DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems)
Applies within the DIFC free zone to deployers and operators of AI systems that process personal data. Requires clear notice at first use describing purposes, underlying principles and safeguards; certification-based demonstrations of compliance; and for high-risk processing an Autonomous Systems Officer with DPO-like duties.
Why it matters
Firms in the DIFC using AI on personal data need user notices, governance roles and, for high-risk processing, an Autonomous Systems Officer.
What it requires
Cite this record
DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems). Dubai International Financial Centre Authority / DIFC Commissioner of Data Protection. Status: In force. wheresthe.ai, https://wheresthe.ai/rule/ae-difc-data-protection-regulation-10-autonomous-systems/ (verified 4 Oct 2026).
More from United Arab Emirates
-
In forceEffective 10 Jun 2024
-
In forceAdopted 21 Apr 2019