Skip to content
GlanceDeskJurisdiction

Home › Law library › ADGM DPR

AE

ADGM DPR

ADGM Data Protection Regulations 2021

Sourced. Last verified 9 October 2026

Abu Dhabi Global Market (UAE free zone) Privacy

Status
In force since 14 February 2021 (transition periods have ended).
Who it applies to
Processing by controllers/processors established in or operating out of ADGM, wherever the processing takes place, including outside ADGM.
Size thresholds
Applies to all ADGM entities. Firms with fewer than 5 employees are exempt from DPO appointment unless they do high-risk processing.
Regulator
Commissioner of Data Protection, ADGM Office of Data Protection
Breach or incident reporting
Notify the Commissioner within 72 hours of becoming aware, unless unlikely to risk individuals' rights; explain any delay. Tell affected people without undue delay if the breach is high risk.
Deadline to answer personal data requests
Two months from receipt, extendable by a further two months for complex requests.
Data protection officer
Required in certain cases (e.g., high-risk processing). Need not be ADGM-based or an employee, but must have expert data protection knowledge.
Local representative
Being verified
Sending data abroad
Being verified
Cookies and consent
Being verified
Maximum penalty
Up to USD 28 million for administrative breaches (cap applies cumulatively to linked breaches), with scope for higher fines for more serious violations.

Facts marked “Being verified” are still being confirmed and are not given as answers.

What you must do

Recent changes

September 2025: ADGM issued the Substantial Public Interest Conditions Rules on processing special category data.

Sources

Information only, not legal advice. Laws change; confirm with the regulator or a qualified lawyer before relying on this page. Spotted an error? Email [email protected].