Civil Law And Uae Cross-Border Data Flows And Civil Liability Conflicts .

Civil Law and UAE Cross-Border Data Flows and Civil Liability Conflicts

1. Introduction

Cross-border data flows arise when personal, financial, commercial, health, employee, operational or other information moves from the UAE to another country for storage, processing, analysis, hosting, support, outsourcing or onward transfer.

This creates a difficult civil-liability problem because one data incident can be connected to several legal systems simultaneously.

For example:

UAE company → cloud provider in Europe → subcontractor in Asia → data accessed by an employee in another jurisdiction

If the information is lost, disclosed, altered or unlawfully processed, several questions arise:

Which country's data-protection law applies?

Which court has jurisdiction?

Which law governs the civil claim?

Was the overseas transfer lawful?

Who is responsible—the UAE controller, foreign processor, subcontractor or all of them?

Where did the damage occur?

Can a UAE judgment be enforced abroad?

Can a foreign judgment or regulatory decision be enforced in the UAE?

How should conflicting privacy and disclosure obligations be reconciled?

The UAE's Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data expressly regulates transfers of personal data outside the State. Article 22 addresses transfers where an adequate level of protection exists, while Article 23 provides mechanisms for transfers where an adequate level is not available, subject to specified safeguards and circumstances. (UAE Legislation)

2. Meaning of Cross-Border Data Flow

A cross-border data flow does not necessarily require the physical shipment of a hard drive.

It can occur through:

cloud storage;

international data centres;

SaaS applications;

multinational HR platforms;

payment processors;

international banks;

global customer-service centres;

remote technical support;

international email systems;

data analytics;

AI services;

cybersecurity monitoring;

group-company databases;

international outsourcing.

Example

A UAE hospital stores patient information with a cloud provider whose servers are located in Germany.

The data may subsequently be accessed by:

the UAE hospital;

the cloud provider;

a European support team;

a subcontractor in India;

a cybersecurity provider in another jurisdiction.

The data has therefore moved through a multi-jurisdictional processing chain.

3. UAE Legal Framework

The principal general federal legislation is:

Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data

It establishes a framework for:

processing personal data;

data-subject rights;

controllers;

processors;

security;

confidentiality;

data transfers;

regulatory supervision.

Article 22 permits cross-border transfers where the destination has an appropriate data-protection framework meeting the statutory requirements or where the UAE has entered into an applicable bilateral or multilateral arrangement. (UAE Legislation)

Article 23 addresses situations where the destination does not have an adequate level of protection and identifies circumstances in which transfers may nevertheless occur, including contractual mechanisms and other prescribed safeguards. (UAE Legislation)

4. Cross-Border Transfer Is Not the Same as Data Disclosure

Three different concepts should be distinguished.

Transfer

Moving or making data available to another jurisdiction.

Processing

Collecting, storing, modifying, analysing, using or otherwise handling data.

Disclosure

Making information available to another person or authority.

One transaction may involve all three.

For example:

UAE bank → transfers customer information to foreign cloud provider → foreign provider stores and processes it → foreign regulator requests access.

Each step can generate a different legal question.

5. Controller and Processor Liability

Cross-border arrangements commonly involve:

UAE controller

Determines why and how personal data is processed.

Foreign processor

Processes data on behalf of the controller.

Subprocessor

Processes data through a downstream contractual arrangement.

Independent foreign controller

Uses the information for its own purposes.

The contractual allocation of responsibilities is therefore extremely important.

A data-processing agreement should address:

purpose of processing;

permitted jurisdictions;

security;

confidentiality;

subcontracting;

breach notification;

deletion;

return of data;

audit rights;

regulatory cooperation;

international transfers;

indemnities;

limitation of liability.

6. Civil Liability Versus Regulatory Liability

Cross-border data conflicts can produce different proceedings.

Civil proceeding

Data subject → company

for legally recoverable damage.

Contractual proceeding

UAE company → foreign processor

for breach of a data-processing contract.

Regulatory proceeding

Data-protection authority → controller/processor

for statutory non-compliance.

Criminal proceeding

State → individual/offender

for prohibited conduct.

These should not be automatically conflated.

A regulatory violation may provide important evidence, but the existence of a regulatory breach does not necessarily answer every question concerning private compensation.

7. Territorial Scope of UAE Data Protection Law

A cross-border dispute begins with determining whether UAE law applies to the relevant processing activity.

