# GCC LexAI > AI-powered search and Q&A across 205+ regulatory documents covering AI, data protection, fintech, and telecom regulations across all six GCC countries. GCC LexAI is a retrieval-augmented generation (RAG) assistant that lets users ask questions about GCC regulatory frameworks and receive cited, source-grounded answers. It is not a legal advice service. ## Coverage - **UAE** (98 documents): CBUAE, ADGM, FSRA, DIFC, DFSA, TDRA, SCA, MoIAT, DDA, DGE, VARA - **Qatar** (62 documents): MCIT, QFCRA, Qatar Central Bank - **Saudi Arabia** (23 documents): SDAIA, NDMO, SAMA, NCA, CST, CMA - **Bahrain** (11 documents): CBB, PDPA, NCSC - **Kuwait** (7 documents): CBK, CMA, CITRA - **Oman** (3 documents): ITA, MTCIT ## Topics - Data protection and privacy (UAE PDPL, Saudi PDPL, ADGM DPR, DIFC DP Law, Bahrain PDPDL, Qatar PDPPL) - AI governance and ethics (UAE AI Strategy, SDAIA AI Ethics, ADGM AI Guidelines) - Virtual assets and crypto (FSRA, DFSA, VARA, CBB Crypto Module, QFCRA) - Fintech and open banking (CBUAE Open Finance, SAMA Open Banking, CBB sandbox) - Cybersecurity (NCA Saudi Arabia, TDRA UAE, MCIT Qatar) - Telecom regulation (TDRA, CST, BTRC, TRA, CITRA) - Digital transformation (UAE AI Strategy 2031, Digital Oman, Kuwait Vision 2035) - AML/CFT (cross-GCC financial crime regulations) - Risk management (SAMA, CBUAE, QFCRA model risk guidance) ## Key regulatory frameworks - UAE Federal PDPL (2021) - ADGM Data Protection Regulations (2021) - DIFC Data Protection Law (2020) - Saudi Arabia PDPL (Personal Data Protection Law, 2021 / implemented 2023) - SDAIA AI Ethics Principles (2023) - SAMA Open Banking Framework (2022) - Bahrain PDPDL (2018) - Qatar PDPPL (2016, amended 2021) - VARA Virtual Assets Regulations (2023) - CBUAE Open Finance Policy (2023) ## URLs - Main chat: https://gcc-lexai.0xkaz.com - Document browser: https://gcc-lexai.0xkaz.com/docs - Glossary: https://gcc-lexai.0xkaz.com/glossary - UAE regulations: https://gcc-lexai.0xkaz.com/uae - Saudi Arabia regulations: https://gcc-lexai.0xkaz.com/saudi - Bahrain regulations: https://gcc-lexai.0xkaz.com/bahrain - Qatar regulations: https://gcc-lexai.0xkaz.com/qatar - Oman regulations: https://gcc-lexai.0xkaz.com/oman - Kuwait regulations: https://gcc-lexai.0xkaz.com/kuwait ## Topic pages (cross-GCC) - Data Protection & Privacy: https://gcc-lexai.0xkaz.com/topic/data-protection - AI Governance & Ethics: https://gcc-lexai.0xkaz.com/topic/ai-governance - Cybersecurity: https://gcc-lexai.0xkaz.com/topic/cybersecurity - Virtual Assets & Crypto: https://gcc-lexai.0xkaz.com/topic/virtual-assets - Fintech & Open Banking: https://gcc-lexai.0xkaz.com/topic/fintech - Risk Management: https://gcc-lexai.0xkaz.com/topic/risk-management - AML/CFT: https://gcc-lexai.0xkaz.com/topic/aml-cft - Digital Transformation: https://gcc-lexai.0xkaz.com/topic/digital-transformation - Data Governance: https://gcc-lexai.0xkaz.com/topic/data-governance - Consumer Protection: https://gcc-lexai.0xkaz.com/topic/consumer-protection - Licensing & Authorization: https://gcc-lexai.0xkaz.com/topic/licensing - Financial Regulation: https://gcc-lexai.0xkaz.com/topic/financial-regulation ## Country × topic pages - UAE Data Protection: https://gcc-lexai.0xkaz.com/uae/data-protection - UAE Fintech: https://gcc-lexai.0xkaz.com/uae/fintech - UAE Virtual Assets: https://gcc-lexai.0xkaz.com/uae/virtual-assets - UAE AI Ethics: https://gcc-lexai.0xkaz.com/uae/ai-ethics - UAE Telecom: https://gcc-lexai.0xkaz.com/uae/telecom - UAE Cybersecurity: https://gcc-lexai.0xkaz.com/uae/cybersecurity - Saudi Data Protection: https://gcc-lexai.0xkaz.com/saudi/data-protection - Saudi AI Strategy: https://gcc-lexai.0xkaz.com/saudi/ai-strategy - Saudi Fintech: https://gcc-lexai.0xkaz.com/saudi/fintech - Saudi Cybersecurity: https://gcc-lexai.0xkaz.com/saudi/cybersecurity - Saudi Virtual Assets: https://gcc-lexai.0xkaz.com/saudi/virtual-assets - Bahrain Fintech: https://gcc-lexai.0xkaz.com/bahrain/fintech - Bahrain Data Protection: https://gcc-lexai.0xkaz.com/bahrain/data-protection - Bahrain Virtual Assets: https://gcc-lexai.0xkaz.com/bahrain/virtual-assets - Bahrain Cybersecurity: https://gcc-lexai.0xkaz.com/bahrain/cybersecurity - Bahrain AI Governance: https://gcc-lexai.0xkaz.com/bahrain/ai-governance - Qatar Data Protection: https://gcc-lexai.0xkaz.com/qatar/data-protection - Qatar Fintech: https://gcc-lexai.0xkaz.com/qatar/fintech - Qatar Virtual Assets: https://gcc-lexai.0xkaz.com/qatar/virtual-assets - Qatar AI Governance: https://gcc-lexai.0xkaz.com/qatar/ai-governance - Qatar Cybersecurity: https://gcc-lexai.0xkaz.com/qatar/cybersecurity - Oman Data Protection: https://gcc-lexai.0xkaz.com/oman/data-protection - Oman Fintech: https://gcc-lexai.0xkaz.com/oman/fintech - Oman Virtual Assets: https://gcc-lexai.0xkaz.com/oman/virtual-assets - Oman Cybersecurity: https://gcc-lexai.0xkaz.com/oman/cybersecurity - Kuwait Data Protection: https://gcc-lexai.0xkaz.com/kuwait/data-protection - Kuwait Fintech: https://gcc-lexai.0xkaz.com/kuwait/fintech - Kuwait Virtual Assets: https://gcc-lexai.0xkaz.com/kuwait/virtual-assets - Kuwait AI Governance: https://gcc-lexai.0xkaz.com/kuwait/ai-governance - Kuwait Cybersecurity: https://gcc-lexai.0xkaz.com/kuwait/cybersecurity ## Key law pages - UAE PDPL: https://gcc-lexai.0xkaz.com/law/uae-pdpl - ADGM Data Protection Regulations: https://gcc-lexai.0xkaz.com/law/adgm-dpr - DIFC Data Protection Law: https://gcc-lexai.0xkaz.com/law/difc-dpl - Saudi Arabia PDPL: https://gcc-lexai.0xkaz.com/law/saudi-pdpl - Bahrain PDPDL: https://gcc-lexai.0xkaz.com/law/bahrain-pdpdl - VARA Virtual Assets Regulations: https://gcc-lexai.0xkaz.com/law/vara-regulations - CBUAE Open Finance Policy: https://gcc-lexai.0xkaz.com/law/cbuae-open-finance - SAMA Open Banking Framework: https://gcc-lexai.0xkaz.com/law/sama-open-banking - NCA Essential Cybersecurity Controls: https://gcc-lexai.0xkaz.com/law/nca-ecc - SDAIA AI Ethics Principles: https://gcc-lexai.0xkaz.com/law/sdaia-ai-ethics - CBB Crypto-Asset Module: https://gcc-lexai.0xkaz.com/law/cbb-crypto ## Regulatory body pages - ADGM: https://gcc-lexai.0xkaz.com/body/adgm - FSRA: https://gcc-lexai.0xkaz.com/body/fsra - CBUAE: https://gcc-lexai.0xkaz.com/body/cbuae - DIFC: https://gcc-lexai.0xkaz.com/body/difc - DFSA: https://gcc-lexai.0xkaz.com/body/dfsa - VARA: https://gcc-lexai.0xkaz.com/body/vara - TDRA: https://gcc-lexai.0xkaz.com/body/tdra - SCA: https://gcc-lexai.0xkaz.com/body/sca - MoIAT: https://gcc-lexai.0xkaz.com/body/moiat - DDA: https://gcc-lexai.0xkaz.com/body/dda - SAMA: https://gcc-lexai.0xkaz.com/body/sama - SDAIA: https://gcc-lexai.0xkaz.com/body/sdaia - NCA: https://gcc-lexai.0xkaz.com/body/nca - CST: https://gcc-lexai.0xkaz.com/body/cst - CBB: https://gcc-lexai.0xkaz.com/body/cbb - PDPA: https://gcc-lexai.0xkaz.com/body/pdpa - NCSC: https://gcc-lexai.0xkaz.com/body/ncsc - MCIT Qatar: https://gcc-lexai.0xkaz.com/body/mcit-qatar - QFCRA: https://gcc-lexai.0xkaz.com/body/qfcra - CBK: https://gcc-lexai.0xkaz.com/body/cbk - CITRA: https://gcc-lexai.0xkaz.com/body/citra - ITA: https://gcc-lexai.0xkaz.com/body/ita ## Source documents All source documents are publicly available regulatory publications from official GCC government and regulatory authority websites. Documents include laws, regulations, frameworks, policies, guidance, and strategy papers. ## Notes - Arabic originals are the legally binding versions where applicable - This service provides information only — consult qualified legal counsel for compliance decisions - Document database is updated as new regulations are published - Full document index with AI summaries: https://gcc-lexai.0xkaz.com/llms-full.txt --- # Full document index with summaries This file contains AI-generated summaries of all 179 GCC regulatory documents in the GCC LexAI database. Summaries are generated from document content and are provided for indexing and context purposes. Arabic originals are the legally binding versions where applicable. ## United Arab Emirates (101 documents) ### ADGM Brand Book - URL: https://gcc-lexai.0xkaz.com/docs/af2a9a4b-6f85-44cd-b4e3-67eacb6cf3d9 - Issuing body: ADGM - Type: guidance - Topics: brand guidelines, logo usage, marketing assets, visual identity - Applies to: entities and individuals involved in marketing and public relations activities representing the ADGM brand This ADGM Brand Book provides comprehensive guidelines for the correct usage of the ADGM brand assets, including its logo, language, and visual elements. It serves as a resource for ensuring consistent and appropriate representation of the ADGM brand in all marketing and public relations activities, maintaining brand integrity and recognition. Key requirements: - The primary ADGM logo must always maintain a minimum clear space and not appear smaller than 50px (digital) or 10mm (print) to ensure legibility. - The dual language ADGM logo must be used for official documents, dual language/Arabic collateral, buildings, and road signage, adhering to minimum size requirements. - Users must only use supplied ADGM logos and are prohibited from rescaling elements, distorting, recolouring, cropping, rotating, or adding visual effects to the logo. - The ADGM logo should not be placed on unsuitable colours or busy imagery where it would lack stand-out or obscure the focus of the background. - When pairing the ADGM logo with partner logos, balanced spacing and clear hierarchy must be maintained, ensuring each logo is displayed at an appropriate size and approved colour format without distortion. ### ADGM Courts Form Fees Reference Table - Effective 8 February 2025 - URL: https://gcc-lexai.0xkaz.com/docs/7d6e1f54-0757-44d3-b501-145d55ab0265 - Issuing body: ADGM - Type: guidance - Date: 2025 - Topics: court fees, dispute resolution, ADGM Courts, legal proceedings - Applies to: Parties initiating or responding to legal proceedings within the ADGM Courts, including litigants, legal representatives, and individuals seeking court services. This ADGM Courts document, effective February 8, 2025, outlines the forms and associated filing fees for various court proceedings within the Court of First Instance. It details fees for claims, applications, and other court-related actions across commercial, employment, small claims, and civil divisions. The document should be read in conjunction with the ADGM Courts Schedule of Fees. Key requirements: - Filing fees for claims (CFI 1) are determined by Table A of the ADGM Courts Schedule of Fees. - Filing fees for Small Claims (CFI 2) are 3% of the claim value, with a minimum of USD 100 and a maximum of USD 3,000. - Application Notices (CFI 12) have varying fees based on hearing time, ranging from USD 250 to USD 3,000 depending on the type of claim and hearing duration. - Application for Witness Summons (CFI 16) costs USD 100 across Commercial, Employment, Small Claims, and Civil divisions. ### ADGM Courts Guidelines for self-represented litigants %28Arabic%29 - URL: https://gcc-lexai.0xkaz.com/docs/8a0875aa-9dbd-4821-8c90-cc8ba1f79d6a - Issuing body: ADGM - Type: guidance - Topics: Court procedures, Self-representation, ADGM Courts - Applies to: Self-represented litigants in the ADGM Courts This document provides guidance for self-represented litigants in the Abu Dhabi Global Market (ADGM) Courts. It outlines key aspects of court procedures, including communication protocols, document submission, and expected conduct. The guidelines aim to assist individuals navigating the legal process without legal representation within the ADGM court system. Key requirements: - Adhere to respectful conduct in court proceedings. - Refrain from contacting the judge directly. - Familiarize yourself with the court's procedures and practice directions. - Follow the guidelines for electronic filing and forms. ### ADGM Courts Guidelines for self-represented litigants %28English%29 - URL: https://gcc-lexai.0xkaz.com/docs/feb098eb-123d-4466-a76f-997c1a274b08 - Issuing body: ADGM - Type: guidance - Topics: Court Procedures, Litigation, Legal Assistance - Applies to: Individuals representing themselves in legal proceedings before the ADGM Courts This document provides guidelines for self-represented litigants in the ADGM Courts. It outlines key aspects of court procedures, including duties of litigants, interaction with the registry, court rules, fees, and how to conduct a case. The guidelines aim to assist individuals navigating the legal system without legal representation. Key requirements: - Self-represented litigants must be polite in court. - Self-represented litigants must not contact the judge directly. - Self-represented litigants must adhere to court rules and practice directions. - Self-represented litigants are responsible for paying applicable court fees. ### ADGM Data Protection Regulations (Substantial Public Interest) Rules 2025 - URL: https://gcc-lexai.0xkaz.com/docs/10053d3d-28b3-4306-8097-3272eac08b9b - Issuing body: ADGM - Type: regulation - Date: 2025 - Topics: data protection, substantial public interest, insurance, child safeguarding - Applies to: Organizations processing special categories of personal data within the Abu Dhabi Global Market (ADGM) under section 7(2)(k)(xii) of the Data Protection Regulations 2021. The ADGM Data Protection Regulations (Substantial Public Interest) Rules 2025 outlines specific conditions for processing special categories of personal data when it is necessary for reasons of substantial public interest. These rules supplement the Data Protection Regulations 2021 and are enforced by the Commissioner of Data Protection of the ADGM. The regulation focuses on scenarios where consent may not be required. Key requirements: - Processing of special categories of personal data for insurance purposes must be necessary for an insurance purpose and reasons of substantial public interest. - Processing related to insurance cannot be carried out for measures or decisions regarding the data subject if they lack rights or obligations related to the insurance contract, unless it can reasonably be done without consent. - Processing for safeguarding children and at-risk individuals must be necessary for protecting them from harm or well-being, carried out without consent under specific reasons, and necessary for substantial public interest. ### ADGM Office of Data Protection — Circular No. 1 of 2025 - URL: https://gcc-lexai.0xkaz.com/docs/0ced3c26-8134-4bfe-9f3e-b17caac684d3 - Issuing body: ADGM - Type: guidance - Date: 2025 - Topics: data protection, data protection register, compliance, ADGM - Applies to: All ADGM Entities ADGM Office of Data Protection Circular No. 1 of 2025 reminds ADGM entities of their obligations under the DPR 2021 to maintain an accurate and up-to-date Data Protection Register, including the contact details of their designated Data Protection Contact Person. Failure to comply may result in enforcement actions, including fines and inspections. Key requirements: - Maintain accurate information on the Data Protection Register, including processing purposes, data subject categories, and data transfers. - Ensure the Data Protection Register is kept up-to-date, reflecting any changes in processing activities. - Ensure the contact details of the designated Data Protection Contact Person are current, including any changes in appointment. ### ADGM RA Service of Alcohol Guidance - URL: https://gcc-lexai.0xkaz.com/docs/80f5691c-b8c5-4e91-96c9-2538690a49f6 - Issuing body: ADGM - Type: guidance - Topics: alcohol regulation, licensing, hospitality, ADGM - Applies to: ADGM Entities located in Al Maryah Island that serve alcohol to guests This ADGM guidance outlines the requirements for ADGM entities located on Al Maryah Island that serve alcohol to guests. It covers commercial licenses, alcohol permits, service protocols, record keeping related to liquor stock and suppliers, and monitoring systems. The guidance aims to ensure compliance with UAE laws concerning alcohol service within ADGM. Key requirements: - ADGM Entities must hold a valid commercial license and alcohol permit issued by the RA. - Alcoholic beverages may be served in transparent or colored vessels within the ADGM Entities’ premises. - The ADGM Entity’s outdoor area(s) should not be in full open view to the public, requiring a level of screening. - ADGM Entities must maintain up-to-date and accurate records relating to the quantities and movement of its liquor stock. ### ADGM Supplementary Guidance on Whistleblowing July 2025 - URL: https://gcc-lexai.0xkaz.com/docs/9f4fb1cf-77e4-4436-a032-e49336b01327 - Issuing body: ADGM - Type: guidance - Date: 2025 - Topics: whistleblowing, compliance, ethics, governance - Applies to: Global Market Establishments as defined in the ADGM Whistleblower Protection Regulations This ADGM supplementary guidance clarifies the regulatory framework for whistleblowing within the ADGM, referencing the Whistleblower Protection Regulations 2024. It outlines key aspects of protected disclosures, whistleblower protection, organizational arrangements, and the development of written policies and procedures to foster a culture of compliance and ethical conduct. Key requirements: - Establish organizational arrangements for internal whistleblowing processes. - Develop and maintain written policies and procedures for whistleblowing. - Maintain records related to whistleblowing disclosures and investigations. ### Annual Accounts Extension Guidance V2 - URL: https://gcc-lexai.0xkaz.com/docs/8f7ec631-66d3-4eab-95ee-0adfc534b0b3 - Issuing body: ADGM - Type: guidance - Topics: annual accounts, filing extensions, regulatory compliance - Applies to: ADGM-incorporated private limited companies and limited liability partnerships (LLPs) This guidance from the ADGM Registration Authority outlines the process for private companies and limited liability partnerships to apply for an extension to file their annual accounts. It details the relevant legal framework under the ADGM Companies Regulations 2020 and the Limited Liability Partnership Rules 2020, specifying the Registrar's power to grant extensions up to 3 months. Key requirements: - Companies must keep adequate accounting records, whether trading or not. - Applications for extensions must be delivered to the Registration Authority. - The Registrar will consider specific factors when determining whether to grant extensions. - Companies must refer to the Commercial Licensing Regulations 2015 section 28. ### Beneficial Ownership Guidance Note 20260604 - URL: https://gcc-lexai.0xkaz.com/docs/bd8b16c7-3359-457e-a9e4-975eafd7d37a - Issuing body: ADGM - Type: guidance - Topics: Beneficial Ownership, Ultimate Beneficial Owner (UBO), Legal Entities, Transparency - Applies to: entities registered with the ADGM Registration Authority, including Companies, Limited Liability Partnerships, Limited Partnerships, Foundations, DLT Foundations, and Trusts. This ADGM Guidance Note provides detailed instructions on identifying beneficial owners for various legal entities registered within the ADGM jurisdiction. It outlines specific tests (Ownership, Control, Management) to determine Ultimate Beneficial Owners (UBOs) for companies, limited liability partnerships, limited partnerships, foundations, and trusts, aiming to enhance transparency and compliance with beneficial ownership requirements. Key requirements: - Determine the UBO of a Company using the Ownership Test, Control Test, and Management Test. - Identify beneficial owners for Limited Liability Partnerships through Ownership, Control, and Management Tests. - Ascertain beneficial owners for Limited Partnerships by applying Ownership, Control, and Management Tests. - Determine beneficial owners for Foundations and DLT Foundations. - Identify beneficial owners for Trusts. ### Beneficial Ownership and Control Guidance 2021 - URL: https://gcc-lexai.0xkaz.com/docs/b0cd9e12-e7d3-497b-aa01-92c1a39b74e0 - Issuing body: ADGM - Type: guidance - Date: 2021 - Topics: Beneficial Ownership, Registration, ADGM Regulations - Applies to: Entities registered within the Abu Dhabi Global Market (ADGM) This guidance document, issued by the Abu Dhabi Global Market (ADGM), assists clients in identifying and registering beneficial owners of ADGM entities. It outlines the Registration Authority's role and functions, including the registration of ADGM establishments and maintenance of registers. The document provides tests to determine beneficial ownership. Key requirements: - Identify beneficial owners of ADGM entities. - Register beneficial owners with the Registration Authority. - Apply the Ownership Test to determine direct and indirect ownership. - Apply the Control Test to determine control over the entity. - Apply the Officer Test to determine beneficial ownership. ### Branch - Financial Services and Non-Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/9ec6a557-853d-4729-9c6b-6ef987a8c992 - Issuing body: ADGM - Type: guidance - Topics: Branch Registration, Business Plan, Financial Projections, Organizational Structure - Applies to: Foreign companies seeking to register a branch in ADGM, whether engaged in financial or non-financial activities. This ADGM guidance document outlines the standard requirements for registering a branch of a foreign company, covering both financial and non-financial firms. It details the necessary steps, including in-principle approval for financial services and the submission of a comprehensive business plan for non-financial activities, which is crucial for the ADGM Registration Authority's assessment. Key requirements: - Obtain in-principle approval from ADGM Financial Services if the business activity is financial. - Submit a business plan as part of the online application if the business activity is non-financial. - Provide an ownership structure chart identifying all controllers, direct or indirect, and ownership percentage, including ultimate beneficial owners. - Provide a full organization chart of the applicant’s proposed key appointments. - Provide financial projections, including initial capital injection and estimated annual expenses. ### Continue LTD into ADGM - URL: https://gcc-lexai.0xkaz.com/docs/475691eb-6ef4-47cc-be6e-0b717b237d25 - Issuing body: ADGM - Type: guidance - Topics: Company Registration, Corporate Governance, ADGM Regulations - Applies to: Body corporates incorporated outside the Abu Dhabi Global Market (ADGM) seeking to continue registration within ADGM as a private company limited by shares This ADGM guidance document outlines the eligibility criteria and requirements for a body corporate incorporated outside of ADGM to continue its registration within ADGM as a private company limited by shares. It includes a checklist to determine eligibility based on factors like solvency, winding-up status, and creditor arrangements. Key requirements: - Confirm that members of the body corporate applying for continuance in ADGM do not have unlimited liability in their home jurisdiction, unless applying as an unlimited company. - Verify that the body corporate applying for continuance within ADGM is not being wound up or in liquidation. - Ensure the body corporate applying for continuance within ADGM is not insolvent. - Obtain approval to use a sensitive company name from the relevant authority, if applicable. - Provide evidence showing the right to use the proposed trade name (e.g., trademark registration, franchise agreement). ### Decision Procedures Disqualification and Enforcement Manual October 2025 - URL: https://gcc-lexai.0xkaz.com/docs/3b8c67dd-65b1-4ef5-b4a5-a4fb72630737 - Issuing body: ADGM - Type: guidance - Date: 2025 - Topics: Enforcement, Disqualification, Investigations - Applies to: Entities and individuals subject to the regulatory oversight of the ADGM Registration Authority. This document, issued by the ADGM Registration Authority, outlines the procedures for enforcement and disqualification actions. It details the legal basis, application, and purpose of the manual, including defined terms and statutory notices. The manual covers the enforcement process, from initial awareness of potential issues to investigations and potential warrants. Key requirements: - Comply with statutory notices issued by the Registration Authority. - Cooperate with information gathering requests from the Registration Authority. - Avoid obstruction of the Registration Authority during investigations. ### Effective Management of Climate-related Financial Risks Guidance 20231004 - URL: https://gcc-lexai.0xkaz.com/docs/a2ce700c-4648-446c-9a0a-f5410bc26177 - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: Climate Risk, Financial Risk Management, Sustainable Finance, ESG - Applies to: Financial institutions operating within Abu Dhabi Global Market (ADGM) This guidance from the UAE Sustainable Finance Working Group, issued by ADGM, outlines principles for the effective management of climate-related financial risks. It aims to support the UAE's economic transition and the adoption of sustainable finance, aligning with national initiatives like the UAE Green Agenda and the Net Zero by 2050 Strategic Initiative. The guidance provides a framework for financial institutions to integrate climate considerations into their operations. Key requirements: - Oversight and responsibility of climate-related financial risk exposures - Incorporation of climate-related financial risk exposures into overall business strategy - Assigning climate-related financial risk management responsibilities within the organization - Incorporation of climate-related financial risks into risk management framework - Monitoring and reporting of climate-related financial risks ### Environmental Social and Governance Disclosures - Guidance 200825 - URL: https://gcc-lexai.0xkaz.com/docs/d77c47fd-e937-473b-835e-bd78d986c03b - Issuing body: ADGM - Type: guidance - Topics: ESG disclosures, Reporting requirements, Threshold conditions, ADGM regulations - Applies to: Companies operating within ADGM and FSRA-regulated fund and asset managers operating within ADGM that meet specific turnover or AUM thresholds. This ADGM guidance document outlines the framework for Environmental, Social, and