Civil Law And Uae Biometric Data Civil Misuse Claims .
Civil Law and UAE: Biometric Data Civil Misuse Claims
1. Introduction
Biometric data civil misuse claims arise when biometric information—such as fingerprints, facial images/templates, iris patterns, voice characteristics, DNA-related identifiers or other physiological identifiers—is collected, processed, disclosed, transferred, retained or used unlawfully, causing harm to the individual.
In the UAE, biometric information receives particularly strong protection because the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data expressly includes biometric data within personal data and sensitive personal data. The law regulates collection, processing, security, correction, erasure and restriction of processing.
A civil claim may therefore arise where, for example:
- an employer collects fingerprints for an unrelated purpose;
- a company uses facial-recognition data without a lawful basis;
- biometric templates are disclosed to another company;
- biometric data are retained after the legitimate purpose ends;
- a database is inadequately secured and biometric information is leaked;
- inaccurate biometric information causes financial or reputational harm;
- biometric information is used beyond the purpose for which it was collected.
Important case-law qualification: reported UAE case law specifically dealing with civil damages for misuse of biometric data is still limited. Therefore, the six-plus cases below are UAE judicial authorities dealing with the underlying principles—privacy, civil fault, damage, causation, evidence, judicial reasoning and protection of legal rights—which can be applied to biometric-data disputes. They should not be described as biometric-data judgments unless the judgment itself says so.
2. Meaning of Biometric Data
Biometric data are information relating to a person's physical or physiological characteristics that can identify that person.
Examples include:
- Fingerprints
- Facial-recognition information
- Iris/retina patterns
- Voice characteristics
- Hand geometry
- DNA-related identifying information
- Other physiological identifiers
The UAE Personal Data Protection Law defines personal data broadly enough to include information connected with a natural person through physical or physiological characteristics, and expressly states that personal data include sensitive personal data and biometric data.
3. Why Biometric Data Are Different From Ordinary Data
A major legal concern is immutability.
A password can be changed.
A PIN can be changed.
A biometric characteristic generally cannot be replaced in the same way.
For example:
If a password is stolen, the user can create a new password. If a biometric template is compromised, the individual cannot simply obtain a new face or fingerprint.
Consequently, misuse of biometric information may create long-term privacy and security risks.
4. UAE Legal Framework
The principal federal framework includes:
A. UAE Personal Data Protection Law
Federal Decree-Law No. 45 of 2021 Concerning the Protection of Personal Data
B. Civil liability law
The UAE civil-law framework provides remedies for unlawful harm, including compensation where the requirements of civil responsibility are established.
C. Electronic transactions law
Digital identity and electronic transactions can become relevant where biometric authentication is used electronically.
D. Cybercrime legislation
Unauthorised access, disclosure or misuse may also have consequences under cybercrime legislation, although a civil claim and criminal liability are legally distinct.
The UAE Government itself lists the Personal Data Protection Law and Electronic Transactions and Trust Services Law among the country's principal cyber/data laws.
5. Consent and Lawful Processing
Article 4 of the Personal Data Protection Law establishes the general rule that personal data may not be processed without the data subject's consent, while identifying statutory exceptions.
These include circumstances such as:
- public interest;
- legal claims or defence;
- judicial or security procedures;
- occupational or preventive medicine;
- protection of vital interests;
- performance of a contract;
- compliance with another legal obligation.
Therefore:
Consent is important, but consent is not the only possible legal basis for processing.
A biometric-data claim must therefore examine why the data were collected and whether a lawful statutory basis existed.
6. Purpose Limitation
Suppose an employer collects fingerprints for:
“Attendance and access control.”
The employer subsequently uses the same biometric database to:
- monitor employee behaviour;
- sell information to another company;
- create unrelated employee profiles;
- conduct facial-recognition experiments.
The employee could argue that the later use is outside the legitimate purpose for which the information was collected.
This is an important concept in biometric-data disputes:
Collection for one legitimate purpose does not automatically authorise every subsequent use.
7. Right to Correct Biometric Data
Article 15 of the Personal Data Protection Law provides a right to request correction or completion of inaccurate personal data without unjustified delay.
