ADGM Data Protection Regulations: Do You Need a DPO? (2026)

ADGM Data Protection Regulations: Do You Need a DPO? (2026)

ADGM Data Protection Regulations: Do You Need a DPO? (2026)

ADGM Data Protection Officer Requirements: The DPR 2021 Guide for ADGM Companies (2026)

Last updated: October 2026.

The short answer first. Companies registered in the Abu Dhabi Global Market follow the ADGM Data Protection Regulations 2021 (DPR 2021), not the UAE PDPL. Section 35 makes a data protection officer (DPO) mandatory in three cases: the processing is carried out by a public authority, your core activities involve regular and systematic monitoring of individuals on a large scale, or your core activities involve large-scale processing of special categories of personal data. Company size does not change the answer, because ADGM repealed its small-company exemption in 2022.

Most ADGM fund managers, holding companies and B2B firms fall outside those triggers. They still have to keep a record of processing, pay the data protection fee every year, answer data subject requests within two months and report notifiable breaches to the Commissioner of Data Protection within 72 hours where feasible. Somebody has to own that work, and in many smaller firms nobody does until a bank's due diligence questionnaire or a complaint arrives.

Where a DPO is required, ADGM is flexible about who it is. The DPO can be an external provider, can sit outside ADGM and can cover a whole group. The Commissioner must be notified within one month of the appointment. This guide covers when the requirement applies, what the role involves, how ADGM differs from the DIFC and the PDPL, and what an outsourced DPO costs.

Your DPO of record in the UAE and Middle East
A named Data Protection Officer, backed by a delivery team that builds and runs your privacy programme. From $1,900 / mo

Your DPO of record in the UAE and Middle East
A named Data Protection Officer, backed by a delivery team that builds and runs your privacy programme. From $1,900 / mo

ADGM data protection at a glance

Topic

ADGM rule

Law

Data Protection Regulations 2021, as amended

Regulator

Commissioner of Data Protection, through the Office of Data Protection

Who it covers

Every entity established in ADGM, including on Al Reem Island, wherever the processing takes place

When a DPO is mandatory

Processing by a public authority; core activities involving large-scale regular and systematic monitoring; core activities involving large-scale special category data (section 35(1))

Who can be the DPO

An employee or an external provider under a written agreement, based anywhere if easily accessible (section 35(2))

DPO notification

To the Commissioner within one month of appointment or resignation (section 35(4))

Record of processing

Required for every controller and processor (section 28)

Data protection fee

Paid on registration and renewed every year (section 24)

Data subject requests

Within two months, extendable by one further month (section 10)

Breach notification

To the Commissioner within 72 hours where feasible; to affected individuals without undue delay if the risk to them is high

Maximum fine

USD 28 million (section 55)

Who the ADGM Data Protection Regulations apply to

The DPR 2021, ADGM's data privacy law, applies to personal data processed in the context of the activities of an establishment in ADGM, whether the processing itself happens in ADGM or elsewhere. An ADGM company whose customer database runs in a Frankfurt cloud region and whose support team works from Bangalore is fully in scope.

Two kinds of company are often surprised to find themselves here. The first is any business on Al Reem Island. UAE Cabinet Resolution No. 41 of 2023 extended ADGM's jurisdiction to the island from 24 April 2023, and businesses there had until 31 December 2024 to move to an ADGM licence. A company that swapped its Abu Dhabi mainland licence for an ADGM one changed data protection regimes at the same moment, from the PDPL to the DPR 2021.

The second is a group that spans regimes. The UAE PDPL (Federal Decree-Law No. 45 of 2021) does not apply in free zones with their own data protection law, so an ADGM holding company with an operating subsidiary in Dubai mainland runs two regimes, and a DIFC affiliate adds a third. Our UAE PDPL compliance guide covers the onshore side.

When an ADGM company must appoint a DPO

Section 35(1) sets three triggers. Any one of them makes the appointment mandatory, for processors as well as controllers.

  1. The processing is carried out by a public authority, other than courts acting in their judicial capacity. This covers ADGM's own bodies and almost never a private firm.

  2. Your core activities consist of processing operations that require regular and systematic monitoring of individuals on a large scale.

  3. Your core activities consist of large-scale processing of special categories of personal data.

The Office of Data Protection explains the key terms in its guidance on DPOs, and four of them decide most cases.

