DIFC and ADGM data protection,
how the free zone regimes work.
The two financial free zones in the UAE run their own GDPR-style data protection laws, with their own regulators, registration fees and fines. This guide covers what each requires, how they differ from the federal PDPL, and which one applies to your entity. Not legal advice: check the current consolidated text with counsel.
Last updated Published by TryTrustableNot legal advice
The DIFC Data Protection Law (DIFC Law No. 5 of 2020) applies to companies incorporated in the Dubai International Financial Centre and to anyone processing personal data in the DIFC as part of stable arrangements. The ADGM Data Protection Regulations 2021 apply to processing in the context of an establishment in Abu Dhabi Global Market. Both are close to the GDPR, both require registration with their Commissioner of Data Protection, and both replace the federal UAE PDPL for companies inside those free zones. Companies on the Dubai or Abu Dhabi mainland, and in free zones without their own data protection law, fall under the federal PDPL instead.
Which data protection law applies in Dubai and Abu Dhabi?
The UAE has one federal data protection law, the UAE PDPL, and two free zone regimes outside it: the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) have their own laws, courts and data protection regulators.
| Where your entity is | Data protection law | Regulator |
|---|---|---|
| DIFC (Dubai) | DIFC Data Protection Law No. 5 of 2020 and the DIFC Data Protection Regulations | DIFC Commissioner of Data Protection |
| ADGM (Abu Dhabi) | ADGM Data Protection Regulations 2021 | ADGM Commissioner of Data Protection (Office of Data Protection) |
| Dubai or Abu Dhabi mainland | Federal Decree-Law No. 45 of 2021 (UAE PDPL) | UAE Data Office |
| Another free zone without its own data protection law | UAE PDPL | UAE Data Office |
| Outside the UAE, processing data of people in the UAE | UAE PDPL; and DIFC law if you process in the DIFC as part of stable arrangements | UAE Data Office; DIFC Commissioner |
A group with a DIFC entity and a mainland entity usually answers to both regimes, one per entity. PDPL Article 2(2)(g) excludes free zones with their own data protection legislation.
The DIFC Data Protection Law No. 5 of 2020
The DIFC Data Protection Law came into force on 1 July 2020, replacing the 2007 law. The current consolidated version (July 2025) includes amendments made in 2022 and by DIFC Laws Amendment Law No. 1 of 2025. It is closely modelled on the GDPR: lawful bases including consent and legitimate interests, special categories of personal data, data protection by design and by default, records of processing, DPIAs, processor contracts and the full set of data subject rights.
Who it covers. Under Article 6 it applies to a controller or processor incorporated in the DIFC, wherever the processing happens, and to any controller or processor processing personal data in the DIFC as part of stable arrangements, wherever it is incorporated.
Registration. Every controller and processor must register with the Commissioner of Data Protection by filing a notification of its processing operations (Article 14(7)). Under the Regulations the notification is due within 30 days of starting processing and is renewed each year. Fees depend on the category: USD 1,250 to register and USD 500 to renew for DFSA-authorised firms, USD 750 and USD 250 for other non-retail firms, and USD 250 and USD 100 for retail.
DPO. A DPO is mandatory for DIFC Bodies and for any controller or processor carrying out High Risk Processing Activities on a systematic or regular basis, and the Commissioner can require one in other cases. The DPO must reside in the UAE unless they hold a similar group-wide role. Controllers that must appoint a DPO also file an annual assessment of their processing (Article 19). Organisations that do not need a DPO must still allocate responsibility for data protection clearly. See our DPO guide.
Breaches. A controller must notify the Commissioner as soon as practicable of a personal data breach that compromises a data subject's confidentiality, security or privacy, and tell affected data subjects as soon as practicable where the breach is likely to result in a high risk to them (Articles 41 and 42). Processors must tell the controller without undue delay.
Transfers. Transfers out of the DIFC need an adequate level of protection in the destination, as determined by the Commissioner, or appropriate safeguards under Article 27, such as standard data protection clauses adopted by the Commissioner or binding corporate rules, or one of its derogations. See standard contractual clauses.
