01
Document overview
A current section-level corpus of all 64 provisions covering processing principles and lawful bases, individual rights, controller and processor duties, DPOs, DPIAs, breaches, international transfers, supervision, fines and remedies.
- All 64 sections are available on-site in four languages.
- The official August 2025 consolidated version is reflected.
- The 72-hour breach notice, DPIAs, DPOs and international transfers are separately searchable.
02
Scope and exclusions
Applies to
Processing within ADGM's special data-protection regime, including controllers, processors and its stated extraterritorial reach.
Limitations and exclusions
The federal PDPL and DIFC regime apply separately; sector rules may operate in parallel.
03
Document text
The on-site text is a structured editorial rendering, not the full official text. Open the official source for citation and application.
Subject-matter and objectives
Editorial rendering — not the official textPermanent link →Part I · General provisions
The Regulations protect natural persons in relation to the processing of personal data and safeguard the free movement of personal data within ADGM, while requiring a high and consistent level of protection.
Material scope
Editorial rendering — not the official textPermanent link →Part I · General provisions
The Regulations apply to automated processing and to non-automated processing forming part of a filing system, subject to stated exclusions such as purely personal or household activity.
Territorial scope
Editorial rendering — not the official textPermanent link →Part I · General provisions
The territorial rules cover processing in the context of an ADGM establishment and specified processing connected with offering goods or services to, or monitoring, individuals in ADGM.
Principles relating to processing
Editorial rendering — not the official textPermanent link →Part II · Principles
Personal data must be processed lawfully, fairly and transparently; collected for specified purposes; limited, accurate, retained no longer than necessary and secured. The Controller must demonstrate compliance.
Lawfulness of processing
Editorial rendering — not the official textPermanent link →Part II · Principles
Processing requires a lawful basis, including consent, contract, legal obligation, vital interests, public tasks or legitimate interests, subject to the conditions and balancing required by the Regulations.
Conditions for consent
Editorial rendering — not the official textPermanent link →Part II · Principles
The Controller must be able to prove consent. A consent request must be distinguishable, clear and accessible; consent must be freely given and may be withdrawn as easily as it was given.
Special categories of personal data
Editorial rendering — not the official textPermanent link →Part II · Principles
Processing sensitive categories is prohibited unless an express condition applies, such as explicit consent, employment or social-protection law, vital interests, legal claims, substantial public interest, health or approved research safeguards.
Processing not requiring identification
Editorial rendering — not the official textPermanent link →Part II · Principles
A Controller need not retain or obtain extra identifying information solely to comply where the processing purpose does not require identification, but must inform a Data Subject if it cannot identify them.
Archiving and research purposes
Editorial rendering — not the official textPermanent link →Part II · Principles
Archiving, scientific or historical research and statistical processing must use appropriate safeguards, including data minimisation and, where feasible, measures such as pseudonymisation.
Transparency and exercise of rights
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
Information and communications must be concise, transparent, intelligible and easily accessible. Controllers must facilitate rights requests and respond within the prescribed periods, generally without charge.
Information collected from the Data Subject
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
At collection, the Controller must provide prescribed information including identity, purposes, lawful bases, recipients, transfers, retention, rights, complaints and any automated decision-making.
Information not obtained from the Data Subject
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
Where data comes from another source, the Controller must give similar notice plus the categories and source of the data within the applicable period, unless a stated exemption applies.
Right of access
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
A Data Subject may obtain confirmation of processing, access to personal data and prescribed contextual information, together with a copy subject to safeguards for the rights of others.
Right to rectification
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
A Data Subject may require inaccurate personal data to be corrected without undue delay and incomplete data to be completed, including by supplementary statement.
Right to erasure
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
Personal data must be erased where a listed ground applies, subject to exceptions for expression, law, public interest, health, archiving, research or legal claims.
Right to restriction of processing
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
A Data Subject may require processing to be restricted in specified cases concerning disputed accuracy, unlawful processing, legal claims or a pending objection. Restricted data may be used only on limited grounds.
Notification after rectification, erasure or restriction
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
The Controller must notify recipients of rectification, erasure or restriction unless impossible or disproportionate, and identify recipients to the Data Subject on request.
Right to data portability
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
For qualifying consent- or contract-based automated processing, the Data Subject may receive supplied data in a structured, commonly used, machine-readable format and transmit it to another Controller.
Right to object
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
A Data Subject may object to public-task or legitimate-interest processing, including profiling. Direct-marketing processing must stop on objection; research objections are subject to the public-interest exception.
Automated decision-making and profiling
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
Individuals are protected against solely automated decisions producing legal or similarly significant effects, subject to limited exceptions and safeguards including human intervention and the ability to contest the decision.
Restrictions
Editorial rendering — not the official textPermanent link →Part III · Rights of the Data Subject
Certain obligations and rights may be restricted by proportionate legislative measures protecting specified public interests, investigations, courts, professional duties or the rights of others, with required safeguards.
Responsibility of the Controller
Editorial rendering — not the official textPermanent link →Part IV · Controller and Processor
Controllers must implement and review proportionate technical and organisational measures and policies that ensure and demonstrate compliance, taking account of risk, context, scope and purpose.
Data protection by design and by default
Editorial rendering — not the official textPermanent link →Part IV · Controller and Processor
Controllers must embed data-protection principles and safeguards into systems and processing and ensure default settings limit data, extent, retention and accessibility to what each purpose requires.
Data Protection Fee
Editorial rendering — not the official textPermanent link →Part IV · Controller and Processor
Controllers must register, pay the prescribed Data Protection Fee and renewal fee, and maintain the required particulars with the Commissioner, subject to applicable rules and exemptions.
04
Publication status
Coverage by language
- RU
- 64 / 64 · 100%
- EN
- 64 / 64 · 100%
- AR
- 64 / 64 · 100%
- 中文
- 64 / 64 · 100%
Source and translation status
The official source is English; all 64 sections are covered through a structured editorial rendering, not a certified verbatim copy.
Legal review
All 64 sections have completed four-language alignment and data-protection terminology review; editorial versions are not official. · August 24, 2026
Republication status
ADGM terms checked on 20 August 2026 permit personal use, while commercial use requires a licence from ADGM or the relevant licensor. Pending a licence, the site provides its own attributed structured editorial rendering and does not reproduce the Rulebook/PDF verbatim in full.
Change history
- 16 August 2026 — official-source version imported.
- 17 August 2026 — classification, scope, translation status and publication coverage reviewed.
- 24 August 2026 — four-language alignment of 64 sections and ADGM data-protection terminology completed.
06
Official primary source
ADGM Data Protection Regulations 2021 · consolidated August 2025
ADGM terms checked on 20 August 2026 permit personal use, while commercial use requires a licence from ADGM or the relevant licensor. Pending a licence, the site provides its own attributed structured editorial rendering and does not reproduce the Rulebook/PDF verbatim in full.
Verify official text ↗
+7 (495) 221 31 46