Civil Law And Uae Privacy Violations And Compensation Claims .
Civil Law and UAE: Privacy Violations and Compensation Claims
1. Introduction
Privacy violations in the UAE can arise when a person's personal data, private communications, photographs, financial information, biometric information, location data, confidential records, or other private information is collected, processed, disclosed, published, transferred, or misused unlawfully.
The legal consequences may include:
- stopping or restricting unlawful processing;
- correction or erasure of personal data;
- confidentiality or non-disclosure orders;
- recovery or deletion of improperly disclosed information;
- civil compensation for proven damage;
- contractual damages where confidentiality obligations exist;
- regulatory complaints and administrative sanctions;
- in appropriate cases, consequences under criminal or sector-specific legislation.
The principal modern framework is the UAE Personal Data Protection Law, Federal Decree-Law No. 45 of 2021, together with the current Civil Transactions Law, Federal Decree-Law of 2025, the Evidence Law, and applicable sectoral legislation. The PDPL expressly gives data subjects rights concerning information, correction, erasure, restriction, objection and automated processing.
A particularly important point is that a privacy violation and a compensation claim are not necessarily the same thing. Establishing unlawful processing may support regulatory or corrective relief, while a civil damages claim generally requires establishing the legally recognized damage and causal connection.
2. Meaning of Privacy Violation
A privacy violation may broadly occur where there is:
- Unauthorised collection of personal information;
- Processing for an incompatible purpose;
- Unauthorised disclosure to third parties;
- Publication of private information;
- Unauthorised access to electronic accounts or devices;
- Improper sharing of photographs or recordings;
- Misuse of financial or employment information;
- Improper retention of personal data;
- Unlawful cross-border transfer;
- Improper automated profiling or decision-making;
- Failure to protect personal data from a security breach;
- Misuse of confidential information obtained through a contractual relationship.
The PDPL defines personal data broadly, including information capable of identifying a natural person directly or indirectly, and specifically includes sensitive and biometric data within its framework.
3. Current UAE Legal Framework
A. Personal Data Protection Law
Federal Decree-Law No. 45 of 2021 establishes the general federal framework for personal-data processing.
Among other rights, the data subject may:
- obtain information concerning processing;
- request correction;
- request erasure in applicable circumstances;
- restrict processing;
- object to certain processing;
- object to certain automated decisions;
- exercise rights concerning the handling and retention of personal data.
Article 16 is particularly relevant to litigation because it allows continued retention of personal data where necessary for claiming or defending rights and lawsuits. It also recognizes circumstances in which processing may continue for judicial proceedings.
Thus, privacy law does not mean that evidence relevant to litigation must automatically be destroyed.
4. Civil Liability for Privacy Damage
The current UAE Civil Transactions Law provides the general framework for compensation for harmful acts.
Article 256 provides that compensation is normally assessed in money, while the court may, depending on the circumstances and at the injured party's request, order restoration of the previous position or specific performance connected with the harmful act.
It also allows installment or periodic compensation and permits reconsideration where damage subsequently becomes more serious.
Therefore, a privacy claim can potentially involve both:
Corrective relief
- deletion;
- restoration;
- cessation of processing;
- non-disclosure;
- removal of unlawful material.
Monetary relief
- actual financial loss;
- proven consequential loss;
- other legally compensable damage resulting from the wrongful act.
5. Essential Elements of a Privacy Compensation Claim
A claimant should generally establish the following:
1. Protected interest
There must be a legally protected privacy, personal-data, confidentiality, contractual or other civil interest.
2. Wrongful conduct
Examples include:
- disclosure without lawful basis;
- unauthorised access;
- misuse of confidential data;
- processing beyond the permitted purpose;
- unlawful publication.
3. Damage
The claimant must identify the damage resulting from the violation.
Examples may include:
- financial loss;
- business loss;
- loss arising from misuse of confidential information;
- reputational or other legally recognizable harm where supported by the applicable liability rules.
4. Causation
The claimant must connect the unlawful conduct to the alleged loss.
5. Proof
Evidence may include:
- emails;
- WhatsApp messages;
- access logs;
- photographs;
- database records;
- metadata;
- forensic reports;
- employment records;
- witness testimony;
- expert evidence;
- electronic communications.
The UAE Evidence Law expressly recognizes electronically conducted evidentiary proceedings and gives them binding evidentiary force under the statutory framework.
