Civil Law And Uae Data Ownership Civil Law Theories .
Civil Law and UAE Data Ownership — Civil Law Theories
1. Introduction
Data ownership is a difficult concept in modern civil law because “data” is not always equivalent to a traditional movable or immovable property asset.
A database may contain:
personal information;
customer information;
financial records;
business intelligence;
trade secrets;
intellectual property;
metadata;
behavioural information;
employee information;
commercially generated information.
The important legal question is therefore not simply:
“Who owns the data?”
but rather:
“What legal rights does each person or organisation have in relation to the data, and what legal basis protects those rights?”
This distinction is particularly important in the UAE because personal-data protection, confidentiality, intellectual property, contractual rights and civil obligations may protect different aspects of the same dataset.
The federal UAE Personal Data Protection framework is principally established by Federal Decree-Law No. 45 of 2021, while DIFC has its own data-protection regime. DIFC case law has developed useful principles concerning personal data, confidential information, databases and commercial information.
2. The Central Proposition: Data Is Not Necessarily “Owned”
Traditional property law generally asks whether something is capable of being owned.
Data creates a more complicated situation.
Consider a customer database containing:
Name + telephone number + financial information + transaction history + investment preferences.
Different legal interests may coexist:
| Interest | Potential holder |
|---|---|
| Personal identity information | Data subject |
| Right to privacy/data protection | Data subject |
| Database structure | Database/controller/business |
| Confidentiality | Business/controller |
| Copyright in database compilation | Potentially creator/rightsholder |
| Trade-secret protection | Business |
| Contractual control | Contracting parties |
| Processing authority | Controller/processor |
| Commercial value | Business/data controller |
| Access/correction rights | Data subject |
Therefore, UAE civil-law analysis is better expressed as:
Data rights rather than absolute data ownership.
3. Main Civil-Law Theories of Data Ownership
There are several competing theories.
Theory 1 — Data as Property
Under the property theory, data is treated as an economic asset capable of being controlled, transferred, licensed or protected.
This approach is particularly attractive for:
commercial databases;
proprietary datasets;
machine-generated datasets;
valuable business intelligence;
digital assets.
However, personal data presents difficulties because treating an individual's personal information simply as the property of a company can conflict with privacy and data-protection principles.
4. Theory 2 — Data as a Personality Right
Under the personality-right theory, personal information is closely connected to the individual.
The individual is not merely an economic owner.
Instead, the individual has rights relating to:
privacy;
identity;
control over certain processing;
access;
correction;
lawful processing;
protection from misuse.
This approach fits personal-data regulation better than a simple property model.
The UAE Personal Data Protection Law reflects this rights-based approach by regulating processing and recognising rights and protections associated with data subjects.
5. Theory 3 — Data as Confidential Information
A third theory treats data according to its confidential character.
The crucial question becomes:
Is the information confidential and has another person misused it?
This is particularly relevant for:
customer lists;
financial information;
pricing information;
investment strategies;
business plans;
proprietary databases.
The DIFC Court's decision in AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060 provides an important illustration.
The court distinguished between:
genuinely confidential compiled client information; and
information such as publicly available or individually known contact details.
The court held that confidentiality depends upon the nature, context, acquisition and use of the information. (DIFC Courts)
6. Theory 4 — Data as Intellectual Property
Another approach is to protect the creation or compilation of data, rather than saying that every item of data is property.
For example:
A company spends AED 10 million creating a sophisticated database containing:
customer information;
market information;
pricing history;
analytics;
categorisation;
proprietary algorithms.
The underlying facts may not necessarily be exclusively owned.
But legal protection may arise from:
copyright;
database rights where applicable;
confidential-information law;
trade-secret protection;
contract;
unfair competition principles.
Thus:
The database and the individual pieces of information within it may have different legal characteristics.
7. Theory 5 — Data as a Contractual Asset
Businesses frequently obtain data under contracts.
For example:
Company A → collects customer information
Company B → processes information
Company C → provides cloud storage
The contract may regulate:
permitted use;
access;
retention;
deletion;
confidentiality;
security;
return of data;
restrictions on commercial exploitation.
In this model, “ownership” may be less important than contractual rights of control and use.
