Civil Law And Uae Cyber Forensic Preservation Rules .

Civil Law and UAE Cyber Forensic Preservation Rules

1. Introduction

Cyber forensic preservation means the lawful identification, protection, collection, imaging, storage and production of digital information so that it remains reliable and capable of being used as evidence in civil or commercial proceedings.

In the UAE, there is not one single statute titled the “Cyber Forensic Preservation Law.” Instead, preservation obligations arise from a combination of:

Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services;

the UAE Civil Procedure framework;

the current Civil Transactions Law;

applicable data-protection and cybersecurity legislation;

rules governing expert evidence and document production;

DIFC and ADGM procedural rules where those jurisdictions apply.

The Federal Electronic Transactions Law is particularly important because it provides that an electronic document does not lose legal force merely because it is electronic. (UAE Legislation)

The DIFC framework is especially developed. DIFC Rule 28.2 expressly includes emails, databases, deleted electronic documents, servers, backups and metadata within the definition of documents. Rule 28.10 requires parties to discuss preservation of electronic documents at an early stage. (DIFC Courts)

2. Meaning of Cyber Forensic Preservation

Cyber forensic preservation is the process of ensuring that potentially relevant digital evidence is protected from:

deletion;

alteration;

overwriting;

corruption;

manipulation;

unauthorised access;

loss of metadata;

destruction through automatic retention systems.

Digital evidence may include:

emails;

WhatsApp messages;

SMS;

cloud files;

databases;

server logs;

access logs;

CCTV;

mobile-phone data;

computer hard drives;

USB devices;

blockchain records;

cryptocurrency wallet information;

browser histories;

system logs;

GPS/location records;

metadata;

deleted files;

backup copies;

authentication records;

IP addresses.

The central objective is:

To preserve the evidence in a manner that allows the court to determine what the information was, where it came from, whether it was altered, and whether it can reliably be attributed to a person or system.

3. UAE Legal Foundation

A. Federal Decree-Law No. 46 of 2021

The Electronic Transactions and Trust Services Law is fundamental to digital evidence.

Article 5 provides that an electronic document does not lose its legal force or enforceability merely because it is in electronic form. It also addresses accessibility of information contained in electronic documents. (UAE Legislation)

This creates an important distinction:

Electronic evidence is not automatically inferior to paper evidence.

The real questions are generally:

Is it authentic?

Can it be attributed to the relevant person?

Has its integrity been maintained?

Can its contents be reliably retrieved?

Is the evidence relevant?

Has it been properly preserved?

Has it been altered or manipulated?

4. Preservation Versus Admissibility

These concepts should not be confused.

Preservation

Preservation asks:

Was the digital evidence protected from alteration or destruction?

Admissibility

Admissibility asks:

Can the court legally receive the evidence?

Weight

Weight asks:

How much reliance should the court place upon it?

For example, an email may be admissible but given little weight if there is uncertainty concerning:

its author;

authenticity;

completeness;

metadata;

transmission;

alteration.

Therefore:

Preservation strengthens authenticity and evidential weight; it does not automatically prove the truth of the document.

5. The Basic Cyber-Forensic Preservation Lifecycle

A useful UAE litigation model is:

Identify → Preserve → Collect → Image → Hash → Document → Analyse → Produce → Explain

Step 1 — Identify

Identify potentially relevant sources:

laptops;

mobile phones;

servers;

cloud accounts;

email accounts;

databases;

messaging applications;

cryptocurrency wallets.

Step 2 — Preserve

Prevent deletion or modification.

Step 3 — Collect

Collect data using appropriate forensic methodology.

Step 4 — Image

Where appropriate, create a forensic image rather than working directly on the original device.

Step 5 — Hash

Calculate cryptographic hashes to demonstrate that a forensic copy remains identical to the collected data.

Step 6 — Document

Record:

who collected it;

when;

where;

how;

with what equipment;

from which device;

under whose authority.

Step 7 — Analyse

Experts examine:

metadata;

timestamps;

logs;

communications;

deleted files;

access history.

Step 8 — Produce

Relevant evidence is disclosed in an appropriate format.

Step 9 — Explain

An expert may explain the technical significance to the court.