Core activities are the processing you need to achieve your main business objectives, as opposed to processing that supports the business. The Commissioner's example: a recruitment agency processing candidate data does so as a core activity, while a bank's internal recruitment team does not, because hiring is ancillary to banking. Payroll, HR records and the CRM of an ordinary company are not core activities.

Regular and systematic monitoring, in the Commissioner's view, includes all forms of tracking and profiling, online and offline. The guidance cites a retail bank whose website algorithms follow customers' searches and purchases to recommend financial products.

Large scale is not defined. You weigh the number of people involved, the volume of data, the range of data items, the geographic reach and how long the processing lasts.

Special categories are wider in ADGM than many teams assume. Section 7 covers racial or ethnic origin, political opinions, religious or philosophical beliefs, genetic data, biometric data used to identify a person, health data, data about sex life or sexual orientation, and personal data relating to criminal convictions and offences. The guidance's example of large-scale special category processing is a retail insurer collecting medical information to handle claims and set premiums. Two items on the list catch fintechs in particular: biometric data, when an onboarding flow matches a selfie to an identity document, and criminal offence data, which screening against enforcement and adverse-media records can produce. A consumer app that runs a biometric check on every new customer can meet the third trigger on that basis alone.

Applied to the companies we see in ADGM, our reading is this:


Company

Likely position

Reason

Digital bank or wealth app that profiles users to recommend products

DPO likely required

Large-scale profiling as part of the core service, close to the Commissioner's bank example

Health-tech or insurtech platform built on health data

DPO likely required

Large-scale special category data is the product

Identity verification or RegTech provider screening individuals for clients

DPO likely required

Biometric or criminal offence data processed at scale as the service itself

Asset manager or family office with a few hundred investors

Usually not required

KYC and investor records support the business and are limited in scale

Holding company or SPV

Not required

Little personal data beyond directors and shareholders

B2B software company

Depends on the product

Client contacts and staff data do not count; special category data processed for clients as the service can

Write the decision down either way, with the reasoning, so you can show the Commissioner how you reached it. The Office of Data Protection publishes a short DPO requirement assessment on its guidance page that walks through the same questions.

Ignore older articles that mention an exemption for companies with fewer than five employees. It existed in the original 2021 text, and ADGM repealed it in July 2022 together with the matching exemption from the data protection fee and notification. A five-person health-tech startup can need a DPO while a 200-person B2B firm does not.

If you do not need a DPO

Most of the Regulations apply anyway. Every controller and processor must keep a written record of processing activities (section 28), and the Office of Data Protection warns that updating it once a year is likely to be insufficient. Controllers pay the data protection fee on registration and renew it every year (section 24), and non-payment carries a fine of up to 150% of the fee. Contracts with processors must contain the terms in section 26, and the Commissioner publishes standard clauses that meet them. Transfers outside ADGM need an adequate destination, a safeguard such as standard contractual clauses, or a derogation. Processing likely to result in a high risk needs a data protection impact assessment (DPIA) before it starts, and breaches and data subject requests run on fixed clocks covered below.

You can still appoint a DPO voluntarily, and many regulated firms do, because banks, investors and enterprise customers ask for a named privacy contact. Treat a voluntary appointment as a full one. Section 35(4) refers to the appointment of any DPO, so the safer course is to notify the Commissioner and give the person the position and access that sections 36 and 37 describe. If you only want someone to coordinate privacy work, give the role a different title.

What the DPO must be and do

Section 35(2) allows the DPO to be an employee or an external provider under a written agreement, to be based outside ADGM, and to act for a single entity, a group, or several independent companies. Two conditions apply: the DPO must be easily accessible to every entity they act for, and no other role they hold may conflict with the DPO duties. The guidance accepts that regular use of video calls can be enough for accessibility, provided the DPO is genuinely reachable that way. Section 35(3) requires the appointment to rest on professional qualities, in particular expert knowledge of data protection law and practice, and the Commissioner recommends that the DPO's experience match the risk of your processing.

Section 36 sets the DPO's position. The company must involve the DPO properly and in good time in every data protection issue, give them the resources and access to data the role needs, and let them report directly to the highest level of management. It may not dismiss or penalise the DPO for doing the job. Data subjects can contact the DPO directly about anything concerning their data, so the DPO's contact details belong in every privacy notice and in the record of processing.

