Civil Law And Uae Cross-Jurisdiction Enforcement Of Digital Torts .
Civil Law and UAE Cross-Jurisdiction Enforcement of Digital Torts
1. Introduction
Cross-jurisdiction enforcement of digital torts concerns situations where an online or technology-related harmful act occurs in one jurisdiction, affects a person or business in another, and the defendant, evidence, platform, or assets are located somewhere else.
Examples include:
cyberattacks;
unauthorised access to computer systems;
online defamation;
digital fraud;
misuse of personal data;
interference with websites or databases;
cryptocurrency-related wrongdoing;
online intellectual-property infringement;
malicious publication;
digital business interruption;
cross-border privacy violations.
The UAE presents a particularly interesting environment because enforcement may involve UAE onshore courts, DIFC Courts, ADGM Courts, foreign courts, arbitration, and international enforcement mechanisms.
The central problem is:
How can a claimant obtain a civil remedy for a digital wrong occurring across jurisdictions and then make that remedy effective against the defendant or assets in another jurisdiction?
2. What Is a Digital Tort?
A digital tort is a civil wrong committed through, against, or substantially involving digital technology.
It can involve:
| Digital wrong | Possible civil consequence |
|---|---|
| Hacking | Compensation |
| Data destruction | Property/economic damages |
| Data misuse | Privacy/data-related remedies |
| Online defamation | Damages/injunction |
| Digital fraud | Restitution/compensation |
| Website interference | Injunction/damages |
| Cyber extortion | Compensation/restoration |
| Unauthorised access | Damages/injunctive relief |
| Digital asset interference | Proprietary/injunctive relief |
| Trade-secret leakage | Damages/injunction |
The UAE's current general civil-liability framework is contained principally in the 2025 Civil Transactions Law, effective from 1 June 2026, while special legislation may apply depending on the digital wrong involved.
3. Why Cross-Jurisdiction Digital Torts Are Difficult
Digital torts create unusual jurisdictional problems because a single act can have multiple geographical connections.
For example:
A person in Country A hacks a UAE company's server located in Country B, uses a cloud service in Country C, causes financial losses to a DIFC company, and transfers the resulting funds to Country D.
Potential questions include:
Where did the tort occur?
Where was the damage suffered?
Which court has jurisdiction?
Which law governs?
Where should evidence be collected?
Where can an injunction operate?
Where are the defendant's assets?
How can a UAE judgment be enforced abroad?
4. The Enforcement Chain
A cross-border digital-tort claim can be represented as:
Digital wrong
↓
Identification of defendant
↓
Jurisdiction
↓
Evidence preservation
↓
Civil judgment/injunction
↓
Recognition in foreign jurisdiction
↓
Asset identification
↓
Execution
↓
Compensation
The weakness of any stage can undermine the entire claim.
5. First Principle: Establish Jurisdiction
Before enforcement, the claimant must establish jurisdiction.
Possible jurisdictional connections include:
defendant's domicile;
defendant's business presence;
location of the affected business;
location of the computer system;
place where damage occurred;
contractual jurisdiction clause;
DIFC/ADGM connection;
location of relevant assets.
Digital activity makes this particularly complicated because the physical location of the computer used by the wrongdoer may not be the location where the legal injury occurred.
6. Territoriality and Digital Harm
Traditional tort law often relies on territorial concepts.
Digital torts challenge that model.
Consider:
A defamatory post is uploaded in London, viewed in Dubai, Singapore and New York, and causes financial loss to a UAE company.
Potentially relevant jurisdictions include:
England;
UAE;
DIFC;
Singapore;
United States.
The court therefore needs to identify the legally relevant connection rather than simply asking where the keyboard was located.
7. Choice of Law
After jurisdiction comes applicable law.
The parties may argue for:
UAE law;
DIFC law;
ADGM law;
foreign tort law;
contractual law;
mandatory data-protection legislation.
A cross-border digital tort can therefore involve:
Forum law ≠ necessarily substantive law ≠ enforcement law.
For example:
A UAE court could potentially hear a dispute involving foreign conduct while having to consider foreign-law issues concerning particular aspects of the claim.
8. Graciela Limited v Giacobbe
Case 1: Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the most important UAE digital-tort authorities.
Graciela's IT system was deliberately sabotaged.
