Civil Law And Uae Cyber Evidence Authenticity Verification Systems .

Civil Law and UAE Cyber Evidence Authenticity Verification Systems

1. Introduction

Cyber evidence authenticity verification means the legal and technical process used to determine whether digital evidence presented in a civil case is:

  • genuine;
  • complete;
  • unaltered;
  • attributable to the alleged sender or creator;
  • generated or stored by the claimed system;
  • reliable;
  • properly preserved; and
  • sufficiently connected with the disputed transaction or event.

In UAE civil litigation, this issue is increasingly important because disputes may depend on:

  • emails;
  • WhatsApp messages;
  • SMS;
  • electronic contracts;
  • electronic signatures;
  • digital invoices;
  • cloud records;
  • CCTV/video;
  • server logs;
  • GPS/location records;
  • blockchain transactions;
  • cryptocurrency-wallet records;
  • metadata;
  • access logs;
  • electronic bank instructions;
  • digitally signed documents; and
  • AI-generated or electronically modified material.

The UAE's Federal Evidence Law expressly recognises electronic evidence. Article 53 defines it broadly as evidence derived from data or information generated, stored, extracted, copied, transmitted, reported or received through information technology and capable of being retrieved understandably.

A key principle is:

Digital evidence is not authenticated merely because it exists electronically. The court must be satisfied about its authenticity, integrity, attribution and reliability.

2. Current UAE Legal Framework

The principal federal statute is Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions.

Part Four specifically addresses electronic evidence.

Article 53 — Electronic evidence

Electronic evidence includes information derived from:

  • electronic systems;
  • computers;
  • communication systems;
  • digital storage;
  • transmitted data; and
  • other information-technology environments.

The definition is technologically neutral.

Article 54 — Types of electronic evidence

Electronic evidence includes, among other things:

  • electronic records;
  • electronic documents;
  • electronic signatures;
  • electronic communications;
  • electronic messages; and
  • other electronic evidence.

Articles 55–60

These provisions deal with:

  • evidentiary treatment of electronic evidence;
  • formal electronic evidence;
  • informal electronic evidence;
  • challenges to validity;
  • evidentiary weight; and
  • production of electronic evidence in original or other acceptable electronic form. 

Therefore, the UAE system does not treat electronic evidence as inherently inferior to paper evidence.

3. What Is an Authenticity Verification System?

A cyber-evidence authenticity system can be understood as a chain:

Creation → Collection → Preservation → Identification → Integrity Verification → Attribution → Corroboration → Expert Examination → Judicial Assessment

For example, suppose a company claims:

“The defendant sent this WhatsApp message approving the AED 2 million transaction.”

The court may need to examine:

  1. Who controlled the phone/account?
  2. Was the number associated with the defendant?
  3. Is the conversation complete?
  4. Are messages missing?
  5. Was the screenshot altered?
  6. Is the original device available?
  7. Is the message present in the native application?
  8. Are there metadata or backup records?
  9. Do bank records corroborate the conversation?
  10. Does the defendant admit or deny authorship?
  11. Is an expert examination necessary?
  12. Is there evidence explaining how the message was generated?

This demonstrates that authentication is a process rather than a single technological test.

4. Five Core Authentication Questions

A UAE civil court can conceptually approach cyber evidence through five questions.

1. Existence

Did the electronic record actually exist?

2. Integrity

Has the record remained substantially unchanged?

3. Attribution

Who created, sent, signed or controlled it?

4. Reliability

Was the system through which it was generated reasonably reliable?

5. Relevance

Does it actually prove a fact material to the dispute?

Thus:

Authenticity ≠ merely showing a screenshot.

5. Electronic Signature Authentication

Electronic signatures are particularly important.

An electronic signature may authenticate:

  • identity;
  • intention;
  • approval;
  • acceptance;
  • execution;
  • attribution.

But the existence of a signature image alone does not necessarily establish that the person authorised its use.

This distinction was examined carefully in ICICI Bank Ltd v Bavaguthu Raghuram Shetty.

6. Case Law

Case 1 — ICICI Bank Limited v Bavaguthu Raghuram Shetty

[2022] DIFC CFI 034

This is one of the most important UAE authorities on electronic-signature authenticity.

The dispute concerned guarantees bearing signatures that were, in some instances, electronically reproduced.

The Court examined handwriting-expert evidence and distinguished between:

  1. whether the underlying signature was genuinely the person's signature; and
  2. whether the person authorised that signature to be electronically applied to the particular document.

