UAE PDPL vs. GDPR: Federal Law, DIFC, and ADGM Compared

Most comparisons of the UAE's data protection law against the GDPR treat "the UAE" as a single regime. That framing misses the fact that matters most to any business actually operating there: the UAE runs three separate data protection systems at once, and which one applies to you depends entirely on where your entity is legally established.
A company incorporated on the UAE mainland answers to the federal Personal Data Protection Law. A company set up in the Dubai International Financial Centre answers to DIFC's own law and its own Commissioner. A company set up in Abu Dhabi Global Market answers to a third, separate law and a third regulator. These three regimes do not share a regulator, do not share an adequacy list, and, as this page lays out in detail, are not equally enforceable today.
At a Glance: GDPR vs. UAE Federal PDPL vs. DIFC vs. ADGM
| GDPR (EU) | UAE Federal PDPL | DIFC Data Protection Law | ADGM Data Protection Regulations | |
|---|---|---|---|---|
| Governing law | Regulation (EU) 2016/679 | Federal Decree-Law No. 45 of 2021 | DIFC Law No. 5 of 2020, as amended by Law No. 1 of 2025 | Data Protection Regulations 2021 |
| In force since | 25 May 2018 | 2 January 2022 | 1 July 2020 (amendments in force 15 July 2025) | 2021, phased in through 2022 |
| Territory | EU/EEA, plus extraterritorial reach to non-EU controllers targeting EU residents | UAE mainland and free zones without their own data protection law | Dubai International Financial Centre only | Abu Dhabi Global Market only |
| Regulator | National data protection authorities, coordinated by the European Data Protection Board | UAE Data Office, designated but never operational; folded into the new Artificial Intelligence and Data Authority in June 2026 | Commissioner of Data Protection (DIFC), standing and active | Office of Data Protection / Commissioner of Data Protection (ADGM), standing and active |
| Implementing detail | Fully in force, with extensive guidance from the EDPB and national authorities | Executive Regulations required by the law itself have never been issued | Consolidated law text plus published Commissioner guidance | Consolidated Regulations plus published Rulebook guidance |
| Private right of action | Yes (Articles 79 and 82) | Not established; no functioning enforcement mechanism yet exists | Yes, added by the July 2025 amendment (DIFC Courts) | Yes, since 2021. Section 59 gives any person who suffers material or non-material damage a right to compensation from the controller or processor, enforceable in the ADGM Court (s59(8)), plus a right to seek a compliance order (s59(9)). |
| Published adequacy list | Yes, European Commission adequacy decisions | None published | Yes, Commissioner-published list | Yes, Commissioner-published list, largely mirroring the EU Commission's |
| Real enforcement track record | Extensive, many national-authority fines | None to date; no penalty schedule exists | Extensive. The Commissioner publishes decision notices and administrative fines: 273 administrative-fine decision notices in 2025 (from 717 preliminary notices), plus a handful of full investigation decision notices since 2022. | Two published actions: Okadoc Technologies (2024) and VentureRock Global (2023) |
| Breach notice to regulator | Within 72 hours (Article 33) | No standard at all. Article 9(1) requires notice to the Bureau "at the time it becomes aware" but sets the actual period "in accordance with the measures and requirements set by the Executive Regulations" of the Decree-Law, which have never been issued. | No fixed hour deadline; "as soon as practicable in the circumstances" | Without undue delay, and where feasible not later than 72 hours |

Which Regime Applies to You
This is the question every reader of this page actually has, and the answer is jurisdictional, not sector-based.
- If your entity is licensed on the UAE mainland (in Dubai, Abu Dhabi, or any other emirate, outside the two financial free zones), the federal PDPL applies to your processing of personal data.
- If your entity is licensed in the DIFC, DIFC's own Data Protection Law applies to your DIFC operations, not the federal PDPL.
- If your entity is licensed in ADGM, ADGM's Data Protection Regulations apply to your ADGM operations, not the federal PDPL.
