Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

Which UAE, DIFC or ADGM regime applies to a breach?

Updated

Three UAE regimes. Federal PDPL Art. 9: immediately / as set by Executive Regulations (72h is not in the Decree-Law). DIFC Arts 41–42: as soon as practicable. ADGM Art. 32: without undue delay / 72h where feasible. Not legal advice; does not start a clock.

UAE / Dubai jurisdiction guide, last verified 8 September 2026 against an unofficial English translation of Federal Decree-Law No. 45 of 2021 (PDPL) Article 9, DIFC Data Protection Law No. 5 of 2020 Articles 41–42, ADGM Data Protection Regulations 2021 Article 32 as restated on the ADGM Office data-breach-notifications page, and DIFC Commissioner Security Breach Guidance. Article 28 of the Decree-Law required Executive Regulations within six months of promulgation. As of 8 September 2026 this page has not verified those Executive Regulations as a published discrete gazette instrument; 72 hours is not a Federal PDPL statutory deadline in the Decree-Law this page fetched. Guidance is not the Law. It is not legal advice, not a filing, not a determination that any of the three regimes applies, and not a substitute for counsel.

This is three regimes, not YOUR determination

Audience: a compliance lead, privacy officer, CISO, or counsel at a controller or processor established onshore in the UAE, in the DIFC, in ADGM, or with processing that may sit under more than one of those. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that Federal PDPL, DIFC Law No. 5 of 2020, or ADGM Data Protection Regulations 2021 applies, that you are a Controller, or that you must file.

The UAE has three personal-data breach regimes this page discusses. They are not interchangeable. Filing one does not discharge the others. Do not paste GDPR Article 33(1) 72 hours onto all three. Last verified 8 September 2026. Not legal advice.

  • Statute versus guidance: Federal Decree-Law No. 45 of 2021 Article 9 is a legal requirement only if the PDPL applies. DIFC Articles 41–42 are a legal requirement only if the DIFC DP Law applies. ADGM Article 32 is a legal requirement only if the ADGM DPR apply. DIFC Commissioner Security Breach Guidance and ADGM Office pages are guidance or Office materials, not the Law. This page quotes which kind of text it is relying on.
  • Executive Regulations status, above the fold: Article 28 required Executive Regulations within six months of promulgation (issued 20 September 2021; in force 2 January 2022). As of last-verified 8 September 2026, treat those Executive Regulations as not verified as a published discrete gazette instrument. Do not write 72 hours as a Federal PDPL statutory deadline. The Decree-Law says immediately / as set by the Executive Regulations.
  • The reporting-deadlines page on this site is the statute table of clocks. The who-to-notify page on this site is the recipient-class map. The which-jurisdictions-apply page on this site is the applicability map. The supporting-evidence page on this site is the evidentiary record.
  • The signed-in CRA ladder tracks recorded awareness for findings the organisation classified as CRA-in-scope. That tracker is not PDPL Article 9, not DIFC Article 41, and not ADGM Article 32. A named human still files.

Which regulator — onshore, DIFC, or ADGM

Where the controller is established, and what processing is in play, are inputs to which regime this page discusses. This table is a decision aid, not a determination. An incident can sit under more than one regime if the facts connect more than one establishment. This page does not choose. Last verified 8 September 2026. Not legal advice.

Which-regulator decision aid (not a determination; not legal advice; onshore vs DIFC vs ADGM; filing one does not discharge the others; this page does not choose)
Where is the controller established / what processing?Which regime this page discussesWhat this page does not do
Onshore / mainland UAE, or most other UAE zones other than DIFC and ADGMFederal PDPL (Decree-Law No. 45 of 2021) / UAE Data Office (Office established by Decree-Law No. 44 of 2021)Does not decide that the PDPL applies to YOU. Does not start Article 9. Does not file with the Office.
DIFC-registered entityDIFC Data Protection Law No. 5 of 2020 / DIFC Commissioner of Data ProtectionDoes not decide that YOU are established in the DIFC. Does not start Article 41. Does not file with the Commissioner.
ADGM-registered entityADGM Data Protection Regulations 2021 / ADGM Office of Data Protection (Commissioner)Does not decide that YOU are established in ADGM. Does not start Article 32. Does not file with the ADGM Office.
Facts connect more than one establishment, or processing that more than one regime may reachMore than one of the three. Filing one does not discharge the others.This page does not choose which regime applies. Mapping more than one row is not a filing pack.

