Civil Law And Uae Cyber Forensic Preservation Rules .
Civil Law and UAE Cyber Forensic Preservation Rules
1. Introduction
Cyber forensic preservation means the lawful identification, protection, collection, imaging, storage and production of digital information so that it remains reliable and capable of being used as evidence in civil or commercial proceedings.
In the UAE, there is not one single statute titled the “Cyber Forensic Preservation Law.” Instead, preservation obligations arise from a combination of:
Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services;
the UAE Civil Procedure framework;
the current Civil Transactions Law;
applicable data-protection and cybersecurity legislation;
rules governing expert evidence and document production;
DIFC and ADGM procedural rules where those jurisdictions apply.
The Federal Electronic Transactions Law is particularly important because it provides that an electronic document does not lose legal force merely because it is electronic. (UAE Legislation)
The DIFC framework is especially developed. DIFC Rule 28.2 expressly includes emails, databases, deleted electronic documents, servers, backups and metadata within the definition of documents. Rule 28.10 requires parties to discuss preservation of electronic documents at an early stage. (DIFC Courts)
2. Meaning of Cyber Forensic Preservation
Cyber forensic preservation is the process of ensuring that potentially relevant digital evidence is protected from:
deletion;
alteration;
overwriting;
corruption;
manipulation;
unauthorised access;
loss of metadata;
destruction through automatic retention systems.
Digital evidence may include:
emails;
WhatsApp messages;
SMS;
cloud files;
databases;
server logs;
access logs;
CCTV;
mobile-phone data;
computer hard drives;
USB devices;
blockchain records;
cryptocurrency wallet information;
browser histories;
system logs;
GPS/location records;
metadata;
deleted files;
backup copies;
authentication records;
IP addresses.
The central objective is:
To preserve the evidence in a manner that allows the court to determine what the information was, where it came from, whether it was altered, and whether it can reliably be attributed to a person or system.
3. UAE Legal Foundation
A. Federal Decree-Law No. 46 of 2021
The Electronic Transactions and Trust Services Law is fundamental to digital evidence.
Article 5 provides that an electronic document does not lose its legal force or enforceability merely because it is in electronic form. It also addresses accessibility of information contained in electronic documents. (UAE Legislation)
This creates an important distinction:
Electronic evidence is not automatically inferior to paper evidence.
The real questions are generally:
Is it authentic?
Can it be attributed to the relevant person?
Has its integrity been maintained?
Can its contents be reliably retrieved?
Is the evidence relevant?
Has it been properly preserved?
Has it been altered or manipulated?
4. Preservation Versus Admissibility
These concepts should not be confused.
Preservation
Preservation asks:
Was the digital evidence protected from alteration or destruction?
Admissibility
Admissibility asks:
Can the court legally receive the evidence?
Weight
Weight asks:
How much reliance should the court place upon it?
For example, an email may be admissible but given little weight if there is uncertainty concerning:
its author;
authenticity;
completeness;
metadata;
transmission;
alteration.
Therefore:
Preservation strengthens authenticity and evidential weight; it does not automatically prove the truth of the document.
5. The Basic Cyber-Forensic Preservation Lifecycle
A useful UAE litigation model is:
Identify → Preserve → Collect → Image → Hash → Document → Analyse → Produce → Explain
Step 1 — Identify
Identify potentially relevant sources:
laptops;
mobile phones;
servers;
cloud accounts;
email accounts;
databases;
messaging applications;
cryptocurrency wallets.
Step 2 — Preserve
Prevent deletion or modification.
Step 3 — Collect
Collect data using appropriate forensic methodology.
Step 4 — Image
Where appropriate, create a forensic image rather than working directly on the original device.
Step 5 — Hash
Calculate cryptographic hashes to demonstrate that a forensic copy remains identical to the collected data.
Step 6 — Document
Record:
who collected it;
when;
where;
how;
with what equipment;
from which device;
under whose authority.
Step 7 — Analyse
Experts examine:
metadata;
timestamps;
logs;
communications;
deleted files;
access history.
Step 8 — Produce
Relevant evidence is disclosed in an appropriate format.
Step 9 — Explain
An expert may explain the technical significance to the court.
