Civil Law And Uae Data Protection Under Uae Pdpl (Federal Decree-Law No. 45 Of 2021) .

1. Introduction

The UAE Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021, is the principal federal framework governing personal-data protection in the UAE outside regimes with their own special data-protection legislation. It came into force on 2 January 2022. The UAE Government describes it as an integrated framework for confidentiality, privacy, data governance, and the rights and duties of parties involved in personal-data processing.

The PDPL is important from a civil-law perspective because misuse of personal data can simultaneously involve:

  • breach of statutory data-protection duties;
  • contractual liability;
  • privacy violations;
  • confidentiality;
  • cybersecurity failures;
  • reputational harm;
  • material financial loss;
  • moral damage;
  • evidentiary issues.

A significant qualification is necessary at the outset: there is still a relatively limited body of reported UAE onshore judgments directly interpreting private compensation claims under Federal Decree-Law No. 45 of 2021 itself. Therefore, the case-law section below distinguishes direct privacy/data authorities from analogous UAE civil and technology cases dealing with damages, evidence, technological misconduct and privacy.

2. Purpose of the UAE PDPL

The PDPL seeks to establish rules for the lawful processing of personal data while protecting:

  • privacy;
  • confidentiality;
  • security;
  • individual control over personal information;
  • responsible data processing.

The official UAE Government summary states that the law regulates processing, establishes controls for organizations holding personal data, and gives data subjects rights including correction and restriction or cessation of processing in specified circumstances.

The law therefore represents a shift from treating personal information merely as a business resource toward treating it as information carrying legally protected individual interests.

3. Scope of the PDPL

The PDPL generally concerns the processing of personal data by controllers and processors within its statutory scope.

It can have relevance to processing:

  • electronically;
  • partly electronically;
  • through organized filing systems.

The law also contains exclusions and special-regime considerations. In particular, UAE financial, health, government, free-zone and other sector-specific regimes may interact with or affect the application of the general federal framework.

Therefore, before commencing a claim, one should ask:

Does the PDPL actually apply to this controller, processor, data and processing activity?

This is the first legal question—not merely whether personal information was involved.

4. Meaning of Personal Data

Personal data broadly concerns information relating to an identified or identifiable natural person.

Examples include:

  • name;
  • identification information;
  • contact details;
  • location information;
  • financial information;
  • employment information;
  • photographs;
  • biometric information;
  • health-related information;
  • online identifiers.

The precise statutory definitions should always be applied to the particular facts.

5. Sensitive Personal Data

Certain information presents greater risks because disclosure or misuse can seriously affect an individual.

Examples can include information concerning:

  • health;
  • biometric characteristics;
  • financial information;
  • family circumstances;
  • other specially protected categories.

The legal analysis may become more stringent where the nature of the information creates heightened privacy or security risks.

6. Controller and Processor

The PDPL distinguishes between different actors involved in processing.

Controller

The party that determines important aspects of:

  • why data is processed;
  • how processing occurs.

Processor

A party that processes personal data on behalf of the controller.

This distinction is important in civil disputes because responsibility may depend upon:

  • who determined the processing;
  • who actually processed the information;
  • what the contract provided;
  • which security obligation was breached;
  • who had operational control.

7. Lawful Processing

The PDPL adopts a structured approach to lawful processing.

The legislation generally places consent at the centre of processing, subject to statutory exceptions. The law also recognizes circumstances in which processing may occur without consent, including specified legal, public-interest, contractual and other circumstances.

Consequently:

Absence of consent should not automatically be treated as the end of every legal analysis; the statutory exceptions must also be examined.

8. Principles of Personal-Data Processing

The PDPL framework emphasizes important principles including:

1. Lawfulness and transparency

Processing should have a lawful basis and be carried out transparently.

2. Purpose limitation

Data should be collected for specified and legitimate purposes.

3. Data minimization

Processing should be limited to what is necessary for the relevant purpose.

4. Accuracy

Personal data should be accurate and appropriately updated.

5. Storage limitation

Information should not be retained indefinitely without an appropriate legal basis.

6. Security and confidentiality

Appropriate technical and organizational safeguards should be maintained.

These principles are central to determining whether a controller or processor complied with its obligations.

