What the federal cybercrime regime actually covers
The UAE's cybercrime framework is federal, and its breadth is the first thing to understand about it. It is not a computer-misuse statute confined to hacking. It reaches unauthorised access to systems and accounts; interception and disclosure of communications; electronic forgery and identity misuse; online fraud and deception; extortion and threats made by electronic means; unlicensed dealing in virtual assets; and a wide band of content offences covering defamation, insult, false information, material offensive to public morals, and content touching state institutions and social cohesion.
Two consequences follow, and both surprise foreign-managed businesses.
- The conduct threshold is lower than in most common-law systems. Content that would be a civil defamation claim elsewhere is a criminal matter here, and the medium is not limited to publication. Private messages, one-to-one exchanges and closed groups are within reach.
- Corporate exposure is real, not theoretical. The framework contemplates liability of legal persons where an offence is committed in the entity's name, by someone acting for it, or to its benefit — alongside the individual's own exposure.
The practical effect is that decisions ordinarily taken by IT or HR — terminate the account, delete the post, message the counterparty, pay the demand — are decisions with criminal consequences. They should be taken with counsel in the room, not reported to counsel afterwards. We do not describe the statute to clients; we tell them which of their intended next steps is an offence.
Online defamation and reputational offences
Speech-based complaints are the highest-volume cyber matter in the UAE and the least well understood by clients who arrived from jurisdictions where reputation is a civil question. Here it is primarily criminal, and the complaint is cheap to file.
That asymmetry drives the tactics. A criminal cyber complaint is routinely used as leverage in a commercial dispute — a supplier who has not been paid posts a warning, a former employee writes a review, a partner sends an angry message to a group. The complaint that follows is not really about reputation; it is about creating a travel restriction and a bargaining position while the underlying money dispute is negotiated.
Both sides of that dynamic need advice, and the advice differs sharply:
- For the accused, the priority is the position at prosecution stage, before referral. Most speech matters are capable of resolution there — withdrawal of the complaint, removal of the content, an agreed statement. Once a file is referred to court, the cost, duration and travel consequences multiply for a dispute that was never worth them.
- For the complainant, the priority is proving publication and attribution to a standard that survives challenge, and deciding honestly whether a criminal route serves the commercial objective. It frequently does not: a conviction does not remove the content, and it does not recover the money.
We take instructions on both sides and give the same answer to each: identify what you actually want, then choose the route. Filing first and thinking second is how these matters become long.
Data breach and incident response
A breach triggers obligations under a different body of law from the one that criminalises the intrusion, and the two run on different timetables. The criminal framework tells you what was done to you. The data protection regime tells you what you now owe your regulator and the individuals whose data moved.
Which data regime applies turns on where the controller is established, and this is the most commonly conflated point in UAE incident response. Onshore entities sit under the federal Personal Data Protection Law. DIFC-established entities sit under the DIFC's own data protection law and answer to the DIFC Commissioner of Data Protection. ADGM-established entities sit under ADGM's own regulations and answer to its data protection office. These are three distinct statutes with three distinct notification standards. A group with entities in more than one of them has more than one notification decision to make, and they are not interchangeable.
Sector rules layer on top. Licensed financial institutions carry Central Bank expectations; telecommunications and technology providers carry TDRA obligations; entities within scope of national cyber-security arrangements carry reporting expectations of their own. Free-zone licensing does not displace these.
