Law note · United Arab Emirates

ADGM Data Protection Regulations, comprehensive regime

cite ADGM Data Protection Regulations 2021 (consolidated February 2024) stage IN FORCE in force since 2021-02-14 kind Comprehensive regime binds private bodies reviewed 2026-08-29

What it requires

  • An app that is a controller or processor established in or targeting the ADGM free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier, including one derived from a photo, video, or audio recording.

When LexLint raises it

  • crawls_web
  • trains_models
  • generates_content
  • deploys_chatbot
  • automated_outreach
  • high_risk_decisions
  • processes_voice
  • processes_biometrics
Excludes recording-derived identifiers
No

What we found

The ADGM Data Protection Regulations are the equivalent statute of the Abu Dhabi Global Market free zone (Abu Dhabi's Al Maryah and Al Reem Island financial free zone), enforced by ADGM's own Commissioner of Data Protection under ADGM's separate court system, and apply only within that free-zone footprint, not to a UAE business operating outside it.

This document cites the consolidated text as amended through February 2024; the exact original 2021 commencement date was not independently re-derived from primary text in this research pass, so 2021-02-14 is carried from the corpus's own record rather than independently confirmed. Section 1's Biometric Data definition names facial images and dactyloscopic data as worked examples, with the same adequacy-plus-alternative-safeguards cross-border transfer structure as the federal PDPL and DIFC Law. No source-based exclusion for a recording-derived biometric identifier was found.

← Back to the example  ·  Lint your app →