Civil Law And Uae Cross-Border Data Flows And Civil Liability Conflicts .
Civil Law and UAE Cross-Border Data Flows and Civil Liability Conflicts
1. Introduction
Cross-border data flows arise when personal, financial, commercial, health, employee, operational or other information moves from the UAE to another country for storage, processing, analysis, hosting, support, outsourcing or onward transfer.
This creates a difficult civil-liability problem because one data incident can be connected to several legal systems simultaneously.
For example:
UAE company → cloud provider in Europe → subcontractor in Asia → data accessed by an employee in another jurisdiction
If the information is lost, disclosed, altered or unlawfully processed, several questions arise:
Which country's data-protection law applies?
Which court has jurisdiction?
Which law governs the civil claim?
Was the overseas transfer lawful?
Who is responsible—the UAE controller, foreign processor, subcontractor or all of them?
Where did the damage occur?
Can a UAE judgment be enforced abroad?
Can a foreign judgment or regulatory decision be enforced in the UAE?
How should conflicting privacy and disclosure obligations be reconciled?
The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data expressly regulates transfers of personal data outside the State. Article 22 addresses transfers where an adequate level of protection exists, while Article 23 provides mechanisms for transfers where an adequate level is not available, subject to specified safeguards and circumstances. (UAE Legislation)
2. Meaning of Cross-Border Data Flow
A cross-border data flow does not necessarily require the physical shipment of a hard drive.
It can occur through:
cloud storage;
international data centres;
SaaS applications;
multinational HR platforms;
payment processors;
international banks;
global customer-service centres;
remote technical support;
international email systems;
data analytics;
AI services;
cybersecurity monitoring;
group-company databases;
international outsourcing.
Example
A UAE hospital stores patient information with a cloud provider whose servers are located in Germany.
The data may subsequently be accessed by:
the UAE hospital;
the cloud provider;
a European support team;
a subcontractor in India;
a cybersecurity provider in another jurisdiction.
The data has therefore moved through a multi-jurisdictional processing chain.
3. UAE Legal Framework
The principal general federal legislation is:
Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data
It establishes a framework for:
processing personal data;
data-subject rights;
controllers;
processors;
security;
confidentiality;
data transfers;
regulatory supervision.
Article 22 permits cross-border transfers where the destination has an appropriate data-protection framework meeting the statutory requirements or where the UAE has entered into an applicable bilateral or multilateral arrangement. (UAE Legislation)
Article 23 addresses situations where the destination does not have an adequate level of protection and identifies circumstances in which transfers may nevertheless occur, including contractual mechanisms and other prescribed safeguards. (UAE Legislation)
4. Cross-Border Transfer Is Not the Same as Data Disclosure
Three different concepts should be distinguished.
Transfer
Moving or making data available to another jurisdiction.
Processing
Collecting, storing, modifying, analysing, using or otherwise handling data.
Disclosure
Making information available to another person or authority.
One transaction may involve all three.
For example:
UAE bank → transfers customer information to foreign cloud provider → foreign provider stores and processes it → foreign regulator requests access.
Each step can generate a different legal question.
5. Controller and Processor Liability
Cross-border arrangements commonly involve:
UAE controller
Determines why and how personal data is processed.
Foreign processor
Processes data on behalf of the controller.
Subprocessor
Processes data through a downstream contractual arrangement.
Independent foreign controller
Uses the information for its own purposes.
The contractual allocation of responsibilities is therefore extremely important.
A data-processing agreement should address:
purpose of processing;
permitted jurisdictions;
security;
confidentiality;
subcontracting;
breach notification;
deletion;
return of data;
audit rights;
regulatory cooperation;
international transfers;
indemnities;
limitation of liability.
6. Civil Liability Versus Regulatory Liability
Cross-border data conflicts can produce different proceedings.
Civil proceeding
Data subject → company
for legally recoverable damage.
Contractual proceeding
UAE company → foreign processor
for breach of a data-processing contract.
Regulatory proceeding
Data-protection authority → controller/processor
for statutory non-compliance.
Criminal proceeding
State → individual/offender
for prohibited conduct.
These should not be automatically conflated.
A regulatory violation may provide important evidence, but the existence of a regulatory breach does not necessarily answer every question concerning private compensation.
7. Territorial Scope of UAE Data Protection Law
A cross-border dispute begins with determining whether UAE law applies to the relevant processing activity.
