News & Events

Cyber Crime in the UAE

Submitted By Firm: Clyde & Co

Contact(s): David Salt, Emma Higham, Rebecca Ford, Sara Khoja

Author(s):

Rebecca Kelly and Diana Hudson.

Date Published: 10/1/2012

Article Type: Legal Update

Share This:

This article provides an overview of data privacy in the UAE, explores the risks that companies face in relation to data loss by reference to case studies from the region and provides practical suggestions as to how businesses might seek to mitigate their exposure to risks of cyber crime.

In an era where we have increasingly put more of our lives and businesses online, individuals and businesses face new challenges protecting their information and reputation in the form of cyber crime. For individuals there is the threat of viruses, identity theft and cyber stalking.  For businesses, there is the fear their systems can come under attack, either externally or by negligent and malicious acts of their employees or third parties, putting vital data and reputations at risk. 

Pricewaterhouse Coopers' (PwC) Global Economic Crime Survey of 2011 highlighted cyber crime as a serious emerging risk and threat to businesses the world over.  The Middle East is no exception.  Indeed, one need only refer to the cyber attack suffered by Saudi Aramco in August 2012 to note this worrying trend.

As awareness of the implications of cyber crime increases around the globe, many jurisdictions have put into place specific legislative regimes, compliance with which is crucial in the effort to limit the financial and reputational harm that consumers and businesses may suffer as a result of such breaches.

Data Privacy and Data Loss

Data privacy laws are enacted to focus on the protection of and storage of personal data.  These laws usually address and sanction illegal use, disclosure and processing of personal data. In most legal systems, “personal data" refers to information relating to an identified or identifiable individual.

The term 'data loss' refers not just to the accidental loss of information, but may also include any data breach.  It may, therefore, take the form of infiltration of a company's IT system by external parties or a virus.  Or, most likely, result from an employee's deliberate or negligent actions, such as leaking confidential information to external parties, incorrect use of email forwarding or losing (or having stolen) equipment such as laptops or USB flash drives. 

UAE Legal Framework

Federal Laws

There is no specific data protection law in the UAE, however there is a data protection law in certain free zones (explained in more detail below). For the rest of the UAE, restrictions and or penalties relating to data privacy can be found in a number of legislative sources including:

  • The UAE Constitution of 1971, which enshrines the right to privacy of personal information and guarantees "Freedom of communication by post, telegraph or other means of communication and the secrecy thereof."
  • The UAE Penal Code of 1987 (as amended), which in particular prohibits:
    • (a) the publication, through any means, of news, pictures or comments pertaining to the secrets of people's private or familial lives;
    • (b) any person who by reason of profession, craft, circumstance or art, is entrusted with a secret from disclosing or using (to his or another’s advantage) that secret without the consent of the individual concerned or where not otherwise permitted by law; and
    • (c) the interception and/or disclosure of correspondence or a telephone conversation without the consent of the relevant individuals.  For those who fail to adhere to the law, the Penal Code sets severe penalties, which include fines and imprisonment.
  • The UAE Civil Transactions Law, Federal Law No. 5 of 1985 (as amended), provides that a person is liable for all acts causing harm. This could include harm caused by un-authorised use or publication of the personal or private information of another.

Some other UAE laws that contain privacy protection and or requirements relating to data collection, storage and use (other than the Penal Code; Civil Transactional Law and the Constitution) include:

  • Labour Law (Law No. 8 of 1980 as amended).
  • Electronic Transactions and E-Commerce Law (Dubai Law No.2 of 2002)
  • Combating Cyber Crimes Law (Federal Law 2 of 2006)
  • E-transactions and E-commerce (Federal Law No. 1 of 2006)

Free Zones

Certain Free Zone areas of Dubai International Financial Centre (DIFC) and Dubai Healthcare City (DHCC) have enacted comprehensive data protection framework based upon the European model, which place a number of obligations on businesses established in those zones.  These include restrictions on transferring personal data or patient health information to recipients located in jurisdictions outside the DIFC or DHCC respectively, without the individual's consent. 

Transferring Data Overseas

In addition, UAE companies performing cross-border data transfers may also be subject to data protection rules of the jurisdiction from which the data is exported.  This is a particularly important consideration for intra-group transfers where, for example, under the EU Data Protection Directive, such transfers may take place only if there is an adequate level of protection for the data or information in the importing jurisdiction and the exporting company retains primary liability for any data breach.

