Abu Dhabi boasts first-class infrastructure and unparalleled global connectivity, making it a premier international destination. Its exceptional qualities make it an ideal location to live, work, and conduct business.
A financial centre that provides transparency, efficiency, and integrity, through its progressive frameworks, future focused infrastructure, all within a familiar independent legal jurisdiction – ADGM is the perfect platform for success.
AccessRP is a next-generation digital platform transforming the real estate experience in ADGM. Designed to streamline interactions across the ecosystem, AccessRP brings together landlords, developers, and tenants in one seamless environment, providing real-time access to services, data, and insights.
Our community of business professionals, entrepreneurs, and investors can depend on ADGM to provide timely news and reliable insights.
At ADGM, we offer various support options, including contact details, FAQs, enquiry forms, and a whistleblowing form.
Privacy Policy (Last Updated on 29/09/2026)
Overview
This Privacy Policy applies to anyone whose Personal Data is provided to us or whose Personal Data we otherwise collect, except in relation to such ADGM platforms or apps where a separate privacy notice applies.
This Privacy Policy sets out how and why we collect, store, use and share your Personal Data. It also tells you about your privacy rights and how the law protects you. It tells you how you can contact us if you have any suggestions, questions or concerns about how we handle your Personal Data.
“We” or “us” means Abu Dhabi Global Market (ADGM) composed of three legally independent Authorities:
each an Authority and together the Authorities. Additionally, ADGM encompasses various support functions grouped under an informal umbrella of the “ADGM Authority”, the Board Executive Offices, and Assurance functions (collectively referred to as “ADGM”). More information about ADGM and its Authorities can be found on our website www.adgm.com .
The entity (ADGM or an Authority) that you deal with when providing your Personal Data will usually be the Controller in relation to the Processing of your Personal Data. It should be clear to you from your dealings with us which entity that is – if it is not, you can contact us for more information.
An Authority may sometimes Process Personal Data as a joint Controller, for example where it makes joint decisions about Processing Personal Data with other entities, or as a separate Controller, for example where we share Personal Data with other entities.
Certain terms used in this Privacy Policy are explained in the Glossary . To make it easier to read, we may still use or define terms that are defined in the Glossary in full in the body of this Privacy Policy as well.
The Data Protection Regulations 2021 (DP Regulations) apply to how we approach data privacy. In certain circumstances, other laws may apply to Personal Data we Process.
Contents
1. How we collect Personal Data
We collect Personal Data from individuals or their authorised representatives. There are several ways in which we collect this data, including through:
We may receive Personal Data from entities in connection with their registration or licensing in ADGM or by any Authority, including in relation to officers, directors and approved individuals. Entities may also share Personal Data with us in connection with visa and immigration services. We expect anyone who provides us with Personal Data to do so in compliance with all applicable laws including the DP Regulations.
In some circumstances we may collect Personal Data about individuals from other third parties in the course of:
Where we collect personal data about you from sources other than yourself, those sources may include: your employer or sponsoring entity; other ADGM registered or licensed entities; government agencies, regulatory bodies and law enforcement authorities (both within and outside the UAE); public registers and publicly accessible sources; individuals who make complaints or reports to us; parties to legal proceedings; and third-party service providers acting on your behalf or on behalf of your employer.
Where we collect your Personal Data from third parties, we do so on the legal bases set out in sections 3 and 4 of this Policy.
2. What personal Data we collect
The Personal Data we collect depends on how or why you are interacting with us, what services we are providing, or what supervisory or regulatory functions we are carrying out.
In many cases, it will be mandatory for you to provide Personal Data to us to enable us to provide services and/or to fulfil our statutory functions, such as to incorporate, maintain and dissolve a company, to supervise regulated financial activities, to receive claims at the Courts and/or to obtain immigration services. If you do not provide us with the requested Personal Data in these instances, we will not be able to provide you with the relevant services.
The types of personal information we may collect include:
Minors (i.e. individuals under the age of 18) should not provide us with their Personal Data – it should be provided via their parent or guardian. Where we receive Personal Data relating to a minor, we will assume it has been appropriately provided.