The sequencing we advise is consistent: preserve and contain, scope the affected data, take the notification decisions under privilege on the evidence actually available, and only then decide whether to file a criminal complaint. Reversing that order commits you to facts you have not yet verified. See also Data Protection & PDPL.
| Regime | What it governs | Who a breach is reported to | Criminal jurisdiction |
|---|---|---|---|
| UAE Federal | Cybercrime offences across all emirates and free zones; the federal data protection law for onshore controllers | Federal data protection authority; sector regulators including the Central Bank and TDRA where applicable | Yes — federal criminal law, prosecuted at emirate level |
| Dubai (onshore) | Federal criminal law applied through Dubai's police and prosecution structures | Federal and sector channels; the incident is reported to Dubai Police for the criminal element | Dubai Public Prosecution and Dubai Courts |
| Abu Dhabi (onshore) | Federal criminal law applied through Abu Dhabi's police and judicial structures | Federal and sector channels; the criminal element goes to Abu Dhabi Police | Abu Dhabi Public Prosecution and the Abu Dhabi Judicial Department |
| DIFC | Its own data protection law and its own civil and commercial court rules | The DIFC Commissioner of Data Protection | None — criminal complaints go to onshore police and prosecution |
| ADGM | Its own data protection regulations and its own civil and commercial court rules | The ADGM data protection office | None — criminal complaints go to onshore police and prosecution |
Ransomware, extortion and financial fraud
Extortion matters compress every decision into a short window, usually with incomplete information. Three points determine the outcome.
The payment decision is a legal decision, not a commercial one. Before any transfer, the question is who is being paid. If the recipient is sanctioned, or the payment is made through an unlicensed channel, the victim has created a second problem larger than the first. Sanctions screening, counterparty tracing and the licensing status of any virtual-asset route need to be resolved before funds move — see Virtual Assets / VARA.
Payment fraud is a recovery race, not a prosecution. In business email compromise and invoice-redirection matters, the realistic objective is freezing funds downstream while they are still identifiable. That means an immediate approach to the receiving bank and, where the file supports it, precautionary attachment — not waiting for a criminal investigation to reach the same accounts weeks later. Investigation and asset recovery run in parallel or the money is gone.
Investment and romance fraud files are usually about tracing, not liability. Liability is rarely in dispute; the perpetrator's identity and asset position are. Where the trail runs through virtual assets, on-chain analysis can establish flow, but it converts into recovery only where the terminus is a regulated exchange or an identifiable UAE-resident asset.
We tell clients early when recovery is not realistic. A criminal complaint filed to satisfy a board rather than to recover funds is an expensive way to document a loss.
Corporate internal investigations and employee devices
When a company suspects its own people, the investigation itself creates exposure. Three constraints shape how we run these.
Privilege. UAE onshore practice does not replicate common-law legal professional privilege, and an internal report written on the assumption that it will never be disclosed is a document written on a false premise. We structure the workstream around who commissions the report, who holds it, and what is committed to writing at each stage — on the working assumption that it may be seen.
Device access. The instinct to image an employee's phone or open their mailbox the moment misconduct is suspected is where employers most often convert a strong case into a compromised one. Access to a corporate-issued device under a clear acceptable-use policy is a different proposition from access to a personal device, a personal account, or private messages — and the data-protection analysis differs again from the employment-law analysis. Both have to be answered before the image is taken, not justified afterwards. See Employment & Labour.
Sequencing against the criminal route. Confronting the employee before evidence is secured produces deletion. Filing a complaint before the internal facts are settled produces a complaint the company cannot stand behind. Terminating before either is done can hand the employee a labour claim that runs alongside your criminal file and undermines it.
The order we work in is: preserve, scope, verify, then decide on confrontation, termination and complaint — as one decision, not three.
Digital evidence and how it survives challenge
Most cyber files are won or lost on evidence handling rather than on legal argument, and the weaknesses are predictable.
Screenshots are the weakest common exhibit. They show content but not provenance, and they are trivially challenged as fabricated or edited. They should be supported by platform-level records, device-level extraction, or notarised capture — not offered alone. Attribution is the second recurring gap: proving that an account published something is not proving that a particular person controlled the account, and defence work in speech and fraud matters concentrates precisely there.
Chain of custody is the third. Where an image is taken, by whom, on what tooling, with what hash verification, and who has held it since are all questions capable of being asked. A file assembled informally by an IT manager rarely answers them.
