Rules / United Arab Emirates

DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems)

In forceRegulationBinding

Applies within the DIFC free zone to deployers and operators of AI systems that process personal data. Requires clear notice at first use describing purposes, underlying principles and safeguards; certification-based demonstrations of compliance; and for high-risk processing an Autonomous Systems Officer with DPO-like duties.

Why it matters

Firms in the DIFC using AI on personal data need user notices, governance roles and, for high-risk processing, an Autonomous Systems Officer.

What it requires

Transparency to usersData governanceHuman oversightRegistration or filing
SourceMayer Brown (secondary): https://www.mayerbrown.com/ja/insights/publications/2026/01/ai-regulation-in-the-difc-personal-data-processed-through-autonomous-and-semi-autonomous-systems Checked against the source on 4 Oct 2026. Some details could not be confirmed from a primary source. Primary DIFC page could not be loaded from this environment. Introduced in late 2023 (September 2023 per law-firm reports); exact enactment/enforcement dates not verified.

Cite this record

DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems). Dubai International Financial Centre Authority / DIFC Commissioner of Data Protection. Status: In force. wheresthe.ai, https://wheresthe.ai/rule/ae-difc-data-protection-regulation-10-autonomous-systems/ (verified 4 Oct 2026).

More from United Arab Emirates

  • UAE AI Charter
    GuidelineUAE Government (Artificial Intelligence, Digital Economy and Remote Work Applications Office)Non-binding
    In forceEffective 10 Jun 2024
  • National AI Strategy 2031
    StrategyUAE Government (AI Office)Non-bindingPartly confirmed
    In forceAdopted 21 Apr 2019