DIFC Data Protection Law (DIFC Law No. 5 of 2020): what it means for websites
Businesses established in the Dubai International Financial Centre follow the DIFC's own data protection law, not the UAE federal one. Its Regulation 9 is unusually specific about cookie banners: colour-neutral buttons, an unticked box or another positive action, and no consent from pre-ticked boxes, silence or inactivity. The Commissioner of Data Protection has already applied it to a cookie banner, in a decision notice issued to Careem Group.
Jul 2020
Law in force (Article 4)
USD 100,000
Highest Schedule 2 fine per contravention; Article 62(3) fines are not limited to it
Regulation 9
The cookie rules: colour-neutral buttons, unticked boxes
The short answer
What does the DIFC require of a cookie banner?
Regulation 9 of the DIFC Data Protection Regulations treats cookies used for personalisation, analytics or advertising, and pixel and cross-app tracking, as behavioural advertising. For those, the visitor gets notice and a chance to refuse the first time data is collected, the defaults collect the minimum, the buttons are colour-neutral, and consent, where you rely on it, comes from a clear affirmative act such as ticking an unticked box. Pre-ticked boxes, silence and inactivity are not consent.
The Commissioner has applied this to a real banner. Decision Notice 1/2024, issued to Careem Group under Regulation 9 and listed by the Commissioner under 2024, criticised its cookies banner for lacking colour-neutral buttons. In our reading, a bright Accept button beside a faint Reject link is exactly the pattern Regulation 9.2.3(a) rules out.
Commissioner of Data Protection: supervision, enforcement and decision notices (DIFC)What the law is
The DIFC Data Protection Law is DIFC Law No. 5 of 2020, enacted on 21 May 2020 and in force from 1 July 2020 under its Article 4.
It has been amended by DIFC Law No. 2 of 2022 and by the DIFC Laws Amendment Law No. 1 of 2025 of 8 July 2025. It applies to controllers and processors incorporated in the DIFC, wherever they process personal data, and to anyone who processes personal data in the DIFC as part of stable arrangements (Article 6(3)).
The regulator is the Commissioner of Data Protection. The DIFC Data Protection Regulations add the detail; the consolidated version in force since 1 September 2023 contains Regulation 9 on digital communications and services, which is where the cookie rules sit.
Online identifiers are personal data under the law's definitions (Schedule 1). The law lists six lawful bases for processing, including legitimate interests, which public authorities cannot rely on (Articles 10 and 13(1)).
The UAE federal law, Federal Decree-Law No. 45 of 2021, excludes companies in free zones that have their own data protection legislation (Article 2(2)(g)); it does not name the DIFC.
What the law requires of a website
- 01
Consent by a clear affirmative act, that you can demonstrate
Where you rely on consent, it must be given by a clear affirmative act, and you must be able to demonstrate it (Article 12). Consent is sought separately for each purpose, withdrawing it must be as easy as giving it, it should be re-affirmed periodically, and your methods of recording it must be demonstrable to the Commissioner (Article 12(9)).
- 02
Notice and a chance to refuse, the first time
Regulation 9 defines behavioural advertising to include the use of cookies for personalisation, analytics or advertising profile development, and pixel, in-app and cross-app tracking. You must say so in plain language when you collect the data (Regulation 9.2.1) and give the visitor an opportunity to refuse or opt out the first time you collect it for those purposes (Regulation 9.2.2).
- 03
Colour-neutral buttons and privacy-protective defaults
Privacy preferences must be set by default so that no more than the minimum data is collected (Regulation 9.2.3). The choice must use clear, colour-neutral selection boxes or buttons that neither promote nor discourage any particular setting (Regulation 9.2.3(a)), and an easily accessible means, such as a preferences link or dashboard, must let the visitor change their choice later (Regulation 9.2.3(c)).
- 04
No pre-ticked boxes, silence or inactivity
Consent must come from a clear affirmative act, at least an unticked selection box or another easy method the visitor actively uses (Regulations 9.3.1 and 9.3.2). Pre-ticked selection boxes, silence and inactivity are not acceptable ways of collecting it (Regulation 9.3.3).
- 05
Breach reporting and a DPO where required
Report a personal data breach to the Commissioner as soon as practicable (Article 41(1)); the law sets no hour limit. Tell the people affected as soon as practicable, and promptly where there is an immediate risk to them (Article 42). A data protection officer is mandatory for DIFC Bodies and for controllers or processors carrying out High Risk Processing on a systematic or regular basis (Article 16(2)), and must reside in the UAE unless the role is held within a group (Article 16(7)).
