Aureus Worldwide

ADGM

ADGM Data Protection Regulations 2021 Explained

· 8 min read · By Aureus Worldwide

ADGM Data Protection Regulations 2021 Explained

Any business established in the Abu Dhabi Global Market handles personal data under its own dedicated privacy law: the ADGM Data Protection Regulations 2021. Closely modelled on the EU General Data Protection Regulation (GDPR), these regulations set out how controllers and processors in ADGM must collect, use, secure and transfer personal data, and give individuals enforceable rights over their information. This guide explains what the ADGM Data Protection Regulations 2021 require, who they apply to, and the practical steps to compliance.

What the ADGM Data Protection Regulations 2021 are

The ADGM Data Protection Regulations 2021 came into force in February 2021, replacing ADGM's earlier 2015 regime and bringing the free zone up to the GDPR standard now expected of an international financial centre. They are administered by the Office of Data Protection, headed by the Commissioner of Data Protection, which registers entities, issues guidance and enforces the law. Because ADGM applies English common law directly and positions itself for global financial and professional services, its data protection framework is deliberately built to a standard that international counterparties recognise. Existing entities were given a transition period to reach full compliance; new entities are expected to comply from the outset.

Crucially, ADGM's regime is separate from both the DIFC's Data Protection Law 2020 and the UAE Federal Personal Data Protection Law (PDPL). Which law applies depends on where your entity is established and where the processing takes place.

Who the regulations apply to

The regulations apply to controllers and processors that process personal data in the context of activities carried on in ADGM:

  • A controller determines the purposes and means of processing personal data.
  • A processor processes personal data on a controller's behalf.
  • Personal data is any information relating to an identified or identifiable natural person (a data subject).
  • Special categories of data, health, biometric, genetic, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, and data about a person's sex life or sexual orientation, attract stricter conditions.

These obligations bite whether you are a bank, a fund manager, a holding company, a family office or a professional-services firm. Any ADGM entity that holds employee, client or counterparty data is within scope.

The core data protection principles

Like the GDPR, ADGM's regulations are built on a set of principles that every processing activity must satisfy:

  1. Lawfulness, fairness and transparency, process data on a valid legal basis and tell people what you do with it.
  2. Purpose limitation, collect data for specified, legitimate purposes and nothing more.
  3. Data minimisation, hold only what you genuinely need.
  4. Accuracy, keep data correct and up to date.
  5. Storage limitation, retain data no longer than necessary.
  6. Integrity and confidentiality, secure data with appropriate technical and organisational measures.
  7. Accountability, be able to demonstrate compliance with all of the above.

Accountability is the principle that turns the others into work: it is not enough to comply, you must be able to show that you comply.

Lawful bases for processing

You may only process personal data where you have a lawful basis. The regulations recognise the familiar GDPR-style grounds:

  • Consent of the data subject;
  • Performance of a contract with the data subject;
  • Compliance with a legal or regulatory obligation;
  • Protection of someone's vital interests;
  • Performance of a task in the public interest; or
  • Legitimate interests pursued by the controller, balanced against the individual's rights and freedoms.

Processing special-category data requires an additional, narrower condition, for example explicit consent or a specific employment-law obligation. Choosing and documenting the right basis for each activity is a foundational step, not an afterthought.

Rights of data subjects

The regulations give individuals a suite of enforceable rights. Controllers must have processes to recognise and respond to them within the timeframes the regulations set.

Right What it means
Access Obtain confirmation and a copy of their personal data
Rectification Correct inaccurate or incomplete data
Erasure Have data deleted where there is no lawful reason to keep it
Restriction Limit processing in certain circumstances
Portability Receive their data in a usable format, or have it transferred
Objection Object to processing, including direct marketing
Automated decisions Not be subject to solely automated decisions with significant effects

Accountability in practice

Meeting the accountability principle means putting documented governance in place:

  • Records of processing activities (RoPA), maintain an inventory of what you process, why, and with whom you share it.
  • Data protection impact assessments (DPIAs), assess high-risk processing before you begin.
  • Data protection by design and by default, build privacy into systems and default to the least intrusive settings.
  • Processor contracts, impose the required data protection terms on any vendor that processes data on your behalf.
  • A Data Protection Officer (DPO) where the thresholds are met, see our detailed guide to DPO obligations under the ADGM Data Protection Regulations.
  • Security measures, appropriate technical and organisational safeguards against loss, misuse or unauthorised access.

