Understanding Regulation 10
Regulation 10 of the DIFC Data Protection Regulations was enacted on 1 September 2023. It addresses the processing of personal data through autonomous and semi-autonomous systems, including artificial intelligence, and establishes a certification framework for systems operating within, or targeting individuals in, the DIFC.
In force
Enacted 1 September 2023 as part of the DIFC Data Protection Regulations.
Who it applies to
Controllers and processors deploying AI that processes personal data in the DIFC.
Enforcement
Overseen by the DIFC Commissioner of Data Protection, with fines up to 50 million USD.
Core obligations
What the regulation requires
Lawfulness and transparency
Personal data processed through autonomous and semi-autonomous systems must have a lawful basis, and individuals must be informed clearly about how those systems use their data.
Risk and impact assessment
Controllers must assess the risks their AI systems create for individuals and document mitigating technical and organisational measures.
Human oversight and accountability
Meaningful human oversight, defined accountability and an auditable governance framework must be in place for systems that make or support decisions about individuals.
Certification of higher-risk systems
Systems presenting higher risk, or processing sensitive personal data, may require certification by an accredited certification body before deployment.
Scope
Is your system in scope?
- AI systems operated by entities established in the DIFC
- Systems processing the personal data of individuals in the DIFC
- Autonomous or semi-autonomous decision making about individuals
- Systems processing sensitive categories of personal data
Penalties for non-compliance
Non-compliance can result in fines of up to 50 million USD, prohibition of processing activities and significant reputational damage. Penalties depend on the severity of the violation, the number of individuals affected and other factors determined by the DIFC Commissioner of Data Protection.