- If your group has entities in more than one of these, each entity is separately subject to its own regime. There is no single "UAE data protection compliance" answer for a multi-entity group; there are up to three.
The federal PDPL is written to apply broadly across the mainland, but Article 2(2)(g) carves out "companies and establishments located in free zones in the Country and have special legislations regarding Personal Data protection." DIFC and ADGM both fall inside that carve-out because each has its own data protection statute, though neither is named in the PDPL itself. The carve-out sits in Article 2(2)(g) of the PDPL itself, and it matches how the two zones actually operate: each maintains its own Commissioner, its own statute, and its own enforcement history entirely separate from the federal side.
For background on the UAE's data privacy laws overall, including how the framework fits into the broader Gulf region, see our dedicated country page.

Background and Current Status of Each Regime
GDPR
The General Data Protection Regulation took effect across the EU/EEA on 25 May 2018. It is the most mature and most litigated data protection framework in the world, with an extensive body of regulatory guidance, court decisions, and a coordinated network of national data protection authorities operating under the European Data Protection Board. For a fuller primer, see what is GDPR.
UAE Federal PDPL
Federal Decree-Law No. 45 of 2021 "Concerning the Protection of Personal Data" was issued on 20 September 2021, published in Official Gazette No. 712 on 26 September 2021, and took effect on 2 January 2022. The official UAE legislation portal lists the law's status as active.
What has not happened is the part that gives most data protection laws their teeth. The PDPL itself requires Executive Regulations to spell out the operative detail, including the specific administrative penalty schedule. Those regulations have never been issued, nearly five years after the law was passed. The regulator the PDPL assigns those functions to, the UAE Data Office, established not by the PDPL itself but by its companion statute, Federal Decree-Law No. 44 of 2021, was described on the UAE government's own website in forward-looking terms, as a body that "will act as" the federal regulator, language consistent with an authority that never actually became operational.
On 14 June 2026, the UAE's Vice President and Prime Minister, Sheikh Mohammed bin Rashid Al Maktoum, approved the establishment of a new Artificial Intelligence and Data Authority, described as the single national body responsible for data, artificial intelligence, and digital government, reporting directly to the Cabinet. It consolidates three existing bodies, including the UAE Data Office. The official Cabinet announcement of the new Authority does not mention the PDPL or data protection by name; its stated mandate is framed around AI strategy, the digital economy, and digital government standards. Some law firms have suggested the new Authority will eventually finish the PDPL's Executive Regulations, but that is an inference from outside commentary, not a stated government commitment, and the timing is explicitly described as uncertain given competing AI-governance priorities.
The practical result: the federal PDPL's substantive provisions on consent, data protection officers, breach notice, and cross-border transfer are formally in force, but the administrative machinery needed to enforce them, including any penalty schedule, has never been switched on, and the body meant to run that machinery no longer exists as a standalone data protection regulator.
DIFC
The Dubai International Financial Centre's Data Protection Law No. 5 of 2020 came into force on 1 July 2020 (Article 4). It is modeled closely on the GDPR and is administered by a dedicated, active regulator, the Commissioner of Data Protection (DIFC), which is entirely separate from the federal side.
On 8 July 2025, DIFC enacted the DIFC Laws Amendment Law No. 1 of 2025, which entered into force on 15 July 2025 and made several substantive changes to the Data Protection Law:
- It introduced an express private right of action at Article 64A, so a DIFC data subject can sue a controller or processor directly in the DIFC Courts for compensation rather than relying only on a Commissioner complaint. This brought DIFC into line with ADGM, whose Regulations have carried an equivalent compensation right at section 59 since 2021.
- It expanded the law's extraterritorial reach to cover controllers and processors incorporated in DIFC regardless of where the actual processing occurs, and to processing that takes place in DIFC as part of "stable arrangements," now explicitly including sub-processors.