6. DIFC Rule 28: One of the Most Important UAE Frameworks

DIFC Rule 28 provides an unusually detailed framework for electronic-document preservation.

The definition of a document expressly includes:

electronic documents;

emails;

electronic communications;

databases;

servers;

backup systems;

deleted electronic documents;

metadata. (DIFC Courts)

This is critical because a party cannot necessarily argue:

“The email was deleted, so it no longer exists as evidence.”

Deleted information may potentially remain recoverable from:

servers;

backups;

devices;

forensic images;

metadata;

cloud repositories.

7. Early Preservation Obligation

DIFC Rule 28.10 requires parties, before the first Case Management Conference, to discuss issues concerning:

searches;

preservation of electronic documents;

categories of electronic documents;

computer systems;

devices;

storage systems;

document-retention policies;

anticipated costs. (DIFC Courts)

This means preservation is treated as an early litigation-management issue, not merely something undertaken immediately before trial.

8. Metadata Preservation

Metadata can be as important as the visible content of a document.

Examples include:

creation date;

modification date;

author;

device identifier;

file path;

software used;

GPS information;

email headers;

transmission information;

access history.

DIFC Rule 28 expressly includes metadata within the definition of electronic documents. (DIFC Courts)

Example

A company produces a PDF showing:

“Contract approved — 15 March.”

The opposing party may ask:

When was the PDF created?

Who created it?

Was it modified?

From which computer?

Was the signature inserted later?

Does the metadata correspond with the alleged date?

Thus, preservation of the original electronic environment can become important.

9. Forensic Imaging

Forensic imaging means making a technically controlled copy of digital storage.

Instead of repeatedly examining the original laptop, a forensic investigator may create an image and analyse the image.

This protects the original from unnecessary alteration.

A good forensic process normally records:

device identification;

serial number;

date/time;

investigator;

acquisition method;

software/hardware;

hash values;

storage location;

transfer history.

10. Cryptographic Hashing

A hash is a mathematical fingerprint of digital information.

For example:

Original evidence → SHA-256 → Hash A

After copying:

Forensic image → SHA-256 → Hash B

If:

Hash A = Hash B

this supports the proposition that the contents of the copy have not changed.

Hashing therefore provides an important integrity mechanism.

But a hash does not by itself establish:

who created the file;

whether the original file was itself authentic;

whether the person had authority;

whether the underlying transaction was genuine.

It proves something narrower:

The compared digital datasets correspond according to the hashing process.

11. Chain of Custody

Chain of custody records the history of evidence.

A simplified chain is:

Device seized/collected

Forensic investigator receives device

Forensic image created

Hash calculated

Secure storage

Expert analysis

Copy supplied to lawyers

Evidence produced to court

Every transfer should ideally be documented.

Important information includes:

date;

time;

person;

purpose;

location;

method;

integrity verification.

A weak chain of custody may provide an opposing party with grounds to challenge the reliability or weight of evidence.

12. Case Law

Case 1 — The Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017

This is one of the most directly relevant UAE/DIFC authorities for cyber-forensic preservation.

The DIFC Court ordered production of documents and data and provided for an independent IT forensic expert to inspect:

emails;

computer systems;

servers;

backup systems;

electronic devices;

electronic media.

The order contemplated forensic examination while taking account of possible alterations in hardware and software. (DIFC Courts)

Principle

Where electronic evidence is disputed, a court can use independent forensic expertise to investigate relevant electronic repositories.

Importance

This case demonstrates that preservation and forensic investigation can be judicially supervised rather than left entirely to the parties.

13. Case 2 — Shiraz Mahmood v Standard Chartered Bank [2022] DIFC CFI 044/2021

This case is particularly important concerning electronic document preservation and cooperation.

The Court referred to RDC Part 28 and criticised the parties' approach to electronic-document production because the rules required parties to confer collaboratively concerning:

searches;

preservation;

electronic documents;

search methodology;

production format. (DIFC Courts)

The Court also considered proportionality and the overriding objective.

Principle

Electronic discovery is not simply an adversarial “search everything” exercise.

Parties must approach preservation and production:

collaboratively;

proportionately;

efficiently;

with regard to forensic usefulness.