Governance (ESG) disclosures. It clarifies the scope, thresholds (turnover and AUM), and reporting process for companies and fund/asset managers operating within ADGM. The guidance aims to promote transparency and accountability regarding ESG factors within the ADGM ecosystem. Key requirements: - Companies and FSRA fund/asset managers must meet specific turnover or AUM thresholds to be in scope for ESG disclosures. - In-scope companies must submit ESG disclosures according to the prescribed timeline and method. - ESG disclosures must adhere to a defined standard. - Companies included in the group annual accounts of a larger group may be exempt from individual ESG disclosure requirements. ### Environmental Social and Governance Disclosures Guidance 20230704 - URL: https://gcc-lexai.0xkaz.com/docs/230fc0fa-c64f-48f8-bcc3-5e6f6a2b9763 - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: ESG disclosures, reporting, AUM, turnover - Applies to: Companies operating within the Abu Dhabi Global Market (ADGM) that meet specific turnover thresholds and FSRA Fund and Asset Managers that meet specific AUM thresholds. This ADGM guidance document outlines the Environmental, Social, and Governance (ESG) disclosures framework for companies operating within the ADGM. It specifies the scope, timeline for compliance, and threshold conditions based on turnover and Assets Under Management (AUM). The guidance also addresses the review process and potential consequences for non-submission of ESG disclosures. Key requirements: - Companies meeting a certain turnover threshold must make ESG disclosures. - FSRA Fund and Asset Managers meeting a certain AUM threshold must make ESG disclosures. - In-scope companies must submit ESG disclosures or face potential consequences. - Companies included in the group accounts of a larger group may be exempt from individual disclosures. ### Guidance - Listing Applications and Eligibility VER01.100425 - URL: https://gcc-lexai.0xkaz.com/docs/5c0b71b7-0dd3-4014-8ecf-71c548bcf098 - Issuing body: ADGM - Type: guidance - Topics: Listing, Eligibility, Securities Regulation - Applies to: Entities seeking to list securities on the ADGM This ADGM guidance document outlines the requirements and procedures for listing applications and eligibility assessments. It details when a listing application is necessary, the documents and criteria involved, available exemptions, and the overall application process. The document also specifies general eligibility requirements for listing on the ADGM. Key requirements: - Submission of a Listing Application when required. - Meeting general eligibility requirements as per MKT 2.3, including incorporation and audited financial statements. - Undergoing an eligibility assessment to determine suitability for listing. - Issuers must make specific disclosures associated with admission to the official list. ### Guidance - Restricted Securities VER01.061125 - URL: https://gcc-lexai.0xkaz.com/docs/5398d1fe-3893-493b-bf9f-8861be1dca51 - Issuing body: ADGM - Type: guidance - Topics: Securities, ADGM, Financial Regulation, Restricted Securities - Applies to: Issuers and holders of restricted securities within the ADGM jurisdiction, including founders, related parties, service providers, and investors. This ADGM guidance document outlines requirements related to restricted securities, including background, restrictions, and categories of holders. It details implications for issuers and holders, procedures for applicants, restriction agreements, holding locks, free float calculation, and prospectus disclosure. The guidance aims to ensure transparency and manage risks associated with restricted securities. Key requirements: - Issuers must understand the implications of restricted securities on their operations. - Holders of restricted securities must understand the implications of holding such securities. - Applicants must follow specific procedures related to restriction agreements and holding locks. - Free float calculation must be performed according to the guidelines. - Prospectus disclosure must include information about restricted securities. ### Guidance Private Credit Funds 20230504 - URL: https://gcc-lexai.0xkaz.com/docs/e74057ae-cdeb-4663-9678-dbe2d03d22b3 - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: private credit funds, fund management, investment restrictions, regulatory compliance - Applies to: Authorised Persons and Applicants seeking to act as the Fund Manager of a Private Credit Fund in ADGM This ADGM guidance clarifies the regulatory requirements for Private Credit Funds and their managers. It supplements existing regulations (FSMR, GEN, FUNDS) and focuses on eligibility, authorization, and ongoing compliance. The guidance emphasizes investment restrictions, operational requirements, and investor suitability for these funds, which provide alternative financing to companies. Key requirements: - Fund Managers of Private Credit Funds must satisfy requirements in addition to those in GEN and FUNDS. - Private Credit Funds are limited to Exempt Funds and Qualified Investor Funds offered to Professional Clients. - Private Credit Funds must adhere to specific investment and operational requirements outlined in FUNDS. ### Guidance on ESG Funds and Model Portfolios in ADGM 20241114 - URL: https://gcc-lexai.0xkaz.com/docs/8151b4fe-c898-489e-a252-53ea698e8954 - Issuing body: ADGM - Type: guidance - Date: 2024 - Topics: ESG Funds, Greenwashing, Disclosure, Investment Management - Applies to: Domestic Funds, Model Portfolios, and Foreign Funds that hold themselves out as having ESG characteristics within ADGM, as well as other Authorised Persons providing financial services or raising investor funds with ESG characteristics. This ADGM guidance clarifies the expectations of the Financial Services Regulatory Authority (FSRA) regarding the management and marketing of ESG Investment Vehicles, including Domestic Funds, Model Portfolios, and Foreign Funds. It aims to mitigate greenwashing risks by ensuring clear, fair, and non-misleading marketing practices and encourages ESG-related information disclosure in line with global best practices. Key requirements: - Ensure that the names of ESG Investment Vehicles are not undesirable or misleading. - Implement ESG investment strategies that align with the stated ESG characteristics. - Disclose ESG-related information clearly and transparently in marketing materials. - Consider using third-party attestation to validate ESG claims. ### Guidance on Exemptions from the requirement to appoint a CSP 08-04-2021 %281%29 - URL: https://gcc-lexai.0xkaz.com/docs/4bc5ec95-a543-47ca-bbfa-29e757d7e026 - Issuing body: ADGM - Type: guidance - Date: 2021 - Topics: Company Service Provider, Exemptions, ADGM Regulations, Corporate Governance - Applies to: Bodies corporate seeking to establish a presence in ADGM and potentially eligible for exemption from appointing a Company Service Provider (CSP) This ADGM guidance document clarifies exemptions from the requirement to appoint a Company Service Provider (CSP) as outlined in the Companies Regulations 2020. It details specific scenarios where a body corporate, particularly subsidiaries, may be exempt, focusing on factors like regulatory status of the parent company and demonstration of adequate presence in the UAE. The document provides examples and criteria for assessing these exemptions. Key requirements: - Subsidiaries of entities exempt under the Commercial Licensing Regulations 2015 (Exemptions) Order 2020 are exempt from appointing a CSP. - Subsidiaries of authorized persons under the Financial Services and Markets Regulations 2015 are exempt from appointing a CSP. - Subsidiaries of companies whose shares are admitted to trading on a regulated market in the UAE (including ADGM) are exempt from appointing a CSP. - A company can demonstrate adequate presence in the UAE based on assets, turnover, employees, and governance policies to be exempt from appointing a CSP. ### Guidance on Exemptions from the requirement to appoint a CSP 08-04-2021 - URL: https://gcc-lexai.0xkaz.com/docs/aac319fa-0cf6-42ac-90b2-7f2aad1939a4 - Issuing body: ADGM - Type: guidance - Date: 2021 - Topics: Company Service Provider, Exemptions, ADGM Regulations, Corporate Governance - Applies to: Bodies corporate seeking to establish a presence in ADGM and potentially eligible for exemption from the requirement to appoint a Company Service Provider (CSP) This ADGM guidance document clarifies exemptions from the requirement to appoint a Company Service Provider (CSP) as per the Companies Regulations 2020. It outlines specific conditions under which a body corporate, particularly subsidiaries of certain entities, may be exempt. The guidance details the criteria the Registrar uses to assess adequate presence in the UAE for exemption purposes. Key requirements: - Subsidiaries of entities exempt under the Commercial Licensing Regulations 2015 (Exemptions) Order 2020 are exempt from appointing a CSP. - Subsidiaries of authorized persons under the Financial Services and Markets Regulations 2015 are exempt from appointing a CSP. - Subsidiaries of companies with shares admitted to trading on a regulated market in the UAE (including ADGM) are exempt from appointing a CSP. - A company demonstrating adequate presence in the UAE to the Registrar's satisfaction is exempt from appointing a CSP. ### Guidance on Preparing Prospectus 20240220 - URL: https://gcc-lexai.0xkaz.com/docs/291fca0c-a89a-471b-b909-0d71385328eb - Issuing body: ADGM - Type: guidance - Date: 2024 - Topics: Prospectus, Disclosure, Securities Offerings, ADGM - Applies to: Issuers of securities within the ADGM seeking to offer those securities to the public. This ADGM guidance document outlines the requirements for preparing a prospectus. It details when a prospectus is needed, the necessary content, acceptable formats, and the application process for approval. The guidance also covers exemptions from prospectus obligations and specific disclosure requirements for issuers. Key requirements: - Prospectuses must include all information investors and their professional advisors would reasonably require to make an informed assessment of the rights attaching to the securities. - Prospectuses must not contain misleading or deceptive statements or omissions. - Issuers must submit required documents as part of the prospectus application process. - Prospectuses must include a summary, a registration statement, and a securities note. ### Guidance on accounts and audit for ADGM QFZPs 20250825 - URL: https://gcc-lexai.0xkaz.com/docs/0966935c-4d21-4375-9272-734e4edebbbf - Issuing body: ADGM - Type: guidance - Date: 2025 - Topics: Financial Reporting, Auditing, Corporate Tax, Free Zones - Applies to: ADGM entities that are 'qualifying free zone persons' under UAE Corporate Tax Law This ADGM guidance document outlines the financial statement, accounts, and audit requirements for ADGM entities that qualify as 'qualifying free zone persons' (QFZPs) under UAE Corporate Tax Law. It details audit exemptions and filing requirements for small or dormant QFZPs, emphasizing the need for ADGM-registered auditors where applicable. Key requirements: - QFZPs must adhere to specific financial statement requirements. - QFZPs must determine if they qualify for any audit exemptions based on size, parent company status, subsidiary status, or dormancy. - QFZPs must file accounts with ADGM. - Audits, when required, must be conducted by an ADGM Registered Auditor. ### Guidance on client money - March 2023 - URL: https://gcc-lexai.0xkaz.com/docs/7848ddfb-0ef5-4e34-95c9-26fd06ac4b10 - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: Client Money, Financial Regulation, ADGM, Compliance - Applies to: Licensed Firms required to comply with the Client Money Rules in accordance with the Commercial Licensing Regulations 2015 (Conditions of Licence and Branch Registration) Rules 2021, and any other person whose conditions of licence require it to hold Client Money solely in accordance with the Client Money Rules. This ADGM guidance clarifies the Client Money Rules 2021, focusing on the safeguarding of client funds against misuse, misappropriation, loss, or theft. It provides information and clarification on the operation and requirements of the Client Money Rules, emphasizing the policies, systems, and controls necessary for handling client money. Key requirements: - Licensed Firms must have policies, systems, and controls for identifying, handling, segregating, and withdrawing Client Money from Client Accounts. - Licensed Firms must properly safeguard money belonging to Clients against misuse, misappropriation, loss or theft. - Licensed Firms must comply with the Client Money Rules in accordance with the Commercial Licensing Regulations 2015 (Conditions of Licence and Branch Registration) Rules 2021. ### Guidance-on-Revising-Defective-Accounts-and-Reports - URL: https://gcc-lexai.0xkaz.com/docs/77330da7-73e8-4200-9a02-75e92f77dc71 - Issuing body: ADGM - Type: guidance - Topics: Financial Reporting, Accounting Standards, Regulatory Compliance - Applies to: Companies operating within the ADGM that are subject to the Companies Regulations 2020 and the Revision of Accounts Rules. This ADGM guidance document provides an interpretation of the rules and regulations surrounding the revision of defective company accounts and reports. It clarifies the processes and restrictions outlined in the Companies Regulations 2020 and the Revision of Accounts Rules, offering a suggested approach for directors to ensure accounts are free from material misstatement. Key requirements: - Comply with ADGM Companies Regulations 2020 and the International Accounting Standards when preparing accounts. - Adhere to the rules outlined in the Companies Regulations 2020 and the ADGM Companies Regulations (Revision of Defective Accounts and Reports) Rules 2022 when revising accounts. - Be aware of restrictions on revisions after the annual report and accounts have been sent to members, delivered to the Registrar, or laid before the company in a general meeting. ### Information Technology Risk Management Guidance 20241120 - URL: https://gcc-lexai.0xkaz.com/docs/4916297e-522b-44ad-bcf9-abb9fc3c70e1 - Issuing body: ADGM - Type: guidance - Date: 2024 - Topics: IT Risk Management, Governance, Third-Party Risk - Applies to: Entities operating within the ADGM jurisdiction This ADGM guidance outlines principles for effective Information Technology Risk Management. It provides a framework for establishing a strong IT control environment, covering governance, risk management, third-party oversight, compliance, and system lifecycle management. The guidance aims to help organizations manage IT risks and ensure alignment with business objectives. Key requirements: - Establish and maintain a risk assessment framework for identifying and evaluating IT risks. - Implement a robust incident management process for detecting, responding to, and recovering from IT incidents. - Develop and implement a third-party risk management program to oversee IT service providers. - Ensure compliance with relevant regulations and conduct regular IT audits. ### Limited Liability Partnership - Financial and Non-Financial firms - URL: https://gcc-lexai.0xkaz.com/docs/042ef774-025c-4fad-af7d-77e6589c3cbc - Issuing body: ADGM - Type: guidance - Topics: Limited Liability Partnership, Business Plan, Financial Projections, ADGM - Applies to: Financial and non-financial Limited Liability Partnerships seeking incorporation in ADGM This ADGM guidance document outlines the standard requirements for incorporating a Limited Liability Partnership (LLP), covering both financial and non-financial entities. It details the necessary business plan components, including financial projections, ownership structure, and operational details, which are crucial for the ADGM Registration Authority's assessment. Key requirements: - Submit a comprehensive business plan detailing the applicant's history, experience, and proposed business activities. - Provide an ownership structure chart identifying all controllers and ultimate beneficial owners. - Describe the applicant's proposed staffing in ADGM, headcount, and office size. - Set out the initial capital injection and estimated annual expenses with supporting assumptions. ### Limited Partnership - Financial and Non-Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/c246b3cb-03d6-443c-8df6-6ffbfa98c499 - Issuing body: ADGM - Type: guidance - Topics: Limited Partnership, Business Registration, Financial Services, Non-Financial Services - Applies to: Entities seeking to register a Limited Partnership within the Abu Dhabi Global Market (ADGM) This ADGM guidance document outlines the standard requirements for registering a Limited Partnership in ADGM, covering both financial and non-financial services. It details the necessary business plan components, including applicant overview, business activities, target markets, ownership structure, organizational structure, human resources, and financial projections, which are crucial for the ADGM Registration Authority's assessment. Key requirements: - Submit a business plan detailing the applicant's history, experience, and proposed business activities. - Provide an ownership structure chart identifying all controllers and ultimate beneficial owners. - Describe the applicant's proposed staffing in ADGM, headcount, and office size. - Set out the initial capital injection and estimated annual expenses with supporting assumptions. ### Private Company Limited by Shares %28RSC%29 - Non-Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/51dd6a8e-8058-4f14-b910-2aea5ccb422a - Issuing body: ADGM - Type: guidance - Topics: company incorporation, business plan, ADGM, non-financial services - Applies to: Companies seeking to incorporate as a Private Company Limited by Shares (RSC) for non-financial services within the ADGM. This ADGM guidance document outlines the requirements for incorporating a Private Company Limited by Shares (RSC) engaged in non-financial services. It details the necessary steps and information required for the company set-up process, including business plan specifications, financial projections, and naming conventions. The document serves as a checklist for applicants seeking to establish an RSC within the ADGM. Key requirements: - Choose business activities from the list of permitted non-financial activities available on the ADGM website. - Prepare a business plan including an overview of the applicant, business activities, target markets, ownership structure, organization structure, HR plan, and financial projections. - Choose a company name that includes ‘Restricted Scope Company’ or ‘RSC’ and ends with ‘LTD’ or ‘Limited’. - Provide an ownership structure chart identifying all controllers, direct or indirect, and ownership percentage, including ultimate beneficial owners. ### Private Company Limited by Shares - Non-Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/b4d79de1-f094-4911-9fe9-dacaec2a260c - Issuing body: ADGM - Type: guidance - Topics: Company Incorporation, Business Plan, ADGM Regulations - Applies to: Companies seeking to incorporate as a private company limited by shares (non-financial services) within the Abu Dhabi Global Market (ADGM) This ADGM guidance document outlines the standard requirements for incorporating a private company limited by shares (non-financial services) within the Abu Dhabi Global Market. It emphasizes the importance of a comprehensive business plan for the application process, which the ADGM Registration Authority uses to assess the applicant's readiness and ability to meet licensing conditions. Key requirements: - Prepare a detailed business plan including company history, business activities, target markets, and ownership structure. - Provide an organization chart of proposed key appointments and details of staffing and physical presence in ADGM. - Submit financial projections including initial capital injection, estimated annual expenses, and underlying assumptions. - Choose a company name and ensure its availability, adhering to ADGM's Business and Company Name Rules. ### Private Company Limited by Shares - Retail - URL: https://gcc-lexai.0xkaz.com/docs/b7d0591b-5148-43cc-a04f-5c1ce3af131b - Issuing body: ADGM - Type: guidance - Topics: company registration, retail, ADGM, corporate governance - Applies to: Companies seeking to incorporate or register as a private company limited by shares in the retail sector within the ADGM. This ADGM guidance document outlines the standard requirements for incorporating or registering a private company limited by shares in the retail sector. It details the necessary steps and documentation, including lease agreements, company and trade name registration, articles of association, and information on authorized signatories and directors. Key requirements: - Secure a signed lease agreement with the landlord for a retail store located in ADGM. - Choose a company name and, optionally, a trade name, ensuring availability and compliance with ADGM rules. - Appoint at least one authorized signatory who is a UAE national, GCC national, or holds a valid UAE residence visa. - Draft articles of association compliant with ADGM Companies Regulations. ### RA-Annual-Accounts-Guidance-V10-09092022 - URL: https://gcc-lexai.0xkaz.com/docs/c410f57a-beec-4537-9d33-72cf121aaeb0 - Issuing body: ADGM - Type: guidance - Topics: Financial Reporting, Accounting Standards, Audit Requirements - Applies to: Companies registered with the Abu Dhabi Global Market (ADGM) Registration Authority This document provides guidance on annual account preparation and filing requirements for companies registered with the Abu Dhabi Global Market (ADGM) Registration Authority. It outlines accounting and reporting standards, deadlines, and specific requirements based on company size, including micro-entities, small, medium-sized, and dormant companies. The guidance also addresses audit exemptions and revisions to accounts. Key requirements: - Companies must adhere to specified accounting and reporting standards. - Companies must determine their company size based on defined criteria. - Companies must file accounts with the Registration Authority by established deadlines. ### Sustainable Finance Supplementary Guidance 20230704 - URL: https://gcc-lexai.0xkaz.com/docs/cd123e25-1820-420e-b535-7bb0014c253f - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: sustainable finance, green taxonomy, designation marks - Applies to: Authorised Persons operating within ADGM who are seeking designations for Green Funds, Climate Transition Funds, Portfolios, Bonds and Sukuks This ADGM supplementary guidance provides additional information on the rules for granting designations and using associated marks for ADGM Green Funds, Climate Transition Funds, Portfolios, Bonds, and Sukuks. The designations are voluntary and signify that the recipient invests in green or greening economic activities according to applicable rules, but are not a guarantee of compliance. Key requirements: - ADGM Green Funds can choose any published, credible, and independent green taxonomy to assess the environmental sustainability of their assets. - Persons must receive appropriate permission from the Regulator to use the relevant mark corresponding to the designation received. - Fund Managers are given flexibility to select the most suitable taxonomy considering the strategy of the Fund. ### Voluntary Liquidation Guidance 2023 - URL: https://gcc-lexai.0xkaz.com/docs/69517b1d-e3f9-4fe8-a21d-b34424834055 - Issuing body: ADGM - Type: guidance - Date: 2023 - Topics: Voluntary Liquidation, Members’ Voluntary Liquidation, Creditors’ Voluntary Liquidation - Applies to: Companies registered within the Abu Dhabi Global Market (ADGM) This ADGM guidance document outlines the procedures for voluntary liquidation of companies within the ADGM, covering both Members' Voluntary Liquidation (MVL) and Creditors' Voluntary Liquidation (CVL). It details the conditions for each type of liquidation, the required declarations, and the steps involved in commencing and managing the liquidation process, including notices and potential conversion between MVL and CVL. Key requirements: - Declaration of solvency is required for Members’ Voluntary Liquidation (MVL). - Notice of a members’ voluntary liquidation must be issued. - Companies must understand the implications on their status once liquidation commences. ### adgm-courts-procedural-flowchart-civil-and-employment-divisions-out-of-adgm-and-ad-290718-arabic - URL: https://gcc-lexai.0xkaz.com/docs/5e776927-125d-45a5-9d1e-8cca7454ef74 - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Employment Law, ADGM Courts, Litigation - Applies to: Claimants and defendants involved in civil and employment disputes before the ADGM Courts, where the claim originates outside the ADGM. This ADGM guidance document outlines the procedural flowchart for civil and employment divisions of the ADGM courts, specifically for cases originating outside of the ADGM jurisdiction. It details the steps and timelines for claim submission, defendant notification, defense filing, and counterclaim procedures within the ADGM court system. The document references specific articles of the Rules of Court Procedure. Key requirements: - The claimant must notify the defendant of the claim form and statement of reasons within a maximum of 6 months from the date of issuance of the claim form. - The defendant must file a defense within 28 days of the date of notification and submission. - The defendant can submit a request contesting the jurisdiction of the court, accompanied by written evidence. - The claimant may file a reply to the defense within 21 days of the defense notification. ### adgm-courts-procedural-flowchart-civil-and-employment-divisions-out-of-adgm-and-ad-amended-280618 - URL: https://gcc-lexai.0xkaz.com/docs/3b3bc96d-40ab-454e-a30d-d9a627fc3299 - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Employment Law, ADGM Courts, Dispute Resolution - Applies to: Parties involved in civil and employment disputes before the ADGM Court of First Instance where the claim form is served outside of ADGM/Abu Dhabi. This ADGM guidance outlines the procedural flow for civil and employment cases in the Court of First Instance when a claim form is served outside of ADGM or Abu Dhabi. It details timelines and actions required for claimants and defendants, including serving claims, filing defenses, and addressing jurisdiction. Key requirements: - Claimant must serve the claim form or discontinue the claim within 6 months of the issue date. - Defendant must file and serve an acknowledgment of service within 14 days after service of the claim form. - Defendant must file and serve a defense within 28 days after service of the claim form. - Claimant may file and serve a reply to a defense within 21 days after service of the defense. ### adgm-courts-procedural-flowchart-civil-and-employment-divisions-within-adgm-and-ad-290718-arabic - URL: https://gcc-lexai.0xkaz.com/docs/eec8f49f-9029-4734-b33d-cbf37ae642ae - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Employment Disputes, ADGM Courts - Applies to: Parties involved in civil and employment disputes within the ADGM jurisdiction This document outlines the procedural flowchart for civil and employment divisions within the ADGM Courts. It details the steps and timelines for claim notification, defense submission, and counterclaims. The document references specific articles within the Rules of Court Procedure and Practice Directions, providing guidance on the process. Key requirements: - The claimant must complete the necessary steps related to notification using the chosen method when the claim form is issued against the defendant. - The defendant must file and serve an acknowledgment of service within 14 days of service of the claim form. - A defendant wishing to defend all or part of a claim must file and serve a defense within 28 days of service of the claim form. - A claimant wishing to defend all or part of a counterclaim must file and serve a reply to the defense within 21 days of service of the defense. ### adgm-courts-procedural-flowchart-civil-and-employment-divisions-within-adgm-and-ad-amended-280618 - URL: https://gcc-lexai.0xkaz.com/docs/309fc120-f38e-47ad-9fa5-820506cdd3da - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Employment Law, ADGM Courts, Litigation - Applies to: Parties involved in civil and employment litigation within the ADGM Court of First Instance. This ADGM guidance document outlines the procedural flow for civil and employment cases within the ADGM Court of First Instance. It details the steps and timelines for serving claim forms, filing defenses, applying for summary judgments, and other key actions within the court process. The document aims to provide clarity on the required procedures for parties involved in litigation. Key requirements: - Claimant must serve the claim form within ADGM/Abu Dhabi following Rule 30 procedure. - Defendant must file and serve an acknowledgment of service within 14 days after service of the claim form. - Defendant must file and serve a defense within 28 days after service of the claim form. - Claimant may apply for default judgment if the defendant fails to file an acknowledgment of service or a defense. ### adgm-courts-procedural-flowchart-enforcement-of-judgments-of-adgm-courts-by-adjd-25032018 - URL: https://gcc-lexai.0xkaz.com/docs/8e967408-ffb6-442d-b541-2c1609f5eae1 - Issuing body: ADGM - Type: guidance - Topics: enforcement of judgments, ADGM Courts, Abu Dhabi Judicial Department - Applies to: Judgment creditors seeking to enforce ADGM Court judgments outside of ADGM through the Abu Dhabi Judicial Department. This ADGM guidance outlines the procedures for enforcing judgments issued by ADGM Courts outside of the ADGM jurisdiction, specifically through the Abu Dhabi Judicial Department (ADJD). It details two methods: deputization by ADGM Courts and direct application by the judgment creditor to the ADJD, specifying required documents and processes for each. Key requirements: - Judgment creditor must file an application for a certified copy of the judgment. - A copy of the judgment must be translated into Arabic by a legal translator. - ADGM Courts will affix an executory formula in Arabic to the judgment. - If seeking deputization, the judgment creditor must file an Application for Deputisation of Judgment of ADGM Courts. ### adgm-courts-procedural-flowchart-small-claim-divisions-within-adgm-ad-260418-arabic - URL: https://gcc-lexai.0xkaz.com/docs/ff7f38db-eacd-414a-989f-c6011482305d - Issuing body: ADGM - Type: guidance - Topics: court procedure, small claims, ADGM, dispute resolution - Applies to: Parties involved in small claims disputes within the ADGM Court of First Instance This ADGM guidance document outlines the court procedure flow for the Small Claims Division within the ADGM Court of First Instance. It details the steps and timelines for serving claims, filing defenses, and addressing jurisdictional challenges, aiming to provide clarity on the process for parties involved in small claims disputes. Key requirements: - The claimant must take action regarding the claim form in accordance with Article 30 of the Procedures. - The defendant must acknowledge service within 14 days of service. - The defendant must file a defense before judgment is issued. - The claimant may file a reply to the defense within 21 days of service of the defense. ### adgm-courts-procedural-flowchart-small-claim-divisions-within-adgm-ad-amended-260418 - URL: https://gcc-lexai.0xkaz.com/docs/a0b2dc6b-d25c-48d8-b846-e5fbc1cc24c9 - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Small Claims, ADGM Courts - Applies to: Claimants and defendants involved in small claims disputes within the ADGM Court of First Instance. This ADGM guidance document outlines the procedural flow for small claims divisions within the ADGM Court of First Instance. It details the steps involved in serving claim forms, filing defenses, applying for summary or default judgments, and preparing for hearings. The document aims to provide clarity on the process for resolving small claims disputes within the ADGM. Key requirements: - Claimant must serve the claim form on the defendant before 12 noon on the calendar day 14 days after the date of issue of the claim form. - Defendant must file and serve an acknowledgment of service within 14 days after service of the claim form. - A defendant who wishes to defend all or part of a claim must file and serve a defence within 28 days after service of the claim form. - Claimant may file and serve a reply to a defence within 21 days after service of the defence. ### adgm-courts-procedural-flowchart-small-claims-division-out-of-adgm-ad-260418-arabic - URL: https://gcc-lexai.0xkaz.com/docs/c9041918-5037-44c2-b7f9-cf39504d6a78 - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Small Claims, ADGM Courts - Applies to: Parties involved in small claims disputes before the ADGM Courts Small Claims Division where the claim originates outside of ADGM. This ADGM guidance document outlines the procedural flowchart for the Small Claims Division, focusing on claims originating outside of ADGM. It details the steps involved in filing a claim, serving the defendant, and subsequent actions such as judgments, defenses, and counterclaims, ultimately leading to a hearing. Key requirements: - The claimant must serve the claim form on the defendant with an explanatory statement of reasons. - The defendant must acknowledge service within 14 days of being served with the claim form. - The defendant must file a defense within 21 days of being served with the claim form. - The claimant may file a reply to the defense within 21 days of being served with the defense. ### adgm-courts-procedural-flowchart-small-claims-division-out-of-adgm-ad-amended-260418 - URL: https://gcc-lexai.0xkaz.com/docs/e99dcf62-045b-4aab-8059-1ad4997f4b2f - Issuing body: ADGM - Type: guidance - Topics: Civil Procedure, Small Claims, ADGM Courts - Applies to: Claimants and defendants involved in Small Claims Division cases in the ADGM Court of First Instance where the claim is served outside of ADGM/Abu Dhabi. This ADGM guidance document outlines the procedural flow for the Small Claims Division of the Court of First Instance, specifically for claims served outside of ADGM/Abu Dhabi. It details timelines and processes for serving claim forms, filing defenses, counterclaims, and acknowledgments of service, as well as procedures for summary judgment and default judgment. Key requirements: - Claimant must serve the notice of statement of grounds with the claim form on the defendant no later than 21 days of the date of issue of the claim form. - Defendant must file and serve an acknowledgment of service within 14 days after service of the claim form. - A defendant who wishes to defend all or part of a claim must file and serve a defence within 28 days after service of the claim form. - Claimant may file and serve a reply to a defence within 21 days after service of the defence. ### guidance_charges_ver11_20180509 - URL: https://gcc-lexai.0xkaz.com/docs/844f2987-0248-4e63-943c-d3404c80b689 - Issuing body: ADGM - Type: guidance - Topics: charge registration, ADGM, regulatory compliance - Applies to: Companies and other entities registering charges with the ADGM Registration Authority This ADGM guidance document outlines the process for registering charges under the Companies and Commercial Licensing Regulations and Foundation Regulations 2017. It details registrable charges, registration procedures, timelines, and the effects of both valid and failed registration. The document also covers rectification of statements, amendments, and satisfaction or release of charges. Key requirements: - Deliver the charge for registration within the period allowed. - Fulfill all requirements for registration of charges as specified. - Notify the Registration Authority of any addition to or amendment of a charge. - Follow the prescribed steps for completing the Application to register a Charge. ### guidancenotes_tradenames_v1 - URL: https://gcc-lexai.0xkaz.com/docs/a2afe304-2b1a-4bd4-9286-2b7954bbce93 - Issuing body: ADGM - Type: guidance - Topics: trade names, registration, licensing - Applies to: ADGM registered entities operating in or from Al Maryah Island, Abu Dhabi This guidance document, issued by the ADGM Registration Authority, provides information and assistance to ADGM registered entities regarding trade names. It outlines the requirements and application process for trade names within the ADGM framework, referencing the Commercial Licensing Regulations 2015. The guide aims to clarify the Registrar's role in trade name registration. Key requirements: - Adhere to permitted trade name guidelines as defined by ADGM. - Submit a trade name application to the Registration Authority. - Provide the necessary supporting documents as outlined in the checklist. - Pay the applicable fees for trade name registration. ### hotels_tourism_establishments_guide_v1_april_2017 - URL: https://gcc-lexai.0xkaz.com/docs/31355434-6877-4d2e-8748-cbdb9f8953af - Issuing body: ADGM - Type: guidance - Topics: tourism, hospitality, licensing, ADGM - Applies to: Hotels and tourism establishments (including tourism restaurants, tour organizers, travel agencies, and alcohol suppliers) operating in or from Al Maryah Island within ADGM. This guidance note from the ADGM Registration Authority outlines the application of requirements for hotels and tourism establishments operating within Abu Dhabi Global Market, specifically on Al Maryah Island. It details the cooperation agreement between ADGM and the Abu Dhabi Tourism & Culture Authority (TCA) regarding tourism activities. Key requirements: - Adherence to relevant requirements for hotel and tourism establishments operating in ADGM. - Compliance with the cooperation arrangements between the Registration Authority and Abu Dhabi Tourism & Culture Authority (TCA). - Entities organizing or hosting events, exhibitions, or conferences on Al Maryah Island must adhere to this guide. ### license_renewal_guide_updated-draft-v3-5 - URL: https://gcc-lexai.0xkaz.com/docs/65c5afbe-7315-44fc-b1bd-2da96231e8e7 - Issuing body: ADGM - Type: guidance - Topics: license renewal, commercial licensing, ADGM regulations - Applies to: ADGM registered entities operating in or from Al Maryah Island, Abu Dhabi This guidance document, issued by the ADGM Registration Authority, outlines the process and requirements for annual commercial license renewal within the Abu Dhabi Global Market. It details the Registrar's functions, contact information, payment methods (including electronic funds transfer), and applicable license renewal fees. The guide aims to assist ADGM registered entities in fulfilling their renewal obligations. Key requirements: - Adhere to the ADGM's Commercial Licensing Regulations 2015. - Pay license renewal fees as stipulated by the Registration Authority. - Comply with monitoring and enforcement actions by the Registrar, including potential financial penalties. - Notify the Registrar of any changes in particulars of the ADGM establishment (e.g., change in business name, director, or registered address). ### Consumer Protection Regulation - URL: https://gcc-lexai.0xkaz.com/docs/8c74ac0d-070f-4961-aa45-00c34d535c99 - Issuing body: CBUAE - Type: regulation - Topics: consumer protection, financial regulation, institutional oversight, market conduct - Applies to: All Licensed Financial Institutions in the UAE The Consumer Protection Regulation issued by the CBUAE aims to protect the interests of consumers using financial products, services, or engaging in relationships with licensed financial institutions in the UAE. It establishes standards of conduct expected from these institutions and defines regulatory requirements to ensure consistent interpretation and implementation. Key requirements: - Licensed Financial Institutions must adhere to standards for consumer protection. - Licensed Financial Institutions must practice responsible financing. - Licensed Financial Institutions must properly manage and resolve complaints. - Licensed Financial Institutions must ensure Shari’ah compliance for Islamic financial services. ### Consumer Protection Standards - URL: https://gcc-lexai.0xkaz.com/docs/47315956-8544-4abb-9675-8a12b35a2181 - Issuing body: CBUAE - Type: regulation - Topics: consumer protection, disclosure, transparency, financial services - Applies to: Licensed Financial Institutions in the UAE The Consumer Protection Standards, issued by the CBUAE, outline mandatory requirements for Licensed Financial Institutions in the UAE. These standards aim to ensure transparency, fair market conduct, and protection of consumer data and assets. The document supplements Circular No. 8 – 2020 and is enforceable in the same manner as the regulation. Key requirements: - Licensed Financial Institutions must apply disclosure and transparency requirements to all financial products and services provided through all communication channels. - All disclosure information must be available in both Arabic and English. - Information must be available in a format accessible and suitable for People of Determination. - Information must be in clear and plain language, using user-friendly font, color, and spacing. ### Digital Dirham (CBDC) Strategy - URL: https://gcc-lexai.0xkaz.com/docs/840311cb-9179-4221-96cd-a6380870bfe0 - Issuing body: CBUAE - Type: strategy - Topics: CBDC, Digital Dirham, Financial Infrastructure, Payment Systems - Applies to: Entities involved in the development, implementation, and usage of the Digital Dirham, including G42 Cloud and R3. The Central Bank of UAE (CBUAE) launched its Central Bank Digital Currency (CBDC) Strategy, named "The Digital Dirham", as part of its Financial Infrastructure Transformation (FIT) Programme. The strategy aims to address domestic and cross-border payment inefficiencies, promote financial inclusion, and support the UAE's transition to a cashless society by implementing a CBDC. Key requirements: - Soft launch of mBridge to facilitate real-value cross-border CBDC transactions for international trade settlement. - Proof-of-concept work for bilateral CBDC bridges with India. - Proof-of-concept work for domestic CBDC issuance covering wholesale and retail usage. ### Digital Dirham - Policy Considerations - URL: https://gcc-lexai.0xkaz.com/docs/c40d8414-2d1e-4549-ba21-ef61cf175fac - Issuing body: CBUAE - Type: policy - Topics: digital currency, monetary policy, payment systems, financial stability - Applies to: Central Bank of the UAE (CBUAE), licensed financial institutions in the UAE This CBUAE working paper introduces the concept of the Digital Dirham, the UAE's upcoming digital currency. It explores policy considerations for its implementation, including its potential impact on monetary policy, payment systems, and financial inclusion. The paper also addresses potential risks related to financial stability and cybersecurity. Key requirements: - Integrate the Digital Dirham into the payment system to function as legal tender. - Implement a two-tiered distribution model involving licensed financial institutions. - Incorporate design features and policy principles to mitigate potential risks to financial stability. - Apply appropriate restrictions on Digital Dirham usage to prevent large-scale shifts from deposits and savings. ### Guidance on Digital Identification for Customer Due Diligence - URL: https://gcc-lexai.0xkaz.com/docs/9d95973b-12a5-478e-92c1-be6baee68cfe - Issuing body: CBUAE - Type: guidance - Topics: Digital Identification, Customer Due Diligence, AML/CFT, Risk Management - Applies to: Licensed Financial Institutions (LFIs) of the United Arab Emirates Central Bank (CBUAE) This CBUAE guidance assists licensed financial institutions (LFIs) in understanding and performing their obligations related to Anti-Money Laundering and Combating the Financing of Terrorism (AML/CFT) when using digital identification for Customer Due Diligence (CDD). It outlines the use of digital ID systems for CDD, associated risks, and how to assess the reliability of these systems. Key requirements: - Understand and effectively perform statutory obligations under the legal and regulatory framework related to AML/CFT. - Assess the reliability and independence of Digital ID Systems for CDD. - Understand the system’s assurance levels. - Determine appropriate usage of Digital ID systems in the context of risk. ### Guidance on Responsible Use of Artificial Intelligence in Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/8f6ee591-8ce4-4fd9-ae3d-7a1afb817366 - Issuing body: CBUAE - Type: guidance - Topics: AI governance, Consumer protection, Data privacy, Financial innovation - Applies to: All licensed financial institutions operating within the UAE's supervisory ecosystem The CBUAE issued guidance on the responsible adoption and use of AI and machine learning by licensed financial institutions in the UAE. It establishes a framework to safeguard consumer rights, strengthen governance and transparency, and promote fair practices. The guidance aligns with the UAE’s national AI strategy. Key requirements: - Governance and accountability for AI systems - Fairness and non-discrimination in AI applications - Transparency and explainability of AI models - Effective human oversight of AI systems - Data management and privacy requirements ### Guidance on Risks Related to Virtual Assets and Virtual Asset Providers - URL: https://gcc-lexai.0xkaz.com/docs/4b60385a-4894-4b4e-b7fe-99fcec597114 - Issuing body: CBUAE - Type: guidance - Topics: Virtual Assets, VASPs, AML/CFT, Risk Management - Applies to: Licensed Financial Institutions (LFIs) in the UAE This CBUAE guidance outlines the risks associated with virtual assets (VAs) and virtual asset service providers (VASPs) and provides instructions for Licensed Financial Institutions (LFIs) on mitigating money laundering and terrorist financing (ML/TF) risks. It details the process for LFIs to obtain CBUAE's non-objection for opening new accounts for VASPs and managing VA-related customer transactions. Key requirements: - LFIs must apply a risk-based approach when dealing with VASP customers and VA-related transactions. - LFIs must conduct thorough Customer Due Diligence (CDD) on all VASP customers, including specific due diligence measures. - LFIs must obtain CBUAE's non-objection before opening new administrative or transactional accounts for VASPs. - LFIs must apply enhanced due diligence measures for higher-risk VASP customers. ### Model Management Guidance — AI/ML Model Risk - URL: https://gcc-lexai.0xkaz.com/docs/956ea07b-9ff4-4432-bc35-7d12c0f38680 - Issuing body: CBUAE - Type: guidance - Topics: model risk management, AI governance, financial modeling - Applies to: Financial institutions operating in the UAE and regulated by the CBUAE This CBUAE guidance outlines principles for managing risks associated with AI/ML models used by financial institutions. It provides specific guidance on various model types, including rating, PD, LGD, macro, interest rate risk, and net present value models. The document emphasizes governance, data analysis, model construction, validation, and monitoring. Key requirements: - Establish a robust governance framework for model development, implementation, and use. - Implement thorough data collection and analysis processes to ensure data quality and relevance. - Conduct regular model validation and monitoring to assess performance and identify potential weaknesses. ### Open Finance Regulation - URL: https://gcc-lexai.0xkaz.com/docs/72dc1275-a49e-42b9-b9ef-fd27a4531207 - Issuing body: CBUAE - Type: regulation - Topics: open finance, data sharing, consumer consent, financial technology - Applies to: All financial institutions subject to the supervision of the CBUAE The Central Bank of the UAE (CBUAE) issued the Open Finance Regulation to promote innovation, competitiveness, and efficiency in financial services. It mandates participation in the open finance framework for all CBUAE-supervised financial institutions, enabling them to access and utilize consumer financial data with user consent to create personalized experiences and tailored offerings. Key requirements: - Licensed financial institutions (LFIs) must provide participants in the Open Finance Framework with access to customer data. - LFIs must enable the initiation of transactions on accounts and products, subject to user consent. - LFIs must utilize a consumer consent model for sharing financial data with trusted third parties. - Participation in the open finance framework is mandatory for all CBUAE-supervised financial institutions. ### Dubai Blockchain Policy - URL: https://gcc-lexai.0xkaz.com/docs/1b00fe0b-149d-4180-aa7b-be17e29ca197 - Issuing body: DDA - Type: policy - Topics: blockchain, data privacy, security, smart contracts - Applies to: Entities involved in the formation, governance, and operation of blockchain networks within Dubai. The Dubai Blockchain Policy outlines the framework for blockchain network formation, governance, and operations within Dubai. It establishes guidelines for data privacy, security, interoperability, and the use of smart contracts. The policy aims to promote the adoption of blockchain technology while ensuring compliance and standardization across various applications. Key requirements: - Adherence to specified data formats and interoperability standards for blockchain networks. - Implementation of robust data privacy and confidentiality measures. - Compliance with security protocols for blockchain network operations. - Regular policy audits to ensure ongoing compliance. ### Dubai Data Compliance Framework - URL: https://gcc-lexai.0xkaz.com/docs/bc5afb9f-54d8-4c70-b19f-c0535c7262ba - Issuing body: DDA - Type: framework - Topics: data governance, data compliance, data management, KPIs - Applies to: Entities subject to the Dubai Data Law The Dubai Data Compliance Framework outlines the methodology for measuring compliance with the Dubai Data Law. It establishes key performance indicators (KPIs) based on timeliness and completeness across various elements, assigning weights to each element based on its importance. The framework also defines roles and responsibilities within entities to ensure data governance. Key requirements: - Designate a Dubai Data Team within the entity. - Determine and inventory data assets. - Classify data according to the Dubai Data Manual. - Prepare a data release plan. - Ingest data into the platform and maintain it. ### Dubai Data Policies - URL: https://gcc-lexai.0xkaz.com/docs/202cfa50-ab41-4d4f-a593-69233b81def3 - Issuing body: DDA - Type: policy - Topics: data classification, data dissemination, data exchange, data protection - Applies to: Government Entities (Local and Federal) and Private Entities possessing data related to the Emirate of Dubai Resolution No. (2) of 2017 approves the Policies Document on Classification, Dissemination, Exchange, and Protection of Data in the Emirate of Dubai. The document establishes rules, procedures, regulations, forms, and mechanisms for managing data. The Dubai Data Establishment (DDE) is responsible for supervising the implementation of these policies. Key requirements: - Classify data according to the policies outlined in the document. - Disseminate and exchange data in accordance with the established regulations. - Protect data as per the policies outlined in the document. - Comply with the supervision of the Dubai Data Establishment (DDE) regarding policy implementation. ### Dubai State of AI Report - URL: https://gcc-lexai.0xkaz.com/docs/53dd7373-0fa0-46a9-bd33-5cae448f0a66 - Issuing body: DDA - Type: report - Topics: AI governance, AI strategy, Digital transformation - Applies to: Dubai public sector entities and stakeholders involved in AI development and deployment. The Dubai State of AI Report focuses on AI developments within the public sector in Dubai, UAE. It highlights the UAE's commitment to AI integration across key sectors, driven by