You have a UAE company, you handle personal data, and you have been told there is a UAE data protection law for that. There is more than one. DIFC and ADGM data protection sit alongside the federal PDPL as three separate regimes, each with its own regulator and its own reach.
Getting the mapping wrong is the difference between a compliance programme aimed at an authority that cannot enforce against you, and one built for the authority that can.
Key Takeaways
- The UAE has three separate data protection regimes — Federal Decree-Law No. 45 of 2021 (PDPL), in force since 2 January 2022, covers mainland entities and can extend to free zones. DIFC and ADGM each run their own separate law and regulator on top of that. Your licence location is the starting point, not the final answer.
- A free-zone licence doesn't block federal PDPL exposure — DIFC and ADGM each have their own independent regulator, but the federal PDPL's scope can still extend to free-zone entities depending on the nature of the processing and the residency of the individuals whose data is handled.
- DIFC's law tracks EU and UK data standards — DP Law 2020 was written to be consistent with EU and UK data protection regulations and OECD guidelines, and DIFC is one of six jurisdictions the UK recognises as a Data Bridge priority partner — relevant if you transfer data to UK counterparties.
- Overlap between regimes is the default, not the exception — A DIFC entity handling mainland UAE residents' data, or routing data through a foreign cloud provider, can face simultaneous obligations under more than one regime. The compliance programme needs to be built for that overlap, not for a single regulator.
Three Regimes, One Country: How UAE Data Law Is Structured
The UAE does not run a single data protection law. It runs three, and none of them cancels the others out.
Mainland entities sit under Federal Decree-Law No. 45 of 2021, the PDPL, which came into force on 2 January 2022 and is enforced by the UAE Data Office established under Federal Decree-Law No. 44 of 2021.
For the plain-English version of that federal regime and how it lands on companies deploying AI, we cover it in our PDPL guide.
DIFC operates as a self-contained free-zone regime with its own law, DIFC Law No. 5 of 2020, enacted in May 2020. DIFC was the first jurisdiction in the GCC to enact a dedicated data protection law, doing so back in 2004, and the independent Office of the Commissioner of Data Protection has existed since 2007.
ADGM runs its own independent framework in parallel, with its own regulator, separate from both the DIFC Commissioner and the federal UAE Data Office.
Each regime rests on its own law, its own regulator, and its own default scope, and laying them out side by side makes the split easier to hold onto.
The same ministry sets the consumer protection rules that apply to automated sales contact just as they do to a human sales team.
| Regime | Governing Law | Regulator | Default Scope |
|---|---|---|---|
| Federal PDPL | Federal Decree-Law No. 45 of 2021 (in force 2 Jan 2022) | UAE Data Office | Mainland entities; can extend to free zones |
| DIFC | DIFC Law No. 5 of 2020 (DP Law 2020) | Commissioner of Data Protection | DIFC-licensed entities |
| ADGM | ADGM data protection regulations | ADGM's own regulator | ADGM-licensed entities |
The Decision Test: Which Framework Governs Your Business

Photo: joao Guerreiro on Pexels
Start with your licence. A DIFC licence puts you under DP Law 2020. An ADGM licence puts you under the ADGM framework.
A mainland licence or any other free-zone licence puts you under the federal PDPL by default. That is the starting point, not the end of the analysis.
The federal PDPL's scope can extend to free-zone entities depending on whose personal data they process and where those individuals sit. A DIFC company handling personal data of mainland UAE residents is not automatically outside the PDPL simply because it lives inside a free zone.
A single business can be subject to a free-zone regime and federal obligations at the same time, and the two do not cancel each other out.
What matters is which regulator can actually enforce against you for a given processing activity, and building your compliance programme to satisfy that authority.
DIFC Data Protection Law 2020: What It Requires
DIFC's data protection story is older than most people assume. The zone first enacted a data protection law in 2004, established the independent Office of the Commissioner in 2007, and refreshed the regime with DP Law 2020, enacted in May 2020.
The Commissioner of Data Protection, Jacques Visser, is responsible for supervision and enforcement of DP Law 2020.
DP Law 2020 was written to be consistent with EU and UK data protection regulations and OECD guidelines. DIFC has been recognised by the United Kingdom as one of six Data Bridge priority partners, which is directly relevant if your business transfers personal data to or from UK counterparties.
The core obligations sit in familiar buckets: accountability and governance, data subject rights, personal data breach reporting to the Commissioner, and restrictions on international data transfers. Notifications to the Commissioner and specific procedural requirements are set out in the DIFC Data Protection Regulations 2020, which sit under the law.
If you are planning an AI deployment inside DIFC and need help scoping how DP Law 2020 lands on your specific use case, Lenoo AI can walk it through with you.
ADGM's Data Protection Framework: A Separate Regime
ADGM is not a copy of DIFC. It runs its own data protection regulations and its own regulator, entirely separate from the DIFC Commissioner of Data Protection and from the federal UAE Data Office.
