Civil Law And Uae Data Ownership And Personal Data Monetisation Disputes .
Civil Law and UAE Data Ownership and Personal Data Monetisation Disputes
1. Introduction
“Data ownership” and “personal-data monetisation” are increasingly important issues in UAE civil law. Businesses collect customer names, contact information, purchasing histories, financial information, location information, behavioural profiles, biometric information and other datasets. Those datasets may have substantial commercial value, but commercial value does not automatically mean that the business owns the individual’s personal data as property.
The UAE legal framework is better understood as a combination of:
personal-data protection rights and obligations under Federal Decree-Law No. 45 of 2021;
civil-law rules concerning property and financial rights;
contractual rights concerning databases, customer lists and confidential information;
intellectual-property and trade-secret protections where applicable;
confidentiality and fiduciary obligations;
tort/civil-liability principles; and
sector-specific regulation, including financial, healthcare and telecommunications regulation.
The current UAE Civil Transactions Law defines “property (Mal)” broadly as a tangible thing or a right having material value in transactions, and recognises that corporeal or incorporeal things capable of lawful possession and enjoyment can be subjects of financial rights. (UAE Legislation) This provides an important conceptual framework, but it does not mean that an individual's personal data automatically becomes an owned commodity capable of unrestricted sale.
The UAE PDPL is particularly important because Article 4 generally prohibits processing personal data without the data subject's consent, subject to specified exceptions, including public interest, publicly available data made available by the data subject, legal claims and judicial/security procedures, and specified healthcare purposes. (UAE Legislation)
2. Meaning of Data Ownership
Data ownership can mean several different things.
A. Ownership of the physical medium
A company may own:
servers;
computers;
databases;
storage systems;
cloud infrastructure; or
documents containing information.
But ownership of the physical medium does not necessarily mean ownership of every item of personal information contained in it.
B. Ownership of a database
A business may have rights in:
the structure of a database;
software used to create it;
proprietary compilation;
customer-management systems;
business analytics; and
confidential commercial information.
These rights can exist independently from the privacy rights of individual data subjects.
C. Rights concerning personal data
A person may have legally protected interests in information relating to them even though another organisation possesses or processes the information.
For example:
A bank may possess a customer's account records, but the bank's possession of those records does not transform the customer's personal information into an unrestricted asset that the bank can sell to anyone.
D. Commercial information
Some information may simultaneously be:
personal data;
confidential information;
trade-secret material;
commercially valuable information; and
part of a company's database.
The legal analysis therefore depends on what the information is, who it relates to, how it was obtained, how it is being used and what legal rights attach to it.
3. UAE PDPL and the Concept of Personal Data
Federal Decree-Law No. 45 of 2021 regulates personal-data processing in the UAE.
The law's basic approach is not “data ownership” in the traditional property-law sense. Instead, it establishes rules concerning:
processing;
consent;
legitimate exceptions;
confidentiality;
security;
data-subject rights;
controllers;
processors;
cross-border transfers;
breach management; and
regulatory supervision.
Article 4 is particularly important because it establishes the general consent principle while identifying circumstances in which processing can occur without consent. (UAE Legislation)
Therefore, a commercial contract saying:
“All customer data belongs exclusively to the company”
does not necessarily eliminate statutory personal-data protections.
4. Personal Data Is Not Automatically a Commodity
One of the most important principles is the distinction between economic value and ownership.
Personal data can have significant economic value without becoming ordinary property.
For example:
a customer's purchasing history may be valuable;
a patient's medical profile may be commercially useful for statistical research;
a consumer's preferences may be valuable to advertisers;
a location dataset may have significant commercial value;
a financial institution's customer database may be commercially valuable.
But the organisation's economic interest does not necessarily give it unrestricted authority to:
sell the data;
disclose it;
transfer it to unrelated third parties;
combine it with other datasets;
use it for a new purpose; or
monetise it indefinitely.
The legality of monetisation must therefore be assessed separately from the commercial value of the information.
5. What Is Personal-Data Monetisation?
Personal-data monetisation occurs where information relating to individuals is used to generate economic value.
Common models include:
5.1 Targeted advertising
A company analyses customer behaviour and sells advertising access based upon customer profiles.
5.2 Data analytics
Personal information is processed to create:
market reports;
consumer predictions;
behavioural models;
risk scores; or
business intelligence.
5.3 Data licensing
A company permits another business to access or use a dataset for a fee.
