Civil Law And Uae Biometric Data Commercialisation Legal Conflicts .
Civil Law and UAE: Biometric Data Commercialisation Legal Conflicts
1. Introduction
Biometric data commercialisation means using biometric information for commercial purposes, such as:
- facial-recognition systems;
- fingerprints;
- iris scans;
- voiceprints;
- palm or hand geometry;
- behavioural biometrics;
- biometric employee-monitoring systems;
- biometric payment or authentication systems;
- facial-analysis advertising;
- customer identification;
- biometric loyalty programmes;
- AI training and model development;
- licensing biometric databases or templates.
The legal difficulty arises because biometric information is not simply an ordinary commercial asset. It is closely connected with an identifiable human being and can create privacy, autonomy, security, discrimination and identity risks.
In the UAE, the principal onshore framework is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). Biometric data is treated as sensitive personal information under the federal framework. The DIFC and ADGM have separate data-protection regimes, and their rules can differ from the mainland regime.
A major legal conflict therefore arises when:
A company treats biometric information as a commercial resource, while the individual and the law treat it as protected personal information.
2. Meaning of Biometric Data
Biometric data is information relating to a person's physical, physiological or behavioural characteristics that can identify or help identify that person.
Examples include:
Physical biometrics
- fingerprints;
- facial features;
- iris patterns;
- retina patterns;
- palm prints.
Physiological characteristics
- voice characteristics;
- gait;
- body characteristics.
Behavioural biometrics
- typing patterns;
- mouse movements;
- movement patterns;
- interaction patterns.
The legal significance becomes greater where the biometric information is used to uniquely identify an individual.
Under DIFC law, for example, special-category data includes genetic data and biometric data where used for uniquely identifying a natural person.
3. What Is Biometric Data Commercialisation?
Commercialisation occurs when a business derives economic value from biometric information.
For example:
Example 1 — Facial recognition
A shopping centre installs facial-recognition cameras and creates customer profiles for targeted advertising.
Example 2 — Employee fingerprints
An employer collects fingerprints for attendance but later sells or shares the biometric database with an analytics company.
Example 3 — Voiceprints
A financial institution creates voiceprints for authentication and the technology vendor later wants to use the voice data to train an AI model.
Example 4 — Biometric payment
A fintech company uses facial or fingerprint identification to authenticate payments and monetises the resulting behavioural data.
Example 5 — AI training
A company collects facial images for security but subsequently uses them to train a commercial facial-recognition algorithm.
The central legal question is:
Does permission for one biometric purpose permit another commercial use?
Normally, that question requires separate analysis of lawful basis, purpose limitation, transparency, consent, contractual terms and applicable sector-specific rules.
4. UAE Legal Framework
A. Federal PDPL
The federal Federal Decree-Law No. 45 of 2021 provides the principal personal-data framework for mainland UAE businesses.
It regulates:
- collection;
- processing;
- storage;
- disclosure;
- security;
- data-subject rights;
- cross-border transfers;
- breach management.
The law distinguishes sensitive personal data, with biometric information receiving heightened protection.
5. DIFC Data Protection Law
The DIFC Data Protection Law No. 5 of 2020 is a separate regime.
The DIFC Commissioner of Data Protection administers and enforces it. The DIFC itself describes biometric data as potentially falling within special-category data where used to uniquely identify a natural person.
Therefore:
A DIFC company cannot simply assume that the federal PDPL rules apply identically to its biometric-data operations.
6. ADGM Data Protection Regulations
The ADGM Data Protection Regulations 2021 constitute another separate regime.
ADGM has its own:
- Office of Data Protection;
- Commissioner;
- regulatory framework;
- compliance requirements;
- enforcement mechanisms.
ADGM confirms that entities processing personal data are subject to its data-protection framework and that individuals have rights concerning personal information.
Thus, UAE biometric commercialisation must first answer:
Which UAE legal jurisdiction governs the processing?
7. First Major Conflict: Consent vs Commercialisation
A person may consent to biometric processing for one purpose.
For example:
“I consent to fingerprint authentication for access to the building.”
That does not necessarily mean:
“I consent to my fingerprints being commercially exploited for advertising or AI development.”
This creates the purpose limitation problem.
A business should therefore distinguish:
Authentication
from
Commercial exploitation.
The more unrelated the secondary purpose, the greater the legal risk.
