Civil Law And Uae Cyber Law Fundamentals .
Civil Law and UAE Cyber Law Fundamentals
1. Introduction
UAE cyber law is not contained in a single statute. It is a multi-layered legal framework dealing with cybercrime, electronic transactions, electronic evidence, personal data, privacy, financial fraud, and civil liability.
The principal federal cybercrime statute is Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes, which took effect on 2 January 2022. It addresses misuse of information technology, hacking, attacks on information systems, electronic fraud, privacy violations and other online offences.
For civil-law disputes, cyber law operates together with:
- Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions;
- Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services;
- Federal Decree-Law No. 45 of 2021 on Personal Data Protection;
- applicable UAE civil and commercial legislation;
- sector-specific regulations concerning banking, financial services and telecommunications; and
- in the DIFC, the separate DIFC laws and Rules of the DIFC Courts.
The UAE Government itself identifies the Cybercrimes Law, Personal Data Protection Law and Electronic Transactions and Trust Services Law as major components of the UAE cyber-law framework.
2. Meaning of Cyber Law
Cyber law means the body of legal rules governing activities involving:
- computers;
- computer networks;
- the internet;
- electronic communications;
- digital information;
- electronic transactions;
- cybersecurity;
- personal data;
- digital identity;
- electronic evidence;
- cyber fraud; and
- unlawful access or interference with information systems.
Cyber law therefore has both a public-law/criminal dimension and a private-law/civil dimension.
Criminal dimension
The State may prosecute:
- hacking;
- unauthorised access;
- electronic fraud;
- unlawful interception;
- misuse of information systems;
- certain forms of online abuse;
- unlawful disclosure or use of information; and
- other offences specified by the Cybercrimes Law.
Civil dimension
A cyber incident can simultaneously create:
- contractual liability;
- tort/delict liability;
- compensation claims;
- restitution;
- injunctions;
- confidentiality claims;
- banking disputes;
- data-protection claims;
- employment disputes; and
- claims for recovery of digitally transferred assets.
3. Principal UAE Cyber-Law Framework
| Legal instrument | Main subject |
|---|---|
| Federal Decree-Law No. 34 of 2021 | Cybercrimes and misuse of information technology |
| Federal Decree-Law No. 35 of 2022 | Civil and commercial evidence, including electronic evidence |
| Federal Decree-Law No. 46 of 2021 | Electronic transactions, electronic signatures and trust services |
| Federal Decree-Law No. 45 of 2021 | Personal-data protection |
| UAE civil/commercial legislation | Compensation, contracts, obligations and damages |
| Sector-specific financial rules | Cybersecurity and electronic banking risks |
| DIFC legislation | Separate civil/commercial framework within the DIFC |
The Electronic Transactions and Trust Services Law expressly provides that an electronic document does not lose its legal force merely because it is in electronic form.
4. Federal Cybercrimes Law
Federal Decree-Law No. 34 of 2021
The Cybercrimes Law provides a comprehensive federal framework concerning misuse of information technology, networks and online platforms. It covers matters including attacks on information systems, electronic fraud, privacy and protection of government information systems.
The basic legal idea is that digital technology does not remove ordinary legal responsibility.
For example, a person cannot escape liability merely because:
- the fraud was committed through email;
- the property was transferred electronically;
- the attack was conducted remotely;
- the communication occurred through WhatsApp;
- the information was stored on a cloud server; or
- the wrongdoer used another person's credentials.
5. Cybercrime and Civil Liability
A particularly important distinction is:
Criminal liability and civil liability are separate questions.
Suppose an employee hacks a company's server and deletes business information.
There may be:
Criminal consequences
The conduct may constitute a cybercrime under applicable federal law.
Civil consequences
The company may separately claim:
- restoration costs;
- loss caused by interruption;
- investigation expenses;
- damage to property or systems;
- contractual damages;
- compensation for proven financial loss; and
- appropriate injunctive relief.
This distinction is particularly clear in Graciela Limited v Giacobbe, discussed below.
6. Electronic Transactions
Federal Decree-Law No. 46 of 2021 gives legal recognition to electronic transactions and trust services.
A fundamental principle is that an electronic document cannot be denied legal force simply because it exists electronically.
