If you’re setting up or operating a business in the Dubai International Financial Centre (DIFC), understanding its compliance requirements is essential.
Businesses in the Dubai International Financial Centre (DIFC) must adhere to an independent common law framework, including mandatory registration with the Registrar of Companies (ROC), data protection compliance, and financial reporting or audit requirements where applicable.
In other words, the DIFC operates under an independent legal and regulatory framework, so businesses need to navigate requirements that can differ from those elsewhere in the UAE.
From company registration and corporate governance to tax, data protection, financial reporting and, where applicable, DFSA regulation, compliance is an ongoing responsibility and should not be treated as a one-time setup task.
This guide breaks down the key DIFC compliance requirements founders and finance teams should understand to keep their businesses properly registered, regulated and in good standing.
Understanding DIFC Compliance Framework
The Dubai International Financial Centre (DIFC) was established under Federal Decree No. 35 of 2004 as a financial Free Zone, allowing it to create its own legal and regulatory framework. This is not to be confused with Federal Decree-Law No. 8 of 2004, which provided the federal framework for financial free zones.
The DIFC regulations operate under an independent jurisdiction within the UAE, operating under its own civil and commercial laws. In general, the framework is built around common-law principles, alongside applicable laws and a dedicated court system.
DIFC entities may qualify as Qualifying Free Zone Persons (QFZPs) for UAE Corporate Tax purposes where 0% rate is applied on qualifying income.
Since the benefit is conditional, businesses need to satisfy QFZP conditions on adequate substance, de minimis threshold, compliance and reporting requirements to maintain their qualifying status.
Federal Decree No. 35 of 2004 and the DIFC Regulatory Framework for DIFC Requirements
The DIFC has three principal independent bodies:
- The DIFC Authority is responsible for the strategic development and operational management of the DIFC, overseeing laws and regulations not related to financial services.
- The DFSA oversees regulation of financial and related services.
- DIFC Courts are part of an independent common-law court system for civil and commercial matters within DIFC.
Today, DIFC businesses are subject to a range of DIFC laws and regulations covering company registration, financial services, data protection, employment and other areas of compliance.
A company may have obligations involving compliance with:
| Federal Law Entity / Requirements | What it covers / governs |
|---|---|
| DIFC Authority / Registrar of Companies (ROC) | Company registration, corporate filings and ongoing entity requirements |
| Dubai Financial Services Authority | Financial-services licensing, supervision and regulatory compliance |
| DIFC Commissioner of Data Protection | Personal data, privacy and breach-management requirements |
| DIFC Courts | Civil and commercial disputes, litigation and arbitration |
| Federal Tax Authority | VAT and Corporate Tax registration, filing and tax compliance |
| United Arab Emirates Anti-Money Laundering and Countering the Financing of Terrorism (UAE AML / CFT) framework | Anti-money laundering controls, customer due diligence and suspicious-activity reporting |
| Common Reporting Standard (CRS) and Foreign Account Tax Compliance Act (FATCA) | International tax transparency and financial-account reporting |
| DIFC Employment Law | Employment contracts, workplace rights and employer obligations |
| Ultimate Beneficial Ownership (UBO) requirements | Beneficial ownership records and corporate transparency |
| Accounting and audit requirements | Financial records according to International Financial Reporting Standards (IFRS) and Statutory audits |
Dubai Financial Services Authority for Financial Services
The Dubai Financial Services Authority (DFSA) is the independent regulator responsible for supervising financial services conducted in or from the DIFC, as established by the Regulatory Law, DIFC Law No. 1 of 2004.
The DFSA’s mandate includes policy making, authorization, recognition, supervision, enforcement and cooperation with international standards.
The DFSA employs a risk-based approach to supervision, which varies depending on the nature, scale, and complexity of each regulated firm.
Regulatory obligations should be proportionate to the risks associated with the business, and a continuous risk management cycle with the DFSA identifies and mitigates unnecessary risk.