9. Consent Under the PDPL

Consent should not be confused with a blanket authorization to use information for every purpose.

A valid consent analysis can require consideration of:

  • who gave consent;
  • what was disclosed;
  • what purpose was identified;
  • whether the consent was sufficiently informed;
  • whether the subsequent processing remained within the relevant scope.

The PDPL also recognizes circumstances where processing can occur without consent.

10. Data-Subject Rights

The PDPL provides a range of rights.

The statutory framework includes rights relating to:

  • obtaining information concerning processing;
  • access to personal data;
  • correction;
  • erasure in applicable circumstances;
  • restriction of processing;
  • objection in specified circumstances;
  • withdrawal of consent where consent is the relevant basis;
  • portability in applicable circumstances;
  • information concerning automated processing and profiling.

For example, Article 13 expressly provides a right to obtain information concerning the types of personal data being processed, processing purposes, certain automated decisions, recipients and storage standards.

11. Right to Correct Inaccurate Data

Incorrect personal information can cause significant civil harm.

For example:

A financial institution's database incorrectly identifies a person as having a serious unpaid debt.

Possible consequences could include:

  • denial of services;
  • reputational injury;
  • financial loss;
  • commercial consequences.

The PDPL's correction mechanisms are therefore important not only as compliance rights but also as tools for preventing continuing harm.

12. Right to Erasure

Under applicable conditions, a data subject may seek deletion/erasure of personal data.

However, this is not necessarily an absolute right.

There may be legitimate reasons for continued retention, including:

  • legal obligations;
  • litigation;
  • regulatory requirements;
  • public-interest purposes;
  • establishment or defence of legal claims.

Therefore:

A request for deletion must be tested against the statutory exceptions and competing legal obligations.

13. Restriction and Objection to Processing

A data subject may have circumstances in which processing can be restricted or objected to.

This becomes particularly important where:

  • information is disputed;
  • processing is excessive;
  • the original purpose has changed;
  • the individual challenges continued processing.

The specific statutory conditions must be applied to each case.

14. Data Security Obligations

A controller or processor must adopt appropriate measures to protect personal data.

Security governance can involve:

  • access controls;
  • authentication;
  • encryption;
  • secure storage;
  • employee controls;
  • incident response;
  • monitoring;
  • appropriate technical measures.

The PDPL specifically addresses security and protection of processing operations. The legislation also imposes obligations on processors concerning security of processing media and electronic devices containing personal data.

15. Personal-Data Breach

A data breach can involve:

  • unauthorized access;
  • accidental disclosure;
  • hacking;
  • loss;
  • destruction;
  • alteration;
  • unauthorized copying.

Article 9 requires the controller, upon becoming aware of a qualifying personal-data breach affecting privacy, confidentiality or security, to notify the competent data-protection authority in accordance with the statutory procedures and applicable requirements.

The breach-notification duty is primarily a regulatory obligation.

It should not automatically be equated with a private damages award.

16. Data Breach and Civil Liability

A useful distinction is:

Regulatory question

Did the controller or processor violate the PDPL?

Civil question

Did the violation cause the claimant legally compensable damage?

These questions can overlap but are not identical.

For civil compensation, the claimant may still need to establish:

Duty → breach → damage → causation → quantum.

17. Civil Liability Under the UAE Civil Transactions Law

The PDPL operates alongside the UAE's general civil-law principles.

Federal Law No. 5 of 1985 provides the broader framework concerning:

  • unlawful acts;
  • obligations;
  • compensation;
  • causation;
  • material damage;
  • moral damage.

Consequently, a data incident may create:

Statutory data-protection issues

and simultaneously:

General civil liability

and/or:

Contractual liability.

18. Contractual Data-Protection Claims

A company may contract with a processor containing obligations concerning:

  • confidentiality;
  • cybersecurity;
  • data retention;
  • deletion;
  • incident notification;
  • access controls.

If the processor violates these obligations, the claimant may have a contractual claim independent of or alongside statutory data-protection issues.

The analysis becomes:

Contract → obligation → breach → damage → causation → compensation.

19. Tortious/Non-Contractual Data Claims

A claimant may also rely upon general civil liability where unlawful conduct causes damage.

