Civil Law And Uae Data Breach Class Action Strategy .
Civil Law and UAE Data Breach Class Action Strategy
1. Introduction
A data-breach class action strategy in the UAE requires a different approach from the U.S.-style class-action model.
The first question is not simply whether many people suffered a data breach. It is:
What procedural mechanism can bring those affected persons before the competent UAE court, and what common legal and factual issues can properly be determined together?
For onshore UAE litigation, the practical strategy is generally built around individual civil claims, joinder/consolidation where procedurally available, coordinated evidence and common legal issues, rather than assuming that a U.S.-style opt-out class action automatically exists.
The position is different in the DIFC, where the Rules of the DIFC Courts expressly contain representative-party and Group Litigation Order (GLO) mechanisms. Part 20 permits claims involving persons with the same interest to proceed through representative parties and separately provides a group-register procedure with common and individual issues. (DIFC Courts)
The substantive data-protection framework also differs. The mainland is principally governed by Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL), while the DIFC and ADGM have separate regimes. (Chambers Practice Guides)
2. What Is a Data-Breach Class Action?
A data-breach group claim arises where one security incident potentially affects numerous individuals.
For example:
A UAE company suffers a ransomware attack and the attacker obtains the names, Emirates ID information, telephone numbers, email addresses and financial information of 500,000 customers.
Possible affected persons may seek:
compensation;
declaration of legal responsibility;
deletion or correction of unlawfully retained information;
injunctions;
security improvements;
preservation of evidence;
disclosure;
notification-related relief;
compensation for financial loss;
compensation for proven non-economic harm where legally available.
The difficulty is that the existence of a common data breach does not necessarily mean every claimant suffered the same legally compensable damage.
3. The Three-Layer UAE Strategy
A sophisticated UAE data-breach group strategy should normally separate three questions:
Layer 1 — Common liability
Was there:
unlawful processing?
inadequate security?
unauthorised disclosure?
contractual breach?
negligence or other civil wrong?
breach by a controller or processor?
Layer 2 — Common causation
Did the defendant's conduct cause the relevant data exposure?
Layer 3 — Individual damage
What did each affected person actually lose?
This can be represented as:
Common breach
↓
Common questions of law/fact
↓
Group/representative procedure where available
↓
Individual damage assessment where necessary
This distinction is crucial because proving that 10,000 records were exposed does not automatically prove that every one of the 10,000 persons suffered an identical monetary loss.
4. Current UAE Data-Protection Framework
A. Mainland UAE
The principal federal legislation is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data.
It establishes principles concerning:
lawful processing;
consent and other legal bases;
transparency;
purpose limitation;
data minimisation;
accuracy;
security;
data-subject rights;
controllers;
processors;
cross-border transfers;
data protection officers in relevant circumstances.
The PDPL operates alongside other legislation, including:
Civil Transactions Law;
Cybercrimes Law;
Electronic Transactions and Trust Services Law;
consumer-protection legislation;
sector-specific banking rules;
health-data rules;
contractual obligations.
The PDPL does not create a straightforward UAE equivalent of the U.S. GDPR/CCPA-style statutory damages class action. Recent academic analysis also notes that the PDPL does not contain an express standalone compensation provision equivalent to GDPR Article 82, meaning that civil compensation generally requires analysis under the applicable general civil-liability framework. (Springer)
5. DIFC Data-Breach Litigation
The DIFC is particularly important for a group litigation strategy because its procedural framework expressly accommodates group claims.
Part 20
Under DIFC Rule 20.35, where more than one person has the same interest in a claim:
the claim may be commenced by one or more representative persons; or
the court may order continuation through representative parties.
Rule 20.38 provides that, unless the court directs otherwise, a judgment in such representative proceedings binds the represented persons, although enforcement by or against a non-party represented person requires court permission. (DIFC Courts)
6. Group Litigation Orders
DIFC Part 20 also provides a more structured Group Litigation Order (GLO) procedure.
