Civil Law And Uae Data Ownership Civil Law Theories .

Civil Law and UAE Data Ownership — Civil Law Theories

1. Introduction

Data ownership is a difficult concept in modern civil law because “data” is not always equivalent to a traditional movable or immovable property asset.

A database may contain:

personal information;

customer information;

financial records;

business intelligence;

trade secrets;

intellectual property;

metadata;

behavioural information;

employee information;

commercially generated information.

The important legal question is therefore not simply:

“Who owns the data?”

but rather:

“What legal rights does each person or organisation have in relation to the data, and what legal basis protects those rights?”

This distinction is particularly important in the UAE because personal-data protection, confidentiality, intellectual property, contractual rights and civil obligations may protect different aspects of the same dataset.

The federal UAE Personal Data Protection framework is principally established by Federal Decree-Law No. 45 of 2021, while DIFC has its own data-protection regime. DIFC case law has developed useful principles concerning personal data, confidential information, databases and commercial information.

2. The Central Proposition: Data Is Not Necessarily “Owned”

Traditional property law generally asks whether something is capable of being owned.

Data creates a more complicated situation.

Consider a customer database containing:

Name + telephone number + financial information + transaction history + investment preferences.

Different legal interests may coexist:

InterestPotential holder
Personal identity informationData subject
Right to privacy/data protectionData subject
Database structureDatabase/controller/business
ConfidentialityBusiness/controller
Copyright in database compilationPotentially creator/rightsholder
Trade-secret protectionBusiness
Contractual controlContracting parties
Processing authorityController/processor
Commercial valueBusiness/data controller
Access/correction rightsData subject

Therefore, UAE civil-law analysis is better expressed as:

Data rights rather than absolute data ownership.

3. Main Civil-Law Theories of Data Ownership

There are several competing theories.

Theory 1 — Data as Property

Under the property theory, data is treated as an economic asset capable of being controlled, transferred, licensed or protected.

This approach is particularly attractive for:

commercial databases;

proprietary datasets;

machine-generated datasets;

valuable business intelligence;

digital assets.

However, personal data presents difficulties because treating an individual's personal information simply as the property of a company can conflict with privacy and data-protection principles.

4. Theory 2 — Data as a Personality Right

Under the personality-right theory, personal information is closely connected to the individual.

The individual is not merely an economic owner.

Instead, the individual has rights relating to:

privacy;

identity;

control over certain processing;

access;

correction;

lawful processing;

protection from misuse.

This approach fits personal-data regulation better than a simple property model.

The UAE Personal Data Protection Law reflects this rights-based approach by regulating processing and recognising rights and protections associated with data subjects.

5. Theory 3 — Data as Confidential Information

A third theory treats data according to its confidential character.

The crucial question becomes:

Is the information confidential and has another person misused it?

This is particularly relevant for:

customer lists;

financial information;

pricing information;

investment strategies;

business plans;

proprietary databases.

The DIFC Court's decision in AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060 provides an important illustration.

The court distinguished between:

genuinely confidential compiled client information; and

information such as publicly available or individually known contact details.

The court held that confidentiality depends upon the nature, context, acquisition and use of the information. (DIFC Courts)

6. Theory 4 — Data as Intellectual Property

Another approach is to protect the creation or compilation of data, rather than saying that every item of data is property.

For example:

A company spends AED 10 million creating a sophisticated database containing:

customer information;

market information;

pricing history;

analytics;

categorisation;

proprietary algorithms.

The underlying facts may not necessarily be exclusively owned.

But legal protection may arise from:

copyright;

database rights where applicable;

confidential-information law;

trade-secret protection;

contract;

unfair competition principles.

Thus:

The database and the individual pieces of information within it may have different legal characteristics.

7. Theory 5 — Data as a Contractual Asset

Businesses frequently obtain data under contracts.

For example:

Company A → collects customer information

Company B → processes information

Company C → provides cloud storage

The contract may regulate:

permitted use;

access;

retention;

deletion;

confidentiality;

security;

return of data;

restrictions on commercial exploitation.

In this model, “ownership” may be less important than contractual rights of control and use.