For example:

A person unlawfully obtains and publishes another person's private information.

Potential claims may concern:

  • privacy;
  • reputation;
  • moral damage;
  • financial loss.

The availability of particular remedies depends upon the applicable legal provisions and facts.

20. Material Damage

Material damage is economically measurable.

Examples include:

  • financial losses;
  • identity-restoration costs;
  • documented remediation costs;
  • business interruption;
  • lost revenue;
  • expenses caused by a data incident.

A claimant should provide evidence rather than simply estimating a large amount.

21. Moral Damage

Data breaches can produce non-economic injury.

Examples include:

  • invasion of privacy;
  • humiliation;
  • reputational injury;
  • emotional harm;
  • exposure of confidential personal information.

A 2026 Dubai civil judgment concerning publication of a person's photograph and insulting social-media content awarded AED 80,000 for moral damage and ordered removal of the offending content, while the larger claim for material loss was not accepted for lack of sufficient proof. The case was upheld through the appellate process.

This was not a PDPL damages judgment, but it illustrates how UAE courts may distinguish moral harm from unproven financial loss in privacy-related disputes.

22. Causation

Causation is one of the most difficult parts of a data claim.

Consider:

A company's database is breached, and six months later a customer suffers financial fraud.

The claimant must establish the relevant connection between:

breach → disclosure/access → misuse → financial injury.

The mere fact that both events occurred does not necessarily establish causation.

23. Data Protection and Cybersecurity

Cybersecurity and data protection overlap but are not identical.

Cybersecurity asks:

Was the information adequately protected against unauthorized technological access?

Data protection asks:

Was personal data lawfully collected, processed, retained, disclosed and otherwise handled?

One incident can violate both regimes.

For example:

Ransomware compromises a company's customer database.

Potential issues include:

  • PDPL security obligations;
  • cybercrime legislation;
  • contractual security obligations;
  • civil compensation;
  • regulatory notification.

24. Cross-Border Data Transfers

Cross-border processing is particularly important for multinational businesses.

The PDPL contains a framework for transferring personal data outside the UAE, including circumstances involving adequate protection and specified situations where adequate protection is not available. One statutory exception concerns transfers necessary to establish, exercise or defend rights before judicial authorities.

This is important for:

  • international litigation;
  • arbitration;
  • multinational investigations;
  • global cloud services;
  • international discovery.

25. Data Protection and Litigation

A data subject may need to use personal data as evidence in court.

This creates a potential tension:

privacy protection

versus

right to establish or defend a legal claim.

The PDPL itself recognizes certain circumstances concerning legal claims and judicial proceedings. Cross-border transfer provisions also contemplate circumstances connected with judicial rights.

Therefore, data protection should not be interpreted as making all personal information unusable in litigation.

26. Data Protection and Electronic Evidence

Data claims frequently depend upon:

  • emails;
  • server logs;
  • database records;
  • electronic contracts;
  • WhatsApp messages;
  • access records;
  • metadata;
  • forensic reports.

The UAE Evidence Law and Electronic Transactions and Trust Services Law are therefore important complementary frameworks.

The central evidentiary questions are:

  1. Is the information authentic?
  2. Is it complete?
  3. Has it been altered?
  4. Can its source be established?
  5. What does it prove?

27. Expert Evidence

Cybersecurity and privacy disputes may require experts to examine:

  • security architecture;
  • access logs;
  • system vulnerabilities;
  • database activity;
  • data exfiltration;
  • financial consequences.

But an expert does not determine the legal outcome.

This is strongly consistent with UAE case law concerning the judicial treatment of expert reports.

28. Case Law

Case 1 — Dubai Court of Cassation, Case No. 611 of 2025

This is one of the most relevant recent UAE technology-related authorities.

The dispute involved allegations concerning a computer engineer's interference with company systems, programs, emails and information.

The Dubai Court of Cassation emphasized the distinction between establishing wrongful conduct and establishing the actual financial damage and precise amount of compensation claimed.

Relevance to PDPL claims

A claimant cannot necessarily argue:

“Personal data was compromised, therefore the defendant owes the entire amount claimed.”

Instead, the claimant should establish:

  • the incident;
  • the defendant's responsibility;
  • actual damage;
  • causation;
  • quantum.