6. Privacy Violation Versus Confidentiality Breach
These concepts overlap but are not identical.
| Privacy violation | Confidentiality breach |
|---|---|
| Usually concerns personal information | Usually concerns information subject to an obligation of confidence |
| PDPL may be directly relevant | Contract, fiduciary obligations or confidentiality law may be relevant |
| May involve controller/processor | May involve employer, employee, consultant, partner or contracting party |
| Can involve regulatory remedies | Often directly supports civil damages |
| Personal data is central | Information may be business or commercial information |
For example, disclosure of an employee's salary information may potentially involve both personal-data/privacy issues and contractual/confidentiality obligations.
7. Privacy Violations Through Electronic Communications
Modern UAE privacy disputes increasingly involve:
- WhatsApp;
- email;
- cloud storage;
- mobile phones;
- CCTV;
- employee monitoring;
- social media;
- databases;
- customer-management systems;
- biometric systems;
- location tracking.
The important legal question is not simply whether information exists electronically. The court must consider:
Was the information obtained lawfully?
Was it used for a lawful purpose?
Was disclosure authorized?
Was the disclosure necessary and proportionate?
Did the claimant suffer compensable damage?
8. Compensation for Confidential Information: DIFC Authority
DIFC case law provides particularly useful examples of how UAE courts may approach compensation for wrongful disclosure or misuse of confidential information.
Because these are DIFC authorities, they should not be treated as binding Federal Supreme Court or mainland UAE precedents.
Case Law 1: TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006
This is one of the most important authorities for compensation arising from confidentiality violations.
The defendant was found to have breached a confidentiality agreement and obligations under the DIFC Law of Obligations. The first-instance court awarded AED 250,000 in damages.
The Court of Appeal considered the difficulty of quantifying the economic value of confidentiality. It accepted that where the precise amount of loss cannot be established with sufficient certainty, the court may assess damages using its judicial discretion.
Principle
A confidentiality violation can cause legally compensable loss even where the exact monetary value of the information is difficult to calculate.
Relevance
This is highly relevant to privacy claims because private information may have substantial value even when the claimant cannot demonstrate a simple invoice-style financial loss.
9. Case Law 2: DFSA v Commissioner of Data Protection & Anna Waterhouse [2020] DIFC CFI 051/085
This case concerned the DIFC data-protection regime and a subject-access request.
The Court considered the distinction between personal data and entire documents containing personal information. The case demonstrates that the existence of a person's information within a document does not automatically mean that every part of the document becomes that person's personal data.
The judgment also considered the relationship between data protection, legal privilege and litigation-related use of information.
Principle
Data protection rights must be applied according to the statutory definition and purpose of the relevant data-protection regime.
Relevance
A claimant alleging privacy violation must identify:
- what constitutes personal data;
- what processing occurred;
- who processed it;
- why the processing was unlawful.
10. Case Law 3: AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd [2023] DIFC CFI 060
This case involved allegations concerning misuse of confidential commercial information.
The information included:
- client lists;
- customer contact information;
- assets-under-management information;
- fees;
- investment strategies;
- risk profiles;
- other commercially sensitive information.
The DIFC Court identified the basic elements of a confidentiality claim, including receipt of specific information, its confidential character, knowledge or constructive knowledge of confidentiality, and misuse.
Principle
Not every piece of information connected with a business is automatically confidential. The claimant must establish the confidential character of the information and the circumstances of its misuse.
Relevance to privacy
The same analytical discipline is useful in privacy litigation: the claimant should precisely identify the information, the unlawful processing or disclosure, and the resulting harm.
11. Case Law 4: Graciela Limited v Giacobbe [2014] DIFC CFI 027
This case involved an alleged internal IT attack and deletion/manipulation of company data.
The court relied heavily on circumstantial and technical evidence, including:
- server evidence;
- IP information;
- data copying;
- deletion;
- system access;
- forensic evidence.
The court found the evidence sufficiently strong to establish responsibility for the attack and considered compensatory damages under the DIFC statutory framework.
Principle
Digital privacy and data disputes can be proved through technical evidence even where there is no conventional eyewitness.
Relevance
In a privacy claim, access logs, forensic images, metadata and server records can establish:
access → possession → disclosure/use → damage.
12. Case Law 5: Ahmed Seddiq Mohamed Samea Almutawa v Mohamed Seddiq Mohamed Samea Al Mutawa [2024] DIFC CFI 095
This case concerned legal professional privilege and disclosure of information.
The court emphasized that confidentiality by itself does not automatically make every communication privileged. The nature and purpose of the communication must be examined.
The court also considered protective mechanisms where commercially sensitive information had to be disclosed.
Principle
Confidentiality, privacy and legal privilege are related but legally distinct concepts.