The analysis may consider:
where the controller is established;
where processing occurs;
where the data subject is located;
purpose of processing;
destination of the data;
nature of the transaction;
applicable special legislation.
This is especially important for multinational businesses.
A company may be:
incorporated in the UAE,
while:
processing data through infrastructure in another country.
The location of the server alone does not necessarily answer the question of applicable law.
8. Conflict of Laws
A cross-border data dispute can involve multiple legal systems.
For example:
| Connection | Possible legal system |
|---|---|
| UAE controller | UAE law |
| DIFC entity | DIFC law |
| ADGM entity | ADGM law |
| European processor | EU/member-state law |
| Indian subprocessor | Indian law |
| Data subject | law of another residence |
| Cloud server | law connected with hosting |
| Contract | chosen governing law |
| Litigation | law of forum |
The court therefore needs to distinguish:
Jurisdiction
Which court hears the case?
from:
Applicable law
Which law does that court apply?
from:
Recognition/enforcement
Will another jurisdiction recognise and enforce the judgment?
These are separate questions.
9. Contractual Choice of Law
A data-processing contract may state:
"This agreement is governed by UAE law."
But this does not necessarily eliminate all foreign mandatory laws.
For example, a UAE company may contract with a European processor.
The contract may select UAE law, but mandatory European data-protection requirements may still apply to processing occurring within the relevant foreign regulatory framework.
Thus:
Choice of law is important but does not necessarily eliminate mandatory regulatory rules of another jurisdiction.
10. Public Policy
Cross-border data disputes may also raise public-policy considerations.
Suppose:
UAE law permits a particular disclosure;
foreign law prohibits that disclosure;
a court in one jurisdiction orders disclosure;
the data is stored in another jurisdiction.
The parties may face conflicting legal obligations.
The court may need to consider:
applicable mandatory law;
public policy;
privacy rights;
confidentiality;
national-security requirements;
regulatory obligations;
procedural fairness.
This is particularly important in international litigation and arbitration.
11. Case Law 1 — DFSA v Commissioner of Data Protection & Waterhouse
Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse, DIFC CFI 051/2018 and CFI 085/2018
This is an important DIFC data-protection authority.
The dispute concerned a subject-access request by Anna Waterhouse to the DFSA for personal data held during regulatory investigations.
The court considered:
personal data;
subject-access rights;
regulatory investigations;
confidentiality;
exemptions;
proportionality;
interaction between data-protection rights and regulatory functions.
The court recognised that disclosure of information could raise concerns about confidentiality and the effect on regulatory investigations. (DIFC Courts)
Relevance to cross-border data flows
Although the case was not principally an international-transfer case, it illustrates a fundamental principle:
Data-protection rights must sometimes be reconciled with competing regulatory and confidentiality interests.
The same problem becomes more complicated where those interests belong to different jurisdictions.
12. Case Law 2 — Graciela Ltd v Giacobbe
Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the most significant UAE/DIFC technology-liability cases.
A former IT employee was found responsible for deliberately interfering with the claimant's IT system.
The claimant's IT infrastructure included systems located in the DIFC as well as equipment in other locations around the world.
The court relied on:
server evidence;
IP information;
access credentials;
system architecture;
witness evidence;
forensic evidence.
The court awarded USD 690,533 in compensatory damages for system restoration, investigation, emergency servers, network rebuilding and employee time. (DIFC Courts)
Cross-border significance
The case illustrates that digital systems can be geographically distributed while the legal claim remains connected to a particular forum.
It also demonstrates the importance of:
forensic evidence + causation + identifiable loss.
13. Case Law 3 — Aegis Resources DMCC v Union Bank of India
Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
This case concerned cyber fraud involving fraudulent payment instructions transmitted through a compromised email system.
The court examined the security arrangements and conduct of the parties in deciding where the loss should fall. The dispute illustrates that cyber liability cannot simply be determined by asking who was technically hacked.
Instead, the court examined:
security controls;
contractual obligations;
banking procedures;
customer conduct;
cyber fraud;
causation.
The case is particularly important for cross-border financial data and payment systems, because financial institutions frequently operate across multiple jurisdictions. (DIFC Courts)
Legal lesson
Responsibility for a cross-border cyber loss requires examination of the entire transaction and the obligations of the parties.
14. Case Law 4 — Gate MENA DMCC v Tabarak Investment Capital
Gate MENA DMCC & Huobi MENA FZE v Tabarak Investment Capital Ltd & Christian Thurner [2020] DIFC TCD 001
This technology dispute concerned cryptocurrency-related transactions and allegations of negligence.