6. DIFC Rule 28: One of the Most Important UAE Frameworks
DIFC Rule 28 provides an unusually detailed framework for electronic-document preservation.
The definition of a document expressly includes:
electronic documents;
emails;
electronic communications;
databases;
servers;
backup systems;
deleted electronic documents;
metadata. (DIFC Courts)
This is critical because a party cannot necessarily argue:
“The email was deleted, so it no longer exists as evidence.”
Deleted information may potentially remain recoverable from:
servers;
backups;
devices;
forensic images;
metadata;
cloud repositories.
7. Early Preservation Obligation
DIFC Rule 28.10 requires parties, before the first Case Management Conference, to discuss issues concerning:
searches;
preservation of electronic documents;
categories of electronic documents;
computer systems;
devices;
storage systems;
document-retention policies;
anticipated costs. (DIFC Courts)
This means preservation is treated as an early litigation-management issue, not merely something undertaken immediately before trial.
8. Metadata Preservation
Metadata can be as important as the visible content of a document.
Examples include:
creation date;
modification date;
author;
device identifier;
file path;
software used;
GPS information;
email headers;
transmission information;
access history.
DIFC Rule 28 expressly includes metadata within the definition of electronic documents. (DIFC Courts)
Example
A company produces a PDF showing:
“Contract approved — 15 March.”
The opposing party may ask:
When was the PDF created?
Who created it?
Was it modified?
From which computer?
Was the signature inserted later?
Does the metadata correspond with the alleged date?
Thus, preservation of the original electronic environment can become important.
9. Forensic Imaging
Forensic imaging means making a technically controlled copy of digital storage.
Instead of repeatedly examining the original laptop, a forensic investigator may create an image and analyse the image.
This protects the original from unnecessary alteration.
A good forensic process normally records:
device identification;
serial number;
date/time;
investigator;
acquisition method;
software/hardware;
hash values;
storage location;
transfer history.
10. Cryptographic Hashing
A hash is a mathematical fingerprint of digital information.
For example:
Original evidence → SHA-256 → Hash A
After copying:
Forensic image → SHA-256 → Hash B
If:
Hash A = Hash B
this supports the proposition that the contents of the copy have not changed.
Hashing therefore provides an important integrity mechanism.
But a hash does not by itself establish:
who created the file;
whether the original file was itself authentic;
whether the person had authority;
whether the underlying transaction was genuine.
It proves something narrower:
The compared digital datasets correspond according to the hashing process.
11. Chain of Custody
Chain of custody records the history of evidence.
A simplified chain is:
Device seized/collected
↓
Forensic investigator receives device
↓
Forensic image created
↓
Hash calculated
↓
Secure storage
↓
Expert analysis
↓
Copy supplied to lawyers
↓
Evidence produced to court
Every transfer should ideally be documented.
Important information includes:
date;
time;
person;
purpose;
location;
method;
integrity verification.
A weak chain of custody may provide an opposing party with grounds to challenge the reliability or weight of evidence.
12. Case Law
Case 1 — The Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017
This is one of the most directly relevant UAE/DIFC authorities for cyber-forensic preservation.
The DIFC Court ordered production of documents and data and provided for an independent IT forensic expert to inspect:
emails;
computer systems;
servers;
backup systems;
electronic devices;
electronic media.
The order contemplated forensic examination while taking account of possible alterations in hardware and software. (DIFC Courts)
Principle
Where electronic evidence is disputed, a court can use independent forensic expertise to investigate relevant electronic repositories.
Importance
This case demonstrates that preservation and forensic investigation can be judicially supervised rather than left entirely to the parties.
13. Case 2 — Shiraz Mahmood v Standard Chartered Bank [2022] DIFC CFI 044/2021
This case is particularly important concerning electronic document preservation and cooperation.
The Court referred to RDC Part 28 and criticised the parties' approach to electronic-document production because the rules required parties to confer collaboratively concerning:
searches;
preservation;
electronic documents;
search methodology;
production format. (DIFC Courts)
The Court also considered proportionality and the overriding objective.
Principle
Electronic discovery is not simply an adversarial “search everything” exercise.
Parties must approach preservation and production:
collaboratively;
proportionately;
efficiently;
with regard to forensic usefulness.