the UAE National Strategy for AI 2031 and the Dubai Universal Blueprint for Artificial Intelligence. The report emphasizes ethical deployment, regulatory foresight, and international collaboration in AI governance. Key requirements: - Embrace AI to transform government services. - Integrate AI across key sectors to build a competitive, knowledge-based economy. - Adopt innovative, AI-driven solutions as outlined in the Dubai Universal Blueprint for Artificial Intelligence. ### Framework for Implementation of Synthetic Data Techniques - URL: https://gcc-lexai.0xkaz.com/docs/8da71976-ecef-48ee-8a9b-18c6d8430c73 - Issuing body: DDA - Type: framework - Topics: synthetic data, data governance, privacy, data sharing - Applies to: Government entities and private sector organizations in Dubai This framework, issued by the Digital Dubai Authority (DDA), provides guidance on the implementation of synthetic data techniques in Dubai. It outlines the benefits of synthetic data for data sharing and privacy preservation. The framework includes a decision matrix to help organizations determine if synthetic data is the right solution for their needs. Key requirements: - Utilize the decision matrix to assess the suitability of synthetic data for specific problems. - Follow the outlined synthetic data generation process. - Adhere to existing data governance processes when using synthetic data. ### Law No. 24 of 2023 on Dubai Data and Digital Authority - URL: https://gcc-lexai.0xkaz.com/docs/e54d9069-0f6c-4153-83f9-e40d1761d839 - Issuing body: DDA - Type: law - Date: 2023 - Topics: data governance, statistics, digital authority - Applies to: Federal Government Entities, Local Government Entities, Other Entities, and Private Entities operating in Dubai Law No. 24 of 2023 establishes the Dubai Data and Statistics Establishment (DDSE) under the Dubai Digital Authority (DDA). It defines key terms related to government and private entities, and outlines the scope and application of the law within the Emirate of Dubai. The law aims to regulate data and statistics management within Dubai. Key requirements: - Compliance with the definitions of Government Entities, including Federal and Local entities. - Adherence to the regulations and guidelines issued by the Dubai Data and Statistics Establishment (DDSE). - Understanding the roles and responsibilities of the Dubai Digital Authority (DDA) in relation to data and statistics. ### Law No. 26 of 2015 Regulating Data Dissemination and Exchange - URL: https://gcc-lexai.0xkaz.com/docs/e73729eb-1958-4ecf-96fa-90276f5b19af - Issuing body: DDA - Type: law - Date: 2015 - Topics: data dissemination, data exchange, data governance, open data - Applies to: Federal Government Entities, Local Government Entities, and Persons determined by the Competent Entity (Data Providers) in the Emirate of Dubai Law No. 26 of 2015 regulates the dissemination and exchange of data within the Emirate of Dubai. It establishes definitions for key terms like 'Dubai Data,' 'Open Data,' and 'Shared Data,' and outlines the roles of Data Providers and the Competent Entity in supervising the implementation of the law. The law aims to facilitate the sharing and accessibility of data while ensuring its protection. Key requirements: - Data Providers must adhere to the Dubai Data Manual when disseminating, exchanging, and protecting Dubai Data. - Data Providers must use the Electronic Platform for disseminating and exchanging Dubai Data. - Shared Data must be exchanged among Data Providers in accordance with the conditions and rules determined by the Competent Entity. ### Smart Dubai AI Ethics Principles and Guidelines - URL: https://gcc-lexai.0xkaz.com/docs/df5bee12-4d4b-43e4-a501-499b8fc5e879 - Issuing body: DDA - Type: framework - Topics: AI ethics, AI governance, Transparency, Accountability - Applies to: AI operator organizations developing and deploying AI systems in Dubai The Smart Dubai AI Ethics Principles and Guidelines provide a framework for the ethical development and deployment of AI systems in Dubai. It outlines key principles related to ethics, security, humanity, and inclusiveness, and offers guidelines for ensuring fairness, accountability, transparency, and explainability in AI systems. The document aims to promote innovation while delivering human benefit and happiness. Key requirements: - AI systems should be fair, considering data representativeness and bias in decision-making processes. - Accountability for AI system outcomes should not lie with the system itself, and risks should be mitigated. - AI subjects should be able to challenge significant automated decisions and opt out where appropriate. - Traceability should be considered for significant decisions, especially those with potential for loss, harm, or damage. ### DFSA Crypto Token Regulatory Regime - URL: https://gcc-lexai.0xkaz.com/docs/c39216ee-519b-4857-820f-14620cffc23d - Issuing body: DFSA - Type: framework - Topics: crypto assets, financial regulation, licensing - Applies to: Firms in the Dubai International Financial Centre (DIFC) seeking to provide financial services with Crypto Tokens. This DFSA document outlines the regulatory framework for Crypto Tokens within the Dubai International Financial Centre (DIFC). It details the criteria for recognizing Crypto Tokens, including Fiat Crypto Tokens, and the process for obtaining DFSA recognition. The regime aims to foster innovation while addressing risks like money laundering and consumer protection. Key requirements: - Crypto Tokens must be recognized by the DFSA to be used in the DIFC (with limited exceptions). - Fiat Crypto Tokens must maintain a stable price relative to the reference fiat currency. - Entities seeking Crypto Token recognition must submit an application to the DFSA and pay a fee of USD 5,000. ### DFSA Cyber Risk Management Guidelines - URL: https://gcc-lexai.0xkaz.com/docs/39185570-4e9c-4273-b922-ec1e42abde32 - Issuing body: DFSA - Type: guidance - Topics: cyber risk management, cybersecurity, incident response, governance - Applies to: Firms operating within the Dubai International Financial Centre (DIFC) The DFSA Cyber Risk Management Guidelines provide best practices for firms to establish a robust cyber risk management framework and strengthen system security, reliability, resiliency, and recoverability. These guidelines are principle-based and encourage firms to implement a framework consistent with the G7 Fundamental Elements of Cybersecurity for the Financial Sector. The DFSA will consider these guidelines in future risk assessments. Key requirements: - Implement a cyber risk management framework tailored to the Firm’s size, complexity, and risk appetite. - Establish cyber risk identification and assessment capabilities. - Implement continuous monitoring and detection capabilities. - Develop a cyber incident response plan. ### DFSA FinTech: Fostering Innovation in Financial Services - URL: https://gcc-lexai.0xkaz.com/docs/604c3e7e-cb32-4d38-86a4-589066ec530a - Issuing body: DFSA - Type: report - Topics: FinTech, Innovation, Regulation, Economic Trends - Applies to: Authorised Firms, Registered Auditors, and Designated Non-Financial Businesses and Professions (DNFBPs) regulated by the DFSA in the DIFC. This DFSA report provides an update on the DFSA's activities and outlines broader industry trends, with a focus on fostering innovation in financial services, particularly FinTech. It highlights the DFSA's strategy for the next two years, emphasizing delivery, sustainability, and engagement, and discusses the growth of the regulated population and the aggregate balance sheet of firms regulated by the DFSA. Key requirements: - Firms must adhere to DFSA regulations as the scale of regulated activities in the DIFC increases. - Firms must comply with the DFSA's framework for crowdfunding. - Firms must comply with the DFSA's framework for the Innovation Testing Licence. ### UAE Digital Data Interoperability Principles and Standards - URL: https://gcc-lexai.0xkaz.com/docs/e1a48138-efce-4257-a5db-b471f7b04760 - Issuing body: DGE - Type: framework - Topics: data interoperability, data governance, data standards, data classification - Applies to: Entities involved in digital data management and exchange within the UAE. The UAE Digital Data Interoperability Framework outlines principles and standards for digital data management and exchange within the UAE. It aims to facilitate seamless data sharing and reuse across different entities while ensuring data quality, security, and privacy. The framework promotes collaborative governance and continuous improvement in data practices. Key requirements: - Classify digital data according to the Digital Data Classification Standard. - Adhere to rules for opening and sharing classified digital data. - Comply with the Digital Data Exchange Standards. - Adopt open standards for digital data management. - Ensure digital data quality. ### UAE Digital Data Interoperability Standards — Implementation Guide (Part 2) - URL: https://gcc-lexai.0xkaz.com/docs/f537bc8c-be67-4566-9436-2a5c83896351 - Issuing body: DGE - Type: framework - Topics: data interoperability, data governance, data standards, data management - Applies to: Government Entities in the UAE This document, "UAE Digital Data Interoperability Standards — Implementation Guide (Part 2)", provides guidance to UAE government entities on implementing the UAE Digital Data Interoperability Framework. It outlines processes for data governance, roadmap development, data inventory creation, prioritization, and ensuring data conformance to standards, aiming to facilitate effective data sharing and interoperability across government organizations. Key requirements: - Establish digital data governance roles and processes. - Build a Digital Data Interoperability Roadmap. - Develop and maintain a Data Inventory. - Prioritize data for interoperability based on defined criteria. - Ensure digital data conforms to standards through classification, formatting, metadata, quality management, and validation. ### UAE Digital Government Maturity Model - URL: https://gcc-lexai.0xkaz.com/docs/194eb533-dcee-4cd1-9b18-4dc38286a65c - Issuing body: DGE - Type: framework - Topics: digital government, maturity model, government strategy, technology governance - Applies to: UAE Ministries/Authorities The UAE Digital Government Maturity Model (UAEDGMM) framework provides dimensions to assess and enhance digital government capabilities across UAE Ministries/Authorities. It focuses on enablers rather than stages, with three pillars: Leadership, Strategy, and Governance, encompassing nine dimensions. The goal is to inform investment decisions for digital government innovation, not to benchmark entities against each other. Key requirements: - Ministries/Authorities must assess their digital government maturity level using the framework's dimensions and sub-dimensions. - Ministries/Authorities should use the assessment results to inform investment decisions for improving digital government capabilities. - Ministries/Authorities should focus on the nine dimensions of the framework: Leadership, Strategy, Governance, Legal, Technology, Cybersecurity, API Ecosystem Management, Specific Technologies and New Trends, and Ministry/Authority Specific. ### DIFC Commissioner of Data Protection — Overview of Personal Data Regime - URL: https://gcc-lexai.0xkaz.com/docs/a4836655-3953-436e-a063-a27bcf8582e9 - Issuing body: DIFC - Type: guidance - Date: 2020 - Topics: data protection, privacy, DIFC, data governance - Applies to: Controllers and processors operating within the Dubai International Financial Centre (DIFC) This document provides an overview of the data protection law and regulations within the Dubai International Financial Centre (DIFC). It outlines the interplay between DIFC, Federal, and Emirate laws, the authority of the DIFC Commissioner of Data Protection, and the principles for processing personal data. It also covers the rights of data subjects and the legal duties of controllers and processors. Key requirements: - Controllers and processors must adhere to internationally recognized data protection principles. - Controllers and processors must comply with accountability requirements. - Controllers and processors must fulfill legal duties as defined by DIFC data protection law. ### DIFC Comprehensive Guide to Data Protection Law and Regulations - URL: https://gcc-lexai.0xkaz.com/docs/08bdc84e-5d72-484a-8629-1e51be5e9202 - Issuing body: DIFC - Type: guidance - Date: 2020 - Topics: data protection, personal data, data breaches, data export - Applies to: Organizations operating within the Dubai International Financial Centre (DIFC) that process personal data. This document is a comprehensive guide issued by the DIFC Commissioner of Data Protection regarding Data Protection Law, DIFC Law No. 5 of 2020, and its associated regulations. It aims to provide accessible information about the legislation, covering definitions of personal and special category data, obligations of controllers and processors, data export, data subject rights, and breach procedures. Key requirements: - Controllers and processors must comply with the Data Protection Law and Regulations. - Organizations must provide information to data subjects regarding the processing of their personal data. - Organizations must implement procedures for handling personal data breaches. - Organizations must adhere to rules regarding data export and sharing. ### DIFC Data Protection Law No. 5 of 2020 (Consolidated Version) - URL: https://gcc-lexai.0xkaz.com/docs/cc32282d-d3c2-43cf-9ccb-9e7eb3792b7e - Issuing body: DIFC - Type: law - Date: 2020 - Topics: data protection, privacy, DPO, data processing - Applies to: Entities processing personal data within the Dubai International Financial Centre (DIFC) The DIFC Data Protection Law No. 5 of 2020 (Consolidated Version) outlines the requirements for processing personal data within the Dubai International Financial Centre (DIFC). It establishes principles for lawful processing, special categories of data, consent, legitimate interests, and accountability. The law aims to protect individuals' privacy rights and regulate data processing activities within the DIFC. Key requirements: - Process personal data lawfully, fairly, and transparently. - Implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk. - Maintain records of processing activities. - Designate a Data Protection Officer (DPO) under certain conditions. ### DIFC Data Protection Regulations — Consolidated Version (incl. Reg 10 AI, 2023) - URL: https://gcc-lexai.0xkaz.com/docs/10500451-3703-4cb6-916a-b1bb52f4ef51 - Issuing body: DIFC - Type: regulation - Date: 2023 - Topics: data protection, data breach, DIFC, privacy - Applies to: Entities processing personal data within the Dubai International Financial Centre (DIFC) The DIFC Data Protection Regulations outline the requirements for processing personal data within the Dubai International Financial Centre. This consolidated version includes updates related to AI and covers obligations related to data processing records, notifications, supervision, data transfers, breach reporting, and potential fines for non-compliance. It aims to protect personal data and ensure responsible data handling practices. Key requirements: - Maintain Records of Processing Activities (RoPA) - Notify the Commissioner of Processing Operations - Submit an Annual Assessment - Report Personal Data Breaches to the Commissioner and Data Subjects - Comply with rules regarding transfers of data outside the DIFC ### DIFC Regulation 10 Accelerator Framework — AI and Autonomous Systems - URL: https://gcc-lexai.0xkaz.com/docs/fec771a7-e831-4a3e-b7f4-f167fff6006d - Issuing body: DIFC - Type: framework - Topics: AI governance, privacy by design, regulatory sandbox, autonomous systems - Applies to: DIFC entities, non-DIFC entities with operations in DIFC, and any other entity looking to utilize the Accelerator. DIFC Regulation 10 Accelerator Framework provides an environment for testing autonomous and semi-autonomous systems for privacy by design and compliance with Regulation 10. It allows developers, deployers, and operators to assess their systems using various standards and frameworks, acting as a bolt-on to existing regulatory sandboxes or as a standalone assessment. Key requirements: - Apply to participate in the Reg 10 Accelerator environment, including responding to initial questions. - Execute a mutual, binding non-disclosure agreement upon request. - Provide a design document of the system to be tested. - Provide demonstration materials, such as a testing platform demo. ### DIFC Regulation 10 — Accreditation and Certification Framework for Autonomous Systems - URL: https://gcc-lexai.0xkaz.com/docs/f9f94ed9-958d-4d26-9af7-982c50ea5740 - Issuing body: DIFC - Type: framework - Topics: data protection, AI governance, accreditation, certification - Applies to: Any person to whom the Data Protection Law, DIFC Law No. 5 of 2020, and the DIFC Data Protection Regulations 2020 applies, specifically those involved with autonomous and semi-autonomous systems processing personal data. DIFC Regulation 10 establishes an accreditation and certification framework for autonomous and semi-autonomous systems that process personal data within the Dubai International Financial Centre (DIFC). It outlines the criteria for accrediting certification bodies and the requirements for certifying systems used in high-risk processing activities, ensuring compliance with the Data Protection Law and Regulations. Key requirements: - Accredited Certification Bodies must demonstrate independence and expertise in the subject matter of certification. - Accredited Certification Bodies must establish transparent procedures for complaints handling and dispute resolution. - Deployers, operators, and providers of systems must adhere to principles outlined in the Systems Certification Program Requirements. - Systems must meet audit criteria as defined within the framework. ### Federal Decree No. 35 of 2004 - URL: https://gcc-lexai.0xkaz.com/docs/433490aa-25f4-4d7a-b935-61954122ade4 - Issuing body: DIFC - Type: law - Topics: Financial Free Zones, DIFC, UAE Law - Applies to: Competent authorities within the UAE and entities operating within or regulated by the DIFC. Federal Decree No. 35 of 2004, issued by the President of the UAE, establishes the Dubai International Financial Centre (DIFC) as a financial free zone in the Emirate of Dubai. The decree mandates competent authorities to implement the provisions outlined within and ensures its publication in the official Gazette. Key requirements: - Establishment of the Dubai International Financial Centre (DIFC) - Implementation of the decree by competent authorities - Publication of the decree in the official Gazette ### Federal Law No. 8 of 2004 - URL: https://gcc-lexai.0xkaz.com/docs/64c3bd0f-fd7a-4a98-beff-e18c6f035474 - Issuing body: DIFC - Type: law - Topics: Financial Free Zones, Financial Regulation, Money Laundering, Licensing - Applies to: Financial Free Zones established in the UAE and the companies and establishments operating within them. Federal Law No. 8 of 2004 pertains to the establishment and regulation of Financial Free Zones within the UAE. It defines the scope of financial activities permitted within these zones and outlines the legal framework governing their operations. The law aims to regulate financial activities and ensure compliance with federal laws, particularly concerning money laundering. Key requirements: - Financial Free Zones and their operations must comply with Federal Law No. 4 of 2002 regarding Criminalisation of Money Laundering. - Companies and Establishments licensed in the Financial Free Zones cannot engage in deposit-taking from the State’s markets or deal in the UAE Dirham. - Licensing standards for Companies and Establishments in Financial Free Zones must be at least as stringent as those applicable in the State. ### cabinet resolution no 28 of 2007 english - URL: https://gcc-lexai.0xkaz.com/docs/44578b97-cd11-49ff-b156-78fe5a43991a - Issuing body: DIFC - Type: law - Date: 2007 - Topics: Financial Free Zones, Anti-Money Laundering, Counter-Terrorism Financing - Applies to: Financial Free Zones established in any Emirate of the UAE and entities operating within them. Cabinet Resolution No. 28 of 2007 outlines the implementing regulations for Federal Law No. 8 of 2004, concerning Financial Free Zones in the UAE. It defines key terms related to financial activities within these zones, establishes the legal framework for their operation, and emphasizes compliance with federal laws regarding money laundering and anti-terrorism financing. Key requirements: - Financial Free Zones must comply with federal laws concerning criminalization of money laundering and anti-terrorism finance. - A Financial Free Zone is established by federal decree and has a corporate body legally represented by the Chairman of its Board of Directors. - The location and area of a Financial Free Zone can be specified, added to, or changed by resolution of the Chairman of the Cabinet upon application of the concerned Free Zone. ### law 5 of 2021 concerning difc english 31012022 2 - URL: https://gcc-lexai.0xkaz.com/docs/8a1d3e58-546a-4e4c-aba4-8a03cb0a60f1 - Issuing body: DIFC - Type: law - Date: 2021 - Topics: Financial Regulation, DIFC Governance, Definitions - Applies to: Entities operating within or regulated by the Dubai International Financial Centre (DIFC), including the DIFCA, DFSA, and DIFC Courts. Law No. (5) of 2021 concerns the Dubai International Financial Centre (DIFC) and defines key terms related to its operation. It establishes the legal framework for the DIFC, referencing previous laws and regulations governing financial free zones and related bodies within the Emirate of Dubai. The law outlines the scope and definitions relevant to the DIFC's activities. Key requirements: - Reference must be made to the original Arabic text for interpretation and application of the law. - DIFC Bodies include the DIFCA, the DFSA, the DIFC Courts, and any other body established under the DIFC Laws, or established upon approval of the President as independent or affiliated entities of the said bodies. - Financial Services are defined as financial activities and services which require regulation by the DFSA under the DIFC Laws and the DIFC Regulations. ### AI Applications in Web3 SupTech and RegTech — A Regulatory Perspective (FSRA/ADGM) - URL: https://gcc-lexai.0xkaz.com/docs/84facf49-1584-4155-9c95-0b1917ef5481 - Issuing body: FSRA - Type: report - Date: 2025 - Topics: AI, RegTech, Web3, Digital Assets - Applies to: Financial institutions and technology developers operating within the ADGM regulatory framework, particularly those involved with Web3 technologies and virtual assets. This FSRA report explores the integration of Artificial Intelligence (AI) into regulatory technologies (RegTech) and supervisory technologies (SupTech) within the Web3 space. It discusses opportunities, innovations, challenges, and future directions of AI in regulating Web3 activities, including pilot programs conducted in ADGM. The report aims to enhance compliance monitoring and risk management in the evolving digital asset landscape. Key requirements: - Assess smart contract suitability using AI. - Utilize AI for audit report assessment. - Implement AI for smart due diligence. ### FSRA Consultation Paper No. 10 of 2025 — Proposed Framework for the Staking of Virtual Assets - URL: https://gcc-lexai.0xkaz.com/docs/279eb911-b10c-4a62-a34a-f371c249d84c - Issuing body: FSRA - Type: guidance - Date: 2025 - Topics: Virtual Assets, Staking, Financial Regulation, Abu Dhabi Global Market (ADGM) - Applies to: Authorised Persons carrying on Regulated Activities involving VAs, Applicants considering undertaking any of those activities, other Persons active in the digital asset sector including Staking Service Providers within ADGM, and their respective professional advisors. FSRA Consultation Paper No. 10 of 2025 outlines a proposed regulatory framework for the staking of Virtual Assets (VAs) within Abu Dhabi Global Market (ADGM). The paper seeks public comment on the proposed regulations and requirements for Authorized Persons involved in staking activities. It builds upon previous consultations and industry feedback. Key requirements: - Provide written comments to the FSRA by October 31, 2025. - Include the consultation paper number in the subject line of submitted comments. - Identify the organization represented when providing comments. - Expressly request confidentiality if you do not want your comments published. ### FSRA Consultation Paper No. 11 of 2024 — Proposed Amendments to the Digital Asset Regulatory Framework - URL: https://gcc-lexai.0xkaz.com/docs/8ea7bbcc-9b23-4da0-866b-0b01e0a78246 - Issuing body: FSRA - Type: guidance - Date: 2024 - Topics: digital assets, virtual assets, venture capital, financial regulation - Applies to: VA Firms, Authorised Persons intending to conduct Regulated Activities involving FRTs, Fund Managers of VC Funds, Applicants considering undertaking any of the foregoing activities, other Persons active in the VA sector, and their respective professional advisors within ADGM FSRA Consultation Paper No. 11 of 2024 outlines proposed amendments to the digital asset regulatory framework in Abu Dhabi Global Market (ADGM). It seeks public comment on revisions to the Virtual Asset (VA) framework, criteria for accepting Fiat-Referenced Tokens (FRTs), and expanding investment scope for Venture Capital Funds (VC Funds). The aim is to refine and update regulations for VA activities within ADGM. Key requirements: - Comply with revised processes for VA acceptance within ADGM. - Adhere to updated capital requirements and fees for VA Firms. - Meet the criteria for acceptance of Fiat-Referenced Tokens (FRTs) issued outside ADGM. - Comply with expanded investment scope for Venture Capital Funds (VC Funds). ### FSRA Guidance — Regulation of Virtual Asset Activities in ADGM - URL: https://gcc-lexai.0xkaz.com/docs/e0d5ac7a-0e6b-4af0-b6d7-91fea53c1e76 - Issuing body: FSRA - Type: guidance - Topics: Virtual Assets, AML/CFT, Technology Governance - Applies to: Authorised Persons engaged in Regulated Activities in relation to Virtual Assets within ADGM This FSRA guidance outlines the regulatory framework for virtual asset activities within the Abu Dhabi Global Market (ADGM). It details the Financial Services Regulatory Authority's (FSRA) approach to regulating virtual assets, covering authorized persons engaged in regulated activities related to virtual assets. The guidance aims to provide clarity on compliance expectations. Key requirements: - Comply with AML/CFT regulations. - Adhere to technology governance and control standards. - Meet capital requirements for virtual asset activities. ### UAE National Strategy for Artificial Intelligence 2031 - URL: https://gcc-lexai.0xkaz.com/docs/0a802710-f828-4769-9352-f4f09730219c - Issuing body: MoIAT - Type: strategy - Date: 2022 - Topics: AI strategy, AI governance, AI development, Talent development - Applies to: Government entities, businesses, educational institutions, and individuals involved in AI development and deployment within the UAE. The UAE National Strategy for Artificial Intelligence 2031 outlines the UAE's ambition to become a world leader in AI by investing in key sectors and talent. It aims to create economic, educational, and social opportunities, generating significant economic growth through AI adoption and development across various industries and government services. Key requirements: - Develop a reputation as an AI destination to attract investment and talent. - Increase the UAE's competitive assets in priority sectors through AI deployment. - Adopt AI across customer services to improve lives and government efficiency. ### Cabinet Decision No. 111/2022 on Virtual Assets and Their Service Providers - URL: https://gcc-lexai.0xkaz.com/docs/c02acbfc-9105-4e30-a361-57e627c53506 - Issuing body: SCA - Type: regulation - Date: 2022 - Topics: Virtual Assets, Regulation, Licensing, VASPs - Applies to: Virtual Asset Service Providers (VASPs) operating within the UAE, including Virtual Asset Platform Operators, brokers, and custodians. UAE Cabinet Decision No. 111/2022 establishes a regulatory framework for virtual assets and virtual asset service providers (VASPs) within the UAE. It defines key terms such as virtual assets, virtual asset activities, and VASPs, outlining the scope of regulation. The decision aims to regulate the provision of virtual asset services and related transactions within the UAE. Key requirements: - Licensing is required for engaging in virtual asset activities within the UAE. - Virtual Asset Platform Operators must be licensed by the Authority. - VASPs are defined as legal persons engaging in activities related to virtual assets for or on behalf of a person. - Virtual Asset Platforms are defined as digital platforms for listing, trading, and transferring ownership of Virtual Assets. ### SCA Guidelines for Regulation of Virtual Assets and Virtual Asset Service Providers - URL: https://gcc-lexai.0xkaz.com/docs/eab61e27-d7c9-4019-a044-d1a8459e437c - Issuing body: SCA - Type: guidance - Topics: Virtual Assets Regulation, VASP Licensing, AML/CFT, Cybersecurity - Applies to: Virtual Assets (VAs) and Virtual Assets Services Providers (VASPs) operating in the UAE, with the exception of financial free zones, including virtual asset platform operators, safe custody providers, financial consultants in virtual assets, virtual asset portfolio managers, virtual asset brokers, and virtual asset dealers. The SCA Guidelines provide a regulatory framework for Virtual Assets (VAs) and Virtual Asset Service Providers (VASPs) in the UAE, excluding financial free zones. Issued under Cabinet Resolution No. (111) of 2022, these guidelines detail licensing requirements, operational standards, and obligations for entities dealing with VAs as investment instruments, aiming to ensure market integrity and investor protection. Key requirements: - Virtual asset activities are subject to licensing, including platform operation, safe custody, financial consulting, portfolio management, brokerage, and dealing. - Licensed bodies must implement robust technology governance, security procedures, and measures for cryptographic keys and wallets storage. - VASPs are obligated to protect client funds, disclose virtual asset risks, and comply with anti-money laundering (AML), combating the financing of terrorism (CFT), and sanctions evasion requirements. - Specific requirements are outlined for virtual asset platform operators regarding operational efficiency, integrity, transparency, and trading regulation. - Licensed bodies must protect individual data and adhere to rules regarding transactions with unknown counterparties and margin trading. ### Decision of the Supreme Committee for the Supervision of the Telecommunications Sector No 3 of 2004 - URL: https://gcc-lexai.0xkaz.com/docs/17a801fc-0825-4c27-86a7-e55776f163fc - Issuing body: TDRA - Type: regulation - Topics: telecommunications, regulation, definitions - Applies to: Telecommunications operators and entities within the UAE Decision No. 3 of 2004 from the UAE's Supreme Committee for the Supervision of the Telecommunications Sector issues the Executive Order of Federal Law by Decree No. 3 of 2003, which concerns the organization of the telecommunications sector. The document defines key terms and provides interpretations related to the Federal Law by Decree No. (3) of 2003. Key requirements: - Expressions and wordings in Federal Law by Decree No. (3) of 2003 shall have the same meanings as ascribed in that decree. - The Authority is defined as the General Authority for Regulating the Telecommunication Sector. - Interconnection is defined as the linking of Telecommunication Networks to allow users to communicate with each other. - Private Telecommunication Network is defined as a network operated exclusively to serve the requirements of one person or a group of persons with common ownership. ### Final TDRA telecom law Final english o 02 07 2022 W OUT Bleed - URL: https://gcc-lexai.0xkaz.com/docs/d856dc35-1473-40d3-a48b-d8516a706fdf - Issuing body: TDRA - Type: regulation - Date: 2022 - Topics: Telecommunications Regulation, UAE Law, TDRA - Applies to: Telecommunications operators and service providers operating within the UAE This document from the TDRA of the UAE pertains to the regulation of the telecommunications sector. It references Federal Law by Decree No. (3) of 2003, as amended, which serves as the foundation for this regulation. The document outlines various aspects related to the oversight and governance of telecommunications activities within the UAE. Key requirements: - Compliance with Federal Law by Decree No. (3) of 2003 - Adherence to regulations set forth by the TDRA - Regulation of activities within the telecommunications sector ### VARA Company Rulebook — General Requirements for Licensed VA Activities - URL: https://gcc-lexai.0xkaz.com/docs/92748f32-4a6c-43ba-ae9c-c30a98a58d69 - Issuing body: VARA - Type: regulation - Topics: virtual assets, virtual asset platforms, regulation - Applies to: Virtual Asset Service Providers operating in the Emirate of Dubai The VARA Company Rulebook outlines general requirements for licensed Virtual Asset (VA) activities in the Emirate of Dubai, UAE, as regulated by the Dubai Virtual Assets Regulatory Authority (VARA). It is based on Law No. (4) of 2022, which regulates virtual assets within Dubai and defines key terms like Virtual Assets, Virtual Tokens, and Virtual Asset Platforms. Key requirements: - Compliance with Law No. (4) of 2022 Regulating Virtual Assets in the Emirate of Dubai - Adherence to VARA's determinations regarding digital representations of value - Operation of Virtual Asset Platforms must be managed by a Virtual Asset Service Provider ### VARA Compulsory Rulebook — Broker-Dealer Services - URL: https://gcc-lexai.0xkaz.com/docs/0e0b8adc-c808-4f2c-b7a3-a804d202b5aa - Issuing body: VARA - Type: regulation - Topics: Virtual Assets, Marketing Regulation, Enforcement, Penalties - Applies to: Entities involved in marketing, promotion, or advertising of virtual assets in Dubai under VARA's jurisdiction. This VARA (Dubai Virtual Assets Regulatory Authority) document outlines penalties and enforcement measures for violations of marketing regulations related to virtual assets. It details actions VARA can take, including warnings, fines, suspension of marketing activities, license revocation, and public statements, for entities failing to comply with marketing and advertising rules. Key requirements: - Ensure marketing materials meet the requirements of paragraphs II.1 and II.5 of the Marketing Regulation. - Comply with cease and desist warnings issued by VARA. - Refrain from violations that may lead to penalties, including fines and suspension of activities. ### VARA Compulsory Rulebook — Custody Services - URL: https://gcc-lexai.0xkaz.com/docs/9733d3f8-4222-45f0-a1d3-07978ed5cf25 - Issuing body: VARA - Type: regulation - Topics: Virtual Assets, Custody Services, Staking, Regulation - Applies to: Virtual Asset Service Providers (VASPs) licensed by VARA in Dubai, UAE, that offer custody services for virtual assets. This VARA rulebook outlines the regulatory framework for custody services related to virtual assets in Dubai, UAE. It establishes requirements for board oversight, policies, procedures, public disclosures, and the storage and custody of virtual assets. The rulebook also covers staking from custody services and collateral wallet services, ensuring client protection and market integrity. Key requirements: - Custodians must adhere to specific requirements for VA wallet management, including private key protection and transaction monitoring. - Custodians must segregate and control client virtual assets to prevent commingling and unauthorized use. - Custodians offering staking services must comply with rules related to client instructions, segregation of assets, and node management. - Custodians must provide a risk disclosure statement to clients engaging in staking activities. ### VARA Compulsory Rulebook — Exchange Services - URL: https://gcc-lexai.0xkaz.com/docs/b88299f9-37ef-464e-ab86-609e9f6e12a6 - Issuing body: VARA - Type: regulation - Topics: Virtual Assets, Exchange Services, Margin Trading, Market Surveillance - Applies to: Virtual Asset Exchange Service Providers licensed by VARA in Dubai, UAE This VARA rulebook outlines the regulatory requirements for Virtual Asset Exchange Services in Dubai, UAE. It establishes rules related to board composition, policies, procedures, public disclosures, trading venue participants, market surveillance, business continuity, settlement, and margin trading. The rulebook aims to ensure fair and transparent operations of virtual asset exchanges. Key requirements: - Exchanges must establish and maintain policies and procedures related to risk management, AML/CFT, and cybersecurity. - Exchanges must conduct market surveillance and report suspicious activities to VARA. - Exchanges must have a business continuity plan to ensure continued operation in the event of disruptions. ### VARA Compulsory Rulebook — Lending and Borrowing Services - URL: https://gcc-lexai.0xkaz.com/docs/0fc1a184-beda-48de-add7-8157673d209a - Issuing body: VARA - Type: regulation - Topics: virtual assets, lending and borrowing, regulatory compliance, risk management - Applies to: Virtual Asset Service Providers (VASPs) licensed by VARA to carry out Lending and Borrowing Services in the Emirate of Dubai This document, issued by the Dubai Virtual Assets Regulatory Authority (VARA), outlines the rules for Virtual Asset Service Providers (VASPs) licensed to conduct Lending and Borrowing Services in Dubai. It supplements the Virtual Assets and Related Activities Regulations 2023 and other VARA rulebooks, establishing specific requirements for these services. Key requirements: - VASPs must establish policies and procedures related to lending and borrowing services. - VASPs must provide public disclosures, including activity-specific disclosures. - VASPs must adhere to client reporting and valuation requirements. - VASPs must fulfill additional record-keeping requirements. - VASPs must implement risk management and due diligence processes. ### VARA Compulsory Rulebook — Management and Investment Services - URL: https://gcc-lexai.0xkaz.com/docs/9a8876a0-1c96-4a7b-93f8-0384570df6d1 - Issuing body: VARA - Type: regulation - Topics: virtual assets, transfer services, settlement services, VARA regulation - Applies to: VASPs licensed by VARA to carry out VA Transfer and Settlement Services in and/or from the Emirate of Dubai This document, issued by Dubai's Virtual Assets Regulatory Authority (VARA), outlines the rules for Virtual Asset (VA) Transfer and Settlement Services. It applies to all Virtual Asset Service Providers (VASPs) licensed by VARA to conduct these services in or from Dubai. The rulebook supplements existing regulations and other VARA rulebooks applicable to all VASPs. Key requirements: - VASPs must establish policies and procedures for VA transfer and settlement services. - VASPs must provide public disclosures related to their VA transfer and settlement services. - VASPs must ensure the protection of client Virtual Assets and property interests. - VASPs must obtain authorization and ensure responsibility for transmissions, transfers, and settlements. - VASPs must provide client disclosures related to VA transfer and settlement services. ### VARA Compulsory Rulebook — Payment and Remittance Services - URL: https://gcc-lexai.0xkaz.com/docs/a339a2b2-bb79-41bb-b351-e3411d2b9604 - Issuing body: VARA - Type: regulation - Topics: grievance, virtual assets, regulatory enforcement - Applies to: Parties in the virtual asset sector subject to VARA regulations in Dubai Administrative Resolution No. (01) of 2023 establishes the VARA Grievance Committee to address grievances from parties in the virtual asset sector. The committee will review actions, penalties, or sanctions imposed under applicable legislation and related to VARA inspections. The resolution outlines the committee's formation, membership, meeting procedures, and decision-making processes. Key requirements: - The VARA Grievance Committee is formed to consider grievances related to actions, penalties, or sanctions imposed under VARA legislation. - The Committee consists of the Managing Director, a member of the Executive Board and CEO of Regulatory Policy and Governance, and the Chief Executive Officer of VARA. - Committee decisions require a simple majority and must adhere to the grievance period outlined in Law No. (4) of 2022. - The Committee has the discretion to cancel or modify decisions related to sanctions, penalties, or fines for violations of the Legislation. ### VARA Compulsory Rulebook — VA Issuance Activities - URL: https://gcc-lexai.0xkaz.com/docs/f0fb4f7a-0a98-4378-88b8-304277476b99 - Issuing body: VARA - Type: regulation - Topics: virtual assets, marketing, advertising, promotions - Applies to: Any legal entity or individual providing or facilitating Virtual Asset services in the Emirate of Dubai. Administrative Order 01/2022, issued by the Dubai Virtual Assets Regulatory Authority (VARA), regulates the marketing, advertising, and promotion of virtual assets and related activities within the Emirate of Dubai, excluding the Dubai International Financial Centre. It aims to provide a clear framework for responsible advertising and promotion of virtual assets. Key requirements: - The regulation applies to all marketing, promotions, and advertisements related to Virtual Assets (VA) or VA Activities in the Emirate of Dubai. - Marketing includes communications, publications, promotional material across media channels, social media posts, and advertisements. - Activities held in the Emirate to encourage market participation in the VA sector are covered, specifically those soliciting clients or incentivizing purchase of VA products/services. ### VARA Marketing Regulations 2024 - URL: https://gcc-lexai.0xkaz.com/docs/3b521e60-4a09-4b5a-b14f-5608c723ad7d - Issuing body: VARA - Type: regulation - Date: 2024 - Topics: virtual assets, marketing, regulation - Applies to: Virtual Asset Service Providers (VASPs) and any entity marketing virtual assets or related activities within the Emirate of Dubai, excluding the Dubai International Financial Centre. The VARA Marketing Regulations 2024 outlines the rules for marketing virtual assets and related activities within the Emirate of Dubai. Issued by the Virtual Assets Regulatory Authority (VARA), the regulations aim to regulate Virtual Assets and Virtual Asset Service Providers (VASPs) and promote Dubai as a regional hub for virtual assets. Key requirements: - Marketing must not target inexperienced investors. - Marketing communications must be truthful, avoid misleading information, and be clearly identifiable as marketing. - Marketing must include risk warnings and disclaimers as specified by VARA. ### VARA Virtual Assets and Related Activities Regulations 2023 - URL: https://gcc-lexai.0xkaz.com/docs/55d68eea-6865-4482-bc68-b52eebe4b366 - Issuing body: VARA - Type: regulation - Date: 2023 - Topics: virtual assets, licensing, regulation, data protection - Applies to: Virtual Asset Service Providers (VASPs) operating within the Emirate of Dubai and its free zones Cabinet Decision No. 112/2022 delegates certain competencies related to the regulation of virtual assets to the Dubai Virtual Assets Regulatory Authority (VARA). VARA is authorized to license, supervise, and control virtual asset activities and service providers within the Emirate of Dubai and its free zones, ensuring compliance with relevant legislation and international requirements. Key requirements: - License virtual asset activities and supervise service providers within Dubai and its free zones. - Issue decisions regulating virtual asset transactions and licensing service providers, consistent with Cabinet Decision No. 111/2022. - Verify compliance with personal data protection legislation. - Implement evaluation and monitoring mechanisms for controls and requirements on virtual asset service providers. - Ensure fulfillment of licensing requirements for virtual asset service providers as stipulated in Cabinet Decision No. 111/2022. ## Saudi Arabia (23 documents) ### Corporate Governance Regulations (CMA Saudi Arabia, 2023) - URL: https://gcc-lexai.0xkaz.com/docs/3774ab34-16a3-438d-872e-985e4495bc4f - Issuing body: CMA - Type: regulation - Date: 2023 - Topics: Corporate Governance, Shareholder Rights, Board of Directors, Conflict of Interest - Applies to: Companies listed on the Saudi Stock Exchange (Tadawul) and other entities subject to CMA oversight in Saudi Arabia. The Corporate Governance Regulations issued by the Capital Market Authority (CMA) of Saudi Arabia establish a framework for corporate governance practices within companies. These regulations aim to protect shareholder rights, define the responsibilities and competencies of the board of directors, and address conflicts of interest to ensure transparency and accountability. Key requirements: - Fair treatment of all shareholders, including equal rights related to shares and access to information. - Establishment of a competent and responsible board of directors with clearly defined roles, responsibilities, and duties. - Implementation of policies and procedures to identify, manage, and disclose conflicts of interest. - Mandatory training and assessment programs for board members to enhance their knowledge and skills. ### Investment Law of the Kingdom of Saudi Arabia (2025) - URL: https://gcc-lexai.0xkaz.com/docs/06b286d9-ed25-4d06-ab50-83e9d0190922 - Issuing body: CMA - Type: guidance - Date: 2025 - Topics: investment law, foreign investment, investor rights, economic development - Applies to: Local and foreign investors in the Kingdom of Saudi Arabia The Investment Law of the Kingdom of Saudi Arabia (2025) aims to enhance the investment environment and promote economic development by establishing a favorable ecosystem for both local and foreign investors. It outlines the scope of investment activities, investor rights and obligations, and incentives, replacing the previous Foreign Investment Law. Key requirements: - Adherence to all laws and regulations applicable in the Kingdom - Adherence to the Kingdom’s international commitments - Foreign investors may be restricted from engaging in certain activities determined by the Permanent Ministerial Committee for the Examination of Foreign Investments - Investors must allow the Ministry of Investment to provide available data and statistics, essential services, and resolution of their complaints ### Saudi Arabia Digital Transformation and Regulatory Framework (ITU) - URL: https://gcc-lexai.0xkaz.com/docs/e3be30fd-252e-46e5-9cbd-7439ca78139e - Issuing body: CST - Type: report - Topics: digital transformation, regulation, telecommunications, collaborative regulation - Applies to: Organizations and individuals copying, redistributing, or adapting the ITU report on Saudi Arabia's digital transformation. This report by the International Telecommunication Union (ITU) examines Saudi Arabia's digital transformation and regulatory landscape. It analyzes the country's progress towards its digital goals and provides insights into collaborative regulation approaches. The document serves as a case study for other countries pursuing digital transformation. Key requirements: - Adherence to the Creative Commons Attribution-Non-Commercial-Share Alike 3.0 IGO license for copying, redistribution, and adaptation of the work. - Appropriate citation of the work when used. - Avoidance of suggesting ITU endorsement of specific organizations, products, or services. - Licensing adapted works under the same or equivalent Creative Commons license. ### Cloud Cybersecurity Controls (CCC-2: 2024) - URL: https://gcc-lexai.0xkaz.com/docs/f17254b8-6c8e-4093-9201-e7867cfc0a62 - Issuing body: NCA - Type: framework - Date: 2024 - Topics: cloud security, cybersecurity framework, regulatory compliance - Applies to: Organizations utilizing cloud services within the Kingdom of Saudi Arabia The Cloud Cybersecurity Controls (CCC-2: 2024) framework, issued by the NCA of Saudi Arabia, outlines cybersecurity controls for cloud services. It aims to establish a baseline for cloud security practices within the Kingdom, updating the previous version (CCC-1: 2020) to reflect current cybersecurity requirements and industry updates. The Arabic version of the document is the binding version. Key requirements: - Implement controls in accordance with the laws of the Kingdom of Saudi Arabia. - Adhere to the Arabic version of the document for interpretation. - Comply with updated versions of the CCC as published by the NCA. ### Cloud Cybersecurity Controls Implementation Guide for CSPs - URL: https://gcc-lexai.0xkaz.com/docs/03ee6424-5c06-4dc3-b647-18ea8fb63476 - Issuing body: NCA - Type: guidance - Topics: Cloud Security, Cybersecurity Governance, Risk Management, Access Management - Applies to: Cloud Service Providers (CSPs) operating in Saudi Arabia This document, the "Cloud Cybersecurity Controls Implementation Guide for CSPs (GCCC-CSP)", provides guidance to Cloud Service Providers (CSPs) on implementing cybersecurity controls. It outlines a structure of cybersecurity domains and subdomains, offering implementation guidance to enhance the security posture of CSPs operating within Saudi Arabia. Key requirements: - Implement cybersecurity risk management processes. - Comply with cybersecurity standards, laws, and regulations. - Manage identity and access. - Protect information systems and processing facilities. ### Cloud Cybersecurity Controls Implementation Guide for CSTs - URL: https://gcc-lexai.0xkaz.com/docs/ba6f9a9d-58fa-4f3f-8c31-1ef703b8058a - Issuing body: NCA - Type: guidance - Topics: Cloud Security, Cybersecurity Governance, Risk Management, Access Management - Applies to: Cloud Service Tenants (CSTs) in Saudi Arabia This document, titled "Cloud Cybersecurity Controls Implementation Guide for CSTs (GCCC-CST)," provides guidance on implementing cloud cybersecurity controls for cloud service tenants in Saudi Arabia. It outlines objectives, scope, and applicability, covering various cybersecurity domains and their structure to ensure a secure cloud environment. The guide aims to help tenants understand and implement necessary security measures. Key requirements: - Implement cybersecurity roles and responsibilities. - Manage cybersecurity risks effectively. - Comply with cybersecurity standards, laws, and regulations. - Manage identity and access control. - Protect information systems and processing facilities. ### Critical Systems Cybersecurity Controls (CSCC-1: 2019) - URL: https://gcc-lexai.0xkaz.com/docs/2d03a289-69c5-4c7d-9c37-02a2a8803ada - Issuing body: NCA - Type: framework - Date: 2019 - Topics: cybersecurity, critical infrastructure, governance, resilience - Applies to: Organizations operating critical systems within the Kingdom of Saudi Arabia The Critical Systems Cybersecurity Controls (CSCC-1: 2019) framework, issued by the NCA of Saudi Arabia, outlines cybersecurity controls for critical systems. It provides a structure for establishing and maintaining cybersecurity governance, defense, and resilience, including third-party and cloud computing considerations. The framework aims to protect critical infrastructure and sensitive data within the Kingdom. Key requirements: - Establish cybersecurity governance frameworks. - Implement cybersecurity defense mechanisms. - Ensure cybersecurity resilience. - Address third-party and cloud computing cybersecurity risks. ### Critical Systems Cybersecurity Controls Implementation Guidelines - URL: https://gcc-lexai.0xkaz.com/docs/ef2d9fc5-f878-42f0-9347-d165e9c7e932 - Issuing body: NCA - Type: guidance - Topics: cybersecurity, risk management, critical infrastructure, governance - Applies to: Organizations responsible for critical systems