The DIFC Technology and Construction Division considered issues including:
duty of care;
negligence;
causation;
loss;
contractual relationships;
digital assets.
The judgment was delivered on 5 October 2022. (DIFC Courts)
Cross-border significance
Digital assets and digital information can move between jurisdictions almost instantaneously.
The case therefore illustrates the need to identify:
the legal relationship + applicable duty + actual loss
rather than assuming that the location of a server or digital asset determines liability.
15. Case Law 5 — R.E. Lee International v Imran Khan
R.E. Lee International (Middle East) Ltd & R.E. Lee International (Cayman) Ltd v Imran Khan, DIFC CFI 087/2022
This litigation involved allegations concerning data breach and related disputes involving entities with international connections.
The case illustrates the procedural complexity of technology-related disputes involving entities from different jurisdictions. The DIFC Court file records extensive case-management proceedings concerning the litigation. (DIFC Courts)
Cross-border significance
It illustrates why a cross-border data claim requires careful identification of:
parties;
corporate relationships;
location of relevant information;
applicable contractual obligations;
pleaded causes of action;
evidence;
jurisdiction.
This is especially important where a UAE entity and foreign group entity share systems or information.
16. Case Law 6 — Al Khorafi v Bank Sarasin-Alpen
Al Khorafi v Bank Sarasin-Alpen (ME) Ltd [2011] DIFC CA 003
This DIFC Court of Appeal decision is important for jurisdictional analysis involving tortious claims.
The case considered the concept of an "incident" for purposes of DIFC jurisdiction and examined whether an essential component of the cause of action was connected with the DIFC.
Cross-border data significance
A data breach may have multiple locations:
UAE company
↓
foreign cloud server
↓
foreign employee
↓
UAE financial loss
The question becomes:
Where did the legally relevant incident occur?
Al Khorafi is useful by analogy for understanding why identifying the territorial connection of the cause of action matters.
It is not, however, a specific cross-border data-transfer case.
17. Case Law 7 — Schrems II
Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems, Case C-311/18
This is a major comparative authority on international data transfers.
The Court of Justice of the European Union examined transfers of personal data from the EU to the United States and considered:
adequacy;
standard contractual clauses;
foreign-government access;
privacy safeguards;
supervisory authority powers.
The Court invalidated the EU-US Privacy Shield while maintaining the validity of standard contractual clauses subject to the required safeguards and assessment of the receiving country's legal environment. (EUR-Lex)
Relevance to UAE
Schrems II is not binding UAE law, but it provides an important comparative model.
It demonstrates that:
A contractual data-transfer mechanism may not by itself eliminate the need to assess the legal environment of the destination country.
That concept is relevant when analysing the UAE's own adequacy and safeguard requirements under Articles 22–23 of Federal Decree-Law No. 45 of 2021.
18. Case Law 8 — Google Spain
Google Spain SL v Agencia Española de Protección de Datos, Case C-131/12
The European Court of Justice considered the territorial and substantive application of data-protection law to an international internet company.
The case concerned:
processing of personal data;
search engines;
territorial scope;
responsibility of the operator;
data-subject rights.
The Court recognised circumstances in which a search-engine operator's activities through an establishment in a Member State could bring processing within the applicable European data-protection framework. (EUR-Lex)
UAE significance
Again, this is comparative rather than binding UAE authority.
Its importance lies in demonstrating that:
Territorial data-protection responsibility can extend beyond the physical location of the server.
That is a central issue in UAE multinational data processing.
19. The Adequacy Principle
Under Article 22 of the UAE Personal Data Protection Law, cross-border transfers can occur where the destination has an appropriate legal framework for personal-data protection and the required rights and enforcement mechanisms. (UAE Legislation)
The underlying concept is:
Destination jurisdiction → adequate protection → lawful transfer
This requires businesses to assess the legal environment of the receiving country rather than treating international transfer as purely technical.
20. Transfers to Countries Without Adequate Protection
Article 23 addresses situations where an adequate level of protection is not available.
The legislation nevertheless identifies circumstances where transfers may occur, including contractual arrangements and other prescribed safeguards. (UAE Legislation)
Therefore:
No adequacy decision does not necessarily mean that international transfer is impossible.
Instead, the organisation must identify and satisfy the applicable statutory mechanism.
