Civil Law And Uae Data-Driven Harm Attribution Models .
Civil Law and UAE Data-Driven Harm Attribution Models
1. Introduction
Data-driven harm attribution concerns the legal method used to determine who should bear responsibility when harm results from the collection, processing, analysis, transfer, storage, or misuse of data.
In the UAE, this issue is becoming increasingly important because civil disputes may involve:
personal-data breaches;
algorithmic decision-making;
automated profiling;
AI systems;
cybersecurity incidents;
financial-data misuse;
customer databases;
employee monitoring;
cloud-service failures;
inaccurate data;
unlawful disclosure;
multiple controllers and processors.
The fundamental legal question is:
When several people, organisations, technologies, or events contribute to a data-related injury, how does a UAE court attribute the resulting harm to the legally responsible party or parties?
The answer is not simply that the person who physically handled the data is responsible. UAE civil law requires analysis of duty, wrongful conduct, causation, contribution, damage and the appropriate measure of compensation.
The current UAE Civil Transactions Law is particularly important. Article 253 addresses situations where multiple persons are responsible for harm and allows the court to allocate responsibility according to contribution or, where appropriate, impose joint and several liability. It also permits reduction or denial of compensation where the injured person contributed to causing or aggravating the harm. Article 254 recognises moral harm, while Article 255 bases compensation on the loss suffered and lost profit where that loss is a natural consequence of the harmful act. (UAE Legislation)
2. Meaning of Data-Driven Harm
Data-driven harm occurs where information or a data-processing system contributes materially to injury.
Examples include:
Personal-data harm
A company unlawfully discloses a customer's personal information.
Algorithmic harm
An automated system incorrectly classifies an individual as a fraud risk.
Cybersecurity harm
A vulnerability allows attackers to access customer information.
Financial harm
Compromised data facilitates unauthorised transfers.
Reputational harm
Incorrect information is processed or disclosed, damaging a person's reputation.
Commercial harm
A competitor obtains confidential customer or business information.
Privacy harm
Sensitive personal information is processed or disclosed without an appropriate legal basis.
3. The UAE Civil-Law Attribution Structure
A useful model is:
Duty → Conduct → Data event → Causation → Damage → Attribution → Remedy
Each stage raises a separate legal question.
Duty
Did the defendant owe a legal, contractual, statutory or confidentiality duty?
Conduct
What exactly did the defendant do or fail to do?
Data event
What happened to the information?
Causation
Did that conduct cause the injury?
Damage
What legally recognised harm occurred?
Attribution
Which party or parties should legally bear the loss?
Remedy
What compensation or other relief is appropriate?
This structure is particularly important where a data incident involves several organisations.
4. Model One — Direct Causation
The simplest attribution model is direct causation.
The claimant establishes:
Defendant's conduct → immediate data-related harm
For example:
A company employee deliberately downloads a customer's confidential database and gives it to a competitor.
The causal chain is relatively straightforward:
Unauthorised extraction → disclosure → misuse → commercial injury
The stronger the evidentiary connection between the conduct and damage, the easier attribution becomes.
5. Model Two — Natural-Consequence Causation
The current Civil Transactions Law provides an important compensation principle.
Article 255 states that compensation is assessed according to the loss suffered and lost profit where that loss is a natural consequence of the harmful act. (UAE Legislation)
This principle is particularly useful for data-related claims.
Consider:
Inadequate security → database breach → exposure of customer information → fraudulent use → financial loss
The court may have to determine whether the financial loss was a sufficiently natural consequence of the original wrongful conduct.
Not every event occurring after a data breach necessarily becomes recoverable damage.
6. Model Three — Multiple-Actor Attribution
Modern data systems frequently contain several actors:
Customer → Controller → Processor → Cloud Provider → Sub-processor
Suppose a processor fails to secure the database and a sub-processor's vulnerability is exploited.
The court may need to determine:
who owed the relevant duty;
who controlled the processing;
who caused the security weakness;
whether another party independently contributed;
whether the damage is divisible;
whether liability should be allocated jointly.
Article 253 specifically addresses multiple persons responsible for harm. The court may allocate responsibility according to their respective contribution or impose joint and several liability where appropriate. (UAE Legislation)
This is one of the most important statutory foundations for a multi-party data-liability model.
7. Model Four — Contributory Harm
Data-related injuries can sometimes be aggravated by the claimant's own conduct.
Examples include:
continuing to use compromised credentials;
ignoring security warnings;
voluntarily giving an attacker authentication information;
failing to notify a bank after discovering fraud;
failing to take reasonable steps to mitigate loss.
