Civil Law And Uae Data Breach Liability Assessment .
Civil Law and UAE Data Breach Liability Assessment
1. Introduction
Data breach liability arises when personal, confidential, financial, commercial, or other protected information is accessed, disclosed, altered, destroyed, lost, or otherwise processed without proper authority or adequate protection.
In UAE civil-law analysis, a data breach should not be treated as merely a cybersecurity problem. It can potentially create several overlapping forms of liability, including:
- breach of statutory data-protection obligations;
- breach of contract;
- breach of confidentiality;
- negligence or wrongful interference;
- employment-related liability;
- financial loss;
- business interruption;
- loss caused by misuse of confidential information;
- regulatory consequences; and
- claims for compensation or other civil remedies.
The UAE framework is particularly important because the Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data establishes the federal personal-data framework, while DIFC has a separate DIFC Data Protection Law No. 5 of 2020. The DIFC Courts' Part 58 expressly covers claims under the DIFC Data Protection Law and disputes involving digital data, cloud data, cybersecurity, AI and related technology.
A crucial distinction is therefore:
A cybersecurity incident does not automatically establish civil damages. The claimant must connect the breach to a legally recognised injury and establish the amount of recoverable loss.
2. What Is a Data Breach?
A data breach can involve:
- unauthorised access;
- unauthorised disclosure;
- accidental disclosure;
- loss of personal data;
- theft of credentials;
- hacking;
- ransomware;
- insider misuse;
- unauthorised copying;
- destruction or alteration of information;
- disclosure of confidential business information; or
- compromise of databases or cloud systems.
Example
A UAE company maintains a database containing:
- customer names;
- Emirates ID information;
- telephone numbers;
- email addresses;
- financial information.
A hacker obtains the database.
The legal assessment then involves several separate questions:
Was there unauthorised access?
↓
Was protected information involved?
↓
Did the organisation breach an applicable duty?
↓
Was the breach caused by inadequate security or another legally relevant act?
↓
Did the affected person suffer actionable loss?
↓
What compensation or other remedy is legally available?
3. UAE Legal Framework
A. Federal Personal Data Protection Law
Federal Decree-Law No. 45 of 2021 establishes the UAE's federal personal-data protection framework.
The legislation regulates matters including:
- processing of personal data;
- consent;
- data-subject rights;
- security measures;
- confidentiality;
- cross-border transfers;
- controllers and processors; and
- protection against unauthorised processing.
For a data-breach liability assessment, the statutory duties should be examined together with the underlying contractual and civil obligations.
4. DIFC Data Protection Framework
The DIFC operates under its own data-protection regime.
The DIFC Data Protection Law No. 5 of 2020 is particularly important in DIFC disputes.
DIFC Courts' Part 58 expressly includes claims under the DIFC Data Protection Law and disputes involving:
- substantial or complex databases;
- digitally stored data;
- cloud platforms;
- AI;
- blockchain;
- cybersecurity;
- digital assets;
- digital signatures;
- software and IT systems; and
- cyber-physical systems.
Thus, DIFC provides a particularly developed judicial environment for analysing data-breach disputes.
5. The Data Breach Liability Assessment Model
A useful legal framework is:
Stage 1 — Identify the data
What information was compromised?
Stage 2 — Identify the legal duty
Was there:
- statutory duty;
- contractual duty;
- confidentiality obligation;
- fiduciary duty;
- professional duty;
- negligence duty?
Stage 3 — Identify the breach
What exactly went wrong?
Stage 4 — Identify the responsible party
Possible parties include:
- controller;
- processor;
- employer;
- employee;
- IT provider;
- cloud provider;
- bank;
- cybersecurity provider;
- contractor.
Stage 5 — Establish causation
Did the breach actually cause the claimed loss?
Stage 6 — Establish actionable damage
Was there legally recognised injury?
Stage 7 — Quantify the loss
How much compensation is justified?