The analysis may consider:

where the controller is established;

where processing occurs;

where the data subject is located;

purpose of processing;

destination of the data;

nature of the transaction;

applicable special legislation.

This is especially important for multinational businesses.

A company may be:

incorporated in the UAE,

while:

processing data through infrastructure in another country.

The location of the server alone does not necessarily answer the question of applicable law.

8. Conflict of Laws

A cross-border data dispute can involve multiple legal systems.

For example:

ConnectionPossible legal system
UAE controllerUAE law
DIFC entityDIFC law
ADGM entityADGM law
European processorEU/member-state law
Indian subprocessorIndian law
Data subjectlaw of another residence
Cloud serverlaw connected with hosting
Contractchosen governing law
Litigationlaw of forum

The court therefore needs to distinguish:

Jurisdiction

Which court hears the case?

from:

Applicable law

Which law does that court apply?

from:

Recognition/enforcement

Will another jurisdiction recognise and enforce the judgment?

These are separate questions.

9. Contractual Choice of Law

A data-processing contract may state:

"This agreement is governed by UAE law."

But this does not necessarily eliminate all foreign mandatory laws.

For example, a UAE company may contract with a European processor.

The contract may select UAE law, but mandatory European data-protection requirements may still apply to processing occurring within the relevant foreign regulatory framework.

Thus:

Choice of law is important but does not necessarily eliminate mandatory regulatory rules of another jurisdiction.

10. Public Policy

Cross-border data disputes may also raise public-policy considerations.

Suppose:

UAE law permits a particular disclosure;

foreign law prohibits that disclosure;

a court in one jurisdiction orders disclosure;

the data is stored in another jurisdiction.

The parties may face conflicting legal obligations.

The court may need to consider:

applicable mandatory law;

public policy;

privacy rights;

confidentiality;

national-security requirements;

regulatory obligations;

procedural fairness.

This is particularly important in international litigation and arbitration.

11. Case Law 1 — DFSA v Commissioner of Data Protection & Waterhouse

Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse, DIFC CFI 051/2018 and CFI 085/2018

This is an important DIFC data-protection authority.

The dispute concerned a subject-access request by Anna Waterhouse to the DFSA for personal data held during regulatory investigations.

The court considered:

personal data;

subject-access rights;

regulatory investigations;

confidentiality;

exemptions;

proportionality;

interaction between data-protection rights and regulatory functions.

The court recognised that disclosure of information could raise concerns about confidentiality and the effect on regulatory investigations. (DIFC Courts)

Relevance to cross-border data flows

Although the case was not principally an international-transfer case, it illustrates a fundamental principle:

Data-protection rights must sometimes be reconciled with competing regulatory and confidentiality interests.

The same problem becomes more complicated where those interests belong to different jurisdictions.

12. Case Law 2 — Graciela Ltd v Giacobbe

Graciela Limited v Giacobbe [2014] DIFC CFI 027

This is one of the most significant UAE/DIFC technology-liability cases.

A former IT employee was found responsible for deliberately interfering with the claimant's IT system.

The claimant's IT infrastructure included systems located in the DIFC as well as equipment in other locations around the world.

The court relied on:

server evidence;

IP information;

access credentials;

system architecture;

witness evidence;

forensic evidence.

The court awarded USD 690,533 in compensatory damages for system restoration, investigation, emergency servers, network rebuilding and employee time. (DIFC Courts)

Cross-border significance

The case illustrates that digital systems can be geographically distributed while the legal claim remains connected to a particular forum.

It also demonstrates the importance of:

forensic evidence + causation + identifiable loss.

13. Case Law 3 — Aegis Resources DMCC v Union Bank of India

Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004

This case concerned cyber fraud involving fraudulent payment instructions transmitted through a compromised email system.

The court examined the security arrangements and conduct of the parties in deciding where the loss should fall. The dispute illustrates that cyber liability cannot simply be determined by asking who was technically hacked.

Instead, the court examined:

security controls;

contractual obligations;

banking procedures;

customer conduct;

cyber fraud;

causation.

The case is particularly important for cross-border financial data and payment systems, because financial institutions frequently operate across multiple jurisdictions. (DIFC Courts)

Legal lesson

Responsibility for a cross-border cyber loss requires examination of the entire transaction and the obligations of the parties.

