Dubai DIFC Updates Data Protection Laws

by

The Dubai International Financial Centre (DIFC) has enacted amendments to the current framework of Data Protection Regulations. Regulation 10 is the first enacted regulations in the MEASA region on the processing of personal data via autonomous and semi-autonomous systems such as artificial intelligence (AI) or generative, machine learning technology.

Amendments to the Data Protection Regulations

The amendments to the Data Protection Regulations address the means for better, safer and more ethical management of personal data processing and operations.

The updated regulations provide clarity on:

  • Personal data breach assessment and reporting obligations in Regulation 8, including situations where a temporary custodian finds personal data that has been inadvertently left behind or lost;
  • Use and collection of personal data for marketing and communications, particularly regarding appropriate notices when employing systems that may impair data individuals’ rights to restrict or remove their personal data, default cookies settings and conditions for consent, as set out in Regulation 9;
  • Investigations and enforcement powers of the Commissioner when a Controller or Processor may employ unfair or deceptive practices as defined in Regulation 6.2;
  • Personal data processed through digital, generative technology systems under Regulation 10.

Compliance with Regulation 10

Regulation 10 enables DIFC to be a platform for interoperability of the many and varied guidelines and principles issued by sovereign governments and non-governmental organisations. This creates a plug and play space for application of ‘best fit’ principles to AI technology development is fundamental, responsible and ethical processing of personal data in such systems.

Jacques Visser, commissioner of Data Protection, DIFC said: “DIFC’s outcomes-based approach vis-a-vis application of the DP Law 2020 obligations to the development and use cases for systems provides a more collaborative, transparent way of creating and maintaining an innovative yet safe autonomous system.”

Use cases are expected to be tested through further consultation, inspection or supervision.

The Commissioner’s Office is also considering testing use cases through participation in a regulatory sandbox comprised of technology developers, users, regulators and non- governmental or quasi-governmental organisations, all of whom have an interest in keeping systems safe and their uses practical for the digital age.

Guidance will be issued to accompany the updated regulations in due course, the DIFC has said.

Related Reading

 

About Us

Middle East Briefing is one of five regional publications under the Asia Briefing brand. It is supported by Dezan Shira & Associates, a pan-Asia, multi-disciplinary professional services firm that assists foreign investors throughout Asia, including through offices in Dubai (UAE), China, India, Vietnam, Singapore, Indonesia, Italy, Germany, and USA. We also have partner firms in Malaysia, Bangladesh, the Philippines, Thailand, and Australia.

For support with establishing a business in the Middle East, or for assistance in analyzing and entering markets elsewhere in Asia, please contact us at dubai@dezshira.com or visit us at www.dezshira.com. To subscribe for content products from the Middle East Briefing, please click here.

Related reading
Back to top