Importance

This is particularly valuable when a PDPL dispute also contains a damages claim.

29. Case 2 — Dubai Court of Cassation Criminal Cassation No. 536 of 2024

This case concerned the criminal-law threshold for invasion of privacy through information technology.

The reported judicial analysis states that the Dubai Court of Cassation considered unauthorized voyeurism or spying through computer networks or information-technology tools and held that the relevant criminal intent could be established without requiring a special ulterior intent beyond the applicable general intent.

Relevance

Although criminal rather than civil, the case illustrates the UAE judiciary's treatment of privacy as a legally protected interest in digital environments.

It can therefore provide context for civil privacy disputes, although it should not be presented as a direct PDPL compensation precedent.

30. Case 3 — Dubai Civil Court Social-Media Privacy/Defamation Case, 2026

In a 2026 Dubai civil dispute, a person's photograph was published without consent together with insulting content.

The court awarded AED 80,000 in moral damages, ordered removal of the offending content, and rejected the larger claimed material damages because adequate financial loss had not been demonstrated. The judgment was upheld on appeal and cassation.

Principle

The case demonstrates an important distinction between:

privacy/moral injury

and

provable financial loss.

PDPL relevance

The case is not a direct Article-by-Article PDPL ruling, but it is highly relevant to the civil-law treatment of privacy-related injury.

31. Case 4 — Federal Supreme Court Cassation No. 880 of 2021

This authority concerns material damage, future damage and loss of opportunity and also addresses the relationship between criminal findings and civil proceedings.

Principle

Civil compensation requires an assessment of the actual legally relevant damage and its connection with the conduct.

PDPL relevance

A data-protection violation may produce:

  • present financial loss;
  • future economic consequences;
  • loss of opportunity.

But each category requires adequate proof.

Importance

It provides the general UAE damages framework within which a PDPL-related compensation claim may be analyzed.

32. Case 5 — Federal Supreme Court Cassation No. 683 of 2021

This case concerns the role of expert evidence.

Principle

The court is not automatically bound by the conclusions of an expert.

PDPL application

Suppose a cybersecurity expert concludes:

“The breach caused AED 4 million in losses.”

The court may examine:

  • the methodology;
  • source data;
  • assumptions;
  • causation;
  • financial records;
  • competing expert evidence.

Importance

This is particularly significant in complex data-breach litigation.

33. Case 6 — Federal Supreme Court Cassation No. 769 of 2021

This authority similarly concerns judicial assessment of expert reports.

Principle

The court may assess an expert report in conjunction with the broader evidentiary record.

Application to data protection

Experts may disagree about:

  • whether information was actually accessed;
  • whether it was copied;
  • whether the system was compromised;
  • the financial consequences.

The court retains the ultimate evidentiary judgment.

34. Case 7 — Federal Supreme Court Cassation No. 473 of 2005

This case concerns technical and financial expert evidence in commercial disputes.

Relevance

Data-protection litigation may require specialists to calculate:

  • restoration costs;
  • forensic costs;
  • business interruption;
  • lost profits;
  • other financial effects.

Principle

Specialized technical questions may appropriately be examined through expert evidence.

Limitation

This is a general commercial/evidentiary authority, not a PDPL case.

35. Case 8 — Dubai Court of Cassation Civil Cassation No. 1008 of 2024

This authority concerns documentary and technical evidence and expert assessment.

Relevance to PDPL disputes

A data claim may depend upon:

  • electronic documents;
  • contractual records;
  • technical records;
  • expert reports.

The case supports the broader UAE judicial approach of assessing documentary and technical material as part of the evidentiary record.

Limitation

It should be regarded as an analogous evidentiary authority, not as a direct interpretation of Federal Decree-Law No. 45 of 2021.

36. Case 9 — Dubai Court of Cassation Civil Appeal No. 158 of 2021

This authority concerns evidence originating from another proceeding.

Data-protection relevance

A data breach can produce evidence from:

  • police investigations;
  • criminal proceedings;
  • forensic investigations;
  • regulatory inquiries.

Such material may be relevant to civil litigation, but its evidentiary significance remains a matter for judicial assessment.