The court can establish a group register for claims raising common or related issues.
Case management can include:
identifying common issues;
identifying individual issues;
selecting test claims;
appointing lead legal representatives;
setting a deadline for joining the group;
requiring Group Particulars of Claim;
determining common questions first;
subsequently resolving individual questions.
The current DIFC Rules expressly contemplate both test claims and separate determination of common and individual issues. (DIFC Courts)
This makes the DIFC procedural model particularly relevant to a large-scale data breach.
7. Why a Data Breach Can Be Suitable for Group Litigation
A data breach may produce substantial common questions.
Common questions
For example:
Did the defendant control the relevant data?
Was the claimant's data processed?
Did the security incident occur?
When did the breach occur?
What data was exposed?
Was the defendant responsible?
Were appropriate technical safeguards implemented?
Did the defendant comply with its contractual obligations?
Was a processor involved?
Was the processor properly supervised?
These questions may be common to thousands of claimants.
8. Individual Questions
Other issues may remain claimant-specific.
For example:
Was the claimant's record actually accessed?
What category of data was exposed?
Did the claimant suffer identity theft?
Did the claimant incur financial loss?
Was a fraudulent transaction caused by the breach?
Did the claimant incur credit-monitoring expenses?
Did the claimant suffer a particular privacy injury?
Did the claimant mitigate the loss?
Therefore:
Common liability does not necessarily mean identical damages.
A good litigation strategy should therefore avoid presenting every claimant's damages as automatically identical.
9. Identifying the Correct Defendant
A data breach can involve several entities:
Data subject
→ controller
→ processor
→ sub-processor
→ cloud provider
→ cybersecurity provider
→ payment processor
→ authentication provider
→ insurer
Potential defendants should be analysed separately.
The fact that a company processed the information does not automatically mean that it caused the breach.
The claimant must establish the appropriate legal basis for liability.
10. Controller and Processor Analysis
The first strategic task is to determine:
Controller
Who determined:
why the data was processed;
what data was collected;
how it was used;
retention purposes;
disclosure arrangements?
Processor
Who processed data on behalf of the controller?
Subprocessor
Who actually operated:
cloud infrastructure;
databases;
applications;
payment systems;
storage;
security tools?
This is important because a sophisticated data-breach claim may involve multiple contractual and statutory relationships.
11. Contractual Cause of Action
A data-breach claim may arise from a contract.
For example:
A bank's customer agreement contains confidentiality and cybersecurity obligations.
If inadequate protection causes disclosure, the claimant may formulate a contractual claim based upon:
breach of confidentiality;
breach of express security obligations;
breach of data-processing obligations;
breach of implied obligations where legally recognised;
consequential financial loss.
The claimant must then establish:
contract → obligation → breach → causation → damage.
12. Tort / Civil Wrong Analysis
A separate route may arise under general UAE civil-liability principles.
The current Civil Transactions Law provides a general framework for liability arising from harmful acts.
A data breach can potentially involve:
unlawful interference;
privacy-related harm;
financial loss;
reputational harm;
loss caused by misuse of information;
costs incurred in responding to the breach.
However, the precise cause of action depends upon the facts and applicable law.
13. Criminal-Civil Interaction
A serious cyberattack may produce two parallel dimensions:
Criminal/regulatory
Authorities may investigate:
unauthorised access;
interception;
misuse of data;
cybercrime;
unlawful disclosure.
Civil
Affected persons may pursue:
compensation;
restitution;
injunctions;
deletion;
preservation;
other civil remedies.
A criminal investigation therefore does not automatically replace a civil claim.
Nor does the existence of a criminal offence automatically establish the amount of civil compensation.
14. Evidence Strategy
Evidence is often the most important part of a data-breach group action.
