Who it applies to
The regulation distinguishes deployers operating systems for their own benefit from operators acting on a deployer’s instructions. Both roles carry responsibilities when personal data is processed in the DIFC.
What the system must support
The operating model must address fairness, transparency, security and accountability. Human intervention must be available where processing may lead to unfair or unjust outcomes.
Organisations also need a register of relevant use cases and an explanation of processing that can be understood outside the technical team.
From policy to operation
A written policy does not by itself show how a specific output was handled. The control path must capture the applicable rule, intervention and outcome when the system acts.
DIFC Data Protection Regulations · Regulation 10