8. Theory 6 — Data as a Controlled Resource
A modern approach views data as a resource subject to multiple overlapping control rights.
For example:
Individual
Controls certain personal-data rights.
Business
Controls its proprietary database.
Processor
Has limited contractual processing authority.
Government
May have statutory access powers.
Court
May order disclosure or preservation.
Third party
May have lawful access under contract or legislation.
Thus, the same dataset can simultaneously be subject to several legally distinct interests.
9. UAE Personal Data Protection Law and Ownership
Federal Decree-Law No. 45 of 2021 should not simply be described as a law declaring that individuals “own” their personal data.
Its structure is more accurately understood as a rights-and-obligations framework governing personal-data processing.
This includes concepts involving:
data subjects;
controllers;
processors;
lawful processing;
consent;
security;
confidentiality;
data-subject rights;
cross-border transfers.
Therefore:
Possession of a database does not automatically give the database holder unrestricted legal authority to use every item of information in it.
10. Controller vs Owner
One of the most important distinctions is:
Controller
The entity determining the purposes and means of processing.
Processor
The entity processing data on behalf of another.
Neither concept should automatically be equated with traditional property ownership.
Example
A UAE hospital stores patient information with a cloud provider.
The hospital may determine:
why the data is collected;
how it is used;
who may access it.
The cloud provider merely processes or stores it according to contractual and legal instructions.
Therefore:
Physical possession of data does not necessarily equal legal ownership or unrestricted control.
11. Case Law 1 — TVM Capital Healthcare Partners Ltd v Ali Akbar Hashemi [2014] DIFC CA 006
This is one of the most important UAE/DIFC cases for understanding the confidential-information theory of data rights.
TVM Capital provided confidential business and financial information to Hashemi under a confidentiality agreement.
The information included substantial information concerning the business and financial affairs of ProVita.
The defendant was found to have breached the confidentiality agreement and Article 37 of the DIFC Law of Obligations.
The Court of Appeal upheld the damages award of:
AED 250,000. (DIFC Courts)
The Court explained that the relevant information was broader than merely statutory “trade secrets”; the contractual definition covered information supplied under the confidentiality agreement.
Importantly, the court recognised that the value of confidentiality itself could constitute a legally compensable interest even when the precise monetary value could not be calculated with certainty. (DIFC Courts)
Data-ownership significance
This supports the proposition that:
Data can have legally protected value without necessarily being traditional property.
12. Case Law 2 — AES Middle East Insurance Broker LLC v GSB Capital Ltd [2023] DIFC CFI 060
This is perhaps the most directly useful modern UAE/DIFC authority for commercial database ownership theories.
AES alleged misuse of:
client lists;
customer information;
assets-under-management information;
fee information;
investment portfolios;
risk profiles;
confidential client data.
The court held that client lists can constitute confidential information, particularly where they contain commercially valuable information compiled through substantial effort and are not publicly available in aggregated form. (DIFC Courts)
However, the court also distinguished individual contact information.
For example:
public LinkedIn connections;
readily accessible contact details;
information personally known by employees.
Such information may not automatically belong to the employer or qualify as confidential. (DIFC Courts)
Principle
A database may receive stronger legal protection than isolated pieces of information contained within it.
This is one of the most important principles for data ownership analysis.
13. Case Law 3 — The Dubai Financial Services Authority v Commissioner of Data Protection & Anna Waterhouse [2018] DIFC CFI 051 and CFI 085
This is particularly important for the personal-data theory.
The case concerned the interpretation of the DIFC Data Protection Law and the meaning of personal data.
The Court considered principles concerning whether information held by a data controller constitutes the individual's personal data.
The judgment discussed the approach that personal data is connected to information concerning the identifiable individual and is not simply every document in which the individual's name happens to appear. (DIFC Courts)
The Court considered the concept of a relevant filing system and the distinction between information genuinely relating to an individual and documents merely connected with an individual.
Principle
Personal data is not equivalent to every item of information that happens to mention a person.
Data-ownership significance
This reinforces a rights-based theory rather than an absolute property theory.
14. Case Law 4 — Elseco Limited v Pierre-Eric Daniel Bernard Lys [2016] DIFC CA 011
Elseco involved allegations concerning the use of customer information from the company's database.