The claimant should seek to preserve:
server logs;
access logs;
firewall logs;
authentication records;
database logs;
cloud records;
endpoint data;
email records;
security alerts;
incident-response reports;
forensic images;
penetration-test reports;
vulnerability assessments;
cybersecurity policies;
employee access records;
processor contracts;
data-processing agreements;
incident-response communications.
15. Why Forensic Evidence Matters
A defendant may argue:
“A vulnerability existed, but there is no proof that the claimant's information was actually accessed.”
That creates an important distinction:
Security vulnerability ≠ proven data access
and:
data access ≠ proven financial damage.
The claimant therefore needs a forensic methodology capable of establishing:
attack → system compromise → data access → relevant individual → resulting harm.
16. Case Law 1 — Graciela Limited v Giacobbe
Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the most useful UAE/DIFC technology-related civil authorities.
The claimant's IT infrastructure was deliberately sabotaged by a former employee. The court relied heavily upon:
forensic evidence;
event logs;
expert analysis;
system architecture;
access credentials;
circumstantial evidence.
The court ultimately awarded USD 690,533 for system restoration, investigation, emergency servers and employee time associated with the incident. (DIFC Courts)
Relevance to group data litigation
The case demonstrates the importance of:
forensic reconstruction;
expert evidence;
technical attribution;
proving causation;
proving actual financial loss.
A data-breach group claim should therefore establish a common forensic narrative before attempting to quantify thousands of individual claims.
17. Case Law 2 — DFSA v Commissioner of Data Protection
Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051 / CFI 085
This is an important DIFC data-protection authority.
The dispute concerned a Subject Access Request and the extent of the data controller's obligations.
The court considered:
personal data;
data-controller obligations;
proportionality;
disclosure;
regulatory functions;
confidentiality;
exemptions;
the extent of searches required.
The court's reasoning demonstrates that data-protection rights must be applied with attention to proportionality and the nature of the information sought. (DIFC Courts)
Relevance
In a data-breach group action, claimants may seek extensive records.
This case illustrates why the litigation strategy should distinguish:
personal data disclosure
from
general litigation disclosure.
A data-subject request should not automatically be treated as a substitute for the procedural disclosure process.
18. Case Law 3 — Industrial Group Ltd v Bradley Dexter
Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017
This authority is particularly relevant to electronic evidence.
The dispute involved electronic information and the use of independent IT forensic expertise.
Relevance
A data-breach group claim should consider early appointment of independent forensic specialists to establish:
integrity of evidence;
access chronology;
deleted information;
server activity;
email activity;
metadata;
authentication;
chain of custody.
This is particularly important when thousands of individual claims depend on a single technical event.
19. Case Law 4 — Barclays Bank PLC v Bavaguthu Raghuram Shetty
Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061
This case involved electronic documentation and questions concerning the integrity and authenticity of electronic records.
Relevance to data-breach litigation
A group claimant should be prepared to prove:
whether electronic evidence is authentic;
whether records were altered;
whether electronic communications can be attributed to the relevant person;
whether different versions of documents exist;
whether metadata supports the claimed chronology.
This is particularly important where a defendant disputes the forensic reconstruction.
20. Case Law 5 — Ondina v Olin
Ondina v Olin [2025] DIFC CFI 046
The DIFC Court considered the legal significance of electronic communications and electronic signatures.
The case is useful for the broader principle that digital communications can have legal significance where attribution and intention are established.
Relevance
In a data-breach claim, the parties may need to establish:
who authorised access;
who communicated instructions;
whether security procedures were followed;
whether an employee or contractor was authorised;
whether a particular electronic act can be attributed to a particular person.
Thus, digital attribution can become an important liability issue.
21. Case Law 6 — Naho v Neukirchi
Naho v Neukirchi [2024] DIFC SCT 415
This case concerns electronic records, signatures and attribution.
Relevance
For a data-breach claim, electronic evidence may include:
customer consent;
privacy notices;
data-processing agreements;
online terms;
security acknowledgements;
electronic instructions.
