Civil Law And Uae Data Protection Liability Under Uae Pdpl .
Civil Law and UAE Data Protection Liability Under the UAE PDPL
1. Introduction
The UAE's principal federal data-protection statute is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL). It came into force on 2 January 2022. The PDPL establishes duties for data controllers and processors concerning lawful processing, security, confidentiality, data-subject rights, breach management and cross-border transfers.
For civil-liability analysis, an important distinction should be made:
The PDPL establishes regulatory duties and administrative enforcement, but it does not contain a GDPR-style standalone provision expressly setting out a general private right to compensation for every PDPL violation.
Consequently, a claim for monetary compensation will generally require consideration of the UAE Civil Transactions Law, contractual obligations, applicable sectoral legislation, and the particular damage and causal connection proved by the claimant. Contemporary legal analysis likewise identifies this distinction between the PDPL's regulatory enforcement mechanism and general UAE civil-law remedies.
A further qualification is important for the case law: reported judgments directly applying Federal Decree-Law No. 45 of 2021 to civil damages remain limited. The six-plus cases below therefore include the closest UAE/DIFC judicial authorities concerning data-protection rights, confidentiality, personal information, cybersecurity and information-related civil remedies. They should not be inaccurately described as six federal-PDPL damages judgments.
2. Scope of UAE PDPL
The PDPL regulates the processing of personal data and establishes obligations for:
- Controllers — persons/entities determining the purpose and means of processing;
- Processors — persons/entities processing data on behalf of controllers;
- Data Subjects — individuals to whom personal data relates.
The federal regime is subject to important exclusions, including certain government, security, judicial, health, banking/credit and free-zone regimes. The DIFC and ADGM have separate data-protection frameworks.
Therefore, before assessing liability, the first question should be:
Does the federal PDPL actually apply to the relevant processing activity?
3. Main Sources of Liability
UAE data-protection liability can arise through several routes.
3.1 Statutory/regulatory liability
The controller or processor may violate obligations imposed directly by the PDPL.
3.2 Contractual liability
A data-processing agreement, employment contract, service agreement or confidentiality agreement may impose additional obligations.
3.3 Civil liability
Where unlawful conduct causes legally recognised damage, the claimant may rely upon applicable principles of UAE civil liability.
3.4 Confidentiality liability
Personal information can also constitute confidential information, creating a separate claim where information is misused.
3.5 Sector-specific liability
Banking, healthcare, insurance, telecommunications and other regulated activities may have additional data-security requirements.
4. Lawful Processing
A fundamental PDPL principle is that personal data cannot simply be processed without a lawful basis.
The PDPL regulates consent and provides statutory circumstances in which processing can take place without ordinary consent requirements.
Therefore, liability assessment should begin by asking:
- What data was collected?
- Who collected it?
- Why was it collected?
- What was the lawful basis?
- Was the processing consistent with the stated purpose?
- Was more data collected than necessary?
- Was the information subsequently disclosed to another party?
A company that collects information for one purpose but subsequently uses it for an unrelated purpose may face a different legal analysis from an organisation processing the same information for a legitimate and disclosed purpose.
5. Controller Liability
The controller has a central role because it determines the purposes and means of processing.
The controller should establish appropriate governance concerning:
- lawful processing;
- data accuracy;
- security;
- confidentiality;
- retention;
- processor management;
- data-subject rights;
- breach response.
The PDPL also provides for appointment of a Data Protection Officer in specified higher-risk situations, including certain processing involving large amounts of sensitive personal data or systematic assessment/profiling.
6. Processor Liability
A processor is not simply immune because it acts on another organisation's instructions.
Article 20 requires controllers and processors to adopt appropriate technical and regulatory measures for information security proportionate to the risks of processing.
Where a processor becomes aware of a personal-data breach, it must notify the controller, which then has the reporting responsibility specified by the PDPL.
Thus:
Controller → overall governance and reporting responsibility
Processor → security and incident-notification responsibilities
The exact allocation will also depend upon the processing agreement and applicable law.
