01
Scope of application & addressees
- Organisations subject to DIFC data-protection law that deploy autonomous systems
- Businesses operating or supplying AI systems that process personal data
- People responsible for system governance, certification, transparency and data-subject rights
02
Core regulatory mandates & key requirements
01Deployers and operators identify their respective responsibilities for system processing.
02Systems follow applicable data-protection principles and relevant ethical and trustworthy-system standards.
03Qualifying organisations appoint an Autonomous Systems Officer and maintain certification and oversight.
03
Enforcement & compliance timeline
Regulation 10 entered into force.
DIFC publicly announced the regulation.