The case illustrates the broader importance of proving attribution and authenticity of electronic records.
22. Case Law 7 — AES Middle East Insurance Broker LLC v GSB Capital Ltd
AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd [2023] DIFC CFI 060
The case involved alleged misuse of confidential information, including client information and sensitive commercial information.
The court considered claims involving:
confidential information;
client information;
misuse;
causation;
loss;
expert damages evidence.
The judgment records a damages claim based on the alleged misuse of client information and a comparison between the actual and hypothetical positions. (DIFC Courts)
Relevance
It demonstrates the importance of separating:
unauthorised information use
from
provable economic loss resulting from that use.
That distinction is highly relevant to data-breach litigation.
23. Case Law 8 — Al Ramz Capital v DFSA
Al Ramz Capital LLC v Dubai Financial Services Authority [2025] DIFC CFI 087/2024
This is relevant to the broader regulatory/data-governance environment in the DIFC.
The case illustrates that regulatory data-protection and confidentiality questions can arise alongside ordinary civil/commercial disputes.
Strategic relevance
A claimant should therefore identify whether the incident involves:
ordinary civil liability;
data-protection regulation;
financial regulation;
professional confidentiality;
cybercrime;
contractual obligations.
These regimes may overlap without becoming identical causes of action.
24. Representative Claim Strategy in the DIFC
Where the DIFC has jurisdiction, the strategy can potentially be structured as follows:
Stage 1 — Identify the affected group
Create a database of:
claimant identity;
data category;
date of exposure;
account relationship;
evidence of misuse;
financial loss;
non-financial harm;
mitigation.
Stage 2 — Establish common issues
For example:
Whether the defendant failed to implement appropriate security measures.
Stage 3 — Establish representative suitability
Determine whether claimants have sufficiently common interests.
Stage 4 — Seek representative/GLO treatment
Depending on the facts, consider:
representative proceedings;
GLO;
group register;
test claims.
Stage 5 — Resolve common liability
Determine:
breach;
responsibility;
causation;
common legal issues.
Stage 6 — Determine individual damages
Individual claims can then be assessed where necessary.
25. Test-Case Strategy
A particularly useful GLO technique is a test claim.
Suppose:
20,000 customers were affected;
19,500 have no demonstrated financial loss;
300 suffered fraud;
150 suffered identity theft;
50 suffered substantial financial losses.
The court could potentially need different evidence for different categories.
A test-case structure can therefore determine common issues before the parties incur the expense of proving every individual issue simultaneously.
DIFC Rule 20.90 expressly allows case-management directions concerning test claims, lead representatives and separate common and individual issues. (DIFC Courts)
26. Damages Strategy
A major challenge is determining whether damages should be:
Model A — Individual assessment
Each claimant proves actual loss.
Model B — Common methodology
The court establishes a methodology and individual claimants provide their individual inputs.
Model C — Mixed approach
Common liability is determined collectively, while individual financial losses are subsequently determined.
For large data breaches, the third model can be particularly useful conceptually because:
common breach + individual damage
is often more realistic than assuming identical damages.
27. Categories of Potential Damage
Potential claims may involve:
A. Direct financial loss
Examples:
unauthorised transactions;
stolen funds;
account takeover;
fraudulent purchases.
B. Response expenses
Examples:
replacement identification documents;
forensic assistance;
account recovery;
security expenses.
C. Business losses
For commercial claimants:
business interruption;
customer loss;
operational disruption;
incident-response expenditure.
D. Privacy-related harm
Depending on applicable law and proof:
misuse of personal information;
confidentiality injury;
reputational consequences;
other legally recognised non-economic harm.
But the claimant must establish the applicable legal basis and causation.
28. Avoiding Speculative Damages
One of the largest weaknesses in a data-breach group claim is claiming a uniform amount without evidence.
For example:
“Every affected customer suffered AED 50,000.”
