Abu Dhabi Global Market's free-zone data protection regime, enforced by the independent ADGM Office of Data Protection, with fines for serious breaches capped at USD 28 million.
Source: IQWorks Glossary โ iqworks.ai | Last updated: 2026-08-09
Last verified: August 9, 2026
ADGM DPR Regulation Guide
Requirements, penalties, individual rights, and enforcement details
The Data Protection Regulations 2021 govern entities established in Abu Dhabi Global Market, the financial free zone on Al Maryah Island. The Regulations were made on 14 February 2021 and applied from 14 August 2021 to entities registered on or after 14 February 2021, and from 14 February 2022 to entities already in existence before that date. Supporting Fees Rules and Fines Rules were issued alongside them.
Like the DIFC regime, the ADGM Regulations follow the GDPR structure: a lawful basis for each processing activity, transparency obligations, data subject rights, accountability documentation, impact assessments for high-risk processing, breach notification, and controls on international transfers. Enforcement sits with the independent ADGM Office of Data Protection, which has power to issue directions and impose fines for non-compliance with those directions or with the Regulations themselves. The Fines Rules cap penalties for serious breaches at USD 28 million, with much smaller fixed fines for administrative failures.
ADGM and DIFC are separate jurisdictions with separate regulators, and neither is governed by the UAE federal law. Organizations with entities in more than one of the three need to map obligations per entity rather than assuming a single UAE-wide programme will satisfy all of them.
How IQWorks Helps
Related Terms
DIFC Data Protection Law (DIFC Law No. 5 of 2020)
The Dubai International Financial Centre's own GDPR-aligned data protection law, enforced by the DIFC Commissioner of Data Protection, substantially amended in July 2025 to add a private right of action.
UAE PDPL (Federal Decree-Law No. 45 of 2021)
The UAE's federal personal data protection law, in force since January 2022, establishes controller and processor obligations across the Emirates, though its executive regulations remain incomplete, leaving several operational details unresolved.
Data Protection Impact Assessment (DPIA)
A Data Protection Impact Assessment is a systematic process for evaluating the potential impact of a data processing activity on individuals' privacy, required under the GDPR for processing likely to result in high risk to data subjects.
Records of Processing Activities (ROPA)
Records of Processing Activities is a mandatory documentation requirement under the GDPR that obliges organizations to maintain detailed records of all personal data processing activities they conduct.