UAE Data Protection: Federal, DIFC and ADGM
Three separate regimes govern personal data in the UAE. This guide covers which applies to your entity and how to run a programme across all of them.
Key Takeaways
- The UAE has three separate data protection regimes: the federal PDPL, the DIFC law, and the ADGM regulations. Which applies depends on where the entity is registered, not where the data sits.
- Federal Decree-Law No. 45 of 2021 has been in force since 2 January 2022, but its executive regulations remain incomplete, leaving several operational details unresolved.
- The DIFC amended its law with effect from 15 July 2025, introducing a private right of action in the DIFC Courts and raising several fine ceilings.
- ADGM penalties for serious breaches are capped at USD 28 million under the Fines Rules 2021, with the independent ADGM Office of Data Protection enforcing.
- A group with mainland, DIFC and ADGM entities is running three programmes at once, and records of processing, consent evidence and breach procedures must be scoped per entity.
Which Regime Applies
Three Jurisdictions, Not One
The most common and most expensive mistake in UAE privacy programmes is assuming a single national law. There are three regimes, and they are genuinely separate: Federal Decree-Law No. 45 of 2021 applies across the Emirates and is overseen by the UAE Data Office; DIFC Law No. 5 of 2020 applies to entities established in the Dubai International Financial Centre and is enforced by the DIFC Commissioner of Data Protection; and the ADGM Data Protection Regulations 2021 apply to entities established in Abu Dhabi Global Market and are enforced by the independent ADGM Office of Data Protection.
Which regime governs an entity is determined by where that entity is registered. A DIFC-registered company is governed by the DIFC law rather than the federal Decree-Law, even for processing that happens physically elsewhere in the UAE. Financial services groups routinely hold entities in more than one of the three, which means one group can be answerable to three different regulators on the same underlying dataset.
The first deliverable in any UAE programme is therefore an entity map: which legal entities exist, where each is registered, and which processing activities each one controls.
Checklist:
- List every UAE legal entity and its registration jurisdiction
- Assign each processing activity to the controlling entity
- Identify activities shared across mainland and free-zone entities
- Confirm which regulator each entity answers to
- Flag any entity whose regime assumption has never been formally checked
The Federal Regime and Its Pending Regulations
Building Against an Incomplete Framework
Federal Decree-Law No. 45 of 2021 entered into force on 2 January 2022. Its substantive obligations are recognisable from the GDPR: a lawful basis for processing, transparency to data subjects, records of processing, a Data Protection Officer where processing is high risk or involves large volumes of sensitive data, impact assessments, breach notification, and a full set of data subject rights including access, rectification, erasure, restriction, portability and objection.
The complication is that the executive regulations expected to set out registration mechanics, response timelines and the detailed cross-border transfer conditions remain incomplete. Organizations sometimes read that as permission to wait. It is not: the obligations stated directly in the Decree-Law are in force now, and only the operational detail is outstanding.
The workable approach is to build to what the Decree-Law states, document the judgment calls made where it is silent, and structure the programme so that outstanding detail can be slotted in without rework. Recording the reasoning behind each judgment call matters as much as the decision itself, because it is the evidence that the organization acted in good faith on the law as it stood.
The Free-Zone Regimes
DIFC After the July 2025 Amendments
DIFC Law No. 5 of 2020 is closely modelled on the GDPR and has been enforced by the Commissioner of Data Protection since 2020. The amendment package that took effect on 15 July 2025 is the most significant change since enactment.
Two elements stand out. First, the introduction of a private right of action: individuals can now bring claims directly in the DIFC Courts without first exhausting administrative remedies. That shifts the risk profile of a DIFC entity from purely regulatory to litigation exposure, and it is the change most likely to be underestimated by teams that track only fine ceilings. Second, the revised penalty schedule raised the maximum fine for failing to conduct a data protection impact assessment before high-risk processing from USD 20,000 to USD 50,000, raised the maximum for non-compliance with the Article 28 public-authority disclosure obligations from USD 10,000 to USD 50,000, and made failure to submit the annual DPO assessment to the Commissioner a distinct breach attracting up to USD 25,000.
The annual DPO assessment is worth singling out because it is an easy, entirely avoidable failure: it is a recurring filing obligation, and missing it is now independently sanctionable.
ADGM and Running Multiple Regimes
The ADGM Data Protection Regulations 2021 were made on 14 February 2021 and applied from 14 August 2021 to entities registered on or after 14 February 2021, and from 14 February 2022 to entities that existed before that date. The structure again follows the GDPR, and the Fines Rules cap penalties for serious breaches at USD 28 million alongside smaller fixed fines for administrative failures.
For a group operating across mainland, DIFC and ADGM, the practical question is how much of the programme can be shared. Policies, training and security controls generally can be. What cannot be shared is the evidence layer: records of processing, consent records, impact assessments and breach registers all need to be attributable to the specific entity and producible to that entity's regulator.
ComplyIQ handles this by scoping compliance records per entity while allowing shared policy and control libraries, so a group runs one programme with three defensible evidence sets rather than three disconnected programmes or one undifferentiated pile.
Checklist:
- Diarise the DIFC annual DPO assessment filing
- Confirm which ADGM commencement date applies to each entity
- Separate evidence artefacts per entity while sharing policies and controls
- Maintain a per-entity breach register with the correct regulator named
- Review transfer arrangements separately for each regime
Tools That Help
Frequently Asked Questions
Does the UAE federal PDPL apply to DIFC and ADGM entities?
No. Entities registered in the DIFC are governed by DIFC Law No. 5 of 2020, and entities registered in ADGM are governed by the ADGM Data Protection Regulations 2021. Federal Decree-Law No. 45 of 2021 applies to entities outside those free zones.
Are the UAE federal executive regulations in force yet?
As of 2026 the executive regulations remain incomplete. The obligations set out directly in Federal Decree-Law No. 45 of 2021 are in force regardless, so organizations should build to those and document the judgment calls made where operational detail is still outstanding.
What changed in the DIFC data protection law in 2025?
Amendments effective 15 July 2025 introduced a private right of action allowing individuals to claim directly in the DIFC Courts, raised the maximum DPIA-failure fine from USD 20,000 to USD 50,000, raised the Article 28 disclosure fine from USD 10,000 to USD 50,000, and made failure to submit the annual DPO assessment a separate breach attracting up to USD 25,000.
Can one compliance programme cover all three UAE regimes?
Partly. Policies, training and security controls can be shared. Evidence artefacts such as records of processing, consent records, impact assessments and breach registers must be scoped per entity, because each is producible to a different regulator.