3. Ways we use your Personal Data
Some of the ways we may use your Personal Data are set out below.
General
Website Use
We may use Personal Data which you provide to us or we collect to maintain and improve our website services, as well as to develop new features to improve customer experience and support, authenticate users and send administrative messages. We may conduct data analysis, testing, and research and to monitor and analyse usage and activity trends .
Communications and Events
When you sign up with us to receive news or information relating to an event or updates to our website(s) (for example: alerts, media releases, discussion papers, publications, changes to our legal framework and SEO letters), we will collect and Process your Personal Data to use in providing that news or information service to you.
We also collect and Process the Personal Data of individuals acting in their capacity as representatives of their organisations during their professional engagement with us. We may do this via online surveys or submissions, emails, general enquiries via our website(s) or verbal communications with us. Where you have asked to receive news or information relating to an event from us, we will use the contact details you provide, such as your name and email address, for that purpose.
We will sometimes use the contact details of those with whom we have a relationship in their capacity as representatives of their organisation, to invite them to events or to provide them with information relevant to their relationship with us. We will also use the Personal Data you provide to us for the above purpose to ensure any of our information sessions and events are carried out in an appropriate and safe manner, and in accordance with agreed contracts and applicable law and regulations.
We regularly arrange and host events. Photography and videography may take place at these events and may be published on our website and social media channels. If you attend an event and do not wish to be photographed, please speak to a member of staff so that suitable arrangements can be made, as far as possible.
Payments
You may make payments to us via our website or other systems we make available, in which case we will Process certain Personal Data in connection with that payment. This may include your name, email address, billing address, partial card details, the transaction amount, date and reference number and information required for fraud prevention purposes. The transaction itself will be processed by an independent third-party payment services provider, who will collect your full payment details through a secure encrypted connection and process the payment. We will not have access to, nor be able to store, your full payment details. We will use this Personal Data primarily to verify your payment and provide any associated confirmations and receipts.
In certain circumstances, we may also collect bank account details directly from you or on your behalf where this is necessary to return funds to you, including where funds have been deposited pursuant to a court order (for example, for security for costs).
Recruitment
As part of any recruitment process, we will collect and Process the Personal Data of candidates at various stages. This includes personal details, family details, resume information and interview records.
Consultation
Various functions across ADGM and its Authorities are involved in strategic planning which covers several areas of activity, including agreement on strategic themes and the setting of regulatory priorities. This includes working with Abu Dhabi and federal government bodies as well as international public authorities. We also engage with international standard setting bodies, working groups and committees on changes in international standards and the need to regulate appropriately new business models and types of financial services activity.
In carrying out the above responsibilities, we regularly consult with bodies and individuals who are affected by or are interested in the legislation we administer, and receive information as a result. We may receive this information in the form of submissions in response to a consultation or discussion paper we have published or through less formal processes, such as meetings, telephone calls or written correspondence. We use this information for the purpose of reviewing and determining our policies. The information provided to us during consultation may include Personal Data, such as the contact details of the individual giving us the information or Personal Data relating to the conduct of their regulated activities. We may publish the results of our consultations (for example, in a feedback statement).
Sharing information with other agencies or authorities: International Data Processing
To achieve our various objectives, including as a global financial centre and a financial services regulator, we need to work with other regulatory agencies and official bodies and authorities within Abu Dhabi and the UAE, as well as with international regulators and organisations (Official Agencies and Authorities).
We have statutory authority and obligation to exercise various powers at the request of, and on behalf of, other governmental, regulatory and law enforcement agencies both inside and outside the ADGM and the UAE. We are a signatory to international cooperation agreements with several Official Agencies and Authorities. During our engagement with Official Agencies and Authorities, we may obtain confidential information, including Personal Data, on their behalf and share that information with them to assist with their official duties and functions. We may also receive confidential information, including Personal Data, from Official Agencies and Authorities to assist with our regulatory functions and duties. The information we obtain on behalf of Official Agencies and Authorities and share with them will depend upon the nature of the request they have made but may include Personal Data and Special Categories of Personal Data relating to the individual from whom we obtain the information or relating to other third parties. When considering whether to comply with a request made by an official agency or authority, we will assess whether there are legitimate reasons for the request and whether the authority making the request has the appropriate standards in place to deal with any confidential information, including Personal Data, we provide to it.
