Quick answer
The DIFC Data Protection Law is explicitly modelled on GDPR and shares its core principles: lawful basis for processing, data subject rights, controller and processor accountability, breach notification, and restrictions on cross-border transfers. Regulation 10 sits inside that framework and adds obligations GDPR does not have, specifically mandatory certification of AI systems used for high-risk processing, appointment of an Autonomous Systems Officer, and AI-specific transparency notices. GDPR compliance does not automatically mean Regulation 10 compliance. The two frameworks are aligned at the foundation but Regulation 10 requires additional steps that GDPR does not.
How Similar Is the DIFC Data Protection Law to GDPR?
The DIFC Data Protection Law (No. 5 of 2020) was drafted to be consistent with GDPR and has been described by the DIFC's own Commissioner as embodying international best practice in line with EU and UK data protection regulations. The 2020 law drew on GDPR, the California Consumer Privacy Act, and other frameworks to produce a regime that DIFC-regulated firms with EU or UK connections could satisfy without running two entirely separate compliance programmes.
The structural similarities are substantial:
- The same six lawful bases for processing apply, including consent, contract, legal obligation, legitimate interests, vital interests, and public task.
- Data subject rights mirror GDPR: access, rectification, erasure, restriction, portability, and objection.
- Controllers and processors carry equivalent accountability obligations, including records of processing activities and data protection impact assessments for high-risk activities.
- Breach notification is required without undue delay, with the Commissioner able to direct notification to data subjects.
- Cross-border transfers require an adequacy finding or an alternative safeguard such as standard contractual clauses.
- A Data Protection Officer must be appointed by controllers and processors that conduct High Risk Processing Activities on a systematic or regular basis.
The July 2025 amendments (Amendment Law No. 1 of 2025) moved the DIFC regime even closer to GDPR by introducing a private right of action under Article 64A, allowing data subjects to bring civil claims directly in the DIFC Courts. This mirrors rights that have existed under GDPR since 2018 and have generated significant litigation volume in EU member states. Kennedys Law noted at the time that the DIFC was explicitly following the GDPR model in making this change.
Where Does Regulation 10 Go Beyond GDPR?
GDPR contains provisions on automated decision-making under Article 22 and requires DPIAs for high-risk processing under Article 35. Regulation 10 goes further in three specific ways.
Mandatory certification for high-risk AI systems. Under Regulation 10.3.3, commercial operation of any AI system for High Risk Processing is prohibited unless the system has been certified by a DIFC-accredited certification body. GDPR has no equivalent certification requirement. Article 42 of GDPR provides a voluntary certification mechanism, but it is not mandatory and does not carry an outright prohibition on operation without it.
Autonomous Systems Officer. Regulation 10 requires firms engaging in High Risk Processing to appoint an ASO, a role with specific accountability for AI system compliance. GDPR requires a Data Protection Officer in certain circumstances, but it has no equivalent role focused specifically on AI systems. The DIFC allows one person to hold both the DPO and ASO roles, but the ASO function is a separate requirement.
AI-specific transparency notices. Any product or platform using an AI system to process personal data must provide a clear notice at the point of initial use, detailing the human-defined purposes, principles, and limits governing the processing. GDPR's transparency requirements apply to processing generally; Regulation 10 adds a specific, point-of-use disclosure obligation tied to AI deployment that sits on top of the standard privacy notice requirement.
The EU chose a separate legislative instrument, the EU AI Act, to address AI governance. The DIFC chose to embed AI governance inside its existing data protection framework. The practical result is that a firm operating in the DIFC faces a single, integrated set of obligations, but those obligations are more demanding for AI than GDPR alone requires.
Does GDPR Compliance Satisfy Regulation 10?
No. GDPR compliance is a strong foundation but does not cover Regulation 10's AI-specific requirements. A firm that is fully compliant with GDPR will still need to:
- Identify every AI system it operates in the DIFC that processes personal data and assess whether it constitutes High Risk Processing.
- Complete a DPIA that is specific to each AI system and its risks, not a general data protection DPIA.
- Obtain certification for any AI system used for High Risk Processing from a DIFC-accredited certification body.
- Appoint an Autonomous Systems Officer for each entity engaging in High Risk Processing.
- Publish AI-specific transparency notices on products and platforms that use AI to process personal data.
- Maintain audit trails demonstrating that AI systems operate within human-defined purpose constraints and include triggers for human intervention when processing may produce unfair or discriminatory outcomes.
Firms with mature GDPR programmes will find the documentation disciplines familiar. The records of processing activities, DPIA methodology, and accountability structures they already maintain will reduce the effort required. But the certification requirement and the ASO function are genuinely new obligations with no GDPR equivalent.
Does the EU Recognise DIFC as Adequate?
No. The European Commission has not issued an adequacy decision for the DIFC. This means that transfers of personal data from the EU or EEA to the DIFC cannot rely on adequacy and instead require an alternative transfer mechanism, most commonly standard contractual clauses.
The DIFC has its own adequacy list, which determines which jurisdictions DIFC-registered firms can transfer personal data to without additional safeguards. This list is maintained by the Commissioner and broadly tracks prevailing international standards. Transfers to jurisdictions not on that list require a documented adequacy assessment or an alternative mechanism such as the DIFC's standard contractual clauses.
Since Amendment Law No. 1 of 2025, every transfer of personal data outside the DIFC requires a documented adequacy assessment held by the controller, including transfers to the UAE mainland.
What Does Regulation 10's Interoperability Design Mean in Practice?
Regulation 10 was explicitly designed to be interoperable with international AI governance frameworks, drawing on the OECD AI Principles, the European Commission's AI Ethics Guidelines, and the UNESCO AI Ethics Framework. The aim is that a firm complying with Regulation 10 will have a compliance posture that translates reasonably well across jurisdictions, rather than requiring a wholly separate programme for each regime.
In practice, this means:
- A firm that has completed Regulation 10 certification will have documentation and governance structures that are relevant to EU AI Act compliance, even though the two regimes use different mechanisms.
- A firm that has built GDPR-aligned data protection governance will have the accountability, documentation, and rights-management processes that Regulation 10 builds on.
- A firm mapping systems against both frameworks should start with the DIFC framework if it operates in the DIFC, since Regulation 10's requirements are binding and currently enforceable, while EU AI Act obligations for most system types apply from August 2026.
The interoperability design reduces duplication but does not eliminate it. The certification requirement under Regulation 10 has no direct equivalent elsewhere, and firms will need to manage it as a DIFC-specific obligation regardless of how well they satisfy other frameworks.
The Practical Position for Dual-Regulated Firms
For a DIFC-licensed financial institution that is also subject to GDPR, the working approach is to treat GDPR compliance as the baseline and Regulation 10 as the layer that applies specifically to AI. Where the two frameworks share requirements, the GDPR-aligned documentation will satisfy Regulation 10. Where Regulation 10 goes further, additional steps are needed.
The three areas requiring specific action beyond GDPR are certification, the ASO appointment, and the AI transparency notices. Everything else, including DPIAs, lawful basis assessments, data subject rights procedures, and breach notification, can be managed within a single integrated programme with DIFC-specific adaptations.
Magpie provides the audit trails, DPIA documentation, and observability records that Regulation 10 requires for AI systems, built to integrate with existing GDPR compliance programmes. Request a demo.