37. Case 10 — Dubai Court of Cassation Civil Appeal No. 1202 of 2026

This recent authority concerns compensation assessment and expert evidence.

PDPL relevance

Data-protection disputes may require calculation of:

  • forensic expenses;
  • restoration costs;
  • business interruption;
  • financial losses.

Technical and financial experts can assist in establishing these amounts.

Again, this is an analogous damages authority, not a direct PDPL ruling.

38. Summary of the Case Law

CasePrincipal issuePDPL relevance
Dubai Cassation 611/2025Technology wrongdoing and proof of damageStrong modern analogy
Dubai Criminal Cassation 536/2024Digital privacy/invasion of privacyPrivacy principle
Dubai Civil Court, 2026 social-media casePrivacy, moral damage and material lossStrong privacy/damages analogy
Federal Supreme Court 880/2021Material/future/loss-of-opportunity damageDamages framework
Federal Supreme Court 683/2021Expert evidenceCyber/forensic evidence
Federal Supreme Court 769/2021Evaluation of expert reportsTechnical data evidence
Federal Supreme Court 473/2005Technical/financial expertsData valuation
Dubai Cassation 1008/2024Documentary/technical evidenceElectronic-data proof
Dubai Civil Appeal 158/2021Evidence from another proceedingCyber/criminal evidence
Dubai Civil Appeal 1202/2026Compensation/expert evidenceData-breach quantum

Important: The table deliberately distinguishes direct privacy/technology authorities from general analogous authorities. It would be inaccurate to describe all of these decisions as judgments directly interpreting the PDPL.

39. PDPL Complaint vs Civil Lawsuit

This distinction is extremely important.

PDPL regulatory complaint

The PDPL permits a data subject to complain to the competent authority where there are grounds to believe that the PDPL has been contravened or personal data has been processed contrary to its requirements.

Civil claim

A civil lawsuit focuses on questions such as:

  • What legal right or interest was violated?
  • What damage occurred?
  • Who caused it?
  • What compensation or other remedy is legally available?

Therefore:

Regulatory enforcement and private civil compensation are related but distinct mechanisms.

40. Administrative Sanctions and Civil Compensation

The PDPL contains an administrative-enforcement framework.

This should be distinguished from compensation.

For example:

Regulatory sanction

→ punishment/remedial enforcement for non-compliance.

Civil compensation

→ compensation for legally recognized damage suffered by a claimant.

A regulatory penalty does not automatically equal the claimant's compensation.

41. Data Protection and Moral Damages

A privacy claim can be particularly important because personal data concerns the individual rather than merely an economic asset.

Suppose:

A person's sensitive medical information is unlawfully published online.

Possible harm may include:

  • privacy injury;
  • humiliation;
  • reputational harm;
  • emotional distress;
  • professional consequences.

The 2026 Dubai social-media case demonstrates that UAE civil courts can distinguish moral injury from unproven financial loss in privacy-related disputes.

42. Data Protection and Financial Damages

Financial damage may include:

Direct losses

  • unauthorized payments;
  • remediation expenses;
  • identity restoration;
  • forensic investigation.

Business losses

  • lost customers;
  • interruption;
  • loss of contracts;
  • additional security expenses.

Future losses

Potential continuing losses must be established sufficiently rather than being purely speculative.

43. Data Protection and Loss of Opportunity

Suppose a business's confidential personal-data analytics are improperly disclosed to a competitor.

The business may claim that it lost an opportunity to secure a contract.

However:

A possible future contract is not automatically an established loss.

The claimant should provide evidence showing the opportunity's genuine and identifiable economic value.

This principle is consistent with the UAE damages jurisprudence concerning loss of opportunity.

44. Data Protection and Cloud Computing

Many UAE businesses outsource data processing.

Example:

Customer → UAE Company → Cloud Processor → Foreign Server

This creates several legal questions:

  1. Is the processor properly appointed?
  2. What contractual security obligations exist?
  3. Is the transfer lawful?
  4. Who controls access?
  5. What happens after termination?
  6. How is the data deleted?
  7. Who responds to a breach?

The PDPL expressly addresses processor obligations, including security and recordkeeping requirements.

45. Data Protection and Employees

Employers process substantial amounts of employee information:

  • identity documents;
  • salary information;
  • attendance;
  • performance records;
  • health information;
  • biometric information.