5.4 Data brokerage
Information is aggregated and supplied to third parties.
5.5 AI training
Personal information may be incorporated into datasets used for:
machine learning;
predictive models;
recommendation systems;
generative AI; or
automated decision-making.
5.6 Platform monetisation
A digital platform may generate revenue from behavioural information generated by its users.
The legal dispute arises when the commercial exploitation exceeds the purpose for which the information was originally collected or violates applicable statutory, contractual or confidentiality obligations.
6. Consent and Monetisation
Consent is particularly important under the UAE PDPL.
Article 4 establishes the general prohibition on processing personal data without consent, subject to listed exceptions. (UAE Legislation)
Consequently, consent questions can arise at several stages:
Collection → Storage → Analysis → Profiling → Sharing → Licensing → Sale → Commercial exploitation
Consent to one activity should not automatically be treated as permission for every subsequent commercial activity.
For example:
A customer gives information to an online retailer to purchase a product.
That does not necessarily establish unrestricted authority to transfer the customer's information to an unrelated advertising company for a different commercial purpose.
7. Data Ownership Dispute Between Employer and Employee
A common UAE dispute concerns whether an employee can take or commercially exploit:
customer lists;
contact databases;
CRM records;
client preferences;
transaction histories;
pricing data;
customer financial information; or
personal information collected during employment.
The employer may argue that the database is company property.
The employee may argue that certain information consists of:
personal knowledge;
publicly available information;
professional contacts; or
information lawfully remembered by the employee.
The court must therefore determine whether the information is genuinely proprietary or confidential.
8. Case Law
There is an important limitation: published UAE onshore judgments directly deciding whether personal data itself is “owned” and freely monetisable under Federal Decree-Law No. 45 of 2021 remain limited. Accordingly, the following cases include UAE/DIFC authorities dealing with personal data, confidentiality, commercial databases, cyber misuse and information-related damages. DIFC decisions should not be treated as binding precedents for the federal UAE PDPL, but they provide useful persuasive and comparative guidance.
Case 1: DFSA v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051/085
This is one of the most relevant DIFC data-protection decisions.
The case concerned an appeal involving the DIFC Data Protection Law and a subject-access request.
The court considered whether information retrieved through a computer search against an individual's name or identifier automatically constituted that person's personal data.
The court rejected an excessively broad approach. It explained that mere mention of an individual in a document does not necessarily make all information in that document the individual's personal data; the relevance and connection of the information to the individual must be examined. (DIFC Courts)
Importance
The case is significant for UAE data disputes because it demonstrates that:
not every piece of information mentioning a person is necessarily personal data;
context matters;
relevance matters;
privacy interests must be examined; and
data protection analysis cannot simply be reduced to ownership.
Application to monetisation
A company attempting to monetise a large database cannot simply argue:
“The database belongs to us, therefore everything inside it is ours to commercially exploit.”
The nature and legal status of each category of information must be considered.
Case 2: TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006
This is particularly important for commercial valuation of information.
The defendant had breached confidentiality obligations concerning information supplied by TVM Capital.
The DIFC Court of Appeal upheld an award of AED 250,000.
The court recognised that confidential information can have economic value even where precise loss cannot be mathematically established. Where damages cannot be established with sufficient certainty, the court may assess them using its discretion. (DIFC Courts)
Principle
The case demonstrates an important distinction:
Information does not have to be conventional physical property to have compensable economic value.
Relevance to personal-data monetisation
Suppose a business unlawfully commercialises a valuable dataset.
The claimant may have difficulty demonstrating:
“Exactly AED X was lost from each individual record.”
TVM Capital demonstrates how a court can approach the economic value of information and misuse where conventional loss calculation is difficult.
However, this does not mean that personal data automatically belongs to the claimant as property.
Case 3: AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060
This case is highly relevant to customer databases and confidential client information.
The DIFC Court considered whether information such as:
client lists;
contact details;
fees;
assets under management;
investment strategies;
risk profiles; and
other sensitive client information
could constitute confidential information.
The court emphasised that whether information is confidential depends on matters including:
how it was obtained;
how it was treated;
whether it was publicly accessible; and
whether it possessed the necessary quality of confidence. (DIFC Courts)
The court also identified the essential elements of a confidentiality claim, including receipt of specific information, confidentiality, knowledge or constructive knowledge of confidentiality, and misuse.