8. Theory 6 — Data as a Controlled Resource

A modern approach views data as a resource subject to multiple overlapping control rights.

For example:

Individual

Controls certain personal-data rights.

Business

Controls its proprietary database.

Processor

Has limited contractual processing authority.

Government

May have statutory access powers.

Court

May order disclosure or preservation.

Third party

May have lawful access under contract or legislation.

Thus, the same dataset can simultaneously be subject to several legally distinct interests.

9. UAE Personal Data Protection Law and Ownership

Federal Decree-Law No. 45 of 2021 should not simply be described as a law declaring that individuals “own” their personal data.

Its structure is more accurately understood as a rights-and-obligations framework governing personal-data processing.

This includes concepts involving:

data subjects;

controllers;

processors;

lawful processing;

consent;

security;

confidentiality;

data-subject rights;

cross-border transfers.

Therefore:

Possession of a database does not automatically give the database holder unrestricted legal authority to use every item of information in it.

10. Controller vs Owner

One of the most important distinctions is:

Controller

The entity determining the purposes and means of processing.

Processor

The entity processing data on behalf of another.

Neither concept should automatically be equated with traditional property ownership.

Example

A UAE hospital stores patient information with a cloud provider.

The hospital may determine:

why the data is collected;

how it is used;

who may access it.

The cloud provider merely processes or stores it according to contractual and legal instructions.

Therefore:

Physical possession of data does not necessarily equal legal ownership or unrestricted control.

11. Case Law 1 — TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006

This is one of the most important UAE/DIFC cases for understanding the confidential-information theory of data rights.

TVM Capital provided confidential business and financial information to Hashemi under a confidentiality agreement.

The information included substantial information concerning the business and financial affairs of ProVita.

The defendant was found to have breached the confidentiality agreement and Article 37 of the DIFC Law of Obligations.

The Court of Appeal upheld the damages award of:

AED 250,000. (DIFC Courts)

The Court explained that the relevant information was broader than merely statutory “trade secrets”; the contractual definition covered information supplied under the confidentiality agreement.

Importantly, the court recognised that the value of confidentiality itself could constitute a legally compensable interest even when the precise monetary value could not be calculated with certainty. (DIFC Courts)

Data-ownership significance

This supports the proposition that:

Data can have legally protected value without necessarily being traditional property.

12. Case Law 2 — AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060

This is perhaps the most directly useful modern UAE/DIFC authority for commercial database ownership theories.

AES alleged misuse of:

client lists;

customer information;

assets-under-management information;

fee information;

investment portfolios;

risk profiles;

confidential client data.

The court held that client lists can constitute confidential information, particularly where they contain commercially valuable information compiled through substantial effort and are not publicly available in aggregated form. (DIFC Courts)

However, the court also distinguished individual contact information.

For example:

public LinkedIn connections;

readily accessible contact details;

information personally known by employees.

Such information may not automatically belong to the employer or qualify as confidential. (DIFC Courts)

Principle

A database may receive stronger legal protection than isolated pieces of information contained within it.

This is one of the most important principles for data ownership analysis.

13. Case Law 3 — The Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051 and CFI 085

This is particularly important for the personal-data theory.

The case concerned the interpretation of the DIFC Data Protection Law and the meaning of personal data.

The Court considered principles concerning whether information held by a data controller constitutes the individual's personal data.

The judgment discussed the approach that personal data is connected to information concerning the identifiable individual and is not simply every document in which the individual's name happens to appear. (DIFC Courts)

The Court considered the concept of a relevant filing system and the distinction between information genuinely relating to an individual and documents merely connected with an individual.

Principle

Personal data is not equivalent to every item of information that happens to mention a person.

Data-ownership significance

This reinforces a rights-based theory rather than an absolute property theory.

14. Case Law 4 — Elseco Limited v Pierre-Eric Daniel Bernard Lys [2016] DIFC CA 011

Elseco involved allegations concerning the use of customer information from the company's database.

