Civil Law And Uae Data Protection Cases .

Civil Law and UAE Data Protection Cases

1. Introduction

UAE data-protection law operates through several overlapping legal regimes. For mainland UAE, the principal federal framework is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (PDPL). In financial free zones, particularly the DIFC, separate data-protection legislation applies. The ADGM likewise has its own data-protection framework.

For civil-law purposes, data protection can generate disputes involving:

unlawful collection or processing of personal data;

disclosure of confidential information;

misuse of customer databases;

employee-data disputes;

cyber incidents;

data-subject access requests;

confidentiality during litigation;

cross-border transfer of information;

electronic evidence;

data-controller and processor responsibilities;

damages and injunctive relief.

A particularly important point is that reported UAE judgments directly applying the 2021 federal PDPL remain limited. The most developed UAE case law comes from the DIFC, where the courts have decided disputes under the DIFC Data Protection Law and related confidentiality/e-disclosure principles. Accordingly, the cases below distinguish direct data-protection decisions from closely related UAE/DIFC authorities.

2. Principal UAE Legal Framework

A. Federal Personal Data Protection Law

Federal Decree-Law No. 45 of 2021 establishes the general federal framework governing personal-data processing.

Important concepts include:

data subject;

controller;

processor;

processing;

consent;

lawful processing;

data-security obligations;

data-subject rights;

cross-border transfers;

breach management.

The legislation must be considered together with applicable implementing decisions and sector-specific rules.

B. DIFC Data Protection Law

The DIFC has its own statutory regime.

The leading judicial authority is:

The Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2020] DIFC CFI 051/085.

The dispute concerned the interaction between a regulator's investigative responsibilities and a data subject's right to obtain personal data under the DIFC Data Protection Law. The DIFC Court expressly considered provisions concerning controllers, subject-access requests and the powers of the Data Protection Commissioner. (DIFC Courts)

3. Case Law

Case 1 — The Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2020] DIFC CFI 051/085

Facts

The Dubai Financial Services Authority had conducted a regulatory investigation involving Deutsche Bank and individuals connected with the investigation.

Anna Waterhouse made a Subject Access Request (SAR) seeking personal information held by the DFSA.

The Commissioner of Data Protection concluded that the DFSA had contravened the applicable DIFC Data Protection Law by refusing to comply with the request. The DFSA appealed and also pursued judicial-review proceedings. (DIFC Courts)

Decision and significance

The Court examined:

the scope of personal data;

subject-access rights;

regulatory investigations;

confidentiality;

third-party information;

the relationship between data-protection rights and regulatory functions.

The Court considered the proposition that not every document retrievable through a person's name constitutes that person's personal data. The legal analysis therefore requires consideration of the relationship between the information and the data subject rather than simply asking whether the person's name appears somewhere in a document. (DIFC Courts)

Civil-law significance

This case demonstrates that a data-access right is not necessarily equivalent to unrestricted document discovery.

It is particularly relevant where a person attempts to use data-protection legislation to obtain information for separate litigation.

4. Case 2 — Graciela Limited v Giacobbe [2014] DIFC CFI 027

This case concerned deliberate interference with an IT system.

The DIFC Court considered extensive evidence concerning the defendant's interaction with the claimant's information-technology infrastructure and awarded substantial damages.

Relevance to data protection

Although this was not a PDPL damages case, it is important for modern data-protection disputes because it demonstrates the civil consequences that can arise from wrongful interference with information systems.

The case is particularly useful for:

forensic evidence;

electronic records;

system integrity;

investigation costs;

restoration expenses;

causation;

damages arising from technological misconduct.

It therefore provides a useful civil-law bridge between cybersecurity and data protection.

5. Case 3 — Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004

This case involved cyber fraud connected with the compromise of an email account and fraudulent payment instructions.

Legal significance

The case demonstrates why data-protection disputes cannot be separated completely from cybersecurity.

Where a person's or company's electronic account is compromised, the resulting dispute may involve:

security controls;

authentication;

electronic communications;

contractual obligations;

causation;

financial loss.