The Court explained that an electronic or copied signature is not automatically evidence of fraud or forgery. A genuine signature may legitimately be reproduced electronically.

However, expert evidence concerning handwriting could not by itself establish whether the person authorised the electronic application.

Principle

Authenticity of the signature and authorisation of its electronic application are separate questions.

This is extremely important for digital evidence verification.

7. Case 2 — Barclays Bank PLC v Bavaguthu Raghuram Shetty

[2020] DIFC CFI 061

The case involved different electronic versions of an agreement and allegations concerning the integrity of electronic execution.

The Court examined whether different electronic copies indicated alteration or falsification.

It found that the existence of multiple electronic versions did not automatically demonstrate manipulation. The availability of an unchallenged complete executed version provided important corroboration.

The Court placed emphasis on the evidentiary context rather than treating differences between electronic copies as conclusive evidence of fraud.

Principle

Different electronic versions do not automatically establish alteration. Their provenance, completeness and surrounding evidence must be examined.

8. Case 3 — Ondina v Olin

[2025] DIFC CFI 046

This case demonstrates that an email can function as an electronic signature.

The Court considered emails exchanged concerning a change to an employment contract.

The relevant DIFC Electronic Transactions Law treated an electronic signature as an electronic sound, symbol or process attached to or logically associated with a record and adopted with an intention to sign.

The Court concluded that the employee's email, which included her name and communicated her acceptance, satisfied the statutory concept of an electronic signature.

Principle

Authentication does not necessarily require:

  • handwritten signatures;
  • scanned signature pages; or
  • specialised signature software.

An electronic communication can constitute a legally effective signature where statutory requirements are satisfied.

9. Case 4 — Nashtar v Nasiruddin

[2024] DIFC SCT 351

The dispute involved WhatsApp communications and an allegedly forged contract.

The claimant produced WhatsApp conversations showing the document being:

  • sent;
  • reviewed;
  • corrected;
  • returned; and
  • signed.

The defendant argued that the contract was forged.

The Court found that the defendant had not provided sufficient evidence supporting the forgery allegation. The repeated exchange and review of the document through WhatsApp supported the authenticity of the contractual record.

Principle

Digital communications can corroborate authenticity where the surrounding communication history supports the document's provenance.

This is particularly important because courts frequently receive isolated screenshots when the actual evidentiary value may lie in the entire conversation.

10. Case 5 — Stephan Karl Morgenstern v Saif Sultan Al Mehrzi Lawyer & Legal Consultants

[2025] DIFC CFI 036

This case provides an important lesson concerning completeness and preservation.

The Court examined WhatsApp messages relied upon by the parties. The messages were not complete because some had apparently been deleted.

The Court considered the available messages together with other evidence and the absence of expected documentary material.

Principle

A screenshot or extracted conversation should not automatically be treated as the complete digital record.

Authenticity verification may therefore require examination of:

  • complete chat history;
  • deleted messages;
  • backups;
  • device records;
  • account records;
  • metadata;
  • surrounding communications.

11. Case 6 — Karthi Keyan Venkataramana v Ahmed Mohammad Abdul Rahman Ali

[2025] DIFC CFI 110

The Court considered expert evidence concerning disputed signatures and documentary authenticity.

The case demonstrates the importance of the technical foundation of expert conclusions.

One expert's theory concerning how a document may have been created was not supported by sufficient technical analysis. The Court examined whether the proposed mechanism would actually leave detectable forensic characteristics.

The Court also considered WhatsApp exchanges and the reliability of witness evidence.

Principle

Expert evidence must have a technically supportable foundation. A court does not have to accept an authenticity theory merely because an expert proposes it.

12. Case 7 — Saif Saeed Sulaiman Mohammad Al Mazrouei v Bankmed

[2019] DIFC CA 011

The Court of Appeal considered a challenge involving alleged forgery and authentication of a signature.

The Court emphasized that a party alleging forgery must produce evidence supporting that important allegation. It rejected the notion that the court should simply send the signature for expert verification without an evidential basis being properly developed by the party relying on forgery.

Principle

A bare allegation that digital or documentary evidence is forged is not itself proof of forgery.

13. Case 8 — Linux v Lizeth

[2022] DIFC SCT 237

The case involved WhatsApp evidence concerning an alleged breach of confidentiality.

The claimant relied upon WhatsApp communications and other digital material to establish the alleged breach.

The Court concluded that the evidence was insufficient to establish the alleged violation and dismissed the claim.

