All frameworks
ADGADGM Regulations 2021 · consolidated Feb 2024 + SPI Rules 2025 · Office of Data Protection

ADGM DPR compliance

The GDPR-grade law of Abu Dhabi Global Market.

The ADGM Data Protection Regulations 2021 are the data-protection law of Abu Dhabi Global Market, a common-law financial free zone with its own courts and its own Office of Data Protection. They are explicitly modelled on the EU and UK GDPR, so the principles, six lawful bases including legitimate interests, individual rights, records of processing, security, breach notification, the Data Protection Officer and impact assessments will all be familiar. What differs is in the detail, and those details are exactly where a reused GDPR programme slips: the response clock for data-subject requests is two months rather than one, the breach clock is a risk-gated seventy-two hours, every establishment keeps a record of processing with no small-entity exemption, the impact-assessment duty is to notify the regulator rather than consult it, and every controller and processor registers and pays an annual data-protection fee. The Regulations were consolidated in February 2024 and extended by the Substantial Public Interest (Conditions) Rules 2025.

Start from the basics

The standard

ADGM Data Protection Regulations 2021 (Abu Dhabi Global Market)

Who needs it

Any entity registered in or operating from Abu Dhabi Global Market that processes personal data, from financial firms and funds to the professional and corporate services around them. Businesses in mainland UAE follow the federal PDPL, and those in the DIFC follow the DIFC law, so a group spanning all three runs them side by side on one UAE track.

64

Sections, fully mapped

The basics

What is ADGM DPR?

The ADGM DPR apply to controllers and processors established in the ADGM, and reach a processor acting for a controller outside the ADGM so far as possible. They follow the GDPR structure: the Part 2 principles and accountability, the six lawful bases in section 5, the special categories in section 7 (into which ADGM folds criminal-conviction data), the rights to access, rectification, erasure, restriction, portability and objection in sections 13 to 21, and the controller and processor duties for records, security, breach, the DPO and impact assessments.

The differences from GDPR are specific and consequential. The response time for rights requests is two months, not one. Breaches are notified to the Commissioner within seventy-two hours where feasible, risk-gated. Records of processing have no '250 employee' exemption, so every establishment keeps them. A data protection impact assessment that shows high risk is notified to the Commissioner, not merely consulted on. There is no journalism or academic basis. And every controller and processor must register, file a processing notification and pay an annual fee under section 24, with a fewer-than-five-employee carve-out that is lost the moment the entity does high-risk processing.

Why it matters

What ADGM DPR does for your business

Registration and an annual fee

Unlike GDPR, ADGM controllers and processors register with the Commissioner, file a processing notification and pay an annual data-protection fee under section 24, renewing within a month of the anniversary.

A two-month rights clock

The response deadline for data-subject requests is two months, not GDPR's one and not the DIFC's one, which is an easy mis-configuration if you reuse another regime's tooling.

Impact assessments are notified

Where a DPIA shows high risk, ADGM requires you to notify the Commissioner, a step beyond GDPR's and the DIFC's consult-the-regulator wording.

A clear fine ceiling

The Commissioner can impose a single absolute fine of up to USD 28 million, with no turnover-percentage tiering, plus a penalty of up to 150% of an unpaid fee.

What it covers

Principles & lawful basis

The section 4 principles and accountability, and the six section 5 bases including legitimate interests, which is not available to public authorities for their official tasks.

Transparency & records

The section 10 to 12 information duties, including the enhanced explanation where a right is curtailed, and the section 28 record of processing with no size exemption.

Individual rights

Access, rectification, erasure, restriction, portability and objection on a two-month clock, with an absolute right to object to direct marketing (sections 13 to 21).

Security & breach

Appropriate measures and privacy by design and default (sections 23, 30, 31), with breach notification to the Commissioner within 72 hours where feasible (sections 32 to 33).

DPO, DPIA & registration

A DPO notified to the Commissioner within a month (sections 35 to 37), DPIAs that notify the regulator where high risk (section 34), and registration with an annual fee (section 24).

Transfers & enforcement

Schedule 3 adequacy, section 42 safeguards, BCRs and derogations for transfers, and the Office of Data Protection's powers up to a USD 28m fine (sections 41 to 59).

The hard way

Teams assume ADGM is just GDPR because it reads like it, then miss the ADGM-only duties: the two-month rights clock, the registration and annual fee, the notify-the-regulator DPIA, the record of processing with no size relief, and a breach standard worded differently from both GDPR and the DIFC. Running those by hand, while a group also runs the federal PDPL and the DIFC law, is where things go wrong.

The easier way, with Compliance One

  • A ready control library covering the ADGM Regulations across 16 domains, including the substantial-public-interest conditions and the 2025 insurance and vulnerable-group rules, so you implement the GDPR-grade baseline and the ADGM-specific duties together.
  • The shared privacy registers, records of processing, consent, rights requests, DPIAs, breach, transfers, retention, configured for the ADGM's vocabulary, its two-month rights clock and the Office of Data Protection.
  • Cross-mapping to GDPR so a single evidence set counts across both, with the federal PDPL and the DIFC on the same UAE track for groups that span onshore and the free zones.
  • Reminders for the ADGM-only deadlines, the annual registration renewal, the two-month rights clock, the 72-hour breach window and the DPIA regulator notification, alongside DPO and transfer-safeguard triggers.

Do it once, reuse it everywhere. Evidence you collect for ADGM DPR is automatically mapped to every other framework whose controls it also satisfies — and since these standards overlap heavily, most of that work isn't repeated.

Common questions

How is ADGM different from the DIFC and the federal PDPL?
ADGM and the DIFC are separate common-law free zones, each with its own regulator; both are GDPR-grade, while the federal PDPL is consent-first. ADGM's rights clock is two months (the DIFC's is one), its breach clock is 72 hours (the DIFC's is 'as soon as practicable'), and its DPIA duty is to notify, not consult. We cover all three on one UAE track.
Do we have to register and pay a fee?
Yes. Under section 24 every ADGM controller and processor registers, files a processing notification and pays an annual data-protection fee, renewing within a month of the anniversary. A fewer-than-five-employee exemption exists but is lost if you do high-risk processing.
What is the deadline for data-subject requests?
Two months from receipt, free of charge, extendable by one further month for complex or numerous requests (section 10). This is longer than GDPR's one month and the DIFC's one month.
What are the SPI Rules 2025?
The Substantial Public Interest (Conditions) Rules 2025 add defined conditions, notably for insurance processing and processing concerning vulnerable groups, each with its own safeguards and policy-document requirement. We provide a policy-document template for them.

Ready to tackle ADGM DPR?

See exactly how Compliance One maps ADGM DPR to your environment in a 30-minute walkthrough — and how much of it we handle for you.