Dubai International Financial Centre · Legislation

DIFC Autonomous Systems Data Protection Rules

DIFC Regulation 10 governs autonomous and semi-autonomous systems that process personal data and addresses deployer, operator, governance, certification and officer arrangements.

Current status
In force
Published or updated
7 September 2023
Effective date
1 September 2023
Last verified
19 August 2026

Prepared by Longan Bay Area AI Legal Research Center based on official public materials.

01

Scope of application & addressees

  • Organisations subject to DIFC data-protection law that deploy autonomous systems
  • Businesses operating or supplying AI systems that process personal data
  • People responsible for system governance, certification, transparency and data-subject rights

02

Core regulatory mandates & key requirements

01Deployers and operators identify their respective responsibilities for system processing.

02Systems follow applicable data-protection principles and relevant ethical and trustworthy-system standards.

03Qualifying organisations appoint an Autonomous Systems Officer and maintain certification and oversight.

03

Enforcement & compliance timeline

Regulation 10 entered into force.

DIFC publicly announced the regulation.

Primary text

Statutory & regulatory text

PROJECT ENQUIRY

Need to evaluate this regulation against your system architecture?

Consult with our regulatory team →