The ADGM Data Protection Regulations explained
The ADGM Data Protection Regulations 2021 are the data-protection law of Abu Dhabi Global Market, a common-law financial free zone with its own Office of Data Protection. They were explicitly modelled on the EU and UK GDPR, so most of the structure is familiar. The differences are specific, and they are exactly the kind of thing a reused GDPR programme gets wrong.
The familiar GDPR shape
Six lawful bases including legitimate interests (section 5), special categories in section 7, the full set of rights in sections 13 to 21, records of processing, security, breach notification, a DPO and impact assessments. If you know GDPR, you know the skeleton. One quiet divergence worth noting: ADGM folds criminal-conviction data into its special categories, and there is no journalism or academic basis.
A two-month rights clock
This is the single easiest thing to mis-configure. The ADGM response deadline for data-subject requests is two months, extendable by one further month, free of charge (section 10). That is not GDPR's one month, and it is not the DIFC's one month. If you reuse another regime's tooling and leave the clock at thirty days, you are measuring yourself against a deadline the law does not set.
Registration, breach and impact assessments
Like the DIFC, ADGM requires controllers and processors to register, file a processing notification and pay an annual fee (section 24). There is a fewer-than-five-employee carve-out, but it is lost the moment you do high-risk processing. Breaches are notified to the Commissioner within seventy-two hours where feasible, risk-gated (section 32). And where a DPIA shows high risk, ADGM requires you to notify the Commissioner (section 34(7)), a step beyond GDPR's and the DIFC's consult-the-regulator wording.
Two more ADGM specifics: records of processing have no small-entity exemption, so every establishment keeps them (section 28), and the DPO need not reside in the ADGM but must be notified to the Commissioner within one month of appointment (section 35(4)).
A clear fine ceiling, and the 2025 rules
ADGM caps administrative fines at a single absolute figure of USD 28 million (section 55), with no GDPR-style turnover percentage, plus a penalty of up to 150% of an unpaid fee. And in 2025 the Substantial Public Interest (Conditions) Rules added defined conditions, notably for insurance processing and processing concerning vulnerable groups, each with its own safeguards and policy-document requirement.
ADGM is GDPR you can mostly reuse, as long as you remember the clock is two months, the DPIA gets notified, and everyone keeps a record of processing no matter how small.
In Compliance One
The ADGM control library covers the Regulations across sixteen domains, including the substantial-public-interest conditions and the 2025 insurance and vulnerable-group rules. The shared registers are set to the two-month rights clock and the Office of Data Protection, cross-mapped to GDPR, with reminders for the registration renewal, the two-month rights deadline, the seventy-two-hour breach window and the DPIA regulator notification.
See it on your own frameworks
Book a 30-minute walkthrough and we'll map this to your environment.