- 06
Rights, direct marketing and transfers
Individuals' rights are set out in Articles 32 to 39, and a request must be answered within one month, extendable by two further months (Article 33). Anyone can object to direct marketing (Article 34). Transfers outside the DIFC are governed by Articles 26 and 27; the adequacy list includes the EU and EEA, the UK, Switzerland, ADGM, the QFC, Japan, Korea, Singapore, Canada, California, Israel and New Zealand, among others.
Penalties
The Commissioner can issue an administrative fine for each contravention listed in Schedule 2, up to the maximum set there (Article 62(2)). Schedule 2's per-article maximums run from USD 25,000 to USD 100,000. The Commissioner may also issue a general fine, in addition, that is not limited to the Schedule 2 amounts (Article 62(3)). Individuals have a private right to seek compensation (Article 64A).
- 01
Consent (Articles 10 and 12)
Up to USD 50,000 per contravention under Schedule 2.
- 02
Notice to individuals (Articles 29 to 31)
Up to USD 75,000 per contravention under Schedule 2.
- 03
Individuals' rights (Articles 33 to 38)
Up to USD 100,000 per contravention, the highest amount in Schedule 2.
- 04
DPO and breach notification (Articles 16, 41 and 42)
Up to USD 50,000 for the DPO duty (Article 16) and up to USD 50,000 for breach notification (Articles 41 and 42).
- 05
Published decisions
The Commissioner publishes decision notices. They include FTI Consulting (1/2022, 26 September 2022), Quilter (2/2022, 12 December 2022, a USD 2,000 fine), Careem Group (1/2024, under Regulation 9, on its cookie banner) and Dalma Capital (1/2025).
What Arqam360 does for a website run from the DIFC
- 01
Consent by category, with Reject all
The banner asks for consent by category, with a Reject all choice, and sends Google Consent Mode v2 signals so Google tags know what the visitor allowed.
- 02
A dated record of each choice
Article 12 asks you to be able to demonstrate consent. Each visitor's choice is stored with its date and the categories accepted or refused.
- 03
Withdraw at any time
Visitors can withdraw their consent at any time. Article 12 requires withdrawing to be as easy as giving consent.
- 04
Arabic and English, and the regime by country
A right-to-left Arabic banner with an English version. Regime detection works by the visitor's country: it recognises visitors in the UAE, but it cannot tell whether a site belongs to a DIFC entity, so choose the banner settings for your own case.
Timeline
Law enacted
DIFC Law No. 5 of 2020 enacted on 21 May 2020.
Law in force
Commencement on 1 July 2020 under Article 4.
Regulations consolidated
Consolidated Data Protection Regulations (version No. 2) in force on 1 September 2023, the version that contains Regulation 9.
Careem decision notice (Regulation 9)
Decision Notice 1/2024, issued to Careem Group under Regulation 9, criticised its cookie banner for lacking colour-neutral buttons.
Law amended
DIFC Laws Amendment Law No. 1 of 2025, of 8 July 2025, after an earlier amendment by DIFC Law No. 2 of 2022.
Check what your site does before consent
The free scanner loads your site in a real browser and lists the cookies and trackers that run before a visitor chooses. Regulation 9 is about what happens at that first moment, so it is the place to start.
Scan your siteDone for you
We set it up on your website
We install the consent banner, wire Google Consent Mode v2, test your Google and Meta tags, and publish your bilingual privacy policy. $299 to install, then $99.99 a month per domain.
Regulations
Compliance guides for GDPR, PDPL, and moreregulations.difcDataProtection.faq.title
regulations.difcDataProtection.faq.subtitle
Federal Decree-Law No. 45 of 2021 excludes companies in free zones that have their own data protection legislation (Article 2(2)(g)). It does not name the DIFC, but the DIFC has its own law, DIFC Law No. 5 of 2020, which applies to controllers and processors incorporated in the DIFC wherever they process data, and to processing in the DIFC as part of stable arrangements (Article 6(3)).
Put an Arabic and English consent banner on your site
The banner takes minutes on WordPress, Shopify or any custom site. The DPO, the breach process and your privacy notice are yours to arrange; the banner is the part your visitors see first. Start free, or let our team install it and test your tags.