Onshore vs DIFC vs ADGM — clocks quoted, not converted

Quote the text. Do not paste GDPR 72 hours onto Federal PDPL or DIFC. ADGM Article 32 is the one of the three that uses a 72-hour mark, and even there the Regulations say without undue delay and, where feasible, not later than 72 hours. Last verified 8 September 2026. Not legal advice.

Three-regime comparison (not a determination; not legal advice; onshore vs DIFC vs ADGM; filing one does not discharge the others)
RegimeStatuteClock (quote the text)RecipientIn force as of 8 Sep 2026Kind of text
Federal PDPL Art. 9Federal Decree-Law No. 45 of 2021 (unofficial English translation this page fetched)Controller shall, immediately upon becoming aware of any infringement or breach of the Personal Data of the Data Subject that would prejudice the privacy, confidentiality and security of such data, report such infringement or breach and the results of the investigation to the Office within such period and in accordance with such procedures and conditions as set by the Executive Regulations of this Decree-Law.The Office (UAE Data Office / UAE Data Bureau, established under Federal Decree-Law No. 44 of 2021)Decree-Law issued 20 September 2021; in force 2 January 2022. Executive Regulations specifying the period: not verified as a published discrete gazette instrument as of 8 September 2026.Legal requirement — Art. 9, only if the PDPL applies. Unofficial English. Arabic official text prevails. 72 hours is not in the Decree-Law this page fetched.
DIFC Arts 41–42DIFC Data Protection Law No. 5 of 2020, Part 7 Personal Data BreachesArt. 41(1): If there is a Personal Data Breach that compromises a Data Subject's confidentiality, security or privacy, the Controller involved shall, as soon as practicable in the circumstances, notify the Personal Data Breach to the Commissioner. Art. 42(1): When a Personal Data Breach is likely to result in a high risk to the security or rights of a Data Subject, the Controller shall communicate the Personal Data Breach to an affected Data Subject as soon as practicable in the circumstances.DIFC Commissioner of Data Protection (Art. 41). Affected Data Subject (Art. 42, high-risk limb).Law No. 5 of 2020 is current law this page fetched (enacted 21 May 2020; commenced 1 June 2020). This page did not treat Amendment Law No. 1 of 2025 as a rewrite of Articles 41–42.Legal requirement — Arts 41–42, only if the DIFC DP Law applies. Do not write DIFC as 72 hours.
ADGM Art. 32ADGM Data Protection Regulations 2021ADGM Office data-breach-notifications page (Office materials restating Article 32): Data Controllers must notify the Office of Data Protection of personal data breaches without undue delay and, where feasible, not later than 72 hours after becoming aware of them. Thomson Reuters ADGM rulebook text of Article 32(1) this page fetched: the Controller must without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the Personal Data Breach to the Commissioner of Data Protection, unless the Personal Data Breach is unlikely to result in a risk to the rights of natural persons. Where the notification is not made within 72 hours, it must be accompanied by reasons for the delay.ADGM Office of Data Protection / Commissioner of Data Protection. Report via Online Registry Solution (Office materials on how to report, not a rewrite of Article 32).Regulations 2021 are current law this page fetched (enacted 11 February 2021).Legal requirement — Art. 32, only if ADGM DPR apply. The Office page is ADGM Office materials that restates Article 32; this page labels it.
GDPR Art. 33(1) 72 hoursRegulation (EU) 2016/679Without undue delay and, where feasible, not later than 72 hours after having become aware. That clock is GDPR. It is not Federal PDPL Article 9, not DIFC Article 41, and not a substitute for ADGM Article 32.Competent supervisory authority under GDPRIn force. A different instrument.Legal requirement only if GDPR applies. Filing GDPR does not discharge Federal PDPL, DIFC, or ADGM. The GDPR breach-notification guide on this site is Articles 33–34.

Federal PDPL Article 9 — immediately / as set by Executive Regulations

This page quotes an unofficial English translation of Federal Decree-Law No. 45 of 2021 (Lexis Middle East / privacyarabia PDF fetched 8 September 2026). The official Arabic text on the UAE Legislation portal prevails. This page did not independently fetch a complete official English instrument from uaelegislation.gov.ae this session. Article 9 is a legal requirement only if the PDPL applies. This page does not decide that it does. Last verified 8 September 2026. Not legal advice.