The case considered allegations that customer contact information from Elseco's database had been used for competing purposes. The court ultimately rejected the particular complaint concerning misuse of the customer information. (DIFC Courts)
Importance
The case demonstrates that:
The mere existence of a company database does not automatically establish that every piece of information connected with the company's customers is legally proprietary or confidential.
The claimant still needs to establish:
what information was involved;
its legal character;
how it was obtained;
whether it was confidential;
whether it was misused.
15. Case Law 5 — Linux v Lizeth [2022] DIFC SCT 237
This case involved a confidentiality agreement and a digital platform.
The claimant alleged that information had been placed on a public link and that this exposed the project's database and confidential information to third parties.
The court considered the allegations concerning:
NDA obligations;
confidential information;
third-party software;
database exposure;
publication through a digital platform.
Ultimately, the particular allegations did not establish the claimed NDA breach on the evidence. (DIFC Courts)
Principle
Digital storage does not eliminate the need to prove the underlying contractual or confidentiality obligation.
This is particularly relevant to cloud databases.
16. Case Law 6 — Gate Mena DMCC v Tabarak Investment Capital Ltd [2023] DIFC CA 002
Gate Mena is important because it deals with confidential information in the context of digital assets.
The Court of Appeal considered the meaning and misuse of confidential information and referred to the circumstances in which information loses confidentiality or may lawfully be disclosed. (DIFC Courts)
The underlying dispute involved digital assets and allegations concerning the handling and misuse of information.
Principle
Confidentiality is not absolute.
Information may cease to be confidential or disclosure may be justified in circumstances recognised by law.
Data-ownership significance
This supports a conditional-rights theory:
The holder of information does not necessarily possess an unlimited permanent property right in the information.
17. Case Law 7 — AES Middle East Insurance Broker LLC v GSB Capital Ltd — Preservation Order
A further important procedural aspect of the AES litigation was the court's preservation order.
The court prohibited the respondent from:
accessing;
passing on;
using;
deriving new materials from;
deploying confidential information.
It also required preservation of electronic documents and metadata containing the confidential information. (DIFC Courts)
Principle
Data rights can be protected through injunctive and preservation remedies, not merely monetary compensation.
This is especially important where the value of data lies in its continued secrecy.
18. Case Law 8 — Dimensions / AIMS Arbitration
A DIFC-seated arbitration concerning AIMS, CDS and ICM provides another useful example of contractual and confidential-information protection.
The tribunal found breaches involving:
contractual obligations;
use of confidential information;
trade secrets;
development and sale of products.
Damages were ordered to be assessed separately. (DIFC Courts)
Principle
Data may have multiple legal classifications simultaneously:
contractual information + confidential information + trade secret + commercially valuable asset.
This demonstrates why a single “ownership” label may be inadequate.
19. Six Major Data Ownership Theories Compared
| Theory | Core idea | Main protection |
|---|---|---|
| Property theory | Data is an economic asset | Property/civil law |
| Personality theory | Personal data is connected to the individual | Privacy/data protection |
| Confidentiality theory | Valuable information deserves secrecy | Confidentiality law |
| IP theory | Database creation/structure can be protected | Intellectual property |
| Contract theory | Parties define rights of use/control | Contract |
| Resource/control theory | Multiple parties possess different rights | Mixed legal framework |
20. Personal Data vs Commercial Data
This distinction is fundamental.
Personal data
Example:
Name + Emirates ID + health information.
The primary concern is:
privacy;
lawful processing;
security;
individual rights.
Commercial database
Example:
50,000 customer records + purchasing history + pricing analysis + proprietary segmentation.
The business may have:
confidentiality rights;
contractual rights;
IP-related rights;
trade-secret protection.
Therefore:
Personal data should not automatically be treated as the property of the company that collected it.
21. Database Ownership
Suppose Company A creates a database containing 100,000 customers.
The database contains:
customer names;
addresses;
purchase history;
customer preferences;
internally generated classifications.
There are potentially several layers.
Layer 1 — Customer identity
The individual remains the data subject.
Layer 2 — Personal data
Subject to data-protection regulation.
Layer 3 — Compilation
The company's investment in assembling and organising the database may receive separate legal protection.