14. Case Law 4 — Gate MENA DMCC v Tabarak Investment Capital

Gate MENA DMCC & Huobi MENA FZE v Tabarak Investment Capital Ltd & Christian Thurner [2020] DIFC TCD 001

This technology dispute concerned cryptocurrency-related transactions and allegations of negligence.

The DIFC Technology and Construction Division considered issues including:

duty of care;

negligence;

causation;

loss;

contractual relationships;

digital assets.

The judgment was delivered on 5 October 2022. (DIFC Courts)

Cross-border significance

Digital assets and digital information can move between jurisdictions almost instantaneously.

The case therefore illustrates the need to identify:

the legal relationship + applicable duty + actual loss

rather than assuming that the location of a server or digital asset determines liability.

15. Case Law 5 — R.E. Lee International v Imran Khan

R.E. Lee International (Middle East) Ltd & R.E. Lee International (Cayman) Ltd v Imran Khan, DIFC CFI 087/2022

This litigation involved allegations concerning data breach and related disputes involving entities with international connections.

The case illustrates the procedural complexity of technology-related disputes involving entities from different jurisdictions. The DIFC Court file records extensive case-management proceedings concerning the litigation. (DIFC Courts)

Cross-border significance

It illustrates why a cross-border data claim requires careful identification of:

parties;

corporate relationships;

location of relevant information;

applicable contractual obligations;

pleaded causes of action;

evidence;

jurisdiction.

This is especially important where a UAE entity and foreign group entity share systems or information.

16. Case Law 6 — Al Khorafi v Bank Sarasin-Alpen

Al Khorafi v Bank Sarasin-Alpen (ME) Ltd [2011] DIFC CA 003

This DIFC Court of Appeal decision is important for jurisdictional analysis involving tortious claims.

The case considered the concept of an "incident" for purposes of DIFC jurisdiction and examined whether an essential component of the cause of action was connected with the DIFC.

Cross-border data significance

A data breach may have multiple locations:

UAE company

foreign cloud server

foreign employee

UAE financial loss

The question becomes:

Where did the legally relevant incident occur?

Al Khorafi is useful by analogy for understanding why identifying the territorial connection of the cause of action matters.

It is not, however, a specific cross-border data-transfer case.

17. Case Law 7 — Schrems II

Data Protection Commissioner v Facebook Ireland Ltd and Maximillian Schrems, Case C-311/18

This is a major comparative authority on international data transfers.

The Court of Justice of the European Union examined transfers of personal data from the EU to the United States and considered:

adequacy;

standard contractual clauses;

foreign-government access;

privacy safeguards;

supervisory authority powers.

The Court invalidated the EU-US Privacy Shield while maintaining the validity of standard contractual clauses subject to the required safeguards and assessment of the receiving country's legal environment. (EUR-Lex)

Relevance to UAE

Schrems II is not binding UAE law, but it provides an important comparative model.

It demonstrates that:

A contractual data-transfer mechanism may not by itself eliminate the need to assess the legal environment of the destination country.

That concept is relevant when analysing the UAE's own adequacy and safeguard requirements under Articles 22–23 of Federal Decree-Law No. 45 of 2021.

18. Case Law 8 — Google Spain

Google Spain SL v Agencia Española de Protección de Datos, Case C-131/12

The European Court of Justice considered the territorial and substantive application of data-protection law to an international internet company.

The case concerned:

processing of personal data;

search engines;

territorial scope;

responsibility of the operator;

data-subject rights.

The Court recognised circumstances in which a search-engine operator's activities through an establishment in a Member State could bring processing within the applicable European data-protection framework. (EUR-Lex)

UAE significance

Again, this is comparative rather than binding UAE authority.

Its importance lies in demonstrating that:

Territorial data-protection responsibility can extend beyond the physical location of the server.

That is a central issue in UAE multinational data processing.

19. The Adequacy Principle

Under Article 22 of the UAE Personal Data Protection Law, cross-border transfers can occur where the destination has an appropriate legal framework for personal-data protection and the required rights and enforcement mechanisms. (UAE Legislation)

The underlying concept is:

Destination jurisdiction → adequate protection → lawful transfer

This requires businesses to assess the legal environment of the receiving country rather than treating international transfer as purely technical.

20. Transfers to Countries Without Adequate Protection

Article 23 addresses situations where an adequate level of protection is not available.

The legislation nevertheless identifies circumstances where transfers may occur, including contractual arrangements and other prescribed safeguards. (UAE Legislation)

Therefore:

No adequacy decision does not necessarily mean that international transfer is impossible.

