Civil Law And Uae Cyber Evidence Authenticity Verification Systems .
Civil Law and UAE Cyber Evidence Authenticity Verification Systems
1. Introduction
Cyber evidence authenticity verification means the legal and technical process used to determine whether digital evidence presented in a civil case is:
- genuine;
- complete;
- unaltered;
- attributable to the alleged sender or creator;
- generated or stored by the claimed system;
- reliable;
- properly preserved; and
- sufficiently connected with the disputed transaction or event.
In UAE civil litigation, this issue is increasingly important because disputes may depend on:
- emails;
- WhatsApp messages;
- SMS;
- electronic contracts;
- electronic signatures;
- digital invoices;
- cloud records;
- CCTV/video;
- server logs;
- GPS/location records;
- blockchain transactions;
- cryptocurrency-wallet records;
- metadata;
- access logs;
- electronic bank instructions;
- digitally signed documents; and
- AI-generated or electronically modified material.
The UAE's Federal Evidence Law expressly recognises electronic evidence. Article 53 defines it broadly as evidence derived from data or information generated, stored, extracted, copied, transmitted, reported or received through information technology and capable of being retrieved understandably.
A key principle is:
Digital evidence is not authenticated merely because it exists electronically. The court must be satisfied about its authenticity, integrity, attribution and reliability.
2. Current UAE Legal Framework
The principal federal statute is Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions.
Part Four specifically addresses electronic evidence.
Article 53 — Electronic evidence
Electronic evidence includes information derived from:
- electronic systems;
- computers;
- communication systems;
- digital storage;
- transmitted data; and
- other information-technology environments.
The definition is technologically neutral.
Article 54 — Types of electronic evidence
Electronic evidence includes, among other things:
- electronic records;
- electronic documents;
- electronic signatures;
- electronic communications;
- electronic messages; and
- other electronic evidence.
Articles 55–60
These provisions deal with:
- evidentiary treatment of electronic evidence;
- formal electronic evidence;
- informal electronic evidence;
- challenges to validity;
- evidentiary weight; and
- production of electronic evidence in original or other acceptable electronic form.
Therefore, the UAE system does not treat electronic evidence as inherently inferior to paper evidence.
3. What Is an Authenticity Verification System?
A cyber-evidence authenticity system can be understood as a chain:
Creation → Collection → Preservation → Identification → Integrity Verification → Attribution → Corroboration → Expert Examination → Judicial Assessment
For example, suppose a company claims:
“The defendant sent this WhatsApp message approving the AED 2 million transaction.”
The court may need to examine:
- Who controlled the phone/account?
- Was the number associated with the defendant?
- Is the conversation complete?
- Are messages missing?
- Was the screenshot altered?
- Is the original device available?
- Is the message present in the native application?
- Are there metadata or backup records?
- Do bank records corroborate the conversation?
- Does the defendant admit or deny authorship?
- Is an expert examination necessary?
- Is there evidence explaining how the message was generated?
This demonstrates that authentication is a process rather than a single technological test.
4. Five Core Authentication Questions
A UAE civil court can conceptually approach cyber evidence through five questions.
1. Existence
Did the electronic record actually exist?
2. Integrity
Has the record remained substantially unchanged?
3. Attribution
Who created, sent, signed or controlled it?
4. Reliability
Was the system through which it was generated reasonably reliable?
5. Relevance
Does it actually prove a fact material to the dispute?
Thus:
Authenticity ≠ merely showing a screenshot.
5. Electronic Signature Authentication
Electronic signatures are particularly important.
An electronic signature may authenticate:
- identity;
- intention;
- approval;
- acceptance;
- execution;
- attribution.
But the existence of a signature image alone does not necessarily establish that the person authorised its use.
This distinction was examined carefully in ICICI Bank Ltd v Bavaguthu Raghuram Shetty.
6. Case Law
Case 1 — ICICI Bank Limited v Bavaguthu Raghuram Shetty
[2022] DIFC CFI 034
This is one of the most important UAE authorities on electronic-signature authenticity.
The dispute concerned guarantees bearing signatures that were, in some instances, electronically reproduced.
The Court examined handwriting-expert evidence and distinguished between:
- whether the underlying signature was genuinely the person's signature; and
- whether the person authorised that signature to be electronically applied to the particular document.
The Court explained that an electronic or copied signature is not automatically evidence of fraud or forgery. A genuine signature may legitimately be reproduced electronically.
