Civil Law And Uae Cross-Jurisdiction Enforcement Of Digital Torts .

Civil Law and UAE Cross-Jurisdiction Enforcement of Digital Torts

1. Introduction

Cross-jurisdiction enforcement of digital torts concerns situations where an online or technology-related harmful act occurs in one jurisdiction, affects a person or business in another, and the defendant, evidence, platform, or assets are located somewhere else.

Examples include:

cyberattacks;

unauthorised access to computer systems;

online defamation;

digital fraud;

misuse of personal data;

interference with websites or databases;

cryptocurrency-related wrongdoing;

online intellectual-property infringement;

malicious publication;

digital business interruption;

cross-border privacy violations.

The UAE presents a particularly interesting environment because enforcement may involve UAE onshore courts, DIFC Courts, ADGM Courts, foreign courts, arbitration, and international enforcement mechanisms.

The central problem is:

How can a claimant obtain a civil remedy for a digital wrong occurring across jurisdictions and then make that remedy effective against the defendant or assets in another jurisdiction?

2. What Is a Digital Tort?

A digital tort is a civil wrong committed through, against, or substantially involving digital technology.

It can involve:

Digital wrongPossible civil consequence
HackingCompensation
Data destructionProperty/economic damages
Data misusePrivacy/data-related remedies
Online defamationDamages/injunction
Digital fraudRestitution/compensation
Website interferenceInjunction/damages
Cyber extortionCompensation/restoration
Unauthorised accessDamages/injunctive relief
Digital asset interferenceProprietary/injunctive relief
Trade-secret leakageDamages/injunction

The UAE's current general civil-liability framework is contained principally in the 2025 Civil Transactions Law, effective from 1 June 2026, while special legislation may apply depending on the digital wrong involved.

3. Why Cross-Jurisdiction Digital Torts Are Difficult

Digital torts create unusual jurisdictional problems because a single act can have multiple geographical connections.

For example:

A person in Country A hacks a UAE company's server located in Country B, uses a cloud service in Country C, causes financial losses to a DIFC company, and transfers the resulting funds to Country D.

Potential questions include:

Where did the tort occur?

Where was the damage suffered?

Which court has jurisdiction?

Which law governs?

Where should evidence be collected?

Where can an injunction operate?

Where are the defendant's assets?

How can a UAE judgment be enforced abroad?

4. The Enforcement Chain

A cross-border digital-tort claim can be represented as:

Digital wrong

Identification of defendant

Jurisdiction

Evidence preservation

Civil judgment/injunction

Recognition in foreign jurisdiction

Asset identification

Execution

Compensation

The weakness of any stage can undermine the entire claim.

5. First Principle: Establish Jurisdiction

Before enforcement, the claimant must establish jurisdiction.

Possible jurisdictional connections include:

defendant's domicile;

defendant's business presence;

location of the affected business;

location of the computer system;

place where damage occurred;

contractual jurisdiction clause;

DIFC/ADGM connection;

location of relevant assets.

Digital activity makes this particularly complicated because the physical location of the computer used by the wrongdoer may not be the location where the legal injury occurred.

6. Territoriality and Digital Harm

Traditional tort law often relies on territorial concepts.

Digital torts challenge that model.

Consider:

A defamatory post is uploaded in London, viewed in Dubai, Singapore and New York, and causes financial loss to a UAE company.

Potentially relevant jurisdictions include:

England;

UAE;

DIFC;

Singapore;

United States.

The court therefore needs to identify the legally relevant connection rather than simply asking where the keyboard was located.

7. Choice of Law

After jurisdiction comes applicable law.

The parties may argue for:

UAE law;

DIFC law;

ADGM law;

foreign tort law;

contractual law;

mandatory data-protection legislation.

A cross-border digital tort can therefore involve:

Forum law ≠ necessarily substantive law ≠ enforcement law.

For example:

A UAE court could potentially hear a dispute involving foreign conduct while having to consider foreign-law issues concerning particular aspects of the claim.

8. Graciela Limited v Giacobbe

Case 1: Graciela Limited v Giacobbe [2014] DIFC CFI 027

This is one of the most important UAE digital-tort authorities.

Graciela's IT system was deliberately sabotaged.