  • Legal requirement — Art. 9(1) (unofficial English): the Controller shall, immediately upon becoming aware of any infringement or breach of the Personal Data of the Data Subject that would prejudice the privacy, confidentiality and security of such data, report such infringement or breach and the results of the investigation to the Office within such period and in accordance with such procedures and conditions as set by the Executive Regulations of this Decree-Law.
  • Legal requirement — Art. 9(1) report contents named in the unofficial English: (a) nature, form, causes, approximate number and records of the infringement or breach; (b) data of the Data Protection Officer appointed thereby; (c) potential and expected effects; (d) procedures and measures taken and proposed to address the infringement or breach and reduce its negative effects; (e) documentation of the infringement or breach and the corrective actions taken; (f) any other requirements by the Office.
  • Legal requirement — Art. 9(2) (unofficial English): the Controller must notify the Data Subject if the infringement or breach would prejudice the privacy, confidentiality and security of his/her Personal Data, and advise him/her of the procedures taken, within such period and in accordance with such procedures and conditions as set by the Executive Regulations.
  • Legal requirement — Art. 9(3) (unofficial English): the Processor shall, immediately upon becoming aware, notify the Controller of such infringement or breach in order for the Controller, in turn, to report it to the Office.
  • Legal requirement — Art. 2(2) (unofficial English) carves out, among other limbs, companies and institutions located in zones of the State that are subject to special legislation on Personal Data Protection. DIFC Law No. 5 of 2020 and ADGM Data Protection Regulations 2021 are the two this page discusses. Mapping the carve-out is not a finding that YOU sit in it.
  • Legal requirement — Art. 26 (unofficial English): the Cabinet shall, based on the proposal of the Office General Manager, issue a decision specifying the acts that constitute a violation and the administrative penalties to be imposed. This page invents no typical Data Office fine and no typical incident-cost figure.

Executive Regulations status — 72 hours is not in the Decree-Law

Accuracy trap. Article 28 (unofficial English): the Cabinet shall issue the Executive Regulations of this Decree-Law within six (6) months from the date of its promulgation. The Decree-Law was issued 20 September 2021. As of last-verified 8 September 2026, this page has not verified Executive Regulations as a published discrete gazette instrument from the UAE Legislation portal or Official Gazette. Do not write 72 hours as a Federal PDPL statutory deadline. Last verified 8 September 2026. Not legal advice.

Executive Regulations status actually fetched (not a complete gazette search; not legal advice)
ClaimStatus as fetchedKind of textLast verified
Decree-Law 45/2021 in forceIssued 20 September 2021; Official Gazette No. 712 (annex) 26 September 2021; in force 2 January 2022 (Art. 31). UAE Legislation portal entry last update reported as 20 September 2021.Legal requirement — the Decree-Law, only if it applies. Portal last-update is a portal fact, not a rewrite of Article 9.8 September 2026
Article 28 six-month markThe Cabinet shall issue Executive Regulations within six months of promulgation. That duty is in the Decree-Law. It is not itself a published set of Executive Regulations.Legal requirement — Art. 28. Not a finding that the Regulations exist.8 September 2026
Published discrete gazette instrumentNot verified as of 8 September 2026. This page did not fetch a Cabinet Decision number for PDPL Executive Regulations against the Official Gazette or a related-legislation list on the UAE Legislation portal entry for Decree-Law 45/2021.Absence of a fetch is not a gazette search of every instrument. Gazette/statute wins over consultancies.8 September 2026
72-hour Federal PDPL clockNot in the Decree-Law this page fetched. Article 9 says immediately upon becoming aware / within such period as set by the Executive Regulations. If a consultancy, a Data Office page, or secondary commentary claims 72 hours for Federal PDPL, that is that office's materials or secondary commentary, not the Decree-Law.Not a statutory deadline in the Decree-Law. Do not paste GDPR 72 hours onto Article 9.8 September 2026
UAE Data Office operational statusOffice established by Federal Decree-Law No. 44 of 2021. Operational status last-verified as not independently confirmed on an official page this page fetched. JD Supra (last updated 13 July 2026) notes the Data Office is not fully operational to date — that sentence is secondary commentary, not a .gov.ae page.Secondary commentary, not an official operational finding. This page does not invent a filing portal.8 September 2026

DIFC Articles 41–42 — as soon as practicable, not 72 hours

DIFC Data Protection Law No. 5 of 2020 Part 7 is current law this page fetched. Some blogs wrongly say DIFC is 72 hours. The Law is as soon as practicable in the circumstances. Last verified 8 September 2026. Not legal advice.

