Civil Law And Uae Data Protection In Judicial Systems .

Civil Law and UAE Data Protection in Judicial Systems

1. Introduction

Data protection in judicial systems has become an important part of UAE civil law because courts, tribunals, lawyers, experts, litigants and judicial technology providers routinely handle large quantities of sensitive information.

Judicial files may contain:

  • identity documents;
  • addresses and contact information;
  • financial and banking records;
  • medical records;
  • employment records;
  • family information;
  • children's information;
  • commercially confidential documents;
  • trade secrets;
  • witness statements;
  • expert reports;
  • electronic communications;
  • photographs and video;
  • biometric information;
  • digital evidence; and
  • information obtained through discovery or disclosure.

The central legal problem is therefore:

How can courts administer justice and disclose necessary evidence while simultaneously protecting the personal data and confidentiality of litigants, witnesses and third parties?

The UAE approach requires a balance between access to justice, judicial evidence, procedural fairness, confidentiality, cybersecurity and personal-data protection.

A particularly important distinction is between the federal UAE legal system and the DIFC/ADGM systems. The Federal Personal Data Protection Law is not automatically the governing law of every DIFC judicial-data issue. DIFC has its own Data Protection Law No. 5 of 2020, and DIFC Courts have developed specific procedural mechanisms concerning confidentiality and personal information. The DIFC Courts themselves state that they process personal data under the DIFC Data Protection Law.

2. Meaning of Data Protection in Judicial Systems

Judicial data protection concerns the protection of information throughout the entire litigation lifecycle:

Complaint → filing → service → pleadings → disclosure → evidence → expert examination → hearing → judgment → publication → enforcement → archival/storage

Every stage can create privacy risks.

For example, a court document may contain:

claimant's passport number + bank account + medical report + home address + telephone number.

The information may be relevant to litigation, but relevance does not necessarily mean that the information should become publicly accessible.

Therefore, judicial data protection involves two competing principles:

Principle 1 — Justice requires information

Courts must have sufficient evidence to decide disputes fairly.

Principle 2 — Privacy requires controlled disclosure

Information should not be disclosed more broadly than necessary.

3. UAE Personal Data Protection Law

Federal Decree-Law No. 45 of 2021 establishes the federal UAE framework for personal-data protection.

Its purpose includes protecting confidentiality and privacy and regulating the processing of personal data.

Importantly, the law recognises circumstances in which processing can occur without ordinary consent requirements, including processing connected with legal claims and judicial procedures. This is important because courts could not function if every use of evidence containing personal information required a separate consent from every individual mentioned in the evidence.

The judicial exception, however, should not be interpreted as a general exemption from every data-protection obligation.

The more appropriate approach is:

Personal data may be processed when necessary for a lawful judicial purpose, but unnecessary disclosure and inappropriate secondary use remain separate issues.

4. Judicial Data Is Different From Ordinary Commercial Data

A company processing customer information generally determines its own commercial purposes.

A court is different.

A judicial body may process information because:

  • litigation has been commenced;
  • a procedural rule requires disclosure;
  • the court orders production;
  • evidence is necessary for adjudication;
  • enforcement requires information;
  • an expert must examine evidence; or
  • legislation requires retention.

Therefore, the legal basis for processing judicial information may arise from:

law + judicial authority + procedural necessity, rather than commercial consent.

5. Categories of Judicial Personal Data

Judicial systems may process several categories.

5.1 Basic identity data

  • name;
  • nationality;
  • identification documents;
  • address;
  • telephone number;
  • email.

5.2 Financial information

  • bank statements;
  • account numbers;
  • salary;
  • tax information;
  • assets;
  • investment information.

5.3 Health information

  • medical reports;
  • disability information;
  • treatment records;
  • psychiatric/psychological reports where relevant to proceedings.

5.4 Family information

  • divorce records;
  • children's information;
  • custody evidence;
  • family addresses;
  • financial dependency.

5.5 Digital information

  • emails;
  • WhatsApp communications;
  • cloud records;
  • IP addresses;
  • device information;
  • social-media evidence.

5.6 Commercially confidential information

  • trade secrets;
  • customer lists;
  • pricing;
  • business strategies;
  • proprietary algorithms;
  • financial models.