Stage 8 — Consider defences and reductions
For example:
- claimant's own conduct;
- mitigation;
- contractual limitations;
- lack of causation;
- lack of proof;
- contributory conduct.
6. Liability Is Different from Damages
This distinction is extremely important.
Suppose a company technically violates a security obligation.
That does not automatically mean:
Breach = AED 10 million damages.
The claimant may still have to establish:
Duty → breach → causation → actionable loss → quantification
The DIFC Court made this point particularly clearly in Faizal Babu Moorkath v Expresso Telecom Group Ltd [2023] DIFC CFI 008. The Court stated that actionable loss is fundamental: without legally recognised loss, the existence of allegedly wrongful conduct does not by itself establish a damages claim.
7. Case Law 1 — Graciela Limited v Giacobbe [2014] DIFC CFI 027
This is one of the most important UAE/DIFC authorities for cyber-related civil liability.
A former employee was found responsible for deliberately interfering with and sabotaging the claimant's IT system.
The claimant claimed losses associated with:
- restoration of the IT system;
- investigation;
- network rebuilding;
- emergency servers;
- contractors;
- employee time.
The court awarded:
USD 690,533
The court treated the IT system as property capable of wrongful interference and held that the defendant's conduct created liability under the DIFC Law of Obligations.
Importance for data breaches
Graciela demonstrates that a cyber incident can generate conventional civil damages.
Key principle
Cybersecurity misconduct can produce ordinary civil liability where the claimant establishes wrongful interference and resulting loss.
It is especially useful for calculating:
- forensic investigation costs;
- system restoration;
- emergency IT expenditure;
- employee time;
- business disruption.
8. Case Law 2 — Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
This is an important email-compromise and cyber-fraud case.
A fraudster hacked the customer's email system and sent payment instructions to the bank.
The bank paid money to the fraudster.
The central question was:
Who should bear the loss caused by the compromised email system?
The DIFC Court described the case as an emerging cyber-fraud dispute and concluded, on the particular facts, that the loss fell upon the bank and that the customer recovered some consequential loss.
The case also considered the security of the customer's email system, including matters such as:
- two-factor authentication;
- unusual-access notifications;
- managed email systems;
- cybersecurity providers;
- allocation of security responsibilities.
Importance
Aegis shows that data/cyber liability cannot be determined merely by asking:
"Whose system was hacked?"
The court may need to examine:
- contractual duties;
- security arrangements;
- authentication procedures;
- banking procedures;
- causation;
- reasonable security expectations.
9. Case Law 3 — TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006
This case involved misuse of confidential information rather than a conventional external hacking incident.
The defendant breached:
- a confidentiality agreement; and
- statutory obligations concerning confidential information.
The DIFC Court of Appeal upheld damages of:
AED 250,000
The court explained that the loss consisted of the value of the restriction against using the confidential information. Because the precise monetary value of that loss could not be calculated with sufficient certainty, the court could assess damages using its statutory discretion.
Importance for data breach cases
Data breaches frequently involve information whose value cannot easily be measured.
For example:
- customer databases;
- proprietary algorithms;
- confidential medical information;
- investment information;
- commercial strategies.
The case therefore provides an important methodology where confidential information has clearly been misused but its exact economic value is difficult to calculate.
10. Case Law 4 — AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd [2023] DIFC CFI 060
This case concerned alleged misuse of confidential information involving client information and financial data.
The court considered:
- client lists;
- customer information;
- assets under management;
- fees;
- confidential business information;
- employment confidentiality obligations;
- alleged client solicitation.
The court ultimately found that several alleged confidentiality breaches had not been proved.
Importantly, the court analysed whether information was genuinely confidential rather than assuming that every piece of customer information automatically receives confidentiality protection.
Importance
The case demonstrates:
Not every database field is automatically legally protected confidential information.