  • Legal requirement — Art. 41(1): If there is a Personal Data Breach that compromises a Data Subject's confidentiality, security or privacy, the Controller involved shall, as soon as practicable in the circumstances, notify the Personal Data Breach to the Commissioner.
  • Legal requirement — Art. 41(2): the Processor shall notify a relevant Controller without undue delay after becoming aware.
  • Legal requirement — Art. 41(4): the notification shall at least describe the nature of the Personal Data Breach including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate amount of Personal Data records concerned; communicate the name and contact details of the Data Protection Officer or other contact point; describe the likely consequences; and describe the measures taken or proposed to be taken, including where appropriate measures to mitigate possible adverse effects.
  • Legal requirement — Art. 41(5): where it is not possible to provide the information at the same time, the information may be provided in phases when available.
  • Legal requirement — Art. 41(6): a Controller shall document in writing any Personal Data Breaches, comprising the facts relating to the Personal Data Breach, its effects and the remedial action taken. The information recorded shall be sufficient to enable the Commissioner to verify compliance with this Article and shall be made available without delay on request.
  • Legal requirement — Art. 42(1): When a Personal Data Breach is likely to result in a high risk to the security or rights of a Data Subject, the Controller shall communicate the Personal Data Breach to an affected Data Subject as soon as practicable in the circumstances. If there is an immediate risk of damage to the Data Subject, the Controller shall promptly communicate with the affected Data Subject.
  • DIFC Commissioner Security Breach Guidance restates 'as soon as practicable' per Arts 41(1) and 42(1) and contrasts GDPR's 72 hours. Guidance is not the Law. Schedule 1 of the DP Law: guidance issued under the DPL is indicative and non-binding.
  • How to report (Commissioner materials, not the Law): phone +971 4 362 2222; email commissioner@dp.difc.ae. A named human still files. This product does not.

ADGM Article 32 — without undue delay / 72 hours where feasible

ADGM Data Protection Regulations 2021 Article 32 is current law. This page quotes the ADGM Office data-breach-notifications page as Office materials that restates Article 32, and the Thomson Reuters ADGM rulebook text of Article 32 this page fetched. Last verified 8 September 2026. Not legal advice.

  • ADGM Office materials restating Article 32: Data Controllers must notify the Office of Data Protection of personal data breaches without undue delay and, where feasible, not later than 72 hours after becoming aware of them. Report via Online Registry Solution. You must have authority over the entity on the system in order to report the breach — that 'you must have authority' sentence is Office materials about the portal, not a rewrite of Article 32, and it is not an instruction from this product.
  • Legal requirement — Article 32(1) (rulebook text this page fetched): in the case of a Personal Data Breach, the Controller must without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the Personal Data Breach to the Commissioner of Data Protection, unless the Personal Data Breach is unlikely to result in a risk to the rights of natural persons. Where the notification to the Commissioner of Data Protection is not made within 72 hours, it must be accompanied by reasons for the delay.
  • Legal requirement — Article 32(2): the Processor must notify the Controller without undue delay after becoming aware of a Personal Data Breach.
  • Legal requirement — Article 32(3): the notification must describe the nature of the Personal Data Breach, including where possible the categories and approximate number of Data Subjects concerned and the categories and approximate number of Personal Data records concerned; communicate the name and contact details of the Data Protection Officer or other contact point; describe the likely consequences; and describe the measures taken or proposed to be taken, including where appropriate measures to mitigate possible adverse effects.
  • Legal requirement — Article 32(4): where it is not possible to provide that information at the same time, the information may be provided in phases without undue further delay.
  • Legal requirement — Article 32(5): the Controller must document any Personal Data Breaches, comprising the facts, effects and remedial action taken, sufficient for the Commissioner to verify compliance.
  • Legal requirement — Article 33(1) (rulebook text this page fetched): when the Personal Data Breach is likely to result in a high risk to the rights of natural persons, the Controller must communicate the Personal Data Breach to the Data Subject without undue delay.
  • ADGM guidance Part 5: notify the Commissioner unless the breach is unlikely to result in a risk to the rights of individuals. Timeframe: without undue delay, and within 72 hours of discovering the breach where feasible. If not able to report within 72 hours, explain why. Initial notification then further information as available. That restatement is ADGM guidance, not a substitute for Article 32.
  • Fines: ADGM guidance Part 1 states the Commissioner has the power to issue fines of up to $28 million for breaches of the DPR 2021. That is a maximum in guidance, not a typical fine, not YOUR penalty, and not a typical incident-cost figure. Penalty notices exist (for example Okadoc, 21 May 2024). This page does not invent typical ADGM fines.