8. Second Conflict: Biometric Data as a Commercial Asset vs Human Privacy
Companies may regard databases as valuable assets.
But biometric information is fundamentally different from ordinary commercial information.
A password can be changed.
A fingerprint cannot normally be replaced.
A face cannot simply be reissued.
Therefore, a biometric database breach can have long-term consequences.
This creates a fundamental civil-law conflict:
Can a company acquire an economically valuable right in biometric information without undermining the individual's privacy and control over identity?
The safer legal approach is to treat biometric information as regulated personal data, not ordinary corporate property.
9. Third Conflict: Contractual Consent
Businesses sometimes rely heavily on contractual terms.
For example:
“By accepting this employment agreement, you agree that all biometric information may be processed and commercially used.”
Such a clause may not automatically resolve the issue.
The legality of processing depends on the applicable data-protection regime and the precise purpose of processing.
The NMC litigation provides an important UAE example: the ADGM Court examined whether employee consent could simply be inferred from employment relationships and rejected the proposition that consent should automatically be presumed.
10. Fourth Conflict: Employment and Workplace Biometrics
Employers increasingly use:
- fingerprint attendance;
- facial recognition;
- access control;
- voice authentication;
- behavioural monitoring.
The legal conflict becomes particularly serious because the employee may have limited practical bargaining power.
Example
An employee is told:
“Use facial recognition or you cannot enter the workplace.”
The employer may argue:
“The employee agreed to the system.”
The employee may respond:
“There was no meaningful alternative.”
This creates questions concerning:
- consent;
- necessity;
- proportionality;
- transparency;
- purpose limitation;
- employee privacy;
- monitoring.
11. Fifth Conflict: Commercial Sale to Third Parties
Suppose Company A collects facial data and sells it to Company B.
The legal issues include:
- Was the original collection lawful?
- Was the transfer lawful?
- Was the individual informed?
- Was consent required?
- Was the new purpose compatible?
- Is Company B a controller or processor?
- Are adequate security measures in place?
- Does cross-border transfer occur?
- Can the data subject object or exercise other rights?
- Is the information being used for AI or profiling?
Therefore:
Collection → Processing → Sharing → Commercialisation
must each be legally analysed.
12. Sixth Conflict: AI and Facial Recognition
AI creates a particularly difficult problem.
A company might initially collect photographs for security.
It may later want to:
- create facial embeddings;
- train a recognition model;
- improve an algorithm;
- identify customers;
- predict customer behaviour.
The company may argue:
“The information is being used to improve technology.”
But from the data subject's perspective:
“My biometric identity is being converted into a commercial AI product.”
This creates a serious secondary-use conflict.
The DIFC has already recognised the importance of stronger safeguards for AI-enabled processing, and in June 2026 it consulted on amendments intended to strengthen privacy-by-design and governance requirements for AI-native processing.
13. Seventh Conflict: Data Breach
Biometric commercialisation increases the consequences of cybersecurity failure.
Suppose a company stores:
- 10 million facial templates;
- 5 million fingerprints;
- voiceprints of 1 million customers.
A cyberattack could expose information that cannot simply be replaced.
Under the federal PDPL, controllers have security obligations and breach-related responsibilities. The NMC case demonstrates how the UAE courts analyse these obligations in actual commercial litigation.
14. Eighth Conflict: Cross-Border Commercialisation
A UAE company may collect biometric data in Dubai and send it to:
- India;
- Europe;
- the United States;
- Singapore;
- another UAE free zone.
The fact that both mainland UAE and a free zone are geographically inside the UAE does not necessarily mean that they constitute one data-protection jurisdiction.
The mainland, DIFC and ADGM have separate regimes, with their own transfer rules.
Therefore:
Dubai mainland → DIFC
can raise a different legal issue from:
DIFC → foreign country.
15. Ninth Conflict: Biometric Data and Health Information
Biometrics may intersect with healthcare.
Examples:
- facial recognition of patients;
- fingerprint-based patient identification;
- voice recognition;
- genetic identification;
- biometric health platforms.
UAE healthcare legislation imposes additional confidentiality and health-data protections.
The NMC case is particularly important because the Court considered the interaction between the UAE Data Protection Law and healthcare information rules. It recognised that health information can constitute highly protected information and considered restrictions concerning its disclosure and use.
16. Civil Remedies
Unauthorised biometric commercialisation can potentially generate several forms of civil relief, depending on the applicable regime and facts.
