Notice on first use
Clear and explicit notice when a user first uses or accesses the system, flagging processing that is not human-initiated, controlled or directed, and its effect on the user’s rights.

Regulation · DIFC
Regulation 10 of the DIFC Data Protection Regulations governs personal data processed through autonomous and semi-autonomous systems. It was enacted in September 2023 and revised in August 2024, and it binds across sectors rather than inside one.
Organisations in the Dubai International Financial Centre that deploy or operate AI systems processing personal data. The regulation defines three roles: the deployer, who has authority over or benefits from the system and acts much like a controller; the operator, who runs the system on the deployer’s behalf, much like a processor; and the provider, who develops or procures systems for commercial use.
Clear and explicit notice when a user first uses or accesses the system, flagging processing that is not human-initiated, controlled or directed, and its effect on the user’s rights.
Registers of use cases and of compliance with applicable audit and certification requirements.
Commercial systems engaged in high-risk processing are expected to need certification under a scheme established by the Commissioner. Accreditation of certifiers runs for five years; system certification for up to three.
Where high-risk systems are not restricted to human-defined purposes, an Autonomous Systems Officer is appointed, performing a role similar to a data protection officer.
The Commissioner links Regulation 10 to the rules on unfair or deceptive practices, so misleading notices, false certification claims or misstatements about processing can be enforced against. The FAQs say violations are determined case by case.
We never assess work we have advised on, and we never sell the fix for anything we assess. Where a framework requires a licensed or accredited assessor, we say so and tell you who can sign it.
No. It covers autonomous and semi-autonomous systems that process personal data, including machine learning and natural language processing. Purely automated systems whose operation is deterministically controlled by humans are excluded.
Clear and explicit notice on first use or access, including any processing that is not human-initiated, controlled or directed, and how that affects their rights to rectification, erasure or objection.
The Commissioner’s FAQs say existing certifications under the EU AI Act can fast-track approval through a short-form application.
Checked 30 September 2026. Nothing on this page is legal advice; the regulation as published by the DIFC is the authority.
Tell us which AI systems your DIFC entity uses, who built them and whether any make decisions about people.