Layer 4 — Proprietary analysis
Company-generated algorithms and classifications may receive IP/confidentiality protection.
Layer 5 — Contract
Customer agreements may restrict use.
Thus:
“Company owns database” does not mean “company owns every legal interest in every item of information inside it.”
22. Employee-Generated Data
Consider an employee who creates:
customer lists;
sales reports;
market analyses;
spreadsheets.
The ownership analysis should examine:
employment contract;
intellectual-property provisions;
confidentiality clauses;
applicable law;
whether information is personal data;
whether the information was created within employment duties;
whether the employee merely memorised information;
whether the information was publicly available.
AES is particularly useful because the DIFC Court distinguished proprietary client lists from ordinary personal or publicly available contacts. (DIFC Courts)
23. Customer Data and Employer Rights
Suppose a financial adviser leaves Company A.
The adviser remembers:
“Customer X is wealthy and prefers conservative investments.”
Can Company A automatically claim ownership of the adviser's personal knowledge?
Not necessarily.
But if the adviser takes:
Company A's confidential spreadsheet containing 5,000 clients, AUM, fees, investment strategies and risk profiles,
the legal position is substantially different.
AES provides a strong illustration of this distinction. (DIFC Courts)
24. Data Ownership in Cloud Computing
Cloud storage creates another important problem.
Example
Company A owns a database.
Company B operates the cloud platform.
Company C provides cybersecurity services.
Who owns the data?
The better answer is:
Ownership/control depends upon the underlying legal rights and contracts; physical possession by the cloud provider does not automatically transfer ownership.
The cloud provider may have:
storage rights;
processing authority;
security obligations;
without obtaining unrestricted commercial ownership of the underlying information.
25. Data as a Bundle of Rights
A sophisticated UAE civil-law theory can therefore represent data as:
Data = Bundle of Rights
Including:
access;
use;
exclusion;
correction;
deletion;
disclosure;
confidentiality;
licensing;
processing;
transfer;
commercial exploitation;
security;
preservation.
Different persons may hold different rights.
26. Data Ownership and Contract
Contracts should ideally define:
1. Who controls data?
2. Who may process it?
3. For what purpose?
4. Who may disclose it?
5. Who owns derived data?
6. Who owns analytics?
7. What happens after termination?
8. Must data be returned?
9. Must data be deleted?
10. Who bears breach liability?
This is particularly important for:
SaaS agreements;
cloud contracts;
fintech agreements;
employment contracts;
outsourcing agreements;
data-processing agreements;
joint ventures.
27. Derived Data
A difficult issue is derived data.
Suppose:
Customer provides:
Transaction history.
Company creates:
Credit-risk score.
Who has rights in the credit-risk score?
The answer may depend upon:
applicable data-protection law;
contract;
intellectual property;
confidentiality;
how the derived information relates to the individual;
whether it constitutes personal data.
The derived information may therefore not be treated identically to the original data.
28. Aggregated Data
Suppose Company A combines:
1 million customer records;
removes direct identifiers;
creates market statistics.
Example:
“42% of customers aged 25–35 prefer Product X.”
The legal analysis may differ from the underlying identifiable customer information.
However, aggregation or anonymisation must be legally effective; simply removing names does not automatically eliminate all data-protection or confidentiality considerations.
29. Anonymisation vs Pseudonymisation
Anonymisation
Information is processed so that individuals are no longer identifiable in the legally relevant sense.
Pseudonymisation
Identifiers are replaced but re-identification may remain possible.
This distinction is important because pseudonymised information may continue to attract personal-data protection.
30. Data Ownership and Artificial Intelligence
AI creates a new data-ownership problem.
Suppose:
Company A provides customer data
↓
AI model processes it
↓
Model generates predictions
↓
Company B receives the analytics
Questions arise:
Who controls the original data?
Who controls the model?
Who owns the generated analysis?
Does the output contain personal data?
Can the output be commercially exploited?
Does the contract allocate rights?
Can the processor train an AI system using the information?
These questions demonstrate why traditional property concepts alone are insufficient.
31. Data Ownership and Blockchain
Blockchain creates another problem.