Importance

This is highly relevant to cyber-forensic preservation because indiscriminate imaging of every device may be unnecessary or disproportionate.

14. Case 3 — Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061

This case involved competing versions of electronically presented documents and questions concerning the appearance and origin of signatures.

The evidence included allegations that a document had been scanned or electronically manipulated and that signature elements might have been inserted electronically. The Court considered expert evidence concerning the differences between document versions. (DIFC Courts)

Principle

When authenticity is challenged, the court may need to investigate:

document provenance;

scanning;

electronic insertion;

differences between versions;

expert forensic evidence.

Importance

The case demonstrates why preserving the original electronic file, rather than merely producing a printed or scanned copy, can be important.

15. Case 4 — Naho v Neukirchi [2024] DIFC SCT 415

This case concerned an electronically transmitted contract and the legal significance of an email.

The Court considered the DIFC Electronic Transactions Law provisions concerning:

electronic records;

electronic signatures;

attribution;

intention to sign.

The Court recognised that an electronic record can satisfy a signature requirement where the electronic process is adopted with an intention to sign. (DIFC Courts)

Principle

Electronic evidence must be analysed according to its technological and legal characteristics rather than rejected merely because it is electronic.

Preservation significance

To establish attribution, it may be important to preserve:

the original email;

sender information;

recipient information;

timestamps;

attachments;

headers;

surrounding correspondence.

16. Case 5 — Ondina v Olin [2025] DIFC CFI 046

The Court of First Instance considered the appeal from the Small Claims Tribunal and examined electronic correspondence and the DIFC Electronic Transactions Law.

The case involved an employment contract whose commencement date had been changed through email correspondence. The Court considered whether the electronic correspondence could satisfy statutory requirements concerning written and signed amendments. (DIFC Courts)

Principle

Electronic communications may have legal consequences where legislation recognises electronic signatures and records.

Preservation significance

When the legal effect of an email is disputed, preservation should cover more than a screenshot.

Ideally, the evidential record includes:

the original email;

full headers;

attachments;

timestamps;

server records;

relevant surrounding correspondence.

17. Case 6 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2023] DIFC CA 002

This is particularly important for modern cyber-forensics involving cryptocurrency.

The dispute involved:

Bitcoin;

a Trezor hardware wallet;

private/seed information;

blockchain transactions;

expert evidence.

The Court considered technical evidence concerning Bitcoin, wallets and private keys and held that Bitcoin constitutes property of a third kind. (DIFC Courts)

Preservation significance

Cryptocurrency evidence may need preservation of:

wallet addresses;

transaction IDs;

blockchain records;

seed-phrase evidence where lawfully obtained;

device configuration;

screenshots;

exchange records;

timestamps;

expert analysis.

The case shows that digital-asset disputes can require both legal evidence and technical evidence.

18. Case 7 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2024] DIFC DEC 002

The later Digital Economy Court proceedings involved extensive technical evidence concerning a 300-BTC transaction, a Trezor wallet, seed words and the security configuration of the wallet.

The Court considered expert evidence and factual evidence concerning how access to the wallet was obtained and how Bitcoin was transferred. (DIFC Courts)

The judgment illustrates the importance of preserving technical evidence before the digital environment changes.

Relevant evidence included:

wallet configuration;

seed-word arrangements;

transaction history;

blockchain records;

device operation;

screenshots;

contemporaneous communications;

expert analysis.

Principle

In digital-asset litigation, preservation must address both the digital asset itself and the technological environment through which control over that asset is exercised.

19. Case 8 — GFH Capital Ltd v David Lawrence Haigh [2014] DIFC CFI 020

The case involved electronic communications, email instructions and electronic signatures.

The judgment records the use of email instructions and electronic/facsimile signatures and the defendant's assistant having control over his electronic signature. (DIFC Courts)

Principle

Electronic communications can be important evidence of:

authority;

instructions;

intention;

attribution;

transactions.

Preservation significance

A forensic investigation should preserve the context surrounding an electronic communication, not merely isolated messages.

20. Digital Evidence and Deleted Data

Deletion does not necessarily mean destruction.

Digital information may survive through:

backup systems;

email archives;

server logs;

cloud storage;

mobile backups;

forensic recovery;

database replication;

system images.

