DIFC Data Protection Regulations

Understanding Regulation 10

Regulation 10 of the DIFC Data Protection Regulations was enacted on 1 September 2023. It addresses the processing of personal data through autonomous and semi-autonomous systems, including artificial intelligence, and establishes a certification framework for systems operating within, or targeting individuals in, the DIFC.

In force

Enacted 1 September 2023 as part of the DIFC Data Protection Regulations.

Who it applies to

Controllers and processors deploying AI that processes personal data in the DIFC.

Enforcement

Overseen by the DIFC Commissioner of Data Protection, with fines up to 50 million USD.

Core obligations

What the regulation requires

  • Lawfulness and transparency

    Personal data processed through autonomous and semi-autonomous systems must have a lawful basis, and individuals must be informed clearly about how those systems use their data.

  • Risk and impact assessment

    Controllers must assess the risks their AI systems create for individuals and document mitigating technical and organisational measures.

  • Human oversight and accountability

    Meaningful human oversight, defined accountability and an auditable governance framework must be in place for systems that make or support decisions about individuals.

  • Certification of higher-risk systems

    Systems presenting higher risk, or processing sensitive personal data, may require certification by an accredited certification body before deployment.

Scope

Is your system in scope?

  • AI systems operated by entities established in the DIFC
  • Systems processing the personal data of individuals in the DIFC
  • Autonomous or semi-autonomous decision making about individuals
  • Systems processing sensitive categories of personal data

Penalties for non-compliance

Non-compliance can result in fines of up to 50 million USD, prohibition of processing activities and significant reputational damage. Penalties depend on the severity of the violation, the number of individuals affected and other factors determined by the DIFC Commissioner of Data Protection.