That proposition requires a legal and evidentiary foundation.
The safer methodology is:
Data exposed
risk/event actually experienced
individual consequence
causal connection
proof
=
recoverable loss, where legally established.
29. Data Exposure Does Not Automatically Equal Monetary Damage
This distinction is fundamental.
Suppose 100,000 email addresses are exposed.
There may be:
no financial loss;
phishing attempts;
actual account takeover;
identity fraud;
reputational consequences;
expenses incurred to protect accounts.
Those situations are not necessarily legally identical.
Therefore, a group litigation strategy should create damage categories rather than assuming uniform loss.
30. Evidence Matrix
| Issue | Evidence |
|---|---|
| Existence of breach | Incident report |
| Date of breach | Server/security logs |
| Data affected | Database analysis |
| Individuals affected | Database mapping |
| Access | Authentication logs |
| Exfiltration | Network logs |
| Attribution | Forensic analysis |
| Security failure | Security audit |
| Contractual obligation | Customer agreement |
| PDPL compliance | Privacy/security documentation |
| Financial loss | Bank records |
| Identity fraud | Police/bank records |
| Business loss | Accounting evidence |
| Causation | Expert evidence |
| Mitigation | Claimant records |
31. Preservation Strategy
Immediately after discovering a possible breach, a prospective claimant group should seek preservation of:
cloud logs;
SIEM records;
endpoint logs;
firewall logs;
identity-management records;
backups;
database snapshots;
access-control records;
email archives;
incident-response reports;
forensic images;
communications with cybersecurity vendors.
The objective is to prevent:
breach → investigation → deletion/rotation of logs → evidentiary dispute.
The DIFC's technology litigation framework provides particularly developed mechanisms for dealing with electronic evidence and confidentiality.
32. Confidentiality and Privacy During Litigation
Ironically, a data-breach lawsuit can create a second privacy risk.
Claimants may need to disclose:
Emirates ID information;
medical information;
financial records;
passwords or security information;
personal communications;
account details.
The litigation strategy should therefore seek:
redaction;
confidentiality orders;
restricted disclosure;
confidentiality rings where appropriate;
secure electronic evidence handling.
DIFC Digital Economy Court practice specifically contemplates confidentiality rings and restricted access to confidential technical material. (DIFC Courts)
33. Interim Injunction Strategy
In appropriate cases, claimants may seek urgent relief preventing:
further disclosure;
destruction of evidence;
continued processing;
continued publication;
transfer of data;
disposal of relevant assets.
A freezing order may also become relevant where there is evidence of fraud and a realistic enforcement risk.
The remedy should match the immediate risk rather than simply seeking a broad injunction.
34. Cross-Border Data Breaches
Modern breaches frequently cross borders.
Example:
UAE customer
→ UAE company
→ European cloud provider
→ Indian processor
→ U.S. cybersecurity vendor
→ attacker in another jurisdiction.
This creates questions concerning:
governing law;
jurisdiction;
contractual allocation;
cross-border transfer;
foreign evidence;
enforcement;
data localisation;
foreign proceedings.
The claimant should identify the jurisdictional nexus before selecting the procedural vehicle.
35. DIFC vs Onshore UAE Strategy
| Issue | Onshore UAE | DIFC |
|---|---|---|
| Main data law | Federal PDPL | DIFC Data Protection Law |
| Group litigation | No automatic U.S.-style class-action assumption | Express representative/GLO mechanisms |
| Representative claims | Depends on applicable procedural rules | Part 20 |
| GLO | Not equivalent to DIFC framework | Expressly available |
| Data regulator | Federal framework/Emirates Data Office | DIFC Commissioner/Data Protection framework |
| Digital evidence | Federal electronic-transactions framework | Detailed DIFC procedural framework |
| Damages | General civil-law principles | DIFC statutory/common-law framework |
| Jurisdiction | Federal/onshore courts | DIFC Courts where jurisdiction exists |
The choice cannot be made solely because the DIFC has a more developed group-litigation mechanism. Jurisdiction must independently exist.