in Saudi Arabia This document provides guidelines for implementing cybersecurity controls for critical systems in Saudi Arabia. It outlines general guidelines and specific controls related to cybersecurity governance, risk management, and resilience. The document aims to help organizations protect their critical systems from cyber threats and ensure business continuity. Key requirements: - Implement cybersecurity risk management processes. - Establish and maintain identity and access management controls. - Implement data and information protection measures. - Conduct periodical cybersecurity reviews and audits. ### Data Cybersecurity Controls (DCC-1: 2022) - URL: https://gcc-lexai.0xkaz.com/docs/254a4c7d-6d5b-4dcd-a597-de61456ac44c - Issuing body: NCA - Type: framework - Date: 2022 - Topics: cybersecurity governance, data protection, cloud security, third-party risk - Applies to: Organizations handling data within the Kingdom of Saudi Arabia The Data Cybersecurity Controls (DCC-1: 2022) framework, issued by the NCA in Saudi Arabia, establishes cybersecurity controls for data protection. It outlines requirements for cybersecurity governance, defense, and third-party/cloud computing cybersecurity. The framework aims to safeguard data assets in accordance with Saudi Arabian laws and regulations. Key requirements: - Implement cybersecurity governance controls. - Establish cybersecurity defense mechanisms. - Apply cybersecurity measures for third-party and cloud computing. - Comply with the Data Cybersecurity Controls (DCC-1: 2022) ### Essential Cybersecurity Controls (ECC-2: 2024) - URL: https://gcc-lexai.0xkaz.com/docs/878b8da4-a2c4-4ab3-82a9-1d64e464d761 - Issuing body: NCA - Type: framework - Date: 2024 - Topics: cybersecurity, risk management, compliance - Applies to: Organizations operating within the Kingdom of Saudi Arabia The Essential Cybersecurity Controls (ECC-2: 2024) framework, issued by the National Cybersecurity Authority (NCA) of Saudi Arabia, provides a set of cybersecurity controls. It aims to protect organizations from cyber threats and ensure compliance with national cybersecurity standards. The Arabic version of the document is the binding language. Key requirements: - Implement cybersecurity controls in accordance with the laws of the Kingdom of Saudi Arabia. - Adhere to the Traffic Light Protocol (TLP) for sharing sensitive data. - Implement the updated version of ECC as per the cybersecurity requirements and related industry updates. ### Guide to Essential Cybersecurity Controls (ECC) Implementation - URL: https://gcc-lexai.0xkaz.com/docs/e6ce1dd7-bc20-4478-bc30-fc5a7f03834b - Issuing body: NCA - Type: guidance - Topics: cybersecurity controls, risk management, regulatory compliance - Applies to: Organizations operating in Saudi Arabia This document, issued by the National Cybersecurity Authority (NCA) of Saudi Arabia, provides guidance for organizations on implementing the Essential Cybersecurity Controls (ECC). It serves as an illustrative model to help organizations meet ECC requirements, while emphasizing the need to consider their unique environments. The document outlines the ECC domains and structure to aid in implementation. Key requirements: - Organizations must consider their unique requirements when implementing ECC. - Organizations must not rely solely on this guide to implement the ECC. - Organizations must ensure other methods of implementation do not conflict with NCA requirements. ### Operational Technology Cybersecurity Controls (OTCC-1: 2022) - URL: https://gcc-lexai.0xkaz.com/docs/a01982d0-1705-4663-9e0f-53bd39b77f22 - Issuing body: NCA - Type: framework - Date: 2022 - Topics: Operational Technology, Cybersecurity, Industrial Control Systems, Risk Management - Applies to: Organizations operating Industrial Control Systems (ICS) within the Kingdom of Saudi Arabia. The Operational Technology Cybersecurity Controls (OTCC-1: 2022) framework, issued by the National Cybersecurity Authority (NCA) in Saudi Arabia, establishes cybersecurity controls for Industrial Control Systems (ICS). It aims to address the increasing cyber threats targeting these systems and provides a structured approach to implementing and monitoring cybersecurity measures within the Kingdom. Key requirements: - Implement cybersecurity controls tailored for Industrial Control Systems (ICS). - Comply with the OTCC framework as governed by the laws of the Kingdom of Saudi Arabia. - Adhere to the Arabic version of the document as the binding language for interpretation. - Share information according to the Traffic Light Protocol (TLP) designations (Red, Amber, Green, White). ### Operational Technology Cybersecurity Controls Implementation Guide - URL: https://gcc-lexai.0xkaz.com/docs/2fddc446-adb7-4549-9832-b3eaba1c9309 - Issuing body: NCA - Type: guidance - Topics: operational technology, cybersecurity, governance - Applies to: Organizations operating and maintaining Operational Technology (OT) infrastructure in Saudi Arabia This document, titled "Operational Technology Cybersecurity Controls Implementation Guide," provides guidance on implementing cybersecurity controls for Operational Technology (OT) environments. It outlines general guidelines and specific controls related to cybersecurity governance. The document is intended for public use and aims to improve OT cybersecurity posture. Key requirements: - Establish and maintain a cybersecurity governance framework for OT. - Implement specific cybersecurity controls across various OT domains and subdomains. - Adhere to general guidelines for OTCC implementation. ### Telework Cybersecurity Controls (TCC-1: 2021) - URL: https://gcc-lexai.0xkaz.com/docs/1b79a0af-8702-487a-990a-49cb553326f7 - Issuing body: NCA - Type: framework - Date: 2021 - Topics: cybersecurity, telework, risk management, compliance - Applies to: Entities in the Kingdom of Saudi Arabia that utilize telework systems. The Telework Cybersecurity Controls (TCC-1: 2021) framework, issued by the NCA in Saudi Arabia, establishes cybersecurity requirements for telework systems to mitigate increasing threats and cyber risks associated with remote work environments. It aims to promote economic development and productivity by enabling secure telework practices in accordance with Saudi Arabian laws. The Arabic version of the document is the binding version. Key requirements: - Implement cybersecurity controls to reduce threats and risks to telework systems. - Comply with the TCC domains and structure as outlined in the document. - Adhere to the sharing notice classifications (Red, Amber, Green, White) when disseminating information. - Implement controls in accordance with the laws of the Kingdom of Saudi Arabia. ### Implementing Regulation of Finance Companies Control Law - URL: https://gcc-lexai.0xkaz.com/docs/cb191772-7afc-412a-bfb5-ccd9558af1c9 - Issuing body: SAMA - Type: regulation - Topics: Finance, Regulation, Licensing, SAMA - Applies to: Finance Companies licensed to carry out Finance activity in Saudi Arabia This document is the Implementing Regulation of the Finance Companies Control Law in Saudi Arabia, issued by SAMA. It defines key terms related to finance activities, outlines SAMA's role in organizing and supervising the finance sector, and sets forth general provisions for finance companies operating within the Kingdom. The regulation aims to provide clarity and structure to the finance industry. Key requirements: - Finance Companies must be licensed by SAMA to carry out finance activities. - Finance Companies must adhere to the definitions and provisions outlined in the Regulation. - SAMA shall supervise the business of Finance Companies in accordance with the Law and the Regulation. ### Implementing Regulation of Law of Payments and Payment Services - URL: https://gcc-lexai.0xkaz.com/docs/88013995-8e99-4b00-9aa3-a248691ce99f - Issuing body: SAMA - Type: regulation - Topics: Payment Services, Licensing, Consumer Protection, Payment Systems - Applies to: Payment services providers licensed by SAMA, agents and electronic money distributors This document is the Implementing Regulation of the Law of Payments and Payment Services issued by the Saudi Central Bank (SAMA). It outlines the rules and guidelines for payment services within Saudi Arabia, covering licensing, agent obligations, consumer protection, payment systems, and dispute resolution. The regulation aims to ensure the stability and security of payment services while promoting financial inclusion. Key requirements: - Licensees must adhere to outsourcing rules, auditing standards, and risk management protocols. - Licensees must meet specific requirements for providing payment initiation services and payment account information services. - Licensees must safeguard safeguarded funds according to the regulations. - Systemically important payment systems must adhere to PFMI requirements. ### Open Banking Policy - URL: https://gcc-lexai.0xkaz.com/docs/13bdcc11-186c-4efa-a02d-783d59ec6df6 - Issuing body: SAMA - Type: policy - Topics: open banking, financial innovation, data sharing, financial services - Applies to: Banks, fintechs, and other financial players in Saudi Arabia This Open Banking Policy from the Saudi Central Bank (SAMA) outlines the initiative to develop open banking services in Saudi Arabia, aligning with Saudi Vision 2030 and the Financial Sector Development Program. It aims to foster innovation, enable secure data sharing with third parties, and enhance financial services for customers through collaboration between banks, fintechs, and other financial players. Key requirements: - Securely share customer data with third parties with explicit and informed consent. - Leverage data associated with financial transactions to create new ways of managing money. - Enhance trust between customers and market participants. ### Payment Services Provider Regulations - URL: https://gcc-lexai.0xkaz.com/docs/8f502ae1-d8db-4df1-af1b-782171d34b91 - Issuing body: SAMA - Type: regulation - Topics: Payment Services, Licensing, SAMA Regulations - Applies to: Payment service providers operating in Saudi Arabia, including Micro PIs, Major PIs, Micro EMIs, and Major EMIs. This document outlines the Payment Services Provider Regulations issued by the Saudi Arabian Monetary Authority (SAMA). It establishes the licensing requirements and operational guidelines for payment service providers operating within Saudi Arabia. The regulations cover various aspects, including licensing procedures for different types of providers and the scope of permissible payment services. Key requirements: - Obtain a license from SAMA to operate as a payment service provider. - Comply with specific licensing requirements based on the type of payment service offered (Micro PI, Major PI, Micro EMI, Major EMI). - Meet common requirements for all applicants, including providing necessary documentation and information. - Adhere to SAMA's evaluation criteria during the licensing application process. ### Regulatory Sandbox Framework - URL: https://gcc-lexai.0xkaz.com/docs/d34a0781-92dd-4d6d-a8cb-e37aaf608592 - Issuing body: SAMA - Type: framework - Topics: FinTech, Regulatory Sandbox, Innovation, Financial Services - Applies to: Local and international financial services firms wishing to test new digital solutions in Saudi Arabia. This Saudi Central Bank (SAMA) framework establishes a Regulatory Sandbox to foster financial technology (FinTech) innovation in line with the Kingdom's Vision 2030. It provides a 'safe space' for firms to test new digital solutions under specific conditions and limitations, allowing them to assess the impact of new technologies in the KSA’s financial services market. Key requirements: - Firms must apply to SAMA to participate in the Regulatory Sandbox. - Firms must adhere to customer safeguards deployed within the Sandbox. - Firms must undergo testing of their solutions within a controlled environment for a specified period. - Firms must exit the Sandbox according to SAMA's guidelines. ### SAMA Cyber Security Framework - URL: https://gcc-lexai.0xkaz.com/docs/43878ad8-5368-456d-8906-01f58412796b - Issuing body: SAMA - Type: framework - Topics: cyber security, risk management, governance, maturity assessment - Applies to: Saudi Arabian Banking, Insurance and Financing Companies sectors The SAMA Cyber Security Framework provides guidance and controls for regulated entities in Saudi Arabia to establish robust cyber security governance, infrastructure, and detective/preventive controls. It aims to ensure that the Saudi Arabian Banking, Insurance, and Financing Companies sectors can effectively manage and withstand cyber security threats through a common approach and maturity assessment. Key requirements: - Adoption and implementation of the Framework - Full support and oversight from the Board of Directors and Senior Management - Self-assessment, review and audit of cyber security measures - Achieve a defined Cyber Security Maturity Level ### AI Law in Saudi Arabia — In-Depth Analysis (Latham & Watkins / Lexology) - URL: https://gcc-lexai.0xkaz.com/docs/cadb0df4-530b-42e3-84d2-de7162301b12 - Issuing body: SDAIA - Type: analysis - Topics: AI ethics, Intellectual property, Data privacy, AI regulation - Applies to: AI developers, researchers, and organizations operating in Saudi Arabia This document analyzes the developing AI legal landscape in Saudi Arabia, focusing on the Saudi Data and Artificial Intelligence Authority's (SDAIA) role in promoting AI adoption and establishing a regulatory environment. It highlights key developments such as the draft amendments to intellectual property legislation and the issuance of the AI Ethics Principles. Key requirements: - Adherence to the AI Ethics Principles issued by SDAIA. - Compliance with intellectual property laws related to AI. - Consideration of data privacy regulations when developing and deploying AI. ### National Strategy for Data and AI 2020 (Saudi Arabia) - URL: https://gcc-lexai.0xkaz.com/docs/70192320-7d01-44e0-af76-e6564f76e675 - Issuing body: SDAIA - Type: strategy - Date: 2020 - Topics: Data strategy, AI strategy, Economic development, Digital transformation - Applies to: All stakeholders involved in the KSA Data & AI ecosystem, including government entities, private sector companies, research institutions, and individuals. The National Strategy for Data & AI, developed by SDAIA, outlines Saudi Arabia's vision to become a leading data-driven economy. It aims to maximize data collection, processing, and integration to develop AI solutions and improve public services. The strategy focuses on national priorities by 2025, building competitive advantages by 2030, and becoming a leading economy utilizing and exporting Data & AI after 2030. Key requirements: - Establish KSA as a global hub where the best of Data & AI is made reality. - Address national priorities by 2025 through Data & AI initiatives. - Build foundations for competitive advantage in key niche areas by 2030. - Become one of the leading economies utilizing and exporting Data & AI after 2030. ### Saudi Arabia Data Privacy Handbook 2023 (PwC) - URL: https://gcc-lexai.0xkaz.com/docs/c483de1f-be0c-4cfc-be0a-aa16131d089e - Issuing body: SDAIA - Type: guidance - Date: 2023 - Topics: data privacy, data protection, PDPL compliance - Applies to: All organizations processing personal data and operating in or doing business with Saudi Arabia This handbook, published by PwC, serves as a starter guide for organizations to comply with the Saudi Arabia Personal Data Protection Law (PDPL). It explains key concepts, principles, and steps for building effective data privacy programs in accordance with the PDPL, which came into force on September 14, 2023, with full enforceability starting September 14, 2024. Key requirements: - Organizations need to be transparent about what personal data they are capturing and how it is going to be used. - Organizations need to develop data privacy programmes to meet the requirements of the PDPL. - Organizations need to process personal data in an ethical and legal manner. - Organizations need to implement necessary controls or safeguards when sharing personal data with third parties. ## Bahrain (13 documents) ### CBB Rulebook Vol. 4 — Cyber Security Risk Management Module - URL: https://gcc-lexai.0xkaz.com/docs/957ffff2-b6cd-47f2-a422-9a2247b744a1 - Issuing body: CBB - Type: regulation - Date: 2021 - Topics: cyber security, risk management, investment firms, board responsibilities - Applies to: Category 1 and Category 2 investment firm licensees, and Category 3 investment firm licensees providing digital financial advice This Central Bank of Bahrain (CBB) regulation outlines requirements for cyber security risk management for investment firms. It mandates a robust framework to manage cyber security risks and vulnerabilities, including a cyber security strategy, policy, and risk management approach. The regulation aims to ensure the protection of financial institutions and their customers from cyber threats. Key requirements: - Investment firms must establish a robust cyber security risk management framework. - The Board must approve the cyber security policy and establish clear accountability for cyber risks. - The cyber security risk management framework must be developed in accordance with the NIST Cyber security framework. - Boards must receive comprehensive reports on cyber security issues in every Board meeting. - The Board must evaluate and approve the cyber security risk management framework every three years. ### CBB Rulebook Vol. 5 — Open Banking Regulatory Module 2023 - URL: https://gcc-lexai.0xkaz.com/docs/073d70ec-afff-4335-a4f6-f85d5a2c8075 - Issuing body: CBB - Type: regulation - Date: 2023 - Topics: Open Banking, API Security, Data Security, Customer Protection - Applies to: Ancillary service providers including Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs) operating in Bahrain. This Central Bank of Bahrain (CBB) regulation outlines the framework for Open Banking, focusing on ancillary service providers like Account Information Service Providers (AISPs) and Payment Initiation Service Providers (PISPs). It establishes regulatory standards to ensure the security and integrity of customer data when accessing accounts through APIs, emphasizing risk management and customer protection. Key requirements: - AISPs and PISPs must adhere to the Bahrain Open Banking Framework (BOBF) Operational Guidelines, Security Standards and Guidelines, API Specifications, and Customer Journey Guidelines. - AISPs and PISPs must ensure compliance with BOBF standards is subject to independent review and testing by an independent consultant upon implementation. - AISPs and PISPs must ensure their technology solution is easily accessible and downloadable as a standalone application. ### CBB Rulebook Vol. 6 — Crypto-Asset Module (CRA) 2024 - URL: https://gcc-lexai.0xkaz.com/docs/ab415357-4f89-49c7-8fcd-1d86b7fc5ba1 - Issuing body: CBB - Type: regulation - Date: 2024 - Topics: crypto-asset regulation, licensing, cybersecurity, risk management - Applies to: Licensed crypto-asset service providers in Bahrain The CBB Rulebook Vol. 6, Crypto-Asset Module (CRA) 2024, outlines the regulatory framework for crypto-asset services in Bahrain. It covers licensing requirements, minimum capital, business standards, technology governance, cybersecurity, risk management, and reporting obligations for entities engaged in crypto-asset activities. The module aims to ensure the stability and integrity of the crypto-asset market and protect consumers. Key requirements: - Obtain a crypto-asset service license from the CBB. - Maintain minimum capital requirements as specified by the CBB. - Implement robust technology governance and cybersecurity measures. - Adhere to business standards and ongoing obligations related to client protection and marketing. - Comply with reporting, notification, and approval requirements. ### CBB Rulebook Vol. 6 — Stablecoin Issuance and Offering Module 2024 - URL: https://gcc-lexai.0xkaz.com/docs/5b9b098e-ddc6-4fe9-820e-c6a6edc61db6 - Issuing body: CBB - Type: regulation - Date: 2024 - Topics: Stablecoins, Licensing, Financial Resources, Cybersecurity - Applies to: Entities seeking to issue and offer stablecoins within Bahrain's jurisdiction, licensed or regulated by the CBB. The Central Bank of Bahrain's (CBB) Volume 6, Stablecoin Issuance and Offering Module (SIO) outlines the regulatory framework for stablecoin offerings within Bahrain's capital markets. It covers licensing, financial resource requirements, business standards, reserve asset management, and technology governance. The module aims to ensure the stability and security of stablecoins offered in Bahrain and protect consumers. Key requirements: - Maintain a minimum initial paid-up capital as specified by the CBB. - Comply with reserve asset composition and management requirements. - Publish a stablecoin whitepaper with specified content. - Implement robust technology governance and cybersecurity measures. ### Bahrain NCSC National Cybersecurity Risk Management Framework 2023 - URL: https://gcc-lexai.0xkaz.com/docs/f2ed3e75-fbf3-43d2-a3c5-c617c3cd51d0 - Issuing body: NCSC - Type: framework - Date: 2023 - Topics: risk management, cybersecurity, information security - Applies to: Organizations in Bahrain handling information and requiring information security The Bahrain National Cybersecurity Risk Management Framework (NCSC-RMF-0001) by the National Cybersecurity Center (NCSC) provides a structured approach to managing information security risks across the nation. It outlines a comprehensive methodology for risk assessment, treatment, monitoring, and governance, aiming to enhance cybersecurity posture. The framework serves as the authoritative reference for risk management in Bahrain. Key requirements: - Establish a risk management strategy - Define risk appetite - Implement a risk assessment process - Establish roles and responsibilities for risk management ### Bahrain National Cybersecurity Strategy 2025–2028 - URL: https://gcc-lexai.0xkaz.com/docs/98861a7c-f666-4b27-90c8-d577c6ca4f69 - Issuing body: NCSC - Type: strategy - Date: 2025 - Topics: cybersecurity, digital transformation, national security, risk management - Applies to: Individuals and organizations across the Kingdom of Bahrain, including entities from critical sectors. The Bahrain National Cybersecurity Strategy 2025-2028 outlines the Kingdom's approach to strengthening its cybersecurity landscape. It aims to support national development and enhance global competitiveness by addressing cybersecurity threats and promoting digital transformation. The strategy focuses on building cyber resilience, governance, collaboration, awareness, workforce development, research, and innovation. Key requirements: - Strengthening the protection of national digital infrastructure. - Enhancing cybersecurity regulations and laws. - Expanding regional and global partnerships. - Broadening national cybersecurity awareness. - Developing a skilled cybersecurity workforce. ### Bahrain PDPA Order No. 42 of 2022 — Transfer of Personal Data Outside Bahrain - URL: https://gcc-lexai.0xkaz.com/docs/83a24811-ed2b-4507-9af3-b34bc7c80041 - Issuing body: PDPA - Type: regulation - Date: 2022 - Topics: data protection, cross-border data transfer, data controller obligations - Applies to: Data Controllers operating in the Kingdom of Bahrain who transfer personal data outside of Bahrain Bahrain's Order No. 42 of 2022 outlines the regulations for transferring personal data outside of the Kingdom of Bahrain, as per the Personal Data Protection Law No. 30 of 2018. It specifies conditions under which data controllers can transfer data, including transfers to countries listed in an attached record and transfers authorized by the Personal Data Protection Authority. Key requirements: - Data Controllers must obtain prior authorization from the Authority to transfer data to countries not listed in the attached record. - Prior authorization requests must be submitted on the Authority's prescribed form, including details about the Controller, Processor, data nature, processing purpose, and data protection measures in the destination country. - Data Controllers transferring data within a regional or international group to countries not on the approved list must comply with Article 3 requirements and adhere to corporate rules, if present. ### Bahrain PDPA Order No. 43 of 2022 — Technical and Organisational Measures - URL: https://gcc-lexai.0xkaz.com/docs/2ef7fc76-53b1-4a5e-9154-35d91791404d - Issuing body: PDPA - Type: regulation - Date: 2022 - Topics: data protection, privacy by design, data security, risk management - Applies to: Data Controllers processing personal data in Bahrain Bahrain's Order No. 43 of 2022 outlines the technical and organizational measures required to ensure the protection of personal data, as mandated by the Personal Data Protection Law No. 30 of 2018. It details specific actions data controllers must take to maintain an adequate level of data security during processing activities. The order emphasizes proactive privacy measures and risk mitigation. Key requirements: - Implement Privacy by Design when developing or using applications and services that process data. - Establish privacy frameworks aligned with the PDPA Law and its Orders. - Conduct periodic Vulnerability Assessments and Penetration Testing (VAPT) to evaluate security measures. - Develop a plan to address data breaches and ensure processing continuity. ### Bahrain PDPA Order No. 46 of 2022 — Data Protection Auditor Tasks - URL: https://gcc-lexai.0xkaz.com/docs/d365bdfe-cbb6-46d4-b08f-728096622f3b - Issuing body: PDPA - Type: regulation - Date: 2022 - Topics: data protection, data protection guardian, compliance, Bahrain PDPL - Applies to: Data Controllers operating in Bahrain and individuals seeking accreditation as Data Protection Guardians (internal or external) Bahrain's Order No. 46 of 2022 outlines the regulations for Data Protection Guardians, both internal and external, as mandated by the Personal Data