Relevance to data protection

A controller or processor dealing with personal or financial information must consider whether its security arrangements adequately protect that information.

The case is therefore useful in analysing the civil consequences of inadequate information-security controls, even though it was not a direct application of the federal PDPL.

6. Case 4 — Health Bay Investment in Healthcare Enterprises & Development LLC & Another v Dr Kamal Akkach [2020] DIFC CFI 087/2019

This is one of the most useful UAE cases for confidential personal data in litigation.

The proceedings involved healthcare information. The DIFC Court's e-disclosure arrangements expressly treated patient information—including names, email addresses, medical records and financial information—as confidential information. (DIFC Courts)

The court established protections concerning:

marking confidential documents;

identifying the particular confidential information;

producing redacted versions;

restricting access to authorised persons;

maintaining secrecy;

limiting use of the information to the proceedings. (DIFC Courts)

Importance

This case illustrates a fundamental principle:

The fact that personal information is relevant to litigation does not mean that it should be freely circulated.

The court can use procedural mechanisms to permit necessary disclosure while protecting sensitive information.

This is particularly significant for:

medical records;

financial information;

patient databases;

employee records;

customer information.

7. Case 5 — AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd [2023] DIFC CFI 060

This case provides important guidance on confidential customer information.

The DIFC Court examined client lists and customer information and explained that confidentiality depends upon the nature of the information and the circumstances in which it was obtained and used. The judgment specifically discussed client financial data and customer contact information. (DIFC Courts)

The Court identified the principal elements of a confidentiality claim, including:

receipt of specific information;

a reasonable expectation that the information is confidential;

knowledge, or constructive knowledge, of its confidential character;

misuse of the information. (DIFC Courts)

Importance for data protection

This is highly relevant to disputes involving:

customer databases;

insurance records;

financial information;

employee-held databases;

customer contact details;

proprietary information.

It also demonstrates that not every piece of information connected with a customer is automatically confidential. Context, accessibility and the manner in which the information was obtained can matter.

8. Case 6 — Access Group DWC LLC & Proex Partners Ltd v BLS International FZE [2024] DIFC CFI 091/2023

This case is particularly useful for data protection during civil disclosure.

The Court considered objections based on confidentiality and explained that confidentiality claims should be specific rather than blanket objections.

The judgment recognised mechanisms such as:

redaction;

limited access;

anonymisation;

targeted protection of sensitive information.

The Court stated that it is possible to disclose the substance of relevant documents while protecting particularly sensitive information. (DIFC Courts)

Importance

This provides a practical model for balancing:

evidence disclosure

with

privacy/confidentiality protection.

It is especially relevant where documents contain personal information belonging to third parties.

9. Case 7 — Standard Chartered PLC v Standard Chartered Bank [2025] DIFC ENF 053/2025

This is a useful modern authority concerning cross-border disclosure and customer data.

The DIFC Court considered enforcement of an order connected with foreign proceedings. The judgment specifically addressed protection of customer data and communications through redaction and safeguards against collateral disclosure. (DIFC Courts)

Importance

The case demonstrates that cross-border litigation does not eliminate confidentiality obligations.

Where UAE-related information is required for foreign proceedings, the court can consider mechanisms designed to prevent unnecessary dissemination of customer information.

This is particularly relevant to:

international banking litigation;

financial records;

cross-border discovery;

customer databases;

foreign court orders.

10. Case 8 — ABN Amro Bank N.V. v N/A [2017] DIFC CFI 010

This case provides an interesting illustration of how personal data can be handled during corporate restructuring and court-supervised transactions.

The Court's order expressly addressed the transfer of personal data and provided that personal data forming part of the transferred business would become data for which the transferee was the controller. The order also protected counterparty identities by requiring relevant information to be held under seal by the Court Registry. (DIFC Courts)

Importance

The case demonstrates that data protection can arise in:

mergers;

business transfers;

restructuring;

insolvency;

court-supervised transactions.

It also illustrates the importance of determining who becomes the data controller after a corporate transaction.