Importance
This is particularly relevant to UAE businesses operating:
CRM systems;
fintech platforms;
insurance businesses;
investment businesses;
e-commerce platforms; and
customer analytics businesses.
Monetisation example
If an employee downloads a database containing:
customer names + financial profiles + investment preferences + AUM + contact details
and transfers it to a competitor, the dispute is not simply one of “data ownership.”
It may involve:
confidentiality;
contractual obligations;
trade secrets;
personal-data protection;
fiduciary duties; and
civil damages.
Case 4: Graciela Limited v Giacobbe [2014] DIFC CFI 027
This case demonstrates the economic consequences of unlawful interference with information systems.
A former IT employee was found responsible for an internal cyberattack against his former employer.
The DIFC Court awarded USD 690,533 in compensatory damages, including costs associated with:
system restoration;
investigation;
emergency servers;
rebuilding systems; and
employee time spent responding to the attack.
The court accepted evidence concerning employee diversion and resulting business disruption. (DIFC Courts)
Relevance to data monetisation disputes
Suppose a company discovers that a former employee has:
copied a customer database;
transferred it to a competitor;
deleted the original database; and
disrupted the company's systems.
The claim could potentially include different categories of loss rather than merely the nominal value of the data.
Possible heads include:
investigation costs;
restoration costs;
forensic expenses;
lost business;
business interruption;
remediation costs; and
other legally recoverable losses.
Case 5: Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004
Aegis concerned cyber fraud involving compromised email communications and fraudulent payment instructions.
The DIFC Court held that responsibility for the loss depended upon the circumstances and concluded on the facts that the loss fell upon the bank, with consequential loss also recoverable in part. (DIFC Courts)
The subsequent order awarded damages and interest, including USD 84,580.52 in damages and USD 16,480.30 in interest. (DIFC Courts)
Relevance
The case illustrates an important principle for data-related disputes:
Possession or control of information does not by itself determine legal responsibility.
The court must investigate:
who controlled the information system;
who had security obligations;
who knew or should have known of the risk;
whether reasonable security procedures existed;
whether the loss was foreseeable; and
whether the claimant contributed to the loss.
This is directly relevant to personal-data monetisation disputes involving compromised customer accounts or databases.
Case 6: Nevon v Nader [2024] DIFC SCT 158
This case involved allegations concerning:
mishandling personal information;
discussion of sensitive account information with unauthorised parties;
deletion of company data;
deletion of WhatsApp communications; and
wiping of a work phone.
The factual allegations demonstrate how personal-data handling can become intertwined with employment, confidentiality and civil disputes. (DIFC Courts)
Importance
The case demonstrates the practical importance of:
employee access controls;
data-retention policies;
confidentiality obligations;
company devices;
messaging applications; and
preservation of electronic evidence.
For personal-data monetisation litigation, electronic evidence may establish:
who accessed the information → what information was accessed → when it was copied → where it was transferred → who received it → whether it was commercially exploited.
Case 7: Heitor v Helah [2017] DIFC SCT 141
This case involved allegations of disclosure of confidential and proprietary information and referred to fiduciary duties and the DIFC Law of Obligations.
The claimant relied upon the damages framework under the DIFC Law of Damages and Remedies, under which compensation seeks to place the injured party in the position it would have occupied had the wrong not occurred. (DIFC Courts)
Relevance
The case supports the broader proposition that information-related wrongdoing can produce a compensatory civil claim even where the dispute does not involve conventional physical property.
This is particularly useful in disputes involving:
employee misuse;
confidential databases;
customer information;
proprietary business information; and
fiduciary obligations.
9. Data Ownership Versus Confidentiality
The distinction can be represented as follows:
| Issue | Data ownership | Confidentiality |
|---|---|---|
| Main question | Who has legal rights in the information? | Was information legally protected against disclosure/use? |
| Typical subject | Database/property | Customer lists, trade secrets |
| Requirement | Legal proprietary interest | Quality of confidence |
| Public information | Generally difficult to monopolise | Usually weak protection |
| Personal data | Subject to PDPL | May also be confidential |
| Employee information | Contract may allocate rights | Employment obligations may restrict use |
| Commercial exploitation | Requires lawful basis | Unauthorised use may create liability |
| Damages | Depends on applicable cause of action | Can include information-related loss |
10. Can a UAE Company Sell Personal Data?
The answer cannot simply be yes or no.