Factors can include:
- how the information was obtained;
- whether it was treated as confidential;
- whether it was publicly available;
- whether it had commercial value;
- whether it was sufficiently specific.
This is directly relevant to data-breach assessment.
11. Case Law 5 — Faizal Babu Moorkath v Expresso Telecom Group Ltd [2023] DIFC CFI 008
The DIFC Court examined the concept of actionable loss.
The Court explained that a claimant must establish a loss, injury or damage recognised by law. A wrongful act without actionable damage does not automatically create a compensable tort claim.
Application to data breaches
Suppose:
- 100,000 records are accessed;
- but there is no evidence of misuse;
- no financial loss is demonstrated;
- no legally recognised injury is established.
The existence of the security incident alone may not determine the amount of civil compensation.
Principle
Data compromise and compensable damage are related but legally distinct questions.
12. Case Law 6 — Haya Spa LLC v Harper Real Estate / Hasan Real Estate [2016] DIFC SCT 150
Although not a pure cybersecurity case, Haya Spa provides an important damages methodology.
The DIFC framework considered:
- certainty of loss;
- future loss;
- loss of opportunity;
- foreseeability;
- mitigation;
- judicial assessment.
The court recognised that where the amount cannot be established with sufficient certainty, the court may assess the damages itself.
Application to data breaches
Suppose a company claims:
"The breach damaged our reputation and caused AED 5 million of future customer losses."
The court may ask:
- How many customers actually left?
- Which customers left because of the breach?
- What revenue would those customers have generated?
- Were there other causes?
- Was the claimed future loss reasonably foreseeable?
- Can the amount be established with reasonable certainty?
Haya Spa therefore provides a useful framework for analysing uncertain data-breach losses.
13. Case Law 7 — Globemed Gulf Healthcare Solutions LLC v Oman Insurance Company PSC [2017] DIFC CFI 051
Globemed is useful for understanding sophisticated damages analysis.
The DIFC Court explained that UAE law does not prescribe one universal mathematical formula for assessing every type of injury. The court determines compensation after establishing the relevant injury and its causal relationship with the wrong.
The court distinguished:
- an actual future injury; and
- a merely potential future injury.
An alleged future loss must have an adequate factual basis rather than being purely speculative.
Application to data breaches
A claimant might say:
"Our company will lose AED 20 million in customers over the next five years because of the breach."
An expert valuation cannot automatically transform that prediction into recoverable damages.
The claimant should establish:
- customer behaviour;
- historical churn;
- actual cancellations;
- financial impact;
- causal connection;
- future probability.
14. Case Law 8 — Gate Mena DMCC v Tabarak Investment Capital Ltd
This case involved cryptocurrency and alleged loss of digital assets.
The DIFC proceedings considered claims relating to:
- Bitcoin;
- negligence;
- breach of confidence;
- bailment;
- fiduciary duties;
- regulatory obligations.
The court ultimately rejected the relevant claims against Tabarak on the evidence and found no liability for the loss of the 300 BTC on the causes advanced.
Importance
Gate Mena illustrates that digital assets and digital information can produce complicated liability questions involving:
- custody;
- security;
- control;
- reasonable care;
- fiduciary responsibility;
- regulatory obligations.
It is therefore useful when a data breach involves digital assets or systems rather than only personal information.
15. Case Law 9 — Larmag Holding B.V. v First Abu Dhabi Bank PJSC [2019] DIFC CFI 054
Larmag demonstrates the importance of distinguishing:
- substantive liability;
- applicable UAE law;
- procedural rules;
- remedies.
The case involved allegations concerning breaches of UAE law and the relationship between the governing cause of action and the remedies available in DIFC proceedings.
Importance
A data-breach claim in a DIFC proceeding may involve multiple legal regimes.
The lawyer must therefore ask:
Which law establishes the underlying right, and which law governs the remedy?
