Comparison tableUpdated June 2026

DIFC Regulation 10 vs PDPL vs ADGM DPR: UAE AI Governance Comparison Table

DimensionPDPLDIFC Regulation 10ADGM DPR
Effective dateFull compliance Jan 2027In force Jan 2026In force 2021
Who it coversAll organisations processing UAE residents' personal dataDIFC-licensed entities using autonomous systems to process personal dataADGM-registered entities processing personal data
Legitimate interest basisNoNoYes (GDPR-aligned)
Dedicated AI ruleNo dedicated AI provisionYes — Regulation 10 specifically governs autonomous systemsAutomated decision provisions only
Pre-deployment risk assessmentNo specific mandateYes — required for all High and Medium risk autonomous systemsImplied by DPIA requirements
Explainability requiredImpliedExplicit — for all consequential decisionsExplicit
FinesUp to AED 5 millionUSD 25,000–50,000 per violationUp to USD 28 million
Private right of actionNoYes — data subjects can sue directlyYes
Data residencyYes for certain sensitive categoriesFree zone boundary controlsFree zone boundary controls
Cross-border transfersAdequacy or appropriate safeguards requiredAdequacy assessment required for transfers outside DIFCSCCs or adequacy list (tracks EU list)

Firms operating in multiple jurisdictions — such as a DIFC-licensed entity with mainland UAE clients — may be subject to two or more of these frameworks simultaneously. A single AI system with a data breach could trigger penalties under DIFC, PDPL, and ADGM concurrently. This table is current as of June 2026 and does not constitute legal advice.

© 2026 Magpie. Product of Steinn Labs.Based in Dubai, UAE