Importance
This is highly relevant to cyber-forensic preservation because indiscriminate imaging of every device may be unnecessary or disproportionate.
14. Case 3 — Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061
This case involved competing versions of electronically presented documents and questions concerning the appearance and origin of signatures.
The evidence included allegations that a document had been scanned or electronically manipulated and that signature elements might have been inserted electronically. The Court considered expert evidence concerning the differences between document versions. (DIFC Courts)
Principle
When authenticity is challenged, the court may need to investigate:
document provenance;
scanning;
electronic insertion;
differences between versions;
expert forensic evidence.
Importance
The case demonstrates why preserving the original electronic file, rather than merely producing a printed or scanned copy, can be important.
15. Case 4 — Naho v Neukirchi [2024] DIFC SCT 415
This case concerned an electronically transmitted contract and the legal significance of an email.
The Court considered the DIFC Electronic Transactions Law provisions concerning:
electronic records;
electronic signatures;
attribution;
intention to sign.
The Court recognised that an electronic record can satisfy a signature requirement where the electronic process is adopted with an intention to sign. (DIFC Courts)
Principle
Electronic evidence must be analysed according to its technological and legal characteristics rather than rejected merely because it is electronic.
Preservation significance
To establish attribution, it may be important to preserve:
the original email;
sender information;
recipient information;
timestamps;
attachments;
headers;
surrounding correspondence.
16. Case 5 — Ondina v Olin [2025] DIFC CFI 046
The Court of First Instance considered the appeal from the Small Claims Tribunal and examined electronic correspondence and the DIFC Electronic Transactions Law.
The case involved an employment contract whose commencement date had been changed through email correspondence. The Court considered whether the electronic correspondence could satisfy statutory requirements concerning written and signed amendments. (DIFC Courts)
Principle
Electronic communications may have legal consequences where legislation recognises electronic signatures and records.
Preservation significance
When the legal effect of an email is disputed, preservation should cover more than a screenshot.
Ideally, the evidential record includes:
the original email;
full headers;
attachments;
timestamps;
server records;
relevant surrounding correspondence.
17. Case 6 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2023] DIFC CA 002
This is particularly important for modern cyber-forensics involving cryptocurrency.
The dispute involved:
Bitcoin;
a Trezor hardware wallet;
private/seed information;
blockchain transactions;
expert evidence.
The Court considered technical evidence concerning Bitcoin, wallets and private keys and held that Bitcoin constitutes property of a third kind. (DIFC Courts)
Preservation significance
Cryptocurrency evidence may need preservation of:
wallet addresses;
transaction IDs;
blockchain records;
seed-phrase evidence where lawfully obtained;
device configuration;
screenshots;
exchange records;
timestamps;
expert analysis.
The case shows that digital-asset disputes can require both legal evidence and technical evidence.
18. Case 7 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2024] DIFC DEC 002
The later Digital Economy Court proceedings involved extensive technical evidence concerning a 300-BTC transaction, a Trezor wallet, seed words and the security configuration of the wallet.
The Court considered expert evidence and factual evidence concerning how access to the wallet was obtained and how Bitcoin was transferred. (DIFC Courts)
The judgment illustrates the importance of preserving technical evidence before the digital environment changes.
Relevant evidence included:
wallet configuration;
seed-word arrangements;
transaction history;
blockchain records;
device operation;
screenshots;
contemporaneous communications;
expert analysis.
Principle
In digital-asset litigation, preservation must address both the digital asset itself and the technological environment through which control over that asset is exercised.
19. Case 8 — GFH Capital Ltd v David Lawrence Haigh [2014] DIFC CFI 020
The case involved electronic communications, email instructions and electronic signatures.
The judgment records the use of email instructions and electronic/facsimile signatures and the defendant's assistant having control over his electronic signature. (DIFC Courts)
Principle
Electronic communications can be important evidence of:
authority;
instructions;
intention;
attribution;
transactions.
Preservation significance
A forensic investigation should preserve the context surrounding an electronic communication, not merely isolated messages.
20. Digital Evidence and Deleted Data
Deletion does not necessarily mean destruction.