However, expert evidence concerning handwriting could not by itself establish whether the person authorised the electronic application.
Principle
Authenticity of the signature and authorisation of its electronic application are separate questions.
This is extremely important for digital evidence verification.
7. Case 2 — Barclays Bank PLC v Bavaguthu Raghuram Shetty
[2020] DIFC CFI 061
The case involved different electronic versions of an agreement and allegations concerning the integrity of electronic execution.
The Court examined whether different electronic copies indicated alteration or falsification.
It found that the existence of multiple electronic versions did not automatically demonstrate manipulation. The availability of an unchallenged complete executed version provided important corroboration.
The Court placed emphasis on the evidentiary context rather than treating differences between electronic copies as conclusive evidence of fraud.
Principle
Different electronic versions do not automatically establish alteration. Their provenance, completeness and surrounding evidence must be examined.
8. Case 3 — Ondina v Olin
[2025] DIFC CFI 046
This case demonstrates that an email can function as an electronic signature.
The Court considered emails exchanged concerning a change to an employment contract.
The relevant DIFC Electronic Transactions Law treated an electronic signature as an electronic sound, symbol or process attached to or logically associated with a record and adopted with an intention to sign.
The Court concluded that the employee's email, which included her name and communicated her acceptance, satisfied the statutory concept of an electronic signature.
Principle
Authentication does not necessarily require:
- handwritten signatures;
- scanned signature pages; or
- specialised signature software.
An electronic communication can constitute a legally effective signature where statutory requirements are satisfied.
9. Case 4 — Nashtar v Nasiruddin
[2024] DIFC SCT 351
The dispute involved WhatsApp communications and an allegedly forged contract.
The claimant produced WhatsApp conversations showing the document being:
- sent;
- reviewed;
- corrected;
- returned; and
- signed.
The defendant argued that the contract was forged.
The Court found that the defendant had not provided sufficient evidence supporting the forgery allegation. The repeated exchange and review of the document through WhatsApp supported the authenticity of the contractual record.
Principle
Digital communications can corroborate authenticity where the surrounding communication history supports the document's provenance.
This is particularly important because courts frequently receive isolated screenshots when the actual evidentiary value may lie in the entire conversation.
10. Case 5 — Stephan Karl Morgenstern v Saif Sultan Al Mehrzi Lawyer & Legal Consultants
[2025] DIFC CFI 036
This case provides an important lesson concerning completeness and preservation.
The Court examined WhatsApp messages relied upon by the parties. The messages were not complete because some had apparently been deleted.
The Court considered the available messages together with other evidence and the absence of expected documentary material.
Principle
A screenshot or extracted conversation should not automatically be treated as the complete digital record.
Authenticity verification may therefore require examination of:
- complete chat history;
- deleted messages;
- backups;
- device records;
- account records;
- metadata;
- surrounding communications.
11. Case 6 — Karthi Keyan Venkataramana v Ahmed Mohammad Abdul Rahman Ali
[2025] DIFC CFI 110
The Court considered expert evidence concerning disputed signatures and documentary authenticity.
The case demonstrates the importance of the technical foundation of expert conclusions.
One expert's theory concerning how a document may have been created was not supported by sufficient technical analysis. The Court examined whether the proposed mechanism would actually leave detectable forensic characteristics.
The Court also considered WhatsApp exchanges and the reliability of witness evidence.
Principle
Expert evidence must have a technically supportable foundation. A court does not have to accept an authenticity theory merely because an expert proposes it.
12. Case 7 — Saif Saeed Sulaiman Mohammad Al Mazrouei v Bankmed
[2019] DIFC CA 011
The Court of Appeal considered a challenge involving alleged forgery and authentication of a signature.
The Court emphasized that a party alleging forgery must produce evidence supporting that important allegation. It rejected the notion that the court should simply send the signature for expert verification without an evidential basis being properly developed by the party relying on forgery.
Principle
A bare allegation that digital or documentary evidence is forged is not itself proof of forgery.
13. Case 8 — Linux v Lizeth
[2022] DIFC SCT 237
The case involved WhatsApp evidence concerning an alleged breach of confidentiality.
The claimant relied upon WhatsApp communications and other digital material to establish the alleged breach.
The Court concluded that the evidence was insufficient to establish the alleged violation and dismissed the claim.
Principle
Digital evidence must establish the substantive fact in dispute, not merely demonstrate that electronic communication occurred.