Language is the practical constraint clients underestimate. Onshore proceedings run in Arabic. Technical material — log extracts, forensic reports, chain-of-custody records, chat exports — requires legal translation that preserves technical meaning. A poorly translated forensic report is a weakened forensic report, and the time this takes belongs in the timetable from the start.
On the defence side, the same list is an audit checklist. Where the prosecution file rests on a screenshot with no provenance, an attribution inference with no supporting subscriber or device evidence, or an image taken without documented custody, those are the points to take — and they are best taken at prosecution stage.
Cross-border cooperation and parallel exposure
Cyber matters are rarely contained within one jurisdiction, and the practical questions are narrower than the theory suggests.
UAE authorities assert jurisdiction on a broad basis where an element of the offence connects to the UAE — the victim, the systems, or the money flow. A client whose only connection is that funds passed through a UAE account can find themselves in scope. The converse is also true: conduct within the UAE aimed at victims abroad attracts foreign attention.
Where cooperation runs through formal mutual legal assistance channels, it is slow and the timetable is not within your control. Where a foreign platform holds the evidence, direct preservation requests to the provider are frequently faster and more productive than waiting for a state-to-state route, provided they are made before retention periods expire. That timing point matters more than the choice of channel.
For individuals with exposure in more than one jurisdiction, the sequencing risk is what an admission or a settlement in one place does to the position in another. A statement given to UAE prosecutors, an internal report produced to a foreign regulator, or a settlement recital agreed to close a UAE file can all be read across. Coordination with counsel in the other jurisdiction has to happen before the first substantive step, not after.
International notices and travel restrictions are best addressed while a matter is live rather than years later. See International Litigation.
How the criminal complaint interacts with the civil claim
Clients usually want two things — the perpetrator punished and the money back — and treat them as one process. They are not, and choosing the wrong lead track costs both time and leverage.
The criminal route has advantages the civil route cannot replicate: investigative powers no private party has, access to records a claimant cannot obtain, and travel restrictions that keep a defendant reachable. Its disadvantages are that you do not control it. Once a complaint is filed, the timetable, the scope and the decision to refer or close belong to the prosecution, and a decision not to refer is difficult to work around later.
The civil route is slower to bite but you direct it, and it is the track on which money is actually recovered. Precautionary attachment secured early is worth considerably more than a criminal outcome secured late against a defendant who has moved assets in the interim.
The interaction point that matters is that a criminal finding materially assists the civil claim, while civil proceedings may be paused pending the criminal outcome — so the order in which you start them shapes the whole timeline. Where recovery is the objective, we generally secure the civil position first and use the criminal route to support it. Where deterrence or the removal of content is the objective, the balance reverses. See Judgment Enforcement.
Where this goes wrong
The failure modes in cyber matters repeat with unusual consistency. In order of how often we are called after the fact:
- Evidence destroyed by ordinary operations. Logs rotate, backups overwrite, cloud retention defaults purge, and IT wipes the departing employee's laptop as a matter of routine. Nobody intends it. A preservation hold issued on day one prevents almost all of it.
- The company investigates itself into a defect. Devices imaged without authority, personal accounts accessed, employees interviewed without a record. The underlying case may be sound; the way it was assembled is what gets attacked.
- A complaint filed before the facts are settled. The initial account becomes the account you are held to. When forensics later contradicts it, the credibility problem is yours, not the defendant's.
- Notification decisions taken by the wrong regime. A group applies its onshore analysis to a DIFC entity, or vice versa, and notifies the wrong regulator on the wrong basis — or notifies neither.
- A ransom paid without sanctions screening. The extortion becomes the smaller of two problems.
- Speech matters escalated past the point of cheap resolution. A dispute worth a retraction and an apology is referred to court because nobody engaged at prosecution stage.
- Recovery abandoned to the criminal track. Funds traceable in week one are unreachable by week six because the civil attachment was never sought.
