Tax& Law+7 (495) 221 31 46Discuss a matter
Article-by-article contents · Page 1 / 1
ADGM Data Protection Regulations 2021 — articles 1–64
- Article 1 — Subject-matter and objectives
The Regulations protect natural persons in relation to the processing of personal data and safeguard the free movement of personal data within ADGM, while requiring a high and consistent level of protection.
- Article 2 — Material scope
The Regulations apply to automated processing and to non-automated processing forming part of a filing system, subject to stated exclusions such as purely personal or household activity.
- Article 3 — Territorial scope
The territorial rules cover processing in the context of an ADGM establishment and specified processing connected with offering goods or services to, or monitoring, individuals in ADGM.
- Article 4 — Principles relating to processing
Personal data must be processed lawfully, fairly and transparently; collected for specified purposes; limited, accurate, retained no longer than necessary and secured. The Controller must demonstrate compliance.
- Article 5 — Lawfulness of processing
Processing requires a lawful basis, including consent, contract, legal obligation, vital interests, public tasks or legitimate interests, subject to the conditions and balancing required by the Regulations.
- Article 6 — Conditions for consent
The Controller must be able to prove consent. A consent request must be distinguishable, clear and accessible; consent must be freely given and may be withdrawn as easily as it was given.
- Article 7 — Special categories of personal data
Processing sensitive categories is prohibited unless an express condition applies, such as explicit consent, employment or social-protection law, vital interests, legal claims, substantial public interest, health or appr…
- Article 8 — Processing not requiring identification
A Controller need not retain or obtain extra identifying information solely to comply where the processing purpose does not require identification, but must inform a Data Subject if it cannot identify them.
- Article 9 — Archiving and research purposes
Archiving, scientific or historical research and statistical processing must use appropriate safeguards, including data minimisation and, where feasible, measures such as pseudonymisation.
- Article 10 — Transparency and exercise of rights
Information and communications must be concise, transparent, intelligible and easily accessible. Controllers must facilitate rights requests and respond within the prescribed periods, generally without charge.
- Article 11 — Information collected from the Data Subject
At collection, the Controller must provide prescribed information including identity, purposes, lawful bases, recipients, transfers, retention, rights, complaints and any automated decision-making.
- Article 12 — Information not obtained from the Data Subject
Where data comes from another source, the Controller must give similar notice plus the categories and source of the data within the applicable period, unless a stated exemption applies.
- Article 13 — Right of access
A Data Subject may obtain confirmation of processing, access to personal data and prescribed contextual information, together with a copy subject to safeguards for the rights of others.
- Article 14 — Right to rectification
A Data Subject may require inaccurate personal data to be corrected without undue delay and incomplete data to be completed, including by supplementary statement.
- Article 15 — Right to erasure
Personal data must be erased where a listed ground applies, subject to exceptions for expression, law, public interest, health, archiving, research or legal claims.
- Article 16 — Right to restriction of processing
A Data Subject may require processing to be restricted in specified cases concerning disputed accuracy, unlawful processing, legal claims or a pending objection. Restricted data may be used only on limited grounds.
- Article 17 — Notification after rectification, erasure or restriction
The Controller must notify recipients of rectification, erasure or restriction unless impossible or disproportionate, and identify recipients to the Data Subject on request.
- Article 18 — Right to data portability
For qualifying consent- or contract-based automated processing, the Data Subject may receive supplied data in a structured, commonly used, machine-readable format and transmit it to another Controller.
- Article 19 — Right to object
A Data Subject may object to public-task or legitimate-interest processing, including profiling. Direct-marketing processing must stop on objection; research objections are subject to the public-interest exception.
- Article 20 — Automated decision-making and profiling
Individuals are protected against solely automated decisions producing legal or similarly significant effects, subject to limited exceptions and safeguards including human intervention and the ability to contest the deci…
- Article 21 — Restrictions
Certain obligations and rights may be restricted by proportionate legislative measures protecting specified public interests, investigations, courts, professional duties or the rights of others, with required safeguards.
