ADGM Data Protection and AI: What Applies to Your AI Systems in Abu Dhabi Global Market

ADGM has no standalone AI regulation, but its Data Protection Regulations 2021 already cover the core of AI use: profiling, automated decisions, impact assessments and controller registration.

9+ Years of Compliance Expertise
Saudi Arabia
Oman
Bahrain
End-to-End Execution
Europe
ADGM regulates AI through its Data Protection Regulations 2021, enforced by the ADGM Office of Data Protection. Unlike the DIFC, which has a dedicated regulation for autonomous systems, ADGM has no AI-specific equivalent: AI systems are covered by the general data protection rules. Every ADGM-registered entity that processes personal data must register as a Data Controller. The rules most relevant to AI are those on automated individual decision-making, including profiling, and on Data Protection Impact Assessments (DPIAs). Processing counts as high-risk if it involves, among other criteria, a systematic and extensive evaluation of individuals based on automated processing, or the adoption of new technologies that materially increase risk. High-risk processing requires a DPIA before it begins.
Why This Matters

Many AI use cases meet the regulations' definition of high-risk processing: profiling-based evaluation, new technologies and special category data.

A DPIA must be completed before high-risk processing starts, and if it shows a high risk, the regulator must be notified.
The absence of an AI-specific rule does not mean the absence of obligations. The general rules already apply to AI-driven processing.
The Office of Data Protection publishes notices and directions on contraventions, so enforcement is visible.
Firms authorised by the FSRA face additional governance and operational resilience expectations on top of data protection rules.
What's Included

Check of Data Controller registration status and record of processing activities (ROPA)

Inventory of AI systems processing personal data in ADGM
DPIAs for AI-driven processing, including analysis of whether the regulator must be notified
Procedures and notices for automated decisions and profiling
Data subject rights process, including objections to automated decisions
Review of vendor and processor agreements and cross-border transfers
Data Protection Officer advisory where processing is high-risk

Frequently Asked Questions

Related

Not sure whether your AI systems count as high-risk in ADGM?
By submitting this form, I acknowledge that I have read and agree to the Privacy Policy, and I consent to the processing of my personal data.


Please note: We do not provide any personalized investment advice, token selection guidance, or transaction recommendations. AMLzone is a compliance consultancy and project management services provider, not a Virtual Asset Advisor.