The system included:

computers in the DIFC;

equipment in a DIFC data centre;

equipment located at other locations around the world;

remote internet access.

The defendant was a former senior IT employee.

The DIFC Court found, on the balance of probabilities, that he had deliberately interfered with the claimant's IT system. The Court awarded USD 690,533 in compensatory damages. The damages included system restoration, emergency servers, investigation costs and employee time. (DIFC Courts)

Cross-jurisdiction significance

The case demonstrates that a digital tort can involve:

geographically dispersed infrastructure;

remote access;

electronic evidence;

forensic analysis;

causation;

economic loss.

The location of the digital infrastructure was relevant even though the wrongful conduct could be performed remotely.

Enforcement lesson

A digital-tort claimant should identify every legally significant location:

attacker → device → server → data → business → loss → assets.

That geographical map can determine both jurisdiction and enforcement strategy.

9. Techteryx Ltd v Aria Commodities DMCC

Case 2: Techteryx Ltd v Aria Commodities DMCC & Others [2025] DIFC DEC 001

This is a particularly significant modern case because it was handled by the DIFC Digital Economy Court.

The proceedings involved proprietary and freezing injunctions and extensive disclosure issues concerning transactions and assets.

The Court applied the established principles for freezing and proprietary relief, including the requirement of a sufficiently arguable case and consideration of the risk that conduct could prejudice enforcement. (DIFC Courts)

The proceedings also involved applications concerning the use of disclosed information in related proceedings in other jurisdictions. (DIFC Courts)

Digital-tort relevance

The case demonstrates how modern digital/commercial disputes may require:

cross-border disclosure;

proprietary relief;

freezing orders;

investigation of transactions;

use of information in foreign proceedings.

Enforcement lesson

In digital disputes, preserving the economic value of the eventual judgment can be as important as proving liability.

10. Carmon v Cuenda

Case 3: Carmon Reestrutura-Engenharia e Serviços Técnicos Especiais (SU) LDA v Antonio Joao Catete Lopes Cuenda [2024] DIFC CA 003

Carmon concerned the DIFC Court's power to provide interim protection supporting the enforcement of foreign judgments.

The Court considered the relationship between:

foreign judgment enforcement;

interim injunctions;

freezing relief;

the enforcement principle.

The judgment recognised that the DIFC Courts have powers to grant appropriate interim relief connected with their enforcement jurisdiction. (DIFC Courts)

Digital-tort relevance

Suppose a cyber-fraud defendant has moved proceeds from the UAE to another jurisdiction.

The claimant may need:

judgment or prospective judgment;

asset-preservation relief;

disclosure;

recognition;

enforcement.

Carmon illustrates the importance of interim protection before final recovery.

11. Trafigura v Gupta

Case 4: Trafigura PTE Ltd & Trafigura India PTV Ltd v Prateek Gupta & Ginni Gupta [2025] DIFC CA 001

Trafigura is significant for cross-border freezing relief and enforcement.

The case examined the relationship between the DIFC Court's enforcement jurisdiction and its power to issue freezing relief.

The Court considered the enforcement of foreign judgments and the circumstances in which interim relief may protect the effectiveness of future enforcement. (DIFC Courts)

Digital-tort application

This reasoning can become relevant where digital wrongdoing produces rapidly transferable assets.

For example:

cyber fraud → cryptocurrency conversion → offshore account → foreign asset.

A claimant may need to preserve the asset position before the final enforcement stage.

12. Sandra Holding Ltd v Al Saleh

Case 5: Sandra Holding Ltd & Nuri Musaed Al Saleh v Fawzi Musaed Al Saleh & Others [2023] DIFC CA 003

Sandra Holding is important for understanding the limits of DIFC jurisdiction concerning interim relief in support of foreign proceedings.

The Court considered whether the DIFC Courts could grant broad interim relief against persons without a sufficient DIFC jurisdictional connection.

The Court emphasised that the DIFC Court's jurisdiction cannot simply be expanded indefinitely through the general availability of injunctive relief. (DIFC Courts)

Digital-tort significance

This is particularly important for internet disputes.

A claimant should not assume:

"The defendant is somewhere in the world and the harm involves the UAE, therefore the DIFC Court can automatically issue a worldwide injunction."