36. Jurisdiction Is the First Gate
A sophisticated strategy should begin:
Question 1
Does the defendant have a connection with the UAE?
Question 2
Is the defendant in the DIFC?
Question 3
Does the contract contain a DIFC jurisdiction clause?
Question 4
Is there a Dubai/DIFC jurisdiction gateway?
Question 5
Does another court have exclusive jurisdiction?
Question 6
Is there an arbitration agreement?
Question 7
Which data-protection regime applies?
A recent DIFC decision illustrates the importance of this preliminary analysis: in Atul Ashok Amir Chand Dhawan v Zurich International Life Ltd [2025] DIFC CFI 019, the DIFC Court held that it lacked jurisdiction over the claimant's confidentiality/financial-loss claim. (DIFC Courts)
37. Arbitration Complication
A data-breach group claim may become complicated where individual contracts contain arbitration clauses.
For example:
50,000 customers have similar contracts, but each contains an arbitration clause.
The claimant cannot simply assume that all claims can be placed before a court as a single action.
Questions may include:
Is arbitration mandatory?
Are claims consolidated?
Does the arbitration clause cover statutory data claims?
Can non-contractual claims proceed separately?
Is there institutional group arbitration?
Are third-party claims covered?
This makes contract-by-contract review important.
38. Regulatory Complaint + Civil Claim
A coordinated strategy can have several parallel components:
Regulatory complaint
Forensic investigation
Civil liability claim
Injunction
Compensation
Criminal complaint where appropriate
These mechanisms serve different purposes.
A regulatory authority may investigate compliance, whereas a civil court determines the parties' civil rights and monetary liability.
39. Strategic Timeline
First 24–72 hours
preserve evidence;
identify affected systems;
identify affected persons;
stop ongoing disclosure;
preserve logs;
identify controller/processor relationships.
First 30 days
forensic investigation;
legal analysis;
contractual review;
regulatory assessment;
claimant identification;
preliminary damages categorisation.
30–90 days
jurisdiction analysis;
common-issue analysis;
representative/GLO assessment;
expert appointment;
pre-action communications;
preservation/disclosure requests.
Litigation stage
plead common issues;
establish representative structure;
seek appropriate case-management directions;
determine test claims where appropriate;
prove common liability;
determine individual losses;
negotiate/mediate settlement if appropriate.
40. Settlement Strategy
A large data-breach dispute may ultimately be resolved through a structured settlement.
A settlement model might distinguish:
Category A
Confirmed financial fraud.
Category B
Confirmed identity misuse.
Category C
Verified financial expenditure.
Category D
Exposure without demonstrated consequential loss.
The legal validity of any settlement structure depends on the applicable procedural rules and court approval requirements.
Under DIFC representative procedures, the court's role in approving settlements involving represented persons can become particularly important. Part 20 provides for court approval of settlements in certain representative proceedings. (DIFC Courts)
41. Major Risks in a UAE Data-Breach Group Action
Risk 1 — No suitable group mechanism
An onshore claimant may assume that a U.S.-style class action automatically exists.
Solution: Identify the actual procedural mechanism before filing.
Risk 2 — Jurisdiction failure
The claim may be brought in the wrong court.
Solution: Determine jurisdiction first.
Risk 3 — Speculative damages
Claimants may have evidence of exposure but not actual loss.
Solution: Categorise and individually substantiate damages.
Risk 4 — Causation
A claimant's later fraud may have multiple causes.
Solution: Use forensic and financial experts.
Risk 5 — Arbitration
Customer contracts may contain arbitration clauses.
Solution: Review contractual terms before commencing court proceedings.
Risk 6 — Confidentiality
Litigation itself may expose more personal information.
Solution: Seek appropriate confidentiality protections.
