Civil Law And Uae Data Protection Liability Under Uae Pdpl .

Civil Law and UAE Data Protection Liability Under the UAE PDPL

1. Introduction

The UAE's principal federal data-protection statute is Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data (UAE PDPL). It came into force on 2 January 2022. The PDPL establishes duties for data controllers and processors concerning lawful processing, security, confidentiality, data-subject rights, breach management and cross-border transfers.

For civil-liability analysis, an important distinction should be made:

The PDPL establishes regulatory duties and administrative enforcement, but it does not contain a GDPR-style standalone provision expressly setting out a general private right to compensation for every PDPL violation.

Consequently, a claim for monetary compensation will generally require consideration of the UAE Civil Transactions Law, contractual obligations, applicable sectoral legislation, and the particular damage and causal connection proved by the claimant. Contemporary legal analysis likewise identifies this distinction between the PDPL's regulatory enforcement mechanism and general UAE civil-law remedies.

A further qualification is important for the case law: reported judgments directly applying Federal Decree-Law No. 45 of 2021 to civil damages remain limited. The six-plus cases below therefore include the closest UAE/DIFC judicial authorities concerning data-protection rights, confidentiality, personal information, cybersecurity and information-related civil remedies. They should not be inaccurately described as six federal-PDPL damages judgments.

2. Scope of UAE PDPL

The PDPL regulates the processing of personal data and establishes obligations for:

  • Controllers — persons/entities determining the purpose and means of processing;
  • Processors — persons/entities processing data on behalf of controllers;
  • Data Subjects — individuals to whom personal data relates.

The federal regime is subject to important exclusions, including certain government, security, judicial, health, banking/credit and free-zone regimes. The DIFC and ADGM have separate data-protection frameworks.

Therefore, before assessing liability, the first question should be:

Does the federal PDPL actually apply to the relevant processing activity?

3. Main Sources of Liability

UAE data-protection liability can arise through several routes.

3.1 Statutory/regulatory liability

The controller or processor may violate obligations imposed directly by the PDPL.

3.2 Contractual liability

A data-processing agreement, employment contract, service agreement or confidentiality agreement may impose additional obligations.

3.3 Civil liability

Where unlawful conduct causes legally recognised damage, the claimant may rely upon applicable principles of UAE civil liability.

3.4 Confidentiality liability

Personal information can also constitute confidential information, creating a separate claim where information is misused.

3.5 Sector-specific liability

Banking, healthcare, insurance, telecommunications and other regulated activities may have additional data-security requirements.

4. Lawful Processing

A fundamental PDPL principle is that personal data cannot simply be processed without a lawful basis.

The PDPL regulates consent and provides statutory circumstances in which processing can take place without ordinary consent requirements.

Therefore, liability assessment should begin by asking:

  1. What data was collected?
  2. Who collected it?
  3. Why was it collected?
  4. What was the lawful basis?
  5. Was the processing consistent with the stated purpose?
  6. Was more data collected than necessary?
  7. Was the information subsequently disclosed to another party?

A company that collects information for one purpose but subsequently uses it for an unrelated purpose may face a different legal analysis from an organisation processing the same information for a legitimate and disclosed purpose.

5. Controller Liability

The controller has a central role because it determines the purposes and means of processing.

The controller should establish appropriate governance concerning:

  • lawful processing;
  • data accuracy;
  • security;
  • confidentiality;
  • retention;
  • processor management;
  • data-subject rights;
  • breach response.

The PDPL also provides for appointment of a Data Protection Officer in specified higher-risk situations, including certain processing involving large amounts of sensitive personal data or systematic assessment/profiling.

6. Processor Liability

A processor is not simply immune because it acts on another organisation's instructions.

Article 20 requires controllers and processors to adopt appropriate technical and regulatory measures for information security proportionate to the risks of processing.

Where a processor becomes aware of a personal-data breach, it must notify the controller, which then has the reporting responsibility specified by the PDPL.

Thus:

Controller → overall governance and reporting responsibility

Processor → security and incident-notification responsibilities

The exact allocation will also depend upon the processing agreement and applicable law.