DIFC fines and the private right of action
The Commissioner can issue administrative fines up to the amounts in Schedule 2 for each contravention, and a general fine that is not limited to those amounts. Data subjects who suffer damage, including distress, can also apply to the DIFC Courts for compensation from the controller or processor (Article 64A).
| DIFC contravention (Schedule 2) | Maximum fine per contravention |
|---|---|
| Failing to register with the Commissioner (Article 14(7)), keep records (Article 15) or complete the annual assessment (Article 19) | USD 25,000 |
| Breaching the general processing requirements (Articles 9 to 12) or security measures (Article 14(2)) | USD 50,000 |
| Failing to appoint a DPO (Article 16) or run a DPIA before High Risk Processing (Article 20) | USD 50,000 |
| Failing to report a personal data breach (Articles 41 and 42) | USD 50,000 |
| Transparency failures (Articles 29 to 31) | USD 75,000 |
| Failing to honour data subject rights (Articles 33 to 38) | USD 100,000 |
Article 62(3) also lets the Commissioner impose a general fine not limited to these amounts, proportionate to the seriousness of the contravention and the risk of harm.
DIFC Regulation 10: AI and autonomous systems
Regulation 10 of the DIFC Data Protection Regulations (in the consolidated version in force from 1 September 2023) deals with personal data processed through autonomous and semi-autonomous systems, which in practice covers many AI systems. It introduces the roles of deployer (the person on whose authority, or for whose benefit, a system runs) and operator (a provider running the system for a deployer), held to standards similar to a controller and a processor. Where a website or app uses such a system to process personal data, the deployer or operator must:
- give clear notice on first use that the system may process personal data in ways that are not human-initiated, and how that affects people's rights;
- describe the human-defined purposes, the principles and limits within which the system can set further purposes, the outputs and how they are used, the safeguards built in, and the codes or frameworks it was built to (the Regulation names, among others, the NIST AI framework and OECD and UNESCO principles);
- on request, provide evidence of algorithms that seek human intervention where processing could be unfair or discriminatory, plus a risk and impact assessment; and
- on request, provide a register of use cases, data access routes for data subjects, whether decisions are fully automated, third parties involved and transfer safeguards.
The guidance notes say certification requirements are expected in future guidance. If you deploy AI to DIFC users, our guides to the NIST AI RMF and ISO 42001 cover the frameworks the notice can point to.
The ADGM Data Protection Regulations 2021
ADGM enacted its Data Protection Regulations 2021 on 14 February 2021, replacing the 2015 regulations. For entities incorporated on or after that date they took effect on 14 August 2021. The DPR 2021 apply to processing in the context of the activities of an establishment of a controller or processor in ADGM, whether or not the processing takes place in ADGM, and regardless of where the data subjects are. ADGM's Office of Data Protection describes them as closely aligned with the GDPR.
- Registration and fee. ADGM registered entities that process personal data must register as data controllers and pay a data protection fee (section 24 and the Fees Rules 2021) and a yearly renewal fee. Failing to pay can bring a fine of up to 150% of the fee.
- DPO. Mandatory for public authorities, and where core activities involve regular and systematic monitoring of data subjects on a large scale, or large-scale processing of special categories of data.
- Breaches. Notify the Commissioner without undue delay and, where feasible, within 72 hours; tell data subjects without undue delay when the breach is likely to result in a high risk to them.
- Transfers. ADGM follows the European Commission's approach of designating adequate jurisdictions, and has published an addendum for using the EU standard contractual clauses.
- Fines. The Commissioner can impose fines of up to USD 28 million.
- Micro-businesses. Some exemptions apply to entities with five or fewer employees, unless they carry out high-risk processing.