It also provides circumstances in which a data subject may request erasure, including where:
- data are no longer necessary;
- consent is withdrawn;
- there is an objection and no legitimate reason to continue;
- processing violates the law.
This is particularly important for biometric systems.
Example
A facial-recognition system incorrectly associates an individual with another person's identity.
The person may seek:
- correction;
- restriction of processing;
- deletion where legally available;
- appropriate civil remedies for resulting harm.
8. Right to Restrict Processing
Article 16 permits a data subject to require restriction or cessation of processing in circumstances including:
- dispute about accuracy;
- processing contrary to agreed purposes;
- unlawful processing.
The law also recognises circumstances where data may continue to be processed because it is necessary for legal claims or judicial proceedings.
This is extremely important in civil litigation.
For example:
A claimant may want biometric information deleted, but the same information may need to be preserved as evidence in a pending lawsuit.
The law therefore balances:
privacy protection + access to justice.
9. Data Security and Biometric Misuse
Article 20 requires controllers and processors to implement appropriate technical and organisational measures proportionate to processing risks.
The statutory framework expressly contemplates measures including:
- encryption;
- data masking;
- confidentiality;
- system integrity;
- resilience;
- restoration;
- testing and evaluation of security measures.
The risk assessment must consider unauthorised access, disclosure, alteration, destruction and loss.
This creates an important civil-liability question:
Was the biometric-data controller sufficiently careful in protecting the information?
10. Elements of a Biometric Civil Claim
A claimant will generally need to establish the applicable legal basis of liability and the relevant facts.
A useful analytical model is:
1. Protected biometric information
Was biometric data involved?
2. Processing or misuse
Was it collected, stored, analysed, transferred, disclosed or otherwise processed?
3. Lack of lawful basis or other legal wrong
Was the conduct authorised?
4. Fault or legally relevant responsibility
Was there negligence, unlawful conduct, breach of statutory duty or another basis of responsibility?
5. Damage
Did the claimant suffer:
- financial loss;
- reputational harm;
- privacy harm;
- emotional/moral damage;
- loss of opportunity;
- other legally recognised damage?
6. Causation
Was the damage caused by the biometric misuse?
11. Civil Liability Formula
A simplified model is:
Unlawful Biometric Processing + Damage + Causation = Potential Civil Liability
Where fault is required by the applicable cause of action:
Fault + Unlawful Conduct + Damage + Causation = Civil Liability
The exact elements depend upon the legal basis and applicable legislation.
12. Case Law 1 — UAE Federal Supreme Court, Cassation No. 99 of 1995
The UAE Federal Supreme Court applied the civil-law principle that every harmful act causing damage can give rise to compensation, while discussing direct and causative damage under Articles 282 and 283 of the former Civil Transactions Law.
Relevance to biometric data
Suppose a company unlawfully discloses an employee's biometric information and the disclosure causes demonstrable harm.
The claimant can frame the civil issue around:
- unlawful conduct;
- damage;
- causal connection.
Principle
Biometric technology does not remove the ordinary principles of civil responsibility.
13. Case Law 2 — UAE Federal Supreme Court, Civil Cassation No. 880 of 2021
The Court recognised that compensation may cover:
- established material damage;
- present damage;
- future damage where legally established;
- loss of a genuine opportunity.
Relevance to biometric misuse
Biometric misuse may produce damage that is not immediately measurable.
For example, an unlawful biometric disclosure could potentially cause:
- financial consequences;
- loss of a commercial opportunity;
- reputational harm;
- continuing risk.
The case demonstrates that UAE civil compensation is not necessarily restricted to immediate physical loss.
Principle
Where legally recognised damage is established, civil compensation can extend beyond an immediately measurable financial loss.
14. Case Law 3 — UAE Federal Supreme Court, Cassation No. 950 of 2019
In this privacy-related case, the Court considered the offence of attacking another person's privacy through information technology.
Importantly, the Court examined the purpose and circumstances of the conduct and held that reporting information to the competent authorities in the circumstances of that case did not constitute an unlawful privacy attack.
Relevance to biometric data
This case illustrates an essential principle:
Not every handling or disclosure of personal information is automatically unlawful.
The legal assessment depends upon:
- purpose;
- authorisation;
- circumstances;
- good faith;
- statutory duty;
- legitimate interest.
