|
All DIFC registered entities must obtain a permit or written authorization from the Commissioner of Data Protection for the transfer of data out of the DIFC. A transfer of personal data to a recipient located in a jurisdiction outside the DIFC may take place only if that jurisdiction is deemed to have an adequate level of protection for that personal data. The DIFC Commissioner of Data Protection applies the same adequacy standards with regards to third countries as set out by Article 29 Working Party of the European Commission on Data Protection.
List of Adequate Data Protection Regimes/Centers
27 EU Countries:
European Economic Area (EEA) Member Countries:
Norway
Liechtenstein
Iceland
Other:
Switzerland
Canada
Argentina
Guernsey
Isle of Man
Jersey
US Dept of Commerce Safe Harbor Policy (including the Safe Harbor list of organizations adhering to Safe Harbor framework)
|