Jurisdiction must first be established.

13. Sunteck Lifestyles Ltd v Al Tamimi

Case 6: Sunteck Lifestyles Limited v Al Tamimi & Company Limited & Grand Valley General Trading LLC [2017] DIFC CFI 048

Sunteck concerned an injunction relating to documents held by a DIFC entity.

The Court examined jurisdiction despite a contractual reference to the "courts of the Emirate of Dubai."

The judgment considered earlier DIFC authorities concerning interpretation of jurisdiction clauses, including National Bonds v Taaleem, Corinth Pipeworks v Barclays Bank, and Injazat v DWS. (DIFC Courts)

Digital-tort significance

Digital disputes frequently involve contracts between:

platform operators;

technology vendors;

cloud providers;

data processors;

cybersecurity companies.

A jurisdiction clause can therefore determine where an injunction or disclosure order is sought.

14. Oheo Bank v Parker

Case 7: Oheo Bank v Parker [2025] DIFC CA 006

Oheo Bank concerned arbitration and judicial supervision.

The Court considered the relationship between an arbitral award and judicial intervention.

Digital-tort significance

Digital torts sometimes arise from commercial contracts containing arbitration clauses.

For example:

A cybersecurity provider causes loss through negligent security services.

If the contract contains an arbitration clause, the claimant may have to pursue the contractual dispute through arbitration rather than ordinary court proceedings.

The enforcement strategy then becomes:

Digital harm

arbitration

award

recognition

execution against assets.

15. DNB Bank v Gulf Eyadah

Case 8: DNB Bank ASA v Gulf Eyadah Corporation & Gulf Navigation Holding PJSC [2015] DIFC CA 007

Although not a digital-tort case, DNB Bank is highly relevant to the enforcement stage.

The DIFC Court of Appeal considered recognition and enforcement of an English judgment.

The case demonstrates how a foreign judgment can be recognised within the DIFC framework and subsequently become enforceable through local mechanisms.

Digital-tort significance

Suppose:

A UAE claimant obtains a judgment abroad for cyber fraud.

The substantive dispute may be digital, but recovery still depends upon the recognition and enforcement system where assets are located.

Thus, DNB Bank supplies an important enforcement model for digital-tort judgments.

16. Nine Key Cases at a Glance

CaseDigital/cross-border relevance
Graciela v Giacobbe [2014] DIFC CFI 027IT sabotage, digital evidence and damages
Techteryx v Aria [2025] DIFC DEC 001Digital-economy litigation, freezing/proprietary relief and disclosure
Carmon v Cuenda [2024] DIFC CA 003Cross-border enforcement and freezing relief
Trafigura v Gupta [2025] DIFC CA 001Foreign judgment enforcement and asset preservation
Sandra Holding v Al Saleh [2023] DIFC CA 003Limits on cross-border interim jurisdiction
Sunteck v Al Tamimi [2017] DIFC CFI 048Jurisdiction and injunctions
Oheo Bank v Parker [2025] DIFC CA 006Arbitration and judicial supervision
DNB Bank v Gulf Eyadah [2015] DIFC CA 007Foreign judgment recognition/enforcement

17. Digital Tort Categories

A. Cyber Intrusion

Examples:

hacking;

credential theft;

unauthorised access;

malware;

system sabotage.

Graciela v Giacobbe is the principal UAE authority demonstrating civil liability arising from deliberate IT-system interference. (DIFC Courts)

B. Data Misuse

Potential claims can involve:

unauthorised disclosure;

unlawful processing;

misuse of confidential information;

data theft.

The relevant claim may involve several overlapping legal regimes:

civil liability;

data protection;

confidentiality;

contractual obligations;

cybercrime legislation.

C. Online Defamation

Cross-border online publication creates questions concerning:

place of publication;

place of injury;

audience;

claimant's reputation;

defendant's location;

platform location;

applicable law.

The enforcement problem becomes more complex where the defendant has no UAE assets.

D. Digital Fraud

Digital fraud may involve:

phishing;

fraudulent payment instructions;

account takeover;

cryptocurrency transfers;

fake investment platforms.

Civil remedies can include:

damages;

restitution;

proprietary relief;

freezing orders;

disclosure.

