DIFC Data Protection Law

DIFC - Mandatly Inc.

This Law became effective on 1 July 2020. This Law repeals and replaces the Data Protection Law, being Law No. 1 of 2007, as it was in force immediately prior to the commencement of this Law (“the Previous Law”), and all Regulations made under the Previous Law from commencement of this Law.

The purpose of this Law is to provide standards and controls for the Processing and free movement of Personal Data by a Controller or Processor and protect the fundamental rights of Data Subjects, including how such rights apply to the protection of Personal Data in emerging technologies.

Difc Law Applicability (Article 6)

Data Protection Law is applicable to:
Any Processor or Controller incorporated in the DIFC, regardless of whether the Processing takes place in the DIFC or not or

  • Any business (regardless of its place of incorporation) which processes personal data within the DIFC as part of stable arrangements or
  • For any Controller or Processor carrying out processing activity in DIFC, it includes transfers of Personal Data out of the DIFC or
  • Any business which processes data on behalf of either of the above.

This Law does not apply to the Processing of Personal Data by natural persons in the course of a purely personal or household activity that has no connection to a commercial purpose.

DIFC Important Definitions (Article 3)

Personal Data:

Any information referring to an identified or Identifiable Natural Person.

Data Subject:

The identified or Identifiable Natural Person to whom Personal Data relates.

Controller:

Any person who alone or jointly with others determines the purposes and means of the Processing of Personal Data.

Process, Processed, Processes and Processing (and other variants):

Any operation or set of operations performed upon Personal Data, whether or not by automated means, such as collection, recording, organization, structuring, storage and archiving, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, transfer or otherwise making available, alignment or combination, restricting (meaning the marking of stored Personal Data with the aim of limiting Processing of it in the future), erasure or destruction.

Third Party:

Any person authorized to Process Personal Data, other than Data Subject, Controller, Joint Controller, the Processor, or Sub-processor.

DIFC Data Subject Rights

  1. Right to withdraw consent (Article 32)
    The Data Subject may withdraw consent at any time by notifying the Controller in accordance with Article 12(5).
  2. Rights to access (Article 33)
    Upon request, a Data Subject has the right to obtain from a Controller without charge and within one (1) month of the request about confirmation in writing as to whether or not Personal Data relating to him is being Processed and information at least as to the purposes of the Processing, the categories of Personal Data concerned, and the recipients or categories of recipients to whom the Personal Data are disclosed.
  3. Right to rectification (Article 33)
    Data Subject have the right to have inaccurate personal data rectified.
  4. Right to deletion (Article 33)
    The Data Subject has the right to require the Controller to erase the Data Subject’s Personal Data.
  5. Right to object to Processing (Article 34)
    A Data Subject has the right to object at any time on reasonable grounds relating to his situation to Processing of Personal Data relating to him.
  6. Right to restriction of Processing (Article 35)
    Data Subject shall have the right to require a Controller to restrict Processing.
  7. Right to data portability (Article 37)
    A Data Subject shall have the right to receive Personal Data in a structured, commonly used and machine-readable format.
  8. Right related to automated individual decision-making (Article 38)
    A Data Subject shall have the right to object to any decision based solely on automated Processing, including Profiling, which produces legal consequences concerning him or other seriously impactful consequences and to require such decision to be reviewed manually.
  9. Right to Non-discrimination (Article 39)
    A Controller may not discriminate against a Data Subject who exercises any rights under the Act.

Appointment of Data Protection Officer In DIFC (Article 16)

A DPO shall be appointed by:

  1. DIFC Bodies, other than the Courts acting in their judicial capacity; and
  2. A Controller or Processor performing High Risk Processing Activities on a systematic or regular basis.

A DPO must have knowledge of this Law and its requirements and shall ensure a Controller or Processor monitors compliance with this Law.

Where a Controller is required to appoint a DPO under the Act, the DPO shall undertake an assessment of the Controller’s Processing activities, at least once per year (“the Annual Assessment”), which shall be submitted to the Commissioner.

DIFC Enforcement (Article 62)

The details of these fines are listed under Schedule 2 of the Law. The new law sets a maximum fine of USD 100,000 for administrative breaches, with additional scope for larger fines (unlimited) for more serious violations.

The law adds the ability for compensation claims to be made by or on behalf of data subjects.

Conclusion: DIFC Compliance & Law

Data Protection compliance is not a one-time requirement for organizations incorporated with DIFC or operating within DIFC. To avoid any penalties or legal actions, one must follow Data Protection regulations and maintain compliance on an ongoing basis.

Organizations must also know the existing and upcoming Data Protection compliances across countries as data movement occurs on a global level and data protection regulations differ in one way or another as per the law of the land.

Mandatly Privacy Management - Mandatly Inc.