- It amended the provision governing disclosure to public authorities and law enforcement, requiring controllers and processors to verify that a request is valid and proportionate before disclosing data.
ADGM
Abu Dhabi Global Market's Data Protection Regulations 2021 are ADGM's standalone framework, administered by the Office of Data Protection, also called the Commissioner of Data Protection (ADGM). The Regulations came into force in phases during 2021 and 2022 as entities newly registered in ADGM and pre-existing ADGM entities separately transitioned onto the new rules. Like DIFC's law, ADGM's Regulations are closely modeled on the GDPR's structure.

Scope and Territorial Application
| GDPR | Federal PDPL | DIFC | ADGM | |
|---|---|---|---|---|
| Who it covers | Controllers/processors in the EU/EEA, plus non-EU entities that offer goods/services to, or monitor the behavior of, people in the EU/EEA | Controllers and processors resident in the UAE processing data of subjects inside or outside the State, and controllers/processors resident outside the UAE processing data of subjects inside it (Article 2(1)). Article 2(2) then excludes government data and governmental entities, data held by security and judicial authorities, purely personal processing, health data and banking/credit data that have their own regulating legislation, and free-zone entities with their own data protection law. | Entities established or licensed in DIFC, plus, after the 2025 amendment, processing carried out in DIFC as part of stable arrangements | Entities registered in ADGM |
| Free zone carve-outs | Not applicable | Excluded by class under Article 2(2)(g): free-zone companies and establishments with their own personal data protection legislation. DIFC and ADGM qualify; neither is named in the statute. | Not applicable; DIFC is itself the free zone in question | Not applicable; ADGM is itself the free zone in question |
The scope split matters because it is easy to assume "UAE data protection law" is a single perimeter. It is not. A group with a mainland trading entity and a DIFC-registered financial services entity is running two entirely separate compliance obligations under two different laws, answering to two different regulators, even though both entities sit inside the same country.

Data Subject Rights
All four regimes give individuals broadly similar categories of rights: access to their data, correction of inaccurate data, deletion in defined circumstances, restriction of processing, objection to certain processing (including direct marketing), and protections around automated decision-making. GDPR's rights framework (Articles 15 through 22) is the most extensively litigated and guided version of this model, and DIFC and ADGM's rights provisions both track it closely, consistent with their GDPR-modeled drafting.
The practical gap is not in what rights the federal PDPL grants on paper, but in what happens when a UAE mainland data subject tries to exercise one. Without Executive Regulations or an operating regulator, there is currently no established federal complaint or enforcement pathway comparable to what DIFC's Commissioner, DIFC's Courts, or ADGM's Office of Data Protection can each offer. DIFC's July 2025 amendment sharpens this further for that free zone specifically, since a DIFC data subject can now go to court directly rather than depending solely on the Commissioner to act.
Legal Bases for Processing
GDPR sets out six legal bases for processing under Article 6, including consent, contractual necessity, legal obligation, vital interests, public task, and legitimate interests, with a stricter regime for special category data under Article 9. DIFC and ADGM's laws include a comparable structure of lawful processing grounds and heightened rules for sensitive categories of data, consistent with their GDPR-based drafting approach.
The federal PDPL similarly frames consent as a central basis for processing, alongside other grounds such as contractual necessity and legal obligations, but because the Executive Regulations have not been issued, the operative detail of how these grounds are assessed and enforced in practice has not been fleshed out the way it has under DIFC and ADGM guidance, or under the extensive body of EDPB and national-authority guidance built up around GDPR.
Regulators and Enforcement Reality
This is where the three-regimes trap is sharpest, because it inverts a common assumption. A business that concludes "UAE data law has no teeth" is right only about the federal, mainland leg.
Federal PDPL: The UAE Data Office was designated as the federal regulator but never became operational. As of 14 June 2026, it no longer exists as a standalone body, having been folded into the new Artificial Intelligence and Data Authority alongside two other government units. No penalty schedule has ever been published, because the Cabinet decision needed to set one has not been issued. There is, as of this writing, no functioning federal enforcement pathway for a PDPL violation.