Article 253 expressly permits the court to reduce or deny compensation where the injured person contributed to causing or aggravating the damage. (UAE Legislation)
Therefore:
Defendant's contribution + claimant's contribution
may produce an allocation different from complete liability on the defendant.
8. Model Five — Intervening-Cause Attribution
A difficult situation occurs where a third party intervenes between the defendant's conduct and the ultimate injury.
Example:
Weak security → hacker obtains data → hacker commits identity fraud → victim loses money
The court may have to determine whether the hacker's conduct:
was a foreseeable consequence of the security failure;
constituted an independent intervening cause;
broke the causal connection;
merely contributed to an existing chain of causation.
The answer will depend heavily on the evidence and circumstances.
The existence of criminal conduct by a third party therefore does not automatically resolve the civil-liability question.
9. Model Six — Risk-Based Attribution
The UAE PDPL introduces a particularly important risk-based security concept.
Article 20 requires appropriate technical and regulatory measures for information security, taking account of risks associated with processing, including:
damage;
loss;
accidental or unlawful alteration;
disclosure;
unauthorised access.
The assessment also considers the nature, scope and purposes of processing and the potential risks to confidentiality and privacy. (UAE Legislation)
Consequently, data attribution should not ask only:
"Was there a breach?"
It should also ask:
"Was the defendant's security and governance system reasonably appropriate for the risks associated with the processing?"
This is especially relevant for organisations processing:
health data;
financial data;
biometric information;
large customer databases;
children's data;
sensitive employee information.
10. Model Seven — Evidence-Based Attribution
Data-driven harm often cannot be attributed through ordinary eyewitness evidence.
The relevant evidence may include:
access logs;
IP addresses;
authentication records;
metadata;
forensic images;
database logs;
cloud records;
email headers;
audit trails;
security alerts;
AI-system logs.
The UAE/DIFC jurisprudence provides useful examples of courts examining technical and circumstantial evidence to determine responsibility.
11. Case Law
Case 1 — Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the strongest UAE/DIFC authorities for technology-related harm attribution.
A former employee was accused of deliberately sabotaging the claimant's IT system.
The court considered extensive technical and circumstantial evidence, including the defendant's knowledge of the system, secret creation of a server, copying of data and subsequent events.
The Court concluded that the attack was an internal attack and attributed it to the defendant. The claimant was awarded USD 690,533 in compensatory damages, including system restoration, investigation, emergency-server costs and employee time dealing with the attack. (DIFC Courts)
Principle
The case demonstrates that data-driven attribution can be based on a combination of technical evidence and circumstantial evidence.
The court did not require an eyewitness to the cyberattack.
Application
For a modern data breach, investigators could similarly establish:
Access → system knowledge → unusual activity → forensic evidence → responsible actor
This is an important model for cyber and data-liability litigation.
12. Case 2 — Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
This case involved cyber fraud arising from a hacker compromising the customer's email system and sending fraudulent payment instructions.
The DIFC Court expressly described the question as whether the bank or customer should bear the loss and stated that the answer was fact-specific. On the facts before it, the Court placed the loss on the bank and allowed the customer to recover certain consequential loss. (DIFC Courts)
Attribution principle
The case illustrates that a court should examine the entire causal chain rather than simply identify the hacker.
Potential questions include:
Who controlled the relevant security system?
Who had authentication responsibilities?
What contractual obligations existed?
Could the fraud reasonably have been detected?
Which party's conduct materially contributed to the loss?
Importance
This is highly relevant to data-driven harm because a cyber incident may involve:
Customer + bank + technology provider + attacker
rather than a single responsible actor.
13. Case 3 — DFSA v Commissioner of Data Protection & Anna Waterhouse [2020] DIFC CFI 051/085
This case directly concerned data-protection rights under the DIFC Data Protection Law.
Anna Waterhouse made a subject-access request to the Dubai Financial Services Authority following regulatory investigations.
The Court considered the relationship between the statutory right of access, regulatory investigations and the meaning of personal data. (DIFC Courts)
Attribution significance
This case demonstrates that data-related legal rights must be connected to the specific statutory relationship between the data subject and controller.
The court must identify:
whose data is involved;
who controls it;
why it was processed;
which statutory obligation applies;
whether an exemption applies.
Importance
It prevents an overly broad approach under which every document containing an individual's name is automatically treated as that individual's complete personal-data file.
14. Case 4 — AES Middle East Insurance Broker LLC v GSB Capital Ltd [2025] DIFC CFI 060
The AES litigation concerned allegations involving confidential customer and commercial information, including information relating to clients and assets under management.