The case considered allegations that customer contact information from Elseco's database had been used for competing purposes. The court ultimately rejected the particular complaint concerning misuse of the customer information. (DIFC Courts)

Importance

The case demonstrates that:

The mere existence of a company database does not automatically establish that every piece of information connected with the company's customers is legally proprietary or confidential.

The claimant still needs to establish:

what information was involved;

its legal character;

how it was obtained;

whether it was confidential;

whether it was misused.

15. Case Law 5 — Linux v Lizeth [2022] DIFC SCT 237

This case involved a confidentiality agreement and a digital platform.

The claimant alleged that information had been placed on a public link and that this exposed the project's database and confidential information to third parties.

The court considered the allegations concerning:

NDA obligations;

confidential information;

third-party software;

database exposure;

publication through a digital platform.

Ultimately, the particular allegations did not establish the claimed NDA breach on the evidence. (DIFC Courts)

Principle

Digital storage does not eliminate the need to prove the underlying contractual or confidentiality obligation.

This is particularly relevant to cloud databases.

16. Case Law 6 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2023] DIFC CA 002

Gate Mena is important because it deals with confidential information in the context of digital assets.

The Court of Appeal considered the meaning and misuse of confidential information and referred to the circumstances in which information loses confidentiality or may lawfully be disclosed. (DIFC Courts)

The underlying dispute involved digital assets and allegations concerning the handling and misuse of information.

Principle

Confidentiality is not absolute.

Information may cease to be confidential or disclosure may be justified in circumstances recognised by law.

Data-ownership significance

This supports a conditional-rights theory:

The holder of information does not necessarily possess an unlimited permanent property right in the information.

17. Case Law 7 — AES Middle East Insurance Broker LLC v GSB Capital Ltd — Preservation Order

A further important procedural aspect of the AES litigation was the court's preservation order.

The court prohibited the respondent from:

accessing;

passing on;

using;

deriving new materials from;

deploying confidential information.

It also required preservation of electronic documents and metadata containing the confidential information. (DIFC Courts)

Principle

Data rights can be protected through injunctive and preservation remedies, not merely monetary compensation.

This is especially important where the value of data lies in its continued secrecy.

18. Case Law 8 — Dimensions / AIMS Arbitration

A DIFC-seated arbitration concerning AIMS, CDS and ICM provides another useful example of contractual and confidential-information protection.

The tribunal found breaches involving:

contractual obligations;

use of confidential information;

trade secrets;

development and sale of products.

Damages were ordered to be assessed separately. (DIFC Courts)

Principle

Data may have multiple legal classifications simultaneously:

contractual information + confidential information + trade secret + commercially valuable asset.

This demonstrates why a single “ownership” label may be inadequate.

19. Six Major Data Ownership Theories Compared

TheoryCore ideaMain protection
Property theoryData is an economic assetProperty/civil law
Personality theoryPersonal data is connected to the individualPrivacy/data protection
Confidentiality theoryValuable information deserves secrecyConfidentiality law
IP theoryDatabase creation/structure can be protectedIntellectual property
Contract theoryParties define rights of use/controlContract
Resource/control theoryMultiple parties possess different rightsMixed legal framework

20. Personal Data vs Commercial Data

This distinction is fundamental.

Personal data

Example:

Name + Emirates ID + health information.

The primary concern is:

privacy;

lawful processing;

security;

individual rights.

Commercial database

Example:

50,000 customer records + purchasing history + pricing analysis + proprietary segmentation.

The business may have:

confidentiality rights;

contractual rights;

IP-related rights;

trade-secret protection.

Therefore:

Personal data should not automatically be treated as the property of the company that collected it.

21. Database Ownership

Suppose Company A creates a database containing 100,000 customers.

The database contains:

customer names;

addresses;

purchase history;

customer preferences;

internally generated classifications.

There are potentially several layers.

Layer 1 — Customer identity

The individual remains the data subject.

Layer 2 — Personal data

Subject to data-protection regulation.

Layer 3 — Compilation

The company's investment in assembling and organising the database may receive separate legal protection.

Layer 4 — Proprietary analysis

Company-generated algorithms and classifications may receive IP/confidentiality protection.

Layer 5 — Contract

Customer agreements may restrict use.