Digital information may survive through:
backup systems;
email archives;
server logs;
cloud storage;
mobile backups;
forensic recovery;
database replication;
system images.
DIFC Rule 28.2 expressly recognises that electronic documents stored on servers and backup systems and even deleted electronic documents may fall within the scope of document production. (DIFC Courts)
Therefore:
“Deleted” is not necessarily equivalent to “irretrievable.”
21. Litigation Hold
A litigation hold is a preservation instruction issued when litigation is anticipated or commenced.
A UAE business facing a cyber dispute should consider suspending ordinary deletion procedures for relevant information.
For example, if an employee's emails are automatically deleted after 90 days, the company should identify whether relevant emails must be preserved.
A litigation hold can cover:
email;
WhatsApp;
Teams;
Slack;
mobile devices;
laptops;
cloud storage;
databases;
CCTV;
access logs.
DIFC Rule 28's express reference to preservation and retention policies makes this particularly important in DIFC proceedings. (DIFC Courts)
22. Employee Devices
Employee devices create special problems.
Relevant data may exist on:
company laptop;
personal laptop;
company phone;
personal phone;
personal cloud;
messaging applications.
The investigator must balance:
evidence preservation
against
privacy and confidentiality.
A forensic investigation should therefore be appropriately scoped.
It should not automatically authorise unrestricted examination of an employee's entire personal life.
23. Cloud Evidence
Cloud evidence presents additional challenges.
Data may be stored:
in the UAE;
elsewhere in the Middle East;
Europe;
the United States;
multiple jurisdictions simultaneously.
Preservation therefore needs to identify:
cloud provider;
account;
relevant custodians;
retention policy;
deletion mechanism;
backup arrangements;
metadata;
access logs;
jurisdiction of storage.
DIFC Rule 28 specifically contemplates documents stored on servers and backup systems and provides a framework for determining reasonable electronic searches. (DIFC Courts)
24. Mobile-Phone Forensics
Mobile phones may contain:
WhatsApp;
SMS;
emails;
photographs;
location information;
call logs;
browser history;
authentication applications;
cryptocurrency wallets.
A proper forensic process should avoid casually changing the device.
For example, opening an application may:
alter timestamps;
download new messages;
overwrite temporary files;
trigger synchronisation.
Therefore, forensic acquisition should normally be performed using an appropriate technical methodology.
25. WhatsApp and Messaging Evidence
A screenshot is generally weaker than preservation of the underlying electronic record.
A forensic package may ideally preserve:
message content;
sender;
recipient;
date/time;
attachments;
device information;
surrounding messages;
export information;
relevant metadata.
The issue is not simply:
“Does the screenshot look genuine?”
It is:
Can the evidence be reliably attributed and shown to have remained substantially intact?
26. Email Forensics
Email preservation should ideally include:
Header information
From;
To;
CC;
timestamps;
message ID;
routing information.
Content
body;
attachments;
embedded files.
Metadata
creation;
transmission;
modification.
Server information
Where relevant:
mail-server logs;
mailbox records;
retention archives.
This is substantially stronger than preserving only a printed email.
27. Blockchain Evidence
Blockchain evidence presents a special situation.
A blockchain may provide a highly durable transaction record, but the blockchain itself does not necessarily establish:
the real-world identity behind an address;
ownership;
authority;
whether a private key was stolen;
whether a person voluntarily authorised a transaction.
Therefore:
Blockchain record ≠ complete proof of legal ownership.
It should often be combined with:
exchange records;
KYC information;
wallet evidence;
communications;
device evidence;
expert testimony.
The Gate Mena litigation illustrates this distinction between technical control and legal rights. (DIFC Courts)
28. Cryptographic Hashes and Legal Evidence
A particularly useful forensic combination is:
Original file
↓
Forensic image
↓
Hash
↓
Expert report
↓
Court exhibit
The expert can explain:
acquisition method;
hash algorithm;
hash result;
preservation procedure;
whether the analysed copy corresponds with the original.
This allows the judge to distinguish:
technical integrity
from
substantive truth.
29. Search Methodology
DIFC Rule 28.19 permits electronic-document searches using:
specific files;
search terms;
individuals;
other efficient search methods.
