Blog / UAE compliance
UAE compliance
DIFC, ADGM or Federal PDPL: Which Data Rules Apply to Your Free-Zone Company
DIFC Data Protection Law, ADGM regulations or federal PDPL: how to tell which one governs your data, what changes at the free-zone boundary, and what to fix.
One client list, two legal systems, a daily commute between them
The compliance officer of a 15-person wealth advisory in the DIFC has a clean setup on paper. The firm is licensed in the Centre, the client agreements say DIFC law, and the portfolio system sits with a vendor whose brochure mentions the DIFC Data Protection Law on page one.
The back office is in Deira. Four people process onboarding forms, scan passports and chase signatures from a mainland-licensed service company that the founders set up in 2017 to save on rent. Every morning the DIFC team exports the day's client updates to a shared folder. Every evening the Deira team uploads the scanned files back.
A prospective client's lawyer sends a due-diligence questionnaire in July. Question 14: "Under which data protection regime is the client's personal data processed, and by which legal entity?"
The compliance officer starts to write "DIFC" and stops. The passport scan was taken in Deira, by a mainland company, on a mainland laptop, and stored on a Google Drive account registered to the service company. The DIFC firm never touched it until it appeared in the folder.
He asks the firm's lawyer. The lawyer asks which entity is the controller for the scan. Nobody has ever decided.
What the heck does this mean
The UAE has three data protection regimes that a small firm can fall into, and where your desk sits decides which one.
Federal PDPL: Federal Decree-Law 45 of 2021, the law for the mainland and most free zones, in force since January 2022.
DIFC Data Protection Law: DIFC Law No. 5 of 2020, which governs entities established in the Dubai International Financial Centre, with its own Commissioner of Data Protection.
ADGM Data Protection Regulations 2021: the Abu Dhabi Global Market's equivalent, with its own Office of Data Protection.
Controller: the entity that decides why and how personal data is processed; the one that answers to the regulator.
Processor: an entity that handles data on the controller's instructions, such as your back-office service company or your cloud vendor.
The two financial free zones are carved out of the federal law: PDPL does not apply to DIFC or ADGM entities as such. The catch is that the carve-out follows the legal entity, not the office building. A mainland service company is a mainland company, and its scanning work is under PDPL, whatever the DIFC firm's client agreements say. When data crosses that boundary twice a day, you have two regimes and need to know which one governs each step.
The numbers that matter
DIFC Data Protection Law No. 5 of 2020 came into force on 1 July 2020 under the DIFC's 2020 enactment, and it carries its own breach notification and registration duties administered by the Commissioner of Data Protection. In September 2023 the Commissioner added Regulation 10, covering the use of personal data in AI systems, which matters if your portfolio tool now has a "smart assistant."
ADGM's Data Protection Regulations 2021 came into force on 11 February 2021 under the ADGM's 2021 rules, with the Office of Data Protection as regulator. Firms that hold licences in both centres carry both sets of duties.
Federal PDPL exempts DIFC and ADGM entities from its own scope but not from federal sector rules, under Federal Decree-Law 45 of 2021. A DIFC advisory still answers to its financial regulator on security, and its mainland back office answers to PDPL.
What to do this week
- Decide, in writing, which entity is controller for each dataset: client onboarding files, the portfolio system, marketing lists, staff records. One line per dataset, signed by a partner. (CIS 3 Data Protection)
- Map every hop the data takes between the two offices, including the shared folder, the scanner's email-to-self function and the personal Drive account, and close the hops that have no business reason. (CIS 3 Data Protection)
- Put a written processing agreement between the DIFC firm and the mainland service company, naming the DIFC entity as controller and setting out what the Deira team may do with the data. (CIS 15 Service Provider Management)
- Ask every cloud vendor, in writing, where the data centre is and which regime their contract references, and keep the answers in one folder for the next questionnaire. (CIS 15 Service Provider Management)
- Turn on audit logging on the shared folder and the portfolio system so you can show who opened or exported a client record and from which office. (CIS 8 Audit Log Management)
- Write the breach page for both regimes: who calls the DIFC Commissioner, who calls the UAE Data Office, and who tells the client, with names and mobile numbers. (CIS 17 Incident Response Management)
Where AccuSights fits
Our assessment maps your data flows against DIFC, ADGM or PDPL as they apply to each entity, plus the financial-sector rules on top, and ranks the gaps so the partner knows what to sign off first. The read-only compliance agent keeps that picture current with read-only insight into where data sits and where the controls are missing, so you prioritise and keep an eye on them. We have no access to your systems and we do not remediate; you or your IT partner fix, we show you where.