7. Data-Security Liability

Article 20 is particularly important.

The controller and processor must develop and take appropriate technical and organisational/regulatory measures corresponding to the risks associated with processing.

Security measures can include:

  • encryption;
  • access controls;
  • authentication;
  • network security;
  • logging;
  • vulnerability management;
  • employee training;
  • incident-response procedures;
  • backup systems;
  • data segregation;
  • secure deletion.

The relevant question is not simply whether a breach occurred.

Instead, liability analysis asks:

Were appropriate security measures adopted in light of the risks of the particular processing activity?

 

8. Personal-Data Breach

The PDPL establishes a specific breach-notification framework.

Where an infringement or breach affects the privacy, confidentiality or security of personal data in the circumstances specified by the law, the controller has notification obligations.

The notification framework contemplates information concerning:

  • nature of the breach;
  • form and causes;
  • approximate number of affected records;
  • Data Protection Officer information;
  • likely consequences;
  • remedial measures;
  • documentation of the breach.

Where the breach prejudices privacy, confidentiality or security, the controller must also notify the data subject in accordance with the applicable requirements. A processor that becomes aware of a breach must notify the controller.

9. Civil Liability After a Data Breach

A breach of the PDPL and a successful damages claim are related but not identical.

A claimant seeking compensation should generally establish:

1. Duty

The defendant owed a legal or contractual obligation.

2. Breach

The obligation was violated.

3. Damage

The claimant suffered legally recognised harm.

4. Causation

The breach caused the relevant harm.

5. Quantum

The amount of compensation can be established sufficiently for judicial assessment.

For example:

Weak password controls → unauthorised access → theft of personal information → fraudulent financial transaction

requires proof linking each stage.

The mere fact that personal data was exposed does not automatically establish every claimed consequential financial loss.

10. Material and Moral Damage

Potential losses may include:

  • direct financial loss;
  • fraud-related losses;
  • reasonable remediation expenses;
  • identity-restoration expenses;
  • business losses;
  • certain lost profits;
  • recognised moral harm;
  • reputational harm where legally recoverable.

However, the precise remedy depends upon the applicable UAE civil-law provisions and the evidence presented.

A claimant should distinguish actual proved loss from speculative future losses.

11. Administrative Liability Under the PDPL

Article 24 allows a data subject to complain to the UAE Data Office where the person believes the PDPL has been violated or personal data is being processed contrary to applicable rules. The Office can investigate and impose the administrative penalties provided under Article 26 where a violation is established.

Article 26 provides the statutory framework for administrative violations and penalties, with the specific acts and penalties to be specified by the competent Cabinet decision.

This creates an important distinction:

PDPL mechanismCivil-law mechanism
Complaint to Data OfficeCivil claim before competent court
Regulatory investigationJudicial determination
Administrative penaltiesCompensation/remedial relief
Compliance enforcementRecovery for legally recognised loss
PDPL violationRequires separate analysis of civil damage

12. Case Law

Case 1 — DFSA v Commissioner of Data Protection & Anna Waterhouse, [2020] DIFC CFI 051/085

This is the most directly relevant UAE judicial authority concerning data-protection rights.

The dispute arose from a Subject Access Request made by Anna Waterhouse to the Dubai Financial Services Authority.

The DFSA had conducted a regulatory investigation involving her and refused to provide all of the personal data requested. The dispute concerned the interaction between:

  • subject-access rights;
  • regulatory investigations;
  • the definition of personal data;
  • exemptions;
  • the functions of the regulator.

The DIFC Court examined the applicable DIFC Data Protection Law and the statutory framework governing subject access.

Significance

The case demonstrates that data-protection rights must be analysed in their statutory context.

It is especially important for understanding:

  • data-subject access;
  • regulatory exemptions;
  • personal-data identification;
  • the relationship between privacy rights and regulatory functions.

Relevance to federal PDPL liability

It is not a judgment under Federal Decree-Law No. 45 of 2021. It is a DIFC authority, but it provides persuasive UAE judicial material on how a sophisticated UAE court approaches data-protection rights.

