TwinEthos homeRequest access

Catalog

DIFC Data Protection Regulations, Regulation 10 (AI systems)

DIFC Commissioner of Data Protection (under the DIFC Data Protection Law, DIFC Law No. 5 of 2020) · pack 0.2.0 · verified against the official source as of 2026-10-03. Open it in the explorer.

Binding law — in force

Apps using autonomous or semi-autonomous systems on personal data must give a clear notice on first use describing the system (DIFC Reg. 10.2.2(a)-(b))

In the DIFC, where an application or website service employing Systems (machine-based systems operating autonomously or semi-autonomously that process personal data and generate output, Reg. 10.1.1(a)) is used, the Deployer or Operator must give a clear and explicit notice on the initial use of, or access to, the System, alerting users to the underlying technology and processes that may process personal data without being human-initiated, controlled or directed, and indicating the impact on individual rights (Reg. 10.2.2(a)). The notice must describe the human-defined purposes, the principles and limits within which the System may define further purposes, its outputs and how they are used, its design principles and safeguards, and the codes, certifications or principles it follows (Reg. 10.2.2(b)). Detect an app or route that returns AI output with no AI notice, and a repository with no notice copy covering those elements.

difc-dp-reg10.ai-system-notice-on-first-use · Regulation 10.2.2(a) (notice upon initial use or access) · official source · jurisdictions: AE-DU-DIFC

The guard to add, and how far to trust this rule