If your business processes personal data connected to the Dubai International Financial Centre, whether that means customers, employees or contacts based there, you need to understand the DIFC Data Protection Law. It applies to DIFC registered entities and, since a set of amendments made in 2025, to a wider group of businesses than many assume. The law is closely modelled on the UK and EU General Data Protection Regulation, which makes it more familiar to UK businesses than some other data protection regimes in the region. This guide sets out what the law covers, who it applies to, and what changed most recently.
What Is the DIFC Data Protection Law?
The DIFC Data Protection Law, formally DIFC Law No. 5 of 2020, came into effect on 1 July 2020, with enforcement beginning on 1 October 2020. It replaced an earlier 2007 law and was designed to bring the DIFC data protection regime closer to international standards, particularly the EU General Data Protection Regulation. The law is overseen by the DIFC Commissioner of Data Protection, an independent office responsible for its supervision and enforcement, and it is accompanied by a further set of DIFC Data Protection Regulations that add detail to how the law applies in practice.
Who Does the Law Apply To?
Following amendments made in July 2025, the DIFC Data Protection Law applies to any controller or processor incorporated in the DIFC, regardless of where it actually carries out its data processing. It also applies separately to the processing of personal data within the DIFC, including transfers made outside it, by any controller or processor as part of stable arrangements, even where that entity is not itself incorporated in the DIFC. This is a wider scope than many businesses assume, and it means a UK company with a genuine DIFC presence may be caught by the law even if most of its actual data processing happens outside Dubai.
What the Law Requires
The DIFC Data Protection Law sets out rights for data subjects that will be familiar from GDPR, including the right to access personal data held about them and to have inaccurate data corrected. Controllers processing higher risk categories of data may be required to appoint a Data Protection Officer, and businesses are expected to carry out an annual assessment of whether that requirement applies to them. Before undertaking higher risk processing activities, a data protection impact assessment may also be required, along with appropriate safeguards where personal data is transferred outside the DIFC.
What Changed in the 2025 Amendments
In July 2025, the DIFC Data Protection Law was amended to introduce a new private right of action, meaning data subjects can now apply directly to court for compensation where a breach of the law causes them financial or non-financial loss, rather than having to raise a complaint with the Commissioner first. Financial penalties were also increased significantly. Failing to complete the annual Data Protection Officer assessment can now attract a fine of up to USD 25,000, the maximum fine for failing to carry out a required impact assessment rose from USD 20,000 to USD 50,000, and penalties relating to disclosing personal data to a public authority rose from USD 10,000 to USD 50,000. Businesses already compliant with the previous version of the law should not assume that compliance still holds good, since both the scope and the consequences of getting it wrong have moved.
Need a hand right now?
Contact us now for more information on how MAR Legal can help with DIFC Data Protection Law compliance, or book a consultation to discuss your obligations.
How MAR Legal Can Help
Our solicitors, advise UK businesses with a DIFC connection on what the Data Protection Law requires of them, including whether the law applies to their activities following the 2025 changes, what a Data Protection Officer assessment involves, and how to review data processing practices against the law’s current requirements.
This sits alongside our wider legal services in Dubai for UK businesses with a DIFC connection.
We also advise on employment law in the DIFC, for businesses handling employee data alongside wider workforce compliance in the region.