- Article 22 — Responsibility of the Controller
Controllers must implement and review proportionate technical and organisational measures and policies that ensure and demonstrate compliance, taking account of risk, context, scope and purpose.
- Article 23 — Data protection by design and by default
Controllers must embed data-protection principles and safeguards into systems and processing and ensure default settings limit data, extent, retention and accessibility to what each purpose requires.
- Article 24 — Data Protection Fee
Controllers must register, pay the prescribed Data Protection Fee and renewal fee, and maintain the required particulars with the Commissioner, subject to applicable rules and exemptions.
- Article 25 — Joint Controllers
Joint Controllers must transparently allocate their responsibilities by arrangement, make its essence available to Data Subjects and designate a contact point without limiting individual rights against each Controller.
- Article 26 — Processor
Controllers may use only Processors providing sufficient guarantees. Processing must be governed by a prescribed contract; sub-processing requires authorisation and equivalent obligations.
- Article 27 — Processing under Controller or Processor authority
A Processor or person acting under authority may process personal data only on instructions from the Controller unless required by applicable law.
- Article 28 — Records of processing activities
Controllers, Processors and representatives must maintain prescribed written records of processing and make them available to the Commissioner on request.
- Article 29 — Cooperation with the Commissioner
Controllers, Processors and their representatives must cooperate with the Commissioner in the performance of official tasks.
- Article 30 — Security of processing
Appropriate risk-based security measures may include pseudonymisation, encryption, resilience, recovery and regular testing. Risk assessment must address accidental or unlawful loss, alteration, disclosure or access.
- Article 31 — Cessation of processing
When an establishment ceases or relevant processing ends, the Controller must securely delete, anonymise or transfer personal data as required, while preserving evidence of compliance and lawful retention.
- Article 32 — Breach notification to the Commissioner
A Controller must notify a qualifying personal-data breach to the Commissioner without undue delay and, where feasible, within 72 hours. Processors must notify Controllers without undue delay and breaches must be documen…
- Article 33 — Breach communication to the Data Subject
Where a breach is likely to create high risk, affected Data Subjects must be informed without undue delay in clear language, unless effective protection, later risk removal or disproportionate effort justifies an alterna…
- Article 34 — Data Protection Impact Assessment
Before likely high-risk processing, the Controller must conduct a DPIA covering the proposed operations, necessity, proportionality, risks and safeguards, and consult the Commissioner where residual high risk remains.
- Article 35 — Designation of the Data Protection Officer
A DPO is required for public-authority processing and specified large-scale regular monitoring or sensitive-data processing. Groups may share an accessible DPO and contact details must be published and notified.
- Article 36 — Position of the Data Protection Officer
The DPO must be involved promptly, supported with resources, act independently without conflicting tasks, report to the highest management level and remain bound by confidentiality.
- Article 37 — Tasks of the Data Protection Officer
The DPO advises on obligations, monitors compliance and training, advises on DPIAs, cooperates with the Commissioner and acts as the supervisory contact while taking a risk-based approach.
- Article 38 — Codes of conduct
Associations and representative bodies may prepare or amend codes that specify practical application of the Regulations. Codes require approval and may use accredited monitoring bodies.
- Article 39 — Certification
Voluntary certification mechanisms, seals and marks may demonstrate compliance under approved criteria, but certification does not reduce Controller or Processor responsibility or the Commissioner's powers.
- Article 40 — General principle for transfers
A transfer outside ADGM or to an international organisation is permitted only under Part V and must not undermine the level of protection guaranteed by the Regulations, including for onward transfers.
- Article 41 — Transfers based on adequacy
Transfers may occur without specific authorisation where the Commissioner has recognised an adequate level of protection, following assessment and periodic review of the relevant jurisdiction, sector or organisation.
- Article 42 — Transfers subject to safeguards
Absent adequacy, a transfer requires appropriate safeguards and enforceable rights, such as approved contractual clauses, binding instruments, codes or certification, with authorisation where prescribed.
