DIFC Data Protection Law, comprehensive regime
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 1 July 2020.
A comprehensive regime rule binding private bodies.
As of 29 August 2026.
What it requires
- An app that is a controller or processor established in or targeting the DIFC free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier used to uniquely identify a natural person, including one derived from a photo, video, or audio recording.
What it reaches
Excludes recording-derived identifiersNo
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The DIFC Data Protection Law is a separate statute of the Dubai International Financial Centre free zone, in force since 1 July 2020, enforced by the DIFC Commissioner of Data Protection, not the federal Bureau. It applies only within the DIFC's own geographic free-zone footprint (Dubai's financial district), not to a UAE business operating onshore elsewhere. Controller and Processor are General Data Protection Regulation (GDPR)-style defined roles (Sched. 1). Sched.
1's Special Categories of Personal Data includes "genetic data and biometric data where it is used for the purpose of uniquely identifying a natural person," with no source-based exclusion for an identifier derived from a recording, so processing such data ordinarily requires explicit consent or another qualifying condition.
The DIFC framework is close to full GDPR Chapter III parity on data-subject rights (portability at Art. 37, automated decision-making and profiling safeguards at Art. 38, non-discrimination at Art. 39, confirmed by the Law's own index), and Arts. 26-27 set a near-identical adequacy-plus-alternative-safeguards structure to the federal PDPL for cross-border transfer.
The individual operative texts of these articles, and of the Part 7 breach-notification provisions and any private-right-of-action provision, were not each pulled verbatim; the structure recorded here reflects what the index confirms rather than asserting unconfirmed detail.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
official consolidated statute text, published at assets.u.ae
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.