Relevance
A privacy claimant cannot simply assert that every private or sensitive document is immune from disclosure. The court must balance:
- relevance;
- necessity;
- privilege;
- confidentiality;
- procedural fairness.
13. Case Law 6: Zuzana Kapova v Miloslav Makovini & Others [2025] DIFC CFI 004/2023
This case concerned objections to disclosure of private and confidential business records.
The court considered concerns relating to:
- excessive disclosure;
- fishing expeditions;
- commercial confidentiality;
- relevance;
- materiality;
- proportionality.
The case demonstrates the importance of limiting disclosure to information that is genuinely relevant to the dispute.
Principle
Privacy and confidentiality can be protected through proportionality and controlled disclosure rather than automatically excluding relevant evidence.
Relevance
This is important where a privacy claim itself requires disclosure of sensitive electronic records.
14. Case Law 7: TVM Capital — Assessment of Difficult-to-Quantify Loss
The reasoning in TVM Capital v Hashemi deserves separate emphasis because privacy losses frequently resist precise calculation.
The Court of Appeal accepted that where the amount of loss cannot be established with sufficient certainty, judicial assessment of damages may be appropriate.
For example, suppose confidential customer information is disclosed to a competitor. The claimant may not be able to prove exactly how much business was lost because of the disclosure.
The court may nevertheless consider the economic value of the confidentiality obligation and the circumstances of the misuse.
15. Case Law 8: Heitor v Helah [2017] DIFC SCT 141
The dispute included allegations of disclosure of confidential and proprietary information and relied on the DIFC Law of Obligations and Law of Damages and Remedies.
The claimant relied on the principle that damages should place the injured party, so far as money can do so, in the position that would have existed had the wrong not occurred.
Principle
Damages are fundamentally compensatory.
Relevance
The claimant should therefore establish the actual consequences of the privacy/confidentiality violation rather than treating every technical breach as automatically generating an unlimited monetary award.
16. Case Law 9: Lipika v Lukesh [2021] DIFC SCT 047
This employment dispute involved allegations concerning company information and data stored on personal devices.
The defendant alleged that company information was not returned and that data had been deleted, producing financial consequences for the business. The tribunal considered the contractual and evidentiary context of those allegations.
Principle
Whether information stored on personal devices creates liability depends substantially upon:
- contractual obligations;
- ownership;
- confidentiality;
- authorization;
- actual loss;
- evidence.
Relevance
The case is useful for workplace privacy/data disputes involving employees' devices and electronic records.
17. Case Law 10: Arif Naqvi v DFSA [2021] DIFC CFI 060/2021
The claimant sought privacy for proceedings involving confidential information.
The DIFC Court emphasized the strong presumption that court proceedings are public, while recognizing that privacy may be justified where the interests of justice require it.
Principle
A person's privacy interest does not automatically override open justice.
Relevance
Privacy can arise inside litigation itself. Courts must balance:
privacy + confidentiality + fair trial + open justice.
18. Remedies Available for Privacy Violations
Depending on the applicable law and facts, remedies may include:
A. Compensation
Money may be awarded for legally established damage.
B. Injunction
The court may restrain:
- further publication;
- disclosure;
- misuse;
- continued processing.
C. Erasure
Where legally appropriate, personal information may need to be erased.
D. Restriction of processing
The PDPL expressly recognizes restrictions on processing in specified circumstances.
E. Restoration
The current Civil Transactions Law allows the court, depending on circumstances, to order restoration of the status quo ante as a form of compensation.
F. Declaratory relief
The court may determine that a particular disclosure or use was unlawful.
G. Confidentiality measures
Courts may use:
- restricted access;
- redaction;
- confidentiality rings;
- private hearings in appropriate cases;
- restrictions on use of disclosed documents.
DIFC procedure expressly contemplates confidentiality rings and redaction where commercially or technically confidential information is involved.
19. How Compensation Is Calculated
The claimant should separate different categories of loss.
1. Direct financial loss
Example:
A company's confidential customer database is unlawfully disclosed and identifiable customers are lost.
2. Consequential financial loss
Loss occurring as a consequence of the privacy breach.
3. Commercial value of confidentiality
This is particularly relevant where the information itself has economic value.
4. Restoration costs
Examples:
- cybersecurity investigation;
- forensic analysis;
- notification;
- remediation;
- data restoration.
5. Other legally compensable harm
Depending on the applicable legal basis and evidence, the claimant may seek compensation for other forms of damage recognized by UAE law.
20. Important Limitation: Privacy Breach Does Not Automatically Equal a Large Damages Award
This distinction is important for examination purposes.