For biometric data, this distinction is important because processing may be lawful where required for judicial, security or other statutory purposes.
15. Case Law 4 — UAE Federal Supreme Court, Civil Cassation No. 647 of 2021
The Court held that a judgment must demonstrate adequate understanding of the facts and evidence and must properly consider a material defence supported by documents.
Relevance to biometric-data litigation
Biometric disputes can involve complicated technical evidence:
- biometric matching reports;
- system logs;
- access records;
- consent records;
- encryption records;
- database audit trails;
- expert reports.
A court must properly evaluate material technical evidence rather than simply accept a party's assertion that:
“The computer system says so.”
Principle
Technical evidence remains subject to judicial evaluation.
16. Case Law 5 — UAE Federal Supreme Court, Civil Cassation No. 79 of 2020
The Court discussed admissions and evidence, holding that a valid admission has significant evidentiary consequences and that courts must properly address relevant legal defences.
Relevance
A biometric-data dispute may involve admissions such as:
“The company retained the fingerprint data after the employment relationship ended.”
Such an admission could become highly significant.
Likewise, an organisation's admission that:
- it transferred biometric data;
- it suffered a security incident;
- it had no documented consent;
may materially affect the litigation.
Principle
Admissions and documentary evidence concerning data processing must be properly evaluated.
17. Case Law 6 — UAE Federal Supreme Court, Penal Cassation No. 507 of 2022
The Court held that a judgment should contain sufficient detail demonstrating consideration of the evidence, pleas and requests, and that failure to address a meritorious defence can constitute a serious defect and violation of the right of defence.
Relevance
A biometric-data claimant must have an opportunity to challenge:
- authenticity;
- accuracy;
- consent;
- purpose;
- lawful basis;
- security;
- expert evidence.
A court should not dismiss such a claim merely because the defendant produces an automated technical report.
18. Case Law 7 — UAE Federal Supreme Court, Penal Cassation No. 250 of 2020
The Court recognised that matters connected with public order may be considered by the court on its own initiative.
Relevance to biometric data
Data protection may involve mandatory legal rules that cannot simply be contracted away.
For example:
A private agreement should not automatically validate conduct that mandatory legislation prohibits.
Therefore, contractual consent must always be analysed against applicable mandatory law.
19. Case Law 8 — UAE Federal Supreme Court, Administrative Cassation No. 276 of 2018
The Court stated that administrative liability for a decision requires:
- fault;
- damage;
- causal relationship.
It rejected compensation where the challenged administrative decision was lawful and the necessary element of fault was absent.
Relevance
This provides a useful framework where biometric data are processed by a governmental or public authority.
A claimant may need to establish:
unlawful/fault-based conduct + actual damage + causal connection.
20. Case Law Summary
| Case | Legal principle | Biometric relevance |
|---|---|---|
| UAE FSC Cassation No. 99/1995 | Harmful acts may create civil responsibility | Foundation for biometric misuse damages |
| UAE FSC Civil Cassation No. 880/2021 | Compensation can cover established present/future damage and lost opportunity | Potential damages from biometric misuse |
| UAE FSC Penal Cassation No. 950/2019 | Privacy restrictions depend on purpose and lawful circumstances | Distinguishes lawful from unlawful data disclosure |
| UAE FSC Civil Cassation No. 647/2021 | Material evidence and defences must be examined | Technical biometric evidence requires judicial scrutiny |
| UAE FSC Civil Cassation No. 79/2020 | Admissions and evidence have legal consequences | Useful for consent, disclosure and retention admissions |
| UAE FSC Penal Cassation No. 507/2022 | Material defence must be addressed | Supports meaningful challenge to biometric evidence |
| UAE FSC Penal Cassation No. 250/2020 | Public-order matters may be considered by court sua sponte | Mandatory data-protection rules cannot simply be ignored |
| UAE FSC Administrative Cassation No. 276/2018 | Fault + damage + causation underpin administrative liability | Relevant to governmental biometric processing |
21. Employee Biometric Data
Employers increasingly use:
- fingerprint attendance;
- facial recognition;
- iris recognition;
- voice authentication;
- biometric access cards.