Data breach notification

Where a personal data breach occurs, the controller must notify the Office of Data Protection without undue delay once it becomes aware of it, unless the breach is unlikely to result in a risk to individuals. Where the breach is likely to result in a high risk to the rights of those affected, the individuals themselves must also be told without undue delay. This makes an internal breach-response process essential: you cannot notify on time if you cannot detect and escalate a breach quickly. Keep a record of every breach, including those you decide are not notifiable, and the reasoning behind that decision.

International data transfers

Personal data may be transferred out of ADGM only where the destination provides adequate protection. The regulations permit transfers:

  • to a jurisdiction the Commissioner has recognised as providing an adequate level of protection;
  • subject to appropriate safeguards, such as approved contractual clauses or binding-corporate-rules-type arrangements; or
  • on a specific derogation, such as the data subject's explicit consent or necessity for the performance of a contract.

Groups that move HR or customer data between ADGM and offices abroad need to map those flows and paper them correctly, because an undocumented transfer is a common and avoidable breach.

Registration with the Office of Data Protection

ADGM operates a registration system. Controllers and processors generally register with the Office of Data Protection and renew annually, providing information that can include whether a DPO has been appointed. Fees, forms and timelines are set by ADGM and updated from time to time, so confirm the current requirements directly. Registration and renewal are part of the ongoing compliance calendar that every ADGM entity should maintain.

Enforcement and penalties

The Commissioner has real teeth. Non-compliance can lead to enforcement directions, orders to stop processing, and administrative fines. Beyond the financial penalty, a data protection failure in a jurisdiction chosen for its credibility carries a reputational cost with the banks, investors and counterparties who expect an international standard. Because specific fine levels are set by ADGM and revised over time, treat robust compliance as the objective rather than budgeting for penalties.

Three UAE regimes at a glance

Regime Applies to Regulator
ADGM Data Protection Regulations 2021 Entities in ADGM Office of Data Protection (Commissioner)
DIFC Data Protection Law 2020 Entities in the DIFC DIFC Commissioner of Data Protection
UAE Federal PDPL (Decree-Law 45/2021) Businesses in the wider UAE UAE Data Office

A group with entities in more than one of these zones may need to comply with more than one law at once, see our overviews of the DIFC and federal PDPL regimes.

A practical compliance checklist

  1. Confirm the ADGM regulations, not the DIFC law or PDPL, apply to your entity.
  2. Map your data: what you hold, why, where it sits and who you share it with.
  3. Document a lawful basis for each processing activity.
  4. Build and maintain your records of processing activities.
  5. Update privacy notices to the ADGM standard.
  6. Put data protection terms into every processor contract.
  7. Assess whether you are required to appoint a DPO.
  8. Stand up a breach-detection and notification process.
  9. Map and paper your cross-border transfers.
  10. Register with the Office of Data Protection and diarise the annual renewal.

How Aureus Worldwide can help

Aureus Worldwide is a Dubai-based accounting, tax and compliance-advisory firm. We are not a law firm and not an ADGM-registered auditor, so we work alongside your legal counsel where a formal interpretation of the regulations is required. What we do is help you operationalise data protection: mapping data flows, building your records of processing, drafting the practical policies and vendor controls, resourcing the DPO function through our compliance officers service, and keeping your registration and renewals on track as part of the broader DIFC and ADGM compliance we manage. Sound accounting and governance underpin all of it. To review your ADGM data protection obligations, contact us.

Frequently asked questions

What are the ADGM Data Protection Regulations 2021?

They are ADGM's dedicated data protection law, in force since February 2021 and closely modelled on the EU GDPR. They govern how controllers and processors in the Abu Dhabi Global Market collect, use, secure and transfer personal data, and are administered by ADGM's Office of Data Protection under the Commissioner of Data Protection.

Do the ADGM regulations apply if I already comply with the UAE PDPL?

Not necessarily. ADGM has its own regime that is separate from both the UAE Federal PDPL and the DIFC Data Protection Law. If your entity is established in ADGM and processes data there, the ADGM Data Protection Regulations 2021 apply to that activity, and a group operating across zones may need to comply with more than one law at once.

Does every ADGM entity need to register for data protection?

ADGM controllers and processors generally register with the Office of Data Protection and renew annually. Because fees, forms and timelines are set by ADGM and updated from time to time, confirm the current registration requirements with the Office of Data Protection rather than relying on a summary.

When must an ADGM data breach be reported?

A controller must notify the Office of Data Protection without undue delay after becoming aware of a personal data breach, unless it is unlikely to result in a risk to individuals. Where the breach is likely to result in a high risk to those affected, the individuals must also be told without undue delay.

Talk to our chartered accountants →