Civil Law And Uae Electronic Payment System Disputes .

CIVIL LAW AND UAE ELECTRONIC PAYMENT SYSTEM DISPUTES

1. Introduction

Electronic payment systems have become a central part of UAE commercial and consumer activity. Bank transfers, internet banking, mobile banking, credit cards, debit cards, digital wallets, payment gateways, electronic invoices, QR payments, payment-service platforms and other digital payment mechanisms create civil-law relationships between several parties.

A single electronic payment may involve:

the payer;

the payer's bank;

the recipient;

the recipient's bank;

a payment-service provider;

a card network;

a telecommunications provider;

an electronic-wallet operator;

a merchant; and

sometimes a fraudster or unauthorised third party.

Consequently, disputes may arise concerning:

unauthorised transfers;

hacked email payment instructions;

SIM-swap fraud;

stolen cards;

fraudulent OTP use;

defective payment authentication;

chargebacks;

failed electronic transfers;

mistaken payments;

duplicate payments;

payment-platform failures;

merchant disputes;

digital-wallet balances;

cryptocurrency transfers;

bank negligence;

customer contributory negligence;

cybersecurity failures; and

allocation of financial loss.

The central civil-law question is generally:

Who should bear the financial loss when an electronic payment is made incorrectly, fraudulently, without authority, or through a defective digital-payment system?

The answer depends upon the contract, the payment mandate, applicable legislation, evidence, the conduct of each party, and whether the relevant financial institution or platform breached a contractual or tortious duty.

2. Legal Framework

Electronic-payment disputes in the UAE are governed by a combination of:

A. UAE Civil Transactions Law

The UAE Civil Transactions Law provides the general principles concerning:

contractual obligations;

performance of contracts;

good faith;

unlawful acts;

causation;

compensation;

contributory responsibility;

abuse of rights; and

restitution.

The basic civil-liability structure generally requires examination of:

wrongful conduct/fault → damage → causation.

Where a bank or payment provider has failed to exercise appropriate care, the customer may potentially have a contractual or tortious claim, depending on the circumstances.

B. Federal Decree-Law No. 46 of 2021 on Electronic Transactions and Trust Services

This legislation is particularly relevant to electronic payment disputes because it recognizes legal consequences for electronic transactions and electronic records.

It is important when determining questions such as:

authenticity of electronic records;

electronic signatures;

electronic communications;

attribution;

reliability of electronic systems;

electronic contracts; and

evidentiary value of digital records.

C. Federal Decree-Law No. 35 of 2022 on Evidence in Civil and Commercial Transactions

Electronic payment disputes frequently depend upon digital evidence, including:

bank-system records;

OTP records;

authentication logs;

IP addresses;

mobile-device records;

transaction histories;

emails;

electronic invoices;

card records;

digital-wallet records; and

telecommunications records.

The court may need to determine whether the evidence establishes that the transaction was actually authorised by the customer.

D. Banking and Financial Regulation

Banks and financial institutions operate within a regulated environment. Payment-security obligations may therefore arise not merely from the customer contract but also from applicable regulatory standards.

E. DIFC and ADGM Frameworks

Where the dispute falls within the jurisdiction of the DIFC or ADGM, their own statutory and procedural frameworks may apply.

DIFC decisions are particularly useful because the DIFC Courts have already dealt with:

cyber-fraud;

electronic payment instructions;

cryptocurrency;

payment platforms;

digital assets; and

allocation of risk between financial institutions and customers.

3. Nature of an Electronic Payment System Dispute

Electronic-payment disputes can broadly be divided into six categories.

3.1 Unauthorised payment

This occurs where the customer never authorised the transaction.

Examples include:

hacked internet banking;

forged electronic instructions;

stolen credentials;

employee fraud;

account takeover;

fraudulent payment instructions.

The principal question is whether the bank acted upon a genuine customer mandate.

3.2 Authorised payment induced by fraud

This is different from an unauthorised payment.

For example:

A fraudster deceives a customer into believing that AED 500,000 should be transferred to a particular account.

The customer personally authorises the transfer.

The legal question becomes more complicated because the bank may have received an apparently valid instruction.