Note
A DIFC company is not automatically a DFSA-regulated institution by being located within the free zone.
Only firms with business activities related to Financial Services must obtain DFSA authorization and a specific license. DFSA authorization is separate from ROC incorporation.
Incorporation and Company Registration Requirements under DIFC Law
DIFC provides structure for both financial and non-financial businesses. The legal structure could be any of the following:
- Companies — the standard corporate structure used by many DIFC businesses, with shareholders and directors.
- Branches — an extension of an existing company incorporated outside DIFC, rather than a separate legal entity.
- Partnerships — structures where the business is owned and operated by partners rather than shareholders.
- Foundations — separate legal structures commonly used for wealth, succession, asset-holding and philanthropic purposes.
- Prescribed Companies — SPVs which are generally open to any applicant, subject to the applicable Corporate Services Provider requirements.
- Family offices — company structure used for managing family wealth, investments and related affairs
- Managing Offices — structures used for certain family-office and wealth-management arrangements.
- Holding companies — companies established primarily to hold shares, investments or other assets
Business Registration Process and Documentation
The ROC handles incorporation and registration of entities. DIFC’s current setup process is conducted through a dedicated DIFC Client Portal.
The applicable requirements depend heavily on:
| Business Registration | Details |
|---|---|
| Applicable Requirements | The applicable requirements depend heavily on: ✔️ legal structure; ✔️ business activity; ✔️ whether the activity is regulated by DFSA; ✔️ ownership/control structure; ✔️ whether the company is a Prescribed Company; ✔️ whether it processes personal data; and ✔️ whether it falls within AML/CTF, CRS/FATCA or other regimes |
| For non-financial business | Depending on the entity, documentation can include: ✔️ constitutional documents; ✔️ shareholder/corporate shareholder documents; ✔️ director information and undertakings; ✔️ board resolutions where applicable; ✔️ ownership/UBO information; ✔️ business activity information; ✔️ registered-office information; ✔️ other supporting documents required by the ROC |
| Financial-services business | The process is different: 1. Initial enquiry/engagement with DFSA. 2. Go through the DFSA authorization process. 3. Submission of the regulatory business plan and application documentation 4. DFSA in-principle approval 5. ROC incorporation/registration and operational setup. 6. Fulfillment of applicable conditions 7. DFSA grants the license before the firm begins the regulated activity. |
Corporate Governance and Organizational Structure
DIFC companies are governed principally by the Companies Law (DIFC Law No. 5 of 2018), alongside the Operating Law and applicable entity-specific regulations.
Governance requirements vary according to entity type. Generally, companies need to maintain appropriate corporate records, including information concerning shareholders/members, directors and other required particulars.
Any change to ownership, directors, relevant senior management, or registration particulars (such as corporate structure) require filings or notifications with the ROC through the DIFC Portal. De-registration is also handled through DIFC Client Portal.
The basic process is:
- Log in to the DIFC Portal.
- Search for the relevant corporate action/service.
- Select the appropriate request.
- Complete the required information.
- Upload supporting documents.
- Pay the applicable fee, where required.
- Submit the request for ROC processing.
UBO requirements apply under the DIFC UBO framework.
Financial Services Regulatory Framework under Dubai Law
A DFSA license defines the financial services the authorized firm is allowed to conduct. As mentioned above, the DFSA uses risk-based authorization and supervision, rather than treating every firm identically.
Banking and Investment Services Compliance
Banking, capital-markets, investment and wealth-management activities can fall within DFSA regulation. Depending on the business model, regulated activities can include areas such as:
- advising on financial products;
- arranging deals in investments;
- dealing in investments;
- providing custody;
- providing credit;
- money services;
- fund management and related activities.
Note
Crypto-token activities can also fall within the DFSA framework where they constitute regulated Financial Services; simply using a Crypto Token does not automatically mean a business is providing a Financial Service.