Thus:

“Company owns database” does not mean “company owns every legal interest in every item of information inside it.”

22. Employee-Generated Data

Consider an employee who creates:

customer lists;

sales reports;

market analyses;

spreadsheets.

The ownership analysis should examine:

employment contract;

intellectual-property provisions;

confidentiality clauses;

applicable law;

whether information is personal data;

whether the information was created within employment duties;

whether the employee merely memorised information;

whether the information was publicly available.

AES is particularly useful because the DIFC Court distinguished proprietary client lists from ordinary personal or publicly available contacts. (DIFC Courts)

23. Customer Data and Employer Rights

Suppose a financial adviser leaves Company A.

The adviser remembers:

“Customer X is wealthy and prefers conservative investments.”

Can Company A automatically claim ownership of the adviser's personal knowledge?

Not necessarily.

But if the adviser takes:

Company A's confidential spreadsheet containing 5,000 clients, AUM, fees, investment strategies and risk profiles,

the legal position is substantially different.

AES provides a strong illustration of this distinction. (DIFC Courts)

24. Data Ownership in Cloud Computing

Cloud storage creates another important problem.

Example

Company A owns a database.

Company B operates the cloud platform.

Company C provides cybersecurity services.

Who owns the data?

The better answer is:

Ownership/control depends upon the underlying legal rights and contracts; physical possession by the cloud provider does not automatically transfer ownership.

The cloud provider may have:

storage rights;

processing authority;

security obligations;

without obtaining unrestricted commercial ownership of the underlying information.

25. Data as a Bundle of Rights

A sophisticated UAE civil-law theory can therefore represent data as:

Data = Bundle of Rights

Including:

access;

use;

exclusion;

correction;

deletion;

disclosure;

confidentiality;

licensing;

processing;

transfer;

commercial exploitation;

security;

preservation.

Different persons may hold different rights.

26. Data Ownership and Contract

Contracts should ideally define:

1. Who controls data?

2. Who may process it?

3. For what purpose?

4. Who may disclose it?

5. Who owns derived data?

6. Who owns analytics?

7. What happens after termination?

8. Must data be returned?

9. Must data be deleted?

10. Who bears breach liability?

This is particularly important for:

SaaS agreements;

cloud contracts;

fintech agreements;

employment contracts;

outsourcing agreements;

data-processing agreements;

joint ventures.

27. Derived Data

A difficult issue is derived data.

Suppose:

Customer provides:

Transaction history.

Company creates:

Credit-risk score.

Who has rights in the credit-risk score?

The answer may depend upon:

applicable data-protection law;

contract;

intellectual property;

confidentiality;

how the derived information relates to the individual;

whether it constitutes personal data.

The derived information may therefore not be treated identically to the original data.

28. Aggregated Data

Suppose Company A combines:

1 million customer records;

removes direct identifiers;

creates market statistics.

Example:

“42% of customers aged 25–35 prefer Product X.”

The legal analysis may differ from the underlying identifiable customer information.

However, aggregation or anonymisation must be legally effective; simply removing names does not automatically eliminate all data-protection or confidentiality considerations.

29. Anonymisation vs Pseudonymisation

Anonymisation

Information is processed so that individuals are no longer identifiable in the legally relevant sense.

Pseudonymisation

Identifiers are replaced but re-identification may remain possible.

This distinction is important because pseudonymised information may continue to attract personal-data protection.

30. Data Ownership and Artificial Intelligence

AI creates a new data-ownership problem.

Suppose:

Company A provides customer data

AI model processes it

Model generates predictions

Company B receives the analytics

Questions arise:

Who controls the original data?

Who controls the model?

Who owns the generated analysis?

Does the output contain personal data?

Can the output be commercially exploited?

Does the contract allocate rights?

Can the processor train an AI system using the information?

These questions demonstrate why traditional property concepts alone are insufficient.

31. Data Ownership and Blockchain

Blockchain creates another problem.

Once information is recorded on a distributed ledger:

multiple nodes may hold copies;

deletion may be technically difficult;

control may be decentralised;

the identity of the controller may be unclear.