Protection Law (PDPL). It establishes a register for these guardians and sets forth the conditions for enrollment, including qualifications and ethical standards. The order empowers the Authority to require specific controllers to appoint a guardian. Key requirements: - Data Controllers must notify the Authority of the appointment of a Data Protection Guardian within three working days. - Individuals wishing to be accredited as a Data Protection Guardian must be enrolled in the Data Protection Guardians Register. - External Data Protection Guardians (natural persons) must hold a Bachelor's Degree in information technology or a professional certificate in information security or have practical experience in related fields. - External Data Protection Guardians (natural persons) must be of good reputation and not have been convicted of certain crimes. ### Bahrain PDPA Order No. 48 of 2022 — Data Subjects' Rights - URL: https://gcc-lexai.0xkaz.com/docs/0d9a20f0-796d-4394-a693-1668c160f1d9 - Issuing body: PDPA - Type: regulation - Date: 2022 - Topics: data subject rights, consent, automated processing, data protection - Applies to: Data controllers processing personal data in Bahrain subject to the Personal Data Protection Law No. 30 of 2018. Bahrain's Order No. 48 of 2022 outlines the rights of data subjects under the Personal Data Protection Law (PDPL). It details obligations for data controllers regarding automated processing, consent, and objection procedures. The order aims to ensure data subjects can exercise their rights related to their personal data effectively. Key requirements: - Data controllers must inform data subjects of decisions based on automated processing and provide mechanisms for objection. - Data controllers must obtain explicit consent from data subjects before processing their data, unless otherwise stipulated in the PDPL. - Data controllers must allow data subjects to easily withdraw consent at any time, free of charge, and without responsibility. - Data controllers must establish and publicize clear procedures for data subjects to submit objections. ### Bahrain Personal Data Protection Law (Law No. 30 of 2018) - URL: https://gcc-lexai.0xkaz.com/docs/8e8845a5-85f2-46ec-b0dc-d62fbeecf150 - Issuing body: PDPA - Type: law - Date: 2018 - Topics: data protection, privacy, data security - Applies to: Data controllers and processors operating within Bahrain, or processing personal data of individuals residing in Bahrain. Bahrain's Personal Data Protection Law (Law No. 30 of 2018) establishes a legal framework for safeguarding personal data. It outlines the rights of individuals regarding their data and imposes obligations on data controllers and processors. The law aims to regulate the collection, processing, and transfer of personal data within Bahrain. Key requirements: - Obtain explicit consent from individuals before processing their personal data. - Implement appropriate technical and organizational measures to protect personal data against unauthorized access, use, or disclosure. - Notify the PDPA and affected individuals in the event of a data breach. - Appoint a data protection officer (DPO) if the organization processes a large volume of personal data. ### Bahrain iGA General Policy for the Use of Artificial Intelligence 2025 - URL: https://gcc-lexai.0xkaz.com/docs/e4c22168-05c3-4855-8309-657e565eb52e - Issuing body: iGA - Type: policy - Topics: AI governance, AI policy, Technology adoption, Ethical AI - Applies to: entities and individuals using Artificial Intelligence within the Kingdom of Bahrain, as guided by the iGA. The Bahrain iGA General Policy for the Use of Artificial Intelligence 2025 outlines the foundational principles, objectives, and pillars for the responsible and effective adoption of AI technologies within the Kingdom of Bahrain. It aims to guide the use of AI by establishing rules and requirements across commitment to policies, technology adoption, awareness, and cooperation, ensuring ethical and beneficial integration of AI. Key requirements: - Commitment to existing policies and legislations related to AI use. - Adoption of Artificial Intelligence technologies in line with established rules and requirements. - Promoting awareness and education regarding AI technologies and their implications. - Encouraging local and international cooperation in the field of Artificial Intelligence. ### Kingdom of Bahrain AI Readiness Assessment Methodology (RAM) Report 2025 - URL: https://gcc-lexai.0xkaz.com/docs/f1383965-8d6d-4498-b4b6-b85fcb88436b - Issuing body: iGA - Type: report - Topics: AI Readiness Assessment, AI Governance, Ethical AI, National AI Strategy - Applies to: the Kingdom of Bahrain's national AI landscape and its contributing national entities, including iGA, Ministry of Education, Ministry of Industry and Commerce, Tamkeen, National Cybersecurity Center, Telecommunications Regulatory Authority, and Central Bank of Bahrain. This report details the Kingdom of Bahrain's Artificial Intelligence Readiness Assessment Methodology (RAM), developed in partnership with UNESCO. It outlines Bahrain's comprehensive and inclusive approach to building its national AI ecosystem, emphasizing collaboration, innovation, and responsible progress. The document highlights the establishment of a robust AI and data governance framework, supported by various national entities, to strengthen its domestic AI landscape and contribute to global ethical AI development. Key requirements: - Establish a robust AI and data governance framework. - Engage stakeholders across sectors through workshops, public consultations, strategic partnerships, and advisory committees. - Ensure responsible and ethical AI development. - Strengthen the domestic AI ecosystem through unified national efforts. ## Qatar (31 documents) ### 6 Service Management en - URL: https://gcc-lexai.0xkaz.com/docs/590ad18a-bd95-40f3-8e36-08282bc4453c - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: Service Management, IT Governance, COBIT, ITIL - Applies to: Government entities and service providers operating within the State of Qatar's Government Enterprise Architecture. This document from MCIT Qatar outlines the framework for Service Management within the Government Enterprise Architecture. It details guiding principles, framework options like COBIT and ITIL, and governance processes across the service lifecycle, including strategy, design, transition, and continual improvement. The regulation aims to standardize and improve service delivery within the Qatari government. Key requirements: - Implement continual service improvement processes. - Establish service level management procedures. - Manage service capacity effectively. - Ensure service continuity management. ### 7 Governance Model en - URL: https://gcc-lexai.0xkaz.com/docs/1db1d616-8eb6-4b37-aa1c-112260158c02 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: enterprise architecture, governance, e-government, data management - Applies to: Qatar government entities involved in the development and implementation of e-government services and IT infrastructure. This document outlines the Government Enterprise Architecture (GEA) Governance Model for Qatar, establishing a framework for governing and managing the adoption of enterprise architecture across government entities. It defines the governance structure, roles, processes, and enabling policies to ensure alignment with national objectives and effective implementation of e-government initiatives. Key requirements: - Adoption of overall GEA policies across government entities. - Compliance with Smart Qatar data standards. - Adherence to the service development lifecycle for application architecture. - Implementation of the Government Mobile Services Framework. ### AI Guidelines En - URL: https://gcc-lexai.0xkaz.com/docs/55bbafbc-6dfe-4de6-a5e6-38f8e149fc93 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: AI ethics, AI governance, Emerging technologies - Applies to: All users of Artificial Intelligence (AI) systems, including private companies, government entities, the public, and students in Qatar. This document from MCIT Qatar provides ethical guidelines for the use of Artificial Intelligence (AI) systems in Qatar. It aims to promote responsible AI practices aligned with local values, while advancing human, social, and economic development. The guidelines are intended to support Qatar’s aspirations for ethical AI use across various sectors. Key requirements: - AI systems should be used in a manner that respects cultural norms. - AI developers and implementers shall refer to the related document “Principles and Guidelines for Ethical Development and Deployment”. - Maintain ethical practices in line with Qatar’s values. ### AI Guidelines Developers EN - URL: https://gcc-lexai.0xkaz.com/docs/4e634350-e975-4244-ba54-aed58356aadc - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: AI ethics, AI development, AI deployment - Applies to: AI developers and deployers in Qatar This document from MCIT Qatar provides ethical guidelines for the development and deployment of AI systems impacting the public. It aims to promote responsible AI practices aligned with global standards and Qatar's national goals, serving as a roadmap for developers and publishers under MCIT's guidance. The guidelines are voluntary and will be reviewed periodically. Key requirements: - Adapt the guidelines to fit specific situations and contexts. - Develop AI systems in a manner that respects local values and cultural norms. - Adhere to international standards set by organizations like UNESCO and OECD. ### Dhareeba Tax Platform Positioning Qatar for Digital Government Excellence - URL: https://gcc-lexai.0xkaz.com/docs/290b9c76-6105-4aba-ae2e-514a9cb94795 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: Digital Government, Taxation, Digital Transformation - Applies to: Government entities and stakeholders in Qatar utilizing the Dhareeba tax platform. This white paper by MCIT Qatar, in collaboration with the General Tax Authority (GTA), highlights the progress of digital government services in Qatar, focusing on the Dhareeba digital platform. It positions Dhareeba as a model for delivering efficient, high-quality digital tax services aligned with international best practices and Qatar's Digital Agenda 2030. Key requirements: - Adoption of digital transformation to enhance service quality. - Alignment with Qatar's Digital Agenda 2030. - Implementation of innovative technologies to improve government responsiveness and efficiency. ### FINAL Digital Economy Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/aff9fe16-7b1e-4a70-bc3d-725c397d861b - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital economy, digital transformation, innovation, digital infrastructure - Applies to: Ministries, regulators, public institutions, academia, private sector enterprises, and the investment community within Qatar's digital ecosystem. Qatar's Digital Economy Policy outlines the nation's vision to become a global leader in the digital economy by 2030. It provides policy directions and actions across priority sectors like finance, manufacturing, and healthcare, guided by enablers such as innovation, digital infrastructure, and digital skills. The policy aims to drive inclusive, innovation-led economic growth through digital transformation. Key requirements: - Adopt and integrate appropriate digital economy governmental and legislative frameworks. - Promote an innovation environment to support the adoption of emerging technologies. - Address the digital skills gap by attracting and fostering world-class tech talent. - Embed transformative digital solutions into business models to enhance competitiveness. ### FINAL Digital Inclusion Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/8c30adaf-46c1-4e07-9a59-169bde95a5c7 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital inclusion, digital literacy, accessibility, digital skills - Applies to: All actors across public, private, and civil society sectors in Qatar Qatar's National Digital Inclusion Policy aims to ensure equitable participation in digital transformation, aligning with Qatar National Vision 2030. It addresses digital divides by focusing on access, skills, trust, and co-creation, empowering vulnerable groups to participate in the digital economy. The policy is led by MCIT with multi-sector oversight. Key requirements: - Expand broadband connectivity and affordable device access, especially in underserved regions. - Deliver foundational and advanced digital training across all age groups, targeting low-skilled workers, older adults, and women. - Promote human-centered design and accessibility standards for digital services. - Establish co-creation platforms and civic innovation labs to empower marginalized communities. ### FINAL IoT Adoption Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/21d77201-5799-4020-87bf-a3eeda7e1ada - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: IoT, Cybersecurity, Digital Transformation, Innovation - Applies to: All government and semi-government entities, the private sector, academia, and civil society involved in planning, deploying, or regulating IoT systems in Qatar. Qatar's IoT Adoption Policy aims to promote the widespread, secure, and sustainable deployment of IoT technologies across all sectors. It focuses on public-private collaboration, responsible innovation, interoperability, and long-term sustainability. The policy provides strategic guidance to accelerate IoT adoption and enable digital transformation. Key requirements: - Establish national IoT cybersecurity guidelines and secure-by-design requirements. - Invest in 5G and LPWAN infrastructure and establish unified interoperability standards. - Promote energy-efficient device adoption and e-waste guidelines. - Develop STEM education and upskilling programs for IoT technologies. ### FINAL Lifelong Learning for Digital Skills Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/30702217-9d1e-4fb1-866e-6aebd00e73bf - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital skills, lifelong learning, workforce development, digital literacy - Applies to: All segments of society in Qatar: children, youth, adults, seniors, professionals, and marginalized groups. Qatar's Lifelong Learning for Digital Skills Policy establishes a national framework for integrating digital skills across all life stages. It aims to cultivate a digitally competent society ready for technological change by mainstreaming digital upskilling across sectors. The policy supports inclusive growth, innovation, and workforce transformation through digital competency development. Key requirements: - Integrate digital skills into school curricula starting at the primary level. - Expand Qatar Digital Academy to serve public and private sector professionals. - Extend tailored digital learning programs to migrant workers, women, and older adults. - Support certification and career pathways in AI and other emerging technologies. ### FINAL National AI Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/0987d72d-d86c-40db-8b8a-ccad8c89939b - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: AI governance, Digital infrastructure, Data governance, AI ethics - Applies to: all AI developers and implementers in Qatar, including private sector entities, public-sector institutions, and AI end-users, excluding institutions dealing with national security. The Qatar National AI Policy establishes a framework for the ethical, inclusive, and coordinated deployment of AI across sectors in Qatar, aligning with Digital Agenda 2030 and the Third National Development Strategy. It provides guidelines for AI development, deployment, and governance, empowering responsible AI initiatives while mitigating risks and promoting trust. Key requirements: - Develop scalable and secure computing infrastructure for AI. - Promote the development of ethical, interoperable, and high-quality datasets for AI applications. - Build a robust AI talent pipeline through education and training. - Introduce risk-based AI classification systems. ### FINAL Regulatory Sandbox Guidelines Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/b1ffb077-c645-4e27-8639-fe97b653698c - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: regulatory sandbox, emerging technologies, digital innovation - Applies to: Regulatory entities, line ministries, public entities exploring new digital technologies, firms, start-ups, SMEs engaging with regulators, and external experts in Qatar The Regulatory Sandbox Guidelines document outlines an operational framework for implementing a regulatory sandbox in Qatar, aligned with the Digital Agenda 2030 and NDS3. It aims to enable safe experimentation with emerging technologies across finance, telecom, health, and other digital sectors. The guidelines provide a phased methodology for government agencies and regulators to deploy sandboxes. Key requirements: - Entities should undertake preliminary steps to ensure they can successfully embrace the new regulatory tools before launching a regulatory sandbox. - Entities should be ready to begin planning after completing readiness assessments. - Concisely define the overall objective and outcome of the regulatory experimentation process during the design phase. ### FINAL Regulatory Sandbox Policy Executive Summary EN - URL: https://gcc-lexai.0xkaz.com/docs/11947cea-dc9f-47b3-aa4d-5687f5f59860 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: regulatory sandbox, digital innovation, economic diversification, regulatory policy - Applies to: Regulatory bodies overseeing digital innovation, public institutions, and innovators deploying digital technologies in Qatar Qatar's Regulatory Sandbox Policy establishes a framework for controlled experimentation of digital technologies under regulatory supervision. It aims to modernize the regulatory environment, enhance institutional capacity for digital regulation, and accelerate economic diversification through innovation, aligning with Qatar National Vision 2030 and the Digital Agenda 2030. Key requirements: - Regulatory bodies must assess their readiness for regulatory sandboxes. - Regulatory bodies must enhance their technical and managerial expertise. - Regulatory bodies must coordinate with each other to identify regulatory overlaps and gaps. - Comprehensive evaluation of Qatar’s regulatory landscape. ### MCIT Qatar DII Report Executive English - URL: https://gcc-lexai.0xkaz.com/docs/275ee87b-ae8a-46c4-be23-219e0d48b6f4 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital inclusion, digital accessibility, digital equity, Qatar National Vision 2030 - Applies to: All residents in Qatar, regardless of their background The MCIT Qatar Digital Inclusion Index (Qatar DII) 2024 report evaluates Qatar's progress in creating an inclusive digital ecosystem, aligned with Qatar National Vision 2030 and Digital Agenda 2030. It measures digital accessibility, affordability, ability, and content availability to ensure all residents can participate in the digital world, identifying areas for improvement and promoting global collaboration. Key requirements: - Address the unique challenges faced by different demographic groups, including rural communities, people with disabilities, women, and the elderly. - Ensure policies, strategies, and initiatives reflect the diverse needs of the country. - Extend the advantages of the digital age to all segments of society. - Provide access to the tools, knowledge, and resources necessary to fully participate in the digital ecosystem. ### MCIT Qatar DII Report VF EN 1 - URL: https://gcc-lexai.0xkaz.com/docs/1edb4b18-836a-42a4-9034-397a4b27e346 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital inclusion, digital accessibility, digital literacy, economic development - Applies to: All residents in Qatar, regardless of their background The MCIT Qatar Digital Inclusion Index (Qatar DII) 2024 report evaluates Qatar's progress in creating an inclusive digital ecosystem, aligned with Qatar National Vision 2030 and Digital Agenda 2030. It measures digital accessibility, affordability, ability, and content availability across all segments of society to promote societal well-being, economic growth, and educational opportunities. Key requirements: - Ensure digital technologies are accessible across all segments of society. - Address key areas such as digital accessibility, affordability, ability, and content availability. - Empower young people and equip the workforce with digital skills. - Ensure vulnerable and underrepresented communities are not left behind in the digital age. ### QDA Annual Report 2024 EN V12 - URL: https://gcc-lexai.0xkaz.com/docs/34e8c827-5e74-40c6-bad8-2a6c970deb2a - Issuing body: MCIT Qatar - Type: regulation - Date: 2024 - Topics: digital skills, training programs, digital transformation - Applies to: Government employees and entities in Qatar The Qatar Digital Academy (QDA) Annual Report 2024 by MCIT Qatar highlights the academy's achievements in enhancing digital competencies within Qatar's government sector. It details training programs, strategic partnerships, and initiatives aligned with Qatar National Vision 2030 and Digital Agenda 2030. The report serves to showcase the progress in developing a skilled digital workforce. Key requirements: - Develop and refine training curricula in collaboration with internationally accredited institutions. - Deliver specialized training in areas such as AI, Cybersecurity, Cloud Computing, and Data Analytics. - Promote a culture of continuous learning through specialized programs. - Forge strategic partnerships with leading technology companies and educational institutions. ### Studio 5 Empowering Digital Futures V5 - URL: https://gcc-lexai.0xkaz.com/docs/e77135d6-f23c-439f-bc8a-cc890df7fd39 - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: Digital literacy, Innovation, Digital empowerment, Education - Applies to: The Studio 5 initiative, stakeholders supporting the initiative, and Qatari youth The "Studio 5 Empowering Digital Futures V5" document, issued by MCIT Qatar, assesses the achievements and impact of the Studio 5 initiative in fostering digital literacy and innovation among Qatari youth. It provides insights and recommendations to enhance the initiative's future direction, aligning it with Qatar’s Digital Agenda 2030 and National Vision 2030. Key requirements: - Enhance strategic alignment and collaboration within the Studio 5 initiative. - Expand educational outreach and technological integration. - Advance operational capabilities to meet rising demand. - Formalize partnerships to enhance scalability. ### TA Progress Report External English 6 - URL: https://gcc-lexai.0xkaz.com/docs/43ab1449-9365-4ee7-8893-267358170f6c - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: Digital Transformation, Startup Acceleration, Innovation, Economic Development - Applies to: Growth-stage startups participating in the TASMU Accelerator program in Qatar This is the TASMU Accelerator Achievements Report by MCIT Qatar, detailing the program's success in supporting startups and advancing Qatar's Digital Agenda 2030. The report highlights the accelerator's role in fostering innovation, facilitating collaboration between public and private sectors, and driving growth in key sectors like healthcare, logistics, environment, and tourism. It showcases the economic impact and global reach of the program. Key requirements: - Startups must align with the priorities of the TASMU Smart Qatar Program. - Startups should develop innovative solutions for key sectors such as healthcare, logistics, environment, and tourism. - Startups must participate in mentorship programs and meetings with key Qatari organizations. - Startups are expected to contribute to Qatar's digital transformation and economic diversification. ### digital leap the transformational journey for smes july 2024 0 - URL: https://gcc-lexai.0xkaz.com/docs/80a61fe3-652f-4109-a22b-1f8d8158ce88 - Issuing body: MCIT Qatar - Type: regulation - Date: 2024 - Topics: Digitalization, SMEs, Economic Development - Applies to: Small and Medium-sized Enterprises (SMEs) in Qatar This MCIT Qatar regulation outlines a digitalization program for Small and Medium Enterprises (SMEs) to enhance their digital capabilities and competitiveness, aligning with Qatar's National Vision 2030 and Digital Agenda 2030. It aims to foster economic growth by empowering SMEs through digital transformation, contributing to job creation and technological innovation. Key requirements: - SMEs should adopt digital technologies to enhance their operations. - SMEs should participate in MCIT's digitalization program. - SMEs should contribute to Qatar's economic diversification plans through technological innovation. ### e commerce law en 1 - URL: https://gcc-lexai.0xkaz.com/docs/86069dc3-c2fa-41eb-a8a9-6c92beb4f1f9 - Issuing body: MCIT Qatar - Type: regulation - Date: 2024 - Topics: e-commerce, electronic transactions, consumer protection, electronic signature - Applies to: Businesses and individuals conducting electronic transactions and commerce in Qatar. Decree Law No. 16 of 2010, also known as the Electronic Transactions and Commerce Law, governs electronic transactions and commerce in Qatar. It establishes the legal framework for electronic signatures, certification services, consumer protection in the electronic environment, and defines offenses and penalties related to electronic transactions. The law aims to facilitate and regulate the growing digital economy in Qatar. Key requirements: - Electronic transactions must meet specific requirements as outlined in Chapter Three (Articles 4-19). - Electronic signatures must adhere to the standards defined in Chapter Five (Articles 28-34). - Certification service providers must comply with the regulations specified in Chapter Six (Articles 35-44). - Consumer protection measures must be implemented as detailed in Chapter Eight (Articles 51-59). ### fifa world cup qatar 2022tm mcit connected tournament a digital legacy english 1 - URL: https://gcc-lexai.0xkaz.com/docs/d205e547-fd78-4249-ba68-16487d42fafd - Issuing body: MCIT Qatar - Type: regulation - Date: 2024 - Topics: Sports Technology, Event Management, Digital Economy - Applies to: Government representatives, private sector stakeholders, regulatory agencies, and the Supreme Committee for Delivery & Legacy in Qatar This MCIT Qatar document reviews the digital and technological innovations implemented during the FIFA World Cup Qatar 2022. It highlights the technologies deployed, their impact on fan experience and event management, and the tournament's legacy in establishing Qatar as a leader in sports technology. The report also explores the potential for economic diversification and growth of the entrepreneurial ecosystem. Key requirements: - Leverage technological innovations implemented during the FIFA World Cup for future events. - Capitalize on opportunities for economic diversification and inbound investment. - Promote the growth of the entrepreneurial ecosystem in Qatar. ### law7405 - URL: https://gcc-lexai.0xkaz.com/docs/57a889f8-8865-434a-9978-11653f8e38dd - Issuing body: MCIT Qatar - Type: regulation - Topics: Telecommunications Regulation, Network Operation, Service Provision, Wireless Communication - Applies to: All governmental bodies, public institutions, organizations, individuals, and specifically entities subject to Law No. 21 of 1998, Qatar Telecom (Qtel), and entities operating within free zones in Qatar. Law 7405, issued by MCIT Qatar, pertains to the regulation of telecommunications in Qatar. It establishes the legal framework for telecommunications activities, including network operation and service provision. The law aims to modernize the telecommunications sector and ensure fair competition among service providers. Key requirements: - All entities providing telecommunications services or operating networks must align their operations with the provisions of this law within six months of its effective date. - Qatar Telecom (Qtel) loses its exclusive privilege granted under Law No. 21 of 1998, with all related powers transferring to the Supreme Council. - Companies must register their wireless stations and equipment data with the relevant authorities without fees. - A competitor service provider must pay the prescribed fee before starting to offer its services to the public. ### national artificial intelligence strategy for qatar 2019 en - URL: https://gcc-lexai.0xkaz.com/docs/aba47c0a-e5a0-4637-9926-556ca60bf176 - Issuing body: MCIT Qatar - Type: regulation - Date: 2019 - Topics: AI strategy, AI adoption, Economic development - Applies to: Government, businesses, and residents of Qatar Qatar's National Artificial Intelligence Strategy 2019 outlines a vision for AI integration across life, business, and governance, aiming for Qatar to be a role model in transitioning to an AI-driven future. The strategy focuses on leveraging AI to secure Qatar's economic and strategic future, aligning with Qatar National Vision 2030 and preparing society for AI adoption. Key requirements: - Leverage AI to secure Qatar’s economic and strategic future. - Prepare the society for effective adoption of AI technology that is aligned with local needs and traditions. - Capacity building in AI technology is vital for a sustainable and viable economy. ### national authentication and trust services strategy summary en - URL: https://gcc-lexai.0xkaz.com/docs/2d06d392-e809-4c6a-b1c8-5daa68a34a8b - Issuing body: MCIT Qatar - Type: regulation - Date: 2025 - Topics: digital authentication, trust services, digital transformation, regulatory framework - Applies to: Government entities, private sector entities, and individuals in Qatar utilizing or providing digital services. The MCIT Qatar's National Digital Authentication and Trust Services Strategy (2024-2026) aims to develop a unified digital authentication system to support digital transformation and the digital economy in Qatar. It focuses on establishing the legislative, regulatory, and technical framework for digital authentication and trust services to create a reliable digital environment. Key requirements: - Develop legislative requirements for digital authentication and trust services. - Develop regulatory requirements for digital authentication and trust services. - Develop technical requirements for digital authentication and trust services. ### qatar e government 2020 strategy en 0 - URL: https://gcc-lexai.0xkaz.com/docs/6fcb23f7-45a7-41bc-a379-2b28f0ecdf29 - Issuing body: MCIT Qatar - Type: regulation - Date: 2020 - Topics: e-Government, Digital Transformation, Government Services, Citizen Engagement - Applies to: All government entities in Qatar The Qatar e-Government 2020 Strategy outlines the vision for a more efficient, effective, accessible, and transparent government through technology. It aims to bring all government services online, automate government administration, and enhance citizen participation. The strategy applies to all government entities in Qatar. Key requirements: - Bring 100% of government services online. - Ensure users can complete e-services end-to-end online. - Automate government functions. - Enhance citizen participation in government. ### Implementing Regulations of 2020 (Targeted Financial Sanctions) - URL: https://gcc-lexai.0xkaz.com/docs/ed356f33-431e-4d89-a92c-91aa270c66ce - Issuing body: QFCRA - Type: regulation - Date: 2020 - Topics: Financial Sanctions, Terrorism Financing, Weapons Proliferation - Applies to: Entities subject to QFCRA regulation This QFCRA regulation outlines the implementation mechanisms for targeted financial sanctions related to combatting the financing of terrorism and the proliferation of weapons of mass destruction, pursuant to UN Security Council Resolutions. It defines key terms and establishes procedures for implementing UN Committee Resolutions related to terrorist financing. Key requirements: - Adoption of definitions stipulated in Article (1) of Law No.(27) of 2019 on Combating Terrorism. - Maintenance of a Sanctions List by the NCTC, including individuals and entities designated by the UN Security Council and the Public Prosecutor. - Implementation of targeted financial sanctions against designated individuals and entities based on a Statement of Case by the NCTC. ### Law No. (11) of 2004 (Penal Code of Qatar) - URL: https://gcc-lexai.0xkaz.com/docs/09a87480-8483-43c3-994b-d37d95615742 - Issuing body: QFCRA - Type: regulation - Topics: criminal law, Islamic Sharia, public administration, penal code - Applies to: Individuals and entities within the State of Qatar, including public employees and those handling public funds. Law No. (11) of 2004, the Penal Code of Qatar, establishes the legal framework for criminal offenses and their corresponding punishments within the country. It outlines general provisions, defines public employees and public funds, and specifies the applicability of Islamic Sharia provisions for certain crimes involving Muslims. This law repeals the previous Penal Code of Qatar issued in 1971. Key requirements: - Islamic Sharia provisions apply to crimes such as theft, adultery, defamation, drinking alcohol, and apostasy if the suspect or victim is Muslim. - Islamic Sharia provisions apply to crimes of retaliation and blood money if the suspect or victim is Muslim. - Public employees are defined as those charged to do the public authority, including employees and workers in ministries, governmental corps, and public organizations. - Public funds are defined as all assets owned or controlled by ministries and other governmental authorities. ### Law No. (20) of 2019 - URL: https://gcc-lexai.0xkaz.com/docs/3ce0eefa-8a42-4728-9398-3deb98f4c333 - Issuing body: QFCRA - Type: regulation - Date: 2019 - Topics: AML, CTF, Financial Regulation - Applies to: All concerned parties subject to the provisions of the Law on Combating Money Laundering and Terrorism Financing in Qatar Law No. (20) of 2019, issued by the QFCRA in Qatar, establishes a legal framework for combating money laundering and terrorism financing. It repeals Law No. (4) of 2010 and mandates concerned parties to comply with its provisions within six months of its effective date, with potential extensions granted by the Council of Ministers. The Council of Ministers will issue implementing regulations. Key requirements: - All concerned parties must make necessary arrangements to comply with the provisions of the law within six months of its effective date. - The Council of Ministers shall issue implementing regulations for the law. - Competent authorities are responsible for implementing the law within their respective areas of competence. ### Law No. (27) of 2019 Promulgating the Law on Combating Terrorism - URL: https://gcc-lexai.0xkaz.com/docs/036bf5a2-8083-4f6f-9b0f-951a7b90c7ce - Issuing body: QFCRA - Type: regulation - Date: 2019 - Topics: Combating Terrorism, Criminal Law, National Security - Applies to: All individuals and entities within the State of Qatar Law No. (27) of 2019, issued by the QFCRA in Qatar, promulgates the Law on Combating Terrorism. It defines terrorism offenses and terrorist acts, repeals Law No. (3) of 2004, and ensures consistency with international conventions related to combating terrorism. The law aims to provide a legal framework for preventing and punishing acts of terrorism. Key requirements: - Defines 'Terrorism Offence' as any offense provided for in this Law and any felony provided for in the Penal Code or in any other law, committed with the intent to execute or carry out a terrorist act. - Defines 'Terrorist Act' including acts intended to cause death or serious bodily injury to a person not taking an active part in the hostilities in a situation of armed conflict, when the purpose of such act is to intimidate a population, or to compel a Government or an international organisation to do or to abstain from doing any act. - Repeals Law No. (3) of 2004 on Combating Terrorism. ### Law No. (6) 2020 amending Criminal Procedures Code Law No. (23) 2004 - URL: https://gcc-lexai.0xkaz.com/docs/30e6fa5d-1c22-4a36-97a5-53b4ed4236b3 - Issuing body: QFCRA - Type: regulation - Date: 2020 - Topics: Criminal Procedure, International Cooperation, Money Laundering, Terrorism Financing - Applies to: Judicial authorities in the State of Qatar, Public Prosecutor, Courts Law No. (6) of 2020 amends the Criminal Procedure Code in Qatar, focusing on international judicial cooperation and investigative powers. It updates articles related to mutual legal assistance, extradition, and introduces provisions for undercover operations in cases of money laundering and terrorism financing. The law aims to enhance the effectiveness of criminal investigations and cross-border legal collaboration. Key requirements: - Qatari judicial authorities must cooperate with foreign judicial authorities in criminal matters, subject to reciprocity and applicable international agreements. - Requests for mutual legal assistance from foreign authorities must be submitted to the Public Prosecutor in Arabic, including details of the requesting authority, facts, applicable legal texts, and identities of persons involved. - Undercover operations, authorized by the Public Prosecutor, can be used to investigate money laundering, predicate offenses, and terrorism financing. - Extradition is permissible if the crime is a felony or misdemeanor punishable by at least one year imprisonment in both Qatar and the requesting country, or if the person has been sentenced to at least six months imprisonment. ### The Anti-Money Laundering and Combating the Financing of Terrorism Rules 2019 - URL: https://gcc-lexai.0xkaz.com/docs/01c4457c-0795-415a-a6f4-6653053e5561 - Issuing body: QFCRA - Type: regulation - Date: 2019 - Topics: AML, CFT, Risk-Based Approach, Compliance - Applies to: Firms and financial institutions operating under the QFCRA's jurisdiction in Qatar, including Designated Non-Financial Businesses and Professions (DNFBPs) and Designated TSPs. The Anti-Money Laundering and Combating the Financing of Terrorism Rules 2019 (AML/CFTR) outlines the obligations of firms in Qatar to establish and maintain robust AML/CFT programs. These rules are designed to prevent financial institutions and other designated businesses from being used for money laundering or terrorist financing activities, ensuring compliance with Law No. (20) of 2019. Key requirements: - Firms must develop and maintain a risk-sensitive AML/CFT program. - Firms must appoint a Money Laundering Reporting Officer (MLRO) and a Deputy MLRO. - Firms must conduct risk assessments to identify and mitigate money laundering and terrorist financing risks. - Senior management has overall responsibility for the firm's compliance with AML/CFT regulations. ### the Anti-Money Laundering and Combating the Financing of Terrorism (General Insurance) Rules 2019 - URL: https://gcc-lexai.0xkaz.com/docs/2e948c89-33a8-49cf-845a-8bc5d91de02f - Issuing body: QFCRA - Type: regulation - Date: 2019 - Topics: AML/CFT, General Insurance, Risk-Based Approach, Customer Due Diligence - Applies to: General insurance firms operating within the Qatar Financial Centre (QFC) The Anti-Money Laundering and Combating the Financing of Terrorism (General Insurance) Rules 2019 (AMLG) outlines the obligations of general insurance firms operating within the Qatar Financial Centre (QFC) regarding AML/CFT. It establishes key principles, responsibilities, and procedures for firms to detect, prevent, and report money laundering and terrorist financing activities. Key requirements: - Firms must develop and maintain a risk-sensitive AML/CFT program. - Firms must conduct customer due diligence (CDD) and ongoing monitoring. - Firms must appoint a Money Laundering Reporting Officer (MLRO) and Deputy MLRO. - Firms must report suspicious transactions to the relevant authorities. ## Oman (3 documents) ### Oman Executive Program for AI and Advanced Technologies 2022 - URL: https://gcc-lexai.0xkaz.com/docs/832dccd5-33cc-472e-94df-70dc07a1790c - Issuing body: ITA - Type: strategy - Date: 2022 - Topics: AI strategy, Economic diversification, Human capital, AI governance - Applies to: Government entities and organizations involved in the development and implementation of AI and advanced technologies in Oman. The Oman Executive Program for AI and Advanced Technologies 2022 outlines the strategic direction for AI and advanced technology adoption in Oman. It aims to create a sustainable economy by integrating AI into various sectors, developing human talent, and establishing effective governance. The program will be reviewed annually to assess implementation progress. Key requirements: - Enhance productivity of sectors targeted for economic diversification through smart technologies. - Develop human talent and capabilities in artificial intelligence technologies. - Adopt artificial intelligence in strategic sectors. - Establish governance of artificial intelligence with a human-centered vision. ### Oman Personal Data Protection Law — Royal Decree 6/2022 - URL: https://gcc-lexai.0xkaz.com/docs/ba7a738f-9ba3-4061-b68e-69b8b8989650 - Issuing body: ITA - Type: law - Date: 2022 - Topics: data protection, privacy law, data processing - Applies to: Controllers and Processors of personal data in Oman Royal Decree 6/2022 promulgates the Oman Personal Data Protection Law, repealing Chapter seven of the Electronic Transactions Law. The law defines key terms such as Personal Data, Controller, and Processor, and establishes a framework for the processing of personal data. It aims to protect individuals' privacy by regulating how their personal information is handled. Key requirements: - Personal data processing must adhere to the provisions of the Personal Data Protection Law. - The Minister of Transport, Communications, and Information Technology shall issue the executive regulation of the law. - Existing regulations and decisions continue to operate to the degree that they do not contradict with the provisions of the new law. ### Oman National Program for AI and Advanced Digital Technologies 2024 - URL: https://gcc-lexai.0xkaz.com/docs/4d1b8133-2989-403e-8422-6ad9547fcd53 - Issuing body: MTCIT - Type: strategy - Date: 2024 - Topics: AI strategy, Digital economy, AI governance, Technology localization - Applies to: Startups, researchers, investors, and government entities involved in the development and deployment of AI and advanced digital technologies in Oman. The Oman National Program for AI and Advanced Digital Technologies 2024 outlines Oman's strategy to become a leader in AI adoption and localization. It aims to integrate AI into economic and development sectors, establish governance frameworks, and promote a human-centered approach. The program seeks to enhance the national economy and increase productivity through AI technologies. Key requirements: - Promote and adopt artificial intelligence in the economic and development sectors. - Localize AI technologies. - Govern AI applications and advanced digital technologies with a human-centered vision. - Increase the number of startups specialized in developing and providing services using AI technologies. ## Kuwait (8 documents) ### CBK Cybersecurity Framework for the Kuwaiti Banking Sector 2020 - URL: https://gcc-lexai.0xkaz.com/docs/4bf5b284-39df-4367-bfc7-1e1b8aad7177 - Issuing body: CBK - Type: framework - Date: 2020 - Topics: cybersecurity, risk management, banking regulation - Applies to: Kuwaiti Banking Sector The CBK Cybersecurity Framework for the Kuwaiti Banking Sector 2020 outlines requirements for regulated entities to improve their cyber resilience and manage cyber risks. It aims to protect information and financial assets, promote cooperation, and standardize information sharing within the banking sector. The framework is intended to guide the banking sector in effectively managing imminent cyber risks. Key requirements: - Regulated entities must fulfill requirements to improve their capabilities, readiness, and cooperation. - Regulated entities must improve information sharing and standardization. - Regulated entities are expected to protect information and financial assets entrusted to them. - Regulated entities must proactively pursue efforts to prevent and mitigate cyber threats. ### CBK E-Payment Services Chapter 1 — Organisational Governance - URL: https://gcc-lexai.0xkaz.com/docs/06ced73e-4977-4a64-8264-b9f50738e671 - Issuing body: CBK - Type: regulation - Topics: E-payment, Financial Regulation, Organizational Governance - Applies to: Local Banks, Financing Companies, Exchange Companies, and Electronic Payment Infrastructure Service Providers and their Agents in Kuwait This document from the Central Bank of Kuwait (CBK) introduces updated instructions regulating electronic payment of funds, replacing Resolution No. 44/430 of 2018. It mandates that relevant entities take necessary actions to comply with the new amendments within three months of the effective date. The resolution aims to provide a framework for electronic payment services. Key requirements: - Comply with the updated Instructions Regulating the Electronic Payment of Funds as per Resolution No. 45/471/2023. - Revoke any provisions that contravene the new instructions. - Implement necessary actions to fulfill the requirements of the amendments within 3 months from the date of coming into force. ### CBK E-Payment Services Chapter 2 — Circulars for Electronic Payment - URL: https://gcc-lexai.0xkaz.com/docs/90aa29bb-0c24-43b3-90f9-385ebfed0621 - Issuing body: CBK - Type: regulation - Topics: electronic payments, AML/CFT, cybersecurity, consumer protection - Applies to: Local Banks, Electronic Payment Infrastructure Providers (EPIPs), E-Payment Service Providers, E-Money Service Providers, E-Payment Service Operators, Financing Companies, Large Electronic Money Service Providers, Limited Purpose E-Money Providers in Kuwait This CBK regulation compiles circulars related to electronic payment services in Kuwait. It addresses various aspects of electronic payments, including fraud reporting, fee structures, payment links, BNPL services, cybersecurity, AML/CFT, and the use of POS devices. The regulation aims to provide guidance and controls for electronic payment service providers and related entities. Key requirements: - Local banks and EPIPs must submit card fraud reports. - EPIPs and their agents are prohibited from collecting fees from end users. - E-Payment Service Providers must adhere to minimum cybersecurity and business continuity requirements. - Regulated entities must adhere to AML/CFT instructions. - Local banks must implement measures for protection of customers from electronic fraud. ### CBK Instructions for Conventional Banks 2018 - URL: https://gcc-lexai.0xkaz.com/docs/831e5888-647c-49ea-b7a6-bbf80b431bde - Issuing body: CBK - Type: regulation - Topics: Personal Loans, Consumer Credit, Credit Cards, Lending Regulations - Applies to: Conventional Banks, Investment Companies, and Financing Companies in Kuwait This CBK regulation, effective November 11, 2018, outlines the rules for granting personal loans for consumer and housing purposes, and for the issuance of credit cards in Kuwait. It aims to regulate lending practices by banks and financial companies to meet actual customer needs, reduce excessive borrowing, and ensure lenders verify customer creditworthiness and provide financial advice. The instructions supersede previous guidelines on consumer and installment loans and credit cards. Key requirements: - Establishes maximum limits for personal loans and monthly installment ratios. - Details rules for loan application, minimum contract requirements, and controls for adjusting loan tenure and rescheduling in case of default. - Specifies regulations for interest pricing and collection methods for personal loans. - Sets maximum limits, repayment periods, and interest rates for credit cards issued by conventional banks. - Mandates lenders to verify customer needs, credit position, and provide financial advice regarding obligations and risks. ### CBK Instructions for Regulating Electronic Payment of Funds 2023 - URL: https://gcc-lexai.0xkaz.com/docs/0fe3aa33-28aa-4d59-b858-a42919755d23 - Issuing body: CBK - Type: regulation - Date: 2023 - Topics: Electronic Payments, Financial Regulation, Central Banking - Applies to: Kuwaiti banks, branches of foreign banks registered with CBK, shareholding or limited liability companies involved in electronic payment activities. CBK Resolution No. 45/47/1 of 2023 introduces instructions regulating electronic payment of funds in Kuwait. It revokes the previous Resolution No. 44/430 of 2018 and defines key terms related to electronic payments, electronic money, and the operation of e-payment systems. The regulation aims to provide a framework for electronic payment activities within the country. Key requirements: - Enrollment in the CBK registry for activity service providers. - Compliance with the definitions outlined in Article 1 regarding electronic payments. - Implementation of the resolution by all concerned entities and departments within their respective fields of competence. ### Kuwait CITRA Data Classification Policy v2.3 - URL: https://gcc-lexai.0xkaz.com/docs/bb97218e-d42b-446c-80a6-5ace4a6a8c64 - Issuing body: CITRA - Type: policy - Topics: data classification, data security, data protection - Applies to: Public and private sector entities in Kuwait The Kuwait CITRA Data Classification Policy v2.3 outlines a methodology for data classification in both the public and private sectors within Kuwait. It aims to define acceptable security protection levels, ensure adherence to best practices, and determine appropriate data handling, transmission, and processing methods to mitigate electronic risks. Key requirements: - Classify data into appropriate security levels based on sensitivity. - Define acceptable levels of security protection for each data category. - Adhere to best practices for data handling, transmission, and processing. - Take necessary measures to enhance the security and protection of data and personal data. ### Kuwait Data Privacy Protection Regulation (Resolution 42/2021) - URL: https://gcc-lexai.0xkaz.com/docs/10e06cb0-5a49-4f31-a702-a936aafa8ab2 - Issuing body: CITRA - Type: regulation - Date: 2021 - Topics: data protection, privacy regulation, Kuwait, CITRA - Applies to: The public and private sectors in the State of Kuwait Kuwait's Data Privacy Protection Regulation (Resolution 42/2021) establishes rules for data privacy within the country. Issued by CITRA, the regulation aims to protect personal data and ensure its responsible handling. It applies to both public and private sectors operating within the State of Kuwait and takes effect upon publication. Key requirements: - Compliance with the provisions of the Data Privacy Protection Regulation. - Application of the decision by competent authorities within their respective jurisdictions. - Adherence to the regulation from the date of its publication in the Official Gazette and on CITRA's website. ### Kuwait National Cybersecurity Strategy 2017–2020 - URL: https://gcc-lexai.0xkaz.com/docs/48524265-de4f-4d48-9174-c5a56728e60a - Issuing body: CITRA - Type: strategy - Date: 2020 - Topics: cybersecurity, critical infrastructure, risk management - Applies to: Government entities, the private sector, and individuals in Kuwait The Kuwait National Cybersecurity Strategy 2017-2020, issued by CITRA, outlines Kuwait's approach to cybersecurity, acknowledging the increasing cyber risks and threats facing the country. It aims to promote the security of national critical infrastructure and information, reduce cyber risks, and ensure a reliable and secure cyber environment for the government, private sector, and individuals. Key requirements: - Build new security capabilities to enhance the security of the State of Kuwait and its citizens. - Adopt essential technologies to improve the ability to deal with cyber security issues. - Promote the security of national critical infrastructure and information. - Reduce cyber risks that threaten the country’s economy and national security.