E. Digital Asset Misappropriation

Digital assets may be transferred across borders within minutes.

This makes:

freezing + tracing + disclosure

particularly important.

The Techteryx litigation demonstrates the increasing importance of proprietary and freezing relief in sophisticated digital-economy disputes. (DIFC Courts)

18. Cross-Jurisdiction Enforcement Model

A claimant should consider the following sequence.

Step 1 — Identify the digital wrong

Determine whether the conduct constitutes:

negligence;

intentional interference;

fraud;

misuse of data;

defamation;

breach of confidence;

contractual breach.

Step 2 — Identify the jurisdictions

Map:

defendant;

claimant;

server;

cloud provider;

data;

transaction;

damage;

assets.

Step 3 — Preserve evidence

Immediately preserve:

server logs;

IP records;

emails;

metadata;

blockchain records;

screenshots;

forensic images;

access records.

Step 4 — Establish jurisdiction

Determine the legally available forum.

Step 5 — Seek interim relief

Where justified:

freezing order;

proprietary injunction;

preservation order;

disclosure;

anti-suit relief.

Step 6 — Determine applicable law

Analyse conflict-of-laws rules and mandatory legislation.

Step 7 — Obtain judgment or award

Proceed through:

court;

arbitration;

settlement.

Step 8 — Recognition

Recognise the judgment or award where necessary.

Step 9 — Execution

Identify and seize legally reachable assets.

19. Evidence Is Central to Digital Tort Enforcement

Digital torts frequently depend upon electronic evidence.

Important evidence includes:

Technical evidence

IP addresses;

server logs;

authentication records;

firewall records;

system logs;

malware analysis.

Business evidence

invoices;

transaction records;

customer losses;

restoration costs;

business interruption records.

Communication evidence

email;

messaging applications;

internal communications;

platform messages.

Blockchain evidence

wallet addresses;

transaction hashes;

exchange records;

token transfers.

20. Chain of Custody

Digital evidence should be collected in a manner that permits the court to assess:

authenticity;

integrity;

source;

date;

method of collection;

subsequent handling.

This is particularly important in cross-border proceedings because evidence may need to be transferred between:

UAE courts;

foreign courts;

arbitral tribunals;

forensic experts.

21. Cloud Computing Problem

A UAE company may store data using a cloud provider whose infrastructure is distributed across several countries.

Suppose:

UAE company → cloud provider → servers in Europe and Asia → hacker in another country.

A claimant should distinguish:

location of data

from

location of the legal injury

from

location of the defendant

from

location of enforcement assets.

These may all be different.

22. Cross-Border Injunctions

An injunction can be particularly useful in digital disputes because damages may not adequately repair ongoing harm.

Examples:

stop publication;

stop disclosure;

stop access to systems;

preserve digital evidence;

restrain disposal of assets;

prevent continued misuse of confidential information.

But an injunction must be supported by proper jurisdiction.

Sandra Holding demonstrates that the DIFC's injunctive power cannot simply be treated as unlimited worldwide jurisdiction. (DIFC Courts)

23. Worldwide Freezing Orders

Where digital fraud produces movable assets, a worldwide freezing order may become relevant.

For example:

AED 10 million is fraudulently transferred to an overseas cryptocurrency exchange.

The claimant may seek appropriate freezing or proprietary relief where jurisdictional requirements are satisfied.

Carmon and Trafigura demonstrate the significance of this type of cross-border enforcement protection. (DIFC Courts)

24. Proprietary Versus Personal Claims

This distinction is extremely important.

Personal claim

The defendant owes compensation.

Example:

Defendant owes AED 2 million damages.

Proprietary claim

The claimant asserts that a specific asset belongs to it or represents its property.

Example:

Fraudulently transferred cryptocurrency can be traced into a particular wallet.

Proprietary claims can potentially support stronger forms of interim relief where the legal requirements are satisfied.

The Techteryx litigation illustrates the practical significance of proprietary injunctions in complex commercial/digital disputes. (DIFC Courts)

25. Foreign Defendant With No UAE Assets

Suppose:

Defendant lives in Germany and has no assets in the UAE.

A UAE judgment may still have legal value, but practical enforcement requires consideration of the foreign jurisdiction.

