nature and volume of personal data your DIFC entity processes. The law requires an annual assessment of whether a Data Protection Officer is required, and failing to complete that assessment is itself treated as a breach that can attract a financial penalty, regardless of whether a Data Protection Officer turns out to be required.