Principle

Digital evidence must establish the substantive fact in dispute, not merely demonstrate that electronic communication occurred.

Thus:

Authentic evidence ≠ automatically sufficient evidence.

A genuine WhatsApp message can still fail to prove the legal claim being advanced.

14. Cyber Evidence Authentication: Technical Components

A. Hash Values

A cryptographic hash creates a digital fingerprint of a file.

For example:

Document → SHA-256 → Hash value

If the document changes, its hash will ordinarily change.

A hash can therefore help demonstrate:

  • integrity;
  • consistency;
  • whether a forensic copy changed.

But a hash does not automatically prove:

  • who created the document;
  • who sent it;
  • whether the underlying statement is true;
  • who owns the account.

Therefore:

Hash = integrity tool, not complete attribution proof.

15. Metadata Verification

Metadata can include:

  • creation date;
  • modification date;
  • author;
  • device;
  • software;
  • file path;
  • GPS information;
  • timestamps;
  • system information.

Metadata can help establish provenance.

However, metadata itself can potentially be altered or lost.

Therefore, courts may consider:

Metadata + original file + system records + witness evidence + expert evidence

rather than metadata alone.

16. Email Authenticity

Email authentication may involve:

Header examination

Including:

  • sender;
  • recipient;
  • routing information;
  • timestamps;
  • message identifiers.

Server evidence

For example:

  • mail-server logs;
  • Microsoft 365 records;
  • Google Workspace records;
  • corporate email archives.

Account ownership

Evidence may establish:

  • who controlled the account;
  • whether the account belonged to the alleged sender;
  • whether credentials were compromised.

Context

Earlier and later communications may corroborate the disputed email.

This is why producing only a screenshot of an email can be weaker than producing the native email together with its technical information.

17. WhatsApp Authentication

WhatsApp evidence may include:

  • phone number;
  • account ownership;
  • complete conversation;
  • timestamps;
  • attachments;
  • voice notes;
  • device information;
  • backup records;
  • surrounding messages.

The court should distinguish:

“This screenshot exists”

from:

“This message was actually sent by the defendant and accurately represents the complete conversation.”

Nashtar v Nasiruddin demonstrates the importance of the surrounding WhatsApp history in evaluating authenticity.

18. Blockchain Authentication

Blockchain evidence has a different authentication structure.

A blockchain transaction may contain:

  • transaction hash;
  • wallet address;
  • block number;
  • timestamp;
  • public-key information;
  • transaction amount;
  • destination address.

Blockchain technology can provide strong evidence of transaction history.

But an important legal distinction remains:

A blockchain wallet address is not necessarily identical to the legal identity of the person controlling it.

Therefore, a claimant may need additional evidence connecting:

Wallet → Exchange Account → KYC Information → Person/Company

This is especially important in cryptocurrency fraud litigation.

19. Digital Signatures and Cryptographic Signatures

These should not be confused.

Electronic signature

A legal concept concerning an electronic means used to sign a record.

Digital/cryptographic signature

A technical mechanism using cryptographic keys to establish integrity and authentication.

A cryptographic signature can help prove that:

  • a private key corresponding to a public key was used;
  • the signed data has not been altered after signing.

But it does not necessarily prove:

  • who legally controls the private key;
  • whether the person was authorised;
  • whether the underlying transaction was lawful.

Therefore:

Cryptographic authentication ≠ complete legal attribution.

20. Digital Evidence and Chain of Custody

For important cyber evidence, the party should maintain a clear chain of custody.

A simplified chain is:

Original Device → Forensic Acquisition → Hash → Secure Storage → Expert Examination → Court Production

The record should identify:

  • who collected the evidence;
  • when it was collected;
  • how it was collected;
  • what tool was used;
  • whether the original was preserved;
  • where the forensic copy was stored;
  • whether anyone modified the evidence.

A break in the chain does not necessarily make evidence automatically inadmissible, but it can affect its weight and reliability.

21. Screenshots vs Native Evidence

Screenshot

Advantages:

  • easy to produce;
  • visually understandable;
  • useful for illustrating communications.

Weaknesses:

  • can be cropped;
  • can be edited;
  • may omit context;
  • usually lacks complete metadata;
  • may not establish account ownership.

Native electronic record

Advantages:

  • more information;
  • metadata;
  • system context;
  • easier technical verification.

Therefore, where authenticity is seriously disputed:

Native records should generally be preferred over isolated screenshots where reasonably available.

The reasoning in Morgenstern v Al Mehrzi illustrates why completeness of electronic communications can become important.