Thus:
Authentic evidence ≠ automatically sufficient evidence.
A genuine WhatsApp message can still fail to prove the legal claim being advanced.
14. Cyber Evidence Authentication: Technical Components
A. Hash Values
A cryptographic hash creates a digital fingerprint of a file.
For example:
Document → SHA-256 → Hash value
If the document changes, its hash will ordinarily change.
A hash can therefore help demonstrate:
- integrity;
- consistency;
- whether a forensic copy changed.
But a hash does not automatically prove:
- who created the document;
- who sent it;
- whether the underlying statement is true;
- who owns the account.
Therefore:
Hash = integrity tool, not complete attribution proof.
15. Metadata Verification
Metadata can include:
- creation date;
- modification date;
- author;
- device;
- software;
- file path;
- GPS information;
- timestamps;
- system information.
Metadata can help establish provenance.
However, metadata itself can potentially be altered or lost.
Therefore, courts may consider:
Metadata + original file + system records + witness evidence + expert evidence
rather than metadata alone.
16. Email Authenticity
Email authentication may involve:
Header examination
Including:
- sender;
- recipient;
- routing information;
- timestamps;
- message identifiers.
Server evidence
For example:
- mail-server logs;
- Microsoft 365 records;
- Google Workspace records;
- corporate email archives.
Account ownership
Evidence may establish:
- who controlled the account;
- whether the account belonged to the alleged sender;
- whether credentials were compromised.
Context
Earlier and later communications may corroborate the disputed email.
This is why producing only a screenshot of an email can be weaker than producing the native email together with its technical information.
17. WhatsApp Authentication
WhatsApp evidence may include:
- phone number;
- account ownership;
- complete conversation;
- timestamps;
- attachments;
- voice notes;
- device information;
- backup records;
- surrounding messages.
The court should distinguish:
“This screenshot exists”
from:
“This message was actually sent by the defendant and accurately represents the complete conversation.”
Nashtar v Nasiruddin demonstrates the importance of the surrounding WhatsApp history in evaluating authenticity.
18. Blockchain Authentication
Blockchain evidence has a different authentication structure.
A blockchain transaction may contain:
- transaction hash;
- wallet address;
- block number;
- timestamp;
- public-key information;
- transaction amount;
- destination address.
Blockchain technology can provide strong evidence of transaction history.
But an important legal distinction remains:
A blockchain wallet address is not necessarily identical to the legal identity of the person controlling it.
Therefore, a claimant may need additional evidence connecting:
Wallet → Exchange Account → KYC Information → Person/Company
This is especially important in cryptocurrency fraud litigation.
19. Digital Signatures and Cryptographic Signatures
These should not be confused.
Electronic signature
A legal concept concerning an electronic means used to sign a record.
Digital/cryptographic signature
A technical mechanism using cryptographic keys to establish integrity and authentication.
A cryptographic signature can help prove that:
- a private key corresponding to a public key was used;
- the signed data has not been altered after signing.
But it does not necessarily prove:
- who legally controls the private key;
- whether the person was authorised;
- whether the underlying transaction was lawful.
Therefore:
Cryptographic authentication ≠ complete legal attribution.
20. Digital Evidence and Chain of Custody
For important cyber evidence, the party should maintain a clear chain of custody.
A simplified chain is:
Original Device → Forensic Acquisition → Hash → Secure Storage → Expert Examination → Court Production
The record should identify:
- who collected the evidence;
- when it was collected;
- how it was collected;
- what tool was used;
- whether the original was preserved;
- where the forensic copy was stored;
- whether anyone modified the evidence.
A break in the chain does not necessarily make evidence automatically inadmissible, but it can affect its weight and reliability.
21. Screenshots vs Native Evidence
Screenshot
Advantages:
- easy to produce;
- visually understandable;
- useful for illustrating communications.
Weaknesses:
- can be cropped;
- can be edited;
- may omit context;
- usually lacks complete metadata;
- may not establish account ownership.
Native electronic record
Advantages:
- more information;
- metadata;
- system context;
- easier technical verification.
Therefore, where authenticity is seriously disputed:
Native records should generally be preferred over isolated screenshots where reasonably available.
The reasoning in Morgenstern v Al Mehrzi illustrates why completeness of electronic communications can become important.