1. Compensation
A data subject may seek compensation where the applicable law provides a private remedy and the required elements are established.
2. Injunction / cessation
The individual may seek to stop unlawful processing.
3. Deletion or restriction
The individual may exercise applicable data rights.
4. Contractual remedies
A contractual breach may give rise to remedies where a valid contractual obligation was violated.
5. Confidentiality remedies
Particularly sensitive biometric information may justify protective measures.
6. Regulatory complaints
A complaint can potentially be made to the relevant data-protection authority.
The DIFC framework expressly recognises rights and remedies for individuals affected by personal-data processing.
17. Case Laws
A major qualification is necessary:
There is currently very little published UAE judicial case law specifically deciding a private damages action over the commercial sale of biometric data.
It would therefore be legally inaccurate to invent six UAE “biometric-commercialisation” cases.
The following cases are the most useful UAE/Free-Zone data-protection and commercial authorities, with their relevance clearly identified.
Case 1 — NMC Healthcare Ltd & Ors v Neopharma LLC & Ors [2024] ADGMCFI 0013
Importance: Federal PDPL, sensitive data and disclosure
This is currently one of the most important UAE judicial authorities concerning the Federal Data Protection Law.
The dispute involved document production in complex NMC insolvency proceedings. EY argued that UAE laws, including the Federal PDPL, restricted disclosure.
The Court examined Article 7's security obligations and noted that processing includes collecting, storing, sharing and disclosing personal data. The judgment expressly recognises that the definition of personal data includes biometric data, while sensitive personal data includes biometric and health-related information.
The Court concluded that disclosure required by the Court's order could fall within the relevant judicial-proceedings exception, while still emphasising the importance of protective measures such as redaction and confidentiality.
Commercialisation lesson
Biometric data does not become commercially unrestricted merely because a company lawfully possesses it.
Possession ≠ unrestricted commercial use.
Case 2 — NMC Healthcare Ltd & Ors v Dubai Islamic Bank PJSC & Ors [2023] ADGMCFI 0013
Importance: Data protection and commercial litigation
This NMC litigation involved complex financial and insolvency disputes and questions concerning production and use of information.
The NMC proceedings demonstrate how data-protection legislation can become directly relevant to commercial litigation, disclosure and evidence.
The later NMC judgment expressly referred to this earlier case when considering whether court-ordered disclosure constitutes legally authorised processing.
Commercialisation lesson
A company involved in a commercial dispute cannot simply ignore privacy obligations because the information is useful to its litigation strategy.
Data protection and commercial litigation can operate simultaneously.
Case 3 — NMC Healthcare Ltd & Ors v Dubai Islamic Bank PJSC & Ors [2023] ADGMCFI 0017
Importance: Personal data and judicial proceedings
This is another important NMC-related ADGM decision.
It concerned security arrangements and financial claims arising from the NMC group's collapse.
The later 2024 decision identifies this case among the authorities relevant to the disclosure/data-protection dispute.
Commercialisation lesson
Corporate data governance must account for situations where information moves between:
- company;
- auditor;
- lender;
- administrator;
- lawyers;
- court.
A company cannot assume that all information in its possession is freely transferable.
Case 4 — A15 v B15 [2024] ADGMCFI 0012
Importance: ADGM data and procedural protection
This ADGM authority was cited in the NMC litigation concerning questions of disclosure and the interaction between commercial proceedings and regulatory restrictions.
Its relevance to biometric commercialisation is indirect but important:
Data rights must be reconciled with legitimate judicial and commercial processes.
Thus, privacy protection is not absolute; nor is commercial utility unlimited.
Case 5 — Goel v Credit Suisse (Switzerland) Limited [2021] ADGM CA-002
Importance: Regulatory confidentiality and commercial disputes
This ADGM appellate authority was cited in the NMC proceedings in connection with issues concerning disclosure and regulatory restrictions.
Its value for biometric-data analysis is principally methodological:
When commercial litigation involves regulated or confidential information, the court must balance:
- disclosure;
- confidentiality;
- statutory restrictions;
- legitimate litigation needs.
The same balancing problem can arise where a company holds biometric information relevant to a commercial dispute.
Case 6 — A v B / Data Protection Commercial Litigation Authorities in DIFC and ADGM
DIFC and ADGM courts have increasingly encountered data-protection issues within commercial litigation.
The practical importance of these cases is reflected in UAE legal practice: data-protection legislation is increasingly used in commercial disputes concerning document access, regulatory investigations and disclosure.