Section 37 sets the tasks: inform and advise the company and its staff, monitor compliance with the Regulations, any other applicable data protection law and the company's own policies, advise on DPIAs and review the processing they cover, and act as the contact point for the Commissioner. The DPO carries no personal liability. Responsibility for compliance stays with the company.

The appointment is filed on ADGM's Registry Platform within one month, with the DPO's contact details, and a resignation is notified the same way with the reasons for it. ADGM requires a DPO competency statement with the appointment, and the Office of Data Protection publishes a template for it. The statement should describe real data protection experience that fits your processing. A job title on its own will not show that.

Who should not be your DPO

The conflict test is about decisions. A DPO exists to question how the business uses personal data, so the role cannot sit with someone who decides what data the business collects and why. The Commissioner's example is a technology company's head of growth, whose job is to drive users to take actions in the company's app. That person cannot be the DPO. The same reasoning usually rules out the CEO and COO, and the heads of marketing, product, HR and technology.

Section 35(2)(b) lets the DPO hold other roles where they do not conflict. In smaller ADGM financial firms the compliance officer often takes on the DPO role too, which works if that person has the time and the data protection knowledge. In our view, an external virtual CISO for ADGM firms sits on the right side of the line as well: a security lead advises on and implements the controls that protect personal data, while decisions on what data to collect and why stay with management. That is why one named person holds both roles on our Builder plan.

ADGM vs DIFC vs UAE PDPL: DPO rules compared

Groups with entities in more than one regime need to know where the DPO rules differ. They differ mainly in the trigger and in where the DPO may be based.



ADGM

DIFC

UAE mainland

Law

Data Protection Regulations 2021

Data Protection Law No. 5 of 2020

Federal Decree-Law No. 45 of 2021 (PDPL)

Regulator

ADGM Commissioner of Data Protection

DIFC Commissioner of Data Protection

UAE Data Office

DPO mandatory

Public authorities; large-scale monitoring or large-scale special category data as a core activity

DIFC bodies; high risk processing activities carried out on a systematic or regular basis

High-risk processing through new technology or data volume; systematic evaluation of sensitive data, including profiling; large-scale sensitive data (Article 10)

Where the DPO can be based

Anywhere, if easily accessible

In the UAE, unless a group DPO performs the role internationally

Inside or outside the UAE

Breach notification to the regulator

Within 72 hours where feasible

As soon as practicable

Procedures deferred to the Executive Regulations, which are not yet issued

For a group, the efficient answer is one privacy programme with the filings each regime requires. ADGM allows a single DPO to cover several entities. A DIFC entity, though, needs a DPO who resides in the UAE, unless that person is employed within the group and performs a similar function for the group internationally.

Data moving between your own entities needs a transfer mechanism too. ADGM's list of adequate jurisdictions includes the DIFC, the UK, the EU and EEA, Switzerland and a short list of others, and the United States only for companies in the EU-US Data Privacy Framework. It does not include the UAE mainland, Saudi Arabia, India or Singapore. A transfer from an ADGM company to its own onshore subsidiary, or to a development team in India, needs a safeguard under section 42, usually the ADGM standard contractual clauses or the ADGM addendum to the EU clauses, or a derogation.

Breaches and data subject requests: the clocks that matter

A notifiable personal data breach goes to the Commissioner without undue delay and, where feasible, within 72 hours of discovery, through ADGM's online registry. You can file an initial notification inside the 72 hours and add detail as it emerges, and a late notification must explain the delay. A breach unlikely to create a risk to individuals does not need reporting, but every breach goes into an internal register with its facts, effects and remedial action. Where the risk to individuals is high, you also tell them directly without undue delay, unless encryption or later measures have removed that risk. If contacting everyone would take disproportionate effort, a public communication replaces the individual notices. Processors tell their controller without undue delay and leave the regulatory notification to the controller. The Office of Data Protection publishes a breach notification assessment on the same guidance page.

FSRA-regulated firms run a second clock. GEN 3.5.18 requires material cyber incidents to be reported to the FSRA within 24 hours, so a ransomware attack that exposes client data starts a 24-hour deadline and a 72-hour deadline at once. Our guide to the DFSA and FSRA cyber rules covers the FSRA side. The incident response plan should name both notifications, their owners and their deadlines before anything happens.