Instead, the organisation must identify and satisfy the applicable statutory mechanism.

21. DIFC Cross-Border Data Transfers

The DIFC operates under its own data-protection regime.

The DIFC framework contains rules concerning international transfers and appropriate protection mechanisms.

The DFSA v Commissioner of Data Protection litigation illustrates that DIFC data protection can involve sophisticated questions concerning:

regulatory investigations;

access rights;

confidentiality;

personal data;

competing legal obligations. (DIFC Courts)

Because DIFC legislation is distinct from federal onshore legislation, a DIFC transfer should not simply be analysed under the federal PDPL without checking the applicable DIFC framework.

22. ADGM Cross-Border Data Transfers

ADGM also has its own data-protection regime.

The ADGM Office of Data Protection states that personal data generally may be transferred outside ADGM where the recipient jurisdiction provides an adequate level of protection or where an appropriate safeguard or derogation under the Regulations applies. (ADGM)

ADGM recognises Standard Contractual Clauses as one possible safeguard for international transfers to jurisdictions without adequate protection. (ADGM)

Its adequacy framework expressly identifies jurisdictions considered adequate under its regime. (ADGM)

Thus, a UAE multinational group must first identify whether the data originates from:

onshore UAE;

DIFC;

ADGM.

The answer can materially change the transfer analysis.

23. Conflict Between UAE and Foreign Privacy Laws

Consider this example.

A UAE company transfers employee data to a foreign HR provider.

The UAE law requires a particular transfer safeguard.

The foreign country requires:

local retention of certain employment records.

A third country then demands disclosure for a regulatory investigation.

Three obligations may conflict:

UAE

Privacy and transfer requirements.

Foreign processing country

Data protection and employment requirements.

Third country

Regulatory disclosure requirement.

The business must determine:

whether the disclosure is lawful;

whether the data can be transferred;

whether consent is relevant;

whether a statutory exception applies;

whether the contract allocates the risk;

whether the conflict should be referred to a court or regulator.

24. Civil Liability for Unlawful Transfer

An unlawful transfer can potentially create several categories of liability.

A. Regulatory

Administrative or regulatory consequences.

B. Contractual

The controller may sue the processor for breach of its data-processing agreement.

C. Civil

A data subject or other claimant may seek legally available compensation where the necessary elements are established.

D. Confidentiality

A contractual or equitable confidentiality obligation may have been violated.

E. Employment

Employee data may generate employment-related claims.

F. Professional negligence

A service provider may face claims for inadequate safeguards where a relevant duty exists.

25. Causation in Cross-Border Data Claims

This is one of the hardest issues.

Suppose:

UAE controller

fails to encrypt data

Foreign processor

stores it

Foreign hacker

steals it

Data subject

suffers financial loss.

Who caused the loss?

Potential defendants might argue:

the controller caused the vulnerability;

the processor failed to secure the data;

the hacker was the independent cause;

the data subject contributed to the loss.

The court must establish the causal chain.

Graciela demonstrates how detailed technical evidence can be used to connect an individual to an IT attack and quantify the resulting loss. (DIFC Courts)

26. Data Breach Does Not Automatically Equal Compensation

A crucial principle is:

Proof of a data incident is not necessarily proof of compensable civil damage.

A claimant should ordinarily identify:

the data involved;

the unlawful act or omission;

the applicable legal duty;

the responsible party;

causal connection;

actual legally recoverable damage.

This becomes particularly important in cross-border claims where different legal systems may define compensable harm differently.

27. Cybersecurity and Cross-Border Data Liability

A company can comply with transfer rules and still have a cybersecurity failure.

For example:

UAE company lawfully transfers data to a foreign processor.

But:

foreign processor negligently leaves the database exposed.

There may be no illegality in the initial transfer, but there could still be liability for:

inadequate security;

breach of contract;

confidentiality violation;

data-protection non-compliance.

Therefore:

Lawful transfer ≠ lawful processing in every respect.

28. Data Processing Agreements

A strong cross-border data-processing agreement should identify:

1. Data categories

What data is being transferred?

2. Purpose

Why is it transferred?

3. Destination

Where can the data go?

4. Subprocessors

Who can access it?

5. Security

What controls must exist?

6. Breach notification

How quickly must an incident be reported?

