DIFC Consultation - New Data Protection Law In Dubai International Financial Centre

CC
Clyde & Co

Contributor

Clyde & Co  logo
Clyde & Co is a leading, sector-focused global law firm with 415 partners, 2200 legal professionals and 3800 staff in over 50 offices and associated offices on six continents. The firm specialises in the sectors that move, build and power our connected world and the insurance that underpins it, namely: transport, infrastructure, energy, trade & commodities and insurance. With a strong focus on developed and emerging markets, the firm is one of the fastest growing law firms in the world with ambitious plans for further growth.
The Dubai International Financial Centre (DIFC) has issued a consultation paper relating to an update of the DIFC Data Protection Law
United Arab Emirates Privacy
To print this article, all you need is to be registered or login on Mondaq.com.

The Dubai International Financial Centre (DIFC) has issued a consultation paper relating to an update of the DIFC Data Protection Law*. The current law is based on the European Data Protection Directive which was replaced last year by the European General Data Protection Regulation (GDPR) and the DIFC is seeking to similarly update its own regime in light of that and other international developments.

The new draft law retains the same core principles as the existing law, but any business which processes personal data in the DIFC will need to be aware of some key developments proposed by the new legislation. Consultation responses are welcomed from any interested party.

Key features of the draft law include:

  • Increasing focus on organisational awareness and prominence, including requirements for data protection assessments, appointment of data protection officers, consultation with the Commissioner of Data Protection
  • Updated data export provisions to bring the DIFC closer into line with GDPR mechanisms and to provide a framework for DIFC controllers to respond to requests for data from competent authorities outside the DIFC
  • Extension of direct compliance obligations to data processors
  • Increased detail on data subject consent validity (where consent is the basis for processing)
  • Enhanced data subject rights
  • Anticipation of potential tension between emerging technologies and data protection principles and potential routes for controllers to manage the conflict

All businesses with DIFC operations, and providers of services who act as data processors on behalf of such businesses, will need to consider the implications of the draft law.

*Click here to access the consultation paper on the DIFC Data Protection law.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More