← All updates

UAE REGULATORY UPDATE · DIFC

DIFC: consultation on the amended Data Protection Regulations closed on 18 July 2026

The Dubai International Financial Centre put an amendment to its Data Protection Regulations out for public consultation, and the comment window closed on 18 July 2026. The final text does not appear to have been enacted: no obligation changes today. It is worth following because it touches artificial intelligence systems that process personal data, and the internal officer accountable for them.

What happened

On 18 June 2026 the Dubai International Financial Centre (DIFC), Dubai's financial free zone with its own legal framework, opened a thirty-day public consultation on proposed amendments to its Data Protection Regulations, set out in Consultation Paper No. 3 of 2026. The comment window closed on 18 July 2026. The proposals strengthen security requirements for systems processing personal data in an artificial intelligence (AI) context, clarify certification obligations and the role of the Autonomous Systems Officer — the internal officer accountable for autonomous systems — and give the Commissioner, the DIFC's data protection supervisory authority, new powers to recognise accreditation and certification schemes.

What changes in practice

For now, nothing. The consultation has closed, but the final text does not appear to have been enacted: there is no new obligation to discharge and no date to mark in the calendar. This is a development to monitor, not a compliance step. Presenting it as a rule already in force would be inaccurate, and that is the mistake most often made on subjects of this kind.

Who it applies to

DIFC-licensed entities that process personal data — customer records, KYC (Know Your Customer) files, employee data — and in particular those that route it through artificial intelligence tools. Entities with a DIFC presence serving customers in the European Union will find the subject overlapping with the General Data Protection Regulation (GDPR), which continues to apply in its own right and is not displaced by any of this.

The exposure

The exposure here is not an imminent penalty; it is arriving unprepared. If the text is enacted in the form proposed, businesses using artificial intelligence tools on customer data will need to be able to demonstrate how that data is protected and who, internally, is accountable for it. These are not things that can be built in the week the rule takes effect.

What to do now

Monitor difc.com for publication of the final text, which is the only point at which real obligations will arise. In the meantime, DIFC entities can take one step that is useful either way: record in writing which systems process personal data, which of those use artificial intelligence components, and who is accountable for them, by name. If the reform proceeds, that document is already half the work; if it does not, it remains what the DIFC expects to see today during an inspection.

Sources

Published 22 August 2026 on the basis of public sources and official United Arab Emirates instruments. This is not legal or tax advice. Verify your position with a qualified professional before acting.