The three financial centres have added each other to their respective data protection adequacy lists. This is a simplification, not a new obligation: personal data can move between them without standard contractual clauses. The recognition applies only among the three, and covers neither federal UAE territory nor the European Union.
What happened
On 29 January 2026 the Qatar Financial Centre (QFC), the Dubai International Financial Centre (DIFC) and the Abu Dhabi Global Market (ADGM) announced that they had added each other to their respective adequacy lists for personal data protection. Each of the three financial centres therefore recognises that the other two offer a level of protection equivalent to its own. The recognition follows a mutual assessment of the three regulatory frameworks and of their supervisory practice.
What changes in practice
This is a simplification, not a new compliance step. Before the recognition, moving personal data — client records, know-your-customer (KYC) documentation, employee files — from a DIFC entity to an ADGM or QFC entity required an additional transfer tool: standard contractual clauses or an equivalent mechanism, to be negotiated, signed and retained. Those data now move between the three centres without supplementary safeguards, as though they stayed within a single jurisdiction.
Who it applies to
Entities licensed in DIFC, ADGM or the QFC that share personal data with an affiliate, a parent company or a supplier established in one of the other two centres. The frequent case is a holding company in ADGM with the operating company in DIFC, or administration and accounting outsourced to a service provider based in a different centre from the client's own.
The exposure
The recognition holds between the three centres and only between them. It does not cover transfers to UAE federal territory outside the free zones, nor transfers to the European Union: a firm sending data to an EU-based company still operates under the General Data Protection Regulation (GDPR) and its transfer tools. The mistake to avoid is reading the opening as a general liberalisation and dismantling safeguards that are still required on other routes. It is also worth remembering that in the DIFC, since 15 July 2025, a data subject can bring a claim for compensation directly before the centre's courts without first going through the Commissioner: mishandled data can be challenged by the person affected, not only by the regulator.
What to do now
Map the personal data routes in your structure, recording the origin and destination of each. Where both ends sit among DIFC, ADGM and the QFC, any standard contractual clauses in place can be filed away — the signed versions must still be retained, because they cover the period before 29 January 2026. Where one end sits outside the three centres, the existing safeguards remain necessary and should not be touched.
Sources
- https://www.qfc.qa/en/media-centre/news/list/qfc-adgm-and-difc-enhance-cross-border-data-flow
- https://www.hoganlovells.com/en/publications/qfc-difc-and-adgm-advance-regional-data-protection-cooperation-through-mutual-adequacy-recognition
Published 20 August 2026 on the basis of public sources and official United Arab Emirates instruments. This is not legal or tax advice. Verify your position with a qualified professional before acting.