Rule 28.21 identifies factors relevant to whether an electronic search is reasonable, including:
number of documents;
complexity of proceedings;
ease and expense of retrieval;
location of data;
likelihood of finding relevant material;
recovery costs;
production costs;
likelihood of alteration during recovery. (DIFC Courts)
This introduces a proportionality principle.
30. Proportionality
Cyber-forensic preservation should not become unlimited surveillance.
For example:
Dispute A
AED 100,000 contractual dispute concerning one invoice.
A complete forensic image of 50 employees' phones may be disproportionate.
Dispute B
Major cyberattack involving millions of dirhams and alleged destruction of corporate databases.
Extensive forensic investigation may be justified.
The scope should therefore correspond to:
relevance;
importance;
likely evidential value;
cost;
privacy;
technical complexity.
The DIFC rules expressly consider these factors. (DIFC Courts)
31. Independent Forensic Experts
An independent expert may be particularly useful where parties disagree about:
whether an email was deleted;
whether metadata was modified;
whether a signature was digitally inserted;
whether a file was altered;
who accessed a system;
whether a cryptocurrency wallet was compromised;
whether logs have been manipulated.
The Industrial Group v Dexter order is a clear example of the DIFC Court providing for independent IT forensic expertise. (DIFC Courts)
32. Court-Supervised Preservation
Courts can potentially make orders concerning:
preservation;
inspection;
disclosure;
imaging;
expert access;
production;
search methodology.
In appropriate cases, urgent relief may be important because digital evidence can disappear rapidly.
The DIFC's procedural framework also contains search-and-preservation mechanisms capable of requiring access to computers and relevant data while imposing safeguards against damage to computer systems. (DIFC Courts)
33. Digital Economy Court
The DIFC Digital Economy Court is particularly significant for modern cyber-forensic disputes.
Part 58 covers claims involving:
digital assets;
blockchain;
complex databases;
AI;
cloud-stored data;
digital payment platforms;
virtual assets;
DAOs;
DeFi;
DApps;
digital signatures;
digital identity;
IT systems;
cybersecurity-related technological disputes. (DIFC Courts)
This creates a specialised procedural environment for disputes where digital evidence is central.
34. Digital Asset Preservation
Modern digital-asset cases may require preservation of:
private keys;
seed phrases;
wallet addresses;
transaction hashes;
exchange accounts;
smart contracts;
blockchain records;
custody records.
However, private keys and seed phrases are highly sensitive.
Their preservation should be handled under appropriate security controls rather than casually copied into ordinary litigation files.
The DIFC Digital Economy Court has powers concerning digital assets and can make orders involving digital signatures, cryptographic keys, passwords and other digital access mechanisms. (DIFC Courts)
35. Preservation of AI-Generated Evidence
Modern cyber disputes may involve:
AI-generated communications;
AI logs;
model outputs;
automated decisions;
training datasets;
prompt histories.
Preservation should potentially include:
prompt;
input data;
output;
model/version;
timestamp;
user identity;
system logs;
configuration;
relevant API records.
This becomes particularly important because an AI output may change when:
the model is updated;
system settings change;
prompts change;
underlying data changes.
36. Data Protection and Preservation
Preservation does not mean that all privacy protections disappear.
A company may have to reconcile:
legal preservation
with
data protection obligations.
A proportionate approach can involve:
limiting access;
collecting only relevant material;
using forensic experts subject to confidentiality;
anonymisation where appropriate;
redaction;
secure storage;
access controls.
The objective is not unrestricted collection but lawful preservation of relevant evidence.
37. Common Mistakes in UAE Cyber-Forensic Preservation
Mistake 1 — Taking screenshots only
Screenshots may omit:
metadata;
headers;
underlying database information.
Mistake 2 — Working on the original device
This may alter evidence.
Mistake 3 — Failing to calculate hashes
Integrity becomes harder to demonstrate.
Mistake 4 — No chain of custody
The opposing party may challenge the reliability of the evidence.
Mistake 5 — Ignoring backups
Relevant evidence may remain in backup systems.
Mistake 6 — Continuing automatic deletion
A company's ordinary retention system may destroy relevant evidence.