21. DIFC Cross-Border Data Transfers
The DIFC operates under its own data-protection regime.
The DIFC framework contains rules concerning international transfers and appropriate protection mechanisms.
The DFSA v Commissioner of Data Protection litigation illustrates that DIFC data protection can involve sophisticated questions concerning:
regulatory investigations;
access rights;
confidentiality;
personal data;
competing legal obligations. (DIFC Courts)
Because DIFC legislation is distinct from federal onshore legislation, a DIFC transfer should not simply be analysed under the federal PDPL without checking the applicable DIFC framework.
22. ADGM Cross-Border Data Transfers
ADGM also has its own data-protection regime.
The ADGM Office of Data Protection states that personal data generally may be transferred outside ADGM where the recipient jurisdiction provides an adequate level of protection or where an appropriate safeguard or derogation under the Regulations applies. (ADGM)
ADGM recognises Standard Contractual Clauses as one possible safeguard for international transfers to jurisdictions without adequate protection. (ADGM)
Its adequacy framework expressly identifies jurisdictions considered adequate under its regime. (ADGM)
Thus, a UAE multinational group must first identify whether the data originates from:
onshore UAE;
DIFC;
ADGM.
The answer can materially change the transfer analysis.
23. Conflict Between UAE and Foreign Privacy Laws
Consider this example.
A UAE company transfers employee data to a foreign HR provider.
The UAE law requires a particular transfer safeguard.
The foreign country requires:
local retention of certain employment records.
A third country then demands disclosure for a regulatory investigation.
Three obligations may conflict:
UAE
Privacy and transfer requirements.
Foreign processing country
Data protection and employment requirements.
Third country
Regulatory disclosure requirement.
The business must determine:
whether the disclosure is lawful;
whether the data can be transferred;
whether consent is relevant;
whether a statutory exception applies;
whether the contract allocates the risk;
whether the conflict should be referred to a court or regulator.
24. Civil Liability for Unlawful Transfer
An unlawful transfer can potentially create several categories of liability.
A. Regulatory
Administrative or regulatory consequences.
B. Contractual
The controller may sue the processor for breach of its data-processing agreement.
C. Civil
A data subject or other claimant may seek legally available compensation where the necessary elements are established.
D. Confidentiality
A contractual or equitable confidentiality obligation may have been violated.
E. Employment
Employee data may generate employment-related claims.
F. Professional negligence
A service provider may face claims for inadequate safeguards where a relevant duty exists.
25. Causation in Cross-Border Data Claims
This is one of the hardest issues.
Suppose:
UAE controller
fails to encrypt data
↓
Foreign processor
stores it
↓
Foreign hacker
steals it
↓
Data subject
suffers financial loss.
Who caused the loss?
Potential defendants might argue:
the controller caused the vulnerability;
the processor failed to secure the data;
the hacker was the independent cause;
the data subject contributed to the loss.
The court must establish the causal chain.
Graciela demonstrates how detailed technical evidence can be used to connect an individual to an IT attack and quantify the resulting loss. (DIFC Courts)
26. Data Breach Does Not Automatically Equal Compensation
A crucial principle is:
Proof of a data incident is not necessarily proof of compensable civil damage.
A claimant should ordinarily identify:
the data involved;
the unlawful act or omission;
the applicable legal duty;
the responsible party;
causal connection;
actual legally recoverable damage.
This becomes particularly important in cross-border claims where different legal systems may define compensable harm differently.
27. Cybersecurity and Cross-Border Data Liability
A company can comply with transfer rules and still have a cybersecurity failure.
For example:
UAE company lawfully transfers data to a foreign processor.
But:
foreign processor negligently leaves the database exposed.
There may be no illegality in the initial transfer, but there could still be liability for:
inadequate security;
breach of contract;
confidentiality violation;
data-protection non-compliance.
Therefore:
Lawful transfer ≠ lawful processing in every respect.
28. Data Processing Agreements
A strong cross-border data-processing agreement should identify:
1. Data categories
What data is being transferred?
2. Purpose
Why is it transferred?
3. Destination
Where can the data go?
4. Subprocessors
Who can access it?
5. Security
What controls must exist?
6. Breach notification
How quickly must an incident be reported?
7. Government requests
What happens if a foreign authority demands disclosure?
8. Audit
Can the UAE controller inspect compliance?
9. Deletion
When must data be deleted?
10. Liability
Who bears financial responsibility?
