ADGM Data Protection Regulations 2021
ADGM’s Data Protection Regulations 2021 are overseen by the Commissioner of Data Protection. A controller must notify a personal data breach to the Commissioner without undue delay and, where feasible, within 72 hours of becoming aware of it, unless it is unlikely to result in a risk to individuals. If notification is later than 72 hours, it must explain the delay.
We build the technical measures that make that possible: access control, encryption, logging and a fast way to establish what happened. Decisions about lawful basis, notices and whether a breach must be notified belong with your data protection lead or legal adviser.