In addition, we maintain direct integrations with certain Abu Dhabi and UAE government entities which enable the ongoing and systematic sharing of Personal Data. These integrations facilitate the efficient discharge of our regulatory and public functions, as well as compliance with our statutory and legal obligations. The categories of Personal Data shared through these integrations, the purposes for which it is shared and the identity of the relevant government entities will depend on the nature of the integration and our regulatory or legal requirements but may include Personal Data and Special Categories of Personal Data relating to the individual from whom we obtain the information or relating to other third parties.
Complaints
We collect Personal Data for the purposes of receiving and assessing complaints made against us. We have in place procedures to receive, assess and seek to resolve any formal complaints made in respect of our actions or those of any of our employees in a regulatory matter. While we try to minimise the Personal Data that we collect and Process for this purpose, we are often required to collect a wide range of information to consider and investigate complaints we receive. That information will include Personal Data relating to the complainant and will often include Personal Data of third parties, such as other individuals involved in the matters giving rise to the complaint. Where you make a complaint to us regarding one of our employees, it may be necessary for the person handling the complaint to contact the employee in question. Although we do not explicitly ask for Special Categories of Personal Data in our complaints form, it is possible that such information may be included in the details of the complaint by the complainant.
The Registration Authority
Registration and Licensing
We collect and Process Personal Data relating to the incorporation, administration and dissolution of ADGM-registered companies and other legal persons, as well as applicants for, and holders of, commercial licences in ADGM. This includes Personal Data of individuals acting as directors, shareholders, secretaries, beneficial owners, partners and other officers associated with registered or licensed entities, as well as Personal Data of individuals identified in connection with incorporations, filings, licence applications, renewals, or transfers. The Personal Data collected typically includes names, contact details, nationality, date of birth, addresses, and may extend to Special Categories of Personal Data where relevant.
We Process this Personal Data for the purposes of assessing and determining applications and maintaining accurate records of registered and licensed persons. We are required to maintain a register of all ADGM legal persons, including limited companies and partnerships, in which certain information, such as details of past and present directors, shareholders and officers, is made available to the public in accordance with our statutory obligations.
Immigration Services
We provide immigration services, such as facilitating UAE residency visas for employees of ADGM registered legal entities, in addition to their spouses and dependents where applicable. To arrange these immigration services, we will collect and transfer your Personal Data outside ADGM to certain third parties, including but not limited to, Abu Dhabi Ministry of Interior, visa screening centres, Emirates Identity Authority and health insurance providers. We will not use the information that you provide in relation to these services for any other purpose without your consent.
Monitoring and Enforcement
The RA’s powers and functions include supervision and oversight of firms and legal persons whose activities are regulated by the RA. One of the reasons this is required is to monitor compliance with various legislation we administer. It is necessary for us to collect and Process Personal Data to exercise those powers and functions. This includes information relating to the employees, officers, directors, clients and customers of RA regulated entities to help us make informed judgements on whether they are operating properly and/or whether their customers or clients are experiencing harm. It sometimes includes Special Categories of Personal Data. We expect anyone who provides us with Personal Data about individuals to do so in accordance with applicable laws.
The RA is empowered to conduct investigations into suspected contraventions of the legislation it administers, and may exercise its powers to obtain information, conduct inspections, compulsorily obtain books and records, or require individuals to participate in interviews under oath or affirmation. Court proceedings may be initiated, or penalties or other sanctions may be imposed where we are satisfied that contraventions have occurred, which may involve communicating to the public the basis on which we have taken action and our reasons for doing so. We may also refer any conduct which could constitute a breach of criminal law to relevant local, federal or international authorities.