7. Government requests

What happens if a foreign authority demands disclosure?

8. Audit

Can the UAE controller inspect compliance?

9. Deletion

When must data be deleted?

10. Liability

Who bears financial responsibility?

29. Government Access to Data

One of the most difficult cross-border issues concerns foreign government access.

For example:

UAE data is stored on servers in Country X.

Country X's law permits its authorities to demand access to certain data.

The UAE organisation may then face:

Foreign disclosure obligation

versus

UAE confidentiality/data-protection obligation.

This is precisely the type of structural conflict that made Schrems II significant in the European context. The CJEU examined whether the destination jurisdiction provided protections sufficiently equivalent to those required by EU law. (EUR-Lex)

The UAE framework similarly makes the protection available in the destination jurisdiction relevant to lawful cross-border transfers. (UAE Legislation)

30. Data Localisation Versus Data Transfer

Data localisation means requiring certain data to remain within a particular territory.

Cross-border transfer rules are different.

Localisation

"The data must remain here."

Transfer regulation

"The data may leave, but only if specified legal conditions are satisfied."

The UAE's general PDPL transfer provisions should therefore not be confused with an absolute universal requirement that all personal data remain physically inside the UAE.

Sector-specific rules can, however, impose additional requirements.

31. Sector-Specific Data

Cross-border conflicts become particularly sensitive for:

banking;

healthcare;

insurance;

telecommunications;

government;

national security;

critical infrastructure.

For example, financial institutions may have regulatory requirements beyond the general personal-data regime.

The Aegis Resources litigation demonstrates how financial transactions and cyber risk can interact with contractual and security obligations. (DIFC Courts)

32. Cloud Computing

Cloud computing creates a special cross-border problem.

A UAE company may not know the physical location of every processing activity at every moment.

A cloud architecture could involve:

UAE customer

regional cloud

automated replication

backup in another country

support access from another country

The contract should therefore identify:

permitted regions;

subprocessors;

replication;

backups;

support access;

government requests;

deletion;

audit rights.

33. AI and Cross-Border Data

AI systems create an additional layer.

A UAE company may upload customer information to an AI service whose:

model infrastructure is overseas;

support personnel are overseas;

logging system is overseas;

subprocessors are overseas.

This can create questions about:

lawful transfer;

purpose limitation;

data minimisation;

confidentiality;

automated processing;

security;

intellectual property;

contractual liability.

The legal issue is therefore not simply:

"Where is the AI company incorporated?"

It may be:

Where is personal data processed, who controls the processing, what safeguards exist, and what laws govern each stage?

34. Jurisdictional Problems

A cross-border data claim may involve:

Claimant in UAE

Controller in UAE

Processor in France

Subprocessor in India

Cloud server in Singapore

Data subject in UAE

Hacker in an unknown country

Which court hears the case?

Potential jurisdictional connecting factors include:

defendant's domicile;

place of contractual performance;

place of damage;

agreed jurisdiction clause;

applicable statutory jurisdiction;

DIFC/ADGM connection;

arbitration agreement.

The Al Khorafi line of DIFC jurisdictional jurisprudence is useful in understanding the importance of identifying the legally relevant incident and its connection with the forum.

35. Choice of Forum and Choice of Law

Cross-border contracts should ideally separately address:

Governing law

UAE law.

Forum

UAE courts.

Arbitration

DIFC/DIAC/other agreed arbitration.

Data-protection compliance

Each party must comply with mandatory data-protection laws applicable to its processing activities.

These clauses perform different functions.

A governing-law clause does not automatically establish jurisdiction.

A jurisdiction clause does not necessarily eliminate mandatory foreign data-protection law.

36. Recognition and Enforcement

Suppose a UAE company obtains a judgment against a foreign processor.

The defendant has assets in:

France, Singapore and India.

The UAE judgment may need to be recognised and enforced in those jurisdictions.

Conversely, a foreign judgment against a UAE company may need recognition and enforcement in the UAE.

Therefore, cross-border data disputes can ultimately become:

private international law + enforcement law + data-protection law

problems.

37. Damages in Cross-Border Data Litigation

Potential losses may include:

forensic investigation;

notification expenses;

data restoration;

system replacement;

business interruption;

contractual penalties where legally recoverable;

regulatory response;

customer remediation;

professional fees where recoverable;

proven financial loss.

But recovery depends on the governing law.