Insurance and Takaful Regulatory Standards
Insurers are subject to prudential requirements, including regulatory capital requirements. Takaful operators and insurers operating takaful windows have additional Islamic-finance requirements and endorsements under the DFSA framework.
DIFC’s insurance ecosystem includes:
- insurance providers and reinsurers;
- captives;
- re/takaful operators;
- brokers;
- managing general agents;
- coverholders;
- third-party administrators;
- insurance managers; and
- representative offices
The DFSA’s insurance framework covers both life and non-life insurance classes, with specific regulatory requirements depending on the activity.
Underwriting is part of the DFSA’s prudential and supervisory framework for insurance firms. DFSA supervision specifically examines governance arrangements for underwriting, alongside claims management, reserving, risk management, reinsurance and retrocession arrangements.
The DFSA can review insurers’ underwriting and claims files as part of on-site risk assessments.
License Renewal and Annual Compliance
A standard, non-regulated DIFC Commercial License is effectively valid for one year and renewed annually. The Commercial License states the issue date and expiry date.
Annual License Renewal Procedures
The annual process can also include:
- License renewal Keep the DIFC business license active by submitting the renewal application and paying the applicable renewal fee to the ROC
- Confirmation statement Confirms that the company’s registered corporate information remains accurate and up to date, including relevant details held by the Registrar of Companies.
- Data-protection notification renewal Where applicable, businesses renew their registration/notification with the DIFC Commissioner of Data Protection and confirm relevant details about their personal-data processing activities.
- Establishment-card renewal Where applicable, renews the company’s establishment card, which is used for certain immigration and employee-related administrative processes in the UAE.
License renewal and confirmation statement service becomes available one month before the license expires. Likewise, the renewal payment must be made no later than 30 days after the license expiry date.
Late renewal can trigger administrative fines
- USD 1,000 for the first month of delayed license renewal;
- an additional USD 1,000 for each subsequent month;
- USD 2,000 for failure to file the confirmation statement;
- USD 1,000 for failure to renew the data-protection notification, where applicable
Ongoing Regulatory Obligations
Registered entities need to maintain their corporate information and make required filings/notifications when the particulars change.
Maintaining a physical registered office within the DIFC is mandatory for companies under the Operating Law. However, DIFC’s current Prescribed Company rules allow certain SPVs to use a co-working desk, a registered office (or shared space) of an eligible affiliate or appointed corporate service provider.
Taxable DIFC entities generally must file Corporate Tax Returns with the FTA, including QFZPs benefiting from the 0% rate on Qualifying Income, subject to applicable exemptions and Tax Group rules.
UAE Economic Substance reporting requirements were cancelled for financial years ending after 31 December 2022. DIFC entities remain responsible for any ESR obligations, information requests or penalties relating to earlier periods.
Data Protection and Privacy Regulations
The DIFC Data Protection Law (Law No. 5 of 2020) establishes a modern privacy framework tailored to the DIFC’s independent legal and regulatory environment, effective since July 1, 2020. The law is supported by Data Protection Regulations 2020.
It applies to both regulated and non-regulated organizations that fall within its scope and process personal data in the relevant circumstance
DIFC businesses should:
- Have a lawful basis for processing personal data
- Provide appropriate privacy information, limit data collection and retention
- Protect personal information and maintain procedures for handling individual requests and data breaches.
Businesses transferring personal data internationally or carrying out higher-risk processing may also have additional obligations, including requirements relating to data transfers and Data Protection Officers.
Note
Amendments effective 15 July 2025 introduced an individual’s right of action through the DIFC Courts if their personal data has been processed in breach of the law.
The individual can file claims directly without first filing regulatory complaints.
DIFC Data Protection Law Implementation
Organizations processing personal data in the DIFC are treated as data controllers or processors under the DIFC Data Protection Law.
DIFC entities processing Personal Data are required to submit a data-protection notification to the Commissioner, subject to the applicable rules.