6. Judicial Processing Does Not Mean Unlimited Disclosure

One of the most important principles is:

A court's lawful possession of personal data does not automatically make the information public.

For example, suppose a fraud case requires production of 10,000 bank transactions.

The court may need the records.

But that does not necessarily mean:

  • every member of the public should receive them;
  • the entire database should appear in a published judgment;
  • unrelated personal information should be disclosed;
  • lawyers should use the information for unrelated purposes.

This is why procedural confidentiality and redaction mechanisms are important.

7. Public Hearings and Privacy

The general principle in the DIFC Courts is that hearings are public.

However, Part 35 of the DIFC Rules permits a hearing or part of a hearing to be conducted privately in specified circumstances, including where the proceedings involve confidential information or personal financial matters and publicity would damage confidentiality.

This demonstrates the judicial balancing mechanism:

Open justice

versus

protection of legitimate confidentiality and privacy.

The court can therefore determine that particular information requires restricted treatment.

8. Confidentiality Rings

A sophisticated judicial solution is the confidentiality ring.

Under DIFC Practice Direction No. 1 of 2022 concerning Digital Economy Court claims, the court may consider mechanisms under which confidential material is disclosed only to specified persons, such as:

  • the court;
  • counsel;
  • parties' experts;
  • transcribers;
  • interpreters; and
  • specified representatives.

The Practice Direction also contemplates independent experts reviewing confidentiality claims and redaction of pleadings and submissions referring to confidential material.

This is especially useful in disputes involving:

  • AI;
  • digital assets;
  • fintech;
  • databases;
  • cybersecurity;
  • algorithms;
  • proprietary technology.

9. Anonymisation of Judicial Decisions

Another mechanism is anonymisation.

The DIFC Courts have a specific Practice Direction dealing with anonymisation of judgments and orders. Where appropriate, parties' names can be replaced with neutral names in the interests of confidentiality.

Anonymisation is particularly relevant where proceedings concern:

  • children;
  • medical information;
  • financial information;
  • vulnerable persons;
  • sensitive personal information;
  • confidential business information.

Anonymisation is different from simply restricting access to the underlying evidence.

10. Judicial Data and Electronic Disclosure

Modern litigation increasingly involves electronic disclosure.

A dispute may require production of:

  • emails;
  • WhatsApp messages;
  • cloud documents;
  • databases;
  • mobile-phone data;
  • metadata;
  • computer images;
  • transaction records.

This creates a significant privacy problem.

For example:

A claimant requests the defendant's entire email account.

The requested material may contain thousands of communications unrelated to the litigation and belonging to employees, customers and third parties.

The court therefore has to consider:

  1. relevance;
  2. necessity;
  3. proportionality;
  4. confidentiality;
  5. privilege;
  6. personal-data protection; and
  7. appropriate access restrictions.

11. Case Law

There is an important limitation concerning UAE case law.

Published onshore UAE decisions directly applying Federal Decree-Law No. 45 of 2021 to the management of personal data inside judicial proceedings remain relatively limited.

Consequently, the following cases include important DIFC judicial authorities dealing with data protection, confidentiality, electronic evidence, employee data and judicial confidentiality. They are useful comparative UAE authorities but should not be described as binding interpretations of the federal PDPL.

12. Case 1 — DFSA v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051/085

This is one of the most important judicial data-protection authorities in the UAE's specialised financial-centre system.

The case involved a Subject Access Request made to the Dubai Financial Services Authority.

The dispute concerned whether information held by the DFSA, including extensive investigation records, fell within the relevant data-protection framework.

The court considered the concepts of:

  • personal data;
  • data;
  • relevant filing systems;
  • data-controller obligations;
  • subject-access rights; and
  • regulatory investigation material.

The judgment examined hundreds of files assembled during investigations and the question whether they constituted a relevant filing system.

Legal significance

The case demonstrates that judicial or regulatory possession of information does not eliminate data-protection questions.

It also shows the importance of determining:

What exactly constitutes personal data?

Not every document mentioning an individual should automatically be treated as identical to all other personal information concerning that person.

Relevance to UAE judicial systems

Court and regulatory files can contain both:

  • information genuinely relating to an individual; and
  • broader institutional or investigative information.

The distinction matters when determining access rights and disclosure.

13. Case 2 — TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006

This case involved a breach of confidentiality and the misuse of confidential information.

