Law note · United Arab Emirates

ADGM Data Protection Regulations, breach notification

cite ADGM Data Protection Regulations 2021, personal data breach notification provisions stage IN FORCE in force since 2021-02-14 kind Breach notification binds private bodies reviewed 2026-08-29

What it requires

  • An app that is a controller or processor established in or targeting the ADGM free zone and that suffers a personal data breach must notify the Commissioner of Data Protection without undue delay and, where feasible, not later than 72 hours after becoming aware of it, unless the breach is unlikely to pose a risk to individuals' rights.

When LexLint raises it

  • crawls_web
  • trains_models
  • processes_biometrics
  • processes_voice

What we found

The ADGM Data Protection Regulations set an explicit 72-hour breach-notification rule to the Commissioner of Data Protection, language read verbatim and drawn from the same family as General Data Protection Regulation (GDPR) Art. 33, unless the breach is unlikely to pose a risk to individuals' rights.

This is the only one of the UAE's three regimes where a specific notification window was confirmed by direct reading in this research pass; the federal PDPL defers its timeline to unconfirmed Executive Regulations, and the DIFC Law's own breach-notification timeline (Part 7) was not individually pulled.

← Back to the example  ·  Lint your app →