UAE Federal Decree-Law No. 45 of 2021 on Data Protection
This comprehensive federal data protection law applies across the UAE (except in financial free zones like DIFC and ADGM which have their own laws). The law regulates the processing of personal data and aims to protect individual privacy while facilitating legitimate data use. It establishes core principles including lawfulness, transparency, purpose limitation, data minimization, accuracy, […]
NITI Aayog’s Principles for Responsible AI, 2021
NITI Aayog, the Government of India’s policy think tank, outlines India’s foundational principles for responsible Artificial Intelligence (AI), building upon the 2018 National Strategy on AI. It highlights AI’s economic and social potential while acknowledging the emerging risks and ethical challenges associated with its rapid deployment, such as bias, privacy breaches, and accountability issues. The document examines system and […]
NITI Aayog’s National Strategy for Artificial Intelligence, 2018
Building upon the National AI Strategy, these principles provide a comprehensive framework for ethical and responsible AI development and deployment in India. The document establishes seven core principles: safety and reliability, equality, inclusivity and non-discrimination, privacy and security, transparency, accountability, and protection and reinforcement of positive human values. Under privacy and security, it mandates that […]
Draft Digital Personal Data Protection Rules, 2025
Released on January 3, 2025 by MeitY for public consultation, these draft rules provide the operational framework for implementing the DPDP Act, including provisions for consent managers, data retention periods, security measures, breach notifications within 72 hours, and children’s data protection. Download PDF
RBI Framework for Self-Regulatory Organizations (SRO) in Fintech, 2024
This framework establishes a structured approach for recognizing and overseeing Self-Regulatory Organizations in the fintech sector. The framework aims to foster responsible innovation while ensuring consumer protection and market integrity through industry-led governance. It sets out eligibility criteria for SRO recognition, including requirements for membership diversity, governance structure, and financial resources. SROs are tasked with […]
RBI Guidelines on Digital Lending, 2023
These guidelines were issued by the Reserve Bank of India to regulate digital lending practices and protect consumer interests in the rapidly growing digital lending ecosystem. The guidelines establish comprehensive requirements for all digital lending platforms, including mandatory disclosure of all-inclusive cost of digital loans, standardization of key facts statement, restrictions on unsolicited commercial communications, […]
DIFC Data Protection Law, 2020
The Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020 replaced the previous 2007 law, aligning more closely with GDPR standards. It applies to all entities established in the DIFC and those processing personal data of DIFC data subjects. The law introduces enhanced rights for individuals including right to data portability, right […]
UK GDPR (UK General Data Protection Regulation, Post-Brexit)
Following Brexit, the UK incorporated GDPR into domestic law as the UK GDPR, maintaining largely the same provisions while allowing for future divergence. Effective from January 1, 2021, it works alongside the Data Protection Act 2018 to form the UK’s data protection framework. Key differences include the ICO as the sole supervisory authority, specific provisions […]
NIST AI Risk Management Framework (2024)
The National Institute of Standards and Technology’s AI Risk Management Framework 1.0, released in January 2023 with updates in 2024, provides voluntary guidance for managing AI risks throughout the AI lifecycle. The framework is organized around four core functions: Govern (establishing AI risk management culture and processes), Map (understanding context and identifying risks), Measure (analyzing […]
CPRA (California Privacy Rights Act, 2020)
The California Privacy Rights Act, approved by voters in November 2020 and effective from January 1, 2023, significantly expands and strengthens the CCPA. It creates new consumer rights including the right to correct inaccurate information, right to limit use of sensitive personal information, and extends the “look-back” period for data access requests to 12 months. […]