A civil dispute may arise if an employer:
- collects excessive biometric information;
- uses it for unrelated purposes;
- transfers it to a third party;
- retains it unnecessarily;
- fails to protect it;
- uses inaccurate biometric records against an employee.
Employment-related processing can have statutory exceptions where processing is necessary for employment-related legal obligations, but the processing still needs to remain within the applicable legal framework. Article 4 expressly recognises certain employment-related statutory processing as an exception to the general consent requirement.
22. Biometric Data and Banks
Banks and financial institutions may use biometrics for:
- customer authentication;
- fraud prevention;
- digital onboarding;
- account access.
A civil claim may arise where biometric information is:
- disclosed improperly;
- compromised;
- used for a different purpose;
- linked incorrectly to an account;
- retained contrary to applicable requirements.
However, anti-money-laundering and other statutory obligations can provide lawful bases for certain processing.
Therefore, the court must distinguish:
lawful regulatory processing
from
unnecessary or unlawful processing.
23. Facial Recognition and Civil Liability
Facial-recognition systems create particular risks because a photograph can be transformed into a biometric template.
Potential civil claims include:
A. Unauthorised collection
Facial data collected without an applicable lawful basis.
B. Function creep
Data collected for security later used for unrelated purposes.
C. False identification
System wrongly associates a person with another person.
D. Disclosure
Facial templates transferred to third parties.
E. Security failure
Database accessed without authorisation.
F. Retention
Data kept longer than necessary.
24. Fingerprint Data and Workplace Claims
Suppose a company installs a fingerprint attendance system.
An employee later discovers that the company:
- stores the fingerprints indefinitely;
- gives the database to an external analytics provider;
- uses fingerprints for employee profiling.
The employee could potentially raise:
- data-protection claims;
- civil responsibility claims;
- contractual/employment claims;
- requests for correction;
- restriction of processing;
- erasure where legally available;
- compensation where legally established.
25. Biometric Data Breach
Suppose hackers obtain:
- 500,000 facial templates;
- names;
- Emirates ID information;
- fingerprints.
Potential civil issues include:
- Was the organisation a controller or processor?
- Was appropriate security implemented?
- Was encryption used?
- Was access properly restricted?
- Was the breach caused by negligence?
- Did the breach cause actual damage?
- Is there a causal connection?
- What remedies are available?
Article 20 expressly requires technical and organisational security measures proportionate to processing risk and specifically recognises risks such as unauthorised access, disclosure, destruction, alteration and loss.
26. Damages in Biometric Misuse Claims
Potential categories may include:
1. Material damage
Examples:
- financial loss;
- fraudulent transactions;
- costs incurred because of identity misuse.
2. Moral/non-material damage
Depending on the applicable cause of action and proof:
- distress;
- reputational harm;
- infringement of privacy;
- loss of dignity.
3. Future damage
Where legally recognised and sufficiently established.
4. Loss of opportunity
The UAE Supreme Court has recognised compensation for a legally established lost opportunity.
27. Causation Is Critical
It is not enough to say:
“My biometric data was leaked.”
A civil claim may also require demonstrating how the misuse caused legally compensable harm.
For example:
Biometric leak
↓
Unauthorised use
↓
Identity-related financial loss
↓
Documented financial damage
This creates a much stronger causation argument.
28. Correction and Erasure
A claimant may seek non-monetary relief.
Under Article 15, applicable circumstances can support requests concerning:
- correction;
- completion;
- erasure.
Article 16 provides mechanisms for restricting or stopping processing in specified circumstances.
Therefore, a biometric claim should not be viewed only as:
“How much compensation can I obtain?”
It may also involve:
“How can I stop the unlawful processing?”
29. Preservation of Evidence
A difficult issue arises when the claimant wants biometric information deleted but litigation requires the data to be preserved.
The Personal Data Protection Law recognises exceptions relating to legal claims and judicial proceedings.
Therefore:
Privacy right
must sometimes be balanced against
preservation of evidence and access to justice.
30. Controller and Processor Responsibility
A biometric ecosystem may contain multiple parties:
Individual
↓
Employer/Bank/Platform
↓
Cloud provider
↓
Biometric technology vendor
↓
Analytics provider
The claimant must determine:
- who collected the data;
- who determined the purpose;
- who processed it;
- who had access;
- who transferred it;
- who controlled security.