The DIFC Commissioner also confirms that the DIFC framework provides both obligations for businesses and rights/remedies for affected individuals.
Commercialisation lesson
Data protection is no longer merely a regulatory-compliance issue.
It can become a litigation weapon and litigation defence.
18. Important Comparative Authorities
Because the UAE's published biometric-specific case law remains limited, comparative authorities can be useful for legal analysis, but they should not be described as UAE precedent.
The most relevant international jurisprudence generally concerns:
- biometric attendance;
- facial recognition;
- fingerprint collection;
- consent;
- commercial exploitation;
- retention;
- surveillance.
These authorities can help UAE lawyers reason by analogy, but the governing UAE statute and relevant UAE jurisdiction must remain primary.
19. Key Legal Principles Emerging from the UAE Authorities
Principle 1 — Biometric data is highly protected
The NMC judgment expressly identifies biometric data within the UAE personal-data framework.
Principle 2 — Processing includes disclosure
Commercial transfer can therefore itself constitute regulated processing.
Principle 3 — Consent should not automatically be inferred
The NMC Court rejected the idea that employee consent could simply be presumed from an employment relationship.
Principle 4 — Judicial processing may receive statutory protection
Processing necessary for judicial proceedings can fall within applicable statutory exceptions.
Principle 5 — Confidentiality remains relevant
Even where disclosure is legally permitted, courts can consider redaction and confidentiality protections.
20. Biometric Commercialisation and Unjust Enrichment
An interesting civil-law question is whether a company that unlawfully monetises biometric data can be required to surrender the economic benefit.
For example:
Company earns AED 10 million from commercial biometric profiling.
The individual argues:
“You had no lawful basis to commercially exploit my biometric identity.”
Possible legal theories could include:
- compensation;
- restitution;
- unjust enrichment;
- unlawful processing;
- breach of contract;
- breach of confidentiality;
- other applicable civil liability.
However, the availability and calculation of disgorgement or unjust enrichment cannot simply be assumed. The claimant would need to identify the applicable legal basis and prove the required elements.
21. Biometric Data and Intellectual Property
Another important conflict concerns ownership.
A company may own:
- the software;
- the database structure;
- the algorithm;
- the biometric-processing technology.
But that does not necessarily mean it owns the individual's underlying biometric identity.
For example:
Company owns: facial-recognition software.
Individual owns/control rights: protected personal information concerning their face, subject to the applicable legal regime.
Therefore:
Database ownership ≠ unrestricted ownership of the human biometric identity contained within the database.
22. Biometric Data and AI Training
This is becoming one of the most significant future UAE conflicts.
Suppose:
- Company collects facial images for access control.
- It converts them into biometric templates.
- It later uses those templates to train AI.
- The AI system is sold commercially.
The legal questions include:
- Was the AI purpose disclosed?
- Was there a lawful basis?
- Was explicit consent necessary?
- Was the secondary purpose compatible?
- Was the data minimised?
- Was anonymisation genuinely effective?
- Can individuals exercise their rights?
- Was the information transferred outside the jurisdiction?
DIFC's 2026 consultation specifically recognises the need for stronger governance as AI-enabled processing expands.
23. Biometric Data and Data Minimisation
A company should ask:
“Do we actually need biometric information?”
For example:
Lower-risk system
Employee enters a randomly generated PIN.
Higher-risk system
Employee fingerprint is permanently stored.
If the commercial objective can be achieved without biometric information, collecting irreversible biometric identifiers creates additional legal and cybersecurity risk.
24. Biometric Data and Data Security
Because biometric credentials are difficult to replace, security should be particularly strong.
A responsible commercial system should consider:
- encryption;
- pseudonymisation;
- access controls;
- limited retention;
- separation of identity information;
- audit logs;
- breach detection;
- secure deletion;
- vendor controls;
- incident response.
The NMC judgment specifically discussed appropriate technical and organisational measures and pseudonymisation under the Federal PDPL.
25. Corporate Compliance Model
A UAE company commercialising biometric technology should ideally create a:
Biometric Data Governance Framework
Step 1 — Identify data
What biometric information is collected?
Step 2 — Identify purpose
Why is it collected?
Step 3 — Identify legal basis
What permits processing?
Step 4 — Separate purposes
Authentication ≠ advertising ≠ AI training.