Graciela is an instructive DIFC example because the court accepted documented restoration and investigation expenses and certain employee costs resulting from the cyber incident. (DIFC Courts)

38. Conflicting Foreign Disclosure Orders

Consider:

A UAE company receives a foreign court order demanding production of customer data.

At the same time:

UAE law restricts the transfer or disclosure.

The company should not simply ignore either legal obligation.

The issue may require:

review of the foreign order;

assessment of UAE law;

examination of confidentiality obligations;

consultation with relevant regulators;

possible protective order;

narrowing of disclosure;

anonymisation or redaction;

secure transfer where legally permitted.

This is an area where international judicial cooperation becomes particularly important.

39. Eight Case Laws — Quick Revision Table

CaseJurisdictionMain principle
DFSA v Commissioner of Data Protection & Waterhouse, CFI 051/2018 & 085/2018DIFCData rights balanced against regulatory functions and confidentiality
Graciela Ltd v Giacobbe [2014] DIFC CFI 027DIFCIT interference, forensic evidence, causation and damages
Aegis Resources DMCC v Union Bank of India, CFI 004/2020DIFCCyber fraud, security controls and allocation of loss
Gate MENA DMCC v Tabarak Investment Capital [2020] DIFC TCD 001DIFCDigital-asset negligence, duty, causation and loss
R.E. Lee International v Imran Khan, CFI 087/2022DIFCTechnology/data-breach litigation and procedural complexity
Al Khorafi v Bank Sarasin-Alpen [2011] DIFC CA 003DIFCTerritorial jurisdiction and legally relevant incident
Schrems II, Case C-311/18EUAdequacy, safeguards and third-country government access
Google Spain, Case C-131/12EUTerritorial scope and responsibility for cross-border online processing

The last two are comparative authorities, not binding UAE precedents. (EUR-Lex)

40. Comparative Significance of Schrems II for UAE Law

The comparison can be expressed as follows:

QuestionUAESchrems II approach
AdequacyRelevant under Article 22Central to third-country transfers
Contractual safeguardsRelevant under Article 23Standard contractual clauses recognised subject to safeguards
Destination-country lawRelevantDetailed examination required
Government accessRelevant to protection levelCentral issue
Controller responsibilityImportantController must assess safeguards
Cross-border riskRegulatedRegulated through transfer mechanisms

The comparison is useful but should not be treated as importing EU law into the UAE.

41. Conflict Matrix

A useful way to analyse a UAE cross-border data dispute is:

QuestionRelevant inquiry
Who?Controller, processor, subprocessor or third party?
What?Personal, financial, health, commercial or confidential data?
Where?UAE, DIFC, ADGM or foreign jurisdiction?
Why?Purpose of processing
How?Cloud, outsourcing, transfer, remote access
Which law?UAE, DIFC, ADGM or foreign law
Which court?Jurisdiction/forum
Which safeguards?Adequacy, contract, statutory exception or other mechanism
What damage?Financial, privacy, operational or reputational
Who pays?Controller, processor, insurer or another responsible party

42. Practical Example

Assume a UAE bank uses a foreign cloud provider.

Stage 1 — Transfer

Customer data moves from UAE to the foreign cloud environment.

Stage 2 — Processing

The foreign provider processes and stores the information.

Stage 3 — Subprocessing

A foreign cybersecurity company obtains access.

Stage 4 — Incident

An employee of the subprocessor improperly downloads customer information.

Stage 5 — Regulatory issue

The UAE bank must determine whether the transfer and processing complied with applicable UAE requirements.

Stage 6 — Civil issue

Customers may assert legally available claims if the necessary elements of liability and damage are established.

Stage 7 — Contractual issue

The bank may seek recovery from the cloud provider or subprocessor under the contractual allocation of responsibility.

Stage 8 — Foreign issue

The subprocessor may be subject to the law of its own jurisdiction.

The dispute therefore becomes a multi-layered conflict-of-laws problem.

43. Defences Available to a Data Processor

Depending on the governing law and contract, a processor may argue:

no breach occurred;

transfer was lawful;

appropriate safeguards existed;

another party controlled the relevant processing;

the incident was caused by an independent attacker;

no legally compensable damage was established;

claimant contributed to the loss;

contractual limitation applies;

force majeure applies;

the claim is time-barred;

wrong forum;

wrong defendant.

The controller may similarly argue that:

the processor contractually assumed responsibility for security and compliance.