29. Government Access to Data
One of the most difficult cross-border issues concerns foreign government access.
For example:
UAE data is stored on servers in Country X.
Country X's law permits its authorities to demand access to certain data.
The UAE organisation may then face:
Foreign disclosure obligation
versus
UAE confidentiality/data-protection obligation.
This is precisely the type of structural conflict that made Schrems II significant in the European context. The CJEU examined whether the destination jurisdiction provided protections sufficiently equivalent to those required by EU law. (EUR-Lex)
The UAE framework similarly makes the protection available in the destination jurisdiction relevant to lawful cross-border transfers. (UAE Legislation)
30. Data Localisation Versus Data Transfer
Data localisation means requiring certain data to remain within a particular territory.
Cross-border transfer rules are different.
Localisation
"The data must remain here."
Transfer regulation
"The data may leave, but only if specified legal conditions are satisfied."
The UAE's general PDPL transfer provisions should therefore not be confused with an absolute universal requirement that all personal data remain physically inside the UAE.
Sector-specific rules can, however, impose additional requirements.
31. Sector-Specific Data
Cross-border conflicts become particularly sensitive for:
banking;
healthcare;
insurance;
telecommunications;
government;
national security;
critical infrastructure.
For example, financial institutions may have regulatory requirements beyond the general personal-data regime.
The Aegis Resources litigation demonstrates how financial transactions and cyber risk can interact with contractual and security obligations. (DIFC Courts)
32. Cloud Computing
Cloud computing creates a special cross-border problem.
A UAE company may not know the physical location of every processing activity at every moment.
A cloud architecture could involve:
UAE customer
↓
regional cloud
↓
automated replication
↓
backup in another country
↓
support access from another country
The contract should therefore identify:
permitted regions;
subprocessors;
replication;
backups;
support access;
government requests;
deletion;
audit rights.
33. AI and Cross-Border Data
AI systems create an additional layer.
A UAE company may upload customer information to an AI service whose:
model infrastructure is overseas;
support personnel are overseas;
logging system is overseas;
subprocessors are overseas.
This can create questions about:
lawful transfer;
purpose limitation;
data minimisation;
confidentiality;
automated processing;
security;
intellectual property;
contractual liability.
The legal issue is therefore not simply:
"Where is the AI company incorporated?"
It may be:
Where is personal data processed, who controls the processing, what safeguards exist, and what laws govern each stage?
34. Jurisdictional Problems
A cross-border data claim may involve:
Claimant in UAE
Controller in UAE
Processor in France
Subprocessor in India
Cloud server in Singapore
Data subject in UAE
Hacker in an unknown country
Which court hears the case?
Potential jurisdictional connecting factors include:
defendant's domicile;
place of contractual performance;
place of damage;
agreed jurisdiction clause;
applicable statutory jurisdiction;
DIFC/ADGM connection;
arbitration agreement.
The Al Khorafi line of DIFC jurisdictional jurisprudence is useful in understanding the importance of identifying the legally relevant incident and its connection with the forum.
35. Choice of Forum and Choice of Law
Cross-border contracts should ideally separately address:
Governing law
UAE law.
Forum
UAE courts.
Arbitration
DIFC/DIAC/other agreed arbitration.
Data-protection compliance
Each party must comply with mandatory data-protection laws applicable to its processing activities.
These clauses perform different functions.
A governing-law clause does not automatically establish jurisdiction.
A jurisdiction clause does not necessarily eliminate mandatory foreign data-protection law.
36. Recognition and Enforcement
Suppose a UAE company obtains a judgment against a foreign processor.
The defendant has assets in:
France, Singapore and India.
The UAE judgment may need to be recognised and enforced in those jurisdictions.
Conversely, a foreign judgment against a UAE company may need recognition and enforcement in the UAE.
Therefore, cross-border data disputes can ultimately become:
private international law + enforcement law + data-protection law
problems.
37. Damages in Cross-Border Data Litigation
Potential losses may include:
forensic investigation;
notification expenses;
data restoration;
system replacement;
business interruption;
contractual penalties where legally recoverable;
regulatory response;
customer remediation;
professional fees where recoverable;
proven financial loss.
But recovery depends on the governing law.
Graciela is an instructive DIFC example because the court accepted documented restoration and investigation expenses and certain employee costs resulting from the cyber incident. (DIFC Courts)
38. Conflicting Foreign Disclosure Orders
Consider:
A UAE company receives a foreign court order demanding production of customer data.