13. Case 2 — Graciela Limited v Giacobbe [2014] DIFC CFI 027

This case involved wrongful interference with an information-technology system.

The DIFC Court considered technical evidence concerning the claimant's IT infrastructure and the resulting losses.

Significance

The case is useful for data-breach liability because it illustrates the importance of proving:

  • the security incident;
  • the mechanism of interference;
  • responsibility;
  • technical causation;
  • remediation expenses;
  • consequential loss.

It demonstrates that technology-related civil claims require detailed evidence connecting the defendant's conduct with the claimant's loss.

PDPL relevance

A modern PDPL claim arising from a cyber incident may require similar technical evidence, particularly where the controller or processor disputes whether its security controls caused or contributed to the breach.

14. Case 3 — Aegis Resources DMCC v Union Bank of India (DIFC Branch), [2020] DIFC CFI 004

This case concerned cyber fraud associated with the compromise of an email account and fraudulent payment instructions.

Significance

The case illustrates the importance of determining:

  • which system was compromised;
  • who controlled the relevant security environment;
  • how authentication operated;
  • what contractual obligations existed;
  • whether the subsequent financial loss was caused by the relevant security failure.

PDPL relevance

Where a data breach results in financial fraud, a claimant cannot necessarily attribute every resulting loss to the data controller.

Causation and intervening conduct remain important.

15. Case 4 — Health Bay Investment in Healthcare Enterprises & Development LLC v Dr Kamal Akkach, [2020] DIFC CFI 087

This dispute involved a healthcare business and sensitive information.

The DIFC proceedings demonstrate the court's willingness to use procedural protections concerning confidential and sensitive information, including healthcare-related records.

Significance

Healthcare information illustrates why data protection can overlap with:

  • confidentiality;
  • professional obligations;
  • contractual duties;
  • civil injunctions;
  • information-security obligations.

PDPL relevance

Health data is subject to specific regulatory treatment in the UAE, and the federal PDPL has exclusions for certain health-related personal data regulated under specialised legislation.

Therefore, the applicable sectoral law must be identified before relying solely on the federal PDPL.

16. Case 5 — AES Middle East Insurance Broker LLC & Others v GSB Capital Ltd, [2025] DIFC CFI 060

This is a significant modern DIFC case concerning confidential client information.

The claimants alleged that former employees moved to the defendant and that confidential information concerning clients and assets under management was misused. The claims included breach of confidence and related causes of action. The DIFC Court ultimately dismissed the claims in its 2025 judgment.

Significance

The case is useful because it demonstrates that:

confidential information ≠ automatically protected personal data.

Client information may simultaneously have:

  • personal-data characteristics;
  • commercial confidentiality;
  • contractual protection;
  • trade-secret characteristics.

The precise legal cause of action must therefore be identified.

PDPL relevance

A customer database could give rise to different legal obligations under data-protection law and confidentiality law at the same time.

17. Case 6 — Access Group DWC LLC v BLS International FZE, [2024] DIFC CFI 091/2023

This case involved civil litigation and extensive document production.

The DIFC Court issued case-management orders concerning document production and requests to produce.

Significance

The case is useful for understanding the practical relationship between:

  • disclosure;
  • relevance;
  • confidentiality;
  • document production;
  • protection of sensitive information.

PDPL relevance

A company responding to litigation disclosure may possess personal data concerning customers, employees or third parties.

The existence of a litigation obligation does not mean that every piece of information should be circulated without controls.

18. Case 7 — Standard Chartered PLC v Standard Chartered Bank, [2025] DIFC ENF 053/2025

This modern case concerned recognition and enforcement in the DIFC of a disclosure order originating in English proceedings.

The DIFC Court recognised and enforced the foreign disclosure order.

Significance

This type of case is important for cross-border data protection because international disclosure can involve:

  • customer information;
  • banking records;
  • confidential communications;
  • personal financial information.

It demonstrates the practical importance of reconciling foreign disclosure obligations with confidentiality and data-protection requirements.

