DIFC and ADGM

ADGM Data Protection Policy

ADGM operates its own data protection regime under the **Data Protection Regulations 2021**, administered by its own Office of Data Protection, with **direct application of English common law** in the background. It is not the federal PDPL and it is not identical to DIFC — the two financial free zones maintain separate rules and separate adequacy lists.

Download as Word7 pages20 KBFree
[HEADER — replace with your organisation’s letterhead, if used]

ADGM Data Protection Policy

Abu Dhabi Global Market — [COMPANY NAME]

ADGM operates its own data protection regime under the Data Protection Regulations 2021, administered by its own Office of Data Protection, with direct application of English common law in the background. It is not the federal PDPL and it is not identical to DIFC — the two financial free zones maintain separate rules and separate adequacy lists.

ItemDetail
Entity[COMPANY NAME], ADGM registration [NUMBER]
Role[Controller / Processor / Both]
Governing lawADGM Data Protection Regulations 2021
RegulatorADGM Office of Data Protection
Data Protection Officer[NAME — or "not appointed"; see Section 5]
Registration or notification with the Office[DATE]confirm the current requirement
High risk processing?[Y/N]
Approved by[NAME], [DESIGNATION], on [DATE]
ReviewAnnually

1. Scope

1.1This policy applies to processing of personal data by [COMPANY NAME] as an entity established in the Abu Dhabi Global Market.

1.2The federal UAE Personal Data Protection Law does not apply to processing by an ADGM entity within ADGM. The DIFC Data Protection Law does not apply either — these are separate regimes.

1.3Where the group also operates a mainland, free zone or DIFC entity, that entity is separately subject to its own regime. Mapping is per entity and per dataset.

2. Principles

PrincipleRequirement
Lawfulness, fairness and transparencyProcess lawfully and tell people what you do
Purpose limitationSpecified, explicit, legitimate purposes
Data minimisationAdequate, relevant, limited to what is necessary
AccuracyAccurate and kept up to date
Storage limitationKept no longer than necessary
Integrity and confidentialityAppropriate security
AccountabilityDemonstrate compliance — records, assessments, governance

3. Lawful Basis

3.1Processing requires one of: consent; performance of a contract; compliance with a legal obligation; protection of vital interests; a task in the public interest; or legitimate interests pursued by the Company or a third party, except where overridden by the data subject’s interests or rights.

Generated from www.helionerp.com1

6 more pages in the Word file

This is page 1 of the Word document, exactly as it appears when you open it. Fields shown like THIS are placeholders for you to complete.

Notes for use

These notes accompany the template and explain the drafting choices, the compliance points and the mistakes most often made with this document. They appear as a final page in the Word file, intended to be deleted before the document is executed.

ADGM is its own regime — not federal, not DIFC

The Data Protection Regulations 2021 apply to ADGM entities, administered by the ADGM Office of Data Protection. Applying a federal PDPL policy or a DIFC policy produces a document citing the wrong law, the wrong regulator and the wrong complaint route. The two financial free zones are not interchangeable.

ADGM maintains its own adequacy list

It is not the DIFC list and not a federal position. A destination acceptable for a DIFC transfer is not automatically acceptable for an ADGM one. Check the ADGM list specifically and record the date checked, because lists change.

Assess mainland transfers explicitly

Sending personal data from an ADGM entity to a mainland affiliate, service provider or bank is a transfer out of ADGM and needs assessing. Being within the UAE does not make it domestic for these purposes — the same trap that catches DIFC entities.

A three-regime group is running three analyses

Where a group has mainland, DIFC and ADGM entities, each flow is assessed under the rules of the exporting jurisdiction, and the answers differ. Shared HR and finance systems across such a group need this mapped rather than assumed.

Legitimate interests is available here

Like DIFC and unlike the federal regime, ADGM recognises legitimate interests as a lawful basis — with a documented balancing assessment. That assessment supports the ADGM entity only; a mainland affiliate needs its own analysis under the federal law.

Confirm the registration or notification requirement

ADGM has operated notification and registration requirements for entities processing personal data, and the detail including any fee has been subject to change. Confirm the current position with the Office rather than relying on an earlier understanding.

DPO appointment turns on high risk processing

The trigger is the nature of the processing, not headcount — large-scale special category processing, systematic monitoring, automated evaluation with significant effects. Where in doubt, appoint and notify.

Direct application of English law sits behind the regime

ADGM applies English common law directly, which shapes how the Regulations are interpreted and how disputes are handled in the ADGM Courts. That is an advantage for organisations familiar with English-law data protection concepts.

Report breaches first, assess second

Staff must report immediately without attempting to assess or resolve. The most damaging delays come from a well-intentioned attempt to fix something quietly, which loses containment time and destroys the logs needed to establish scope.

Record why a breach was not notified

Entities log notified breaches and record nothing about those assessed and dismissed. If challenged, an absent record is indistinguishable from no assessment. Log the reasoning either way.

Direct marketing objections are absolute

An objection to direct marketing must be honoured without a balancing exercise. Suppression lists need to be central and applied across every channel and campaign.

Portability needs a technical answer

Providing data in a structured, machine-readable format on request is a real right. Whether the systems can actually export it is usually discovered at the first request rather than in advance.

Employee data is in scope and includes special categories

Passport and visa records, medical test results and health insurance data all pass through a UAE employer, and much of it is special category data. Issue an employee privacy notice at onboarding.

Review annually and on change

A new vendor, a new system, a new group entity or a change to the adequacy list all affect the analysis. Tie the review to those events as well as to the annual cycle.

Current as of

Reflects ADGM requirements current as of {{DATE OF USE}}. The Data Protection Regulations 2021, notification and registration requirements, the adequacy list, response periods and breach notification thresholds all change — confirm the current position with the ADGM Office of Data Protection or an ADGM data protection adviser before relying on this policy.

This is a ready-to-use template provided for convenience. Laws and requirements change, and every situation is different — please have it reviewed by a qualified professional (a lawyer, corporate secretary, or accountant as relevant) before you rely on it.