The claimant may need:

UAE judgment;

recognition application abroad;

foreign execution;

foreign asset seizure.

Alternatively, if a foreign court has jurisdiction, commencing proceedings there may be considered from the outset.

Therefore:

Jurisdiction should be selected with enforcement in mind, not merely liability.

26. UAE Defendant With Foreign Assets

The reverse situation is also possible.

Suppose:

UAE defendant has assets in Singapore and the UK.

A UAE judgment may need recognition in those countries.

The claimant therefore needs an enforcement map before choosing its litigation strategy.

27. Digital Torts and Arbitration

Not every digital wrong is arbitrable in every circumstance.

Where the claim arises from a contractual relationship, the arbitration agreement must be examined.

For example:

A cloud-service agreement contains a DIAC arbitration clause.

A cybersecurity dispute arising directly from that agreement may potentially fall within the arbitration clause.

However, independent tort claims and mandatory statutory rights require separate analysis.

28. Data Protection and Civil Liability

A digital tort may simultaneously produce:

regulatory liability;

contractual liability;

civil liability;

criminal exposure.

These must be distinguished.

For example:

A company unlawfully transfers personal data overseas.

Possible consequences may arise under:

data-protection legislation;

contract;

civil compensation;

regulatory enforcement.

A claimant should identify the correct cause of action rather than assuming that every data violation automatically produces the same civil remedy.

29. Damages

Under the current UAE civil-law framework, compensation generally focuses on legally recognised loss caused by the wrongful act.

Digital damages may include:

restoration expenses;

investigation costs;

business interruption;

lost profits where legally established;

data-recovery costs;

replacement technology;

reputational harm where recoverable;

other proven consequential losses.

Graciela is particularly useful because the Court awarded substantial damages for IT restoration, emergency infrastructure, investigation and employee time. (DIFC Courts)

30. Causation

Digital claims require a clear causal chain:

Wrongful digital conduct

Technical impact

Operational disruption

Financial loss

Claimed damages

For example:

Hacking → database deletion → three-day shutdown → cancelled transactions → AED 2 million loss.

The claimant must establish the legally relevant connection between the cyber event and the claimed loss.

31. Loss of Data Versus Loss of Profit

The claimant should distinguish:

Direct loss

forensic investigation;

system restoration;

replacement hardware.

Consequential loss

business interruption;

lost transactions;

customer losses.

Speculative loss

hypothetical future business;

unsupported projected profits.

The stronger the evidential connection, the easier it is to establish the recoverable amount.

32. Enforcement Against Banks and Platforms

Digital fraud often involves intermediaries.

For example:

Fraudster

Bank

Exchange

Cryptocurrency wallet

Foreign account

The claimant may need disclosure or preservation orders directed toward relevant intermediaries.

However, an intermediary does not automatically become liable simply because it processed a transaction.

Liability depends upon the applicable cause of action and evidence.

33. Cross-Border Digital Evidence Requests

Evidence can be located outside the UAE.

Possible mechanisms include:

court orders;

cooperation between courts;

procedural requests;

disclosure orders;

expert evidence;

applicable international cooperation mechanisms.

The claimant should identify where the evidence is located before seeking an order.

34. Platform Jurisdiction

Social-media and online-platform disputes create an additional layer.

A platform might be:

incorporated abroad;

operating in the UAE;

hosting data abroad;

serving UAE users.

The claimant must distinguish:

jurisdiction over the wrongdoer

from

jurisdiction over the platform.

They are not necessarily identical.

35. Enforcement Optimisation Strategy

A claimant should use the following model:

1. Forum mapping

Identify every plausible court.

2. Asset mapping

Identify assets and ownership.

3. Evidence mapping

Identify where technical evidence is located.

4. Law mapping

Determine potentially applicable substantive laws.

5. Interim-relief mapping

Determine where preservation/freezing orders can realistically operate.

6. Judgment mapping

Determine where the final judgment can be recognised.

7. Execution mapping

Determine where actual asset seizure can occur.

36. Common Mistakes

Mistake 1 — Focusing only on the hacker's location

The defendant's location is only one jurisdictional connection.

Mistake 2 — Ignoring asset location

A judgment is much less useful if the enforcement route is not planned.