22. Expert Evidence
Cyber evidence may require experts where the dispute involves:
- metadata;
- cryptography;
- blockchain;
- malware;
- email headers;
- server logs;
- forensic imaging;
- digital signatures;
- altered files;
- deleted messages.
But an expert should distinguish:
Technical question
Was this file modified?
from:
Legal question
Did the defendant authorise the modification?
ICICI Bank v Shetty is particularly important because the Court distinguished technical signature comparison from the legal question of authorisation.
23. Authentication of AI-Generated Evidence
Modern civil disputes may involve:
- AI-generated documents;
- AI-edited images;
- deepfakes;
- synthetic audio;
- AI-generated emails;
- manipulated videos.
The verification process should ask:
- What was the original source?
- Is the original file available?
- What software created it?
- Was AI used?
- Was the file edited?
- What metadata survives?
- Can the alleged author confirm it?
- Are there independent records?
- Does server evidence corroborate it?
- Can a forensic expert identify manipulation?
The fact that a document looks authentic on screen should not be treated as conclusive.
24. Authentication and Burden of Proof
Under the UAE Evidence Law, electronic evidence has statutory evidentiary treatment, including provisions concerning challenges to validity.
The party challenging certain forms of electronic evidence bears the burden prescribed by the Evidence Law, while the court ultimately evaluates the evidence according to the applicable statutory framework and the circumstances of the dispute.
This means that litigation strategy should not simply be:
“I deny this WhatsApp message.”
A serious authenticity challenge should identify why it is unreliable.
For example:
- wrong account;
- hacked account;
- altered screenshot;
- incomplete conversation;
- manipulated metadata;
- unauthorised electronic signature;
- missing original;
- inconsistent timestamps.
25. Corroboration
Courts can consider digital evidence alongside other evidence.
For example:
WhatsApp message
Bank transfer
Invoice
Contract
Witness testimony
may collectively establish a transaction more convincingly than any individual item.
The Nashtar decision illustrates how surrounding WhatsApp communications can reinforce the authenticity and history of a document.
26. Cyber Evidence Verification Model
A useful UAE civil-litigation model is:
Stage 1 — Identify
What exactly is the digital evidence?
Stage 2 — Preserve
Protect the original and prevent alteration.
Stage 3 — Acquire
Obtain the native/original electronic record where possible.
Stage 4 — Hash
Create an integrity fingerprint for forensic copies.
Stage 5 — Authenticate
Establish source and provenance.
Stage 6 — Attribute
Connect the record to the alleged person or system.
Stage 7 — Corroborate
Compare with independent records.
Stage 8 — Expert Review
Use forensic expertise where technically necessary.
Stage 9 — Challenge
Permit the opposing party to challenge authenticity.
Stage 10 — Judicial Assessment
The court determines admissibility and evidentiary weight.
27. Practical Authentication Matrix
| Evidence | Main Authentication Question |
|---|---|
| Was it actually sent from the alleged account? | |
| Who controlled the account and is the conversation complete? | |
| Who created/signed it and has it been altered? | |
| Electronic signature | Who applied it and was its use authorised? |
| Digital signature | Does the cryptographic signature correspond to the relevant key? |
| Blockchain transaction | Does the transaction exist and who controlled the wallet? |
| CCTV | Is the recording original and continuous? |
| Audio | Is the recording genuine and accurately attributed? |
| Video | Is it original or manipulated? |
| Metadata | Is the metadata reliable and preserved? |
| Server logs | Are the logs generated by a reliable system? |
| Cloud record | Can the provider authenticate the record? |
| Screenshot | Is there an underlying native record? |
28. Important Distinction: Authenticity vs Admissibility vs Weight
These three concepts should not be confused.
Authenticity
Is the evidence what the party says it is?
Admissibility
Can the court legally receive and consider it?
Weight
How persuasive is it after being admitted?
For example:
A genuine WhatsApp screenshot may be authentic, but if it is incomplete, its weight may be limited.
Similarly, an authentic email may establish that an email was sent but not necessarily establish that every factual statement in the email is true.
29. Mainland UAE and DIFC Difference
This is particularly important in UAE cyber-evidence litigation.
Mainland UAE
The principal framework is the Federal Evidence Law 2022, including Articles 53–60 on electronic evidence.
The court operates within a statutory civil-law evidence framework.
DIFC
DIFC has a common-law-oriented procedural and evidentiary system, supplemented by:
- DIFC Electronic Transactions Law;
- DIFC Court Rules;
- specialist digital-evidence procedures.