The Court ultimately dismissed the claimants' substantive claims. The 2025 proceedings involved allegations of breach of confidence, unlawful conspiracy and inducement of breach of legal rights. (DIFC Courts)
Attribution significance
This case is useful because it demonstrates that the claimant must establish more than the mere existence of sensitive information.
The claimant needs to connect:
Information → duty of confidence → wrongful acquisition/use → legally actionable harm
Data-driven significance
A customer database may simultaneously involve:
personal data;
confidential information;
commercially valuable information;
contractual rights.
Different legal doctrines can therefore produce different attribution questions.
15. Case 5 — Health Bay Investment in Healthcare Enterprises & Development LLC v Dr Kamal Akkach [2020–2022] DIFC CFI 087/2019
This litigation involved healthcare businesses and confidential information.
The DIFC Court made specific confidentiality arrangements, including a confidentiality ring, controlling who could receive documents containing confidential information. The order defined confidential information and established procedures for handling documents containing it. (DIFC Courts)
Attribution significance
Healthcare information demonstrates that data-driven harm can involve several overlapping interests:
patient privacy;
business confidentiality;
contractual obligations;
professional duties;
commercial interests.
Importance
The case shows that a court can manage sensitive information through procedural controls rather than treating disclosure as an all-or-nothing question.
16. Case 6 — Access Group DWC LLC & ProEx Partners Ltd v BLS International FZE [2025] DIFC CFI 091/2023
This litigation concerned contractual and commercial disputes between businesses operating in the UAE and internationally.
The DIFC Court issued a substantive judgment in November 2025 following a trial concerning the parties' contractual relationship and alleged wrongdoing. (DIFC Courts)
Attribution significance
The case is useful for demonstrating that attribution depends upon identifying:
the contractual relationship;
the particular obligation;
the conduct alleged to constitute breach;
the causal consequences of that conduct.
For data-driven commercial claims, a claimant should therefore avoid treating every consequence of a technological failure as automatically attributable to the defendant.
17. Case 7 — Standard Chartered PLC v Standard Chartered Bank [2025] DIFC ENF 053/2025
This case involved enforcement in the DIFC of a disclosure order made by the English High Court.
The DIFC Court recognised and enforced the foreign disclosure order under the DIFC enforcement framework. (DIFC Courts)
Data-attribution significance
Cross-border data disputes frequently involve multiple legal systems.
The attribution analysis may therefore require identifying:
where the data was created;
where it was stored;
who controlled it;
where the harmful processing occurred;
which court has jurisdiction;
whether foreign disclosure obligations apply.
This is particularly relevant to multinational financial and technology companies.
18. Case 8 — Atul Ashok Amir Chand Dhawan v Zurich International Life Limited [2025] DIFC CFI 019
This recent DIFC decision provides useful material concerning jurisdiction and the relationship between a claim and the underlying incident or transaction.
The Court discussed the concept of an "incident" in the context of jurisdiction and recognised that an incident can encompass an essential element of conduct or the incidence of loss or damage necessary to give rise to a tort or statutory-duty claim. (DIFC Courts)
Relevance
For data-driven harm, this reinforces the importance of locating the relevant:
conduct;
transaction;
incident;
loss;
damage.
This becomes particularly important when data processing occurs across several jurisdictions.
19. Comparative Attribution Matrix
| Attribution model | Central question | Typical data dispute |
|---|---|---|
| Direct causation | Who directly caused the injury? | Employee steals database |
| Natural consequence | Was the loss a natural consequence? | Breach followed by fraud |
| Multiple actors | Who contributed to the harm? | Controller + processor + cloud provider |
| Contributory harm | Did claimant contribute? | Failure to protect credentials |
| Intervening cause | Did a third party break the chain? | Hacker causes subsequent loss |
| Risk-based | Were security measures appropriate? | Inadequate cybersecurity |
| Evidence-based | What evidence identifies responsibility? | Logs/forensics |
| Cross-border | Where did the relevant conduct/loss occur? | International cloud processing |
20. Attribution of AI-Generated Harm
Data-driven systems increasingly use AI.
Consider an automated credit-risk system:
Incorrect training data → algorithmic classification → loan refusal → financial loss
The attribution analysis could involve:
data supplier;
software developer;
AI provider;
financial institution;
system operator;
human reviewer.
The central question becomes:
Which actor's legally relevant conduct caused the harmful result?
A court may need to examine:
quality of training data;
system design;
foreseeable risks;
validation;
human oversight;
warnings;
contractual responsibilities;
system logs.