- Article 43 — Binding Corporate Rules
The Commissioner may approve legally binding and enforceable group rules that confer rights on Data Subjects and contain the prescribed structure, safeguards, complaint, audit and cooperation provisions.
- Article 44 — Derogations for specific situations
Where neither adequacy nor safeguards apply, limited transfers may rely on explicit informed consent, contract, important public interest, legal claims, vital interests, public registers or a narrowly controlled compelli…
- Article 45 — Data sharing with public authorities
Disclosure to a public authority outside ADGM must rest on applicable legal authority or recognised international cooperation and remain necessary, proportionate and subject to data-protection safeguards.
- Article 46 — International cooperation
The Commissioner may develop international cooperation, mutual assistance, information exchange and common enforcement arrangements to protect personal data, subject to appropriate safeguards.
- Article 47 — Commissioner of Data Protection
The Regulations establish the Commissioner and Office of Data Protection as the independent supervisory authority responsible for monitoring and enforcing the framework.
- Article 48 — Independence
The Commissioner must act with complete independence, remain free from external influence and instructions, avoid incompatible activity and receive the resources necessary for effective performance.
- Article 49 — Functions and obligations of Office staff
Office staff support the Commissioner's functions and remain subject to professional secrecy, integrity, conflict and other statutory obligations during and after service.
- Article 50 — General powers
The Commissioner has monitoring, investigative, corrective, authorisation and advisory powers, including requiring information, conducting audits, issuing warnings and directions and imposing administrative fines.
- Article 51 — Budget
The Office must have a separate and adequate budget prepared, approved and administered under the statutory arrangements that preserve supervisory independence and accountability.
- Article 52 — Accounts and audit
The Office must maintain proper accounts and records, prepare financial statements and arrange independent audit in accordance with prescribed requirements.
- Article 53 — Annual report
The Commissioner must publish an annual report on supervisory activities, which may include notified infringements, measures taken and other information required for transparency and accountability.
- Article 54 — Directions
The Commissioner may issue enforceable directions requiring specified action, restriction, suspension or cessation to secure compliance, subject to notice, reasons and applicable review rights.
- Article 55 — Administrative fines
Administrative fines must be effective, proportionate and dissuasive. The Commissioner considers the nature, duration, gravity, intent, mitigation, cooperation, data categories, history and other prescribed factors, subj…
- Article 56 — Fixed penalty for unpaid fee
Failure to pay the Data Protection Fee or renewal fee may attract a fixed penalty under the prescribed procedure, without limiting recovery of the underlying fee or other enforcement.
- Article 57 — Complaint to the Commissioner
A Data Subject may complain to the Commissioner about processing that allegedly infringes the Regulations. The Commissioner must handle and inform the complainant of progress and outcome, subject to review rights.
- Article 58 — Application to the Court
Persons affected by specified Commissioner decisions or inaction may apply to the ADGM Court for the remedies and review available under the Regulations and Court procedure.
- Article 59 — Rights against a Controller or Processor
A person suffering material or non-material damage from an infringement may seek compensation from the responsible Controller or Processor, subject to allocation of liability and rights of contribution.
- Article 60 — Power of the Board to make rules
The Board may make rules necessary or expedient for carrying out the Regulations, including detailed procedures, safeguards, fees, exemptions and related matters within the enabling power.
- Article 61 — Previously concluded agreements
Existing agreements and arrangements involving personal data must be brought into and maintained in compliance with the Regulations under the applicable transitional treatment.
- Article 62 — Definitions
This section defines the framework's principal terms, including Controller, Processor, Data Subject, Personal Data, Processing, Profiling, consent, breach, special categories and international organisation.
- Article 63 — Repeal of the 2015 Regulations
The Data Protection Regulations 2015 are repealed subject to the commencement and transitional provisions preserving necessary legal effects and orderly migration to the 2021 framework.
- Article 64 — Short title, scope and commencement
The instrument is cited as the Data Protection Regulations 2021 and applies in ADGM. It used transition periods from publication, including six months for new establishments and twelve months for existing establishments.