The DIFC Court of Appeal upheld the finding that the defendant had breached confidentiality obligations and the duty imposed by Article 37 of the DIFC Law of Obligations. Damages of AED 250,000 were awarded.

Importance for judicial systems

Confidential information can enter court proceedings as evidence.

Once that happens, a court must distinguish between:

use for adjudication

and

unrestricted public disclosure.

The case therefore provides an important conceptual basis for treating confidential information as legally protected information even when it has substantial commercial value.

Practical application

Suppose litigation involves:

  • confidential medical-business information;
  • investment information; or
  • commercially sensitive patient information.

The fact that the information becomes evidence does not necessarily eliminate its confidential character.

14. Case 3 — Graciela Limited v Giacobbe [2014] DIFC CFI 027

This is a leading DIFC cyber/evidence case.

A former IT employee was found responsible for sabotaging the claimant's IT system.

The court relied heavily upon:

  • event logs;
  • IP information;
  • server evidence;
  • forensic investigation;
  • system architecture;
  • access credentials;
  • expert evidence; and
  • a reconstructed attack timeline.

The court accepted circumstantial and forensic evidence and awarded USD 690,533 in compensatory damages.

Judicial-data significance

The case demonstrates that electronic evidence can be central to civil adjudication.

It also highlights a second problem:

The evidence necessary to prove a cyber claim may itself contain highly sensitive personal and business information.

Consequently, courts need procedures that permit forensic examination without unnecessarily exposing unrelated information.

15. Case 4 — Nevon v Nader [2024] DIFC SCT 158

This case concerned an employment dispute involving allegations relating to:

  • personal information;
  • communications;
  • deleted text messages;
  • compliance investigations; and
  • information stored in employment-related systems.

The DIFC Small Claims Tribunal ultimately dismissed the claim.

Importance

The case demonstrates how personal information and electronic communications can become evidence in employment litigation.

It also illustrates the importance of:

  • preservation of electronic records;
  • compliance investigations;
  • documentary evidence;
  • deleted communications;
  • internal company data.

Broader judicial principle

Where electronic communications are relied upon in litigation, parties should preserve relevant evidence while avoiding unnecessary disclosure of unrelated personal information.

16. Case 5 — Expresso Telecom Group Ltd v Tarig H.A.G. Rahamtalla [2022] DIFC CA 002

This case is particularly useful for understanding employee obligations concerning information.

The DIFC Court of Appeal considered Article 58 of the DIFC Employment Law, which expressly includes an employee's duty not to disclose an employer's:

  • confidential information;
  • trade secrets; or
  • personal data of other employees,

without the employer's consent.

Relevance to judicial systems

Employment litigation frequently involves:

  • HR records;
  • employee medical information;
  • salaries;
  • disciplinary records;
  • personal contact details.

The case demonstrates that employee-related personal data may simultaneously be subject to:

employment obligations + confidentiality + data-protection considerations.

When such material is filed in court, its evidentiary relevance must be balanced against confidentiality.

17. Case 6 — AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060

This is a particularly significant recent authority concerning client information and confidentiality.

AES alleged that former employees had moved to GSB and that confidential information had been used in connection with client solicitation and transfers of clients and assets under management.

The claim included alleged breaches of confidence and other obligations under the DIFC Law of Obligations.

The proceedings also involved applications for interim injunctions and extensive documentary production.

Relevance to judicial data protection

The case demonstrates how court proceedings can involve enormous quantities of:

  • client information;
  • financial information;
  • investment information;
  • employee information;
  • commercially confidential information.

It reinforces the need for carefully controlled disclosure.

Important distinction

The case is fundamentally a confidentiality/commercial dispute, not a federal UAE PDPL judgment.

Its importance lies in illustrating how courts deal with commercially sensitive information that becomes part of litigation.

18. Case 7 — Heitor v Helah [2017] DIFC SCT 141

This case concerned a dispute involving an alleged wrongful act and resulting financial loss.

The DIFC Small Claims Tribunal considered the evidence and awarded AED 204,422.28 to the claimant in relation to the established claim.

Relevance

Although it is not a dedicated data-protection case, it demonstrates the broader civil-law principle that the court determines liability and compensation by examining:

  • the legal obligation;
  • the wrongful act;
  • causation; and
  • resulting loss.