22. Expert Evidence

Cyber evidence may require experts where the dispute involves:

  • metadata;
  • cryptography;
  • blockchain;
  • malware;
  • email headers;
  • server logs;
  • forensic imaging;
  • digital signatures;
  • altered files;
  • deleted messages.

But an expert should distinguish:

Technical question

Was this file modified?

from:

Legal question

Did the defendant authorise the modification?

ICICI Bank v Shetty is particularly important because the Court distinguished technical signature comparison from the legal question of authorisation.

23. Authentication of AI-Generated Evidence

Modern civil disputes may involve:

  • AI-generated documents;
  • AI-edited images;
  • deepfakes;
  • synthetic audio;
  • AI-generated emails;
  • manipulated videos.

The verification process should ask:

  1. What was the original source?
  2. Is the original file available?
  3. What software created it?
  4. Was AI used?
  5. Was the file edited?
  6. What metadata survives?
  7. Can the alleged author confirm it?
  8. Are there independent records?
  9. Does server evidence corroborate it?
  10. Can a forensic expert identify manipulation?

The fact that a document looks authentic on screen should not be treated as conclusive.

24. Authentication and Burden of Proof

Under the UAE Evidence Law, electronic evidence has statutory evidentiary treatment, including provisions concerning challenges to validity.

The party challenging certain forms of electronic evidence bears the burden prescribed by the Evidence Law, while the court ultimately evaluates the evidence according to the applicable statutory framework and the circumstances of the dispute.

This means that litigation strategy should not simply be:

“I deny this WhatsApp message.”

A serious authenticity challenge should identify why it is unreliable.

For example:

  • wrong account;
  • hacked account;
  • altered screenshot;
  • incomplete conversation;
  • manipulated metadata;
  • unauthorised electronic signature;
  • missing original;
  • inconsistent timestamps.

25. Corroboration

Courts can consider digital evidence alongside other evidence.

For example:

WhatsApp message

  •  

Bank transfer

  •  

Invoice

  •  

Email

  •  

Contract

  •  

Witness testimony

may collectively establish a transaction more convincingly than any individual item.

The Nashtar decision illustrates how surrounding WhatsApp communications can reinforce the authenticity and history of a document.

26. Cyber Evidence Verification Model

A useful UAE civil-litigation model is:

Stage 1 — Identify

What exactly is the digital evidence?

Stage 2 — Preserve

Protect the original and prevent alteration.

Stage 3 — Acquire

Obtain the native/original electronic record where possible.

Stage 4 — Hash

Create an integrity fingerprint for forensic copies.

Stage 5 — Authenticate

Establish source and provenance.

Stage 6 — Attribute

Connect the record to the alleged person or system.

Stage 7 — Corroborate

Compare with independent records.

Stage 8 — Expert Review

Use forensic expertise where technically necessary.

Stage 9 — Challenge

Permit the opposing party to challenge authenticity.

Stage 10 — Judicial Assessment

The court determines admissibility and evidentiary weight.

27. Practical Authentication Matrix

EvidenceMain Authentication Question
EmailWas it actually sent from the alleged account?
WhatsAppWho controlled the account and is the conversation complete?
PDFWho created/signed it and has it been altered?
Electronic signatureWho applied it and was its use authorised?
Digital signatureDoes the cryptographic signature correspond to the relevant key?
Blockchain transactionDoes the transaction exist and who controlled the wallet?
CCTVIs the recording original and continuous?
AudioIs the recording genuine and accurately attributed?
VideoIs it original or manipulated?
MetadataIs the metadata reliable and preserved?
Server logsAre the logs generated by a reliable system?
Cloud recordCan the provider authenticate the record?
ScreenshotIs there an underlying native record?

28. Important Distinction: Authenticity vs Admissibility vs Weight

These three concepts should not be confused.

Authenticity

Is the evidence what the party says it is?

Admissibility

Can the court legally receive and consider it?

Weight

How persuasive is it after being admitted?

For example:

A genuine WhatsApp screenshot may be authentic, but if it is incomplete, its weight may be limited.

Similarly, an authentic email may establish that an email was sent but not necessarily establish that every factual statement in the email is true.

29. Mainland UAE and DIFC Difference

This is particularly important in UAE cyber-evidence litigation.

Mainland UAE

The principal framework is the Federal Evidence Law 2022, including Articles 53–60 on electronic evidence.

The court operates within a statutory civil-law evidence framework.

