By Ananya Sarkar and Pratishtha Sharma
The Dubai International Financial Centre Authority (DIFCA) has released Consultation Paper No. 3 in June 2026 proposing changes to the Data Protection Law (DIFC Law No. 5 of 2020).
In this blog, we outline the proposed changes and the practical implications DIFC businesses should now bear in mind.
1. Introduction of Key Amendments in Regulation 10:
Broader terminology (10.2.2(b)): “Principles” is being expanded to “policy frameworks,” giving organizations more flexibility to reference a wider range of governance instruments when explaining how a system was designed or developed.
Gap-filling requirement (10.2.2(b)(vi)): If no established codes, certifications, or policy frameworks yet exist for a given System, organizations must instead disclose the privacy-by-design/default measures used to meet Article 14(3) of the DIFC Data Protection Law. Regulators may respond by requesting an impact assessment or convening a review/audit body for technical and governance input.
Accessibility of notices (10.2.2(a)): Where a System has a physical form (e.g., a device), the required user notice must be deliverable through common interaction methods such as voice assistants or intelligent agents not just written/digital disclosures.
Physical embodiment (10.3.1(d)): The addition of “physical” here, combined with the above, signals that the framework is being adapted to cover AI systems with physical interfaces or embodiments, not just software.
New “Safety” concept (10.3.1): Safety joins the existing pillars of ethical, fair, transparent, secure, and accountable design. It introduces expectations around identifying data use, assessing harm risks (including physical harm), and mitigating bias/discrimination.
2. Autonomous Systems Officer (ASO)
The DIFC is reinforcing accountability across the board whether or not a formal ASO appointment is triggered, someone within the organisation must own compliance oversight. Regulation 10.3.3 refines requirements for the ASO role. Where a system is used for high risk Processing Activities, the ASO must have competencies and organisational authority comparable to a DPO, plus additional technical, regulatory, and organisational expertise specific to system governance and certification. Therefore, businesses required to appoint an ASO cannot simply assume their existing DPO is qualified for the role. This needs genuine assessment. Organisations must evaluate whether their DPO has the specialized technical and governance expertise the Regulations now demand, rather than treating the appointment as a formality.
Regulation 10.3.4 further extends accountability even to entities not required to appoint an ASO. These organisations must still designate internal responsibility for oversight and compliance with the relevant obligations.
3. A New Framework for Accreditation and Certification
The amendments introduce Regulation 11, granting the Commissioner authority to formally recognise external accreditation and certification frameworks. This means the DIFC may treat certain externally certified systems as equivalent to DIFC standards, at least in appropriate cases. Systems already certified under recognised external frameworks may avoid having to undergo a full, separate DIFC certification process from scratch. Firms operating across multiple jurisdictions that already comply with established international assurance frameworks stand to gain the most, as this reduces duplicative compliance burdens.
These proposed amendments indicate a shift from principle-based data protection toward a governance regime built specifically for AI. For DIFC businesses, the practical impact will vary depending on where they sit today. The proposed regime rewards businesses that can demonstrate substantive governance, while closing the door on generic or superficial compliance. Businesses should use the consultation period to assess where their current AI governance stands against these emerging expectations, and where gaps exist start building towards them now rather than waiting for the final rules to land.