The system included:
computers in the DIFC;
equipment in a DIFC data centre;
equipment located at other locations around the world;
remote internet access.
The defendant was a former senior IT employee.
The DIFC Court found, on the balance of probabilities, that he had deliberately interfered with the claimant's IT system. The Court awarded USD 690,533 in compensatory damages. The damages included system restoration, emergency servers, investigation costs and employee time. (DIFC Courts)
Cross-jurisdiction significance
The case demonstrates that a digital tort can involve:
geographically dispersed infrastructure;
remote access;
electronic evidence;
forensic analysis;
causation;
economic loss.
The location of the digital infrastructure was relevant even though the wrongful conduct could be performed remotely.
Enforcement lesson
A digital-tort claimant should identify every legally significant location:
attacker → device → server → data → business → loss → assets.
That geographical map can determine both jurisdiction and enforcement strategy.
9. Techteryx Ltd v Aria Commodities DMCC
Case 2: Techteryx Ltd v Aria Commodities DMCC & Others [2025] DIFC DEC 001
This is a particularly significant modern case because it was handled by the DIFC Digital Economy Court.
The proceedings involved proprietary and freezing injunctions and extensive disclosure issues concerning transactions and assets.
The Court applied the established principles for freezing and proprietary relief, including the requirement of a sufficiently arguable case and consideration of the risk that conduct could prejudice enforcement. (DIFC Courts)
The proceedings also involved applications concerning the use of disclosed information in related proceedings in other jurisdictions. (DIFC Courts)
Digital-tort relevance
The case demonstrates how modern digital/commercial disputes may require:
cross-border disclosure;
proprietary relief;
freezing orders;
investigation of transactions;
use of information in foreign proceedings.
Enforcement lesson
In digital disputes, preserving the economic value of the eventual judgment can be as important as proving liability.
10. Carmon v Cuenda
Case 3: Carmon Reestrutura-Engenharia e Serviços Técnicos Especiais (SU) LDA v Antonio Joao Catete Lopes Cuenda [2024] DIFC CA 003
Carmon concerned the DIFC Court's power to provide interim protection supporting the enforcement of foreign judgments.
The Court considered the relationship between:
foreign judgment enforcement;
interim injunctions;
freezing relief;
the enforcement principle.
The judgment recognised that the DIFC Courts have powers to grant appropriate interim relief connected with their enforcement jurisdiction. (DIFC Courts)
Digital-tort relevance
Suppose a cyber-fraud defendant has moved proceeds from the UAE to another jurisdiction.
The claimant may need:
judgment or prospective judgment;
asset-preservation relief;
disclosure;
recognition;
enforcement.
Carmon illustrates the importance of interim protection before final recovery.
11. Trafigura v Gupta
Case 4: Trafigura PTE Ltd & Trafigura India PTV Ltd v Prateek Gupta & Ginni Gupta [2025] DIFC CA 001
Trafigura is significant for cross-border freezing relief and enforcement.
The case examined the relationship between the DIFC Court's enforcement jurisdiction and its power to issue freezing relief.
The Court considered the enforcement of foreign judgments and the circumstances in which interim relief may protect the effectiveness of future enforcement. (DIFC Courts)
Digital-tort application
This reasoning can become relevant where digital wrongdoing produces rapidly transferable assets.
For example:
cyber fraud → cryptocurrency conversion → offshore account → foreign asset.
A claimant may need to preserve the asset position before the final enforcement stage.
12. Sandra Holding Ltd v Al Saleh
Case 5: Sandra Holding Ltd & Nuri Musaed Al Saleh v Fawzi Musaed Al Saleh & Others [2023] DIFC CA 003
Sandra Holding is important for understanding the limits of DIFC jurisdiction concerning interim relief in support of foreign proceedings.
The Court considered whether the DIFC Courts could grant broad interim relief against persons without a sufficient DIFC jurisdictional connection.
The Court emphasised that the DIFC Court's jurisdiction cannot simply be expanded indefinitely through the general availability of injunctive relief. (DIFC Courts)
Digital-tort significance
This is particularly important for internet disputes.
A claimant should not assume:
"The defendant is somewhere in the world and the harm involves the UAE, therefore the DIFC Court can automatically issue a worldwide injunction."
Jurisdiction must first be established.