Privacy violation ≠ automatic entitlement to any amount claimed.
The claimant must establish:
Wrongful Privacy Conduct + Protected Interest + Damage + Causation + Proof = Civil Compensation Claim
A regulatory breach may establish unlawful conduct, but the monetary claim still requires a proper legal basis and proof of compensable damage.
21. Burden of Proof and Electronic Evidence
Privacy disputes frequently turn on electronic evidence.
Important evidence includes:
- access logs;
- login records;
- IP addresses;
- email headers;
- WhatsApp messages;
- screenshots;
- cloud records;
- CCTV footage;
- database audit trails;
- metadata;
- forensic reports;
- employee devices.
The Graciela case demonstrates the importance of technical and circumstantial evidence in establishing responsibility for an electronic attack.
The Evidence Law also expressly recognizes electronically conducted evidentiary proceedings.
22. Privacy and Litigation Evidence
A common misconception is:
“If information is private, it can never be disclosed in court.”
That is incorrect.
The PDPL itself recognizes circumstances involving claiming or defending rights and lawsuits. Article 16 allows retention and certain processing necessary for litigation.
Therefore, the court may consider:
- Is the information relevant?
- Is it necessary?
- Is disclosure proportionate?
- Is it privileged?
- Does it contain third-party personal data?
- Can irrelevant information be redacted?
- Should access be restricted?
23. Privacy Violations by Employers
Employment relationships create substantial privacy risks.
Examples include:
- reading employee emails;
- monitoring private communications;
- copying employee WhatsApp data;
- excessive workplace surveillance;
- publishing employee salaries;
- disclosing medical information;
- collecting biometric information without appropriate legal basis;
- monitoring personal devices.
The legality depends on the applicable employment, data-protection, contractual and sectoral rules.
An employer should therefore distinguish between:
legitimate business monitoring
and
unnecessary or unauthorized intrusion into personal information.
24. Privacy Violations by Businesses
A company may face claims where it:
- sells customer data without lawful basis;
- shares customer information with an unauthorized party;
- exposes customer databases;
- retains unnecessary personal data;
- uses personal data for an incompatible purpose;
- fails to implement appropriate security measures;
- transfers information improperly.
The risk becomes greater where the information concerns:
- financial records;
- health information;
- biometric identifiers;
- identity documents;
- children's information;
- location data;
- authentication credentials.
25. Privacy and Automated Processing
The PDPL also addresses automated processing.
Article 18 gives a data subject a right to object to certain decisions resulting from automated processing, particularly where those decisions have legal effects or adversely affect the individual, subject to statutory exceptions.
Therefore, privacy litigation can increasingly involve:
- AI profiling;
- automated credit decisions;
- automated recruitment;
- facial recognition;
- behavioural analytics;
- predictive systems.
A claimant may need to examine not only what data was collected, but also how the data was processed and what decision resulted from it.
26. Privacy and Reputation
Privacy and reputation are closely related but should not be treated as identical.
For example:
Privacy claim
“Someone disclosed my private medical information.”
Reputation claim
“Someone published a false allegation that damaged my reputation.”
The same publication could potentially generate several legal causes of action, but each requires its own legal basis and proof.
27. Privacy Breach and Criminal Conduct
Certain privacy-related conduct may also fall within UAE criminal or cybercrime legislation.
Examples can include:
- unlawful access;
- interception;
- unauthorized disclosure;
- misuse of electronic information;
- unauthorized recording or publication.
Where criminal proceedings arise, the relationship between the criminal case and civil compensation claim must be considered carefully.
The current Civil Transactions Law specifically provides a special limitation rule where a compensation claim arises from a crime and the criminal action remains admissible.
28. Limitation Period
The current Civil Transactions Law provides that a claim for compensation arising from a harmful act generally becomes inadmissible after three years from the date the injured party becomes aware of both the damage and the person responsible.
A special rule applies where the compensation claim arises from a crime and the criminal proceedings remain admissible.
This makes the identification of:
- date of breach;
- date of knowledge;
- identity of wrongdoer;
- continuing harm;
- criminal proceedings
particularly important.
29. Mainland UAE and DIFC Distinction
| Issue | Mainland UAE | DIFC |
|---|---|---|
| General civil liability | UAE Civil Transactions Law | DIFC laws |
| Personal data | Federal PDPL, subject to scope/exclusions | DIFC Data Protection Law |
| Evidence | Federal Evidence Law | DIFC procedural/evidentiary rules |
| Confidentiality | Civil/contractual/statutory framework | DIFC Law of Obligations and related legislation |
| Privacy litigation | Federal courts where jurisdiction exists | DIFC Courts where jurisdiction exists |
| Damages | Current UAE Civil Transactions Law | DIFC damages/remedies legislation |
| Case law | Federal and local UAE courts | DIFC Courts |
DIFC cases should therefore be used as persuasive/illustrative authorities rather than automatically treated as binding mainland UAE precedents.