The DIFC authorities therefore provide valuable persuasive and, within the DIFC system, directly relevant precedent on:
- electronic signatures;
- WhatsApp;
- electronic records;
- expert evidence;
- digital authenticity.
They should not automatically be described as binding on mainland UAE courts.
30. DIFC Digital Authentication Infrastructure
The DIFC Courts have also developed technological mechanisms for authenticating court documents.
The Courts adopted the Ethaq electronic seal, integrating it with UAE PASS and digitally verifiable identity mechanisms. The system was designed to strengthen document authenticity and integrity in the paperless court environment.
This illustrates the broader transition from:
Paper Authentication → Electronic Authentication → Cryptographic/Digital Authentication
31. Common Problems in Cyber Evidence
Problem 1 — Screenshot only
The screenshot may not establish complete provenance.
Problem 2 — Deleted messages
Deletion can make reconstruction and completeness difficult.
Problem 3 — Shared accounts
An account may be controlled by several employees.
Problem 4 — Compromised credentials
A message from an account does not necessarily prove who physically sent it.
Problem 5 — Electronic signature copying
A copied signature may be genuine but used without authorisation.
This distinction is central to ICICI Bank v Shetty.
Problem 6 — Metadata manipulation
Metadata should be examined with other evidence.
Problem 7 — Blockchain identity
Wallet control does not automatically prove legal ownership.
Problem 8 — AI manipulation
Deepfake or synthetic material requires additional forensic verification.
32. Best Evidence Strategy
For a party relying on cyber evidence, the strongest evidentiary package is generally:
Original electronic record
↓
Forensic preservation
↓
Hash/integrity record
↓
Metadata
↓
Account/device identification
↓
Server/provider records
↓
Independent corroboration
↓
Expert report where necessary
↓
Witness evidence
↓
Court assessment
This is considerably stronger than merely filing a screenshot.
33. Case Law Summary
| Case | Key Principle |
|---|---|
| ICICI Bank Ltd v Bavaguthu Raghuram Shetty [2022] DIFC CFI 034 | Electronic/copy signature is not automatically fraudulent; authenticity and authorisation are separate |
| Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061 | Different electronic versions do not automatically prove alteration |
| Ondina v Olin [2025] DIFC CFI 046 | Email containing an intended electronic signature can satisfy statutory signature requirements |
| Nashtar v Nasiruddin [2024] DIFC SCT 351 | WhatsApp history can corroborate authenticity of a disputed contract |
| Stephan Karl Morgenstern v Saif Sultan Al Mehrzi [2025] DIFC CFI 036 | Completeness and preservation of WhatsApp evidence matter |
| Karthi Keyan Venkataramana v Ahmed Mohammad Abdul Rahman Ali [2025] DIFC CFI 110 | Expert authenticity opinions require a sound technical foundation |
| Al Mazrouei v Bankmed [2019] DIFC CA 011 | Allegations of forgery require an evidential foundation |
| Linux v Lizeth [2022] DIFC SCT 237 | Digital communications must actually establish the alleged substantive breach |
34. Examination/Legal Research Formula
For an UAE civil case involving cyber evidence, use:
Identify → Preserve → Acquire → Hash → Authenticate → Attribute → Corroborate → Expert Verify → Challenge → Judicially Assess
Or more simply:
Existence + Integrity + Attribution + Reliability + Relevance = Strong Cyber Evidence
35. Conclusion
UAE civil law increasingly treats electronic evidence as a normal and legally recognised category of evidence. The Federal Evidence Law expressly recognises electronic evidence and provides specific rules governing its evidentiary treatment.
The most important lesson from UAE/DIFC case law is that authenticity is multidimensional.
A court may need to determine:
- whether the electronic record exists;
- whether it has been altered;
- who created or sent it;
- who controlled the relevant account or device;
- whether an electronic signature was authorised;
- whether the record is complete;
- whether metadata and technical evidence support it;
- whether an expert's methodology is reliable; and
- whether independent evidence corroborates it.
The leading ICICI Bank v Shetty decision particularly demonstrates that proving that an electronic signature corresponds to a person's genuine signature is not necessarily the same as proving that the person authorised its application.
Accordingly, in UAE civil litigation, the strongest cyber-evidence system is not simply a “digital signature verification system.” It is an integrated framework combining technical integrity, identity verification, attribution, chain of custody, expert analysis, corroboration and judicial evaluation.

comments