DIFC: The Commissioner of Data Protection (DIFC) is not just standing but by far the busiest data protection enforcer in the UAE. The Commissioner publishes both investigation decision notices and administrative fines, and the volume is substantial: 717 preliminary notices and 273 administrative-fine decision notices in 2025, up from 173 in 2023. Most arise from basic compliance failures such as letting a processing notification lapse or not responding to an investigation request, rather than headline breaches. As of the July 2025 amendment, DIFC also has a judicial enforcement route, since data subjects can now bring a Data Protection Law claim directly in the DIFC Courts.
ADGM: The Office of Data Protection has issued real, named enforcement actions. On 21 May 2024, the ODP issued a Penalty Notice against Okadoc Technologies Limited over contraventions of the Regulations' individual-rights provisions, arising from the company's handling of a data subject access request. On 23 June 2023, the ODP issued a Direction against VentureRock Global Limited over a contravention of the Regulations' security principle. These are ADGM's only two published enforcement actions to date, but they are two more than the federal regime has ever issued, and they demonstrate that ADGM's regulator functions as a real enforcement body, not just a name on a statute.
The upshot: two of the UAE's three data protection regimes are already actively enforcing their laws against named companies. The one that is not is the federal, mainland regime, which is also the one most competitor content treats as "the UAE's data protection law" without qualification.
For businesses weighing whether they need a dedicated compliance role across these regimes, see our overview of data protection officer requirements.
Cross-Border Data Transfers
| GDPR | Federal PDPL | DIFC | ADGM | |
|---|---|---|---|---|
| Adequacy mechanism | European Commission adequacy decisions for specific countries | Data Office was intended to determine adequate countries; no such list has been published | Commissioner-published adequacy list | Commissioner-published adequacy list |
| What the adequacy list includes | A defined set of Commission-approved third countries | Not applicable; no list exists | EU/EEA member states plus Iceland, Liechtenstein and Norway; the UK; Switzerland; Andorra; Argentina; ADGM; California; Canada; Colombia; the Faroe Islands; Guernsey; the Isle of Man; Israel; Japan; Jersey; New Zealand; the Qatar Financial Centre; Uruguay; Singapore; the Global CBPR/PRP framework; and South Korea | Jurisdictions the European Commission itself recognizes as adequate, plus DIFC, Israel, the Qatar Financial Centre, Argentina, Canada (conditioned on PIPEDA coverage), Uruguay, New Zealand, Japan, South Korea, the UK, and Switzerland, plus the United States for organizations certified under the EU-US Data Privacy Framework |
| Non-adequate fallback | Standard Contractual Clauses, Binding Corporate Rules, or narrow derogations | The statute contemplates standard-form contracts, consent, and similar mechanisms, but no template or published mechanism currently exists in practice | DIFC's own Standard Contractual Clauses, modeled on a combination of the EU Model Clauses and the UK's International Data Transfer Agreement, plus Binding Corporate Rules and limited derogations | Standard Contractual Clauses, using ADGM's own official addendum to the EU SCCs, or Binding Corporate Rules, alongside enforceable data-subject rights and remedies |
This table is where the practical trap becomes concrete. Neither DIFC's nor ADGM's adequacy list references the UAE mainland or the federal PDPL as an adequate transfer destination, even though both free zones recognize each other. And the federal side has no adequacy list of its own to receive data at all, because the mechanism that would create one, the Data Office's determination process, never became operational. A group moving personal data from a DIFC or ADGM entity to its own mainland UAE affiliate is not operating under a clearly adequate or clearly safeguarded transfer today; it is operating in a genuine regulatory gap.
For a broader look at how this kind of transfer mechanism works elsewhere, see standard contractual clauses and our survey of data localization laws by country.