It is necessary for us to collect and use Personal Data for the above purposes to meet our statutory obligations. We are often required to collect and Process a wide range of information relevant to suspected contraventions from a wide variety of sources. We may, for example, collect information from individuals who report suspected misconduct, potential witnesses, the firms or individuals who are the subject of our investigations or from other governmental, regulatory or law enforcement agencies. This information will usually include Personal Data (including Special Categories of Personal Data) relating to the subject(s) of our investigation or other actions, or to other individuals, such as the directors, controllers, employees or customers of the subject(s) of our investigation, potential witnesses or the individuals who have made a complaint or raised concerns of misconduct.
For further information on our approach to enforcement, for the RA please refer to its Decision Procedures, Disqualification and Enforcement Manual here.
Real Property
We collect and Process Personal Data in connection with the registration of interests in real property situated within ADGM, including ownership interests. This includes Personal Data of individuals who are parties to property transactions, such as owners, lessors, lessees, mortgagors and mortgagees, as well as their authorised representatives and, where applicable, beneficial owners. Personal Data collected in this context typically includes names, contact details, identification document details, and information relating to the nature and terms of the relevant property interest. The RA maintains a register of real property interests in ADGM, and certain information may be accessible to the public, in accordance with relevant legislation.
We Process this Personal Data for the purposes of registering and maintaining accurate records of interests in ADGM real property, facilitating property transactions and related services through certain platforms, and exercising regulatory functions under the applicable legislation where relevant.
Permits
We collect and Process Personal Data relating to applicants for, and holders of, commercial permits in ADGM. This includes Personal Data of individuals identified in connection with permit applications or renewals. The Personal Data collected typically includes names, contact details, identification numbers, date of birth, and information relating to the nature and scope of the activities for which a permit is sought, which may include Special Categories of Personal Data depending on the type of permit being issued.
We Process this Personal Data for the purposes of assessing and determining permit applications and monitoring ongoing compliance with permit conditions under the applicable legislation.
The Financial Services Regulatory Authority
The FSRA mainly Processes Personal Data when carrying out its regulatory functions including authorisation, supervision, market oversight and enforcement. We have set out further information on when and why this happens below. For further information on our approach to authorisation and supervision, markets and enforcement see our Guidance and Policies manual here .
A. Authorisation and Supervision
The FSRA’s powers and functions under the legislation it administers include assessing and deciding upon applications to be authorised or approved to carry on certain financial and ancillary activities or functions in the ADGM.
Applicants include individuals seeking approval to carry out certain functions within an authorised firm, who are required to meet certain standards relating to their experience, knowledge and qualifications. That means it is necessary for us to collect and Process Personal Data (including some Special Categories of Personal Data) relating to those individuals.
The FSRA’s powers and functions also include supervision and oversight of firms whose activities are regulated by us ( Regulated Entities), the individuals we approve to undertake certain functions, and the markets we regulate. One of the reasons this is required is to monitor compliance with various legislation we administer, including legislation relating to international taxation compliance and anti-money laundering. It is necessary for us to collect and Process Personal Data to exercise those powers and functions. This includes information relating to the employees, officers, directors, clients and customers of Regulated Entities to help us make informed judgements on whether they are operating properly and/or whether their customers or other market participants are experiencing harm. It sometimes includes Special Categories of Personal Data. We expect anyone who provides us with Personal Data about individuals to do so in accordance with applicable laws.
B. Markets
Our powers and functions under the legislation we administer include licensing and supervising recognised bodies including certain kinds of exchange and clearing house. We also recognise those financial markets that operate an exchange or clearing house outside the ADGM without having a physical presence in the ADGM but that make their services available to persons in the ADGM. We also recognise trading and clearing members of a recognised body who operate in a jurisdiction other than the ADGM and do not have a physical presence in the ADGM. We oversee offers of securities in or from the ADGM and supervise reporting entities by monitoring their on-going market disclosures and compliance with relevant regulations and rules.
