Skip to content
Regulation referenceDIFC Law 5/2020

DIFC Data Protection Law (DIFC Law No. 5 of 2020): what it means for websites

Businesses established in the Dubai International Financial Centre follow the DIFC's own data protection law, not the UAE federal one. Its Regulation 9 is unusually specific about cookie banners: colour-neutral buttons, an unticked box or another positive action, and no consent from pre-ticked boxes, silence or inactivity. The Commissioner of Data Protection has already applied it to a cookie banner, in a decision notice issued to Careem Group.

Jul 2020

Law in force (Article 4)

USD 100,000

Highest Schedule 2 fine per contravention; Article 62(3) fines are not limited to it

Regulation 9

The cookie rules: colour-neutral buttons, unticked boxes

The short answer

What does the DIFC require of a cookie banner?

Regulation 9 of the DIFC Data Protection Regulations treats cookies used for personalisation, analytics or advertising, and pixel and cross-app tracking, as behavioural advertising. For those, the visitor gets notice and a chance to refuse the first time data is collected, the defaults collect the minimum, the buttons are colour-neutral, and consent, where you rely on it, comes from a clear affirmative act such as ticking an unticked box. Pre-ticked boxes, silence and inactivity are not consent.

The Commissioner has applied this to a real banner. Decision Notice 1/2024, issued to Careem Group under Regulation 9 and listed by the Commissioner under 2024, criticised its cookies banner for lacking colour-neutral buttons. In our reading, a bright Accept button beside a faint Reject link is exactly the pattern Regulation 9.2.3(a) rules out.

Commissioner of Data Protection: supervision, enforcement and decision notices (DIFC)

What the law is

The DIFC Data Protection Law is DIFC Law No. 5 of 2020, enacted on 21 May 2020 and in force from 1 July 2020 under its Article 4.

It has been amended by DIFC Law No. 2 of 2022 and by the DIFC Laws Amendment Law No. 1 of 2025 of 8 July 2025. It applies to controllers and processors incorporated in the DIFC, wherever they process personal data, and to anyone who processes personal data in the DIFC as part of stable arrangements (Article 6(3)).

The regulator is the Commissioner of Data Protection. The DIFC Data Protection Regulations add the detail; the consolidated version in force since 1 September 2023 contains Regulation 9 on digital communications and services, which is where the cookie rules sit.

Online identifiers are personal data under the law's definitions (Schedule 1). The law lists six lawful bases for processing, including legitimate interests, which public authorities cannot rely on (Articles 10 and 13(1)).

The UAE federal law, Federal Decree-Law No. 45 of 2021, excludes companies in free zones that have their own data protection legislation (Article 2(2)(g)); it does not name the DIFC.

What the law requires of a website

  1. 01

    Consent by a clear affirmative act, that you can demonstrate

    Where you rely on consent, it must be given by a clear affirmative act, and you must be able to demonstrate it (Article 12). Consent is sought separately for each purpose, withdrawing it must be as easy as giving it, it should be re-affirmed periodically, and your methods of recording it must be demonstrable to the Commissioner (Article 12(9)).

  2. 02

    Notice and a chance to refuse, the first time

    Regulation 9 defines behavioural advertising to include the use of cookies for personalisation, analytics or advertising profile development, and pixel, in-app and cross-app tracking. You must say so in plain language when you collect the data (Regulation 9.2.1) and give the visitor an opportunity to refuse or opt out the first time you collect it for those purposes (Regulation 9.2.2).

  3. 03

    Colour-neutral buttons and privacy-protective defaults

    Privacy preferences must be set by default so that no more than the minimum data is collected (Regulation 9.2.3). The choice must use clear, colour-neutral selection boxes or buttons that neither promote nor discourage any particular setting (Regulation 9.2.3(a)), and an easily accessible means, such as a preferences link or dashboard, must let the visitor change their choice later (Regulation 9.2.3(c)).

  4. 04

    No pre-ticked boxes, silence or inactivity

    Consent must come from a clear affirmative act, at least an unticked selection box or another easy method the visitor actively uses (Regulations 9.3.1 and 9.3.2). Pre-ticked selection boxes, silence and inactivity are not acceptable ways of collecting it (Regulation 9.3.3).

  5. 05

    Breach reporting and a DPO where required

    Report a personal data breach to the Commissioner as soon as practicable (Article 41(1)); the law sets no hour limit. Tell the people affected as soon as practicable, and promptly where there is an immediate risk to them (Article 42). A data protection officer is mandatory for DIFC Bodies and for controllers or processors carrying out High Risk Processing on a systematic or regular basis (Article 16(2)), and must reside in the UAE unless the role is held within a group (Article 16(7)).