The legality depends upon:
the nature of the information;
whether it is personal data;
the purpose for which it was collected;
the legal basis for processing;
the consent obtained;
contractual arrangements;
applicable sectoral regulation;
disclosure to third parties;
cross-border transfer issues;
security measures; and
whether the monetisation is compatible with applicable law.
Article 4 of the federal PDPL is therefore fundamental because it establishes the consent requirement while identifying statutory exceptions. (UAE Legislation)
11. Data Monetisation Through Anonymisation
An important distinction exists between personal data and genuinely anonymised information.
For example:
Dataset A
“Ahmed, age 38, Dubai, salary AED X, diabetic, purchased product Y.”
This clearly raises personal-data concerns.
Dataset B
“38-year-old consumers in a particular market showed a 17% preference for product Y.”
The second dataset may be significantly less connected to identifiable individuals.
However, the legal analysis should examine whether the data has genuinely been anonymised or whether individuals can still reasonably be re-identified.
A business should therefore not simply replace names with customer numbers and automatically assume that the information is no longer personal data.
12. Pseudonymisation Is Not the Same as Anonymisation
This distinction is particularly important in UAE compliance.
Pseudonymisation
The identifying information is replaced by another identifier, but re-identification remains possible.
Example:
Customer 78291 → actual identity stored separately.
Anonymisation
The information is transformed so that identification is no longer reasonably possible.
Therefore:
Removing a person's name does not necessarily remove personal-data obligations.
13. Personal Data + Intellectual Property
A database may contain several overlapping legal interests.
For example:
Company database
software → intellectual-property rights;
database structure → proprietary rights;
customer list → potentially confidential information;
customer names → personal data;
transaction records → personal/financial data;
analytics model → intellectual property/trade secret;
customer preferences → potentially personal and commercially valuable information.
Therefore, one dataset can simultaneously attract several different legal regimes.
14. Contractual Data Ownership Clauses
Commercial contracts increasingly contain clauses such as:
“All data generated through the platform shall belong exclusively to the company.”
Such clauses should be drafted carefully.
A stronger contractual structure distinguishes:
Company-owned material
software;
database architecture;
proprietary analytics;
algorithms;
business methodologies.
Customer rights
information relating to the customer;
statutory data-protection rights;
confidentiality rights;
access/correction rights where applicable.
Licensed information
The customer may grant the business limited rights to:
process;
store;
analyse;
transmit; or
use information for specified purposes.
This is usually more precise than treating every item of information as company property.
15. Employee Data Monetisation
A particularly serious dispute occurs where an employee sells customer information to a competitor.
For example:
Company A
→ employee downloads 100,000 customer records
→ employee sends records to Company B
→ Company B uses them for targeted marketing
→ Company A discovers the transfer.
Potential causes of action may include:
breach of employment contract;
breach of confidentiality;
misuse of confidential information;
civil damages;
personal-data violations;
unlawful disclosure;
breach of fiduciary obligations where applicable.
AES is particularly useful here because the DIFC Court considered customer lists and sensitive client information in the context of confidentiality and misuse. (DIFC Courts)
16. Data Monetisation by Artificial Intelligence Companies
AI creates a new category of dispute.
A company may collect:
customer conversations;
transaction information;
location data;
photographs;
voice recordings;
behavioural information;
and use that information to train AI models.
The legal question becomes:
Does permission to process the information for providing the original service also permit its use for AI training and commercial model development?
The answer depends on the applicable legal basis, purpose, contractual terms, data-protection requirements and nature of the processing.
A company's assertion that:
“We own the database”
does not by itself resolve that question.
17. Data Brokerage Disputes
A data-brokerage dispute can involve three parties:
Data Subject → Data Collector → Data Buyer
For example:
A platform collects customer information.
A third-party analytics company purchases access.
The analytics company creates consumer profiles.
A marketing company purchases those profiles.
The individual objects to the use.
The litigation may then involve:
consent;
purpose limitation;
disclosure;
contractual authority;
confidentiality;
data-security obligations;
causation; and
damages.
The legal responsibility may be distributed between multiple entities rather than resting solely on the original collector.
18. Controllers and Processors
The UAE PDPL framework distinguishes between entities performing different functions in data processing.
A business may therefore need to establish:
Controller
Who determines:
why data is processed;
how it is processed; and
what commercial purpose is pursued?
Processor
Who processes information on behalf of another entity?
This distinction becomes particularly important where:
Company A collects data → Company B analyses it → Company C monetises the resulting dataset.
