DIFC implementation differs from generic GDPR work in one structural way: the regulator holds a filed copy of your compliance story. The portal notification states what you process, why, where it goes, and who your DPO is, so every other artifact, notice, RoPA, DSAR responses, transfer file, must reconcile with it or hand an auditor their finding pre-written. Build from the inventory outward and let one source of truth generate every regulator-facing document.
| Step | Deliverable |
|---|---|
| 1. Scope | Entity-regime map (DIFC vs mainland vs ADGM) |
| 2. Inventory | RoPA with bases and transfer lanes |
| 3. File | Portal notification + annual renewal diary |
| 4. DPO | Article 16 analysis, appointment, registration |
| 5. Notices | GDPR-grade, DIFC-specific addressees |
| 6. Rights | 1-month DSAR pipeline |
| 7. Incidents | As-soon-as-practicable Commissioner notice path |
| 8. DPIAs | High-risk triggers wired into product process |
| 9. Transfers | Adequacy check, DIFC/EU SCCs, assessment file |
Executing the build
Generate, don’t duplicate. RoPA as the single source; notification, notice, and transfer file derived from it, so updates propagate instead of drifting. The DIFC DP Law overview covers the legal substance behind each step.
Borrow the GDPR kit. DSAR templates, DPIA forms, and breach runbooks port with addressee changes; calibration guidance sits in the UAE landscape overview.
Watch the regime boundaries. Mainland affiliates are foreign recipients for transfer purposes, and mainland group policies must not dilute the DIFC entity’s standard; see the federal PDPL guide and UAE transfer map for the other side of the line.
Diarize the recurring duties. Annual notification renewal, DPO assessment, and instrument reviews are where steady-state programs quietly lapse.
Notices and consent behavior on your public site are step 5’s visible surface: verify them with a free scan.