13. Sunteck Lifestyles Ltd v Al Tamimi
Case 6: Sunteck Lifestyles Limited v Al Tamimi & Company Limited & Grand Valley General Trading LLC [2017] DIFC CFI 048
Sunteck concerned an injunction relating to documents held by a DIFC entity.
The Court examined jurisdiction despite a contractual reference to the "courts of the Emirate of Dubai."
The judgment considered earlier DIFC authorities concerning interpretation of jurisdiction clauses, including National Bonds v Taaleem, Corinth Pipeworks v Barclays Bank, and Injazat v DWS. (DIFC Courts)
Digital-tort significance
Digital disputes frequently involve contracts between:
platform operators;
technology vendors;
cloud providers;
data processors;
cybersecurity companies.
A jurisdiction clause can therefore determine where an injunction or disclosure order is sought.
14. Oheo Bank v Parker
Case 7: Oheo Bank v Parker [2025] DIFC CA 006
Oheo Bank concerned arbitration and judicial supervision.
The Court considered the relationship between an arbitral award and judicial intervention.
Digital-tort significance
Digital torts sometimes arise from commercial contracts containing arbitration clauses.
For example:
A cybersecurity provider causes loss through negligent security services.
If the contract contains an arbitration clause, the claimant may have to pursue the contractual dispute through arbitration rather than ordinary court proceedings.
The enforcement strategy then becomes:
Digital harm
→ arbitration
→ award
→ recognition
→ execution against assets.
15. DNB Bank v Gulf Eyadah
Case 8: DNB Bank ASA v Gulf Eyadah Corporation & Gulf Navigation Holding PJSC [2015] DIFC CA 007
Although not a digital-tort case, DNB Bank is highly relevant to the enforcement stage.
The DIFC Court of Appeal considered recognition and enforcement of an English judgment.
The case demonstrates how a foreign judgment can be recognised within the DIFC framework and subsequently become enforceable through local mechanisms.
Digital-tort significance
Suppose:
A UAE claimant obtains a judgment abroad for cyber fraud.
The substantive dispute may be digital, but recovery still depends upon the recognition and enforcement system where assets are located.
Thus, DNB Bank supplies an important enforcement model for digital-tort judgments.
16. Nine Key Cases at a Glance
| Case | Digital/cross-border relevance |
|---|---|
| Graciela v Giacobbe [2014] DIFC CFI 027 | IT sabotage, digital evidence and damages |
| Techteryx v Aria [2025] DIFC DEC 001 | Digital-economy litigation, freezing/proprietary relief and disclosure |
| Carmon v Cuenda [2024] DIFC CA 003 | Cross-border enforcement and freezing relief |
| Trafigura v Gupta [2025] DIFC CA 001 | Foreign judgment enforcement and asset preservation |
| Sandra Holding v Al Saleh [2023] DIFC CA 003 | Limits on cross-border interim jurisdiction |
| Sunteck v Al Tamimi [2017] DIFC CFI 048 | Jurisdiction and injunctions |
| Oheo Bank v Parker [2025] DIFC CA 006 | Arbitration and judicial supervision |
| DNB Bank v Gulf Eyadah [2015] DIFC CA 007 | Foreign judgment recognition/enforcement |
17. Digital Tort Categories
A. Cyber Intrusion
Examples:
hacking;
credential theft;
unauthorised access;
malware;
system sabotage.
Graciela v Giacobbe is the principal UAE authority demonstrating civil liability arising from deliberate IT-system interference. (DIFC Courts)
B. Data Misuse
Potential claims can involve:
unauthorised disclosure;
unlawful processing;
misuse of confidential information;
data theft.
The relevant claim may involve several overlapping legal regimes:
civil liability;
data protection;
confidentiality;
contractual obligations;
cybercrime legislation.
C. Online Defamation
Cross-border online publication creates questions concerning:
place of publication;
place of injury;
audience;
claimant's reputation;
defendant's location;
platform location;
applicable law.
The enforcement problem becomes more complex where the defendant has no UAE assets.
D. Digital Fraud
Digital fraud may involve:
phishing;
fraudulent payment instructions;
account takeover;
cryptocurrency transfers;
fake investment platforms.
Civil remedies can include:
damages;
restitution;
proprietary relief;
freezing orders;
disclosure.