The distinction between:

“the customer did not authorise the payment”

and

“the customer authorised the payment but was deceived into doing so”

can materially affect liability.

4. Bank's Duty to Follow the Customer's Mandate

A bank normally has contractual obligations concerning payment instructions.

Where the customer genuinely instructs the bank to make a payment, the bank generally has a duty to execute the instruction according to the applicable banking mandate.

However, the position becomes different where:

the instruction is forged;

the instruction comes from a fraudster;

the bank has reasonable grounds for suspecting fraud;

authentication procedures are defective;

the bank ignores established transaction procedures; or

the bank's own negligence facilitates the loss.

5. Case Law

Case 1 — Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004

This is one of the most important UAE-region authorities concerning electronic payment fraud.

Facts

Aegis Resources maintained a banking relationship with Union Bank of India in the DIFC.

Fraudsters obtained access to Aegis's email system and sent fraudulent payment instructions to the bank.

The bank processed two fraudulent payments totalling approximately USD 1.067 million.

Aegis argued that the payment instructions were not authorised by it.

Decision

The DIFC Court concluded that the payments were unauthorised and that the bank had acted outside its mandate.

The Court also found that the bank had reasonable grounds for believing that the payment instructions represented an attempt to misappropriate Aegis's money.

The bank therefore breached its duty of care.

Importance

The case establishes several highly important principles.

First, an electronic payment instruction is not automatically valid merely because it comes from an apparently authorised email address.

Secondly, an electronic instruction generated by a fraudster can be analogous to a forged cheque.

Thirdly, a bank's contractual protections will not necessarily exclude liability for negligent conduct.

Fourthly, established transaction procedures matter.

If a bank normally expects:

fax confirmation;

telephone confirmation;

supporting documents; or

other verification,

the unexplained absence of those safeguards can become a fraud indicator.

Principle

Electronic authentication is not necessarily equivalent to actual customer authorisation.

This is particularly important in UAE disputes involving:

email compromise;

business-email compromise;

corporate payment fraud;

phishing; and

fraudulent wire transfers.

6. Case 2 — Dubai Court of Cassation, Judgment No. 562 of 2016

This case concerned a bank transfer based upon a forged fax instruction.

Facts

A customer alleged that a bank had transferred money from the customer's account on the basis of a forged faxed instruction.

The customer argued that the bank should have undertaken additional verification before executing the transfer.

The bank relied upon an indemnity concerning fax instructions.

Decision

The Dubai Court of Cassation upheld the effectiveness of the contractual indemnity in the circumstances because the bank had not been shown to have committed fraud or gross error.

Importance

This case demonstrates an important counterbalance to cases such as Aegis.

A bank is not automatically liable merely because an electronic or remotely transmitted instruction later proves fraudulent.

The court may examine:

contractual risk allocation;

indemnity provisions;

bank procedures;

whether the bank committed gross negligence;

whether fraud was established; and

whether the contractual protection applies.

Principle

Electronic-payment liability depends heavily upon the precise contractual allocation of risk and the degree of fault established against the bank.

This is especially important for corporate customers that sign:

electronic-banking agreements;

fax indemnities;

digital-payment mandates;

corporate banking authorisations; and

cybersecurity undertakings.

7. Case 3 — Dubai Court of Cassation: SIM-Swap Fraud and Unauthorised Transactions

A significant Dubai Court of Cassation decision concerned SIM-swap fraud resulting in unauthorised banking transactions.

Facts

A fraudster obtained a replacement SIM card associated with the customer's mobile number.

The replacement SIM was then used to obtain authentication information and facilitate banking transactions.

Approximately AED 1.5 million was transferred through a series of transactions.

The dispute concerned the respective responsibility of the bank and telecommunications provider.

Decision

The Dubai Court of Cassation upheld liability against the relevant institutions in circumstances where failures in security and identity verification facilitated the fraudulent transactions.

Importance

The decision illustrates that electronic-payment liability can extend beyond the immediate payment itself.

The causal chain can be:

identity-verification failure → SIM replacement → OTP interception → banking access → unauthorised payment → financial loss.