Breach Notification
Breach notification timing is one of the clearest points of divergence between these four regimes, and it does not follow a single pattern.
| GDPR | Federal PDPL | DIFC | ADGM | |
|---|---|---|---|---|
| Notice to regulator | Within 72 hours of becoming aware, unless unlikely to result in a risk (Article 33) | Article 9(1) requires the Controller to notify the Bureau "at the time it becomes aware" of the breach, but fixes the period only by reference to "the measures and requirements set by the Executive Regulations," which have never been issued. There is therefore no operative deadline, numeric or qualitative. The "72 hours" commonly cited for the federal regime does not appear in the law. | No fixed hour or day deadline anywhere in the law; the standard is "as soon as practicable in the circumstances" | Without undue delay, and where feasible not later than 72 hours after becoming aware, unless the breach is unlikely to result in a risk to individuals' rights |
| Notice to individuals | Without undue delay, only where the breach is likely to result in a high risk to the individual (Article 34) | Required once a breach is assessed as posing a risk, with individual-notice timing left to Executive Regulations that do not yet exist | As soon as practicable in the circumstances where the breach is likely to result in high risk; if there is immediate risk of damage, notice must be prompt | Without undue delay where the breach is likely to result in high risk, with safe-harbor exceptions where encryption or other mitigations were already in place |
The pattern worth remembering: across these regimes, the regulator-facing leg is sometimes a hard 72-hour clock, but the individual-facing leg is consistently a "without undue delay" or "as soon as practicable" standard rather than a fixed number of hours. Do not treat "72 hours" as a blanket figure that applies identically to every notice obligation in every regime; DIFC in particular has no fixed-hour deadline at all, for either the regulator or the individual, which is a genuine and useful point of contrast against both ADGM and GDPR.
Penalties
| GDPR | Federal PDPL | DIFC | ADGM | |
|---|---|---|---|---|
| Maximum exposure | Up to €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements | No penalty schedule exists; the statute delegates penalty-setting to a Cabinet decision that has never been issued | Two tiers. Schedule 2 sets per-article administrative maximums from USD 25,000 to USD 100,000 (Article 62(2)). On top of that, Article 62(3) lets the Commissioner issue a general fine not limited to the Schedule 2 amounts, in whatever amount is appropriate and proportionate to the seriousness of the contravention and the risk of actual harm, so there is no statutory ceiling for serious contraventions. | Up to USD 28 million per Penalty Notice (s55(1)), and USD 28 million in aggregate where several provisions are contravened in the same or linked processing operations (s55(6)), the highest stated ceiling of any UAE regime. ADGM has used the power sparingly, issuing two named notices to date. |
| Breach-notice-specific figures | Falls under the general fining framework above | Not applicable; no schedule exists | Failing to notify the Commissioner under the relevant breach article carries a fine of up to USD 25,000; failing to notify an affected data subject carries a fine of up to USD 50,000 | Enforcement to date has taken the form of a named Penalty Notice (Okadoc Technologies, 2024) and a Direction (VentureRock Global, 2023) rather than a published, generalized breach-notice fine schedule |
DIFC's penalty structure is worth flagging specifically because it is easy to misreport as a single number. It is not one cap; it is a schedule of per-article maximums that differ depending on which obligation was violated, with breach-notification failures sitting toward the lower end of that schedule and other categories of violation reaching higher. It is also not the whole picture. Schedule 2 governs the administrative tier only; Article 62(3) separately empowers the Commissioner to issue a general fine expressly not limited to the amounts specified in Schedule 2, sized to the seriousness of the contravention and the risk of actual harm. For a serious contravention, DIFC exposure is uncapped.
The federal PDPL's row is the starkest contrast on this table. There is currently no published penalty amount, high or low, for a PDPL violation, because the Cabinet decision that would set one has never been issued.