44. Civil Liability of the UAE Controller

A UAE controller should not assume that outsourcing eliminates its responsibility.

The controller should conduct due diligence regarding:

foreign processor;

security;

destination country;

subprocessors;

transfer mechanism;

contractual protections;

regulatory restrictions.

The underlying principle is:

Outsourcing processing does not necessarily mean outsourcing legal responsibility.

The precise allocation depends on the applicable statute and contractual relationship.

45. Civil Liability of the Foreign Processor

A foreign processor may face UAE-related claims where:

the contract permits UAE litigation;

UAE law governs;

jurisdiction exists;

the processor has sufficient connection with the UAE forum;

the processing relationship creates a relevant cause of action.

The foreign processor may nevertheless invoke:

jurisdiction;

arbitration;

governing-law clause;

limitation of liability;

foreign mandatory law.

46. Importance of Evidence

Cross-border data disputes require detailed technical evidence.

Useful evidence includes:

data-flow maps;

transfer logs;

processing records;

data-processing agreements;

subprocessor agreements;

access logs;

encryption records;

security assessments;

incident reports;

data-protection impact assessments;

regulatory correspondence;

cloud architecture;

contractual schedules;

audit reports.

Graciela illustrates the importance of technical evidence in proving responsibility and quantifying loss in a technology dispute. (DIFC Courts)

47. Compliance Model for UAE Businesses

A UAE business transferring personal data internationally should ideally establish:

Before transfer

identify the data;

identify destination;

identify recipient;

determine applicable law;

assess adequacy;

select lawful safeguard;

document the transfer.

During processing

monitor security;

control access;

monitor subprocessors;

maintain records;

respond to incidents.

After an incident

preserve evidence;

investigate;

notify relevant parties/regulators where legally required;

assess affected individuals;

determine contractual liability;

calculate loss;

consider litigation and insurance.

48. Current UAE Legal Position

The key federal provision is the Personal Data Protection Law, Federal Decree-Law No. 45 of 2021.

Articles 22–23 create a structured framework for transfers outside the UAE, distinguishing transfers to jurisdictions with an appropriate protection level from transfers where such protection is unavailable. (UAE Legislation)

For DIFC, the separate DIFC data-protection framework must be considered.

For ADGM, its Data Protection Regulations 2021 and Office of Data Protection guidance govern the relevant ADGM transfer. ADGM expressly provides for adequacy decisions and alternative safeguards such as standard contractual clauses. (ADGM)

49. Important Distinction Between Onshore UAE, DIFC and ADGM

SystemData-transfer framework
Onshore UAEFederal PDPL, Federal Decree-Law No. 45 of 2021
DIFCDIFC-specific data-protection legislation
ADGMADGM Data Protection Regulations 2021
Foreign jurisdictionRelevant foreign privacy/data laws

Therefore, the phrase "UAE data law" is not always sufficient for legal analysis.

The first question should be:

Where is the relevant entity/data-processing activity legally situated?

50. Conclusion

Cross-border data flows create a particularly complex form of UAE civil liability because data is geographically mobile while legal responsibility remains territorially structured.

The central analytical chain is:

Data → Controller → Transfer → Destination → Safeguard → Processing → Incident → Damage → Applicable law → Jurisdiction → Remedy

The UAE's Federal Personal Data Protection Law regulates international transfers through adequacy and alternative safeguards. (UAE Legislation) DIFC and ADGM have separate regimes that must be considered where their territorial frameworks apply. (DIFC Courts)

The UAE/DIFC authorities such as DFSA v Commissioner of Data Protection, Graciela v Giacobbe, Aegis Resources v Union Bank of India, Gate MENA v Tabarak, R.E. Lee International v Imran Khan, and Al Khorafi v Bank Sarasin-Alpen demonstrate different aspects of data rights, technology liability, cyber loss, jurisdiction and evidence. The comparative Schrems II and Google Spain decisions provide useful international guidance on adequacy, third-country transfers and territorial responsibility, but they are not binding UAE precedents. (EUR-Lex)

Important current-law qualification: UAE civil-liability analysis should also take account of the 2025 Civil Transactions Law, effective from 1 June 2026, where a claim is based on general civil responsibility. Older UAE/DIFC cases interpreting earlier legislation should be treated according to their jurisdiction, date and statutory context rather than automatically assumed to state the current onshore UAE law.

LEAVE A COMMENT