Law note · United Arab Emirates
ADGM Data Protection Regulations, comprehensive regime
What it requires
- An app that is a controller or processor established in or targeting the ADGM free zone must establish a lawful basis for processing personal data, and must obtain explicit consent or another qualifying condition before processing a faceprint, voiceprint, or other biometric identifier, including one derived from a photo, video, or audio recording.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
- Excludes recording-derived identifiers
- No
What we found
The ADGM Data Protection Regulations are the equivalent statute of the Abu Dhabi Global Market free zone (Abu Dhabi's Al Maryah and Al Reem Island financial free zone), enforced by ADGM's own Commissioner of Data Protection under ADGM's separate court system, and apply only within that free-zone footprint, not to a UAE business operating outside it.
This document cites the consolidated text as amended through February 2024; the exact original 2021 commencement date was not independently re-derived from primary text in this research pass, so 2021-02-14 is carried from the corpus's own record rather than independently confirmed. Section 1's Biometric Data definition names facial images and dactyloscopic data as worked examples, with the same adequacy-plus-alternative-safeguards cross-border transfer structure as the federal PDPL and DIFC Law. No source-based exclusion for a recording-derived biometric identifier was found.