7. Data-Security Liability
Article 20 is particularly important.
The controller and processor must develop and take appropriate technical and organisational/regulatory measures corresponding to the risks associated with processing.
Security measures can include:
- encryption;
- access controls;
- authentication;
- network security;
- logging;
- vulnerability management;
- employee training;
- incident-response procedures;
- backup systems;
- data segregation;
- secure deletion.
The relevant question is not simply whether a breach occurred.
Instead, liability analysis asks:
Were appropriate security measures adopted in light of the risks of the particular processing activity?
8. Personal-Data Breach
The PDPL establishes a specific breach-notification framework.
Where an infringement or breach affects the privacy, confidentiality or security of personal data in the circumstances specified by the law, the controller has notification obligations.
The notification framework contemplates information concerning:
- nature of the breach;
- form and causes;
- approximate number of affected records;
- Data Protection Officer information;
- likely consequences;
- remedial measures;
- documentation of the breach.
Where the breach prejudices privacy, confidentiality or security, the controller must also notify the data subject in accordance with the applicable requirements. A processor that becomes aware of a breach must notify the controller.
9. Civil Liability After a Data Breach
A breach of the PDPL and a successful damages claim are related but not identical.
A claimant seeking compensation should generally establish:
1. Duty
The defendant owed a legal or contractual obligation.
2. Breach
The obligation was violated.
3. Damage
The claimant suffered legally recognised harm.
4. Causation
The breach caused the relevant harm.
5. Quantum
The amount of compensation can be established sufficiently for judicial assessment.
For example:
Weak password controls → unauthorised access → theft of personal information → fraudulent financial transaction
requires proof linking each stage.
The mere fact that personal data was exposed does not automatically establish every claimed consequential financial loss.
10. Material and Moral Damage
Potential losses may include:
- direct financial loss;
- fraud-related losses;
- reasonable remediation expenses;
- identity-restoration expenses;
- business losses;
- certain lost profits;
- recognised moral harm;
- reputational harm where legally recoverable.
However, the precise remedy depends upon the applicable UAE civil-law provisions and the evidence presented.
A claimant should distinguish actual proved loss from speculative future losses.
11. Administrative Liability Under the PDPL
Article 24 allows a data subject to complain to the UAE Data Office where the person believes the PDPL has been violated or personal data is being processed contrary to applicable rules. The Office can investigate and impose the administrative penalties provided under Article 26 where a violation is established.
Article 26 provides the statutory framework for administrative violations and penalties, with the specific acts and penalties to be specified by the competent Cabinet decision.
This creates an important distinction:
| PDPL mechanism | Civil-law mechanism |
|---|---|
| Complaint to Data Office | Civil claim before competent court |
| Regulatory investigation | Judicial determination |
| Administrative penalties | Compensation/remedial relief |
| Compliance enforcement | Recovery for legally recognised loss |
| PDPL violation | Requires separate analysis of civil damage |
12. Case Law
Case 1 — DFSA v Commissioner of Data Protection & Anna Waterhouse, [2020] DIFC CFI 051/085
This is the most directly relevant UAE judicial authority concerning data-protection rights.
The dispute arose from a Subject Access Request made by Anna Waterhouse to the Dubai Financial Services Authority.
The DFSA had conducted a regulatory investigation involving her and refused to provide all of the personal data requested. The dispute concerned the interaction between:
- subject-access rights;
- regulatory investigations;
- the definition of personal data;
- exemptions;
- the functions of the regulator.
The DIFC Court examined the applicable DIFC Data Protection Law and the statutory framework governing subject access.
Significance
The case demonstrates that data-protection rights must be analysed in their statutory context.
It is especially important for understanding:
- data-subject access;
- regulatory exemptions;
- personal-data identification;
- the relationship between privacy rights and regulatory functions.
Relevance to federal PDPL liability
It is not a judgment under Federal Decree-Law No. 45 of 2021. It is a DIFC authority, but it provides persuasive UAE judicial material on how a sophisticated UAE court approaches data-protection rights.
