ADGM Data Protection Regulations 2021 compliance software
Abu Dhabi Global Market's data protection law, section by section — 78 obligations across 10 domains from the 2021 Regulations as amended to September 2025, with the 72-hour breach clock and the annual fee tracked as their own indicators.
- RegulatorADGM Office of Data Protection (Commissioner of Data Protection)
- InstrumentData Protection Regulations 2021, consolidated to Amendment No. 1 of 2025 (in force 9 Sep 2025)
- Structure10 domains, 78 controls, each citing its section
- FinesSection 55: up to USD 28 million per Penalty Notice; section 56: up to 150% of an unpaid fee
What ADGM DP Regulations requires
Who it applies to
- Every controller and processor established in ADGM
- Processors in ADGM acting for controllers outside the zone
- FSRA Authorised Persons already assessed against ADGM GEN 3.5
- Groups with both a DIFC and an ADGM entity
The ADGM Data Protection Regulations 2021 replaced the 2015 regulations and apply to processing in the context of an ADGM establishment's activities, wherever the processing takes place, and to processors in ADGM acting for controllers elsewhere. Enacted 11 February 2021, they bound new establishments after six months and existing ones after twelve, and have been amended in 2022, 2024 and 2025. The Office of Data Protection, led by the Commissioner of Data Protection, registers controllers, collects the annual Data Protection Fee and enforces the Regulations. The federal PDPL does not apply inside the zone.
The obligations run from the processing principles, lawful bases, consent and special categories (sections 4–9) through transparency (10–12), the data subject rights (13–21), accountability, registration, records and joint controllers (22–25, 28), processor contracts (26–28), security, cessation and breach notification within 72 hours (30–33), DPIAs and the DPO (34–37), transfers outside ADGM (40–45) and enforcement (54–59). Section 55 caps a Penalty Notice at USD 28 million with no turnover tier; section 56 adds a fixed penalty for an unpaid fee.
GRCLens transcribes the Regulations section by section from the ADGM Rulebook's consolidated text, cites the section on every control, and gives ADGM the same six privacy indicators as the DIFC catalogue so a group with entities in both zones reads them side by side.
How GRCLens supports ADGM DP Regulations
ADGM DP Regulations runs on the same shared control model as every other framework in GRCLens, so evidence captured once can satisfy several obligations at the same time.
Dates, not judgements
The section 24 notification and Data Protection Fee, its annual renewal, and the one-month DPO notification are the sanctions that need no investigation. They are tracked as one readiness indicator.
72 hours
Section 32 fixes the breach clock at 72 hours from awareness, with reasons for any delay. The breach indicator counts every unmet duty in the chain from security measures to data subject communication.
Reads beside DIFC and FSRA
The same six privacy indicators as the DIFC DP Law, and the same tenant as ADGM GEN 3.5 cyber rules, so an FSRA firm's board sees cyber and privacy on one dashboard.
Arabic and English
Every section-level obligation carries Arabic with the same enumerators as the English.
ADGM DP Regulations frequently asked questions
How do the ADGM Regulations differ from the DIFC Law?
Mostly in detail: ADGM fixes breach notification at 72 hours where DIFC says 'as soon as practicable'; ADGM has an annual Data Protection Fee with a fixed penalty; DIFC has an Annual Assessment, a separate digital-marketing regime and the Regulation 10 AI rules. GRCLens carries both with matching domains so the differences are visible control by control.
Is a transfer to onshore UAE a transfer outside ADGM?
Yes. Section 40 applies the transfer Part to any transfer outside ADGM, and the federal PDPL is not an adequacy decision. Onshore group entities need appropriate safeguards or a derogation like any other destination.
What changed in 2025?
Amendment No. 1 of 2025 (in force 9 September 2025) added a Board rule-making condition for special-category processing in section 7 and corrected cross-references. The catalogue is consolidated to that text.
One platform, many obligations

Talk to us about ADGM DP Regulations
Security Solution Consultants provides ADGM data protection advisory alongside the platform, so you can combine tooling with hands-on expertise.