Related Blogs

Data Mapping Requirement for CPRA & CCPA Compliance20240501045009

Data Mapping Requirement for CPRA & CCPA Compliance

Data Mapping Requirement for CPRA & CCPA ComplianceWhat are the CPRA Data Mapping Requirements?The California Consumer Pr...
The Role of Employee Training in GDPR Compliance and Data Security20240205100131

The Role of Employee Training in GDPR Compliance and Data Security

The Role of Employee Training in GDPR Compliance and Data SecurityOverview: GDPR Training For EmployeesIn today's rapidly evo...
Explore the Link Between Cybersecurity and GDPR Compliance20240201044003

Explore the Link Between Cybersecurity and GDPR Compliance

The Intersection of GDPR & CybersecurityWhat is GDPR?Enforced since May 2018, GDPR is a comprehensive set of regulations ...
International Data Transfers: Understanding Legal Frameworks20240125043450

International Data Transfers: Understanding Legal Frameworks

Cross Border Data Transfer & Legal FrameworkA Legal Framework For Data ProtectionBefore delving into the legal mechanisms...
EU-U.S. Data Privacy & GDPR: A Symbiotic Bond20240110045117

EU-U.S. Data Privacy & GDPR: A Symbiotic Bond

The GDPR and the EU-US Data Privacy Framework: A Symbiotic RelationshipEU-US Data Privacy Shield FrameworkThe EU US Data Priv...
PIA Software: Streamlining Privacy Impact Assessments20231229045248

PIA Software: Streamlining Privacy Impact Assessments

Conducting Privacy Impact Assessments with PIA Software: Benefits and Best PracticesAbout Privacy Impact AnalysisIn today's d...
Getting Started with Privacy Impact Assessment (PIA) Software20231221064257

Getting Started with Privacy Impact Assessment (PIA) Software

Getting Started with PIA Software: Step-by-Step Implementation GuideIntroductionPrivacy Impact Assessment (PIA) software has ...
LGPD Compliance: Checklist & Best Practices20231109071852

LGPD Compliance: Checklist & Best Practices

Preparing for LGPD: Compliance Checklist and Best PracticesOverview Of LGPDThe LGPD, or Brazil's General Data Protection Law,...
Brazilian Data Protection Law (LGPD)20231030043222

Brazilian Data Protection Law (LGPD)

Data Subject Rights Under LGPD Access, Rectification, and ErasureIntroductionThe LGPD, or the Brazilian General Data Protecti...
Brazils’ LGPD Compliance Guide You Must Read20231025062215

Brazils’ LGPD Compliance Guide You Must Read

Everything You Need to Know About Brazil LGPD: Penalty For Non-Compliance of LGPDWhat is Brazil’s LGPD?The LGPD, or Lei Geral...
Key GDPR Compliance Privacy Software Features20230906043009

Key GDPR Compliance Privacy Software Features

5 Key Features to Look for in Privacy Management Software for GDPR ComplianceAbout The Features Of GDPR Management Compliance...
Virginia Consumer Data Protection Act – All about CDPA20230104044820

Virginia Consumer Data Protection Act – All about CDPA

Virginia Consumer Data Protection Act – All about CDPAWhat is VCPDA?The Virginia Consumer Data Protection Act CDPA is a...
Difference between CDPA, CCPA, CPRA and CPA20210722111718

Difference between CDPA, CCPA, CPRA and CPA

Difference between CDPA, CCPA, CPRA and CPAUnderstanding CDPA, CPA, CCPA & CPRAOn March 2, 2021, Governor Ralph Northam s...
Colorado Privacy Act (CPA)20210713052349

Colorado Privacy Act (CPA)

Colorado Privacy Act (CPA)Colorado is officially the third U.S state to adopt privacy legislation, after California and Virgi...
CDPA, CCPA and CPRA : Key Difference & Similarities20210705113837

CDPA, CCPA and CPRA : Key Difference & Similarities

CDPA, CCPA and CPRA : Key DifferencesAll About California’s CDPA, CPRA VS CCPAOn March 2, 2021, Governor Ralph Northam signed...
General Data Protection Regulation (GDPR)20210601103221

General Data Protection Regulation (GDPR)

General Data Protection Regulation (GDPR)What is General Data Protection Regulation (GDPR)?In December 2016, the EU Parliamen...
What is California Consumer Privacy Act?20210601090127

What is California Consumer Privacy Act?

What is California Consumer Privacy Act?The California Consumer Privacy Act (CCPA) is a state-wide data privacy law that regu...
Understanding the 7 Foundational Principles of Privacy by Design20210331035135

Understanding the 7 Foundational Principles of Privacy by Design

7 Foundational Principles of Privacy by DesignAbout Privacy By DesignIn our rapidly evolving digital landscape, where data fl...