Filing one does not discharge the others — including GDPR 72 hours

Federal PDPL Article 9 is not DIFC Article 41. DIFC Article 41 is not ADGM Article 32. GDPR Article 33 is none of them. Filing one does not discharge the others. That is a strategy note, not a determination that any named instrument applies to YOU. Last verified 8 September 2026. Not legal advice.

  • GDPR Article 33(1) 72 hours from having become aware does not discharge Federal PDPL Article 9, DIFC Articles 41–42, or ADGM Article 32. The GDPR breach-notification guide on this site is Articles 33–34.
  • A DIFC Article 41 notice to the Commissioner does not discharge ADGM Article 32 or Federal PDPL Article 9. DIFC 'as soon as practicable in the circumstances' is not ADGM 'without undue delay and, where feasible, not later than 72 hours'.
  • An ADGM Article 32 notice does not discharge DIFC Articles 41–42 or Federal PDPL Article 9.
  • HIPAA 60 calendar days from discovery, SEC Form 8-K Item 1.05, PIPEDA s. 10.1 'as soon as feasible', and Australia Part IIIC 'as soon as practicable' also do not discharge these three. The HIPAA, SEC, Canada PIPEDA, and Australia NDB jurisdiction guides on this site.
  • This page is not an Information Assurance (UAE IA) guide and not an ADHICS guide. Those are different instruments.

Checklist

This is a question list, not a filing, not a regime finding, and not YOUR notification. Walk it with counsel. The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table. The supporting-evidence page on this site is the evidentiary record.

  • Is the controller established onshore / mainland UAE, in the DIFC, in ADGM, or in more than one? This page does not decide. The obligation-map keys `uae_pdpl`, `difc_dp`, and `adgm_dpr` in-scope marks are not that determination.
  • If Federal PDPL may apply: Art. 9 is immediately upon becoming aware / as set by Executive Regulations, where the infringement or breach would prejudice privacy, confidentiality and security. 72 hours is not in the Decree-Law. This page does not start that clock.
  • If DIFC may apply: Art. 41 is as soon as practicable in the circumstances where the breach compromises confidentiality, security or privacy. Art. 42 is a separate high-risk Data Subject limb. This page does not convert 'as soon as practicable' into 72 hours.
  • If ADGM may apply: Art. 32 is without undue delay and, where feasible, not later than 72 hours after becoming aware, unless unlikely to result in a risk to the rights of natural persons. If not within 72 hours, reasons for the delay. This page does not start that clock.
  • Do overlapping instruments also sit on the facts — GDPR Articles 33–34, HIPAA Subpart D, Form 8-K Item 1.05, a US-state statute? Filing one does not discharge the UAE regimes.
  • Who is authorised to file, and who is not. A named human files. The product does not. This page does not file.

Glossary

These are teaching labels for this page. They are not legal conclusions about YOUR facts.

Terms used on this page (teaching labels — not a determination)
TermHow this page uses it
Federal PDPLFederal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data. Onshore / mainland UAE personal-data statute this page fetched in unofficial English. Article 9 is the breach-reporting article.
The OfficeThe UAE Data Office / UAE Data Bureau established under Federal Decree-Law No. 44 of 2021. Art. 9 recipient. Operational status last-verified as not independently confirmed on an official page this page fetched.
Executive RegulationsArt. 28 of the Decree-Law required them within six months of promulgation. As of 8 September 2026 this page has not verified them as a published discrete gazette instrument. They are the instrument Article 9 points to for period, procedures, and conditions.
Immediately upon becoming awareArt. 9 unofficial English. Not converted here into 72 hours. Period as set by Executive Regulations.
As soon as practicable in the circumstancesDIFC Arts 41(1) and 42(1). Not converted here into 72 hours. Not ADGM Article 32.
Without undue delay / 72 hours where feasibleADGM Article 32. If not within 72 hours, reasons for the delay. Not DIFC, and not Federal PDPL.
DIFC Commissioner guidanceSecurity Breach Guidance and how-to-report contacts. Indicative and non-binding per Schedule 1. Not the Law.
ADGM Office materialsThe data-breach-notifications page and Online Registry Solution instructions. They restate Article 32. They are not a substitute for the Regulations.

