DIFC DPL vs. ADGM DPR vs. UAE PDPL: Which Applies to Your Business?

DIFC DPL vs. ADGM DPR vs. UAE PDPL: Which Applies to Your Business?

One of the most common points of confusion for businesses operating in the UAE is realising there isn’t one data protection law to comply with: there are potentially three, depending on where and how you’re structured. Getting this wrong means either building a compliance program against the wrong law, or missing one entirely.

The three regimes

UAE PDPL (Federal Decree-Law)

The UAE’s federal Personal Data Protection Law applies broadly across the UAE mainland, to controllers and processors established in the UAE, and to controllers/processors outside the UAE processing personal data of individuals inside the UAE in connection with offering goods or services to them, or monitoring their behaviour. Certain sectors with their own specific data protection regulation (such as some financial and healthcare data) may have sector-specific rules layered on top.

DIFC DPL (DIFC Law No. 5 of 2020)

The Dubai International Financial Centre is a financial free zone with its own legal system, separate from UAE federal law for most civil and commercial matters, including data protection. Entities licensed and operating within the DIFC are generally governed by the DIFC Data Protection Law, overseen by the DIFC Commissioner of Data Protection, rather than UAE PDPL, for their DIFC-based processing activities.

ADGM DPR (ADGM Data Protection Regulations 2021)

Abu Dhabi Global Market operates on the same free-zone model as DIFC: its own jurisdiction, its own data protection regulator, and its own regulation (the ADGM Data Protection Regulations), closely modelled on GDPR. Entities established within ADGM are generally governed by the ADGM DPR for their ADGM-based activities.

How to work out which applies to you

  • Check your entity’s place of incorporation and licensing. A company licensed within the DIFC or ADGM is generally governed by that free zone’s law for its operations there, not automatically UAE PDPL.
  • Check where your data subjects are. If you’re UAE PDPL-scoped and process personal data of individuals physically in the UAE (including outside the free zones), UAE PDPL applies regardless of your own location.
  • Check for overlap. A group with a mainland UAE entity and a DIFC-licensed entity is very likely subject to two different laws simultaneously, one per entity, not one law for the whole group.
  • Check sector-specific rules. Financial services, healthcare, and telecoms often carry additional sector-specific data protection requirements on top of whichever general law applies.

Why this matters in practice

Building a single compliance program against the wrong law, or assuming one UAE entity’s compliance covers a whole corporate group, is one of the most common gaps we see. It’s also one of the most straightforward to fix once identified: a short jurisdiction-mapping exercise against your actual corporate and operational structure tells you definitively which law (or laws) apply, before you spend time or budget building a program against the wrong one.

This article is general guidance, not legal advice. Jurisdictional applicability depends on your specific corporate structure and processing activities. A scoping call can map this precisely for your business.

Not sure which UAE law applies to you? A free scoping call maps your entity structure against UAE PDPL, DIFC DPL, and ADGM DPR. Book a Free Compliance Call



Leave a Reply

Data Trust Consultants
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.