DIFC Rule 28.2 expressly recognises that electronic documents stored on servers and backup systems and even deleted electronic documents may fall within the scope of document production. (DIFC Courts)

Therefore:

“Deleted” is not necessarily equivalent to “irretrievable.”

21. Litigation Hold

A litigation hold is a preservation instruction issued when litigation is anticipated or commenced.

A UAE business facing a cyber dispute should consider suspending ordinary deletion procedures for relevant information.

For example, if an employee's emails are automatically deleted after 90 days, the company should identify whether relevant emails must be preserved.

A litigation hold can cover:

email;

WhatsApp;

Teams;

Slack;

mobile devices;

laptops;

cloud storage;

databases;

CCTV;

access logs.

DIFC Rule 28's express reference to preservation and retention policies makes this particularly important in DIFC proceedings. (DIFC Courts)

22. Employee Devices

Employee devices create special problems.

Relevant data may exist on:

company laptop;

personal laptop;

company phone;

personal phone;

personal cloud;

messaging applications.

The investigator must balance:

evidence preservation

against

privacy and confidentiality.

A forensic investigation should therefore be appropriately scoped.

It should not automatically authorise unrestricted examination of an employee's entire personal life.

23. Cloud Evidence

Cloud evidence presents additional challenges.

Data may be stored:

in the UAE;

elsewhere in the Middle East;

Europe;

the United States;

multiple jurisdictions simultaneously.

Preservation therefore needs to identify:

cloud provider;

account;

relevant custodians;

retention policy;

deletion mechanism;

backup arrangements;

metadata;

access logs;

jurisdiction of storage.

DIFC Rule 28 specifically contemplates documents stored on servers and backup systems and provides a framework for determining reasonable electronic searches. (DIFC Courts)

24. Mobile-Phone Forensics

Mobile phones may contain:

WhatsApp;

SMS;

emails;

photographs;

location information;

call logs;

browser history;

authentication applications;

cryptocurrency wallets.

A proper forensic process should avoid casually changing the device.

For example, opening an application may:

alter timestamps;

download new messages;

overwrite temporary files;

trigger synchronisation.

Therefore, forensic acquisition should normally be performed using an appropriate technical methodology.

25. WhatsApp and Messaging Evidence

A screenshot is generally weaker than preservation of the underlying electronic record.

A forensic package may ideally preserve:

message content;

sender;

recipient;

date/time;

attachments;

device information;

surrounding messages;

export information;

relevant metadata.

The issue is not simply:

“Does the screenshot look genuine?”

It is:

Can the evidence be reliably attributed and shown to have remained substantially intact?

26. Email Forensics

Email preservation should ideally include:

Header information

From;

To;

CC;

timestamps;

message ID;

routing information.

Content

body;

attachments;

embedded files.

Metadata

creation;

transmission;

modification.

Server information

Where relevant:

mail-server logs;

mailbox records;

retention archives.

This is substantially stronger than preserving only a printed email.

27. Blockchain Evidence

Blockchain evidence presents a special situation.

A blockchain may provide a highly durable transaction record, but the blockchain itself does not necessarily establish:

the real-world identity behind an address;

ownership;

authority;

whether a private key was stolen;

whether a person voluntarily authorised a transaction.

Therefore:

Blockchain record ≠ complete proof of legal ownership.

It should often be combined with:

exchange records;

KYC information;

wallet evidence;

communications;

device evidence;

expert testimony.

The Gate Mena litigation illustrates this distinction between technical control and legal rights. (DIFC Courts)

28. Cryptographic Hashes and Legal Evidence

A particularly useful forensic combination is:

Original file

Forensic image

Hash

Expert report

Court exhibit

The expert can explain:

acquisition method;

hash algorithm;

hash result;

preservation procedure;

whether the analysed copy corresponds with the original.

This allows the judge to distinguish:

technical integrity

from

substantive truth.

29. Search Methodology

DIFC Rule 28.19 permits electronic-document searches using:

specific files;

search terms;

individuals;

other efficient search methods.