This framework becomes relevant where misuse of judicial information creates a separate civil wrong.

19. Judicial Data Protection and AI

Artificial intelligence introduces a new dimension.

Lawyers may use:

  • generative AI;
  • legal research systems;
  • document-review AI;
  • transcription tools;
  • summarisation systems;
  • predictive analytics.

These systems may process:

  • client information;
  • witness statements;
  • court documents;
  • financial information;
  • medical records;
  • privileged communications.

The DIFC Courts have issued specific guidance on the use of large language models and generative AI in proceedings.

The guidance states that practitioners should protect client confidentiality and comply with relevant legislation. It specifically advises practitioners to consider how an AI system will use personal data and whether its processing complies with the DIFC Data Protection Law.

Practical rule

A lawyer should not assume:

“Because the document has already been filed in court, I can upload it to any AI platform.”

Court filing and unrestricted secondary processing are different activities.

20. Judicial Data and AI Training

Consider this example:

A lawyer uploads:

500 confidential pleadings + witness statements + medical reports

to an external AI service.

Potential questions include:

  1. Where are the files stored?
  2. Who can access them?
  3. Is the provider acting as processor?
  4. Is the information used for model training?
  5. Is data transferred outside the UAE?
  6. Is encryption used?
  7. Can the information be deleted?
  8. Is client consent required?
  9. Does professional confidentiality permit the disclosure?
  10. Does a court order or procedural rule affect the analysis?

The DIFC AI guidance specifically emphasises understanding the AI provider's treatment of personal data and protecting confidential information.

21. Judicial Data and Cybersecurity

Courts are attractive targets because their systems may contain highly valuable information.

A judicial cybersecurity incident could expose:

  • identity information;
  • financial records;
  • litigation strategies;
  • privileged communications;
  • evidence;
  • witness information;
  • judgments before publication;
  • confidential settlements.

The DIFC Courts' current privacy policy states that the Courts use information-security measures including access controls, encryption, authentication, virus detection, third-party requirements, audits and employee training.

This illustrates the practical relationship between:

data protection + cybersecurity + judicial administration.

22. Judicial Data Breach

Suppose a court database is hacked.

The compromised information includes:

20,000 litigants + bank records + identity documents + medical reports.

The legal analysis may involve:

First

Was personal data processed by the judicial institution?

Second

Was there a security failure?

Third

What data was compromised?

Fourth

Were affected individuals identifiable?

Fifth

What notification obligations apply?

Sixth

Did the breach cause legally compensable harm?

Seventh

Which statutory regime applies?

Eighth

Was the incident caused by an external cyberattack, insider misconduct, vendor failure or inadequate controls?

23. Judicial Data and Third-Party Vendors

Modern courts may use external providers for:

  • cloud storage;
  • e-filing;
  • transcription;
  • translation;
  • document management;
  • cybersecurity;
  • video hearings;
  • digital notarisation;
  • electronic service.

This creates a processor/vendor risk.

A judicial institution must therefore consider:

  • access controls;
  • contractual confidentiality;
  • security standards;
  • data location;
  • subcontractors;
  • retention;
  • deletion;
  • incident response.

The DIFC Courts' privacy policy expressly states that service providers are expected to comply with relevant data-privacy requirements.

24. Judicial Disclosure Versus Public Disclosure

These are not the same.

Judicial disclosure

Information is provided to:

  • judge;
  • opposing party;
  • lawyer;
  • expert;
  • tribunal;
  • court-appointed professional.

Public disclosure

Information becomes available to:

  • journalists;
  • members of the public;
  • internet users;
  • third parties.

A document can therefore be:

disclosable for litigation but not appropriate for unrestricted publication.

This is one reason courts use:

  • redaction;
  • confidentiality rings;
  • private hearings;
  • anonymisation;
  • restricted access;
  • sealed or protected material.

25. Personal Data in Court Judgments

Judgments may themselves contain personal data.

A judgment could identify:

  • names;
  • addresses;
  • financial information;
  • medical information;
  • family circumstances;
  • employment details.

The judicial system therefore faces a difficult question:

How much information is necessary to explain the court's reasoning?

The DIFC anonymisation framework demonstrates one answer: where confidentiality requires it, names can be replaced by neutral identifiers.