16. Data Breach Liability Matrix
| Question | Legal issue |
|---|---|
| What information was compromised? | Nature of data |
| Was the information protected? | Personal/confidential/commercial information |
| Who controlled it? | Controller/processor/custodian |
| Who accessed it? | External attacker/employee/vendor |
| Was access authorised? | Consent/authority |
| Was security adequate? | Duty and breach |
| Was notification required? | Data-protection obligations |
| Did misuse occur? | Causation |
| Did claimant suffer loss? | Actionable damage |
| How much? | Quantum |
| Could loss be avoided? | Mitigation |
| Is future loss certain? | Certainty |
| Was it foreseeable? | Remoteness |
| Are there multiple causes? | Causation allocation |
| Is information confidential? | Confidentiality law |
| Which court has jurisdiction? | UAE/DIFC/ADGM/foreign jurisdiction |
17. Categories of Data-Breach Damage
A. Direct Technical Costs
Examples:
- forensic investigation;
- malware removal;
- database reconstruction;
- system restoration;
- emergency cybersecurity services;
- replacement servers;
- security upgrades.
Graciela is particularly useful here because the court awarded substantial IT restoration and investigation costs.
18. Business Interruption Loss
Suppose:
- Normal daily profit = AED 50,000
- System unavailable for 20 days.
Basic calculation:
AED 50,000 × 20 = AED 1,000,000
But the claimant must consider:
- costs saved during downtime;
- alternative operations;
- insurance recovery;
- actual rather than theoretical profit;
- other causes of the interruption.
Potential loss therefore requires evidence.
19. Personal Financial Loss
A data breach may produce financial consequences for individuals.
For example:
- fraudulent transactions;
- unauthorised withdrawals;
- identity-related expenses;
- account recovery costs.
The claimant must connect the financial loss to the data incident.
20. Reputation Loss
Reputational damage is particularly difficult to quantify.
A company might claim:
"Our reputation declined by AED 10 million."
The court may require evidence such as:
- customer departures;
- reduced sales;
- cancelled contracts;
- measurable price reductions;
- lost opportunities;
- market evidence.
A bare assertion of reputational damage is not equivalent to proof of AED 10 million loss.
21. Loss of Confidential Information
Confidential information may have value even if it is difficult to measure.
For example:
- customer database;
- pricing information;
- investment strategy;
- proprietary software;
- business plans.
TVM Capital v Hashemi is particularly important because the court accepted that the value of a confidentiality restriction could be legally compensable even where the exact monetary amount could not be calculated precisely.
22. Data Breach by Employee
An employee may:
- copy customer data;
- download confidential files;
- send databases to a personal email;
- transfer data to a competitor;
- disclose personal information.
The legal assessment may involve:
- employment contract;
- confidentiality obligations;
- statutory data-protection duties;
- fiduciary obligations;
- employer responsibility;
- causation;
- damages.
AES and TVM Capital provide useful DIFC authorities on confidential information and employee-related obligations.
23. Data Breach Through a Vendor
Suppose a UAE company outsources cloud storage to a vendor.
The vendor suffers a cyberattack.
The legal assessment should consider:
- outsourcing contract;
- security requirements;
- audit obligations;
- processor/controller responsibilities;
- incident-reporting provisions;
- indemnity;
- limitation of liability;
- causation;
- insurance.
A company cannot simply assume:
"The vendor was hacked, therefore the vendor automatically owes all losses."
The contractual and statutory relationship must be examined.
24. Causation in Data Breach Claims
Causation is often the most difficult issue.
Example
A company experiences a data breach in January.
Sales decline by AED 5 million in February.
The company claims:
"The entire AED 5 million was caused by the breach."
But alternative causes may include:
- market downturn;
- competitor activity;
- product problems;
- pricing changes;
- economic conditions.
The claimant must establish the legally relevant causal connection.