  6. 06

    Rights, direct marketing and transfers

    Individuals' rights are set out in Articles 32 to 39, and a request must be answered within one month, extendable by two further months (Article 33). Anyone can object to direct marketing (Article 34). Transfers outside the DIFC are governed by Articles 26 and 27; the adequacy list includes the EU and EEA, the UK, Switzerland, ADGM, the QFC, Japan, Korea, Singapore, Canada, California, Israel and New Zealand, among others.

Penalties

The Commissioner can issue an administrative fine for each contravention listed in Schedule 2, up to the maximum set there (Article 62(2)). Schedule 2's per-article maximums run from USD 25,000 to USD 100,000. The Commissioner may also issue a general fine, in addition, that is not limited to the Schedule 2 amounts (Article 62(3)). Individuals have a private right to seek compensation (Article 64A).

  1. 01

    Consent (Articles 10 and 12)

    Up to USD 50,000 per contravention under Schedule 2.

  2. 02

    Notice to individuals (Articles 29 to 31)

    Up to USD 75,000 per contravention under Schedule 2.

  3. 03

    Individuals' rights (Articles 33 to 38)

    Up to USD 100,000 per contravention, the highest amount in Schedule 2.

  4. 04

    DPO and breach notification (Articles 16, 41 and 42)

    Up to USD 50,000 for the DPO duty (Article 16) and up to USD 50,000 for breach notification (Articles 41 and 42).

  5. 05

    Published decisions

    The Commissioner publishes decision notices. They include FTI Consulting (1/2022, 26 September 2022), Quilter (2/2022, 12 December 2022, a USD 2,000 fine), Careem Group (1/2024, under Regulation 9, on its cookie banner) and Dalma Capital (1/2025).

What Arqam360 does for a website run from the DIFC

  1. 01

    Consent by category, with Reject all

    The banner asks for consent by category, with a Reject all choice, and sends Google Consent Mode v2 signals so Google tags know what the visitor allowed.

  2. 02

    A dated record of each choice

    Article 12 asks you to be able to demonstrate consent. Each visitor's choice is stored with its date and the categories accepted or refused.

  3. 03

    Withdraw at any time

    Visitors can withdraw their consent at any time. Article 12 requires withdrawing to be as easy as giving consent.

  4. 04

    Arabic and English, and the regime by country

    A right-to-left Arabic banner with an English version. Regime detection works by the visitor's country: it recognises visitors in the UAE, but it cannot tell whether a site belongs to a DIFC entity, so choose the banner settings for your own case.

Timeline

May 2020

Law enacted

DIFC Law No. 5 of 2020 enacted on 21 May 2020.

Jul 2020

Law in force

Commencement on 1 July 2020 under Article 4.

Sep 2023

Regulations consolidated

Consolidated Data Protection Regulations (version No. 2) in force on 1 September 2023, the version that contains Regulation 9.

2024

Careem decision notice (Regulation 9)

Decision Notice 1/2024, issued to Careem Group under Regulation 9, criticised its cookie banner for lacking colour-neutral buttons.

Jul 2025

Law amended

DIFC Laws Amendment Law No. 1 of 2025, of 8 July 2025, after an earlier amendment by DIFC Law No. 2 of 2022.

Check what your site does before consent

The free scanner loads your site in a real browser and lists the cookies and trackers that run before a visitor chooses. Regulation 9 is about what happens at that first moment, so it is the place to start.

Scan your site

Done for you

We set it up on your website

We install the consent banner, wire Google Consent Mode v2, test your Google and Meta tags, and publish your bilingual privacy policy. $299 to install, then $99.99 a month per domain.

regulations.difcDataProtection.faq.badge

regulations.difcDataProtection.faq.title

regulations.difcDataProtection.faq.subtitle

Federal Decree-Law No. 45 of 2021 excludes companies in free zones that have their own data protection legislation (Article 2(2)(g)). It does not name the DIFC, but the DIFC has its own law, DIFC Law No. 5 of 2020, which applies to controllers and processors incorporated in the DIFC wherever they process data, and to processing in the DIFC as part of stable arrangements (Article 6(3)).

Put an Arabic and English consent banner on your site

The banner takes minutes on WordPress, Shopify or any custom site. The DPO, the breach process and your privacy notice are yours to arrange; the banner is the part your visitors see first. Start free, or let our team install it and test your tags.