Therefore, blockchain data may require a combination of:

contract;

data protection;

confidentiality;

digital-asset law;

civil obligations.

Gate Mena demonstrates how DIFC courts may encounter confidentiality and digital-asset questions together. (DIFC Courts)

32. Remedies for Unauthorised Data Use

Potential civil remedies may include:

Injunction

Prevent further use or disclosure.

Preservation order

Prevent destruction or alteration of data.

Delivery-up / deletion

Require return or deletion where legally appropriate.

Damages

Compensate proven loss.

Negotiating damages

Particularly relevant where the value of a confidentiality restriction is difficult to quantify.

Account of profits

Potentially relevant depending on the legal cause of action and applicable law.

TVM Capital is particularly significant for the damages approach to misuse of confidential information. (DIFC Courts)

33. Data Ownership and Damages

Suppose Company A's database is unlawfully copied.

The company proves:

database creation costs = AED 2 million;

commercial value = AED 5 million;

actual loss = AED 1 million;

defendant's profits from misuse = AED 1.5 million.

The court does not simply add every number.

It must identify the appropriate legal remedy and avoid double recovery.

The value of the database, the loss caused by misuse, and the defendant's benefit are different valuation concepts.

34. Data Ownership and Confidentiality

A particularly important UAE/DIFC principle is:

Confidentiality may protect information without creating absolute ownership over the information.

For example, AES recognised that client lists could be confidential because of:

commercial value;

compilation effort;

non-public nature;

sensitivity;

usefulness to competitors. (DIFC Courts)

This is different from saying:

“AES owned every fact about every customer.”

The legal protection arises from the relationship, circumstances and characteristics of the information.

35. Data Ownership and Public Information

Information available publicly generally presents a weaker ownership/confidentiality claim.

Example:

Company's public telephone number.

It is difficult to argue that the company has an exclusive proprietary right in the number merely because it appears in its database.

But:

Customer's private number + investment portfolio + AUM + risk profile

is materially different.

AES expressly made this distinction between public/ordinary contact information and confidential compiled client information. (DIFC Courts)

36. Data Ownership and Personal Privacy

A company may spend millions of dirhams collecting customer information.

That does not necessarily mean:

“The company owns the customer's identity.”

The company may instead have legally limited authority to process the information for specified purposes.

This is one of the strongest arguments against a pure property theory of personal data.

37. Advanced Legal Model

A useful UAE model is:

Personal Data

→ Data-subject rights

Commercial Data

→ Contract/confidentiality/IP

Database

→ Compilation/contractual/proprietary interests

Derived Data

→ Contract + privacy + IP + confidentiality

Trade Secret

→ Confidentiality/trade-secret protection

Digital Asset Data

→ Contract + digital-asset + property/obligation principles

Therefore:

The legal character of data depends upon what the data is, who generated it, how it was obtained, how it is used and which legal relationship governs it.

38. Case-Law Principles Table

CaseData-ownership theoryMain principle
TVM Capital v Hashemi [2014] DIFC CA 006ConfidentialityConfidential information has independently protectable economic value
AES v GSB Capital [2023] DIFC CFI 060Database/confidentialityCompiled client data can be confidential; public information may not be
DFSA v Commissioner of Data Protection [2018] DIFC CFI 051/085Personality/data rightsPersonal data is not every document mentioning an individual
Elseco v Lys [2016] DIFC CA 011Database rightsUse of database information requires proof of the relevant legal protection
Linux v Lizeth [2022] DIFC SCT 237Contract/confidentialityDigital publication does not itself establish an NDA breach
Gate Mena v Tabarak [2023] DIFC CA 002Digital/confidential informationConfidentiality is conditional and depends on legal circumstances
Dimensions arbitrationTrade secrets/contractData can simultaneously be contractual and confidential/trade-secret information

39. Seven Practical Data-Ownership Examples

Example 1 — Customer database

A bank creates a database of 500,000 customers.

Legal position:
The bank may have strong contractual/confidential/database rights, but this does not necessarily mean it owns every personal-data right associated with those customers.

