DIFC Data Protection Law, 2020
The Dubai International Financial Centre (DIFC) Data Protection Law No. 5 of 2020 replaced the previous 2007 law, aligning more closely with GDPR standards. It applies to all entities established in the DIFC and those processing personal data of DIFC data subjects. The law introduces enhanced rights for individuals including right to data portability, right […]
GDPR (General Data Protection Regulation, 2016)
The General Data Protection Regulation is the European Union’s comprehensive data protection law that came into force on May 25, 2018. It establishes strict rules for how organizations collect, process, store, and transfer personal data of EU residents. Key provisions include requiring explicit consent for data processing, mandatory data breach notifications within 72 hours, right […]
Information Technology Act, 2000 – Amended 2008)
The IT Act is based on the United Nations Model Law on Electronic Commerce and contains provisions on data protection and privacy, including Section 43A which provides for compensation in case of negligence in protecting sensitive personal data, and Section 72A which provides criminal punishment for unauthorized disclosure of personal information. The Act forms the foundation […]