The FSRA’s powers and functions also involve market surveillance to monitor compliance with the legislation we administer and to detect irregularities, including disclosure of inside information, market abuse and other market related misconduct. To undertake our licensing, supervision and surveillance work, we are often required to collect a wide range of information and may request information to help us make informed judgements on whether persons operating under our oversight are conducting their activities in accordance with applicable legislation, whether investors or other market participants are experiencing harm, and the integrity of the markets we regulate. This information may include Personal Data (including Special Categories of Personal Data) relating to individuals, such as directors, controllers, employees, investors, shareholders and ultimate beneficial owners.
C. Enforcement
The primary function of the enforcement functions in the RA and FSRA is to prevent, detect and restrain conduct that causes or may cause damage to the reputation of the ADGM or the financial services industry in the ADGM.
The RA and FSRA are empowered to conduct investigations into suspected contraventions of the legislation they each administer, and may exercise their powers to obtain information, conduct inspections, compulsorily obtain books and records, or require individuals to participate in interviews under oath or affirmation. Court proceedings may be initiated, or penalties or other sanctions may be imposed where we are satisfied that contraventions have occurred, which may involve communicating to the public the basis on which we have taken action and our reasons for doing so. We may also refer any conduct which could constitute a breach of criminal law to relevant local, federal or international authorities.
It is necessary for us to collect and use Personal Data for the above purposes to meet our statutory obligations. We are often required to collect and Process a wide range of information relevant to suspected contraventions from a wide variety of sources. We may, for example, collect information from individuals who report suspected misconduct, potential witnesses, the firms or individuals who are the subject of our investigations or from other governmental, regulatory or law enforcement agencies. This information will usually include Personal Data (including Special Categories of Personal Data) relating to the subject(s) of our investigation or other actions, or to other individuals, such as the directors, controllers, employees or customers of the subject(s) of our investigation, potential witnesses or the individuals who have made a complaint or raised concerns of misconduct.
For further information on our approach to enforcement, for the RA please refer to its Decision Procedures, Disqualification and Enforcement Manual here and for the FSRA the Guidance and Policies manual here .
Confidentiality
Personal Data held by the FSRA will often be confidential information that the FSRA has received while carrying out its functions and activities as the regulator of financial services in the ADGM. The legal obligations in relation to FSRA’s use and disclosure of such confidential information can be found in Sections 198 and 199 of the Financial Services and Markets Regulations 2015. In certain circumstances, these obligations of confidentiality may mean the FSRA is unable to provide access to Personal Data it holds when requests are made under the DP Regulations 2021. This is consistent with the law.
The Financial Services Regulatory Authority Public Register
The FSRA Public Register is a public record of both firms and individuals that are, or have been, regulated by the FSRA. Most of the information on the FSRA Public Register is about the firm’s business, such as what it does and how it can be contacted, but some Personal Data about the firm’s employees and former employees who are or were required to be approved by us is also included (these are called Approved Persons).
The ADGM Courts
Personal Data Processed by the Courts
The Courts Process a broad range of Personal Data necessary for the administration of justice and other civil justice services. This may include the types of personal Data set out in section 2 of this Policy including highly sensitive information (i.e. Special Categories of Personal Data). The categories of Personal Data Processed by the Courts depend on the nature of the proceedings concerned and the nature of the services provided (i.e. in addition to Personal Data Processed in connection with the judicial services of the Courts, Personal Data may be Processed under the auspices of the Courts pro bono scheme, notary public services and Wills office or court-annexed mediation scheme).
Purpose of Processing and legal basis
Personal Data is Processed for the performance by the Courts of their judicial and related functions. Connected with this is the Personal Data that is Processed by the Courts Registry to facilitate the administration of justice and the efficient management and operation of the Courts. Personal Data may also be Processed for other purposes including statistical analysis and, where appropriate, direct promotion of court-related news, developments or events.