Rule 28.21 identifies factors relevant to whether an electronic search is reasonable, including:

number of documents;

complexity of proceedings;

ease and expense of retrieval;

location of data;

likelihood of finding relevant material;

recovery costs;

production costs;

likelihood of alteration during recovery. (DIFC Courts)

This introduces a proportionality principle.

30. Proportionality

Cyber-forensic preservation should not become unlimited surveillance.

For example:

Dispute A

AED 100,000 contractual dispute concerning one invoice.

A complete forensic image of 50 employees' phones may be disproportionate.

Dispute B

Major cyberattack involving millions of dirhams and alleged destruction of corporate databases.

Extensive forensic investigation may be justified.

The scope should therefore correspond to:

relevance;

importance;

likely evidential value;

cost;

privacy;

technical complexity.

The DIFC rules expressly consider these factors. (DIFC Courts)

31. Independent Forensic Experts

An independent expert may be particularly useful where parties disagree about:

whether an email was deleted;

whether metadata was modified;

whether a signature was digitally inserted;

whether a file was altered;

who accessed a system;

whether a cryptocurrency wallet was compromised;

whether logs have been manipulated.

The Industrial Group v Dexter order is a clear example of the DIFC Court providing for independent IT forensic expertise. (DIFC Courts)

32. Court-Supervised Preservation

Courts can potentially make orders concerning:

preservation;

inspection;

disclosure;

imaging;

expert access;

production;

search methodology.

In appropriate cases, urgent relief may be important because digital evidence can disappear rapidly.

The DIFC's procedural framework also contains search-and-preservation mechanisms capable of requiring access to computers and relevant data while imposing safeguards against damage to computer systems. (DIFC Courts)

33. Digital Economy Court

The DIFC Digital Economy Court is particularly significant for modern cyber-forensic disputes.

Part 58 covers claims involving:

digital assets;

blockchain;

complex databases;

AI;

cloud-stored data;

digital payment platforms;

virtual assets;

DAOs;

DeFi;

DApps;

digital signatures;

digital identity;

IT systems;

cybersecurity-related technological disputes. (DIFC Courts)

This creates a specialised procedural environment for disputes where digital evidence is central.

34. Digital Asset Preservation

Modern digital-asset cases may require preservation of:

private keys;

seed phrases;

wallet addresses;

transaction hashes;

exchange accounts;

smart contracts;

blockchain records;

custody records.

However, private keys and seed phrases are highly sensitive.

Their preservation should be handled under appropriate security controls rather than casually copied into ordinary litigation files.

The DIFC Digital Economy Court has powers concerning digital assets and can make orders involving digital signatures, cryptographic keys, passwords and other digital access mechanisms. (DIFC Courts)

35. Preservation of AI-Generated Evidence

Modern cyber disputes may involve:

AI-generated communications;

AI logs;

model outputs;

automated decisions;

training datasets;

prompt histories.

Preservation should potentially include:

prompt;

input data;

output;

model/version;

timestamp;

user identity;

system logs;

configuration;

relevant API records.

This becomes particularly important because an AI output may change when:

the model is updated;

system settings change;

prompts change;

underlying data changes.

36. Data Protection and Preservation

Preservation does not mean that all privacy protections disappear.

A company may have to reconcile:

legal preservation

with

data protection obligations.

A proportionate approach can involve:

limiting access;

collecting only relevant material;

using forensic experts subject to confidentiality;

anonymisation where appropriate;

redaction;

secure storage;

access controls.

The objective is not unrestricted collection but lawful preservation of relevant evidence.

37. Common Mistakes in UAE Cyber-Forensic Preservation

Mistake 1 — Taking screenshots only

Screenshots may omit:

metadata;

headers;

underlying database information.

Mistake 2 — Working on the original device

This may alter evidence.

Mistake 3 — Failing to calculate hashes

Integrity becomes harder to demonstrate.

Mistake 4 — No chain of custody

The opposing party may challenge the reliability of the evidence.

Mistake 5 — Ignoring backups

Relevant evidence may remain in backup systems.

Mistake 6 — Continuing automatic deletion

A company's ordinary retention system may destroy relevant evidence.

Mistake 7 — Collecting everything

Over-collection creates:

privacy problems;

cost;

confidentiality problems;

proportionality disputes.