This is important for:
- electronic contracts;
- electronic invoices;
- digital signatures;
- electronic notices;
- online banking instructions;
- electronic records;
- digital certificates;
- electronic seals; and
- electronic business communications.
The UAE Government also explains that an electronic signature can have the same binding effect as a handwritten signature when the statutory requirements are satisfied.
7. Electronic Evidence
Federal Decree-Law No. 35 of 2022 is extremely important for civil cyber disputes.
Article 54 recognises various forms of electronic evidence, including:
- electronic instruments;
- electronic signatures;
- electronic seals;
- emails;
- modern communication methods;
- electronic media; and
- other electronic evidence.
Article 55 provides that electronic evidence is subject to the provisions applicable to documentary evidence, while Article 56 addresses the probative value of formal electronic evidence.
Therefore, a UAE civil court can deal with evidence such as:
email + WhatsApp message + server log + digital signature + cloud record + transaction record
as part of the evidentiary framework.
8. Important Evidentiary Principles
Cyber evidence normally raises five questions.
1. Authenticity
Is the electronic record genuine?
2. Attribution
Who actually created or sent it?
3. Integrity
Has the information been altered?
4. Reliability
Was the system that generated the information functioning reliably?
5. Probative value
Even if authentic, how much weight should the court give it?
This distinction is important.
A WhatsApp message may be authentic but still not establish every fact asserted within the message.
Similarly, an IP address can be relevant evidence without necessarily proving conclusively who physically operated the device.
9. Cybersecurity as a Civil-Law Obligation
Cybersecurity is increasingly relevant to ordinary civil obligations.
A business may have contractual or regulatory obligations concerning:
- protection of customer information;
- access controls;
- passwords;
- authentication;
- employee access;
- data retention;
- incident response;
- payment verification; and
- protection of confidential information.
Whether a failure amounts to civil liability depends on the applicable statute, contract, regulatory framework and facts.
The Aegis Resources litigation is particularly useful because it demonstrates how an email compromise can become a civil dispute concerning banking mandates, security procedures, causation and damages.
10. Case Law
Because reported UAE federal civil decisions specifically analysing cyber-law fundamentals remain relatively limited, several of the most useful authorities come from the DIFC Courts. These cases should be understood as DIFC authorities applying the DIFC legal framework; they are not automatically binding precedents for UAE federal courts.
Case 1 — Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the most important UAE-based civil cases concerning a cyberattack.
The claimant's IT system was deliberately sabotaged. The dispute involved server access, administrator accounts, IP addresses, event logs, forensic images and deleted data.
The Court considered extensive technical evidence and concluded, on the civil standard of proof, that the defendant had carried out the sabotage. The Court awarded USD 690,533 in compensatory damages for restoration, investigation, emergency servers and employee time associated with the incident.
Legal significance
The case demonstrates that a cyberattack can constitute a civil wrong capable of producing substantial compensatory liability.
It also demonstrates the importance of:
- forensic investigation;
- server logs;
- IP evidence;
- system architecture;
- expert evidence;
- chronology;
- deleted data;
- access credentials; and
- circumstantial evidence.
Importantly, the Court stated that the ultimate issue was for the Court rather than the expert to decide.
Principle
Technical evidence must be translated into legally sufficient evidence connecting the cyber activity to the alleged wrongdoer.
11. Case 2 — Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
This case involved a sophisticated email-compromise fraud.
A fraudster hacked into the customer's email system and sent payment instructions to the bank. The bank acted on those instructions, resulting in a substantial financial loss.
The central question was whether the loss should fall on the bank or customer.
The DIFC Court treated the matter as fact-specific and examined the banking mandate, the circumstances of the fraudulent instructions and the security arrangements. It ultimately held that the bank had acted outside its mandate in processing the relevant instructions and ordered substantial relief in favour of Aegis.
Legal significance
The case demonstrates that cyber fraud can create ordinary banking and contractual liability.
It also shows that courts may examine:
- normal transaction procedures;
- unusual payment instructions;
- authentication arrangements;
- email security;
- customer conduct;
- bank procedures;
- suspicious circumstances; and
- contractual allocation of risk.
Principle
The fact that a payment instruction was transmitted electronically does not by itself establish that it was validly authorised.