Mistake 3 — Failing to preserve electronic evidence

Digital evidence can disappear rapidly.

Mistake 4 — Assuming a UAE order automatically binds foreign parties

Foreign enforcement may require recognition or other procedures.

Mistake 5 — Assuming DIFC jurisdiction is unlimited

Sandra Holding demonstrates the importance of jurisdictional boundaries. (DIFC Courts)

Mistake 6 — Treating every digital dispute as a tort

Contract, data-protection, confidentiality and other causes of action may also be relevant.

Mistake 7 — Treating a company group as one legal entity

Separate corporate personality must be respected unless a recognised legal basis permits otherwise.

37. Practical Example

Assume:

A Dubai company suffers a cyberattack.

The attacker is in another country.

The servers are partly in the UAE and partly overseas.

AED 5 million is transferred through an international payment network.

The proceeds are converted into cryptocurrency.

The attacker holds real estate in Dubai.

Step 1

Preserve forensic evidence.

Step 2

Identify the attacker and transaction chain.

Step 3

Establish the appropriate UAE jurisdiction.

Step 4

Seek appropriate interim proprietary/freezing relief if the legal requirements are satisfied.

Step 5

Trace the money.

Step 6

Obtain judgment or award.

Step 7

Recognise the judgment where required.

Step 8

Execute against the Dubai property.

Step 9

Use foreign recognition mechanisms for assets outside the UAE.

This demonstrates why digital-tort enforcement is simultaneously a tort problem, jurisdiction problem, evidence problem and asset-recovery problem.

38. Case-Law Principles

PrincipleCase
Digital system sabotage can generate substantial civil damagesGraciela v Giacobbe
Digital disputes may require proprietary and freezing reliefTechteryx v Aria
Foreign judgment enforcement can support interim protectionCarmon v Cuenda
Cross-border asset preservation can support enforcementTrafigura v Gupta
DIFC interim jurisdiction has limitsSandra Holding v Al Saleh
Jurisdiction clauses matter to injunction applicationsSunteck v Al Tamimi
Arbitration may determine contractual technology disputesOheo Bank v Parker
Foreign judgments can be recognised and enforced through appropriate mechanismsDNB Bank v Gulf Eyadah

39. Examination-Style Flowchart

Digital Tort

Identify wrongful conduct

Identify claimant + defendant

Map server/data/device/transaction locations

Determine jurisdiction

Determine applicable law

Preserve electronic evidence

Seek interim relief if justified

Obtain judgment/award

Recognition

Asset tracing

Execution

Recovery

40. Conclusion

UAE cross-jurisdiction enforcement of digital torts requires a combination of civil liability principles, jurisdictional analysis, electronic evidence, interim remedies, recognition and execution mechanisms.

The most important principles are:

Digital wrongdoing is not confined to the physical location of the wrongdoer.

The location of the affected system, claimant, damage and assets can all be legally significant.

Jurisdiction must be established before seeking cross-border injunctive relief.

Electronic evidence must be preserved and authenticated carefully.

Freezing and proprietary relief can be critical where digital assets or fraud proceeds are rapidly movable.

A UAE judgment may require recognition abroad before foreign assets can be executed against.

Foreign judgments may likewise require recognition before UAE enforcement.

Arbitration clauses can substantially alter the dispute-resolution route.

DIFC jurisdiction should not be assumed merely because a dispute has an international or digital character.

The enforcement strategy should be designed from the beginning of the digital-tort claim.

Graciela v Giacobbe provides the clearest UAE civil authority on actual IT-system interference and compensatory damages. Techteryx, Carmon, and Trafigura demonstrate the increasingly important role of proprietary, freezing and cross-border enforcement remedies. Sandra Holding supplies an important jurisdictional limitation: interim powers cannot simply be treated as unlimited worldwide jurisdiction. (DIFC Courts)

Current-law caution: Graciela and several other older authorities were decided under earlier DIFC legislation. Current UAE onshore civil liability is governed by the 2025 Civil Transactions Law effective 1 June 2026, while DIFC and ADGM have their own statutory regimes. DIFC judgments should therefore be distinguished from binding onshore UAE authorities.

LEAVE A COMMENT