Therefore, liability may involve several service providers.

Principle

A payment institution cannot necessarily avoid responsibility merely by showing that an OTP was used.

The court may examine:

how the OTP was obtained;

whether identity was properly verified;

whether account-security procedures were followed;

whether transaction limits were respected;

whether unusual transactions were detected; and

whether the institution's security failures materially caused the loss.

8. Case 4 — Dubai Court Proceedings Concerning AED 9.5 Million SIM-Swap Fraud

Another significant Dubai banking dispute concerned approximately AED 9.5 million transferred from a customer's account following a SIM-swap fraud.

Facts

The customer's mobile identity was compromised and the fraudsters obtained the ability to receive authentication communications.

The fraud resulted in substantial unauthorised transfers.

The litigation examined the responsibilities of the bank and telecommunications infrastructure involved in the authentication chain.

Decision

The Dubai Court of Cassation ultimately imposed liability upon the bank in the circumstances reported in the case.

Importance

The case demonstrates that:

OTP authentication is not conclusive proof of customer authorisation.

A bank may need to demonstrate that the authentication mechanism was used within a properly secured system.

For example:

If a fraudster obtains an OTP because the bank or telecommunications provider failed to properly verify identity during a SIM replacement, simply proving that the OTP was subsequently entered may not dispose of the customer's civil claim.

Principle

The court may examine the entire authentication chain, rather than treating one authentication event as conclusive.

9. Case 5 — Olave v Oleesa [2025] DIFC SCT 542

This is a particularly useful recent payment-platform decision.

Facts

The claimant provided payment-collection and consolidation services through an electronic platform.

The platform allowed businesses to receive payments and manage corporate cards and expenses.

Credit-card payments could be transmitted into an electronic wallet.

The dispute concerned chargebacks generated by customers disputing payments.

Decision

The DIFC Small Claims Tribunal concluded that the payment facilitator had acted according to the parties' contractual arrangements and applicable chargeback procedures.

The defendant remained liable for the relevant amounts.

Importance

This case demonstrates that electronic-payment disputes are not limited to hacking or unauthorised transactions.

They also include chargeback allocation.

The contractual framework may determine:

who bears chargeback losses;

who must provide evidence;

who must challenge the chargeback;

the time limit for challenging it;

whether the payment facilitator acted according to scheme rules; and

whether the merchant must reimburse the payment provider.

Principle

A payment platform's liability is strongly influenced by its contractual role and the agreed payment/chargeback protocol.

10. Case 6 — Gate Mena DMCC / Huobi v Tabarak Investment Capital Ltd [2023] DIFC CA 002

Although this case concerned cryptocurrency rather than an ordinary bank transfer, it is highly relevant to modern electronic-payment disputes.

Facts

The dispute involved cryptocurrency, contractual obligations and the custody/control of digital assets.

The litigation required the court to consider the legal consequences of transactions involving Bitcoin and digital-asset intermediaries.

Importance

Electronic payment systems increasingly include:

cryptocurrency;

stablecoins;

digital wallets;

tokenised assets;

digital exchanges; and

blockchain-based transfers.

The case demonstrates that civil courts can analyse digital assets through established legal principles concerning:

contractual obligations;

possession/control;

custody;

transfer;

breach;

remedies; and

fiduciary or intermediary responsibilities where applicable.

Principle

The digital character of the payment mechanism does not remove the transaction from ordinary civil-law analysis.

The court can examine the underlying legal relationship even where the asset exists digitally.

11. Case 7 — Gate Mena DMCC / Huobi v Tabarak Investment Capital Ltd [2024] DIFC DEC 002

The later Digital Economy Court proceedings provide further insight into digital-payment and digital-asset disputes.

Importance

The court considered questions surrounding contractual duties, reasonable care, risk allocation and digital assets.

The case is important because modern payment systems increasingly blur the boundary between:

payment;

custody;

investment;

exchange;

technology services; and

digital asset management.

Principle

Where a payment intermediary or digital-asset provider undertakes specific contractual responsibilities, the court may analyse the parties' agreement to determine:

what the provider promised;

what risks were allocated;

what level of care was contractually required;

whether the provider breached its obligations; and

whether the alleged loss was caused by that breach.