Recent Developments
Compliance Guidance for Groups Operating Across All Three UAE Regimes
A business with a presence on the mainland and in one or both free zones should treat this as three compliance programs, not one, until the federal side changes materially:
- Map each entity to its regime first. Legal establishment, not business activity, determines which of the three laws applies. A mainland branch of a DIFC-registered company is still a separate question from the DIFC entity itself.
- Do not assume mainland-to-free-zone transfers are safe by default. Because neither DIFC nor ADGM's adequacy list includes the UAE mainland, and the federal side has no adequacy mechanism of its own, moving data between a free zone entity and a mainland affiliate should be treated as an unresolved transfer question, not a routine intra-group flow.
- Register in both free zones, the duty is not ADGM-only. ADGM requires every registered entity that processes personal data to register as a Data Controller, with annual renewal. DIFC separately requires controllers and processors to register with its Commissioner by filing a notification of processing operations, kept up to date by amended notifications, accompanied by a prescribed fee (Article 14(7)-(8)); failing to do so is fineable up to USD 25,000 under Schedule 2, and lapsed notifications are among the most common causes of DIFC administrative fines. The federal regime operates no registration requirement, because the machinery to run one was never established. So the checklist differs across all three, but two of the three do require registration.
- Build your breach-notice playbook around the strictest applicable clock. For a group with DIFC, ADGM, and mainland entities, defaulting internal escalation procedures to ADGM's 72-hour benchmark, and applying GDPR's 72-hour standard wherever EU data subjects are also involved, is the safer operational choice even where DIFC's own law does not impose the same fixed deadline.
- Do not rely on the federal PDPL's stated rights and obligations as a functioning enforcement backstop yet. Contractual and technical safeguards matter more on the mainland today precisely because the regulatory and penalty machinery that would otherwise enforce the statute is not yet running.
- Watch the Artificial Intelligence and Data Authority, not the old UAE Data Office name, for future federal developments. Any Executive Regulations or federal penalty schedule that eventually appears will come from this new body, whose current public mandate is framed around AI and digital government rather than data protection specifically.
Frequently Asked Questions
Is the UAE's data protection law the same everywhere in the country?
No. The UAE runs three separate data protection regimes. The federal Personal Data Protection Law covers the mainland and free zones without their own law. The Dubai International Financial Centre and Abu Dhabi Global Market each have their own separate law and regulator, and neither is governed by the federal statute.
Is the UAE's federal PDPL actually enforceable right now?
The law itself has been in force since 2 January 2022, but its Executive Regulations, which were meant to set the specific penalty schedule and procedural detail, have never been issued. The regulator, the UAE Data Office (created by the PDPL's companion statute, Federal Decree-Law No. 44 of 2021), never became operational and was folded into a new Artificial Intelligence and Data Authority in June 2026. There is currently no published penalty schedule and no established federal enforcement pathway.
Are DIFC and ADGM's data protection laws actually enforced?
Yes. Both have standing, active regulators. ADGM's Office of Data Protection has issued two published enforcement actions against named companies, a Penalty Notice against Okadoc Technologies in 2024 and a Direction against VentureRock Global in 2023. DIFC's Commissioner is also active, and since July 2025 data subjects can additionally bring a claim directly in the DIFC Courts.
What changed in DIFC's data protection law in 2025?
The DIFC Laws Amendment Law No. 1 of 2025, in force from 15 July 2025, added a private right of action allowing data subjects to sue a controller or processor directly through the DIFC Courts, expanded the law's extraterritorial reach, and tightened the conditions under which data can be disclosed to public authorities.
Can a company transfer data from an ADGM or DIFC entity to its own UAE mainland affiliate without extra safeguards?
This is not a settled 'adequate' transfer under either free zone's rules. Neither DIFC's nor ADGM's published adequacy list includes the UAE mainland or references the federal PDPL, and the federal regime has no adequacy list of its own because the mechanism intended to create one was never operationalized. Treat mainland transfers as an open compliance question rather than a routine intra-group flow.