The PDPL's risk-based approach to modern technologies is particularly relevant where processing presents a high risk to privacy or confidentiality. Article 21 requires a data-protection impact assessment in specified high-risk circumstances involving modern technologies. (UAE Legislation)
21. Algorithmic Bias and Attribution
Suppose an automated recruitment system incorrectly rejects an applicant.
The causal chain might be:
Historical data → training model → algorithm → employer decision → employment loss
Possible responsible actors could include:
data provider;
AI developer;
AI vendor;
employer;
human decision-maker.
The claimant would need to establish the legally relevant duty and connect the wrongful conduct to the resulting damage.
This is why algorithmic output alone should not automatically determine legal responsibility.
22. Data-Breach Attribution
A modern breach can be represented as:
Controller
↓
Processor
↓
Cloud provider
↓
Security vulnerability
↓
Attacker
↓
Data disclosure
↓
Identity fraud
↓
Financial loss
A court may ask separate causation questions at every stage.
Question 1
Who created the vulnerability?
Question 2
Who had the duty to eliminate or mitigate it?
Question 3
Who actually exploited it?
Question 4
Was the exploitation foreseeable?
Question 5
Did the claimant take reasonable mitigation measures?
Question 6
Was the ultimate financial loss a natural consequence?
This produces a much more sophisticated attribution model than simply saying "the company was hacked."
23. Evidence Required for Attribution
A claimant should ideally preserve:
Technical evidence
firewall logs;
access logs;
authentication records;
server records;
database logs;
endpoint records;
cloud logs.
Documentary evidence
contracts;
security policies;
data-processing agreements;
risk assessments;
DPIAs;
incident reports.
Expert evidence
cybersecurity forensic reports;
software analysis;
AI-system analysis;
financial-loss analysis.
Financial evidence
bank records;
invoices;
remediation costs;
business-loss calculations.
The Graciela decision illustrates the evidentiary importance of forensic and circumstantial evidence in identifying the responsible actor. (DIFC Courts)
24. Damage Quantification
Attribution and quantification are separate questions.
A claimant may prove:
Defendant caused the data incident
without proving:
Defendant caused AED 10 million of claimed losses.
Article 255 of the Civil Transactions Law connects compensation with the loss actually suffered and lost profit where it is a natural consequence of the harmful act. (UAE Legislation)
Potential heads of loss can include:
direct financial loss;
investigation costs;
restoration costs;
reasonable mitigation expenses;
business interruption;
lost profits;
recognised moral harm.
The Graciela judgment is especially instructive because the Court awarded compensation for system restoration, investigation, emergency servers and employee time associated with the cyberattack. (DIFC Courts)
25. Moral Harm
Data-related injuries may not always be financial.
Article 254 of the current Civil Transactions Law expressly recognises moral harm and identifies infringement of matters including:
freedom;
honour;
reputation;
social standing;
financial status.
This is potentially significant in cases involving:
disclosure of sensitive information;
reputational damage;
misuse of personal information;
privacy-related injury.
However, the claimant still needs to establish the relevant legally recognised harm and its connection to the defendant's conduct.
26. Multiple Defendants and Apportionment
Consider:
Controller — 40% contribution
Processor — 35% contribution
Sub-processor — 25% contribution
Article 253 gives the court flexibility in dealing with multiple responsible parties. It provides for proportional responsibility but also permits equal or joint-and-several liability where appropriate. (UAE Legislation)
This is particularly valuable in technology litigation because responsibility is often distributed across an ecosystem rather than concentrated in one entity.
27. Contractual Allocation of Risk
Data-processing contracts can materially affect attribution.
For example, a contract may require a processor to:
encrypt information;
maintain particular security standards;
notify breaches;
conduct penetration tests;
maintain backups;
supervise subcontractors.
If the processor violates these obligations, the contractual allocation of responsibility becomes important.
However, contractual allocation does not necessarily answer every civil-liability question. The court may still have to determine:
actual causation;
damage;
contribution;
enforceability;
applicable statutory requirements.
28. Risk-Based Data Attribution Model
The UAE PDPL's security framework supports a practical model:
Low-risk processing
Ordinary personal information with limited consequences.
Medium-risk processing
Large customer databases or extensive employee information.
High-risk processing
Sensitive information, extensive profiling or advanced technologies presenting substantial privacy risks.
The greater the foreseeable risk, the stronger the justification for:
encryption;
access controls;
pseudonymisation;
impact assessment;
continuous monitoring;
testing;
incident-response planning.
Article 20 expressly requires security measures to take account of processing risks and Article 21 addresses impact assessments for specified high-risk processing involving modern technologies. (UAE Legislation)
29. Data Governance as Evidence of Reasonable Conduct
Data governance is not merely a compliance exercise.