Once information is recorded on a distributed ledger:
multiple nodes may hold copies;
deletion may be technically difficult;
control may be decentralised;
the identity of the controller may be unclear.
Therefore, blockchain data may require a combination of:
contract;
data protection;
confidentiality;
digital-asset law;
civil obligations.
Gate Mena demonstrates how DIFC courts may encounter confidentiality and digital-asset questions together. (DIFC Courts)
32. Remedies for Unauthorised Data Use
Potential civil remedies may include:
Injunction
Prevent further use or disclosure.
Preservation order
Prevent destruction or alteration of data.
Delivery-up / deletion
Require return or deletion where legally appropriate.
Damages
Compensate proven loss.
Negotiating damages
Particularly relevant where the value of a confidentiality restriction is difficult to quantify.
Account of profits
Potentially relevant depending on the legal cause of action and applicable law.
TVM Capital is particularly significant for the damages approach to misuse of confidential information. (DIFC Courts)
33. Data Ownership and Damages
Suppose Company A's database is unlawfully copied.
The company proves:
database creation costs = AED 2 million;
commercial value = AED 5 million;
actual loss = AED 1 million;
defendant's profits from misuse = AED 1.5 million.
The court does not simply add every number.
It must identify the appropriate legal remedy and avoid double recovery.
The value of the database, the loss caused by misuse, and the defendant's benefit are different valuation concepts.
34. Data Ownership and Confidentiality
A particularly important UAE/DIFC principle is:
Confidentiality may protect information without creating absolute ownership over the information.
For example, AES recognised that client lists could be confidential because of:
commercial value;
compilation effort;
non-public nature;
sensitivity;
usefulness to competitors. (DIFC Courts)
This is different from saying:
“AES owned every fact about every customer.”
The legal protection arises from the relationship, circumstances and characteristics of the information.
35. Data Ownership and Public Information
Information available publicly generally presents a weaker ownership/confidentiality claim.
Example:
Company's public telephone number.
It is difficult to argue that the company has an exclusive proprietary right in the number merely because it appears in its database.
But:
Customer's private number + investment portfolio + AUM + risk profile
is materially different.
AES expressly made this distinction between public/ordinary contact information and confidential compiled client information. (DIFC Courts)
36. Data Ownership and Personal Privacy
A company may spend millions of dirhams collecting customer information.
That does not necessarily mean:
“The company owns the customer's identity.”
The company may instead have legally limited authority to process the information for specified purposes.
This is one of the strongest arguments against a pure property theory of personal data.
37. Advanced Legal Model
A useful UAE model is:
Personal Data
→ Data-subject rights
Commercial Data
→ Contract/confidentiality/IP
Database
→ Compilation/contractual/proprietary interests
Derived Data
→ Contract + privacy + IP + confidentiality
Trade Secret
→ Confidentiality/trade-secret protection
Digital Asset Data
→ Contract + digital-asset + property/obligation principles
Therefore:
The legal character of data depends upon what the data is, who generated it, how it was obtained, how it is used and which legal relationship governs it.
38. Case-Law Principles Table
| Case | Data-ownership theory | Main principle |
|---|---|---|
| TVM Capital v Hashemi [2014] DIFC CA 006 | Confidentiality | Confidential information has independently protectable economic value |
| AES v GSB Capital [2023] DIFC CFI 060 | Database/confidentiality | Compiled client data can be confidential; public information may not be |
| DFSA v Commissioner of Data Protection [2018] DIFC CFI 051/085 | Personality/data rights | Personal data is not every document mentioning an individual |
| Elseco v Lys [2016] DIFC CA 011 | Database rights | Use of database information requires proof of the relevant legal protection |
| Linux v Lizeth [2022] DIFC SCT 237 | Contract/confidentiality | Digital publication does not itself establish an NDA breach |
| Gate Mena v Tabarak [2023] DIFC CA 002 | Digital/confidential information | Confidentiality is conditional and depends on legal circumstances |
| Dimensions arbitration | Trade secrets/contract | Data can simultaneously be contractual and confidential/trade-secret information |
39. Seven Practical Data-Ownership Examples
Example 1 — Customer database
A bank creates a database of 500,000 customers.
