Data Protection Law — United Arab Emirates — Dubai law | Esheria

Data Protection Law

This provision introduces the DIFC Data Protection Law, says the Commissioner administers it, and sets out core obligations for controllers and processors.

Jurisdiction
United Arab Emirates — Dubai
Instrument
Act or statute
Version
Undated source snapshot
Language
en
Official source
View official record ↗
DPO compliance administrative fines breach reporting commissioner powers complaints cross-border data transfer cross-border transfers data sharing data subject rights exemptions fines personal data breach personal data breach notification personal data processing privacy governance processor compliance

Statute overview

About this statute

This provision introduces the DIFC Data Protection Law, says the Commissioner administers it, and sets out core obligations for controllers and processors. Controllers and processors must use written agreements and safeguards for shared processing, control cross-border data transfers, and give data subjects required information and rights. If a personal data breach creates high risk, the Controller must notify the affected Data Subject quickly; the Commissioner can also require notification or a public communication. This segment defines several data protection terms and lists administrative fines for certain contraventions.

LexChat organizes source-backed legal information for research. Verify amendments, commencement, and current legal force with the official publisher before relying on it.