Employment processing therefore requires attention to:

  • lawful basis;
  • purpose;
  • proportionality;
  • security;
  • retention;
  • employee access rights.

An employment contract alone should not be assumed to authorize unlimited processing.

46. Data Protection and CCTV

CCTV and surveillance systems may involve personal data.

Questions can include:

  • why cameras were installed;
  • what areas are recorded;
  • who has access;
  • how long recordings are retained;
  • whether recordings are disclosed;
  • whether monitoring is proportionate.

The UAE's broader privacy and cybercrime framework can become relevant alongside the PDPL.

47. Data Protection and Artificial Intelligence

AI systems can process:

  • customer information;
  • employee data;
  • biometric information;
  • behavioural data;
  • profiling information.

The PDPL specifically contemplates information concerning decisions based on automated processing, including profiling, within the data subject's information rights.

Therefore, organizations deploying AI should consider:

  • purpose;
  • transparency;
  • data accuracy;
  • security;
  • profiling;
  • human oversight;
  • retention.

48. Automated Decision-Making

Automated processing raises additional issues where a decision significantly affects an individual.

The governance model should consider:

Data quality → algorithmic processing → decision → explanation/transparency → legal rights.

A technically accurate algorithm does not automatically make the underlying processing lawful.

49. Cross-Border Litigation

The PDPL expressly recognizes circumstances in which personal data may be transferred outside the UAE for purposes connected with establishing, exercising or defending rights before judicial authorities.

This can be important in:

  • international civil litigation;
  • arbitration;
  • foreign discovery;
  • multinational investigations.

The transfer must nevertheless satisfy the applicable statutory conditions.

50. Data Protection and Arbitration

Where a technology contract contains an arbitration clause, a dispute can combine:

  • PDPL obligations;
  • contractual confidentiality;
  • cybersecurity;
  • electronic evidence;
  • arbitration confidentiality;
  • damages.

The tribunal may need to determine the applicable substantive law and the scope of the parties' contractual obligations.

51. Data Protection and Evidence Preservation

When a data breach occurs, evidence should be preserved promptly.

Potential evidence includes:

  • access logs;
  • security logs;
  • email records;
  • database activity;
  • authentication records;
  • employee communications;
  • forensic images;
  • system backups.

Failure to preserve evidence can make causation and attribution more difficult.

52. Practical Example

Facts

Company A maintains 100,000 customer records.

An attacker obtains unauthorized access.

Step 1 — PDPL question

Was the information personal data within the PDPL?

Step 2 — Scope

Does the PDPL apply to Company A and this processing activity?

Step 3 — Security

Were appropriate technical and organizational measures implemented?

Step 4 — Breach

Was there a qualifying personal-data breach?

Step 5 — Notification

Did the controller comply with applicable breach-notification requirements?

Step 6 — Civil liability

Did affected persons suffer legally recognized harm?

Step 7 — Causation

Can the harm be connected to the breach?

Step 8 — Quantum

What evidence establishes the amount?

This produces a much stronger legal analysis than simply stating:

“A data breach occurred, so compensation is automatically payable.”

53. Practical Compliance Model for UAE Businesses

A UAE business subject to the PDPL should consider:

Governance

  • data inventory;
  • processing register;
  • controller/processor mapping.

Legal

  • lawful basis;
  • privacy notices;
  • consent management;
  • contractual clauses.

Technical

  • encryption;
  • authentication;
  • access control;
  • monitoring;
  • backup.

Organizational

  • employee training;
  • incident-response procedures;
  • vendor management.

Rights management

  • access requests;
  • correction;
  • deletion;
  • restriction;
  • objection.

Litigation readiness

  • evidence preservation;
  • audit trails;
  • incident records;
  • expert documentation.

54. Civil Claim Checklist

A claimant should ideally identify:

A. Data

What information was involved?

B. Legal basis

What PDPL provision or other legal rule protects it?

C. Defendant

Who was the controller, processor or other responsible actor?

D. Conduct

What exactly happened?

E. Evidence

What proves the event?

F. Damage

What injury occurred?

G. Causation

How did the conduct produce the injury?