12. Case 8 — GFH Capital Ltd v David Lawrence Haigh [2014] DIFC CFI 020

This case was not a conventional electronic-payment-system case, but it is relevant to fraudulent payment trails.

Facts

The dispute involved substantial financial transfers, false invoices and payment instructions.

The court examined the movement of funds and documentary evidence surrounding fraudulent transactions.

Importance

Electronic-payment disputes frequently require reconstruction of the money trail.

The court may therefore need to examine:

bank statements;

invoices;

payment instructions;

emails;

accounting records;

transfer histories;

beneficial ownership;

recipient accounts; and

documentary inconsistencies.

Principle

Financial transactions must be analysed through the complete evidentiary chain rather than by examining an individual payment in isolation.

13. Electronic Payment Fraud and the Question of Authorisation

One of the most important distinctions is between:

A. Completely unauthorised payment

The customer never instructed the bank.

Example:

A hacker sends an email payment instruction.

B. Fraudulently authenticated payment

The bank receives credentials that appear valid but the credentials were obtained fraudulently.

Example:

A fraudster obtains:

username;

password;

OTP; and

device access.

C. Customer-authorised payment induced by fraud

The customer personally approves the transaction but was deceived.

Example:

A fraudster impersonates a supplier and convinces the customer to pay a false invoice.

These three situations should not automatically be treated identically.

14. Duty of Care of Banks

A bank's civil responsibility may arise where it fails to take reasonable precautions appropriate to the circumstances.

Relevant factors can include:

14.1 Unusual transaction

A payment dramatically inconsistent with the customer's normal activity may require greater scrutiny.

14.2 Unusual beneficiary

A payment to a previously unknown beneficiary can constitute a warning sign depending on the circumstances.

14.3 Change in payment method

For example:

Normal procedure:

email + fax + telephone confirmation.

New procedure:

email only.

The deviation may be significant.

14.4 Large-value transaction

A high-value transfer can increase the importance of appropriate authentication and fraud monitoring.

14.5 Multiple red flags

A single suspicious circumstance may not establish negligence.

Several indicators together may materially change the analysis.

15. Customer's Responsibilities

Customers also have obligations.

They should normally:

protect passwords;

protect authentication devices;

avoid sharing OTPs;

maintain cybersecurity;

report suspicious transactions;

promptly report loss of devices;

follow contractual security procedures;

maintain internal payment controls; and

notify the bank of suspected fraud.

A corporate customer may additionally have responsibilities concerning:

segregation of payment duties;

dual authorisation;

approval limits;

employee access;

cybersecurity;

supplier verification; and

payment reconciliation.

Failure by the customer can lead to arguments concerning:

contributory negligence;

contractual risk allocation;

causation; and

reduction of damages.

16. SIM-Swap Fraud

SIM-swap fraud is particularly significant because electronic payment systems frequently depend upon mobile authentication.

The typical sequence is:

Identity theft

Fraudulent SIM replacement

OTP interception

Banking authentication

Unauthorised payment

Financial loss

The legal analysis should therefore identify every participant in the chain.

Potentially relevant parties include:

bank;

telecommunications company;

payment processor;

customer;

merchant; and

fraudster.

The court must then identify which failure actually caused the loss.

17. OTP Is Not Necessarily Conclusive

One of the most important practical lessons from modern electronic-payment litigation is that:

“An OTP was used” does not necessarily mean “the customer authorised the payment.”

An OTP can be obtained through:

SIM swapping;

malware;

phishing;

social engineering;

compromised devices;

account takeover; or

interception.

Consequently, the court may investigate how the authentication credential was obtained.

18. Chargeback Disputes

Chargebacks produce a different category of civil dispute.

A customer may claim:

goods were not delivered;

goods were defective;

transaction was fraudulent;

payment was duplicated;

merchant breached the contract.

The card network or payment provider may then reverse the transaction.

A merchant may dispute the chargeback.

The legal dispute may therefore concern:

the merchant agreement;

card-network rules;

payment-service terms;

evidence supplied;

time limits;

allocation of risk; and

contractual indemnities.