26. Confidentiality in Arbitration-Related Judicial Proceedings

Arbitration may generate particularly sensitive information.

The DIFC Courts have a specific practice direction addressing confidentiality of arbitral proceedings.

For closed proceedings, the court may restrict publication of information concerning the proceedings and may require concealment of party identities or other confidential matters.

This is significant for:

  • commercial arbitration;
  • investment disputes;
  • banking disputes;
  • technology disputes;
  • construction disputes;
  • shareholder disputes.

27. Data Protection and Expert Evidence

Experts frequently receive large amounts of personal information.

Examples include:

  • medical experts;
  • forensic accountants;
  • cybersecurity experts;
  • valuation experts;
  • digital-forensics specialists.

The expert's access should normally be connected to the expert's assigned task.

For example:

A forensic accountant examining fraud does not necessarily need access to every unrelated employee's medical record.

This is where proportionality becomes important.

28. Data Minimisation in Litigation

A practical judicial principle is:

Use the minimum personal information reasonably necessary to resolve the dispute.

For example, a bank statement may prove a payment without requiring disclosure of every unrelated transaction.

A medical dispute may require a particular medical report rather than the claimant's complete lifetime medical history.

A damages claim may require financial evidence without requiring unrelated family information.

This reduces privacy risk while preserving evidentiary value.

29. Redaction

Redaction can remove information such as:

  • passport numbers;
  • bank-account numbers;
  • residential addresses;
  • telephone numbers;
  • unrelated medical details;
  • children's identifying information;
  • unrelated third-party information.

Example:

Before

Account No. 1234567890 belonging to X.

After

Account No. XXXXXXX890 belonging to X.

The evidentiary purpose may remain while reducing unnecessary exposure.

30. Data Protection and Privilege

Judicial data protection must also be distinguished from legal privilege.

Privacy

Protects personal information.

Confidentiality

Protects information from unauthorised disclosure.

Legal privilege

Protects certain lawyer-client and litigation communications.

One document can potentially involve all three.

For example:

An email between a client and lawyer concerning medical evidence.

It may contain:

  • personal data;
  • confidential information;
  • privileged legal communications.

The court therefore needs to identify each applicable protection separately.

31. Cross-Border Judicial Data

UAE litigation increasingly involves international parties.

Evidence may be transferred:

UAE → UK → Singapore → USA → UAE

This raises questions concerning:

  • cross-border transfers;
  • foreign privacy legislation;
  • cloud storage;
  • international discovery;
  • confidentiality;
  • data localisation;
  • foreign government access.

A UAE court order requiring production does not necessarily eliminate obligations imposed by another jurisdiction.

This makes cross-border evidence planning increasingly important.

32. Judicial Data and Digital Evidence

Digital evidence can contain enormous quantities of personal information.

For example:

A mobile phone may contain:

  • 20,000 messages;
  • photographs;
  • banking applications;
  • medical information;
  • location history;
  • family communications;
  • unrelated business information.

A court order for forensic examination should therefore be sufficiently controlled to identify:

  • relevant time period;
  • relevant custodians;
  • relevant applications;
  • search terms;
  • relevant categories;
  • permitted experts;
  • retention period.

Graciela illustrates how detailed digital forensic evidence can become central to civil adjudication.

33. Judicial Data and Employee Information

Employee litigation creates special risks because employment files often contain:

  • salaries;
  • bank information;
  • addresses;
  • performance assessments;
  • disciplinary records;
  • medical information;
  • family details.

Expresso Telecom is useful because it expressly recognises employee duties concerning employer confidential information, trade secrets and personal data of other employees.

Thus, an employer filing an employee's entire personnel file should consider whether all of it is actually necessary for the dispute.

34. Remedies for Misuse of Judicial Data

Depending on the applicable jurisdiction and cause of action, potential remedies may include:

Injunction

Preventing further disclosure.

Confidentiality order

Restricting access.

Redaction

Removing unnecessary information.

Anonymisation

Protecting identities.

Deletion/destruction

Where legally permissible and appropriate.

Damages

Where an applicable civil cause of action and compensable loss are established.

Costs

Particularly where inappropriate conduct increases litigation costs.

Regulatory consequences

Where a statutory data-protection violation has occurred.

