Registration and an annual fee
Unlike GDPR, ADGM controllers and processors register with the Commissioner, file a processing notification and pay an annual data-protection fee under section 24, renewing within a month of the anniversary.
The GDPR-grade law of Abu Dhabi Global Market.
The ADGM Data Protection Regulations 2021 are the data-protection law of Abu Dhabi Global Market, a common-law financial free zone with its own courts and its own Office of Data Protection. They are explicitly modelled on the EU and UK GDPR, so the principles, six lawful bases including legitimate interests, individual rights, records of processing, security, breach notification, the Data Protection Officer and impact assessments will all be familiar. What differs is in the detail, and those details are exactly where a reused GDPR programme slips: the response clock for data-subject requests is two months rather than one, the breach clock is a risk-gated seventy-two hours, every establishment keeps a record of processing with no small-entity exemption, the impact-assessment duty is to notify the regulator rather than consult it, and every controller and processor registers and pays an annual data-protection fee. The Regulations were consolidated in February 2024 and extended by the Substantial Public Interest (Conditions) Rules 2025.
The standard
ADGM Data Protection Regulations 2021 (Abu Dhabi Global Market)
Who needs it
Any entity registered in or operating from Abu Dhabi Global Market that processes personal data, from financial firms and funds to the professional and corporate services around them. Businesses in mainland UAE follow the federal PDPL, and those in the DIFC follow the DIFC law, so a group spanning all three runs them side by side on one UAE track.
64
Sections, fully mapped
The basics
The ADGM DPR apply to controllers and processors established in the ADGM, and reach a processor acting for a controller outside the ADGM so far as possible. They follow the GDPR structure: the Part 2 principles and accountability, the six lawful bases in section 5, the special categories in section 7 (into which ADGM folds criminal-conviction data), the rights to access, rectification, erasure, restriction, portability and objection in sections 13 to 21, and the controller and processor duties for records, security, breach, the DPO and impact assessments.
The differences from GDPR are specific and consequential. The response time for rights requests is two months, not one. Breaches are notified to the Commissioner within seventy-two hours where feasible, risk-gated. Records of processing have no '250 employee' exemption, so every establishment keeps them. A data protection impact assessment that shows high risk is notified to the Commissioner, not merely consulted on. There is no journalism or academic basis. And every controller and processor must register, file a processing notification and pay an annual fee under section 24, with a fewer-than-five-employee carve-out that is lost the moment the entity does high-risk processing.
Why it matters
Unlike GDPR, ADGM controllers and processors register with the Commissioner, file a processing notification and pay an annual data-protection fee under section 24, renewing within a month of the anniversary.
The response deadline for data-subject requests is two months, not GDPR's one and not the DIFC's one, which is an easy mis-configuration if you reuse another regime's tooling.
Where a DPIA shows high risk, ADGM requires you to notify the Commissioner, a step beyond GDPR's and the DIFC's consult-the-regulator wording.
The Commissioner can impose a single absolute fine of up to USD 28 million, with no turnover-percentage tiering, plus a penalty of up to 150% of an unpaid fee.
The section 4 principles and accountability, and the six section 5 bases including legitimate interests, which is not available to public authorities for their official tasks.
The section 10 to 12 information duties, including the enhanced explanation where a right is curtailed, and the section 28 record of processing with no size exemption.
Access, rectification, erasure, restriction, portability and objection on a two-month clock, with an absolute right to object to direct marketing (sections 13 to 21).
Appropriate measures and privacy by design and default (sections 23, 30, 31), with breach notification to the Commissioner within 72 hours where feasible (sections 32 to 33).
A DPO notified to the Commissioner within a month (sections 35 to 37), DPIAs that notify the regulator where high risk (section 34), and registration with an annual fee (section 24).
Schedule 3 adequacy, section 42 safeguards, BCRs and derogations for transfers, and the Office of Data Protection's powers up to a USD 28m fine (sections 41 to 59).
Teams assume ADGM is just GDPR because it reads like it, then miss the ADGM-only duties: the two-month rights clock, the registration and annual fee, the notify-the-regulator DPIA, the record of processing with no size relief, and a breach standard worded differently from both GDPR and the DIFC. Running those by hand, while a group also runs the federal PDPL and the DIFC law, is where things go wrong.
Do it once, reuse it everywhere. Evidence you collect for ADGM DPR is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.
See exactly how Compliance One maps ADGM DPR to your environment in a 30-minute walkthrough — and how much of it we handle for you.