PDPL relevance

Article 23 of the federal PDPL specifically recognises circumstances involving international judicial cooperation and circumstances where transfer is necessary to establish or defend rights before judicial entities.

Thus, litigation-related cross-border transfers require analysis of the specific statutory conditions rather than an assumption that all international transfers are prohibited.

19. Case 8 — ABN Amro Bank N.V. v N/A, [2017] DIFC CFI 010

This case provides another useful example of personal-data governance in a court-supervised corporate context.

The proceedings involved arrangements concerning personal data associated with a business transfer and protections for sensitive information.

Significance

It illustrates an important principle:

When ownership or control of a business changes, the legal identity and responsibilities of the person controlling personal data may also change.

This is relevant to:

  • mergers;
  • acquisitions;
  • insolvency;
  • restructuring;
  • business transfers.

20. Six-Case Comparison

CaseMain issueRelevance to PDPL liability
DFSA v WaterhouseSubject access and regulatory investigationData-subject rights
Graciela v GiacobbeIT-system interferenceCybersecurity and causation
Aegis Resources v Union BankEmail compromise and cyber fraudSecurity and financial loss
Health Bay v AkkachHealthcare/confidential informationSensitive data and confidentiality
AES v GSB CapitalCustomer/confidential informationMisuse of client data
Access Group v BLSDocument productionData disclosure and confidentiality
Standard Chartered v Standard Chartered BankCross-border disclosureInternational data transfer
ABN Amro Bank v N/AData in corporate restructuringController/data governance

These are UAE/DIFC authorities rather than six federal-PDPL damages decisions. That distinction is important because the federal PDPL is relatively new and reported case law directly applying it remains limited.

21. Cross-Border Data Transfer Liability

Articles 22 and 23 are important where personal data leaves the UAE.

The PDPL permits transfers under specified circumstances, including transfers to jurisdictions having adequate protection and certain other situations, including contractual necessity, consent and international judicial cooperation.

A controller should therefore document:

  • destination country;
  • recipient;
  • purpose;
  • legal basis;
  • contractual safeguards;
  • security controls;
  • necessity of transfer.

A transfer made simply because a foreign service provider is convenient may require more analysis than a transfer necessary to establish or defend a legal claim.

22. Liability of Cloud Providers

Cloud computing creates a common controller-processor problem.

Suppose:

UAE company → cloud provider → subcontracted hosting provider

A breach occurs at the subcontractor.

The investigation should determine:

  1. Who was the controller?
  2. Who was the processor?
  3. Was there a sub-processor?
  4. What contractual security obligations existed?
  5. Did the processor comply with instructions?
  6. Were appropriate security controls implemented?
  7. Was the controller notified promptly?
  8. Was the incident reported as required?

The mere fact that the breach occurred at a third-party provider does not automatically answer the allocation of liability.

23. Employee Data

Employee records can contain:

  • identification information;
  • salaries;
  • bank details;
  • attendance records;
  • performance information;
  • disciplinary records;
  • medical information.

An employer should therefore distinguish legitimate employment-related processing from unnecessary disclosure.

If an employee brings a civil claim, the employer may have a legal need to use relevant employment records. But that does not necessarily justify unrestricted disclosure of unrelated employees' data.

24. Customer Database Liability

A customer database may contain:

  • names;
  • telephone numbers;
  • email addresses;
  • addresses;
  • purchasing information;
  • financial information;
  • preferences;
  • transaction histories.

A controller may face different forms of liability if the database is:

  • unlawfully collected;
  • used for an incompatible purpose;
  • sold or disclosed without lawful basis;
  • inadequately protected;
  • retained unnecessarily;
  • transferred internationally without satisfying applicable requirements.

The AES litigation illustrates why customer information can simultaneously raise confidentiality and civil-law questions, independently of the federal PDPL.

25. Data Breach Liability Model

A useful legal formula is:

PDPL duty

Failure to comply

Security/privacy violation

Actual or legally recognised harm

Causal connection

Appropriate remedy

For example:

Failure to implement appropriate security controls

→ unauthorised database access

→ exposure of customer information

→ fraudulent use

→ documented financial loss

→ civil claim for recoverable damages.