Where this shows up in ShipReady Metrics

The signed-in app does not decide which UAE regime applies, does not start any of these clocks, does not file with the Data Office, the DIFC Commissioner, or the ADGM Office of Data Protection, and does not notify data subjects. None of the surfaces below is an Article 9 report, a DIFC Article 41 notification, an ADGM Article 32 notification, or an instruction to submit a filing. The product does not have a dedicated UAE, DIFC, or ADGM reporting ladder and does not auto-file.

If you already have a session: signed-in app → Compliance → CRA reporting tracks the Article 14 24-hour and 72-hour stages from recorded awareness, and the 14-day final-report mark from recorded measure availability, for findings the organization has classified as CRA-in-scope. That is one product tracker for the CRA actively-exploited ladder. It is not PDPL Article 9, not DIFC Article 41, not ADGM Article 32, not a Data Office submission, and not a DIFC or ADGM filing. It tracks a clock the organization already recorded. It is not a determination that CRA applies. A named human still files.

Bundled keys `uae_pdpl`, `difc_dp`, and `adgm_dpr` exist, region-tagged `uae`, all in `INTERNAL_TESTER_ONLY_FRAMEWORKS` until reviewed on real estates. Customer surfaces hide them (`isFrameworkCustomerVisible`). They bind only when the organisation recorded `uaeOperations` / `difcOperations` / `adgmOperations` (DIFC and ADGM are sub-facts of `uaeOperations`). Never a fabricated statute. Each starter set includes a 'Breach notification' control, evidenceType `manual`. Defining a control never asserts it is met. Starter subsets; no statutory text reproduced. The obligation map lists frameworks the organization has marked in-scope. That in-scope mark is not a determination that Federal PDPL, DIFC, or ADGM applies. Also `uae_ia` and `adhics` (internal-tester-only) — this page is not an IA or ADHICS guide. The cyber risk register lives under Security. None of those surfaces files with the Data Office, the DIFC Commissioner, or the ADGM Office, notifies a data subject, or starts any of these clocks.

Primary sources (last verified 8 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Federal Decree-Law No. 45 of 2021 (PDPL) is a legal requirement only if it applies. This page fetched an unofficial English translation (Lexis Middle East / privacyarabia PDF). Article 9 is reporting a personal data breach. Article 2 is scope, including the carve-out for zones of the State subject to special Personal Data Protection legislation. Article 26 is administrative penalties to be specified by Cabinet decision — maxima-to-be-specified, not typical fines. Article 28 is Executive Regulations within six months of promulgation. Article 31 is in force 2 January 2022. Issued 20 September 2021. The official Arabic text on the UAE Legislation portal (uaelegislation.gov.ae/en/legislations/1972; last update reported 20 September 2021) prevails. Executive Regulations: not verified as a published discrete gazette instrument as of 8 September 2026. UAE Data Office: Federal Decree-Law No. 44 of 2021; operational status last-verified as not independently confirmed on an official page this page fetched. JD Supra last updated 13 July 2026 is secondary commentary. DIFC Data Protection Law No. 5 of 2020 Part 7 Articles 41–42 is a legal requirement only if that Law applies. DIFC Commissioner Security Breach Guidance restates 'as soon as practicable' and contrasts GDPR 72 hours — guidance, indicative and non-binding per Schedule 1. ADGM Data Protection Regulations 2021 Article 32 is a legal requirement only if those Regulations apply. The ADGM Office data-breach-notifications page is Office materials that restates Article 32. ADGM guidance Part 5 is guidance. ADGM guidance Part 1 $28 million is a maximum in guidance, not a typical fine. The India DPDP / CERT-In jurisdiction guide on this site. Not legal advice.