Sharing and publication of Personal Data
Open justice is an overarching feature of the Courts. Accordingly, court hearings, during which Personal Data may be disclosed, are (with limited exceptions) required to be held in public. Personal Data contained within a judgment or decision of the Courts, or a list or calendar of proceedings or hearings, is usually made accessible to the public by publication on the Courts website. Personal Data that is contained in court records can be made available to persons that are entitled or permitted to access those records (which may include non-parties and members of the press).
The ADGM Arbitration Centre
In its role as a hearing centre for arbitrations and mediations, the ADGM Dispute Resolution Hearing Centre (“DRHC”) will also Process Personal Data. Unlike court hearings, arbitration and mediation hearings are to be conducted in strict confidence. Accordingly, the DRHC will only disclose Personal Data provided to it in discrete circumstances with the consent of the parties and only for the purpose for which the parties’ consent has been provided; usually this occurs in the context of the DRHC facilitating an arbitration hearing (i.e. if the parties to an arbitration request transcription or other hearing-related services which require the involvement of a third party).
The DRHC also Processes Personal Data for other purposes including in relation to its arbitrators and mediators’ panels which are publicly accessible on the DRHC’s pages on ADGM’s website (any disclosure of Personal Data is only made with the consent of the persons concerned). The DRHC may also Process Personal Data for the direct promotion of arbitration or mediation related news, developments or events (but not hearings). An example of this is where an ‘email distribution list’ is used by the DRHC to promote an upcoming seminar, the release of a publication or some other arbitration or mediation related event.
4. Lawful basis for collection and Processing of Personal Data
We collect Personal Data only where it is relevant to and necessary for specified, explicit and legitimate purposes. Those purposes are either described above or will be explained to you at the time we request your Personal Data.
Generally, we Process Personal Data on one or more of the following grounds set out in Section 5 of the DP Regulations:
Where we rely on legitimate interests as our lawful basis for processing, those interests include: (i) screening and evaluating candidates for employment or engagement; (ii) maintaining the security of our networks, systems and premises; (iii) preventing and detecting fraud, money laundering and other financial crime; (iv) conducting internal audits and investigations; (v) administering and managing our relationships with regulated entities, service providers and other stakeholders; and (vi) promoting our services, events and publications to individuals with whom we have an existing relationship. We conduct a balancing assessment before relying on legitimate interests to ensure that our interests do not override the rights and interests of the individuals concerned
The legislation published and/or administered by ADGM and its Authorities can be found here: ADGM laws and regulations.
If we collect Personal Data while exercising one of our powers or functions (for example, receiving a report of suspected misconduct or when conducting an investigation) and that Personal Data is relevant to exercising one of our other powers or functions (for example, determining an application for authorisation), we will, in general, use that Personal Data for that other purpose.
We do not usually ask for any Special Categories of Personal Data from individuals, except in the following circumstances:
The DP Regulations identify certain Personal Data Processing which leads to a high risk to the rights and freedoms of individuals by virtue of the nature, scope, context and purposes of the Processing of their Personal Data and imposes specific requirements concerning such activities. We do not ordinarily undertake any of the high-risk Processing activities as described in the DP Regulations.
Unless we explicitly tell you on a case by case basis, we do not engage in decision making which produces legal or similarly significant effects based solely on automated Personal Data Processing.
5. Sharing Personal Data
We may share Personal Data internally within the ADGM, including between the different Authorities.
We may share Personal Data with third parties in the following circumstances: :
We may also disclose your Personal Data to the public where it is necessary to do so in the exercise of our regulatory powers or functions. That may include circumstances:
We may share your Personal Data with any other person if we notify you and obtain your consent to the disclosure.
Your Personal Data may be processed by us and those other parties described above, outside of the ADGM. Where the ADGM Commissioner of Data Protection has not issued an adequacy decision in relation to the jurisdiction where your Personal Data is processed, we will ensure that there are adequate mechanisms in place to protect your Personal Data in accordance with applicable data protection and privacy law. We will usually do this through use of data transfer agreements implementing standard data protection clauses.
6. Where we store your Personal Data
The Personal Data that we collect from you may be securely transferred to and securely stored on our databases, located on our secure servers both in ADGM and in backup locations in the United Arab Emirates or abroad.