12. Case 3 — Taaleem PJSC v National Bonds Corporation PJSC & Deyaar Development PJSC [2010] DIFC CFI 014
Taaleem is not a conventional hacking case. It is nevertheless important for the electronic-document and e-discovery dimensions of cyber law.
The DIFC Court examined document disclosure and the increasing importance of electronic documents. The Court recognised that electronic searches require consideration of factors such as the ease and expense of retrieval and the likely significance of documents.
Legal significance
Modern civil cyber litigation frequently depends on:
- email archives;
- databases;
- electronic documents;
- cloud storage;
- electronic communications;
- metadata; and
- backup systems.
The case demonstrates that discovery obligations must account for the technological nature of modern business records.
Principle
Electronic discovery is part of modern civil procedure and must be conducted reasonably and proportionately.
13. Case 4 — AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060
The AES litigation involved allegations concerning misuse of confidential information, former employees, client information and movement of business relationships.
The Court dealt with extensive electronic evidence and document-production issues involving modern business communications and digital records.
The substantive 2025 judgment ultimately dismissed the claims, finding insufficient evidence to establish the alleged wrongful conduct and resulting losses.
Legal significance
The case illustrates an important cyber-law principle:
Possession of digital information is not itself proof of unlawful use.
A claimant must establish the necessary elements of the underlying civil cause of action.
Electronic evidence must therefore be connected to:
- the person;
- the conduct;
- the legal obligation;
- the breach; and
- the resulting loss.
14. Case 5 — Anoop Kumar Lal & Paul Patrick Hennessy v Donna Benton [2021] DIFC CFI 005
This litigation illustrates the increasing importance of electronically stored information.
The proceedings involved applications concerning document production and electronic communications. The DIFC Court considered the scope of document-production obligations and the need for parties to comply with disclosure orders.
Legal significance
Cyber litigation is not limited to proving the original cyberattack.
The court may also need to determine:
- which devices should be searched;
- which email accounts should be searched;
- whether messaging applications contain relevant material;
- whether documents have been withheld;
- whether deleted information needs investigation; and
- whether additional electronic searches are proportionate.
Principle
Parties to civil litigation have obligations concerning relevant electronically stored information, subject to applicable procedural rules and proportionality.
15. Case 6 — Gjurd v Gizella (DIFC) Limited [2016] DIFC SCT 081
This case demonstrates the use of electronic communications in ordinary civil litigation.
The DIFC Small Claims Tribunal considered evidence including communications exchanged electronically and made an order for restitution of AED 211,710.14.
Legal significance
The case illustrates that digital communications are not confined to specialist cybercrime litigation.
They can become evidence in:
- employment disputes;
- contractual disputes;
- payment disputes;
- service disputes; and
- restitution claims.
Principle
Electronic communications can form part of the evidentiary record in ordinary civil proceedings when properly presented and assessed.
16. Case 7 — Levent & Lexie v Lilika [2021] DIFC CFI 030
This case concerned international judicial assistance arising from proceedings in Minnesota.
The DIFC Court ordered witnesses located in the UAE, including representatives connected with Sharjah Police, to attend for examination and produce documents in response to letters rogatory.
Cyber-law relevance
Cyber disputes frequently cross borders because:
- servers may be overseas;
- cloud providers may be located abroad;
- victims and defendants may be in different countries;
- payment accounts may be international; and
- evidence may be stored outside the UAE.
Principle
Cross-border digital disputes may require judicial cooperation and formal mechanisms for obtaining evidence located in another jurisdiction.
17. Case 8 — Kitopi Catering Services LLC v Mons Hospitality FZE [2024] DIFC CFI 081
This recent DIFC litigation demonstrates the continuing importance of electronic document production.
The DIFC Court expressly dealt with document-production requests under RDC Part 28, whose definition of documents extends to electronic documents, email, electronic communications, word-processed documents and databases.
The underlying dispute concerned contractual and operational matters rather than a pure cyberattack, making the case useful for understanding the procedural infrastructure surrounding electronic evidence.
Principle
Modern civil litigation treats electronically stored information as an ordinary and potentially essential category of documentary evidence.
18. Civil Remedies for Cyber Wrongdoing
Depending on the applicable law and facts, possible civil remedies include:
1. Compensatory damages
Compensation may cover proven losses resulting from the cyber incident.
2. Restitution
Where money or property has been wrongfully obtained, restitution may be available.