25. Data Breach Damages Calculation Exercise
Assume:
Forensic investigation
AED 300,000
System restoration
AED 500,000
Emergency cybersecurity services
AED 200,000
Lost operating profit
AED 1,500,000
Customer remediation
AED 300,000
Avoided operating expenses
AED 200,000
Initial calculation:
300,000+500,000+200,000+1,500,000+300,000300,000+500,000+200,000+1,500,000+300,000
= AED 2,800,000
Deduct avoided expenses:
2,800,000−200,0002,800,000-200,000
= AED 2,600,000
Indicative damages
AED 2.6 million
This remains an illustrative calculation. The claimant must establish the legal recoverability and causation of every component.
26. Future Data-Breach Loss
Suppose a company claims:
- AED 1 million annual lost profit;
- five years of expected losses.
Simple calculation:
AED 1m × 5 = AED 5m
But the court may need to examine:
- customer retention;
- market conditions;
- probability;
- mitigation;
- alternative suppliers;
- recovery of reputation;
- discounting;
- uncertainty.
Therefore, AED 5 million is only the starting model.
The reasoning in Globemed and Haya Spa is relevant to the assessment of future and uncertain losses.
27. Data Breach and Loss of Chance
Suppose a company had a 40% probability of winning a contract worth AED 4 million.
Expected value:
AED4,000,000×40%AED4,000,000\times40\%
= AED 1,600,000
Potential loss-of-chance value:
AED 1.6 million
But evidence must support the 40% probability.
The DIFC damages framework expressly recognises compensation for loss of opportunity according to its probability.
28. Mitigation
A claimant suffering a data breach may need to take reasonable steps such as:
- changing credentials;
- isolating affected servers;
- notifying customers where legally required;
- restoring systems;
- blocking compromised accounts;
- engaging forensic experts;
- implementing security controls.
Reasonable mitigation costs may themselves form part of the loss.
But avoidable losses may not be fully recoverable.
29. Insurance and Double Recovery
Suppose:
- Total proven data-breach loss = AED 5 million.
- Cyber insurance pays AED 2 million.
The damages analysis must account for the insurance arrangement and applicable law.
The claimant cannot simply ignore other compensation and obtain duplicative recovery for the same loss.
The central principle is:
Compensation should correspond to the legally established injury rather than produce an unjustified financial windfall.
30. Evidence Required in a Data-Breach Claim
A strong claim may require:
Technical evidence
- forensic images;
- system logs;
- access logs;
- authentication records;
- IP addresses;
- firewall records;
- endpoint logs;
- malware analysis;
- database records.
Financial evidence
- invoices;
- bank records;
- accounting records;
- revenue reports;
- customer-loss analysis;
- profit calculations.
Legal evidence
- privacy notices;
- consent records;
- contracts;
- data-processing agreements;
- confidentiality clauses;
- security policies.
Organisational evidence
- incident-response procedures;
- employee training;
- access-control policies;
- cybersecurity audits;
- vendor assessments.
Graciela demonstrates the importance of detailed forensic evidence when establishing responsibility for a cyber incident.
31. Standard of Proof
A claimant generally must establish the relevant facts according to the applicable civil standard.
In Graciela, the court dealt with serious allegations concerning deliberate IT sabotage and relied upon strong circumstantial evidence, including the defendant's knowledge of the system and technical circumstances surrounding the attack.
The case demonstrates an important point:
A data breach can be proved through a combination of technical, documentary and circumstantial evidence.