Contracts should clearly allocate:
security obligations;
permitted processing;
subcontracting;
deletion;
retention;
incident notification;
audit rights;
confidentiality; and
liability.
19. Civil Damages in Data-Monetisation Disputes
Possible losses can include, depending on the applicable cause of action and proof:
A. Direct financial loss
Example:
Company loses a valuable customer contract because confidential customer information was misused.
B. Investigation expenses
Forensic investigation may be necessary to determine:
who accessed the database;
what was copied;
where it went; and
whether information was sold.
Graciela demonstrates that properly supported investigation and restoration costs can form part of compensatory damages in an information-system dispute. (DIFC Courts)
C. Business interruption
A cyberattack or database compromise may interrupt operations.
D. Loss of confidential commercial advantage
A competitor may gain an advantage from unlawfully obtained customer information.
E. Lost profits
These generally require sufficiently persuasive evidence of causation and quantum.
F. Remediation costs
The claimant may need to:
notify affected customers;
rebuild systems;
reset credentials;
implement security controls;
conduct forensic audits.
20. Negotiating Damages and Data
TVM Capital is particularly useful where precise financial loss is difficult.
The court accepted that confidential information could possess economic value even where its precise market value was difficult to establish. (DIFC Courts)
This is potentially important in a personal-data commercialisation dispute because the claimant may argue:
“The defendant commercially exploited information that the claimant had a legally protected interest in controlling.”
But the claimant must still identify an appropriate legal cause of action and establish the applicable elements. The case does not create a general UAE rule that every personal-data misuse automatically produces a property-based damages award.
21. Regulatory Penalty Versus Civil Compensation
Another important distinction is:
Regulatory enforcement ≠ private compensation.
A regulator may investigate unlawful processing or impose regulatory consequences.
Separately, an injured person or business may pursue an appropriate civil claim where a recognised cause of action exists.
The DFSA/Data Protection Commissioner case illustrates the regulatory character of data-protection proceedings within the DIFC framework. (DIFC Courts)
Accordingly, a claimant should not automatically assume:
“A PDPL violation = automatic damages of a fixed amount.”
The actual civil remedy depends upon the relevant statutory and civil-law framework and the evidence of loss.
22. Burden of Proof in Data Monetisation Litigation
A claimant should attempt to establish:
Step 1 — Identify the data
Precisely identify:
names;
financial records;
health information;
customer histories;
location records;
behavioural information;
communications.
Step 2 — Establish legal status
Show whether it constitutes:
personal data;
confidential information;
trade-secret material;
contractual information;
proprietary database content.
Step 3 — Establish control
Who collected and controlled it?
Step 4 — Establish misuse
Show:
unauthorised access;
copying;
disclosure;
transfer;
sale;
profiling;
commercial exploitation.
Step 5 — Establish causation
Connect the misuse to:
financial loss;
lost business;
investigation expenses;
reputational consequences where legally recoverable;
remediation;
other compensable harm.
Step 6 — Quantify damages
Use:
accounting evidence;
transaction records;
forensic evidence;
expert valuation;
customer-loss evidence;
licensing-market evidence.
23. Electronic Evidence
Data-monetisation disputes are particularly dependent on electronic evidence.
Important evidence may include:
server logs;
access logs;
database queries;
download records;
cloud audit trails;
email metadata;
WhatsApp records;
USB activity;
API logs;
authentication records;
IP addresses;
device information;
CRM access histories.
Graciela demonstrates the importance of circumstantial and technical evidence in establishing responsibility for an internal IT attack. (DIFC Courts)
Nevon similarly demonstrates the relevance of company communications, data deletion and handling of personal information in employment-related disputes. (DIFC Courts)
24. Jurisdictional Issue: Federal UAE vs DIFC
This distinction is critical.
| Issue | UAE Federal/onshore | DIFC |
|---|---|---|
| Main data law | Federal PDPL | DIFC Data Protection regime |
| Civil law | Federal legislation | DIFC laws |
| Courts | Federal/local UAE courts | DIFC Courts |
| Case precedents | UAE Court of Cassation and local cassation authorities | DIFC judgments |
| Personal-data rules | Federal PDPL | DIFC-specific legislation |
| Confidential information | Federal civil/contract principles | DIFC statutory/common-law influenced principles |
| Data disputes | Depends on subject and jurisdiction | DIFC jurisdiction rules apply |
A DIFC case therefore should not be described as a judgment “under the UAE PDPL.”