For new entities, you can submit the notification as part of the registration/incorporation service request.
The DIFC Commissioner provides tools covering:
- records of processing;
- data protection impact assessments;
- DPO assessments;
- controller/processor arrangements;
- international data transfers;
- individual rights;
- breach reporting
High-risk processing can trigger additional requirements, including DPO-related obligations. International transfers require attention to the DIFC’s transfer rules and safeguards.
Founders should put practical safeguards around personal data, including role-based access controls, strong authentication and encryption, secure backups, employee training, vendor controls and an incident-response process.
Access rights should be reviewed regularly, while personal data should be securely deleted when it is no longer required.
Data Security and Breach Notification
Non-compliance with the DIFC Data Protection Law can result in administrative fines, with the maximum amount depending on the type of contravention.
Certain violations can attract fines of up to USD 100,000, while failure to report a personal-data breach can carry a maximum fine of USD 50,000.
The Commissioner may also conduct inspections and take enforcement action where organisations fail to meet their data protection obligations.
Employment Law and Labor Compliance
The DIFC has its own Employment Law, DIFC Law No. 2 of 2019, with Employment Regulations 2022 and subsequent amendments.
Employment Contracts and Compliance Standards
DIFC employers have specific requirements for documenting and administering employment relationships, including applicable workplace savings obligations (i.e. mandatory DIFC Employee Workplace Savings Plan or DEWS).
Employees must receive a written employment contract in English within seven days of starting work, covering key terms such as remuneration, working hours, leave, notice periods and job responsibilities.
Employers must also provide itemized pay statements and properly document material changes to employment contracts.
Employee Rights and Dispute Resolution
Employment disputes can fall within the jurisdiction of the DIFC Courts. The DIFC Courts expressly deal with civil, commercial and employment disputes connected with DIFC.
Parties may also agree contractually to alternative dispute-resolution mechanisms, including arbitration, subject to the applicable DIFC Arbitration Law and agreement terms.
Anti-Money Laundering and Financial Crime Prevention (Cabinet Resolution No. 134 of 2025)
DIFC businesses need to understand their obligations under the UAE’s anti-money laundering and counter terrorist financing (AML/CFT) framework.
DFSA-regulated firms have additional requirements, while the DIFC Registrar of Companies also applies AML/CFT measures to non-financial businesses during registration and ongoing oversight.
For founders, the practical focus is on knowing who owns and controls the business, understanding customer and business risks, maintaining appropriate controls, and identifying transactions or activities that may indicate money laundering or terrorist financing.
AML/CFT Compliance Program Requirements
Businesses that fall within the applicable AML/CFT regime need procedures that are proportionate to their risks.
Depending on the entity, this can include:
- documented AML/CFT policies
- risk assessments
- customer due diligence
- transaction monitoring
- sanctions screening
- staff training, and
- processes for identifying and escalating suspicious activity.
For applicable non-financial businesses, the DIFC AML/CFT framework also provides for the appointment of a Money Laundering Reporting Officer (MLRO) at management level. The Money Laundering Reporting Officer (MLRO) supervises the compliance process,and reports suspicious activities.
Businesses must also maintain accurate Ultimate Beneficial Ownership (UBO) information. DIFC uses UBO requirements as part of its broader framework for ownership transparency and financial-crime prevention
For DFSA-supervised Relevant Persons, there is an additional annual reporting obligation: the DFSA Annual AML Return must be submitted by the end of September each year and covers the period from 1 August of the previous year to 31 July of the reporting year.
Customer Due Diligence and Verification
Where AML/CFT rules apply, businesses need to implement Know Your Customer (KYC) and Know Your Business (KYB) protocols.
Know Your Customer (KYC) and Know Your Business (KYB) are useful ways to understand their customers and the risks associated with their relationships.