Mistake 8 — Preserving content but not metadata

This can make authentication more difficult.

38. Practical UAE Cyber-Forensic Preservation Protocol

A business anticipating litigation can use the following sequence:

Phase 1 — Trigger

Identify when a dispute or credible litigation risk arises.

Phase 2 — Legal hold

Suspend relevant automatic deletion.

Phase 3 — Data map

Identify:

custodians;

devices;

servers;

cloud accounts;

applications.

Phase 4 — Forensic preservation

Create appropriate forensic copies.

Phase 5 — Integrity

Calculate and record hashes.

Phase 6 — Chain of custody

Maintain a complete evidence log.

Phase 7 — Expert review

Use an appropriately qualified forensic expert where necessary.

Phase 8 — Proportional search

Use reasonable search terms and repositories.

Phase 9 — Privacy review

Separate privileged, confidential and irrelevant material.

Phase 10 — Production

Produce evidence in the required format.

Phase 11 — Expert report

Explain methodology and findings.

Phase 12 — Court presentation

Provide:

original/certified electronic evidence where appropriate;

forensic copy;

hash information;

chain-of-custody records;

expert report;

relevant metadata.

39. Case-Law Summary

CaseCyber-forensic/preservation significance
Industrial Group Ltd v Bradley Dexter [2018] DIFC CFI 044/2017Independent IT forensic expert; emails, servers, backups and electronic media
Shiraz Mahmood v Standard Chartered Bank [2022] DIFC CFI 044/2021Early preservation, cooperation and proportionality in electronic document production
Barclays Bank PLC v Bavaguthu Raghuram Shetty [2020] DIFC CFI 061Electronic document versions, scanning, manipulation and expert examination
Naho v Neukirchi [2024] DIFC SCT 415Electronic records, attribution and electronic signatures
Ondina v Olin [2025] DIFC CFI 046Email communications and electronic signatures as legally significant records
Gate Mena v Tabarak [2023] DIFC CA 002Blockchain, wallet, private-key technology and expert evidence
Gate Mena v Tabarak [2024] DIFC DEC 002Detailed forensic/technical evidence concerning hardware wallet and seed-word security
GFH Capital v David Lawrence Haigh [2014] DIFC CFI 020Email instructions and electronic communications as evidence

40. Key Legal Principles

The UAE cyber-forensic preservation framework can therefore be reduced to ten principles:

Electronic evidence has legal recognition.

Preservation should begin early.

Deleted data may remain discoverable.

Metadata can be evidentially significant.

Original electronic environments should be protected where practicable.

Forensic imaging can reduce alteration risk.

Hashing can support integrity.

Chain of custody supports evidential reliability.

Forensic investigation must remain proportionate.

Technical evidence should be connected to legal questions of authenticity, attribution, ownership and liability.

41. Conclusion

UAE cyber-forensic preservation law is a combination of electronic-evidence legislation, civil procedure, expert evidence, data-protection principles and specialised DIFC/ADGM procedural rules.

The most developed procedural framework is presently visible in the DIFC. RDC Part 28 expressly encompasses electronic documents, servers, backups, deleted documents and metadata and requires early discussion concerning preservation. (DIFC Courts)

The Federal Electronic Transactions and Trust Services Law establishes the fundamental principle that an electronic document does not lose legal force merely because it exists electronically. (UAE Legislation)

The cases demonstrate that preservation is not simply about saving a screenshot. Modern UAE litigation may require preservation of the original electronic environment, metadata, forensic images, cryptographic hashes, system logs, communications, blockchain records and chain-of-custody documentation.

The central principle is:

A digitally preserved record should allow the court to reconstruct, as far as reasonably possible, what information existed, where it came from, whether it was altered, how it was collected, and how it can reliably be attributed to the relevant person or system.

A final qualification is important: most of the detailed case authorities above are DIFC cases, reflecting the DIFC's sophisticated electronic-disclosure and Digital Economy Court framework. They are not automatically binding precedents for onshore UAE Federal Courts. The federal statutory foundation—particularly Federal Decree-Law No. 46 of 2021 and the applicable civil-procedure/evidence framework—must therefore be analysed separately for an onshore UAE dispute.

LEAVE A COMMENT