# DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems)

- **Jurisdiction:** United Arab Emirates (AE)
- **Type:** Regulation · **Status:** In force · **Binding:** yes
- **Issued by:** Dubai International Financial Centre Authority / DIFC Commissioner of Data Protection
- **Proposed:** — · **Adopted:** — · **Effective:** —
- **Obligations:** Transparency to users, Data governance, Human oversight, Registration or filing
- **Sectors:** All sectors, Finance

## Summary
Applies within the DIFC free zone to deployers and operators of AI systems that process personal data. Requires clear notice at first use describing purposes, underlying principles and safeguards; certification-based demonstrations of compliance; and for high-risk processing an Autonomous Systems Officer with DPO-like duties.

## Why it matters
Firms in the DIFC using AI on personal data need user notices, governance roles and, for high-risk processing, an Autonomous Systems Officer.

## Source
[Mayer Brown (secondary)](https://www.mayerbrown.com/ja/insights/publications/2026/01/ai-regulation-in-the-difc-personal-data-processed-through-autonomous-and-semi-autonomous-systems)
Checked against the source on 4 Oct 2026. Some details could not be confirmed from a primary source. Primary DIFC page could not be loaded from this environment. Introduced in late 2023 (September 2023 per law-firm reports); exact enactment/enforcement dates not verified.

## Cite
DIFC Data Protection Regulations – Regulation 10 (Processing personal data through autonomous and semi-autonomous systems). Dubai International Financial Centre Authority / DIFC Commissioner of Data Protection. Status: In force. wheresthe.ai, https://wheresthe.ai/rule/ae-difc-data-protection-regulation-10-autonomous-systems/ (verified 4 Oct 2026).

---
Canonical page: https://wheresthe.ai/rule/ae-difc-data-protection-regulation-10-autonomous-systems/ · Not legal advice.