Olave v Oleesa demonstrates the importance of the contractual allocation of responsibility in this context.

19. Digital Wallet Disputes

Digital-wallet disputes may involve:

unauthorised access;

wallet hacking;

frozen balances;

failed withdrawals;

mistaken transfers;

chargebacks;

account suspension;

identity verification; and

termination of wallet services.

The legal analysis depends upon the nature of the wallet.

It may be:

a payment wallet;

a stored-value facility;

a banking product;

a cryptocurrency wallet; or

a technological intermediary.

The classification affects the applicable legal obligations.

20. Payment Platforms as Intermediaries

A payment platform may not necessarily be the final recipient or payer.

It may simply:

receive a payment request;

authenticate the transaction;

transmit payment information;

hold funds temporarily;

communicate with a card network;

process chargebacks; and

settle funds with a merchant.

Therefore, liability must be determined according to the platform's precise contractual function.

A platform should not automatically be treated as a bank.

21. Contractual Limitation of Liability

Electronic-payment contracts often contain:

indemnities;

exclusion clauses;

fraud provisions;

authentication provisions;

customer-security obligations;

transaction limits;

liability caps.

Courts will examine the wording and circumstances of such provisions.

The important question is not simply:

“Does the contract contain an indemnity?”

The question is:

“Does the indemnity clearly and legally allocate this particular risk?”

A broadly worded fraud-risk clause may not necessarily protect a bank from liability for its own negligence, particularly where the applicable law requires clear language.

The reasoning in Aegis is particularly important in this regard.

22. Causation

Causation is frequently the decisive issue.

Consider:

Bank security failure

Fraudster obtains access

Unauthorised payment

Customer suffers financial loss

If the security failure materially caused the payment, liability may follow.

But suppose:

the bank complied with all contractual procedures;

the customer voluntarily disclosed credentials;

the customer ignored repeated fraud warnings; and

the bank had no reasonable grounds to suspect fraud.

The causation and fault analysis may be substantially different.

23. Contributory Negligence

Electronic-payment disputes frequently involve competing allegations of negligence.

Bank's alleged negligence

inadequate authentication;

failure to detect unusual activity;

failure to verify identity;

failure to respect transaction limits;

failure to investigate suspicious instructions.

Customer's alleged negligence

weak password;

disclosure of OTP;

failure to update contact details;

failure to report SIM loss;

failure to verify beneficiary;

failure to report suspicious transactions.

The court may therefore assess the conduct of all relevant participants.

24. Evidentiary Issues

Electronic-payment litigation is heavily dependent upon technical evidence.

Important evidence may include:

Bank evidence

transaction logs;

authentication records;

device fingerprints;

IP addresses;

OTP records;

login histories;

beneficiary records;

fraud-monitoring alerts.

Telecommunications evidence

SIM replacement records;

identity-verification documents;

call records;

SMS delivery records;

network information.

Customer evidence

bank statements;

emails;

mobile records;

internal approval records;

accounting records;

correspondence.

Expert evidence

Experts may reconstruct:

when access occurred;

from which device;

how authentication occurred;

whether the transaction was technically authorised;

whether security controls operated properly.

25. Digital Evidence Does Not Automatically Establish Legal Liability

A transaction log may establish:

“The system received an OTP.”

It does not necessarily establish:

“The account holder personally authorised the transaction.”

Similarly, an IP address may show that a transaction originated from a particular network, but it may not conclusively establish who operated the device.

Therefore, courts may consider the entire evidentiary picture.

26. Electronic Payment Disputes and the UAE Civil Code

Several civil-law concepts become particularly important.

26.1 Contractual liability

The bank or payment provider may breach an express or implied contractual obligation.

26.2 Tort liability

A failure to take reasonable precautions may constitute an unlawful act causing damage.

26.3 Causation

The claimant must generally establish a causal relationship between the wrongful conduct and the loss.

26.4 Compensation

Compensation aims to address legally recognised loss resulting from the wrongful conduct.

26.5 Abuse of rights

Article 106 of the UAE Civil Transactions Law may become relevant where a party exercises a legal right in an abusive manner.