Data subject requests run on a longer clock. The controller must act without undue delay and within two months of receiving a request. That period can be extended by one further month for complex or numerous requests, as long as the requester hears about the extension, with reasons, inside the first two months. Where you have reasonable doubts about who is asking, the clock starts only once the requester's identity is confirmed. Two months sounds generous until an access request arrives for a customer whose data sits in a core platform, a CRM, a support desk and three years of email.

In-house vs outsourced DPO: four options for ADGM firms

ADGM firms usually choose between four options, and each fits a different firm.

Naming the compliance officer as DPO costs nothing extra and works for a firm with light processing and a compliance officer who has the time. It strains once the privacy work becomes real: a record of processing to maintain, DPIAs before launches, requests with deadlines and vendor contracts to review, all competing with compliance monitoring and AML.

A group DPO abroad is permitted in ADGM and suits subsidiaries of international groups, provided that person knows the ADGM rules and is reachable during the ADGM working week.

A law firm gives you legal opinions, which you will occasionally need. Few law firms will maintain your records or answer your requests week to week, and hourly billing makes routine privacy work expensive.

An outsourced DPO, also called DPO as a service or a virtual DPO, is a named person appointed under a written agreement, as section 35(2)(c) permits, who runs the programme for a fixed monthly fee. It suits firms that meet a section 35 trigger or face regular due diligence from banks and investors, but do not have enough privacy work for a full-time hire.

What an outsourced DPO does in the first 90 days

The sequence below is how we run a new ADGM engagement. Most of the build work lands in the first quarter.

  1. Weeks 1 to 2, scope and appointment. Confirm whether section 35 applies and record the decision. Appoint the DPO, file the notification and competency statement on the Registry Platform, and check that the data protection fee is current.

  2. Weeks 2 to 5, data mapping. Interview the teams that handle personal data, map systems and data flows, and build the record of processing. Set the lawful basis for each activity, and write an appropriate policy document where a special category condition requires one.

  3. Weeks 4 to 8, notices, vendors and transfers. Rewrite the privacy notices for customers, staff and investors with the DPO's contact details. List every processor, put section 26 terms in place, and record each transfer outside ADGM with its transfer mechanism.

  4. Weeks 6 to 10, DPIAs and retention. Run DPIAs on the high-risk processing that already exists, and set a retention period for each data category.

  5. Weeks 8 to 12, requests, incidents and training. Write the data subject request procedure around the two-month clock and identity checks. Build the breach runbook with the 72-hour notification and, for FSRA firms, the 24-hour one, then test it in a tabletop exercise. Train staff and close the quarter with the first report to senior management.

After that the role settles into a smaller recurring cycle: requests as they arrive, DPIAs when you launch a product or onboard a vendor, updates to the record of processing, the annual fee renewal and a quarterly report. If you want the programme certified, ISO/IEC 27701:2025 can now be certified on its own, and the records above make up most of its evidence.

What it costs

A full-time privacy hire in Abu Dhabi costs a senior package, for work that needs a few days a month once the programme is built. That arithmetic rarely works for a firm below a few hundred staff.

Dynova's prices are public. A named DPO of record costs USD 1,900 a month on a 12-month term. It covers the record of processing, DPIAs, processor agreements, data subject requests, privacy notices, breach notification, liaison with the Commissioner and a quarterly privacy report. The Builder plan, at USD 4,500 a month, adds eight hours a week of vCISO time for security strategy, hands-on control implementation and certification preparation, with one named person in both roles. The full breakdown is on our DPO service page. ADGM's data protection fee is separate and paid through the Registry.

One cost rarely appears in quotes: your own people's time. Even with the DPO carrying the work, the people who own customer data and IT will spend a few hours a week on interviews and decisions during the first quarter.

Frequently asked questions

Does the UAE PDPL apply to companies in ADGM?

No. Federal Decree-Law No. 45 of 2021 does not apply in free zones that have their own data protection law. ADGM companies follow the Data Protection Regulations 2021, and a group with an onshore subsidiary follows the PDPL for that subsidiary only.

Is a DPO mandatory in ADGM?

