| DIFC (DFSA) | ADGM (FSRA) | |
|---|---|---|
| Regulator | Dubai Financial Services Authority (DFSA) | Financial Services Regulatory Authority (FSRA) |
| Cyber rules | GEN 5.5 Cyber risk management | GEN 3.5 Cyber risk management, in force since 31 January 2026 |
| Material incident notice to the regulator | As soon as reasonably practicable, within 72 hours at the latest | Immediately, within 24 hours at the latest |
| Outsourcing and IT providers | GEN 5.3.21 outsourcing, plus GEN 5.5 expectations for ICT providers | Explicit rules on due diligence, contract terms and oversight of ICT providers |
| Data protection law | DIFC Data Protection Law No. 5 of 2020 | ADGM Data Protection Regulations 2021 |
| Personal data breach notice | To the Commissioner as soon as practicable | To the Commissioner without undue delay and, where feasible, within 72 hours |
Summary for orientation, checked against the regulators’ published text on 19 September 2026. Confirm the current wording in the Rulebooks. This is not legal advice.