The who-to-notify page on this site is the recipient-class map. The reporting-deadlines page on this site is the statute table of clocks. The supporting-evidence page on this site is the evidentiary record. The reporting-decision-tree page on this site is the branching tree. The regulator-customer-individual page on this site is the three-stream comparison. The which-jurisdictions-apply page on this site is the applicability map. The prepare-regulatory-report page on this site is the field checklist. The document-your-decision page on this site is the decision record. The failure-to-report-consequences page on this site is the maxima table. The how-regulators-determine-knowledge page on this site is the clock-start analysis. The GDPR breach-notification guide on this site is Articles 33–34. The NIS2 incident-reporting guide on this site. The DORA incident-reporting guide on this site is the jurisdiction treatment of Articles 18–19. The CRA Article 14 reporting guide on this site. The UK GDPR jurisdiction guide on this site is Articles 33–34 to the Commissioner. The US-state-laws guide on this site is the representative high-variance comparison. The SEC cyber-disclosure guide on this site is Form 8-K Item 1.05 and Item 106. The HIPAA breach-notification guide on this site. The Canada PIPEDA jurisdiction guide on this site is PIPEDA ss. 10.1–10.3 and SOR/2018-64. The Australia NDB jurisdiction guide on this site is Part IIIC.

Frequently asked questions

Which UAE, DIFC or ADGM regime applies to a breach?

This page does not choose. Onshore / mainland UAE and most other UAE zones other than DIFC and ADGM are the Federal PDPL / Data Office discussion. A DIFC-registered entity is DIFC Law No. 5 of 2020 / the Commissioner. An ADGM-registered entity is ADGM DPR 2021 / the ADGM Office. An incident can sit under more than one. Filing one does not discharge the others. Last verified 8 September 2026. Not legal advice.

Is this legal advice?

No. It is a UAE / Dubai jurisdiction guide distilled from an unofficial English translation of Federal Decree-Law No. 45 of 2021 Article 9, DIFC Data Protection Law No. 5 of 2020 Articles 41–42, ADGM Data Protection Regulations 2021 Article 32, and labelled guidance / Office materials. Whether any of the three regimes applies, whether a clock has started, and what to file are legal questions for counsel on your facts. This page does not start a reporting clock.

Does ShipReady file with the UAE Data Office?

No. The signed-in app does not file with the UAE Data Office, does not start an Article 9 clock, and does not have a Federal PDPL reporting ladder. Compliance → CRA reporting tracks the Article 14 ladder from recorded awareness for findings the org classified as CRA-in-scope — one product tracker, not PDPL Article 9 and not a Data Office submission. The obligation map is frameworks marked in-scope, not a determination that the PDPL applies. A named human still files.

Does ShipReady file with the DIFC Commissioner?

No. The signed-in app does not file with the DIFC Commissioner, does not send Article 42 Data Subject notices, does not convert 'as soon as practicable' into a number, and does not have a DIFC reporting ladder. The `difc_dp` key is internal-tester-only until reviewed; it binds only when the org recorded `difcOperations`. A named human still files.

Does ShipReady file with the ADGM Office of Data Protection?

No. The signed-in app does not file with the ADGM Office, does not submit via Online Registry Solution, does not start an Article 32 clock, and does not have an ADGM reporting ladder. The `adgm_dpr` key is internal-tester-only until reviewed; it binds only when the org recorded `adgmOperations`. A named human still files.

Is the Federal PDPL clock 72 hours?

No. 72 hours is not in the Decree-Law this page fetched. Article 9 (unofficial English) says immediately upon becoming aware, and within such period as set by the Executive Regulations. As of last-verified 8 September 2026 those Executive Regulations are not verified as a published discrete gazette instrument. If a consultancy or Data Office page claims 72 hours, that is that office's materials or secondary commentary, not the Decree-Law. Not legal advice.

Does a DIFC notice discharge ADGM or Federal PDPL?

No. DIFC Articles 41–42, ADGM Article 32, and Federal PDPL Article 9 are distinct regimes with distinct regulators. Filing one does not discharge the others. An incident can sit under more than one if the facts connect more than one establishment. This page does not choose. Not legal advice.

Is DIFC "as soon as practicable" the same as ADGM 72 hours?

No. DIFC Articles 41(1) and 42(1) say as soon as practicable in the circumstances. ADGM Article 32 says without undue delay and, where feasible, not later than 72 hours after becoming aware, with reasons if later. DIFC Commissioner guidance restates 'as soon as practicable' and contrasts GDPR's 72 hours. Guidance is not the Law. Not legal advice.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.