7. Data Security
We store Personal Data in electronic, digital and paper format. We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only Process your Personal Data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected or actual Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so. Where a direct communication to you will involve disproportionate effort, we may instead inform you via a public communication or other similar measures that are equally effective.
Unfortunately, no data transmission over the internet can be guaranteed to be 100% secure. Therefore, we cannot guarantee the security of any Personal Data you transmit to us over the internet, and you do so at your own risk.
If at any point you suspect or become aware of a security incident (e.g. you receive a suspicious communication from someone holding themselves out to be our employee or from an unauthorised website claiming to be affiliated with us), please forward the communication to us or report the incident by email to dpo@adgm.com or in writing to the ADGM at PO Box 111999 Abu Dhabi, UAE, as soon as possible.
8. Data retention
We Process Personal Data for such periods as is necessary to fulfil our statutory functions and for the purposes set out in this Policy, unless a longer period for the retention of Personal Data is required by law.
We may retain your Personal Data for a longer period in the event of a complaint or if we reasonably believe there is a prospect of litigation in respect to our relationship with you.
The RA and FSRA retain all records of companies for as long as the company is registered. Records of dissolved companies are currently retained for the duration of time that the relevant information is required for legal and statutory purposes, including Personal Data related to company directors and officers.
Personal Data Processed based on consent will be retained for the period specified in the consent, or where not specified, until you withdraw your consent.
9. Cookies & Third-Party Websites
Our website uses cookies. A cookie is a small piece of data that a website stores on a visitor’s browser, computer or mobile device. Details of the cookies used on our website are set out in the ADGM Cookies Policy.
Our website may from time to time contain links to and from other websites. This includes websites owned or controlled by independent parties not controlled or authorised by ADGM. If you follow a link to any of these websites, please note that these websites have their own privacy policy, data collection practices and security measures and we do not accept any responsibility or liability for these policies. Please ensure you check these policies before submitting any Personal Data. If you decide to access linked third-party websites, you do so at your own risk.
The ADGM website is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service will apply to that service.
10. Your rights
Under the DP Regulations, you have the following rights as an individual which you can exercise in relation to the Personal Data we hold about you.
|
Right |
What does this mean? |
|
The right to object to processing |
You have the right to object to certain types of processing, including processing for direct marketing (i.e. if you no longer want to be contacted with potential opportunities) or processing on the basis of our legitimate interests. |
|
The right to be informed |
You have the right to be provided with clear, transparent and easily understandable information about how we use your information and your rights. This is why we’re providing you with the information in this Policy. |
|
The right of access |
You have the right to obtain access to your information (if we’re processing it). This is so you’re aware and can check that we’re using your information in accordance with applicable law. |
|
The right to rectification |
You are entitled to have your information corrected if it’s inaccurate or incomplete. |
|
The right to erasure |
This is also known as ‘the right to be forgotten’ and, in simple terms, enables you to request the deletion or removal of your information where there’s no compelling reason for us to keep using it. |
|
The right to restrict processing |
You have rights to ‘block’ or suppress further use of your information. When processing is restricted, we can still store your information, but may not use it further. We keep lists of people who have asked for no further use of their information to be ‘blocked’ to make sure the restriction is respected in future. |
|
The right to data portability |
You have rights to obtain and reuse your Personal Data for your own purposes across different services. For example, if you decide to switch to a new provider, this enables you to move, copy or transfer your information easily between our IT systems and theirs safely and securely, without affecting its usability. |
|
The right to lodge a complaint |
You have the right to lodge a complaint about the way we handle or Process your Personal Data with the ADGM Commissioner of Data Protection. |
|
Rights in relation to automated decision making |
You have the right not to be subject to a decision based solely on automated Processing, including Profiling, which produces legal effects concerning you or similarly significantly affects you. We do not ordinarily make decisions based solely on automated Processing. |
|
The right to withdraw consent |
If you have given your consent to anything we do with your Personal Data, you have the right to withdraw your consent at any time (although if you do so, it does not mean that anything we have done with your Personal Data with your consent up to that point is unlawful). This includes your right to withdraw consent to us using your Personal Data for marketing purposes. |
Please note that the rights listed above are not absolute rights. Some of the rights only apply in certain circumstances (for example, where we rely on a particular lawful basis for processing your Personal Data) and we have certain rights to refuse your requests.