This is crucial for establishing responsibility.
31. Biometric Data and Third-Party Vendors
Suppose a UAE employer hires an overseas biometric vendor.
The vendor processes employee fingerprints.
A security breach occurs.
Questions include:
- Was the vendor authorised?
- Was processing properly documented?
- Was international transfer lawful?
- Were security safeguards adequate?
- Who is legally responsible?
- What contractual obligations existed?
The existence of a third-party vendor does not automatically eliminate the original controller's responsibilities.
32. Biometric Data and Consent
Consent should be examined carefully.
A valid consent analysis asks:
- Was consent actually given?
- Was it informed?
- Was the purpose clear?
- Was it specific enough?
- Was the individual able to refuse where required?
- Was the data later used for another purpose?
- Was consent withdrawn?
A long employment or consumer contract containing a vague sentence such as:
“We may use your personal information for any purpose”
should not automatically be treated as unlimited permission for every possible biometric use.
33. Biometric Data and Contractual Clauses
Contracts may include provisions about:
- collection;
- storage;
- security;
- retention;
- deletion;
- third-party processing;
- international transfer.
But contractual drafting cannot automatically override mandatory data-protection requirements.
The parties' agreement must therefore be analysed together with the statutory framework.
34. Biometric Misuse and Unjust Enrichment
In unusual cases, misuse of biometric information may produce an economic benefit to the wrongdoer.
For example:
Company A commercially exploits biometric data obtained from individuals without a lawful basis.
Depending upon the precise facts and available cause of action, the claimant may consider whether restitutionary or unjust-enrichment principles are relevant in addition to damages.
However:
Unjust enrichment should not automatically replace a statutory data-protection or tort claim.
The correct cause of action depends on the legal relationship and facts.
35. Biometric Data and Privacy by Design
A modern UAE organisation should adopt privacy by design.
For biometric systems, this may include:
- collecting only necessary biometric information;
- encrypting templates;
- separating identity data from biometric templates;
- limiting employee access;
- using strict retention periods;
- conducting security testing;
- maintaining audit logs;
- deleting data when legally permissible;
- establishing breach-response procedures.
This approach reduces both privacy risk and civil-liability exposure.
36. Practical Example
Facts
A company introduces facial recognition for office entry.
An employee agrees to facial scanning for access control.
Six months later, the company provides the facial database to an advertising company.
The advertising company creates customer profiles.
Possible legal issues
Issue 1: Was the original collection lawful?
Issue 2: Was advertising a compatible purpose?
Issue 3: Was separate consent or another lawful basis required?
Issue 4: Was the disclosure authorised?
Issue 5: Did the company satisfy security requirements?
Issue 6: Can the employee request restriction or deletion?
Issue 7: Was any legally compensable damage suffered?
Issue 8: Who was responsible—the company, vendor, or both?
37. Possible Civil Remedies
Depending on the applicable legal basis, remedies may include:
1. Injunctive/prohibitory relief
Stop unlawful processing.
2. Correction
Correct inaccurate biometric records.
3. Erasure
Delete data where statutory conditions permit.
4. Restriction
Limit processing.
5. Compensation
Recover legally established damage.
6. Restitution
Potentially recover unjustified benefits where the requirements of that doctrine are met.
7. Declaratory relief
Obtain a judicial determination concerning the parties' rights.
38. Important Defence: Lawful Processing
A defendant may argue:
“The biometric processing was lawful.”
Potential grounds can include:
- valid consent;
- statutory obligation;
- public interest;
- legal proceedings;
- security requirements;
- contractual necessity;
- employment-related statutory requirements.
Article 4 expressly lists several situations in which processing can occur without ordinary consent.
Therefore, the claimant must identify why the processing was unlawful, rather than relying solely on the fact that biometric data were involved.
39. Important Defence: No Damage
A defendant may also argue:
“Even if there was a technical violation, the claimant suffered no compensable damage.”
This makes evidence particularly important.
The claimant should preserve:
- breach notifications;
- access logs;
- correspondence;
- expert reports;
- financial records;
- evidence of unauthorised use;
- evidence of reputational harm;
- proof of resulting expenses.