Legal position:
The bank may have strong contractual/confidential/database rights, but this does not necessarily mean it owns every personal-data right associated with those customers.
Example 2 — Employee contact list
Employee memorises five customers' telephone numbers.
Legal position:
Much weaker proprietary argument than taking the employer's confidential database.
AES is particularly relevant. (DIFC Courts)
Example 3 — Private financial information
Employee downloads:
Customer + AUM + portfolio + fees + risk profile.
Legal position:
Strong confidentiality concerns.
Example 4 — Public LinkedIn connection
Employee uses a publicly visible LinkedIn connection.
Legal position:
Not automatically confidential or proprietary.
AES specifically considered LinkedIn connections and public professional networks. (DIFC Courts)
Example 5 — AI-generated customer profile
Company generates:
“Customer has a 78% probability of purchasing Product X.”
Legal position:
Potentially involves personal data, derived information, contractual rights and AI-related governance.
Example 6 — Blockchain information
A transaction is recorded permanently on a distributed ledger.
Legal position:
Traditional exclusive ownership becomes difficult because multiple participants may hold copies.
Example 7 — Trade-secret database
Company spends AED 5 million developing a proprietary pricing database.
Legal position:
Confidentiality, contractual restrictions and potentially intellectual-property protection may operate together.
40. Major Legal Problems in UAE Data Ownership
1. No single universal ownership concept
Different data categories require different legal treatment.
2. Personal data vs property
Privacy rights cannot always be reduced to economic ownership.
3. Database vs underlying information
A company may protect its compilation without acquiring exclusive rights over every underlying fact.
4. Employee mobility
Businesses must balance legitimate confidentiality protection against employees' general skills and knowledge.
5. Cloud processing
Possession and processing do not necessarily equal ownership.
6. AI-generated data
The legal character of derived information is still developing.
7. Blockchain
Decentralised copies complicate conventional property concepts.
8. Cross-border transfers
Data may simultaneously be subject to UAE and foreign legal regimes.
41. Recommended UAE Data-Ownership Contract Structure
A sophisticated contract should expressly address:
Data definition
Personal data
Confidential information
Pre-existing data
Customer-generated data
Derived data
Aggregated data
Analytics
AI training data
Database rights
Processing rights
Licensing
Security
Sub-processors
Cross-border transfer
Return of data
Deletion
Post-termination use
Audit rights
Breach remedies
This reduces disputes about what the parties mean by “ownership.”
42. Overall Legal Theory
The strongest way to understand UAE data ownership is not as:
“One person owns all data.”
Instead, it is:
Data is a legally fragmented resource.
Different legal rights may attach to different aspects:
Individual
→ privacy/data-subject rights
Business
→ database/confidentiality/contractual rights
Creator
→ intellectual-property interests
Processor
→ limited contractual processing rights
Government
→ statutory powers
Court
→ disclosure/preservation authority
Thus, several persons may have legally enforceable interests in the same dataset without each having identical ownership rights.
43. Conclusion
UAE data ownership law is best understood through a combination of property, personality, confidentiality, intellectual-property, contractual and regulatory theories.
The principal propositions emerging from UAE/DIFC jurisprudence are:
Personal data should not automatically be treated as ordinary corporate property.
Data subjects can have legally protected interests even where an organisation stores or processes the information.
Commercial databases may receive strong confidentiality protection.
The database and the individual pieces of information inside it may have different legal statuses.
Publicly available information is generally harder to characterise as proprietary or confidential.
Confidential information can have economic value even where its precise market value is difficult to calculate.
Contract can allocate significant rights concerning collection, use, processing, licensing and deletion of data.
Employee access to information does not automatically give the employee a right to exploit an employer's confidential database.
Cloud possession does not automatically establish ownership.
AI, blockchain and derived-data systems make a single-property theory increasingly inadequate.
The most useful authorities include TVM Capital v Hashemi, AES v GSB Capital, DFSA v Commissioner of Data Protection, Elseco v Lys, Linux v Lizeth, Gate Mena v Tabarak, and the Dimensions arbitration. Together, they demonstrate that UAE/DIFC law generally requires a rights-based analysis of the particular information and relationship, rather than assuming that all data falls into one uniform category of property. (DIFC Courts)

comments