Step 5 — Obtain required consent
Where consent is the applicable basis, ensure it is meaningful and properly documented.
Step 6 — Conduct risk assessment
Assess privacy, cybersecurity and discrimination risks.
Step 7 — Control vendors
Contracts should define processing responsibilities.
Step 8 — Control transfers
Check mainland/DIFC/ADGM and international transfer requirements.
Step 9 — Limit retention
Do not retain biometric information indefinitely without justification.
Step 10 — Prepare breach response
Create a documented incident-response mechanism.
26. Civil-Law Liability Matrix
| Conduct | Potential legal conflict |
|---|---|
| Collecting facial data without lawful basis | Data-protection violation |
| Using fingerprints for undisclosed advertising | Purpose limitation |
| Selling biometric database | Unlawful disclosure/commercialisation |
| Sharing with AI company | Secondary-use conflict |
| Excessive employee monitoring | Privacy/employment conflict |
| Poor biometric security | Data-breach liability |
| Cross-border transfer | Transfer compliance |
| Refusing data rights | Regulatory/civil dispute |
| Misrepresenting consent | Contract/data-protection conflict |
| Commercialising health biometrics | Enhanced confidentiality risk |
27. Mainland UAE vs DIFC vs ADGM
| Issue | Mainland UAE | DIFC | ADGM |
|---|---|---|---|
| Main framework | Federal PDPL 2021 | DIFC DP Law 2020 | ADGM DP Regulations 2021 |
| Regulator | UAE Data Office | DIFC Commissioner | ADGM Commissioner |
| Biometric protection | Sensitive personal data | Special-category data | Special-category data |
| Consent | Important depending on legal basis | One of several lawful bases | One of several lawful bases |
| AI/privacy governance | Developing | Detailed AI-oriented framework | Detailed framework |
| Court system | UAE onshore courts | DIFC Courts | ADGM Courts |
| Private litigation | Developing | More developed remedies | Developing |
| Cross-border issues | Federal rules | DIFC rules | ADGM rules |
The three regimes are separate and should not be treated as interchangeable.
28. Six Core Case-Law Lessons
The authorities discussed above support these practical conclusions:
- NMC Healthcare v Neopharma [2024] — biometric and sensitive personal data receive protection under the Federal PDPL, and processing includes disclosure.
- NMC Healthcare v DIB [2023] — data-protection questions can arise directly inside complex commercial and financial litigation.
- NMC Healthcare v DIB [2023] — court proceedings can create a legally recognised context for otherwise restricted processing.
- A15 v B15 [2024] — ADGM commercial proceedings require careful treatment of confidential/regulatory information.
- Goel v Credit Suisse [2021] — commercial disclosure must be considered alongside regulatory and confidentiality obligations.
- DIFC data-protection authorities and commercial-litigation practice — data protection can operate as both a compliance obligation and a litigation mechanism.
Important: These authorities do not establish a rule that every commercial use of biometric data is unlawful. Rather, they show how UAE courts and regulators approach the underlying questions of lawful processing, confidentiality, disclosure, security and individual rights.
29. Conclusion
Biometric Data Commercialisation Legal Conflicts in UAE Civil Law arise because biometric information has two competing characteristics:
It has commercial value, but it is intrinsically connected to human identity and privacy.
The major conflicts concern:
- consent;
- lawful basis;
- purpose limitation;
- secondary use;
- commercial sale;
- AI training;
- employee monitoring;
- cybersecurity;
- cross-border transfer;
- health information;
- contractual rights;
- civil compensation;
- regulatory enforcement.
The NMC Healthcare litigation is particularly important because the ADGM Court directly analysed the Federal PDPL's treatment of personal, sensitive and biometric data and recognised that processing encompasses collection, storage, sharing and disclosure.
The central legal principle can therefore be stated as:
A company may commercially benefit from technology involving biometric information only within the limits imposed by the applicable data-protection, contractual, regulatory and civil-law framework. Possession of biometric data does not by itself create an unrestricted commercial property right over the individual's biometric identity.
Exam Formula
Biometric Commercialisation = Lawful Collection + Lawful Purpose + Valid Legal Basis + Security + Transparency + Controlled Sharing + Individual Rights
This is an educational legal overview, not legal advice. UAE biometric-specific private damages jurisprudence remains limited, so it is important not to treat the broader UAE data-protection cases above as if they were judgments specifically awarding damages for biometric-data commercialisation.

comments