At the same time:
UAE law restricts the transfer or disclosure.
The company should not simply ignore either legal obligation.
The issue may require:
review of the foreign order;
assessment of UAE law;
examination of confidentiality obligations;
consultation with relevant regulators;
possible protective order;
narrowing of disclosure;
anonymisation or redaction;
secure transfer where legally permitted.
This is an area where international judicial cooperation becomes particularly important.
39. Eight Case Laws — Quick Revision Table
| Case | Jurisdiction | Main principle |
|---|---|---|
| DFSA v Commissioner of Data Protection & Waterhouse, CFI 051/2018 & 085/2018 | DIFC | Data rights balanced against regulatory functions and confidentiality |
| Graciela Ltd v Giacobbe [2014] DIFC CFI 027 | DIFC | IT interference, forensic evidence, causation and damages |
| Aegis Resources DMCC v Union Bank of India, CFI 004/2020 | DIFC | Cyber fraud, security controls and allocation of loss |
| Gate MENA DMCC v Tabarak Investment Capital [2020] DIFC TCD 001 | DIFC | Digital-asset negligence, duty, causation and loss |
| R.E. Lee International v Imran Khan, CFI 087/2022 | DIFC | Technology/data-breach litigation and procedural complexity |
| Al Khorafi v Bank Sarasin-Alpen [2011] DIFC CA 003 | DIFC | Territorial jurisdiction and legally relevant incident |
| Schrems II, Case C-311/18 | EU | Adequacy, safeguards and third-country government access |
| Google Spain, Case C-131/12 | EU | Territorial scope and responsibility for cross-border online processing |
The last two are comparative authorities, not binding UAE precedents. (EUR-Lex)
40. Comparative Significance of Schrems II for UAE Law
The comparison can be expressed as follows:
| Question | UAE | Schrems II approach |
|---|---|---|
| Adequacy | Relevant under Article 22 | Central to third-country transfers |
| Contractual safeguards | Relevant under Article 23 | Standard contractual clauses recognised subject to safeguards |
| Destination-country law | Relevant | Detailed examination required |
| Government access | Relevant to protection level | Central issue |
| Controller responsibility | Important | Controller must assess safeguards |
| Cross-border risk | Regulated | Regulated through transfer mechanisms |
The comparison is useful but should not be treated as importing EU law into the UAE.
41. Conflict Matrix
A useful way to analyse a UAE cross-border data dispute is:
| Question | Relevant inquiry |
|---|---|
| Who? | Controller, processor, subprocessor or third party? |
| What? | Personal, financial, health, commercial or confidential data? |
| Where? | UAE, DIFC, ADGM or foreign jurisdiction? |
| Why? | Purpose of processing |
| How? | Cloud, outsourcing, transfer, remote access |
| Which law? | UAE, DIFC, ADGM or foreign law |
| Which court? | Jurisdiction/forum |
| Which safeguards? | Adequacy, contract, statutory exception or other mechanism |
| What damage? | Financial, privacy, operational or reputational |
| Who pays? | Controller, processor, insurer or another responsible party |
42. Practical Example
Assume a UAE bank uses a foreign cloud provider.
Stage 1 — Transfer
Customer data moves from UAE to the foreign cloud environment.
Stage 2 — Processing
The foreign provider processes and stores the information.
Stage 3 — Subprocessing
A foreign cybersecurity company obtains access.
Stage 4 — Incident
An employee of the subprocessor improperly downloads customer information.
Stage 5 — Regulatory issue
The UAE bank must determine whether the transfer and processing complied with applicable UAE requirements.
Stage 6 — Civil issue
Customers may assert legally available claims if the necessary elements of liability and damage are established.
Stage 7 — Contractual issue
The bank may seek recovery from the cloud provider or subprocessor under the contractual allocation of responsibility.
Stage 8 — Foreign issue
The subprocessor may be subject to the law of its own jurisdiction.
The dispute therefore becomes a multi-layered conflict-of-laws problem.
43. Defences Available to a Data Processor
Depending on the governing law and contract, a processor may argue:
no breach occurred;
transfer was lawful;
appropriate safeguards existed;
another party controlled the relevant processing;
the incident was caused by an independent attacker;
no legally compensable damage was established;
claimant contributed to the loss;
contractual limitation applies;
force majeure applies;
the claim is time-barred;
wrong forum;
wrong defendant.