It is better described as a persuasive UAE-based information-law authority or a DIFC authority illustrating a related legal principle.
25. Practical Example
Assume a UAE shopping platform has:
2 million customers.
It collects:
names;
telephone numbers;
addresses;
purchasing history;
preferences;
payment-related information.
The platform then sells detailed customer profiles to an advertising company.
A dispute may involve the following questions:
Question 1
Was the information personal data?
Question 2
What legal basis permitted processing?
Question 3
Was the commercial sale within the purpose for which the information was collected?
Question 4
Did the customer consent to the relevant processing?
Question 5
Was the information genuinely anonymised?
Question 6
Did the advertising company receive the information lawfully?
Question 7
Did the contract authorise such use?
Question 8
Was confidential information involved?
Question 9
Did the monetisation cause identifiable loss or legally compensable harm?
Question 10
Which court has jurisdiction?
This demonstrates why “Who owns the data?” is often too simplistic a question.
26. Key Legal Principles From the Cases
The cases collectively support the following propositions:
Personal information must be assessed according to its relationship with the individual, not merely because the individual's name appears somewhere in a database. — DFSA v Commissioner of Data Protection. (DIFC Courts)
Confidential information can have substantial economic value even when its exact value is difficult to calculate. — TVM Capital v Hashemi. (DIFC Courts)
Customer lists and client information can constitute protected confidential information depending on their characteristics and circumstances. — AES v GSB Capital. (DIFC Courts)
Information-system interference can produce substantial compensable economic loss. — Graciela v Giacobbe. (DIFC Courts)
Responsibility for data-related financial loss depends upon the particular allocation of duties and the factual circumstances. — Aegis v Union Bank. (DIFC Courts)
Employee handling and destruction of company information can generate civil and employment disputes. — Nevon v Nader. (DIFC Courts)
Confidentiality and fiduciary obligations can create independent civil remedies concerning information. — Heitor v Helah. (DIFC Courts)
27. Important UAE Civil-Law Position
The strongest way to conceptualise UAE data ownership is therefore:
Personal data should not be treated simply as an ordinary movable asset.
Instead, there can be a bundle of legal interests:
Data subject
→ privacy/data-protection interests
Business
→ contractual and commercial interests
Database creator
→ proprietary/database-related interests
Employer
→ confidentiality and business-information interests
Controller
→ lawful processing authority
Processor
→ contractual processing authority
Third party
→ only the rights lawfully transferred or granted
This model is more consistent with modern data disputes than a simple “owner/non-owner” classification.
28. Personal-Data Monetisation Dispute Checklist
Before monetising personal data in the UAE, an organisation should examine:
Legal basis
Is there consent?
Is another statutory basis applicable?
Purpose
Why was the information originally collected?
Is monetisation compatible with that purpose?
Data classification
Is it personal data?
Sensitive personal data?
Confidential information?
Trade-secret material?
Contract
What do customer agreements say?
What do processor agreements say?
Are third-party transfers authorised?
Security
Who can access the dataset?
Are access logs maintained?
Are copying and downloading controlled?
Commercial transaction
Who receives the information?
What exactly is being licensed?
Is the information identifiable?
Evidence
Can the organisation demonstrate consent?
Can it prove the purpose?
Can it prove the scope of processing?
29. Conclusion
UAE law does not support a simplistic proposition that the entity possessing a database automatically owns every item of personal information contained in it and may freely monetise that information.
The more accurate approach is to distinguish between:
personal-data rights;
database rights;
confidentiality;
trade secrets;
contractual rights;
intellectual property;
commercial value; and
civil liability.
Federal Decree-Law No. 45 of 2021 places personal-data processing within a statutory protection framework, including a general consent rule and specified exceptions. (UAE Legislation) Meanwhile, the 2025 Civil Transactions Law recognises broad categories of tangible and intangible financial rights, but that general property concept should not be interpreted as creating unrestricted ownership of another person's personal information. (UAE Legislation)
The DIFC authorities further demonstrate that information can possess substantial economic value, that confidential customer information may receive legal protection, and that misuse of data or information systems can generate substantial compensatory consequences. (DIFC Courts)
The central principle is therefore: commercial value in data does not, by itself, equal unrestricted ownership or unrestricted monetisation rights. The legality of monetisation depends on the nature of the data, the applicable legal basis, purpose of processing, contractual arrangements, confidentiality obligations, jurisdiction and the actual harm caused by any misuse.

comments