How does UAE breach notification timing compare to the GDPR's 72-hour rule?
It varies by regime. ADGM sets a comparable standard: without undue delay, and where feasible not later than 72 hours, to its Commissioner. DIFC sets no fixed hour deadline at all for either the regulator or affected individuals, using only an 'as soon as practicable' standard. The federal PDPL sets no deadline at all. Article 9 requires the controller to notify the UAE Data Bureau when it becomes aware of a breach but leaves the actual period to Executive Regulations that have never been issued, so the 72-hour figure sometimes quoted for the UAE federal regime is not in the statute.
Does the UAE federal PDPL have a private right of action like DIFC now does?
No. The federal PDPL does not establish a comparable court-based enforcement mechanism for data subjects, and with the Executive Regulations and operational regulator both still missing, there is no established federal enforcement pathway of any kind at this time.
Will the UAE's new Artificial Intelligence and Data Authority fix the federal PDPL's gaps?
That is not yet confirmed. The June 2026 Cabinet announcement creating the Authority consolidated the UAE Data Office into a new body focused on AI, the digital economy, and digital government, but the announcement itself did not mention the PDPL or commit to finishing its Executive Regulations. Some legal commentators expect the Authority to eventually take up that task, but this is an outside inference, not a stated government commitment.
Updates
DIFC Laws Amendment Law No. 1 of 2025 entered into force, adding a private right of action through the DIFC Courts, expanding the Data Protection Law's extraterritorial reach, and tightening the standard for disclosing data to public authorities.
The UAE's Vice President and Prime Minister, Sheikh Mohammed bin Rashid Al Maktoum, approved the establishment of a new Artificial Intelligence and Data Authority, consolidating the UAE Data Office (the federal PDPL's intended regulator, which never became operational) with two other government digital and AI bodies. The announcement did not address the status of the PDPL's still-unissued Executive Regulations.
Sources and References
- Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data — official legislation record (issued, gazette, effective dates, active status)(uaelegislation.gov.ae).gov
- UAE government page on data protection laws and the Data Office(u.ae).gov
- UAE Cabinet announcement: Mohammed bin Rashid approves establishing the Artificial Intelligence and Data Authority (14 June 2026)(uaecabinet.ae).gov
- DIFC Data Protection Law No. 5 of 2020 — legal database entry(difc.com).gov
- DIFC announces enactment of amendments through DIFC Laws Amendment Law No. 1 of 2025(difc.com).gov
- DIFC Commissioner of Data Protection — Data Export and Sharing (cross-border transfer, adequacy list)(difc.com).gov
- DIFC Data Protection Law No. 5 of 2020 — consolidated text (Articles 41-42 breach notification, Schedule 2 penalties)(difc.com).gov
- ADGM Office of Data Protection — overview(adgm.com).gov
- ADGM Office of Data Protection — registration and renewal fees(adgm.com).gov
- ADGM Office of Data Protection — adequate jurisdictions for cross-border transfer(adgm.com).gov
- ADGM Office of Data Protection — regulatory actions (Okadoc Technologies Penalty Notice; VentureRock Global Direction Notice)(adgm.com).gov
- ADGM Data Protection Regulations 2021, consolidated text, official ADGM Rulebook (sections 32-33 breach notification, sections 55 and 59 penalties and compensation). NOTE: also change this citation's domain field from 'adgm.com' to 'en.adgm.thomsonreuters.com' (the URL's actual host), and note the DPR uses 'sections' not 'Articles'.(en.adgm.thomsonreuters.com).gov
- Regulation (EU) 2016/679 (General Data Protection Regulation)(eur-lex.europa.eu).gov
- DIFC Commissioner of Data Protection, Supervision and Enforcement (published decision notices and administrative fine volumes)(difc.com).gov
- Federal Decree-Law No. 44 of 2021 establishing the Emirates Data Office(uaelegislation.gov.ae).gov