Documents showing that an organisation:
performed risk assessments;
conducted security audits;
implemented access controls;
trained employees;
tested systems;
maintained incident-response procedures;
investigated vulnerabilities;
can become important evidence in a subsequent civil dispute.
Conversely, the absence of basic governance documentation may make it more difficult for a defendant to demonstrate that its conduct was reasonable.
30. Attribution in Cross-Border Data Systems
Cross-border processing creates a geographical attribution problem.
Example:
UAE company
→ Indian software developer
→ Singapore cloud infrastructure
→ European sub-processor
→ UAE customer
If the customer suffers harm, several questions arise:
Where did the processing occur?
Where did the security failure occur?
Which entity determined the processing purpose?
Which entity controlled the relevant system?
Which jurisdiction governs the contract?
Where did the injury occur?
Which court has jurisdiction?
The Dhawan decision's discussion of the significance of an "incident" and the location of conduct or loss illustrates why these jurisdictional questions matter in complex civil claims. (DIFC Courts)
31. A Unified UAE Data-Harm Attribution Formula
A useful legal model can be expressed as:
A = D × B × C × H × P
Where:
A = Attribution
D = Duty
B = Breach
C = Causation
H = Harm
P = Proof
This is not a statutory mathematical formula. It is an analytical framework.
If any component is weak, the attribution case becomes more difficult.
For example:
Duty = established
Breach = established
Causation = uncertain
Harm = substantial
Proof = weak
The existence of substantial harm does not automatically establish liability.
32. Practical Example
Suppose a UAE bank's customer database is breached.
Stage 1
A processor fails to patch a known vulnerability.
Stage 2
A hacker exploits the vulnerability.
Stage 3
Customer information is stolen.
Stage 4
The information is used for identity fraud.
Stage 5
Customers suffer financial losses.
The court could examine:
Bank
Did it properly supervise the processor?
Processor
Did it implement appropriate security?
Cloud provider
Was the vulnerability within its responsibility?
Hacker
Did the independent criminal conduct alter the causal analysis?
Customer
Did the customer contribute to the subsequent loss?
Evidence
Are logs and forensic records sufficient to establish the chain?
This illustrates why attribution is often a multi-stage legal inquiry.
33. Six Core Lessons from the Case Law
1. Graciela
Technical and circumstantial evidence can establish responsibility for an IT attack. (DIFC Courts)
2. Aegis Resources
Cyber-loss allocation is fact-specific and requires examination of the responsibilities of the parties. (DIFC Courts)
3. DFSA v Waterhouse
Data-protection rights depend upon the statutory relationship between the data subject, controller and processing activity. (DIFC Courts)
4. AES
Confidential information requires proof of the relevant duty and misuse; possession of sensitive information alone does not automatically establish liability. (DIFC Courts)
5. Health Bay
Courts can protect sensitive information through confidentiality mechanisms while permitting litigation to proceed. (DIFC Courts)
6. Access Group
Modern commercial disputes require careful identification of the contractual and factual source of alleged wrongdoing before assigning responsibility. (DIFC Courts)
34. Conclusion
UAE data-driven harm attribution is fundamentally a causation-and-responsibility exercise.
The strongest framework combines:
UAE PDPL duties concerning lawful processing and security;
Civil Transactions Law principles governing harmful acts and compensation;
contractual allocation of responsibility;
technical evidence and forensic attribution;
causation and natural-consequence analysis;
multiple-party contribution rules;
claimant contribution and mitigation;
recognition of material and moral harm;
cross-border jurisdictional analysis; and
appropriate quantification of damages.
The current Civil Transactions Law is particularly significant because Articles 253–255 provide an explicit framework for multiple responsible persons, claimant contribution, moral harm and assessment of compensation according to loss and naturally consequential lost profit. (UAE Legislation)
The UAE/DIFC authorities—especially Graciela v Giacobbe, Aegis Resources v Union Bank of India, DFSA v Commissioner of Data Protection & Waterhouse, AES v GSB Capital, Health Bay v Akkach, and Access Group v BLS International—show that courts approach information-related harm through evidence, duty, causation, confidentiality, contractual responsibility and actual loss, rather than automatically assigning all consequences to the organisation most closely associated with the data.
Important qualification: the cited DIFC decisions are not all judgments under the federal UAE PDPL. They are UAE/DIFC authorities used to develop the civil-law attribution framework because reported decisions directly applying Federal Decree-Law No. 45 of 2021 to data-driven damages remain comparatively limited.

comments