26.6 Good faith

Contractual performance must be examined within the broader principle of good faith.

27. Electronic Payment Dispute Matrix

DisputeMain Legal QuestionPotentially Responsible Party
Hacked email transferWas the instruction genuinely authorised?Bank/customer depending on facts
SIM-swap fraudWho failed to secure authentication?Bank/telecom/customer
Stolen cardWho failed to prevent or report misuse?Bank/customer/merchant
Fake OTP transactionWas authentication genuinely attributable to customer?Depends on evidence
Duplicate paymentWho caused the duplication?Bank/payment provider/merchant
Wrong beneficiaryWas the instruction authorised and correctly executed?Depends on circumstances
ChargebackWho bears contractual chargeback risk?Merchant/payment provider/customer
Digital wallet theftWho controlled the wallet and security credentials?Wallet provider/customer/third party
Cryptocurrency transferWho had contractual custody/control obligations?Exchange/custodian/customer
Payment-platform failureWhat service did the platform contractually undertake?Platform or counterparty

28. Comparison of Important Cases

CasePayment ProblemCore Principle
Aegis Resources v Union BankHacked email payment instructionsBank liable where unauthorised payments and reasonable fraud indicators existed
Dubai Cassation 562/2016Forged fax transferContractual indemnity may operate where bank was not fraudulent or grossly negligent
Dubai SIM-swap decisionUnauthorised banking transactionsSecurity and identity-verification failures can create institutional liability
AED 9.5m SIM-swap litigationAccount takeoverOTP usage alone does not necessarily establish customer authorisation
Olave v OleesaChargebacksContractual allocation of payment-platform risk is important
Gate Mena v TabarakDigital assetsDigital transactions remain subject to ordinary contractual and civil-law principles
Gate Mena v Tabarak (2024)Digital-asset obligationsContractual risk allocation and reasonable-care questions remain central
GFH Capital v HaighFraudulent payment trailFinancial-document and transaction reconstruction can establish fraudulent transfers

29. Practical Test for UAE Electronic Payment Disputes

A court can be approached with the following sequence of questions:

Step 1 — Identify the payment

What exactly happened?

bank transfer;

card transaction;

wallet transfer;

online payment;

cryptocurrency transfer;

direct debit?

Step 2 — Identify the instruction

Who initiated it?

Step 3 — Determine authorisation

Did the customer actually authorise it?

Step 4 — Examine authentication

How was the transaction authenticated?

Step 5 — Examine security

Were appropriate security procedures followed?

Step 6 — Identify red flags

Were there:

unusual amounts;

unusual beneficiaries;

unusual locations;

new devices;

changed SIM cards;

suspicious emails;

repeated failed authentication attempts?

Step 7 — Examine the contract

What did the customer agree to?

Step 8 — Examine regulatory obligations

Did the institution comply with applicable banking/payment-security requirements?

Step 9 — Examine causation

Which failure actually caused the financial loss?

Step 10 — Examine customer conduct

Did the customer contribute to the loss?

Step 11 — Quantify damage

What amount was actually lost?

Step 12 — Consider recovery

Was any amount recovered from:

the receiving bank;

the fraudster;

the payment processor;

insurance;

a chargeback; or

another source?

30. Corporate Electronic Payment Disputes

Corporate payment fraud requires special attention.

A company may have:

several authorised signatories;

multiple bank accounts;

different transaction limits;

employees with payment authority;

ERP systems;

email approval;

dual authorisation;

treasury departments.

If an employee's email is compromised, the court may examine the company's internal controls.

For example:

CFO email compromised → fraudulent invoice → payment instruction → bank executes transfer.

The court may then examine both:

bank controls

and

company controls.

31. Business Email Compromise

Business Email Compromise is one of the most significant electronic-payment risks.

The fraudster may:

compromise the customer's email;

study previous correspondence;

identify suppliers;

imitate invoice formats;

issue a fraudulent payment instruction;

intercept bank responses;

redirect funds.

Aegis is particularly important because it demonstrates how a court can examine the entire transaction history to determine whether the bank should have recognised suspicious circumstances.