13. Case 2 — Graciela Limited v Giacobbe [2014] DIFC CFI 027
This case involved wrongful interference with an information-technology system.
The DIFC Court considered technical evidence concerning the claimant's IT infrastructure and the resulting losses.
Significance
The case is useful for data-breach liability because it illustrates the importance of proving:
- the security incident;
- the mechanism of interference;
- responsibility;
- technical causation;
- remediation expenses;
- consequential loss.
It demonstrates that technology-related civil claims require detailed evidence connecting the defendant's conduct with the claimant's loss.
PDPL relevance
A modern PDPL claim arising from a cyber incident may require similar technical evidence, particularly where the controller or processor disputes whether its security controls caused or contributed to the breach.
14. Case 3 — Aegis Resources DMCC v Union Bank of India (DIFC Branch), [2020] DIFC CFI 004
This case concerned cyber fraud associated with the compromise of an email account and fraudulent payment instructions.
Significance
The case illustrates the importance of determining:
- which system was compromised;
- who controlled the relevant security environment;
- how authentication operated;
- what contractual obligations existed;
- whether the subsequent financial loss was caused by the relevant security failure.
PDPL relevance
Where a data breach results in financial fraud, a claimant cannot necessarily attribute every resulting loss to the data controller.
Causation and intervening conduct remain important.
15. Case 4 — Health Bay Investment in Healthcare Enterprises & Development LLC v Dr Kamal Akkach, [2020] DIFC CFI 087
This dispute involved a healthcare business and sensitive information.
The DIFC proceedings demonstrate the court's willingness to use procedural protections concerning confidential and sensitive information, including healthcare-related records.
Significance
Healthcare information illustrates why data protection can overlap with:
- confidentiality;
- professional obligations;
- contractual duties;
- civil injunctions;
- information-security obligations.
PDPL relevance
Health data is subject to specific regulatory treatment in the UAE, and the federal PDPL has exclusions for certain health-related personal data regulated under specialised legislation.
Therefore, the applicable sectoral law must be identified before relying solely on the federal PDPL.
16. Case 5 — AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd, [2025] DIFC CFI 060
This is a significant modern DIFC case concerning confidential client information.
The claimants alleged that former employees moved to the defendant and that confidential information concerning clients and assets under management was misused. The claims included breach of confidence and related causes of action. The DIFC Court ultimately dismissed the claims in its 2025 judgment.
Significance
The case is useful because it demonstrates that:
confidential information ≠ automatically protected personal data.
Client information may simultaneously have:
- personal-data characteristics;
- commercial confidentiality;
- contractual protection;
- trade-secret characteristics.
The precise legal cause of action must therefore be identified.
PDPL relevance
A customer database could give rise to different legal obligations under data-protection law and confidentiality law at the same time.
17. Case 6 — Access Group DWC LLC v BLS International FZE, [2024] DIFC CFI 091/2023
This case involved civil litigation and extensive document production.
The DIFC Court issued case-management orders concerning document production and requests to produce.
Significance
The case is useful for understanding the practical relationship between:
- disclosure;
- relevance;
- confidentiality;
- document production;
- protection of sensitive information.
PDPL relevance
A company responding to litigation disclosure may possess personal data concerning customers, employees or third parties.
The existence of a litigation obligation does not mean that every piece of information should be circulated without controls.
18. Case 7 — Standard Chartered PLC v Standard Chartered Bank, [2025] DIFC ENF 053/2025
This modern case concerned recognition and enforcement in the DIFC of a disclosure order originating in English proceedings.
The DIFC Court recognised and enforced the foreign disclosure order.
Significance
This type of case is important for cross-border data protection because international disclosure can involve:
- customer information;
- banking records;
- confidential communications;
- personal financial information.
It demonstrates the practical importance of reconciling foreign disclosure obligations with confidentiality and data-protection requirements.
PDPL relevance
Article 23 of the federal PDPL specifically recognises circumstances involving international judicial cooperation and circumstances where transfer is necessary to establish or defend rights before judicial entities.