DIFC vs ADGM vs the federal PDPL
| Topic | DIFC DP Law 2020 | ADGM DPR 2021 | Federal UAE PDPL |
|---|---|---|---|
| In force | 1 July 2020 (consolidated to July 2025) | Enacted 14 February 2021; from 14 August 2021 for entities formed after enactment | 2 January 2022; Executive Regulations not found as of October 2026 |
| Lawful bases | GDPR-style, including legitimate interests | GDPR-style, including legitimate interests | Consent by default, with listed exceptions; no general legitimate interests basis |
| Registration | Notification to the Commissioner within 30 days of starting processing, renewed yearly, with a fee | Register as a controller and pay the data protection fee and yearly renewal | No registration; notify the Data Office of DPO details |
| DPO | Mandatory for DIFC Bodies and for High Risk Processing Activities on a systematic or regular basis; must reside in the UAE unless a group role | Mandatory for public authorities, large-scale regular and systematic monitoring, or large-scale special category data | Mandatory for high-risk processing, systematic assessment of sensitive data, or large volumes of sensitive data |
| Breach notice to regulator | As soon as practicable | Without undue delay, within 72 hours where feasible | Within the period the Executive Regulations set |
| Fines | Up to USD 100,000 per listed contravention, plus general fines not limited to those amounts | Up to USD 28 million | To be set by Cabinet decision; none published |
| Private claims | Data subjects can apply to the DIFC Courts for compensation (Article 64A) | Individuals can seek remedies through the ADGM Courts | Complaints to the Data Office |
| AI and autonomous systems | Regulation 10 on autonomous and semi-autonomous systems | Rights on automated individual decision-making, including profiling | Right to object to automated decisions (Article 18) |
Summarised from the statutes and regulators' guidance listed in our sources. Check the current consolidated versions.
How TryTrustable helps with DIFC and ADGM data protection
The DIFC Data Protection Law and ADGM Data Protection Regulations are both modelled in the platform, next to the UAE PDPL, and map to the same control library as GDPR.
| DIFC or ADGM requirement | What TryTrustable does |
|---|---|
| Lawful basis, consent and withdrawal | A consent banner and tamper-evident consent ledger, with withdrawals relayed to your processors and each delivery logged |
| Data subject rights | A rights-request queue with deadlines, and a public intake endpoint your own form can post to |
| Records, accountability and DPIA | DIFC and ADGM requirements modelled as frameworks and mapped to controls you share with GDPR, SOC 2 and ISO 27001, with evidence in one ledger and risks in the risk register |
| Processors and transfers | A processor register with contract validity and each processor's country checked against the destinations you restrict |
| Regulation 10 and automated decisions | An AI vendor register with an explainable supply-chain risk score, alongside AI governance controls |
| Breach notification | Incident tracking from detection to post-mortem with real timestamps |
You still file your notification with the Commissioner yourself. TryTrustable hosts in Google Cloud Mumbai today, which is a transfer out of the DIFC or ADGM to cover under the transfer rules.
The things people ask us
Does the UAE PDPL apply in the DIFC?
No. The federal PDPL excludes free zones that have their own data protection legislation. Companies incorporated in the DIFC follow the DIFC Data Protection Law No. 5 of 2020 instead.
Do DIFC companies need to register with the Commissioner of Data Protection?
Yes. Every controller and processor must file a notification of its processing operations, within 30 days of starting processing, renew it each year and pay the fee for its category.
What are the fines under the DIFC Data Protection Law?
Schedule 2 sets maximum administrative fines of USD 25,000 to USD 100,000 per contravention, and the Commissioner can also impose a general fine not limited to those amounts. Data subjects can claim compensation in the DIFC Courts.
What is DIFC Regulation 10?
The part of the DIFC Data Protection Regulations that governs personal data processed through autonomous and semi-autonomous systems, such as AI. It sets notice, transparency and evidence duties for deployers and operators.
How quickly must a breach be reported in ADGM?
Without undue delay and, where feasible, within 72 hours of discovering it. Data subjects must be told without undue delay when the breach is likely to result in a high risk to them.
Is a DPO mandatory in the DIFC?
For DIFC Bodies and for controllers or processors carrying out High Risk Processing Activities on a systematic or regular basis. The DPO must live in the UAE unless they perform a similar role for the wider group.
My company is in a Dubai free zone other than the DIFC. Which law applies?
The federal UAE PDPL, unless that free zone has its own data protection legislation. Check the zone's regulations with counsel.
One control library for DIFC, ADGM and the PDPL.
Thirty minutes on the UAE regimes you answer to, alongside GDPR, SOC 2 or ISO 27001.