Every item on that list is a decision taken in the first days, usually by someone who did not know it was a legal decision.
Frequently asked questions
Is online defamation a criminal matter in the UAE?
Yes. The federal cybercrime framework treats defamation, insult and the spread of false information by electronic means as criminal conduct, and the reach extends beyond public publication to private messages and closed groups. This is the single largest adjustment for businesses arriving from jurisdictions where reputation is dealt with civilly. In practice a large proportion of these complaints are commercial leverage rather than genuine reputational grievance, and most are capable of being resolved at prosecution stage before referral to court — which is where engagement is worth the most.
Our company is licensed in DIFC. Does UAE cybercrime law apply to us?
Yes. Criminal law in the UAE is federal and applies inside the free zones. DIFC and ADGM courts have no criminal jurisdiction — they hear civil and commercial matters. If your systems are attacked, or an employee is accused of a cyber offence, the criminal file runs through onshore police and the relevant emirate's Public Prosecution regardless of your licence. What free-zone establishment does change is your data protection regulator and your civil forum, and those are genuinely different from the onshore position.
We have had a data breach. What do we do in the first 24 hours?
Preserve before you investigate: issue a hold that stops log rotation, backup overwriting and device reimaging, and suspend any routine deletion. Contain the intrusion. Establish which entity is the controller, because that determines whether the federal data protection law, the DIFC regime or the ADGM regime governs your notification — they are separate statutes and not interchangeable. Scope the affected data under privilege before making statements. Take the criminal complaint decision last, once the facts are verified. Reversing that order commits you to an account you cannot yet stand behind.
Can we pay a ransomware demand?
Not until you know who you are paying. If the recipient is sanctioned, or the payment route is an unlicensed virtual-asset channel, the payment creates exposure larger than the original incident. Sanctions screening, counterparty tracing and the licensing status of the payment route need to be resolved before funds move — under time pressure, but before, not after. There are also insurance and disclosure consequences to a payment that has not been documented properly. This is a decision to take with counsel in the room rather than to report afterwards.
Can we image an employee's phone if we suspect misconduct?
It depends on whose device it is, what your policies say, and what you are looking for. A corporate-issued device covered by a clear and acknowledged acceptable-use policy is a very different proposition from a personal device, a personal email account, or private messaging content. The employment analysis and the data protection analysis are separate, and both have to be answered before the image is taken. Employers who image first and justify later frequently convert a strong misconduct case into a compromised one, and hand the employee a labour claim in the process.
Are screenshots enough evidence?
Rarely, on their own. A screenshot shows content but not provenance, and it is straightforward to challenge as edited or fabricated. It should be supported by platform-level records, a properly conducted device extraction, or notarised capture. The second and larger gap is attribution: proving that an account published something is not the same as proving that a particular person controlled that account at that time. Most defence work in speech and fraud matters concentrates on exactly those two gaps, so both sides should assess a file against them early.
Should we file a criminal complaint or a civil claim first?
It depends on the objective. If the objective is recovering money, the civil track is usually led first — precautionary attachment secured while funds are still traceable is worth more than a criminal outcome obtained after assets have moved, and civil proceedings may be paused pending a criminal outcome. If the objective is deterrence, removal of content, or access to investigative powers you cannot exercise privately, the criminal route leads. What you should not do is file a complaint reflexively: once filed, the timetable and the scope belong to the prosecution, not to you.
What happens with cross-border cybercrime?
UAE authorities assert jurisdiction where an element of the offence connects to the UAE — the victim, the systems, or the money flow — so a party whose only link is a UAE account can find itself in scope. Where evidence sits with a foreign platform, a direct preservation request to the provider is often faster and more productive than a formal state-to-state channel, provided it is made before retention periods expire. For anyone with exposure in more than one jurisdiction, the critical point is that statements and settlements in one forum can be read across into another, so parallel counsel should be engaged before the first substantive step.