H. Quantum

What evidence proves the amount?

I. Remedy

Is the claimant seeking:

  • compensation;
  • cessation;
  • deletion;
  • correction;
  • restriction;
  • another protective remedy?

55. Key Distinction Between PDPL Violation and Civil Damages

This is perhaps the most important doctrinal point.

PDPL violation

A controller/processor fails to comply with a statutory data-protection requirement.

Civil damage

The claimant suffers legally recognizable injury as a result.

Compensation

The court determines what remedy follows under the applicable civil-law framework.

Therefore:

Every compensable data claim requires more analysis than simply identifying a regulatory violation.

The recent Dubai technology case, particularly Case No. 611/2025, illustrates this distinction between proving wrongful technological conduct and proving the actual amount of financial damage.

56. Doctrinal Flash List

  1. Federal Decree-Law No. 45 of 2021 is the principal federal PDPL.
  2. It entered into force on 2 January 2022. 
  3. It protects personal-data privacy, confidentiality and security.
  4. Its application is subject to statutory scope and exclusions.
  5. Controllers and processors have different roles.
  6. Lawful processing is fundamental.
  7. Consent is important but statutory exceptions must be considered.
  8. Purpose limitation restricts incompatible processing.
  9. Data minimization limits unnecessary processing.
  10. Accuracy is an important processing principle.
  11. Storage should have an appropriate legal basis and period.
  12. Security is a central obligation.
  13. Data subjects have multiple statutory rights.
  14. Access rights promote transparency.
  15. Correction rights address inaccurate information.
  16. Erasure is subject to statutory conditions and exceptions.
  17. Restriction can limit processing in applicable circumstances.
  18. Objection rights can apply to specified processing.
  19. Automated processing and profiling raise additional transparency issues.
  20. Cross-border transfers are specifically regulated.
  21. Article 9 addresses qualifying personal-data breaches. 
  22. A regulatory breach does not automatically establish a fixed civil award.
  23. Civil claims require damage and causation.
  24. Material damage requires evidentiary support.
  25. Moral damage may arise from privacy-related injury.
  26. Expert evidence can be important.
  27. Experts do not replace judicial decision-making.
  28. Cybercrime and data-protection liability may arise from the same incident.
  29. Contractual data obligations can supplement PDPL obligations.
  30. Cloud processors create additional allocation-of-responsibility questions.
  31. Employee data processing requires appropriate governance.
  32. AI processing requires attention to transparency and security.
  33. Litigation may create lawful grounds for certain processing or transfers.
  34. Criminal findings may be relevant but do not automatically determine civil quantum.
  35. The central UAE civil-law formula is: PDPL-protected interest + applicable duty + unlawful/non-compliant processing + damage + causation + proof = potential civil remedy.

57. Conclusion

The UAE's Federal Decree-Law No. 45 of 2021 establishes a comprehensive federal framework for personal-data protection, covering lawful processing, consent, data-subject rights, security, processors, breach management and cross-border transfers.

From a civil-law perspective, however, the PDPL should not be viewed in isolation. A data dispute may simultaneously involve:

PDPL → Civil Transactions Law → Contract → Privacy → Cybersecurity → Evidence → Damages.

The developing UAE case law shows an important pattern: privacy and technological misconduct can generate legally significant consequences, but a claimant seeking compensation must still establish the nature of the injury, causation and the amount of loss. The 2026 Dubai privacy case illustrates the distinction between moral and unsupported material damage, while Dubai Cassation Case No. 611/2025 illustrates the need to prove actual financial consequences arising from technological wrongdoing.

Accordingly, the best doctrinal formulation is:

The UAE PDPL establishes the statutory protection of personal data; UAE civil law determines the broader consequences of actionable harm; and evidence, causation and damages principles determine whether and to what extent a private civil remedy can be obtained.

Case-law qualification: Because Federal Decree-Law No. 45 of 2021 is relatively recent, the listed authorities should not be treated as six direct PDPL compensation precedents. The directly privacy/technology-related cases are supplemented by UAE Supreme Court and Cassation authorities on privacy, expert evidence, technological misconduct, causation and damages, which are the presently useful judicial principles for analysing PDPL-related civil claims.

 

LEAVE A COMMENT