E. Digital Asset Misappropriation
Digital assets may be transferred across borders within minutes.
This makes:
freezing + tracing + disclosure
particularly important.
The Techteryx litigation demonstrates the increasing importance of proprietary and freezing relief in sophisticated digital-economy disputes. (DIFC Courts)
18. Cross-Jurisdiction Enforcement Model
A claimant should consider the following sequence.
Step 1 — Identify the digital wrong
Determine whether the conduct constitutes:
negligence;
intentional interference;
fraud;
misuse of data;
defamation;
breach of confidence;
contractual breach.
Step 2 — Identify the jurisdictions
Map:
defendant;
claimant;
server;
cloud provider;
data;
transaction;
damage;
assets.
Step 3 — Preserve evidence
Immediately preserve:
server logs;
IP records;
emails;
metadata;
blockchain records;
screenshots;
forensic images;
access records.
Step 4 — Establish jurisdiction
Determine the legally available forum.
Step 5 — Seek interim relief
Where justified:
freezing order;
proprietary injunction;
preservation order;
disclosure;
anti-suit relief.
Step 6 — Determine applicable law
Analyse conflict-of-laws rules and mandatory legislation.
Step 7 — Obtain judgment or award
Proceed through:
court;
arbitration;
settlement.
Step 8 — Recognition
Recognise the judgment or award where necessary.
Step 9 — Execution
Identify and seize legally reachable assets.
19. Evidence Is Central to Digital Tort Enforcement
Digital torts frequently depend upon electronic evidence.
Important evidence includes:
Technical evidence
IP addresses;
server logs;
authentication records;
firewall records;
system logs;
malware analysis.
Business evidence
invoices;
transaction records;
customer losses;
restoration costs;
business interruption records.
Communication evidence
email;
messaging applications;
internal communications;
platform messages.
Blockchain evidence
wallet addresses;
transaction hashes;
exchange records;
token transfers.
20. Chain of Custody
Digital evidence should be collected in a manner that permits the court to assess:
authenticity;
integrity;
source;
date;
method of collection;
subsequent handling.
This is particularly important in cross-border proceedings because evidence may need to be transferred between:
UAE courts;
foreign courts;
arbitral tribunals;
forensic experts.
21. Cloud Computing Problem
A UAE company may store data using a cloud provider whose infrastructure is distributed across several countries.
Suppose:
UAE company → cloud provider → servers in Europe and Asia → hacker in another country.
A claimant should distinguish:
location of data
from
location of the legal injury
from
location of the defendant
from
location of enforcement assets.
These may all be different.
22. Cross-Border Injunctions
An injunction can be particularly useful in digital disputes because damages may not adequately repair ongoing harm.
Examples:
stop publication;
stop disclosure;
stop access to systems;
preserve digital evidence;
restrain disposal of assets;
prevent continued misuse of confidential information.
But an injunction must be supported by proper jurisdiction.
Sandra Holding demonstrates that the DIFC's injunctive power cannot simply be treated as unlimited worldwide jurisdiction. (DIFC Courts)
23. Worldwide Freezing Orders
Where digital fraud produces movable assets, a worldwide freezing order may become relevant.
For example:
AED 10 million is fraudulently transferred to an overseas cryptocurrency exchange.
The claimant may seek appropriate freezing or proprietary relief where jurisdictional requirements are satisfied.
Carmon and Trafigura demonstrate the significance of this type of cross-border enforcement protection. (DIFC Courts)
24. Proprietary Versus Personal Claims
This distinction is extremely important.
Personal claim
The defendant owes compensation.
Example:
Defendant owes AED 2 million damages.
Proprietary claim
The claimant asserts that a specific asset belongs to it or represents its property.
Example:
Fraudulently transferred cryptocurrency can be traced into a particular wallet.
Proprietary claims can potentially support stronger forms of interim relief where the legal requirements are satisfied.
The Techteryx litigation illustrates the practical significance of proprietary injunctions in complex commercial/digital disputes. (DIFC Courts)
25. Foreign Defendant With No UAE Assets
Suppose:
Defendant lives in Germany and has no assets in the UAE.
A UAE judgment may still have legal value, but practical enforcement requires consideration of the foreign jurisdiction.