This can include:
- Verifying the identity of customers and relevant counterparties
- Understanding the nature and purpose of the business relationship
- Identifying the Ultimate Beneficial Owner behind a company or arrangement
- Assessing whether customers, transactions or jurisdictions present higher financial-crime risks
- Applying enhanced due diligence where the risk warrants it
- Keeping appropriate records to demonstrate how customer risks were assessed and managed
Suspicious Activity Reporting Obligations
Businesses subject to the reporting requirements must have a process for identifying and escalating suspected money laundering, terrorist financing or other suspicious activity.
Where a report is required, Suspicious Transaction Reports (STRs) and Suspicious Activity Reports (SARs) are filed with the UAE Financial Intelligence Unit through the goAML system. The UAE FIU’s system is used by reporting entities to submit these reports, including entities supervised by the DFSA and other relevant authorities.
Skrooge Tip
Don’t treat suspicious-activity reporting as an ad hoc decision. To simplify, the business should have clear internal escalation procedures, appropriate record-keeping and a designated person responsible for handling AML/CFT reporting where required.
DIFC Courts and Legal Proceedings
The DIFC Courts provide an independent common-law judicial system. The courts deal with civil and commercial disputes, including employment disputes that fall within their jurisdiction. The DIFC Courts do not deal with criminal matters.
The DIFC Courts have jurisdiction over matters falling within their statutory or contractual jurisdiction, including certain disputes involving DIFC entities and disputes where the parties have validly agreed to DIFC Courts jurisdiction.
DIFC Court Jurisdiction and Civil Procedures
Court procedures operate in English and documents are submitted in the English language.
For founders, the most important step happens before a dispute arises: make sure contracts clearly state the governing law, jurisdiction and, where appropriate, arbitration arrangements.
Arbitration and Alternative Dispute Methods
If a dispute does reach the DIFC Courts:
- Check the contract first. Look at the governing-law and jurisdiction clauses before deciding where to bring a claim. DIFC Court claim forms require the claimant to state the law they say governs the dispute and the basis on which the DIFC Courts have jurisdiction.
- Choose the appropriate procedure. Proceedings generally start with a Part 7 or Part 8 claim form. Part 7 is the standard procedure, while Part 8 is an alternative procedure used where the Rules or circumstances make it appropriate.
- Prepare the claim carefully. A claim form needs to identify the parties, briefly explain the nature of the claim and state the remedy being sought. If detailed particulars are not filed with the claim, they may need to be served separately after the defendant acknowledges service and indicates an intention to defend.
- Watch service deadlines. Once issued, a claim form generally must be served within four months if service is within the DIFC or Dubai, or six months if it must be served outside the DIFC or Dubai.
- Keep your evidence organized. Contracts, invoices, emails, payment records, board approvals and other documents can become important evidence. Build a clear record as the commercial relationship develops rather than trying to reconstruct it after a dispute.
- Don’t ignore court deadlines. DIFC Court rules contain specific filing deadlines, and late filings can attract fees. The Court’s current fee framework also makes clear that additional hearings and filings can generate additional costs.
- Budget for litigation. Court proceedings can be expensive. For example, a Part 7 monetary claim of up to USD 500,000 currently carries a filing fee of 5% of the claim value, subject to a USD 5,000 minimum, with higher-value claims subject to a graduated fee structure.
- Consider settlement or mediation early. DIFC Courts have a Mediation Service Centre, and mediation can provide a way to resolve a commercial dispute without taking the matter through a full trial.
- Get legal advice when jurisdiction is unclear. A company being registered in DIFC does not, by itself, mean that every dispute involving it automatically belongs in the DIFC Courts. The contractual terms, parties, subject matter and applicable jurisdictional rules matter.
Financial Reporting and Accounting Standards
IFRS and Accounting Standards Compliance
DIFC companies must maintain accounting records and prepare accounts in accordance with the applicable DIFC requirements, generally using IFRS.
There are limited mechanisms for alternative accounting standards/deviations where the applicable regulatory requirements and Registrar consent permit them.
