DFSA Regulations – Data Protection – DIFC

What you’ll learn:
The course provides a comprehensive understanding of the data protection regulations within the Dubai International Financial Centre (DIFC).
Participants will explore the key provisions, principles, and enforcement mechanisms outlined in the DIFC Data Protection Law, gaining insights into compliance requirements, rights and responsibilities of data controllers and processors, and the role of the Data Protection Commissioner. This course is essential for individuals and organizations operating within the DIFC who handle personal data and seek to ensure compliance with data protection regulations.
Training Fee
-
Live Sessions
-
Printed Study Materials
-
Coffee, Snacks & Lunch
-
Certificate of Attendance
DFSA rules and regulations apply to all firms regulated by the DFSA. These rules and guidelines are intended to safeguard customers when they transact with an authorized firm and purchase a financial good or service, to stop the potential threats to financial stability from materializing and hurting the real economy, and to protect the integrity of the financial markets.
Prudential and conduct of business and data protection legislations are all part of the DFSA regulations.
To fulfill their Continuing Professional Development (CPD) obligations, the DFSA mandates that all Senior Executive Officers, Compliance Officers, and MLROs of Authorized Firms complete a least 15 hours of obligatory training every 12 months.
The purpose of this 5 CPD hours course is to provide an understanding about all the regulatory subjects imposed by the DFSA, and it was specifically developed for Authorized Individuals of DFSA-regulated enterprises.
By the end of the programme, participants will fully understand:
• Legal Framework: Provide participants with an in-depth understanding of the legal framework surrounding DFSA Data Protection – DIFC Rules, including its title, legislative authority, date of enactment, and commencement.
• Scope and Purpose: Explain the scope and purpose of the law, highlighting its application and the role of schedules within the regulations.
• Compliance Requirements: Educate participants about the general requirements for legitimate and lawful processing, emphasizing the lawfulness of processing, consent, and the conditions and accountability associated with consent and legitimate interests.
• Data Protection Officer (DPO): Explore the role of the Data Protection Officer (DPO), including their competencies, status, and responsibilities in ensuring compliance with data protection regulations.
• Data Protection Impact Assessment: Teach participants about the importance and process of conducting Data Protection Impact Assessments and when prior consultation is required.
• Joint Controllers and Processors: Clarify the roles and responsibilities of controllers, processors, and sub-processors, while emphasizing confidentiality in data processing.
• Enforcement and Sanctions: Examine the enforcement mechanisms, including personal data breach notifications, the role and powers of the Commissioner, remedies, liabilities, and sanctions for non-compliance, such as fines, complaints, and court applications.
• Regulatory Oversight: Explain the regulatory oversight of the Commissioner, including their appointment, removal, and powers, as well as the role of advisory committees, codes of conduct, certification schemes, and monitoring of compliance.
• Practical Application: Facilitate practical application exercises and case studies to help participants apply the knowledge gained throughout the course.
• Ethical Considerations: Discuss the ethical considerations related to data protection and privacy within the context of DFSA regulations.
Data Protection – DIFC
Introduction and Scope Enforcement
• Title and Repeal
• Legislative Authority
• Date of Enactment
• Commencement
• Purpose of the Law
• Application of The Law
• Schedules
• Administration of The Law
General Requirements
• Requirements for Legitimate and Lawful Processing
• Lawfulness of Processing
• Processing of Special Categories of Personal Data
• Consent
• Conditions of consent and reliance on legitimate interests
• Legitimate interests
• Accountability and notification
• Records of Processing activities
• Designation of the Data Protection Officer (DPO)
• The DPO: Competencies and Status
• Role and Tasks of the DPO
• DPO Controller Assessment
• Data Protection Impact Assessment
• Prior Consultation
• Cessation of Processing
Joint Controllers and Processors
• Controllers
• Processors
• Processors and Sub-Processors
• Confidentiality
Data Export and Sharing
• Transfers Out of the DIFC: Adequate Level of Protection
• Transfers out of the DIFC in the Absence of an Adequate Level of Protection
• Data Sharing
Information Provision
• Providing Information where Personal Data Has Been Obtained from the Data Subject
• Providing Information Where Personal Data Has Not Been Obtained From the Data Subject
• Nature of Processing Information
Rights of Data Subjects
• Right to Withdraw Consent
• Rights to Access, Rectification and Erasure of Personal Data
• Right to Object to Processing
• Right to Restriction of Processing
• Controller’s Obligation to Notify
• Right to Data Portability
• Automated Individual Decision-Making, Including Profiling
• Non-Discrimination
• Methods of Exercising Data Subject Rights
Personal Data Breaches
• Notification of Personal Data Breaches to the Commissioner
• Notification of Personal Data Breaches to a Data Subject
The Commissioner
• Appointment of the Commissioner
• Removal of the Commissioner
• Resignation of the Commissioner
• Powers, Functions and Objectives of the Commissioner
• Delegation of Powers and Establishment of Advisory Committee
• Codes of Conduct
• Monitoring of Approved Codes of Conduct
• Certification Schemes
• Certification and Accreditation
• Production of Information
• Regulations
• Funding
• Annual Budget of the Commissioner
• Accounts
• Audit of Commissioner
• Annual Report
Remedies, Liability, and Sanctions
• Directions
• Lodging Complaints and mediation
• General Contravention
• Imposition of Fines
• Application to the Court
• Compensation
General Exemptions
Conclusions and Closures
The programme is designed to provide participants with a better understanding of the various DFSA rules and regulations. The use of interactive case studies will help participants to think critically about scenarios that will be relevant to their respective roles and organisations.
By the end of the course, participants will have developed the confidence to comprehend what are the rules and regulations applicable to them in their day to day transacting.
The course is addressed to:
This course is beneficial to all Senior Executive Officers, Compliance Officers and MLROs of DFSA Regulated Firms.
Nadine Ghosn Eid is the Founder of BeyondComply, a compliance consultancy and training firm established to help financial services companies understand and overcome the challenges arising from compliance, regulation, and market developments.
Nadine is a Member of the Advisory Council of AGRC (Association of Governance, Risk, and Compliance).
She is also a Certified Anti-Money Laundering Specialist (CAMS) based in Beirut who’s been a Speaker in various Global Compliance and Financial Crime Prevention Conferences, and has more than 28 years of Banking Experience with a focus on Compliance, Treasury, Capital Markets and Private Banking, in addition to 18 years of concentration in the Cards and Payments Industry.
Nadine serves as a Professional Consultant in Anti-Money Laundering, Governance Risk & Compliance, Regulatory Compliance, Data Protection, Virtual Assets Regulation, and Cards Industry Rules and Regulations.
She is also certified as a Trainer by the European Institute of Management and Finance (EIMF), an EU GDPR Foundation and Practitioner by The Knowledge Academy UK, and in Financial Derivatives, Securities, and FSA Regulations by the UK’s Chartered Institute for Securities & Investments (CISI).
Nadine currently holds also the position of Director of Compliance & Regulatory Affairs at areeba, a Leading Regional Financial Technology company specialized in the payment cards and electronic services and in offering issuing and acquiring services to banks, other financial institutions, merchants and retailers.
Prior to areeba, Nadine worked for 14 years with CSCBank sal, a regional leader in the card and electronic payment processing industry, of which the last three years have been also as Head of Compliance.
Nadine holds a Master’s Degree in Money and Banking from The American University of Beirut.
She has an extended financial experience in the Middle Eastern, African, American, and European markets. She is fluent in English, French and Arabic, and is no stranger to EU and US legislations, having worked for multiple banks that do business in European and American markets.