30. Practical Example
Suppose a financial institution employee downloads a customer's:
- Emirates ID;
- telephone number;
- bank information;
- account details;
and sends them to a third party without lawful justification.
The customer may potentially pursue several forms of relief.
Step 1 — Identify the information
Determine exactly what personal data was disclosed.
Step 2 — Identify the processing
Determine:
- who accessed it;
- who received it;
- how it was transferred;
- why it was transferred.
Step 3 — Determine legality
Examine consent, contractual necessity, statutory authorization and other lawful bases.
Step 4 — Preserve evidence
Preserve:
- access logs;
- emails;
- messages;
- database records;
- forensic evidence.
Step 5 — Establish damage
Identify actual financial or other legally compensable harm.
Step 6 — Establish causation
Show that the damage resulted from the disclosure.
Step 7 — Seek appropriate remedy
Depending on the circumstances:
- restriction;
- deletion;
- injunction;
- restoration;
- confidentiality measures;
- compensation.
31. Important Principles from the Case Law
| Case | Main principle |
|---|---|
| TVM Capital v Hashemi | Confidentiality breach can justify damages even where loss is difficult to quantify |
| DFSA v Commissioner of Data Protection | Personal data must be distinguished from entire documents |
| AES Middle East v GSB Capital | Confidentiality requires identifiable confidential information and misuse |
| Graciela v Giacobbe | Digital/forensic evidence can establish responsibility for electronic wrongdoing |
| Ahmed Almutawa v Al Mutawa | Confidentiality and legal privilege are distinct concepts |
| Kapova v Makovini | Disclosure must remain relevant and proportionate despite confidentiality |
| Heitor v Helah | Damages seek to compensate the position that would have existed absent the wrong |
| Arif Naqvi v DFSA | Privacy must be balanced against open justice |
32. Exam Formula
A useful formula is:
Privacy Interest → Unlawful Processing/Disclosure → Damage → Causation → Evidence → Appropriate Remedy
For compensation specifically:
Wrongful Act + Legally Protected Interest + Actual/Recognized Damage + Causal Link = Potential Compensation
For electronic privacy disputes:
Digital Evidence + Unauthorized Access/Disclosure + Identifiable Harm = Stronger Civil Claim
33. Key Points for Revision
- UAE privacy protection is strongly connected with the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.
- Personal data includes information capable of identifying an individual directly or indirectly.
- Privacy violation can involve collection, processing, disclosure, publication, retention or transfer.
- The PDPL provides data-subject rights concerning information, correction, erasure, restriction and objection.
- Article 16 recognizes the importance of retaining/processing data for claiming or defending legal rights.
- Civil compensation is governed by the general principles of civil liability and the current Civil Transactions Law.
- Article 256 allows monetary compensation and, where appropriate, restoration or specific corrective relief.
- Damage and causation remain important for monetary compensation.
- Electronic evidence is particularly important in privacy disputes.
- Confidentiality and privacy are related but legally distinct.
- TVM Capital v Hashemi is particularly useful for difficult-to-quantify confidentiality damages.
- DIFC authorities must be distinguished from mainland UAE precedents.
- Privacy rights do not automatically prevent disclosure of relevant litigation evidence.
- Courts can use proportionality, redaction and confidentiality mechanisms to protect sensitive information.
- The current Civil Transactions Law generally provides a three-year period for harmful-act compensation claims from knowledge of damage and the responsible person, subject to the statutory exceptions.
Conclusion
UAE civil law increasingly treats privacy as a legally protected interest rather than merely a matter of personal preference. The PDPL provides the principal framework for lawful personal-data processing, while the Civil Transactions Law provides the broader mechanism for civil compensation and corrective relief.
The central issue in a privacy compensation claim is not merely proving that information was private. The claimant should establish what information was protected, what unlawful act occurred, why the processing or disclosure was unauthorized, what damage resulted, and how that damage was caused by the violation. The DIFC decisions discussed above—especially TVM Capital, DFSA v Commissioner of Data Protection, AES Middle East, Graciela, Almutawa, Kapova, Heitor and Arif Naqvi—provide useful judicial illustrations of confidentiality, data protection, electronic evidence, proportionality and damages within the UAE legal environment.

comments