3. Injunctions
A court may, where legally available, restrain:
- continued unauthorised access;
- disclosure of confidential information;
- misuse of data; or
- continuation of wrongful conduct.
4. Preservation orders
Digital evidence may need to be preserved before it is deleted or altered.
5. Disclosure and production
Courts can require production of relevant electronic documents under applicable procedural rules.
6. Tracing and recovery
Cyber-enabled financial transfers may require tracing through:
- bank accounts;
- payment systems;
- cryptocurrency wallets;
- exchanges; and
- other intermediaries.
19. Cyber Fraud and Banking Liability
A cyber fraud transaction usually raises several separate legal questions:
Step 1 — Was the instruction authentic?
Step 2 — Was it authorised by the customer?
Step 3 — Did the bank follow its contractual mandate?
Step 4 — Were there suspicious circumstances?
Step 5 — Did the customer's own conduct contribute to the loss?
Step 6 — What loss was caused by the breach?
Step 7 — Can the transferred money be recovered?
The Aegis case demonstrates why cyber fraud cannot simply be reduced to the question:
“Was the customer's email account hacked?”
The court must examine the entire contractual and factual relationship.
20. Cyber Evidence and Chain of Custody
For serious cyber disputes, evidence preservation is critical.
A proper investigation should ideally record:
- date and time of collection;
- identity of person collecting the evidence;
- device or system from which evidence was obtained;
- method of acquisition;
- forensic imaging procedure;
- hash values where appropriate;
- storage location;
- persons who accessed the evidence;
- subsequent transfers; and
- expert methodology.
Graciela v Giacobbe demonstrates why these matters can become central when parties dispute the reliability of forensic evidence. The Court considered event logs, forensic images, system information and allegations concerning the handling of digital evidence.
21. Cybersecurity and Personal Data
Cyber law also intersects with privacy and personal-data protection.
The UAE's federal cyber-law framework expressly includes the Personal Data Protection Law alongside the Cybercrimes Law and Electronic Transactions and Trust Services Law.
A cyber incident involving personal information may therefore produce multiple legal questions:
| Issue | Possible legal concern |
|---|---|
| Unauthorised access | Cybercrime |
| Personal information exposure | Data protection |
| Employee misuse | Employment/confidentiality liability |
| Customer loss | Civil damages |
| Fraudulent payment | Banking/contract liability |
| Disclosure to third parties | Privacy/confidentiality |
| Cross-border transfer | Data-transfer and jurisdiction issues |
| Litigation evidence | Evidence and procedural law |
22. Cyber Law and Contract Law
Contracts are particularly important in cyber disputes.
A technology contract may contain obligations concerning:
- cybersecurity standards;
- access controls;
- confidentiality;
- incident notification;
- backup;
- disaster recovery;
- data ownership;
- data processing;
- audit rights;
- encryption;
- service availability; and
- indemnification.
If one party fails to comply, the resulting dispute may be primarily contractual, even though the underlying incident was cyber-related.
23. Cyber Law and Tort/Delict
A cyberattack can also constitute an independent civil wrong.
For example:
Hacker → unauthorised access → destruction of data → business interruption → financial loss
The victim may seek compensation under the applicable civil-law rules.
Graciela is a particularly useful illustration because the DIFC Court treated deliberate interference with the company's IT system as a civil wrong and awarded compensation for resulting losses.
24. Jurisdictional Problems
Cyber disputes create difficult jurisdictional questions.
For example:
A company operates in Dubai, its cloud server is located in Europe, the attacker is in another country, and the stolen money is transferred through an Asian bank.
Potential issues include:
- which court has jurisdiction;
- which law applies;
- where the damage occurred;
- whether evidence can be obtained abroad;
- whether foreign judgments can be enforced;
- whether emergency relief is available;
- whether data can legally be transferred across borders.
The Levent & Lexie case illustrates the importance of judicial cooperation where evidence or witnesses are located in another jurisdiction.
25. DIFC and Federal UAE Law — Important Distinction
A major examination point is that DIFC law is not identical to federal UAE law.
Federal UAE courts
Generally apply:
- federal legislation;
- UAE civil and commercial legislation;
- Federal Evidence Law;
- Federal Cybercrimes Law;
- applicable federal regulatory legislation.