This means founders should maintain accounting records capable of supporting:
- financial statements;
- statutory filings;
- tax reporting;
- audit requirements where applicable;
- regulatory reporting where applicable.
DFSA-regulated firms may face additional financial reporting requirements under the DFSA Rulebook, beyond ordinary company-law requirements.
Audit Requirements and External Audit Standards
The current DIFC ROC corporate-actions handbook states that audited accounts are required for:
- Private Companies that do not qualify for the small private company exemption;
- NPIOs;
- certain Foundations; and
- certain LLPs authorized by DFSA or registered as DNFBPs.
For a private company, the handbook identifies the threshold for the small-private-company exemption as:
- no more than 20 shareholders, and
- annual turnover not exceeding USD 5 million, calculated on a consolidated basis including subsidiaries.
Public Companies have separate audit/annual-directors-report requirements.
Auditors must comply with relevant standards issued by the International Auditing and Assurance Standards Board (IAASB).
A DIFC entity that is required to have its accounts audited must appoint an auditor registered with the Registrar of Companies (ROC). DIFC maintains a public list of registered and recognized auditors, so businesses can verify whether an audit firm is eligible before appointing it.
Note
When appointing an auditor, the company must file the appointment with the ROC. The DIFC corporate-actions handbook requires:
- a board resolution confirming the appointment; and
- an acceptance letter from the appointed auditor
The appointment or removal of an auditor must generally be filed within 30 days of the change.
International Tax and Withholding Compliance
DIFC Tax Incentives and Benefits Structure
DIFC entities may qualify for the UAE’s Qualifying Free Zone Person (QFZP) regime, under which qualifying income can be subject to 0% Corporate Tax if the applicable conditions are met.
A Taxable Person must generally submit its Corporate Tax Return and pay any Corporate Tax due within nine months of the end of the relevant Tax Period. This applies even where the company has no tax liabilities because of its tax position.
FATCA and CRS International Reporting
Certain DIFC businesses, particularly financial institutions, may also have international reporting obligations under the Common Reporting Standard (CRS) and Foreign Account Tax Compliance Act (FATCA), depending on their status and activities.
These frameworks support the automatic exchange of financial account information between participating jurisdictions, so affected businesses need appropriate reporting processes and records to maintain compliance.
DIFC has its own CRS framework under DIFC Law No. 2 of 2018, while FATCA applies to relevant US-linked reporting obligations. For entities subject to DIFC reporting, the current filing deadline is 30 June.
Regulatory Examination and Supervision
DFSA Regulatory Examination Procedures
For businesses subject to DFSA regulation, regulatory supervision does not end once a license is granted.
The DFSA may request information, review compliance arrangements, conduct risk assessments, and carry out inspections or compliance reviews to assess whether a firm is meeting its regulatory obligations.
Depending on the firm’s activities and risk profile, this can include reviewing governance, internal controls, reporting processes and audit procedures.
For founders, the practical takeaway is simple: DFSA compliance needs to be maintained throughout the life of the business, not just during DIFC company registration or the initial licensing process.
Enforcement Actions and Remediation
The DFSA can impose financial penalties on firms or individuals that breach legislation it administers. The amount is determined based on the circumstances of the breach rather than one universal tariff.
Other enforcement measures can include:
- Public censure
- Orders requiring restitution or compensation
- Orders requiring a person to account for profits or unjust enrichment
- Cease-and-desist directions
- Directions requiring the firm to remedy the breach
- Restrictions or prohibitions on an individual holding office or working for a regulated entity
The DFSA may also require a firm to remediate weaknesses in its systems and controls and demonstrate that the remediation has been completed and is effective.
Enforcement outcomes are generally publicised, meaning regulatory action can create reputational consequences in addition to financial penalties.
Internal Governance and Compliance Management
Compliance should be treated as an ongoing operating function rather than a one-time registration exercise.