35. Six Core Judicial Data-Protection Principles

The case law and DIFC procedural framework can be summarised into six principles.

Principle 1 — Judicial necessity

Personal information may need to be processed to administer justice.

Principle 2 — Relevance

Information should be connected to the issues being adjudicated.

Principle 3 — Confidentiality

Sensitive information does not automatically become public merely because it enters court proceedings.

Principle 4 — Proportionality

Disclosure should not ordinarily extend unnecessarily beyond what the litigation requires.

Principle 5 — Security

Electronic judicial information requires appropriate technical and organisational safeguards.

Principle 6 — Controlled publication

Judgments and proceedings may require anonymisation, redaction or private hearings where confidentiality interests justify them.

The DIFC procedural rules expressly recognise confidential information and personal financial matters as circumstances in which hearings may be held privately.

36. Practical Judicial Data-Protection Framework

A UAE judicial institution can structure its system around:

1. Data inventory

Identify what personal data the court possesses.

2. Classification

Classify:

  • ordinary;
  • sensitive;
  • confidential;
  • privileged;
  • restricted.

3. Access control

Give access according to judicial function.

4. Encryption

Protect stored and transmitted data.

5. Audit trails

Record:

  • who accessed information;
  • when;
  • what was accessed;
  • what was downloaded.

6. Retention

Maintain information only for legally required periods.

7. Redaction

Remove unnecessary identifiers.

8. Anonymisation

Use neutral names where appropriate.

9. Confidentiality rings

Restrict particularly sensitive information.

10. AI governance

Control external AI processing of court and client information.

11. Vendor management

Ensure technology providers satisfy applicable data-security obligations.

12. Incident response

Maintain procedures for judicial data breaches.

37. Case-Law Summary

CaseMain principleRelevance
DFSA v Commissioner of Data Protection & Waterhouse [2018] DIFC CFI 051/085Personal-data/access-right analysis in regulatory recordsJudicial/regulatory information
TVM Capital v Hashemi [2014] DIFC CA 006Confidential information can attract civil remediesConfidential evidence
Graciela v Giacobbe [2014] DIFC CFI 027Digital forensic evidence and cyber-related damagesElectronic judicial evidence
Nevon v Nader [2024] DIFC SCT 158Electronic communications and personal information in employment disputePreservation/use of digital evidence
Expresso Telecom v Rahamtalla [2022] DIFC CA 002Duties concerning confidential information and employee personal dataEmployment records
AES v GSB Capital [2023] DIFC CFI 060Confidential client information and controlled litigation disclosureFinancial/client information
Heitor v Helah [2017] DIFC SCT 141Civil liability and proof of lossCivil remedy framework

The authorities are predominantly DIFC authorities because directly reported federal onshore cases applying the 2021 UAE PDPL specifically to judicial data management remain comparatively limited. They should therefore be used with the correct jurisdictional qualification rather than presented as federal UAE PDPL precedents.

38. Conclusion

Data protection in UAE judicial systems is fundamentally a balancing exercise between the administration of justice and protection of personal information.

Courts need access to evidence, but judicial necessity does not automatically justify unrestricted disclosure.

The principal legal issues are:

  • lawful processing;
  • judicial necessity;
  • relevance;
  • proportionality;
  • confidentiality;
  • privilege;
  • cybersecurity;
  • electronic disclosure;
  • anonymisation;
  • redaction;
  • confidentiality rings;
  • AI processing;
  • third-party vendors;
  • cross-border evidence; and
  • remedies for misuse.

The DIFC framework provides particularly useful practical examples. Its rules allow private hearings where confidential or personal financial information would otherwise be harmed by publicity, while its procedures permit confidentiality rings and redaction. The DIFC Courts also expressly address personal-data protection and security in their own operations and have issued specific guidance concerning generative AI and client confidentiality.

The central civil-law principle can therefore be stated as:

Information necessary for adjudication should be accessible to the judicial process to the extent legally necessary, but the fact that personal data becomes evidence does not automatically convert it into unrestricted public information.

For UAE judicial systems, effective data protection consequently requires the integration of PDPL principles, procedural law, confidentiality rules, cybersecurity, evidence management, professional duties and judicial discretion, rather than reliance upon a single data-protection rule.

LEAVE A COMMENT