If you wish to exercise any of the rights set out above, please contact dpo@adgm.com
Note: your right of access can be exercised in accordance with DP Regulations and other applicable laws. There are circumstances where we may not be able to comply with your request, such as where we have a legal duty to retain Personal Data, or where access to Personal Data would prejudice the proper function of ADGM’s statutory duties. In addition, certain Authorities are required to adhere to certain legal requirements of confidentiality.
11. Our Data Protection Officer and how you can contact us
We have appointed a Data Protection Officer (DPO) who oversees data privacy and data protection compliance across ADGM and each of the Authorities and informs and advises us on our data protection obligations. The DPO acts as our contact point with the ADGM Office of Data Protection.
If you have any questions or requests or wish to make a complaint, you can let us know by email to dpo@adgm.com or in writing to The Data Protection Officer, Abu Dhabi Global Market, PO Box 111999, Abu Dhabi, UAE.
If you want to file a complaint with or contact the data protection authority in ADGM, i.e., the ADGM Office of Data Protection, you may do so by email to data.protection@adgm.com
12. Changes to our Privacy Policy
We may amend this Policy from time to time to meet changes in the regulatory environment, business needs, or to satisfy the needs of our customers and service providers. Any changes we make to this Policy will be posted on our website and date stamped so that you are always aware of the latest update. You should check this page from time to time to ensure you are happy with any changes.
13. Glossary
This glossary sets out various terms we use in the Policy and what they mean. It doesn’t matter if we use them capitalised or not.
|
ADGM |
Means Abu Dhabi Global Market. See Overview |
|
Authority |
Means any of the four authorities that sit within ADGM being: a) the Registration Authority; b) the Financial Services Regulatory Authority; c) the ADGM Courts; and d) the ADGM Authority, each an Authority and together the Authorities. See Overview |
|
Controller |
Is defined in the DP Regulations. At the date of and in the context of this Privacy Policy, it means the entity which, alone or jointly with others, determines the purposes and means of the Processing of Personal Data. |
|
Courts |
Means the ADGM Courts. |
|
Data Subject |
Is defined in the DP Regulations. At the date of this Privacy Policy, it means an identified or identifiable living natural person. |
|
DP Regulations |
Means the ADGMs Data Protection Regulations 2021, as amended from time to time. You can find these here |
|
FSRA |
Means the Financial Services Regulatory Authority. |
|
Personal Data |
Is defined in the DP Regulations. At the date of this Privacy Policy, it means any information relating to a Data Subject. |
|
Profiling |
Is defined in the DP Regulations. At the date of this Privacy Policy, it means any form of automated Processing of Personal Data consisting of the use of Personal Data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person's performance at work, economic situation, health, personal preferences, interests, reliability, behaviour, location or movements. |
|
Process or Processing |
Is defined in the DP Regulations. At the date of this Privacy Policy, it broadly means any operation or set of operations which is performed on Personal Data or on sets of Personal Data, such as collection, recording, storage, use, disclosure or destruction. |
|
RA |
Means the Registration Authority. |
|
Special Categories of Personal Data |
Is defined in the DP Regulations. At the date of this Privacy Policy, it means (a) Personal Data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs; (b) Genetic Data, Biometric Data for the purpose of uniquely identifying a natural person, Data Concerning Health or data concerning a natural person's sex life or sexual orientation; and (c) Personal Data relating to criminal convictions and offences or related security measures. |
|
“We” or “us” |
Means ADGM and/or (depending on the context) each of the Authorities. |
We use cookies and similar technologies that are necessary to operate the website. Additional cookies are used to perform analysis of website usage. By continuing to use our website, you consent to our use of cookies. For more information, please read our Cookies Policy.