40. Important Defence: No Causation
Another defence may be:
“The alleged damage was not caused by our biometric processing.”
For example, if a claimant's identity information was compromised through several independent sources, establishing that a particular biometric processor caused the loss may become difficult.
This makes causation a central issue.
41. Six Core Questions for UAE Courts
In a biometric-data civil dispute, a court may conceptually ask:
Question 1
What biometric data was processed?
Question 2
Who processed it?
Question 3
For what purpose?
Question 4
What was the lawful basis?
Question 5
Was the processing secure and within the authorised purpose?
Question 6
What legally compensable harm resulted?
42. Biometric Data Claim Checklist
A claimant should try to establish:
- biometric data involved;
- identity of controller;
- identity of processor;
- date of collection;
- purpose of collection;
- consent or other lawful basis;
- subsequent uses;
- third-party disclosure;
- retention period;
- security arrangements;
- breach or misuse;
- resulting damage;
- causation;
- requested correction/erasure;
- requested compensation.
43. Key Distinction: Privacy Violation vs Civil Damages
These concepts should not be automatically equated.
Privacy violation
May establish that processing was unlawful.
Civil damages
Generally require the additional legal requirements for the particular civil claim, including legally recognised damage and causation where applicable.
Therefore:
Unlawful processing does not automatically mean that every claimant receives unlimited monetary compensation.
44. Relationship With Criminal Liability
The same conduct can potentially create:
Civil consequences + administrative consequences + criminal consequences
For example:
Civil
Compensation for damage.
Administrative
Regulatory measures or sanctions.
Criminal
Where the conduct falls within an applicable criminal offence.
These are distinct legal mechanisms.
The UAE Supreme Court's privacy jurisprudence demonstrates that the criminal assessment of privacy-related conduct depends upon statutory elements and the circumstances of the conduct.
45. Current UAE Legal Position
The most important points are:
- Biometric data are expressly protected under UAE personal-data legislation.
- Biometric data are treated as sensitive personal data.
- Processing generally requires consent unless a statutory exception applies.
- Legal proceedings and certain security/public-interest circumstances can constitute exceptions.
- Individuals have rights concerning correction and, in specified circumstances, erasure.
- Individuals can request restriction of processing in specified circumstances.
- Controllers and processors must implement appropriate security measures.
- Civil liability can arise where unlawful conduct causes legally compensable harm.
- Causation and proof of damage remain important.
- UAE judicial principles concerning privacy, evidence, reasoning and civil responsibility are highly relevant even though biometric-specific reported civil case law remains limited.
46. Exam-Ready Definition
Biometric data civil misuse claims in UAE civil law are claims arising from the unlawful collection, processing, disclosure, retention, transfer, security failure or other misuse of biometric information where the conduct infringes applicable data-protection or civil-law rights and causes legally recognised harm. The UAE Personal Data Protection Law treats biometric information as sensitive personal data and provides safeguards concerning lawful processing, correction, erasure, restriction and security. Civil-law principles concerning wrongful conduct, damage and causation determine the availability of compensation.
47. Conclusion
Biometric information represents one of the most sensitive categories of modern personal information because it is closely connected to a person's physical identity and cannot ordinarily be replaced like a password.
The UAE's legal framework therefore combines:
Data protection + privacy + security + civil responsibility + procedural safeguards.
A strong biometric civil claim should establish:
Protected biometric data → processing/misuse → lack of lawful basis or other legal wrong → legally relevant damage → causation → appropriate remedy.
The Personal Data Protection Law is especially significant because it expressly includes biometric data within sensitive personal data and provides rights relating to correction, erasure and restriction, while requiring appropriate technical and organisational security measures.
The available UAE judicial authorities also show that courts recognise broader principles essential to biometric litigation: harmful conduct can attract civil responsibility, compensable damage may extend beyond immediate financial loss, privacy-related conduct must be assessed according to its legal purpose and circumstances, and courts must carefully examine evidence and material defences.
Accordingly, UAE biometric-data law is best understood as a combination of preventive data governance and corrective civil remedies: the law seeks not only to compensate individuals after biometric misuse occurs, but also to force organisations to design systems that minimise unnecessary collection, prevent unauthorised disclosure and maintain strong security from the beginning.

comments