11. Key Principles Emerging from the Cases

11.1 Personal data is not the same as every document mentioning a person

The DFSA v Commissioner of Data Protection litigation is especially important here.

A person's name appearing in a document does not automatically mean the entire document constitutes that person's personal data.

The connection between the information and the individual must be examined.

11.2 Data-protection rights should not automatically become discovery mechanisms

The DIFC Court's consideration of the relationship between subject-access rights and litigation demonstrates that a data-protection request should not simply be treated as an unrestricted method for obtaining an opponent's litigation documents. (DIFC Courts)

This distinction is particularly important in civil litigation.

11.3 Confidential information requires contextual assessment

The AES Middle East case demonstrates that confidentiality depends upon:

nature of information;

circumstances of acquisition;

treatment by the parties;

accessibility;

commercial sensitivity.

Customer information may therefore receive protection even when it does not fall neatly into a single category of statutory personal data. (DIFC Courts)

11.4 Redaction is an important judicial tool

The Health Bay and Access Group cases demonstrate the importance of:

redaction;

anonymisation;

restricted access;

confidentiality undertakings;

confidentiality rings.

The objective is to allow relevant evidence to be considered without exposing unrelated sensitive information. (DIFC Courts)

12. Data Protection and Civil Liability

A data-protection dispute can generate several different civil claims.

A. Breach of statutory obligation

A party may allege violation of an applicable data-protection statute.

B. Breach of contract

A data-processing agreement may contain express security and confidentiality obligations.

C. Breach of confidentiality

Confidential customer or business information may be protected independently of personal-data legislation.

D. Harmful act / civil liability

A claimant may potentially seek compensation for legally recognised harm caused by wrongful conduct.

E. Injunctive relief

A claimant may seek orders preventing continued misuse or disclosure of information.

13. Data Protection and Employee Information

Employment disputes can involve enormous quantities of personal data.

For example, an employer defending a claim may possess:

employee emails;

salary records;

attendance data;

performance reviews;

medical information;

disciplinary records;

HR correspondence.

The existence of litigation does not automatically justify disclosure of every employee's records.

The appropriate approach is generally to identify:

relevance → necessity → confidentiality → proportionality → appropriate disclosure safeguards.

The Health Bay and Access Group decisions provide useful procedural examples of how sensitive information can be protected during disclosure. (DIFC Courts)

14. Healthcare Data

Healthcare information deserves particular care because it may contain highly sensitive personal information.

The Health Bay proceedings are especially useful because the Court expressly addressed patient information including medical and financial records. (DIFC Courts)

A litigation protocol involving medical information should therefore consider:

anonymisation;

redaction;

restricted inspection;

secure transmission;

expert-only access where appropriate;

limitations on secondary use.

15. Financial and Banking Data

Banking disputes may involve:

account numbers;

transaction histories;

customer identities;

payment instructions;

financial records;

communications.

The Aegis Resources and Standard Chartered cases illustrate the interaction between financial information, cybersecurity, litigation and confidentiality. (DIFC Courts)

16. Cross-Border Data Transfers

Cross-border litigation creates an additional problem.

Suppose a UAE company is ordered to produce documents in proceedings outside the UAE.

The documents may contain:

UAE customer data;

employee information;

bank records;

medical data;

confidential commercial information.

The parties should consider:

applicable UAE law;

applicable free-zone law;

foreign data-protection requirements;

confidentiality obligations;

the foreign court's order;

redaction;

restricted disclosure;

secure transmission.

The Standard Chartered decision is particularly useful because the DIFC Court considered measures protecting customer data through redaction and safeguards against collateral disclosure. (DIFC Courts)

17. AI and Data Protection in UAE Proceedings

Modern litigation increasingly involves:

AI document review;

generative AI;

automated transcription;

machine translation;

electronic discovery.

The DIFC Courts have specifically issued guidance concerning generative AI in proceedings.

The guidance emphasises protection of client confidentiality and requires practitioners to consider how a generative-AI tool processes personal data and whether its use complies with the applicable DIFC Data Protection Law. (DIFC Courts)

Therefore, uploading confidential litigation documents to an external AI system without appropriate safeguards can create significant data-governance concerns.