Thus, litigation-related cross-border transfers require analysis of the specific statutory conditions rather than an assumption that all international transfers are prohibited.
19. Case 8 — ABN Amro Bank N.V. v N/A, [2017] DIFC CFI 010
This case provides another useful example of personal-data governance in a court-supervised corporate context.
The proceedings involved arrangements concerning personal data associated with a business transfer and protections for sensitive information.
Significance
It illustrates an important principle:
When ownership or control of a business changes, the legal identity and responsibilities of the person controlling personal data may also change.
This is relevant to:
- mergers;
- acquisitions;
- insolvency;
- restructuring;
- business transfers.
20. Six-Case Comparison
| Case | Main issue | Relevance to PDPL liability |
|---|---|---|
| DFSA v Waterhouse | Subject access and regulatory investigation | Data-subject rights |
| Graciela v Giacobbe | IT-system interference | Cybersecurity and causation |
| Aegis Resources v Union Bank | Email compromise and cyber fraud | Security and financial loss |
| Health Bay v Akkach | Healthcare/confidential information | Sensitive data and confidentiality |
| AES v GSB Capital | Customer/confidential information | Misuse of client data |
| Access Group v BLS | Document production | Data disclosure and confidentiality |
| Standard Chartered v Standard Chartered Bank | Cross-border disclosure | International data transfer |
| ABN Amro Bank v N/A | Data in corporate restructuring | Controller/data governance |
These are UAE/DIFC authorities rather than six federal-PDPL damages decisions. That distinction is important because the federal PDPL is relatively new and reported case law directly applying it remains limited.
21. Cross-Border Data Transfer Liability
Articles 22 and 23 are important where personal data leaves the UAE.
The PDPL permits transfers under specified circumstances, including transfers to jurisdictions having adequate protection and certain other situations, including contractual necessity, consent and international judicial cooperation.
A controller should therefore document:
- destination country;
- recipient;
- purpose;
- legal basis;
- contractual safeguards;
- security controls;
- necessity of transfer.
A transfer made simply because a foreign service provider is convenient may require more analysis than a transfer necessary to establish or defend a legal claim.
22. Liability of Cloud Providers
Cloud computing creates a common controller-processor problem.
Suppose:
UAE company → cloud provider → subcontracted hosting provider
A breach occurs at the subcontractor.
The investigation should determine:
- Who was the controller?
- Who was the processor?
- Was there a sub-processor?
- What contractual security obligations existed?
- Did the processor comply with instructions?
- Were appropriate security controls implemented?
- Was the controller notified promptly?
- Was the incident reported as required?
The mere fact that the breach occurred at a third-party provider does not automatically answer the allocation of liability.
23. Employee Data
Employee records can contain:
- identification information;
- salaries;
- bank details;
- attendance records;
- performance information;
- disciplinary records;
- medical information.
An employer should therefore distinguish legitimate employment-related processing from unnecessary disclosure.
If an employee brings a civil claim, the employer may have a legal need to use relevant employment records. But that does not necessarily justify unrestricted disclosure of unrelated employees' data.
24. Customer Database Liability
A customer database may contain:
- names;
- telephone numbers;
- email addresses;
- addresses;
- purchasing information;
- financial information;
- preferences;
- transaction histories.
A controller may face different forms of liability if the database is:
- unlawfully collected;
- used for an incompatible purpose;
- sold or disclosed without lawful basis;
- inadequately protected;
- retained unnecessarily;
- transferred internationally without satisfying applicable requirements.
The AES litigation illustrates why customer information can simultaneously raise confidentiality and civil-law questions, independently of the federal PDPL.
25. Data Breach Liability Model
A useful legal formula is:
PDPL duty
↓
Failure to comply
↓
Security/privacy violation
↓
Actual or legally recognised harm
↓
Causal connection
↓
Appropriate remedy
For example:
Failure to implement appropriate security controls
→ unauthorised database access
→ exposure of customer information
→ fraudulent use
→ documented financial loss
→ civil claim for recoverable damages.