32. Fraudulent Beneficiary Accounts

Sometimes the payment itself is correctly authorised but the beneficiary information has been manipulated.

For example:

A customer believes:

“Pay Supplier A.”

But the account number has been changed to:

“Fraudster's Account B.”

The legal question may become whether:

the customer supplied the incorrect account;

the bank failed to authenticate the beneficiary;

the payment platform failed to detect the mismatch; or

the fraud occurred entirely outside the bank's responsibility.

The precise contractual and technical arrangements therefore matter.

33. Wrongful Payment by the Bank

Where a bank pays money without proper authority, several legal consequences may arise.

The customer may seek:

restoration of the account balance;

damages;

interest;

consequential losses where legally recoverable;

costs; and

other appropriate remedies.

Aegis illustrates the importance of distinguishing between:

unauthorised payment

and

properly authorised payment.

34. Payment Provider's Liability

Payment providers should distinguish between:

Technical failure

The system incorrectly processes a transaction.

Security failure

The system permits unauthorised access.

Contractual failure

The provider fails to perform a promised service.

Fraudulent transaction

A third party manipulates the system.

Each category can produce a different liability analysis.

35. Future Development of UAE Electronic Payment Law

The UAE's electronic-payment environment is likely to produce increasingly complex civil litigation involving:

artificial intelligence fraud;

deepfake payment instructions;

biometric authentication;

voice cloning;

instant payments;

open banking;

embedded finance;

digital currencies;

stablecoins;

tokenised deposits;

smart contracts;

automated payment systems;

cross-border payment fraud;

algorithmic fraud detection; and

real-time payment reversal.

The central legal question will increasingly move from:

“Was the password correct?”

to:

“Was the entire authentication and transaction environment sufficiently reliable to attribute the payment legally to the customer?”

36. Key Legal Principles

The UAE electronic-payment dispute framework can therefore be summarised as follows:

An electronic payment instruction must be analysed for genuine authorisation.

Electronic authentication is evidence of a transaction, but its legal significance depends upon the circumstances.

Banks may owe contractual and, in appropriate circumstances, tortious duties of care.

Fraud-risk clauses and indemnities are important but do not necessarily eliminate liability for negligence or gross fault.

Unusual transactions may create circumstances requiring greater scrutiny.

SIM-swap fraud demonstrates that authentication failures can produce institutional liability.

Chargeback disputes are substantially controlled by the contractual and payment-scheme framework.

Digital assets can generate ordinary contractual and civil-law disputes despite their technological form.

Customer negligence can be relevant to causation and allocation of loss.

Digital evidence must be assessed in its complete technical and factual context.

Payment-platform liability depends upon the precise role undertaken by the platform.

The decisive issue is frequently the causal connection between the security failure and the financial loss.

37. Conclusion

UAE electronic payment system disputes represent an important intersection between traditional civil law and modern financial technology.

The fundamental principles of UAE civil law remain applicable even when the transaction takes place entirely through digital infrastructure.

The courts may therefore examine:

contract → authorisation → authentication → security → fault → causation → damage → contractual risk allocation → contributory conduct → remedy.

The most significant UAE-region authorities demonstrate that there is no universal rule that either the bank or the customer always bears the loss.

The result depends upon the facts.

Aegis Resources v Union Bank of India illustrates circumstances in which a bank may bear the loss from fraudulent electronic payment instructions. Dubai Cassation Judgment No. 562 of 2016 demonstrates the importance of contractual indemnities where the bank has not committed fraud or gross error. The SIM-swap decisions demonstrate that failures in identity and security controls may create liability for financial institutions. Olave v Oleesa demonstrates the importance of contractual allocation of chargeback risk in payment platforms. The Gate Mena/Huobi decisions demonstrate how traditional contractual principles can be applied to digital assets.

Accordingly, the modern UAE civil-law approach to electronic-payment disputes is best understood not as a special body of law completely separate from traditional civil liability, but as an application of established principles of contract, mandate, negligence, causation, evidence, risk allocation and compensation to technologically sophisticated payment systems.

LEAVE A COMMENT