18. Practical Data-Protection Model for UAE Litigation

A lawyer or organisation handling a UAE civil dispute should consider the following workflow:

StageData-protection measure
1. Identify dataDetermine what personal data exists
2. Establish relevanceIdentify information relevant to the dispute
3. Preserve evidencePrevent alteration or destruction
4. ReviewCheck relevance, confidentiality and privilege
5. MinimiseExclude unnecessary information
6. RedactRemove unrelated sensitive information
7. AnonymiseProtect third-party identities where appropriate
8. Restrict accessGive access only to authorised persons
9. ProduceProvide the legally necessary evidence
10. SecureProtect produced material against unauthorised use
11. MonitorKeep appropriate records of access
12. Retain/deleteFollow applicable retention requirements

19. Relationship Between Data Protection and Confidentiality

These concepts should not be treated as identical.

Personal data concerns information relating to an identifiable individual.

Confidential information concerns information that is subject to an obligation or expectation of confidentiality.

One piece of information can be:

personal data but not confidential;

confidential but not personal data;

both personal and confidential.

For example:

A publicly available company telephone number

may involve little confidentiality.

By contrast:

A private customer database containing financial information

may simultaneously constitute personal data and highly confidential commercial information.

The AES Middle East decision illustrates the importance of analysing the nature and circumstances of the information rather than applying an automatic classification. (DIFC Courts)

20. Damages and Remedies

Depending upon the applicable legal regime and facts, potential remedies may include:

compensation;

injunctions;

orders preventing further disclosure;

orders concerning handling of confidential information;

costs;

regulatory measures;

contractual remedies;

corrective measures.

However, the existence of a data breach does not automatically establish a particular amount of compensation. A claimant generally needs to establish the relevant legal basis, causation and legally recognised harm.

21. Important Distinction: Federal UAE Cases vs DIFC Cases

This distinction is essential for legal research.

CategoryPrincipal regime
Mainland UAEFederal PDPL and other federal/sectoral laws
DIFCDIFC Data Protection Law
ADGMADGM Data Protection Law
Financial sectorAdditional regulatory requirements
HealthcareSector-specific requirements
Civil litigationApplicable procedural and evidentiary rules

Accordingly, DIFC cases should not automatically be described as decisions applying the federal UAE PDPL.

The strongest directly reported UAE data-protection authority among the cases discussed is DFSA v Commissioner of Data Protection & Waterhouse, because it directly concerned the DIFC Data Protection Law. The other authorities provide complementary guidance on confidentiality, personal information, cyber incidents and disclosure. (DIFC Courts)

22. Conclusion

UAE data-protection case law is still developing, particularly under the federal 2021 Personal Data Protection Law. The most substantial judicial guidance currently comes from DIFC litigation.

The principal lessons from the cases are:

Personal-data rights are not unlimited discovery rights.

Information must be assessed according to its connection with the data subject.

Confidentiality can exist independently of statutory personal-data protection.

Customer and healthcare information can require special protection.

Redaction and anonymisation can reconcile disclosure with privacy.

Restricted-access mechanisms can protect sensitive evidence.

Cross-border disclosure requires careful control of customer information.

Cybersecurity incidents can generate civil liability and evidentiary disputes.

Corporate transactions can change the identity of a data controller.

AI tools used in litigation must be assessed for confidentiality and data-protection risks.

The most useful authorities for a UAE civil-law research framework are therefore DFSA v Commissioner of Data Protection & Waterhouse; Graciela v Giacobbe; Aegis Resources v Union Bank of India; Health Bay v Akkach; AES Middle East v GSB Capital; Access Group v BLS International; Standard Chartered v Standard Chartered Bank; and ABN Amro Bank v N/A. Their combined significance is in showing how UAE/DIFC courts approach personal data, confidentiality, cybersecurity, electronic evidence, disclosure and protection of sensitive information.

LEAVE A COMMENT