Data protection in the UAE

Three data protection regimes run side by side in the UAE, and which one reaches you depends on where the company is registered. We will name it and build the file it asks for.

 

ADGM request reply

Ответ в ADGM

two months

два месяца

DIFC registration

Учёт в DIFC

USD 1,250 to 250

1 250 – 250 USD

Top ADGM fine

Потолок штрафа ADGM

USD 28 million

28 млн USD

Federal law in force

Федеральный закон с

2 January 2022

2 января 2022

When you need a data protection audit in the UAE

Your group sits in more than one zone

A mainland company, a DIFC entity and an ADGM affiliate answer to three different regulators. One group-wide policy cannot speak for all three at once.

A customer sent a data questionnaire

Buyers ask which regime governs you and which company is the controller. Signed, those answers bind you the way a contract term does.

Personal data leaked last night

The clock starts when somebody inside the company learns of it. How long that clock runs depends on where the entity is registered.

Your policy was written for Europe

European wording carries deadlines and penalty figures no Emirati regime uses. Copied across, it promises what you do not owe and misses what you do.

What you get

  • The regime that actually reaches each company
  • A register of processing, entity by entity
  • Registration and fees where the zone charges them
  • Notices and processor contracts that match the product
  • A breach plan with the right clock in it

What is required for data protection in the UAE

The first question is not where the servers stand. It is which company decides why the data is collected, and where that company is registered.

The federal law covers controllers and processors inside the country, and also those outside it whenever the people whose data is processed are here. Companies in free zones with personal-data legislation of their own are left out — and that exclusion is what sends DIFC and ADGM entities to their own rulebooks.

Three regimes, one group

Mainland — the federal law

Federal Decree-Law 45 of 2021 has applied since 2 January 2022, and the UAE Data Office supervises it. Processing without the person's agreement is prohibited except in the cases the law lists.

DIFC — its own law and its own commissioner

DIFC Law No. 5 of 2020 covers a controller or processor incorporated in the centre wherever the processing happens, and anyone processing inside the centre as part of stable arrangements.

ADGM — its own regulations

The Data Protection Regulations 2021 follow the establishment: processing in the context of an ADGM establishment is covered whether or not it takes place in ADGM. They were last amended in September 2025.

What each regulator asks you to file

ADGM is the strictest about the paperwork of the register. A controller pays a data protection fee when it starts processing, tells the commissioner its name and its start date, then pays a renewal fee each year within a month of that anniversary. Non-payment carries a penalty of up to 150 per cent of the fee.

DIFC works through a notification on its client portal, priced by category: 1,250, 750 or 250 dollars to register, 500, 250 or 100 to renew. The federal regime has no equivalent register for ordinary companies.

The clock after a breach is not one clock

In ADGM you have 72 hours from becoming aware, and a late notice has to carry its reasons. In DIFC the duty is to notify as soon as practicable — no fixed number of hours.

Federally, the duty starts the moment you become aware, while the length of the window and the form of the report are set by the implementing rules rather than by the law itself.

The price of getting it wrong

An ADGM fine is capped at 28 million dollars, and the cap holds even when one set of operations breaks several provisions. DIFC sets fixed amounts per contravention — 100,000 dollars for mishandling access, correction and erasure requests, 50,000 for failing to report a breach — and the commissioner may add a general fine the schedule does not limit.

Under the federal law the sanctions are set by a Cabinet decision rather than written into the decree-law, so the figure a European policy quotes is never the Emirati one. The rest of what we do in the country is listed on the UAE page.

Sources: scope, exclusions, the breach report and the sanctions — Federal Decree-Law 45 of 2021; the DIFC scope, request and breach rules and the fines — DIFC Law No. 5 of 2020 and its regulations; the ADGM fee, 72 hours and 28 million — the Data Protection Regulations 2021.

Stages of work

Naming the regime for each company — 3–5 working days

It starts with your licences and the place each entity is registered; against those we test the federal, DIFC and ADGM scope. Everything below depends on that answer.

Listing what is collected and by whom

Every field the product asks for, every system it lands in, every service it is passed to — each line with a purpose, a lawful ground and the company that owns it.

Registering where the zone requires it

In ADGM we will handle the notification and the fee, and diarise the renewal against the date processing began. In DIFC we will file the notification on the portal in the right category.

Writing the notices and the contracts

One notice per controller, written against what the product actually does, plus processor terms for the analytics, hosting and support tools you use.

Setting the route for data leaving the country

We will record where each recipient sits and put the transfer on the footing its regime requires, so the route is documented before anyone asks.

Writing the breach plan with the right clock

It records who takes the decision, what goes to which regulator and in what order: 72 hours in one zone, as soon as practicable in the other. Then we test it on a real incident.

Which regime reaches which entity is mapped in our article on the three UAE regimes. The wider practice behind this page is Licensing & Compliance.

Our case studies

No items found.

Leaders of the Area

Alexandra Kurdiumova

Alexandra

Kurdiumova

arrow_outward

FAQ

Does the federal law apply inside DIFC and ADGM?
add
remove
We have no office here. Does the law still reach us?
add
remove
Which breach deadline applies to our entity?
add
remove
Is there a fee for being on a data register?
add
remove
Will our European documents work here?
add
remove

Discuss
the Task

Speak to our team

Speak to our team. Tell us about your task –

we’ll help you with it in any jurisdiction.

Tell us about your task –
we’ll help you with it in any jurisdiction.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

We use cookies to improve your experience.