Only in the three cases in section 35(1): processing by a public authority, core activities involving large-scale regular and systematic monitoring, or core activities involving large-scale special category data. Company size no longer matters, because the exemption for establishments with fewer than five employees was repealed in 2022. Everything else in the Regulations applies whether you appoint a DPO or not.

Can the DPO be outsourced or based outside ADGM?

Yes. Section 35(2) allows an external DPO under a written agreement and does not require residence in ADGM, provided the DPO is easily accessible. The DIFC is stricter: a DIFC entity's DPO must reside in the UAE, unless they are a group DPO working for the group internationally.

How do we register a DPO with the ADGM Commissioner?

On the Registry Platform, within one month of the appointment, with the DPO's contact details and a competency statement. A resignation is notified the same way, within one month and with the reasons.

What is the deadline for reporting a data breach in ADGM?

Without undue delay and, where feasible, within 72 hours of discovering it. A breach unlikely to create a risk to individuals goes into your internal breach register instead. FSRA-regulated firms also report material cyber incidents to the FSRA within 24 hours under GEN 3.5.18.

How long do we have to answer a data subject access request in ADGM?

Two months from receipt, extendable by one further month for complex or numerous requests if you tell the requester within the first two months. If you have reasonable doubts about the requester's identity, the clock starts once identity is confirmed.

What are the fines under the ADGM Data Protection Regulations?

Up to USD 28 million under section 55, imposed in addition to or instead of the Commissioner's other corrective measures. Non-payment of the data protection fee carries a separate fine of up to 150% of the fee, and individuals can claim compensation for damage a contravention causes them. Some recent articles quote USD 54 million for ADGM. That figure comes from the Registration Authority's Administrative Regulations, enacted in late 2025 for licensing and registration breaches. The data protection cap is the one in section 55.

Can our compliance officer or vCISO also be our DPO?

Usually, yes. Section 35(2)(b) allows the DPO to hold other roles that do not conflict with the DPO duties. The conflict lies with people who decide what personal data the business processes and why, such as the CEO or a head of growth. A compliance officer or an external vCISO does not make those decisions.

What changed in ADGM data protection in 2025?

In September 2025 ADGM amended the Regulations and enacted the Data Protection Regulations (Substantial Public Interest Conditions) Rules 2025. They set out when special category data can be processed on substantial public interest grounds, including by insurers for insurance purposes and, without consent, to protect children and adults at risk of harm. Insurers and firms with safeguarding duties should review their lawful bases and policy documents.

Do companies on Al Reem Island follow ADGM data protection rules?

Yes. Cabinet Resolution No. 41 of 2023 brought Al Reem Island into ADGM's jurisdiction, and businesses there had to hold an ADGM licence by 31 December 2024. An ADGM-licensed company on Al Reem follows the Data Protection Regulations 2021, not the PDPL.

Working with Dynova in ADGM

If you are setting up in ADGM, or already licensed and unsure whether section 35 applies to you, get in touch. We will tell you whether you need a DPO, what your record of processing and breach plan are missing, and what the first 90 days should cover. Dynova is an official service provider to Hub71 in Abu Dhabi, and we act as named DPO for regulated companies in the UAE, including InsuranceMarket.ae alongside its in-house security team.

Related: UAE PDPL Compliance: A vCISO and DPO Guide · DFSA & FSRA Cybersecurity Requirements: A vCISO Guide · UAE PDPL Executive Regulations: Status in 2026 · Dynova Is Now a BSI Associate Consultant for ISO 27001 & 27701 · vCISO for Fintechs in the UAE

Written by

Founder of Dynova, vCISO and DPO (CISSP, CISM)

Founder of Dynova, vCISO and DPO for UAE companies. Formerly Head of Information Security and Privacy at Equiti. CISSP, CISM.

Guide

Experience

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01, Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ, License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant

Get started

Don’t scale security harder. Scale smarter.

Dynova provides virtual CISO services, fractional CISO and DPO services in Dubai and across the UAE: security strategy, CBUAE, VARA, ISO 27001, PCI DSS, UAE PDPL and SOC 2 compliance, hands-on execution, penetration testing and code review, all under one named CISO.

info@business-ciso.com

+971 54 458 8631


Report incident:

soc@business-ciso.com


Dynova Services LLC-FZ,

License 2644102.01,

Issued by Meydan Free Zone, Dubai, UAE

Dynova is BSI Associate Consultant