The controller may similarly argue that:
the processor contractually assumed responsibility for security and compliance.
44. Civil Liability of the UAE Controller
A UAE controller should not assume that outsourcing eliminates its responsibility.
The controller should conduct due diligence regarding:
foreign processor;
security;
destination country;
subprocessors;
transfer mechanism;
contractual protections;
regulatory restrictions.
The underlying principle is:
Outsourcing processing does not necessarily mean outsourcing legal responsibility.
The precise allocation depends on the applicable statute and contractual relationship.
45. Civil Liability of the Foreign Processor
A foreign processor may face UAE-related claims where:
the contract permits UAE litigation;
UAE law governs;
jurisdiction exists;
the processor has sufficient connection with the UAE forum;
the processing relationship creates a relevant cause of action.
The foreign processor may nevertheless invoke:
jurisdiction;
arbitration;
governing-law clause;
limitation of liability;
foreign mandatory law.
46. Importance of Evidence
Cross-border data disputes require detailed technical evidence.
Useful evidence includes:
data-flow maps;
transfer logs;
processing records;
data-processing agreements;
subprocessor agreements;
access logs;
encryption records;
security assessments;
incident reports;
data-protection impact assessments;
regulatory correspondence;
cloud architecture;
contractual schedules;
audit reports.
Graciela illustrates the importance of technical evidence in proving responsibility and quantifying loss in a technology dispute. (DIFC Courts)
47. Compliance Model for UAE Businesses
A UAE business transferring personal data internationally should ideally establish:
Before transfer
identify the data;
identify destination;
identify recipient;
determine applicable law;
assess adequacy;
select lawful safeguard;
document the transfer.
During processing
monitor security;
control access;
monitor subprocessors;
maintain records;
respond to incidents.
After an incident
preserve evidence;
investigate;
notify relevant parties/regulators where legally required;
assess affected individuals;
determine contractual liability;
calculate loss;
consider litigation and insurance.
48. Current UAE Legal Position
The key federal provision is the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.
Articles 22–23 create a structured framework for transfers outside the UAE, distinguishing transfers to jurisdictions with an appropriate protection level from transfers where such protection is unavailable. (UAE Legislation)
For DIFC, the separate DIFC data-protection framework must be considered.
For ADGM, its Data Protection Regulations 2021 and Office of Data Protection guidance govern the relevant ADGM transfer. ADGM expressly provides for adequacy decisions and alternative safeguards such as standard contractual clauses. (ADGM)
49. Important Distinction Between Onshore UAE, DIFC and ADGM
| System | Data-transfer framework |
|---|---|
| Onshore UAE | Federal PDPL, Federal Decree-Law No. 45 of 2021 |
| DIFC | DIFC-specific data-protection legislation |
| ADGM | ADGM Data Protection Regulations 2021 |
| Foreign jurisdiction | Relevant foreign privacy/data laws |
Therefore, the phrase "UAE data law" is not always sufficient for legal analysis.
The first question should be:
Where is the relevant entity/data-processing activity legally situated?
50. Conclusion
Cross-border data flows create a particularly complex form of UAE civil liability because data is geographically mobile while legal responsibility remains territorially structured.
The central analytical chain is:
Data → Controller → Transfer → Destination → Safeguard → Processing → Incident → Damage → Applicable law → Jurisdiction → Remedy
The UAE's Federal Personal Data Protection Law regulates international transfers through adequacy and alternative safeguards. (UAE Legislation) DIFC and ADGM have separate regimes that must be considered where their territorial frameworks apply. (DIFC Courts)
The UAE/DIFC authorities such as DFSA v Commissioner of Data Protection, Graciela v Giacobbe, Aegis Resources v Union Bank of India, Gate MENA v Tabarak, R.E. Lee International v Imran Khan, and Al Khorafi v Bank Sarasin-Alpen demonstrate different aspects of data rights, technology liability, cyber loss, jurisdiction and evidence. The comparative Schrems II and Google Spain decisions provide useful international guidance on adequacy, third-country transfers and territorial responsibility, but they are not binding UAE precedents. (EUR-Lex)
Important current-law qualification: UAE civil-liability analysis should also take account of the 2025 Civil Transactions Law, effective from 1 June 2026, where a claim is based on general civil responsibility. Older UAE/DIFC cases interpreting earlier legislation should be treated according to their jurisdiction, date and statutory context rather than automatically assumed to state the current onshore UAE law.

comments