xmodoxmodo

Frameworks · Middle East

ADGM DPR 2021

The ADGM Data Protection Regulations 2021, as amended, govern how establishments in Abu Dhabi Global Market process personal data. The ADGM Office of Data Protection administers them under a Commissioner of Data Protection.

Who it applies to

They apply to controllers and processors established in ADGM, and to entities that process personal data in the context of an ADGM establishment. As with the DIFC, the federal UAE PDPL does not apply inside ADGM because the free zone has its own data protection law.

Main requirements

Principles & accountability

Processing must be lawful, limited to its purpose, minimised and accurate. Organisations keep records of processing and assess the impact of high-risk processing.

Data subject rights

Individuals have rights of access, rectification, erasure, restriction, portability and objection.

Transfers

Personal data may be transferred outside ADGM on the basis of an adequacy decision or appropriate safeguards.

Breach notification

Under Article 32, the Commissioner must be notified without undue delay and, where feasible, within 72 hours of becoming aware. A later notification must give the reasons for the delay.

How xmodo supports it

  • 1

    Each article is set up as a control with an owner, evidence and a calculated readiness score.

  • 2

    When a breach is classified, the 72-hour reporting deadline starts on the incident record. The notification and its timestamps are filed as evidence.

  • 3

    Processors and transfers are kept in registers that use the same data as your vendor assessments.

  • 4

    Mapping between frameworks links it to GDPR, UK GDPR, the DIFC law and the UAE PDPL, so a group can run one privacy programme across its entities.

Related frameworks

ADGM DPR 2021 shares requirements with the frameworks below. Controls you already run for any of them count towards ADGM DPR 2021 as well.

Frequently asked questions

How is ADGM DPR different from the DIFC law?

They are separate laws from separate free zones, with separate Commissioners. The breach deadline differs: ADGM sets 72 hours where feasible, and the DIFC requires notification as soon as practicable. xmodo sets up each law on its own terms and maps the requirements they share.

We already comply with GDPR. How much work is left?

The mapping gives credit for the principles and rights the two laws share. The remaining work is specific to ADGM: registration and notification with the Office of Data Protection, ADGM transfer rules and the local records the Commissioner expects.

See how xmodo works for your organisation

Get a demo on the frameworks that apply to you.

Get a demo