The claimant still needs to establish the relevant causal connection.
26. Defences and Limiting Arguments
A controller or processor may dispute liability by demonstrating, depending upon the claim:
A. No applicable PDPL duty
The activity may fall under an exclusion or a different regulatory regime.
B. Lawful processing
The processing may have had a valid statutory or other lawful basis.
C. Adequate security
The organisation may demonstrate that appropriate security measures were implemented.
D. No damage
The claimant may fail to prove legally recognised harm.
E. No causation
The claimed loss may have resulted from another cause.
F. Contributory conduct
The claimant's own conduct may have contributed to the loss under applicable civil-law principles.
G. Third-party intervention
An independent criminal act may complicate the causation analysis, although it does not automatically eliminate liability.
27. Remedies
Potential consequences can operate on several levels.
Regulatory
- investigation;
- compliance directions;
- administrative penalties;
- complaint procedures.
Civil
- damages;
- contractual remedies;
- injunctions;
- orders preventing continued misuse;
- restoration/corrective measures where legally available.
Procedural
- confidentiality orders;
- redaction;
- restricted disclosure;
- evidence-preservation orders.
The PDPL itself expressly provides a complaint mechanism and administrative penalty framework.
28. Practical Liability Assessment Checklist
For a UAE data-protection dispute, the following checklist is useful:
Step 1 — Identify the data
What personal information was involved?
Step 2 — Identify the parties
Who was the controller, processor and any sub-processor?
Step 3 — Determine applicability
Does the federal PDPL apply, or is another regime applicable?
Step 4 — Establish lawful basis
Why was the information processed?
Step 5 — Examine security
Were appropriate technical and organisational measures implemented?
Step 6 — Investigate the breach
When did the organisation know about the incident?
Step 7 — Examine notification
Were the applicable reporting obligations satisfied?
Step 8 — Determine harm
What actual loss occurred?
Step 9 — Establish causation
Did the PDPL-related violation cause that loss?
Step 10 — Determine remedy
Is the appropriate remedy regulatory, civil, contractual, injunctive, or a combination?
29. Important Legal Qualification
The UAE PDPL should not be treated as an exact equivalent of the EU GDPR.
In particular, Article 26 establishes an administrative-penalty framework, while the PDPL does not contain a directly equivalent general provision to GDPR Article 82 creating a statutory compensation action for material and non-material damage. Current legal scholarship identifies this as an important distinction and points toward general UAE civil-law principles for compensation.
Therefore, in a civil lawsuit, the strongest analysis is usually:
PDPL obligation + contractual/civil obligation + proven breach + damage + causation + applicable remedy.
30. Conclusion
UAE data-protection liability under the PDPL is best understood as a combination of regulatory, contractual and general civil-law responsibility.
The most important principles are:
- Controllers and processors have statutory data-protection obligations.
- Appropriate technical and organisational security is required.
- Data breaches can trigger notification responsibilities.
- Processors must notify controllers of breaches.
- Data subjects can complain to the UAE Data Office.
- Administrative penalties are distinct from private compensation.
- A civil damages claim requires analysis of damage and causation.
- Confidentiality law may provide an additional cause of action.
- Cross-border transfers require separate analysis.
- DIFC and ADGM cases cannot automatically be treated as federal-PDPL precedents.
- Reported UAE judgments directly applying the 2021 federal PDPL to civil damages remain limited.
- DFSA v Waterhouse is particularly important for UAE data-protection jurisprudence, while Graciela, Aegis Resources, Health Bay, AES, Access Group, Standard Chartered and ABN Amro provide complementary authorities concerning cybersecurity, confidential information, disclosure and civil remedies.
Thus, a UAE court assessing a data-protection liability dispute is likely to require a careful separation of PDPL compliance, applicable sectoral rules, contractual obligations, general civil liability, actual damage, and causation, rather than treating every PDPL violation as automatically producing a predetermined damages award.

comments