DIFC

DIFC has a common-law-oriented procedural and evidentiary system, supplemented by:

  • DIFC Electronic Transactions Law;
  • DIFC Court Rules;
  • specialist digital-evidence procedures.

The DIFC authorities therefore provide valuable persuasive and, within the DIFC system, directly relevant precedent on:

  • electronic signatures;
  • WhatsApp;
  • electronic records;
  • expert evidence;
  • digital authenticity.

They should not automatically be described as binding on mainland UAE courts.

30. DIFC Digital Authentication Infrastructure

The DIFC Courts have also developed technological mechanisms for authenticating court documents.

The Courts adopted the Ethaq electronic seal, integrating it with UAE PASS and digitally verifiable identity mechanisms. The system was designed to strengthen document authenticity and integrity in the paperless court environment.

This illustrates the broader transition from:

Paper Authentication → Electronic Authentication → Cryptographic/Digital Authentication

31. Common Problems in Cyber Evidence

Problem 1 — Screenshot only

The screenshot may not establish complete provenance.

Problem 2 — Deleted messages

Deletion can make reconstruction and completeness difficult.

Problem 3 — Shared accounts

An account may be controlled by several employees.

Problem 4 — Compromised credentials

A message from an account does not necessarily prove who physically sent it.

Problem 5 — Electronic signature copying

A copied signature may be genuine but used without authorisation.

This distinction is central to ICICI Bank v Shetty.

Problem 6 — Metadata manipulation

Metadata should be examined with other evidence.

Problem 7 — Blockchain identity

Wallet control does not automatically prove legal ownership.

Problem 8 — AI manipulation

Deepfake or synthetic material requires additional forensic verification.

32. Best Evidence Strategy

For a party relying on cyber evidence, the strongest evidentiary package is generally:

Original electronic record

Forensic preservation

Hash/integrity record

Metadata

Account/device identification

Server/provider records

Independent corroboration

Expert report where necessary

Witness evidence

Court assessment

This is considerably stronger than merely filing a screenshot.

33. Case Law Summary

CaseKey Principle
ICICI Bank Ltd v Bavaguthu Raghuram Shetty [2022] DIFC CFI 034Electronic/copy signature is not automatically fraudulent; authenticity and authorisation are separate
Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061Different electronic versions do not automatically prove alteration
Ondina v Olin [2025] DIFC CFI 046Email containing an intended electronic signature can satisfy statutory signature requirements
Nashtar v Nasiruddin [2024] DIFC SCT 351WhatsApp history can corroborate authenticity of a disputed contract
Stephan Karl Morgenstern v Saif Sultan Al Mehrzi [2025] DIFC CFI 036Completeness and preservation of WhatsApp evidence matter
Karthi Keyan Venkataramana v Ahmed Mohammad Abdul Rahman Ali [2025] DIFC CFI 110Expert authenticity opinions require a sound technical foundation
Al Mazrouei v Bankmed [2019] DIFC CA 011Allegations of forgery require an evidential foundation
Linux v Lizeth [2022] DIFC SCT 237Digital communications must actually establish the alleged substantive breach

34. Examination/Legal Research Formula

For an UAE civil case involving cyber evidence, use:

Identify → Preserve → Acquire → Hash → Authenticate → Attribute → Corroborate → Expert Verify → Challenge → Judicially Assess

Or more simply:

Existence + Integrity + Attribution + Reliability + Relevance = Strong Cyber Evidence

35. Conclusion

UAE civil law increasingly treats electronic evidence as a normal and legally recognised category of evidence. The Federal Evidence Law expressly recognises electronic evidence and provides specific rules governing its evidentiary treatment.

The most important lesson from UAE/DIFC case law is that authenticity is multidimensional.

A court may need to determine:

  • whether the electronic record exists;
  • whether it has been altered;
  • who created or sent it;
  • who controlled the relevant account or device;
  • whether an electronic signature was authorised;
  • whether the record is complete;
  • whether metadata and technical evidence support it;
  • whether an expert's methodology is reliable; and
  • whether independent evidence corroborates it.

The leading ICICI Bank v Shetty decision particularly demonstrates that proving that an electronic signature corresponds to a person's genuine signature is not necessarily the same as proving that the person authorised its application.

Accordingly, in UAE civil litigation, the strongest cyber-evidence system is not simply a “digital signature verification system.” It is an integrated framework combining technical integrity, identity verification, attribution, chain of custody, expert analysis, corroboration and judicial evaluation.

 

 

LEAVE A COMMENT