DIFC Courts
Operate under:
- DIFC legislation;
- DIFC Court Law;
- Rules of the DIFC Courts;
- applicable DIFC commercial and civil laws.
Therefore, the DIFC cases above are highly useful UAE-based persuasive/illustrative authorities, but they should not be described as automatically binding federal UAE precedents.
26. Relationship Between Cybercrime and Civil Litigation
The same incident may produce two proceedings.
Criminal proceeding
State v Cyber offender
Question:
Did the accused commit a cybercrime?
Civil proceeding
Victim v offender/bank/service provider
Question:
Who is legally responsible for the victim's financial or other loss?
The outcomes may interact, but the legal questions and standards applicable to the proceedings are not necessarily identical.
27. Practical Example
Suppose a Dubai company suffers a phishing attack.
An attacker obtains an employee's credentials and enters the company's email system.
The attacker then sends a fake payment instruction for AED 2 million.
The bank transfers the money.
Possible legal issues
1. Cybercrime
Unauthorised access and fraudulent electronic activity may fall within the Cybercrimes Law.
2. Banking law
Was the payment instruction actually authorised?
3. Contract
What did the bank-customer agreement require?
4. Data protection
Was personal or confidential information compromised?
5. Evidence
Can investigators establish:
- login times;
- IP addresses;
- device information;
- emails;
- authentication records;
- transaction records?
6. Civil damages
Who caused the loss and what portion is recoverable?
7. Asset recovery
Can the AED 2 million be traced and recovered?
The Aegis case provides a useful real-world illustration of this type of analysis.
28. Major Challenges in UAE Cyber Law
1. Rapid technological development
Law must address technologies that develop faster than legislation.
2. Anonymous attackers
Attackers may conceal identity through:
- VPNs;
- compromised devices;
- proxy systems;
- multiple jurisdictions; and
- cryptocurrency.
3. Cross-border evidence
Relevant evidence may be outside UAE territory.
4. Cloud computing
Data may be distributed among several countries and service providers.
5. Attribution
Identifying the person responsible is often more difficult than proving that an attack occurred.
6. Digital evidence integrity
Electronic evidence can potentially be altered, deleted or incompletely preserved.
7. Multiple legal regimes
Federal law, emirate-level legislation, DIFC/ADGM regimes and sector-specific rules can overlap.
8. Allocation of cyber risk
Banks, businesses, employees, customers and technology providers may each have different contractual responsibilities.
29. Key Principles
| Principle | Explanation |
|---|---|
| Digital conduct can create civil liability | Cyber wrongdoing may produce damages claims |
| Electronic documents have legal recognition | Electronic form does not automatically invalidate evidence |
| Authentication matters | Courts need to determine who created or sent digital material |
| Integrity matters | Evidence should be protected against alteration |
| Attribution matters | Technical connection must be linked to the relevant person |
| Cyber fraud can become a banking dispute | Liability depends on mandates and circumstances |
| Electronic discovery is important | Emails, databases and communications may be discoverable |
| Criminal and civil liability differ | A cybercrime prosecution and civil claim address different questions |
| Cross-border cooperation is important | Cyber evidence frequently crosses national boundaries |
| DIFC and federal law must be distinguished | DIFC authorities are not automatically federal UAE precedents |
30. Conclusion
UAE cyber law fundamentals are based on the interaction of criminal law, civil liability, electronic transactions, evidence, privacy and regulatory law.
The central legal framework is the Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes, supplemented by the Electronic Transactions and Trust Services Law, Personal Data Protection Law, and Federal Evidence Law.
From a civil-law perspective, the most important lesson is that a cyber incident is not merely a technological event. It can become a dispute concerning:
wrongful conduct → contractual duties → electronic evidence → attribution → causation → loss → damages → recovery.
The cases such as Graciela, Aegis Resources, Taaleem, AES, Anoop Kumar Lal, Gjurd, Levent & Lexie, and Kitopi demonstrate how UAE/DIFC courts have approached different parts of this chain, particularly cyber fraud, IT-system interference, electronic evidence, document production, confidentiality and cross-border evidence.
In short: UAE cyber law protects information systems and digital activity through criminal prohibitions, while civil law provides mechanisms for determining responsibility, proving digital wrongdoing and recovering legally recognised losses.

comments