FNOAIFoundations · Next · Outcomes
GCC AI Obligation RegisterAll jurisdictionsCoverage
Jurisdiction

DIFCAE-DIFC

1 instrument(s) held in this jurisdiction, each cited to its official text. What an instrument says — not whether it reaches you.

Data Protection Regulations (Consolidated Version No. 2)

DIFC Commissioner of Data Protection · binding · in_force · v1 · official text

Regulations made under DIFC Law No. 5 of 2020. Regulation 10 governs personal data processed through autonomous and semi-autonomous systems: it defines System, Deployer, Operator and Provider, imposes notice, evidence and register obligations on deployers and operators, and sets design requirements — ethical, fair, transparent, secure and accountable — for AI systems that process personal data.

  1. 10.1 Autonomous and Semi-Autonomous Systems — definitions — Defines System, Deployer, Operator and Provider. A System is any machine-based system operating autonomously or semi-autonomously that processes personal data for human-defined purposes or purposes it defines itself, and generates output.
  2. 10.2 Obligations of Deployers and Operators of Systems — Deployers and operators must give clear notice of non-human-initiated processing, describe the purposes, limits, outputs and design principles of the system, and produce on request evidence of certification, of the algorithms that trigger human intervention where processing may be unfair or discriminatory, and a register of use cases and third parties.
  3. 10.3 General Requirements for Artificial Intelligence Autonomous and Semi-Autonomous Systems — Systems that may affect a data subject must be designed to be ethical, fair, transparent, secure and accountable. No system may be made available commercially unless it processes personal data only for human-defined or human-approved purposes and complies with those design requirements.

← All jurisdictions