Example 2 — Employee contact list

Employee memorises five customers' telephone numbers.

Legal position:
Much weaker proprietary argument than taking the employer's confidential database.

AES is particularly relevant. (DIFC Courts)

Example 3 — Private financial information

Employee downloads:

Customer + AUM + portfolio + fees + risk profile.

Legal position:
Strong confidentiality concerns.

Example 4 — Public LinkedIn connection

Employee uses a publicly visible LinkedIn connection.

Legal position:
Not automatically confidential or proprietary.

AES specifically considered LinkedIn connections and public professional networks. (DIFC Courts)

Example 5 — AI-generated customer profile

Company generates:

“Customer has a 78% probability of purchasing Product X.”

Legal position:
Potentially involves personal data, derived information, contractual rights and AI-related governance.

Example 6 — Blockchain information

A transaction is recorded permanently on a distributed ledger.

Legal position:
Traditional exclusive ownership becomes difficult because multiple participants may hold copies.

Example 7 — Trade-secret database

Company spends AED 5 million developing a proprietary pricing database.

Legal position:
Confidentiality, contractual restrictions and potentially intellectual-property protection may operate together.

40. Major Legal Problems in UAE Data Ownership

1. No single universal ownership concept

Different data categories require different legal treatment.

2. Personal data vs property

Privacy rights cannot always be reduced to economic ownership.

3. Database vs underlying information

A company may protect its compilation without acquiring exclusive rights over every underlying fact.

4. Employee mobility

Businesses must balance legitimate confidentiality protection against employees' general skills and knowledge.

5. Cloud processing

Possession and processing do not necessarily equal ownership.

6. AI-generated data

The legal character of derived information is still developing.

7. Blockchain

Decentralised copies complicate conventional property concepts.

8. Cross-border transfers

Data may simultaneously be subject to UAE and foreign legal regimes.

41. Recommended UAE Data-Ownership Contract Structure

A sophisticated contract should expressly address:

Data definition

Personal data

Confidential information

Pre-existing data

Customer-generated data

Derived data

Aggregated data

Analytics

AI training data

Database rights

Processing rights

Licensing

Security

Sub-processors

Cross-border transfer

Return of data

Deletion

Post-termination use

Audit rights

Breach remedies

This reduces disputes about what the parties mean by “ownership.”

42. Overall Legal Theory

The strongest way to understand UAE data ownership is not as:

“One person owns all data.”

Instead, it is:

Data is a legally fragmented resource.

Different legal rights may attach to different aspects:

Individual

→ privacy/data-subject rights

Business

→ database/confidentiality/contractual rights

Creator

→ intellectual-property interests

Processor

→ limited contractual processing rights

Government

→ statutory powers

Court

→ disclosure/preservation authority

Thus, several persons may have legally enforceable interests in the same dataset without each having identical ownership rights.

43. Conclusion

UAE data ownership law is best understood through a combination of property, personality, confidentiality, intellectual-property, contractual and regulatory theories.

The principal propositions emerging from UAE/DIFC jurisprudence are:

Personal data should not automatically be treated as ordinary corporate property.

Data subjects can have legally protected interests even where an organisation stores or processes the information.

Commercial databases may receive strong confidentiality protection.

The database and the individual pieces of information inside it may have different legal statuses.

Publicly available information is generally harder to characterise as proprietary or confidential.

Confidential information can have economic value even where its precise market value is difficult to calculate.

Contract can allocate significant rights concerning collection, use, processing, licensing and deletion of data.

Employee access to information does not automatically give the employee a right to exploit an employer's confidential database.

Cloud possession does not automatically establish ownership.

AI, blockchain and derived-data systems make a single-property theory increasingly inadequate.

The most useful authorities include TVM Capital v Hashemi, AES v GSB Capital, DFSA v Commissioner of Data Protection, Elseco v Lys, Linux v Lizeth, Gate Mena v Tabarak, and the Dimensions arbitration. Together, they demonstrate that UAE/DIFC law generally requires a rights-based analysis of the particular information and relationship, rather than assuming that all data falls into one uniform category of property. (DIFC Courts)

LEAVE A COMMENT