Risk 7 — Evidence destruction
Logs may be overwritten.
Solution: Issue preservation demands immediately.
42. Recommended Legal Architecture
A technically strong UAE data-breach group claim can be structured as:
Module 1 — Jurisdiction
Determine the appropriate UAE court or tribunal.
Module 2 — Applicable data law
Identify:
federal PDPL;
DIFC law;
ADGM law;
sector-specific rules.
Module 3 — Common liability
Prove the common breach.
Module 4 — Technical causation
Establish:
vulnerability → intrusion → access → exfiltration → affected data.
Module 5 — Common evidence
Use common forensic evidence.
Module 6 — Individual evidence
Determine claimant-specific loss.
Module 7 — Procedure
Use:
representative proceedings;
GLO;
joinder/consolidation;
test claims;
where legally available.
Module 8 — Remedies
Seek:
compensation;
injunctions;
declarations;
preservation;
disclosure;
deletion/correction where legally appropriate.
43. Eight Case Laws — Quick Revision Table
| Case | Area | Strategic lesson |
|---|---|---|
| Graciela Ltd v Giacobbe [2014] DIFC CFI 027 | Cyberattack/damages | Forensic proof + causation + quantified loss |
| DFSA v Commissioner of Data Protection [2018] DIFC CFI 051/085 | Data protection | Proportionality and scope of data access |
| Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017 | Electronic evidence | Forensic preservation/expert evidence |
| Barclays Bank v Shetty [2020] DIFC CFI 061 | Electronic records | Authenticity and integrity of digital evidence |
| Naho v Neukirchi [2024] DIFC SCT 415 | Electronic records | Attribution of electronic evidence |
| Ondina v Olin [2025] DIFC CFI 046 | Electronic communications | Digital attribution and legal effect |
| AES Middle East v GSB Capital [2023] DIFC CFI 060 | Confidential information | Misuse must be connected to provable loss |
| Atul Dhawan v Zurich [2025] DIFC CFI 019 | Jurisdiction/confidentiality | Establish jurisdiction before pursuing the claim |
44. Important Qualification on “Class Actions” in the UAE
The term “class action” should therefore be used carefully.
For the onshore UAE, it is safer to describe the strategy as potentially involving:
multiple claimant litigation, joinder/consolidation, coordinated claims, or another available collective procedural mechanism, depending on the applicable procedural rules.
For the DIFC, the position is clearer because Part 20 expressly provides:
representative-party proceedings;
group litigation;
group registers;
common issues;
individual issues;
test claims;
lead representatives. (DIFC Courts)
That distinction is particularly important when preparing a legal memorandum because calling every multi-claimant UAE proceeding a “class action” may inaccurately import concepts from U.S. federal procedure.
45. Conclusion
A UAE data-breach class/group action strategy should be constructed around four central questions:
1. Jurisdiction — Where can the claim legally proceed?
2. Common liability — What breach is common to the affected persons?
3. Common causation — Can one forensic/evidentiary record establish the breach and responsibility?
4. Individual damage — What loss can each claimant legally and evidentially establish?
For DIFC litigation, Part 20 provides a particularly developed framework for representative and group litigation, including group registers and test claims. (DIFC Courts)
For onshore UAE litigation, the strategy should not assume an American-style class action. The claim should instead be designed around the available UAE procedural mechanisms and the substantive combination of the PDPL, Civil Transactions Law, Cybercrimes Law, Electronic Transactions Law, contractual obligations and applicable sector-specific rules.
The most important practical principle is:
A common data breach can establish a common factual foundation, but the existence and amount of compensable damage may still require claimant-specific proof.
The strongest litigation model is consequently:
Preserve evidence → identify jurisdiction → identify controller/processor → establish common breach → prove forensic causation → establish representative/group procedure where available → determine common issues → categorise individual losses → quantify damages → obtain appropriate collective and individual remedies.

comments