Data and digital law · ADGM

ADGM Data Protection Regulations 2021

A current section-level corpus of all 64 provisions covering processing principles and lawful bases, individual rights, controller and processor duties, DPOs, DPIAs, breaches, international transfers, supervision, fines and remedies.

Material typeADGM legislation
Legal branchData and digital law
Legal systemADGM
Source languageOfficial English source · on-site text may be an editorial rendering
Review dateAugust 24, 2026
IssuedFebruary 11, 2021
EffectiveAugust 14, 2021
Official Gazette
Version checkedAugust 17, 2026
Consolidated throughAugust 31, 2025

01

Document overview

A current section-level corpus of all 64 provisions covering processing principles and lawful bases, individual rights, controller and processor duties, DPOs, DPIAs, breaches, international transfers, supervision, fines and remedies.

  • All 64 sections are available on-site in four languages.
  • The official August 2025 consolidated version is reflected.
  • The 72-hour breach notice, DPIAs, DPOs and international transfers are separately searchable.

02

Scope and exclusions

03

Document text

The official Arabic text and government-published English version are available; Russian and Chinese follow the actual coverage shown on the page.

The on-site text is a structured editorial rendering, not the full official text. Open the official source for citation and application.

Published articles64 / 64
Structured editorial rendering64 / 64

Subject-matter and objectives

Editorial rendering — not the official textPermanent link

Part I · General provisions

The Regulations protect natural persons in relation to the processing of personal data and safeguard the free movement of personal data within ADGM, while requiring a high and consistent level of protection.

Material scope

Editorial rendering — not the official textPermanent link

Part I · General provisions

The Regulations apply to automated processing and to non-automated processing forming part of a filing system, subject to stated exclusions such as purely personal or household activity.

Territorial scope

Editorial rendering — not the official textPermanent link

Part I · General provisions

The territorial rules cover processing in the context of an ADGM establishment and specified processing connected with offering goods or services to, or monitoring, individuals in ADGM.

Principles relating to processing

Editorial rendering — not the official textPermanent link

Part II · Principles

Personal data must be processed lawfully, fairly and transparently; collected for specified purposes; limited, accurate, retained no longer than necessary and secured. The Controller must demonstrate compliance.

Lawfulness of processing

Editorial rendering — not the official textPermanent link

Part II · Principles

Processing requires a lawful basis, including consent, contract, legal obligation, vital interests, public tasks or legitimate interests, subject to the conditions and balancing required by the Regulations.

Conditions for consent

Editorial rendering — not the official textPermanent link

Part II · Principles

The Controller must be able to prove consent. A consent request must be distinguishable, clear and accessible; consent must be freely given and may be withdrawn as easily as it was given.

Special categories of personal data

Editorial rendering — not the official textPermanent link

Part II · Principles

Processing sensitive categories is prohibited unless an express condition applies, such as explicit consent, employment or social-protection law, vital interests, legal claims, substantial public interest, health or approved research safeguards.

Processing not requiring identification

Editorial rendering — not the official textPermanent link

Part II · Principles

A Controller need not retain or obtain extra identifying information solely to comply where the processing purpose does not require identification, but must inform a Data Subject if it cannot identify them.

Archiving and research purposes

Editorial rendering — not the official textPermanent link

Part II · Principles

Archiving, scientific or historical research and statistical processing must use appropriate safeguards, including data minimisation and, where feasible, measures such as pseudonymisation.

Transparency and exercise of rights

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

Information and communications must be concise, transparent, intelligible and easily accessible. Controllers must facilitate rights requests and respond within the prescribed periods, generally without charge.

Information collected from the Data Subject

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

At collection, the Controller must provide prescribed information including identity, purposes, lawful bases, recipients, transfers, retention, rights, complaints and any automated decision-making.

Information not obtained from the Data Subject

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

Where data comes from another source, the Controller must give similar notice plus the categories and source of the data within the applicable period, unless a stated exemption applies.

Right of access

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

A Data Subject may obtain confirmation of processing, access to personal data and prescribed contextual information, together with a copy subject to safeguards for the rights of others.

Right to rectification

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

A Data Subject may require inaccurate personal data to be corrected without undue delay and incomplete data to be completed, including by supplementary statement.

Right to erasure

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

Personal data must be erased where a listed ground applies, subject to exceptions for expression, law, public interest, health, archiving, research or legal claims.

Right to restriction of processing

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

A Data Subject may require processing to be restricted in specified cases concerning disputed accuracy, unlawful processing, legal claims or a pending objection. Restricted data may be used only on limited grounds.

Notification after rectification, erasure or restriction

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

The Controller must notify recipients of rectification, erasure or restriction unless impossible or disproportionate, and identify recipients to the Data Subject on request.

Right to data portability

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

For qualifying consent- or contract-based automated processing, the Data Subject may receive supplied data in a structured, commonly used, machine-readable format and transmit it to another Controller.

Right to object

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

A Data Subject may object to public-task or legitimate-interest processing, including profiling. Direct-marketing processing must stop on objection; research objections are subject to the public-interest exception.

Automated decision-making and profiling

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

Individuals are protected against solely automated decisions producing legal or similarly significant effects, subject to limited exceptions and safeguards including human intervention and the ability to contest the decision.

Restrictions

Editorial rendering — not the official textPermanent link

Part III · Rights of the Data Subject

Certain obligations and rights may be restricted by proportionate legislative measures protecting specified public interests, investigations, courts, professional duties or the rights of others, with required safeguards.

Responsibility of the Controller

Editorial rendering — not the official textPermanent link

Part IV · Controller and Processor

Controllers must implement and review proportionate technical and organisational measures and policies that ensure and demonstrate compliance, taking account of risk, context, scope and purpose.

Data protection by design and by default

Editorial rendering — not the official textPermanent link

Part IV · Controller and Processor

Controllers must embed data-protection principles and safeguards into systems and processing and ensure default settings limit data, extent, retention and accessibility to what each purpose requires.

Data Protection Fee

Editorial rendering — not the official textPermanent link

Part IV · Controller and Processor

Controllers must register, pay the prescribed Data Protection Fee and renewal fee, and maintain the required particulars with the Commissioner, subject to applicable rules and exemptions.

04

Publication status

Coverage by language

RU
64 / 64 · 100%
EN
64 / 64 · 100%
AR
64 / 64 · 100%
中文
64 / 64 · 100%

Source and translation status

The official source is English; all 64 sections are covered through a structured editorial rendering, not a certified verbatim copy.

Legal review

All 64 sections have completed four-language alignment and data-protection terminology review; editorial versions are not official. · August 24, 2026

Republication status

ADGM terms checked on 20 August 2026 permit personal use, while commercial use requires a licence from ADGM or the relevant licensor. Pending a licence, the site provides its own attributed structured editorial rendering and does not reproduce the Rulebook/PDF verbatim in full.

Change history

  • 16 August 2026 — official-source version imported.
  • 17 August 2026 — classification, scope, translation status and publication coverage reviewed.
  • 24 August 2026 — four-language alignment of 64 sections and ADGM data-protection terminology completed.

06

Official primary source

ADGM Data Protection Regulations 2021 · consolidated August 2025

ADGM terms checked on 20 August 2026 permit personal use, while commercial use requires a licence from ADGM or the relevant licensor. Pending a licence, the site provides its own attributed structured editorial rendering and does not reproduce the Rulebook/PDF verbatim in full.

Verify official text ↗
WAWhatsAppTGTelegram