Questions people ask
Does DIFC law apply to a mainland branch? DIFC law follows the DIFC entity and the processing done in its context. A mainland office with its own licence is a separate footprint, and PDPL governs it. When the same client list moves between the two every day, you are effectively under both, so the practical answer is to run the whole business to the stricter rule and document which entity is controller for each dataset.
Do I need to register with the DIFC Commissioner? If you are a DIFC-established entity that processes personal data, yes: controllers notify the Commissioner of Data Protection and keep that notification current. It is an online filing, not an audit, but the Commissioner can and does ask follow-up questions about what you declared. Treat the filing as the summary of your data map, so the two never disagree.
Can DIFC data be hosted in the EU? Generally yes. The DIFC recognises a list of jurisdictions with adequate protection, and EU member states are on it, so transfers there do not need extra safeguards beyond a contract with the provider. Transfers to countries not on the list need appropriate safeguards or another lawful basis. Check where your cloud vendor's data centre actually is, not where its sales office is.
Question 14 is not a trick. It is a client asking if you know where his passport is. Be the firm that can answer in one sentence.
Questions people ask
Does DIFC law apply to a mainland branch?
DIFC law follows the DIFC entity and the processing done in its context. A mainland office with its own licence is a separate footprint, and PDPL governs it. When the same client list moves between the two every day, you are effectively under both, so the practical answer is to run the whole business to the stricter rule and document which entity is controller for each dataset.
Do I need to register with the DIFC Commissioner?
If you are a DIFC-established entity that processes personal data, yes: controllers notify the Commissioner of Data Protection and keep that notification current. It is an online filing, not an audit, but the Commissioner can and does ask follow-up questions about what you declared. Treat the filing as the summary of your data map, so the two never disagree.
Can DIFC data be hosted in the EU?
Generally yes. The DIFC recognises a list of jurisdictions with adequate protection, and EU member states are on it, so transfers there do not need extra safeguards beyond a contract with the provider. Transfers to countries not on the list need appropriate safeguards or another lawful basis. Check where your cloud vendor's data centre actually is, not where its sales office is.
Controls this post maps to
CIS Controls v8.1, the baseline the UAE IA Standard and ADHICS build on. These are the same controls our assessment scores.
Sources
Sam Khan, Founder and CEO. CISA and CRISC. More than two decades in financial services security and risk, from the Federal Reserve System to Guggenheim. Reads the week in threats so an owner does not have to. About the team →
Keep reading
Three more from the same shelf.
AI Governance for a Small Business: NIST AI RMF, ISO 42001 and the UAE AI Charter Without the Consultancy Bill
An AI governance framework a 30-person business can run: what NIST AI RMF, ISO 42001 and the UAE's AI rules ask, and the five documents to write first.
Practical controlsAudit Logging for a Small Business: What to Keep, for How Long, and How to Stop Your Data Walking Out the Door
Audit logging for a small business: which logs to keep, for how long, and the DLP settings that stop a departing employee taking the whole database with them.
UAE complianceCBUAE Cyber Rules for Fintechs and the Suppliers Who Serve Banks
CBUAE cybersecurity framework explained for a small fintech or bank supplier: which regulations reach you, why the bank's questionnaire exists, and what to fix.