Being licensed inside ADGM binds you to the ADGM framework, not DP Law 2020, even though both zones sit within the UAE.
Structurally, both free-zone frameworks share a philosophy of alignment with international standards, but the governing authority, the enforcement channel, and the procedural steps differ. A breach notification submitted to the DIFC Commissioner does not discharge an obligation owed to ADGM's regulator, and the reverse is equally true.
If your group has a presence in both zones, you inherit obligations under both regimes at once, on top of any federal exposure that the nature of your processing brings in.
Federal PDPL: Scope, Obligations, and Enforcement

Photo: SHOX ART on Pexels
Federal Decree-Law No. 45 of 2021, in force on 2 January 2022, is the default regime for entities outside DIFC and ADGM. It can also reach into the free zones depending on the nature of the processing and the residency of the data subjects involved.
The full text of the law is published on the UAE government portal.
The UAE Data Office, established under Federal Decree-Law No. 44 of 2021, is the federal regulator with authority over mainland entities.
Core obligations track the international pattern: identify a lawful basis for processing, publish a privacy notice that reflects what you actually do, honour data subject rights, report personal data breaches, and control cross-border transfers. Non-compliance is not a theoretical risk. We cover that separately in our PDPL penalties article.
Overlap Scenarios: When More Than One Regime Applies at Once
Overlap is where most UAE compliance work actually lives. A DIFC-licensed entity that processes personal data of mainland UAE residents can face obligations under both DP Law 2020 and the federal PDPL simultaneously. The free-zone regime does not pre-empt the federal one when the federal one's scope is triggered.
The moment personal data leaves the UAE through a foreign cloud provider or a model API hosted abroad, transfer rules under whichever regime binds you become live obligations.
If your AI stack uses a model provider outside the UAE, that is a cross-border transfer, and it needs handling under DIFC, ADGM, or federal rules depending on where you sit. We unpack the mechanics in our piece on cross-border transfers and foreign model providers.
Automated decisioning and agent-based customer interactions all touch personal data, and transparency and notice obligations apply across all three frameworks.
If you have deployed an agent that talks to customers, your privacy notice needs to say so. We walk through what to include in our AI-agent privacy notice guide.
The practical order is short. Map your data flows against your licence location, then against the residency of the data subjects.
Then ask whether any transfer or automation use-case pulls in a regime you would not otherwise face. Only then decide what compliance programme to build.
Get the Mapping Right Before You Build the Programme
If you are not sure which regime applies to your business, fix that first, before you spend money on policies, notices, or DPIAs aimed at the wrong regulator. Book a free 30-minute consultation with Lenoo AI and we will map which data protection obligations apply to your setup and where your current programme has gaps.
No pitch. If your existing arrangement is fine, we will tell you.
FAQ
Does the federal PDPL apply to companies that are licensed inside DIFC or ADGM?
Not automatically, but not never either. Free-zone entities are primarily bound by their zone's regime, but the federal PDPL's scope can extend to them depending on the nature of the processing and the individuals whose data is being handled. Map your processing activities before assuming a free-zone licence is a full shield.
What is the practical difference between the DIFC and ADGM data protection regimes?
They are two separate frameworks with two separate regulators. DIFC operates under DP Law 2020 with the Commissioner of Data Protection, Jacques Visser, handling supervision and enforcement. ADGM has its own independent regulations and its own regulator, and the two are not interchangeable.
Who enforces data protection law inside DIFC, and how do I submit a complaint or notification?
The DIFC Commissioner of Data Protection supervises and enforces DP Law 2020. Individuals can submit complaints to the Commissioner's Office, and regulated entities file breach notifications and other regulatory submissions to the same office, following the procedures set out in the DIFC Data Protection Regulations 2020.
If my business has entities in both DIFC and mainland UAE, do I need separate compliance programmes for each?
You need one programme that satisfies both regimes. The DIFC entity is bound by DP Law 2020, the mainland entity by the federal PDPL, and the two do not cancel each other out. Common controls can serve both, but breach reporting channels and regulator interactions have to be handled to each authority's own requirements.
Does sending personal data from DIFC to a cloud provider based outside the UAE trigger the DIFC cross-border transfer rules?
Yes. DP Law 2020 places restrictions on international data transfers, and routing personal data to a cloud, SaaS, or model API hosted outside the UAE is a cross-border transfer for that purpose. You need a lawful basis for the transfer and appropriate safeguards, matched to the destination.
What does UK Data Bridge status mean for a DIFC-licensed business, and does it affect how I transfer data to UK partners?
DIFC is recognised by the United Kingdom as one of six Data Bridge priority partners, on the basis that DP Law 2020 is consistent with UK data protection regulations. In practice it signals a shorter path for personal data flows between DIFC-based entities and UK counterparties.