Mistake 7 — Collecting everything
Over-collection creates:
privacy problems;
cost;
confidentiality problems;
proportionality disputes.
Mistake 8 — Preserving content but not metadata
This can make authentication more difficult.
38. Practical UAE Cyber-Forensic Preservation Protocol
A business anticipating litigation can use the following sequence:
Phase 1 — Trigger
Identify when a dispute or credible litigation risk arises.
Phase 2 — Legal hold
Suspend relevant automatic deletion.
Phase 3 — Data map
Identify:
custodians;
devices;
servers;
cloud accounts;
applications.
Phase 4 — Forensic preservation
Create appropriate forensic copies.
Phase 5 — Integrity
Calculate and record hashes.
Phase 6 — Chain of custody
Maintain a complete evidence log.
Phase 7 — Expert review
Use an appropriately qualified forensic expert where necessary.
Phase 8 — Proportional search
Use reasonable search terms and repositories.
Phase 9 — Privacy review
Separate privileged, confidential and irrelevant material.
Phase 10 — Production
Produce evidence in the required format.
Phase 11 — Expert report
Explain methodology and findings.
Phase 12 — Court presentation
Provide:
original/certified electronic evidence where appropriate;
forensic copy;
hash information;
chain-of-custody records;
expert report;
relevant metadata.
39. Case-Law Summary
| Case | Cyber-forensic/preservation significance |
|---|---|
| Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017 | Independent IT forensic expert; emails, servers, backups and electronic media |
| Shiraz Mahmood v Standard Chartered Bank [2022] DIFC CFI 044/2021 | Early preservation, cooperation and proportionality in electronic document production |
| Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061 | Electronic document versions, scanning, manipulation and expert examination |
| Naho v Neukirchi [2024] DIFC SCT 415 | Electronic records, attribution and electronic signatures |
| Ondina v Olin [2025] DIFC CFI 046 | Email communications and electronic signatures as legally significant records |
| Gate Mena v Tabarak [2023] DIFC CA 002 | Blockchain, wallet, private-key technology and expert evidence |
| Gate Mena v Tabarak [2024] DIFC DEC 002 | Detailed forensic/technical evidence concerning hardware wallet and seed-word security |
| GFH Capital v David Lawrence Haigh [2014] DIFC CFI 020 | Email instructions and electronic communications as evidence |
40. Key Legal Principles
The UAE cyber-forensic preservation framework can therefore be reduced to ten principles:
Electronic evidence has legal recognition.
Preservation should begin early.
Deleted data may remain discoverable.
Metadata can be evidentially significant.
Original electronic environments should be protected where practicable.
Forensic imaging can reduce alteration risk.
Hashing can support integrity.
Chain of custody supports evidential reliability.
Forensic investigation must remain proportionate.
Technical evidence should be connected to legal questions of authenticity, attribution, ownership and liability.
41. Conclusion
UAE cyber-forensic preservation law is a combination of electronic-evidence legislation, civil procedure, expert evidence, data-protection principles and specialised DIFC/ADGM procedural rules.
The most developed procedural framework is presently visible in the DIFC. RDC Part 28 expressly encompasses electronic documents, servers, backups, deleted documents and metadata and requires early discussion concerning preservation. (DIFC Courts)
The Federal Electronic Transactions and Trust Services Law establishes the fundamental principle that an electronic document does not lose legal force merely because it exists electronically. (UAE Legislation)
The cases demonstrate that preservation is not simply about saving a screenshot. Modern UAE litigation may require preservation of the original electronic environment, metadata, forensic images, cryptographic hashes, system logs, communications, blockchain records and chain-of-custody documentation.
The central principle is:
A digitally preserved record should allow the court to reconstruct, as far as reasonably possible, what information existed, where it came from, whether it was altered, how it was collected, and how it can reliably be attributed to the relevant person or system.
A final qualification is important: most of the detailed case authorities above are DIFC cases, reflecting the DIFC's sophisticated electronic-disclosure and Digital Economy Court framework. They are not automatically binding precedents for onshore UAE Federal Courts. The federal statutory foundation—particularly Federal Decree-Law No. 46 of 2021 and the applicable civil-procedure/evidence framework—must therefore be analysed separately for an onshore UAE dispute.

comments