The claimant still needs to establish the relevant causal connection.

26. Defences and Limiting Arguments

A controller or processor may dispute liability by demonstrating, depending upon the claim:

A. No applicable PDPL duty

The activity may fall under an exclusion or a different regulatory regime.

B. Lawful processing

The processing may have had a valid statutory or other lawful basis.

C. Adequate security

The organisation may demonstrate that appropriate security measures were implemented.

D. No damage

The claimant may fail to prove legally recognised harm.

E. No causation

The claimed loss may have resulted from another cause.

F. Contributory conduct

The claimant's own conduct may have contributed to the loss under applicable civil-law principles.

G. Third-party intervention

An independent criminal act may complicate the causation analysis, although it does not automatically eliminate liability.

27. Remedies

Potential consequences can operate on several levels.

Regulatory

  • investigation;
  • compliance directions;
  • administrative penalties;
  • complaint procedures.

Civil

  • damages;
  • contractual remedies;
  • injunctions;
  • orders preventing continued misuse;
  • restoration/corrective measures where legally available.

Procedural

  • confidentiality orders;
  • redaction;
  • restricted disclosure;
  • evidence-preservation orders.

The PDPL itself expressly provides a complaint mechanism and administrative penalty framework.

28. Practical Liability Assessment Checklist

For a UAE data-protection dispute, the following checklist is useful:

Step 1 — Identify the data

What personal information was involved?

Step 2 — Identify the parties

Who was the controller, processor and any sub-processor?

Step 3 — Determine applicability

Does the federal PDPL apply, or is another regime applicable?

Step 4 — Establish lawful basis

Why was the information processed?

Step 5 — Examine security

Were appropriate technical and organisational measures implemented?

Step 6 — Investigate the breach

When did the organisation know about the incident?

Step 7 — Examine notification

Were the applicable reporting obligations satisfied?

Step 8 — Determine harm

What actual loss occurred?

Step 9 — Establish causation

Did the PDPL-related violation cause that loss?

Step 10 — Determine remedy

Is the appropriate remedy regulatory, civil, contractual, injunctive, or a combination?

29. Important Legal Qualification

The UAE PDPL should not be treated as an exact equivalent of the EU GDPR.

In particular, Article 26 establishes an administrative-penalty framework, while the PDPL does not contain a directly equivalent general provision to GDPR Article 82 creating a statutory compensation action for material and non-material damage. Current legal scholarship identifies this as an important distinction and points toward general UAE civil-law principles for compensation.

Therefore, in a civil lawsuit, the strongest analysis is usually:

PDPL obligation + contractual/civil obligation + proven breach + damage + causation + applicable remedy.

30. Conclusion

UAE data-protection liability under the PDPL is best understood as a combination of regulatory, contractual and general civil-law responsibility.

The most important principles are:

  1. Controllers and processors have statutory data-protection obligations.
  2. Appropriate technical and organisational security is required.
  3. Data breaches can trigger notification responsibilities.
  4. Processors must notify controllers of breaches.
  5. Data subjects can complain to the UAE Data Office.
  6. Administrative penalties are distinct from private compensation.
  7. A civil damages claim requires analysis of damage and causation.
  8. Confidentiality law may provide an additional cause of action.
  9. Cross-border transfers require separate analysis.
  10. DIFC and ADGM cases cannot automatically be treated as federal-PDPL precedents.
  11. Reported UAE judgments directly applying the 2021 federal PDPL to civil damages remain limited.
  12. DFSA v Waterhouse is particularly important for UAE data-protection jurisprudence, while Graciela, Aegis Resources, Health Bay, AES, Access Group, Standard Chartered and ABN Amro provide complementary authorities concerning cybersecurity, confidential information, disclosure and civil remedies. 

Thus, a UAE court assessing a data-protection liability dispute is likely to require a careful separation of PDPL compliance, applicable sectoral rules, contractual obligations, general civil liability, actual damage, and causation, rather than treating every PDPL violation as automatically producing a predetermined damages award.

LEAVE A COMMENT