The claimant may need:
UAE judgment;
recognition application abroad;
foreign execution;
foreign asset seizure.
Alternatively, if a foreign court has jurisdiction, commencing proceedings there may be considered from the outset.
Therefore:
Jurisdiction should be selected with enforcement in mind, not merely liability.
26. UAE Defendant With Foreign Assets
The reverse situation is also possible.
Suppose:
UAE defendant has assets in Singapore and the UK.
A UAE judgment may need recognition in those countries.
The claimant therefore needs an enforcement map before choosing its litigation strategy.
27. Digital Torts and Arbitration
Not every digital wrong is arbitrable in every circumstance.
Where the claim arises from a contractual relationship, the arbitration agreement must be examined.
For example:
A cloud-service agreement contains a DIAC arbitration clause.
A cybersecurity dispute arising directly from that agreement may potentially fall within the arbitration clause.
However, independent tort claims and mandatory statutory rights require separate analysis.
28. Data Protection and Civil Liability
A digital tort may simultaneously produce:
regulatory liability;
contractual liability;
civil liability;
criminal exposure.
These must be distinguished.
For example:
A company unlawfully transfers personal data overseas.
Possible consequences may arise under:
data-protection legislation;
contract;
civil compensation;
regulatory enforcement.
A claimant should identify the correct cause of action rather than assuming that every data violation automatically produces the same civil remedy.
29. Damages
Under the current UAE civil-law framework, compensation generally focuses on legally recognised loss caused by the wrongful act.
Digital damages may include:
restoration expenses;
investigation costs;
business interruption;
lost profits where legally established;
data-recovery costs;
replacement technology;
reputational harm where recoverable;
other proven consequential losses.
Graciela is particularly useful because the Court awarded substantial damages for IT restoration, emergency infrastructure, investigation and employee time. (DIFC Courts)
30. Causation
Digital claims require a clear causal chain:
Wrongful digital conduct
↓
Technical impact
↓
Operational disruption
↓
Financial loss
↓
Claimed damages
For example:
Hacking → database deletion → three-day shutdown → cancelled transactions → AED 2 million loss.
The claimant must establish the legally relevant connection between the cyber event and the claimed loss.
31. Loss of Data Versus Loss of Profit
The claimant should distinguish:
Direct loss
forensic investigation;
system restoration;
replacement hardware.
Consequential loss
business interruption;
lost transactions;
customer losses.
Speculative loss
hypothetical future business;
unsupported projected profits.
The stronger the evidential connection, the easier it is to establish the recoverable amount.
32. Enforcement Against Banks and Platforms
Digital fraud often involves intermediaries.
For example:
Fraudster
↓
Bank
↓
Exchange
↓
Cryptocurrency wallet
↓
Foreign account
The claimant may need disclosure or preservation orders directed toward relevant intermediaries.
However, an intermediary does not automatically become liable simply because it processed a transaction.
Liability depends upon the applicable cause of action and evidence.
33. Cross-Border Digital Evidence Requests
Evidence can be located outside the UAE.
Possible mechanisms include:
court orders;
cooperation between courts;
procedural requests;
disclosure orders;
expert evidence;
applicable international cooperation mechanisms.
The claimant should identify where the evidence is located before seeking an order.
34. Platform Jurisdiction
Social-media and online-platform disputes create an additional layer.
A platform might be:
incorporated abroad;
operating in the UAE;
hosting data abroad;
serving UAE users.
The claimant must distinguish:
jurisdiction over the wrongdoer
from
jurisdiction over the platform.
They are not necessarily identical.
35. Enforcement Optimisation Strategy
A claimant should use the following model:
1. Forum mapping
Identify every plausible court.
2. Asset mapping
Identify assets and ownership.
3. Evidence mapping
Identify where technical evidence is located.
4. Law mapping
Determine potentially applicable substantive laws.
5. Interim-relief mapping
Determine where preservation/freezing orders can realistically operate.
6. Judgment mapping
Determine where the final judgment can be recognised.
7. Execution mapping
Determine where actual asset seizure can occur.
36. Common Mistakes
Mistake 1 — Focusing only on the hacker's location
The defendant's location is only one jurisdictional connection.
Mistake 2 — Ignoring asset location
A judgment is much less useful if the enforcement route is not planned.