32. Advanced Liability Model
A sophisticated UAE data-breach assessment can be represented as:
Data Event
↓
Protected Information
↓
Legal Duty
↓
Security/Processing Failure
↓
Breach
↓
Causal Connection
↓
Actual or Future Actionable Loss
↓
Quantum
↓
Mitigation / Avoided Loss
↓
Other Compensation
↓
Final Recoverable Damages
33. Case-Law Comparison
| Case | Main relevance |
|---|---|
| Graciela v Giacobbe [2014] | Cyberattack, IT interference and restoration damages |
| Aegis Resources v Union Bank [2020] | Email compromise and allocation of cyber-fraud loss |
| TVM Capital v Hashemi [2014] | Confidential information and difficult-to-quantify damages |
| AES v GSB Capital [2023] | Confidential client data and proof of misuse |
| Faizal Babu Moorkath v Expresso [2023] | Actionable loss and causation |
| Haya Spa v Harper/Hasan [2016] | Certainty, foreseeability, loss of opportunity and mitigation |
| Globemed v Oman Insurance [2017] | Actual versus merely potential future loss |
| Gate Mena v Tabarak | Digital assets, custody, negligence and cyber-related liability |
| Larmag v First Abu Dhabi Bank [2019] | UAE law, DIFC jurisdiction and remedies |
34. Important Distinction: Onshore UAE vs DIFC
This distinction should always appear in a legal research answer.
Onshore UAE
The principal federal personal-data framework is Federal Decree-Law No. 45 of 2021, supplemented by other federal legislation depending on the facts.
DIFC
DIFC has its own Data Protection Law and its own civil-law framework.
ADGM
ADGM operates under a separate legal framework.
Therefore:
A DIFC case involving data or confidentiality should not automatically be presented as a binding precedent for every UAE onshore data-breach dispute.
The cases above are especially valuable as UAE-related comparative judicial authorities, with the DIFC decisions directly governing where DIFC law applies.
35. Practical Data-Breach Liability Checklist
When analysing a UAE data-breach dispute, ask:
A. Data
- What information was compromised?
- Was it personal data?
- Was it confidential business information?
- Was it financial information?
B. Duty
- Who controlled the information?
- Was there a contractual duty?
- Was there a statutory duty?
- Was there a confidentiality obligation?
C. Breach
- Was access authorised?
- Were reasonable security measures adopted?
- Was there an employee or vendor failure?
- Was there an external cyberattack?
D. Causation
- Did the breach cause the claimed injury?
- Are there alternative causes?
E. Damage
- What actual financial loss occurred?
- What future loss is sufficiently established?
- Was confidential information commercially valuable?
F. Quantum
- What is the repair cost?
- What is the business interruption loss?
- What profits were actually lost?
- What expenses were avoided?
- What losses were mitigated?
G. Procedure
- Which court has jurisdiction?
- Which law governs?
- What evidence is available?
- Are expert witnesses necessary?
36. Conclusion
UAE data-breach liability assessment requires much more than proving that a computer system was hacked. The central legal analysis is:
Protected information → legal duty → breach → causation → actionable damage → quantification → appropriate remedy.
The principal lessons from the case law are:
- Graciela v Giacobbe demonstrates that cyber sabotage can produce substantial civil liability and recovery of reasonable restoration and investigation costs.
- Aegis v Union Bank demonstrates that email compromise requires a fact-specific analysis of security responsibilities, contractual relationships and causation.
- TVM Capital v Hashemi demonstrates that confidential-information loss may be compensable even where exact valuation is difficult.
- AES v GSB Capital shows that not every customer-data element is automatically confidential and that misuse must be proved.
- Faizal Babu Moorkath establishes the importance of proving actionable loss rather than merely wrongful conduct.
- Haya Spa provides a framework for reasonable certainty, foreseeability, loss of opportunity and judicial assessment of difficult-to-quantify damages.
- Globemed is useful for distinguishing actual future injury from speculative potential loss.
- Gate Mena demonstrates the additional complexity created when cybersecurity, custody and digital assets intersect.
The most important practical proposition is therefore:
A data breach establishes an incident; civil liability requires a legally relevant breach of duty; and damages require proof of causally connected, legally recoverable loss.
For a current UAE analysis, the federal Personal Data Protection Law, the applicable civil-law regime, and any specialised DIFC/ADGM framework must be considered separately rather than treating all UAE jurisdictions as having identical rules.

comments