The applicable governance framework depends on the entity’s:
- legal structure;
- activities;
- regulatory status;
- size;
- risk profile;
- ownership structure.
DIFC’s various regimes require businesses to maintain appropriate records, controls, notifications and reporting processes. Effective compliance programs should translate from paper to practice, ensuring they are integrated into the organization rather than just a checklist.
Compliance Officer and Internal Controls
DIFC businesses should assign clear responsibility for compliance and put practical controls behind their policies.
- For DFSA-regulated firms, compliance arrangements should be proportionate to the firm’s risk profile.
- Non-financial businesses may need to appoint a Money Laundering Reporting Officer (MLRO) under the AML/CFT framework.
- Data protection requirements may also require a Data Protection Officer (DPO) depending on the nature and risk of the organization’s data processing.
The key for founders is to ensure compliance policies are actually implemented through documented procedures, monitoring and clearly assigned responsibilities.
Regulatory Reporting and Periodic Filings
Organizations must conduct effective gap analyses and develop robust risk review and mitigation plans to enhance their compliance efforts.
Founders should keep a compliance calendar covering, where applicable:
- DIFC license renewal;
- confirmation statement;
- data-protection notification/renewal;
- Corporate Tax return;
- audited accounts/account filings;
- DFSA regulatory returns;
- annual AML Return;
- CRS/FATCA reporting;
- UBO updates;
- employment-related records;
- regulatory notifications triggered by ownership, directors or other corporate changes
Frequently Asked Questions (FAQs) on Dubai International Financial Centre (DIFC) Compliance
DIFC is a UAE financial free zone with its own civil and commercial legal and regulatory framework.
Businesses registered in DIFC are subject to applicable DIFC laws and regulations.
Financial-services firms additionally require DFSA authorisation and ongoing regulatory compliance.
Registration is handled through the DIFC/ROC framework and Client Portal.
Requirements vary according to legal structure and business activity.
Financial-services businesses must additionally go through DFSA authorization.
DIFC entities generally have annual license-renewal requirements.
The current ROC process combines license renewal with the confirmation statement and, where applicable, data-protection notification renewal
DIFC Authority: strategic and operational management and non-financial regulatory framework
ROC: incorporation, registration and various corporate/compliance filings
DFSA: financial-services regulation
DIFC Commissioner of Data Protection: data-protection supervision/enforcement
DIFC Courts: civil and commercial dispute resolution
Digital-asset businesses can have overlapping obligations under the DIFC Data Protection Law and, where their activities constitute regulated Financial Services, the DFSA’s regulatory framework.
Data protection requirements focus on lawful processing, security, accountability, data-subject rights, retention and international transfers.
The 2025 amendments also introduced a private right of action for data subjects through the DIFC Courts.
DIFC is also developing its privacy framework around AI and data-driven systems; amendments to the Data Protection Regulations were under consultation in June 2026
Requirements depend on whether the company is a Relevant Person/DNFBP or otherwise falls within an applicable AML regime.
Applicable entities may need:
✔️ risk assessments;
✔️ AML/CFT policies and controls;
✔️ customer due diligence and KYC processes;
✔️ UBO identification;
✔️ MLRO appointment;
✔️ suspicious-activity reporting (SARs);
✔️ ongoing monitoring and training;
✔️ annual AML reporting where DFSA-supervised
DIFC Courts operate as an independent English-language common-law court system.
They hear civil and commercial matters, including qualifying employment disputes.
Parties can also agree to DIFC Courts jurisdiction contractually.
DIFC companies generally need to prepare their financial statements in accordance with International Financial Reporting Standards (IFRS).
Audit requirements depend on the company’s legal structure and whether a statutory exemption applies.
For private companies, the small private company exemption may be relevant where the company meets the applicable USD 5 million turnover and 20-shareholder thresholds.
Businesses should therefore confirm whether they qualify for an exemption rather than assuming that every DIFC company has the same audit obligation.