Mistake 3 — Failing to preserve electronic evidence
Digital evidence can disappear rapidly.
Mistake 4 — Assuming a UAE order automatically binds foreign parties
Foreign enforcement may require recognition or other procedures.
Mistake 5 — Assuming DIFC jurisdiction is unlimited
Sandra Holding demonstrates the importance of jurisdictional boundaries. (DIFC Courts)
Mistake 6 — Treating every digital dispute as a tort
Contract, data-protection, confidentiality and other causes of action may also be relevant.
Mistake 7 — Treating a company group as one legal entity
Separate corporate personality must be respected unless a recognised legal basis permits otherwise.
37. Practical Example
Assume:
A Dubai company suffers a cyberattack.
The attacker is in another country.
The servers are partly in the UAE and partly overseas.
AED 5 million is transferred through an international payment network.
The proceeds are converted into cryptocurrency.
The attacker holds real estate in Dubai.
Step 1
Preserve forensic evidence.
Step 2
Identify the attacker and transaction chain.
Step 3
Establish the appropriate UAE jurisdiction.
Step 4
Seek appropriate interim proprietary/freezing relief if the legal requirements are satisfied.
Step 5
Trace the money.
Step 6
Obtain judgment or award.
Step 7
Recognise the judgment where required.
Step 8
Execute against the Dubai property.
Step 9
Use foreign recognition mechanisms for assets outside the UAE.
This demonstrates why digital-tort enforcement is simultaneously a tort problem, jurisdiction problem, evidence problem and asset-recovery problem.
38. Case-Law Principles
| Principle | Case |
|---|---|
| Digital system sabotage can generate substantial civil damages | Graciela v Giacobbe |
| Digital disputes may require proprietary and freezing relief | Techteryx v Aria |
| Foreign judgment enforcement can support interim protection | Carmon v Cuenda |
| Cross-border asset preservation can support enforcement | Trafigura v Gupta |
| DIFC interim jurisdiction has limits | Sandra Holding v Al Saleh |
| Jurisdiction clauses matter to injunction applications | Sunteck v Al Tamimi |
| Arbitration may determine contractual technology disputes | Oheo Bank v Parker |
| Foreign judgments can be recognised and enforced through appropriate mechanisms | DNB Bank v Gulf Eyadah |
39. Examination-Style Flowchart
Digital Tort
↓
Identify wrongful conduct
↓
Identify claimant + defendant
↓
Map server/data/device/transaction locations
↓
Determine jurisdiction
↓
Determine applicable law
↓
Preserve electronic evidence
↓
Seek interim relief if justified
↓
Obtain judgment/award
↓
Recognition
↓
Asset tracing
↓
Execution
↓
Recovery
40. Conclusion
UAE cross-jurisdiction enforcement of digital torts requires a combination of civil liability principles, jurisdictional analysis, electronic evidence, interim remedies, recognition and execution mechanisms.
The most important principles are:
Digital wrongdoing is not confined to the physical location of the wrongdoer.
The location of the affected system, claimant, damage and assets can all be legally significant.
Jurisdiction must be established before seeking cross-border injunctive relief.
Electronic evidence must be preserved and authenticated carefully.
Freezing and proprietary relief can be critical where digital assets or fraud proceeds are rapidly movable.
A UAE judgment may require recognition abroad before foreign assets can be executed against.
Foreign judgments may likewise require recognition before UAE enforcement.
Arbitration clauses can substantially alter the dispute-resolution route.
DIFC jurisdiction should not be assumed merely because a dispute has an international or digital character.
The enforcement strategy should be designed from the beginning of the digital-tort claim.
Graciela v Giacobbe provides the clearest UAE civil authority on actual IT-system interference and compensatory damages. Techteryx, Carmon, and Trafigura demonstrate the increasingly important role of proprietary, freezing and cross-border enforcement remedies. Sandra Holding supplies an important jurisdictional limitation: interim powers cannot simply be treated as unlimited worldwide jurisdiction. (DIFC Courts)
Current-law caution: Graciela and several other older authorities were decided under earlier DIFC legislation. Current UAE onshore civil liability is governed by the 2025 Civil Transactions Law effective 1 June 2026, while DIFC and ADGM have their own statutory regimes. DIFC judgments should therefore be distinguished from binding onshore UAE authorities.

comments