UAE Data Breach Examples

Companies in the UAE have not been immune to data breaches.  Indeed, there have been a number of widely reported incidences of hacking, phishing, identity theft and cyber attacks which go beyond the scope of this article.  Some of the more recent examples include:

Accidental Email leading to Disclosure of Personal Data

In this case, a UAE-based company outsourced its payroll function, as is common practice.  An employee of the payroll company (also based in the UAE) accidentally sent an email to all employees of the client company, which contained the personal and private financial information of those employees.  The payroll company took a number of steps in an effort to minimise the further dissemination of the personal data but the damage had already been done. 

The legal implications in the UAE's data protection regime are not immediately obvious, but included consideration of the extent of:

(i) any obligation on the company to notify the breach to the authorities, including the Ministry of Labour who, given certain rules relating to data handling in the Labour Law, may wish to investigate the breach;

(ii) any breach of the Penal and/or Civil Code including the technical requirement to report a criminal offence;

(iii) any possible civil action by an employee for harm caused by the disclosure of his/her personal data; and

(iv) any other data protection legislative regimes that might have been triggered as a result of the breach.

Employee Using Email to disclose Confidential Company Information

In this case, an in-house Legal Counsel at (the "Employer") was charged with revealing company secrets to another company via email.  The company secrets in question included Employer's financial information, names of the Employer's clients and allegations that the Employer had failed to execute certain projects and was facing financial ruin.

The Legal Counsel denied the charges, saying he simply emailed a friend from work a couple of times about what was going on in his life.  He did not believe that the Employer had suffered any loss or that the other company gained a competitive advantage as a result of the email.  However, the Employer said he provided the information in an attempt to secure a position elsewhere. 

The Legal Counsel was convicted in absentia and sentenced to 3 years imprisonment.  A civil suit was also filed and temporary compensation of AED 200,000 was ordered.  This case serves to highlight the interplay between the civil and criminal laws to combat cyber crime.

Future Trends

The PwC Global Economic Crime Survey 2011 reported that 34% of respondents had experienced economic crime in the last 12 months, an increase of 21% from 2009, with almost 1 in 10 of respondents reporting losses of more than USD 5 million, illustrating the huge financial losses that companies can face. 

As an emerging market, there is no reason to think companies in the UAE will not suffer at least the similar growth in cyber crime as experienced globally.  In addition, the variety of legal regimes and the risks posed by cyber crime should encourage UAE businesses to take reasonable measures to prevent data breaches. 

It may be prudent of a company to draw up policies and procedures based on international best practices that comprise:

  • assigning responsibility at senior level for dealing with data security;
  • establishing a specific committee to assess, monitor and control data security risk;
  • putting in place written policies which are accessible and easily understandable by all and reflect the uptake by individuals in using social media tools;
  • introducing appropriate software which assists with data management;
  • establishing an emergency response plan; and
  • providing training, regular updates and notifications to employees on their obligations and permitted use of confidential and commercially sensitive information.

To help bear the costs associated with data breaches, businesses may also wish to consider cyber liability insurance as part of their overall risk management strategy.  Such specialised insurance products are now available from international insurers based in the region.  The insurance is designed to address first and third party losses or liabilities associated with data breach. 

Cover for first party losses (i.e. a business's own losses) arising from cyber risks include: the costs of data recovery and rectification whether through a network security breach or another cause such as human error, cyber extortion, business interrupt and crisis management costs.  Cover for third party liabilities (i.e. liability to pay others) on the other hand include: claims arising from privacy/confidentiality breach, defamation or copyright infringement through email or website content and damage to another's network systems through transmissions of viruses.  With the assistance from insurance brokers with specialist knowledge of cyber risks, businesses could benefit from purchasing such insurance.

To conclude, in a world of increasing reliance on the electronic storage and transfer of information, the risk of data loss, by whatever means, is only becoming greater.  However, businesses could limit their exposure by ensuring that the right mitigation measures are in place. 

Find an Employment Lawyer

In all 50 U.S. states, every Canadian province, and over 135 countries. View or print a complete ELA member list by clicking here.

Find an Immigration Lawyer

Facilitate employee transfers around the globe. View or print a complete ELA member list by clicking here.

International Background Checks Summaries

Your free resource summarizing the requirements for pre-employment checks around the world.

Client Successes

Altra Industrial Motion Inc.

Altra Industrial Motion Inc. has multiple locations in the U.S., as well as Central America, Europe, and Asia. The Employment Law Alliance has proved to be a great asset in assisting us in dealing with employment issues and matters in such diverse venues as Mexico, Australia, and Spain. We have obtained excellent results using the ELA network for matters ranging from a multi-state review of employment policies to assisting with individual employment issues in a variety of foreign jurisdictions.

In one instance, we were faced with an employment dispute with a former associate in Mexico that had the potential for substantial economic exposure. The matter had been pending for over a year, and we were not confident in the employment advice we had been receiving. I obtained a referral to the ELA counsel in Mexico, who was able to obtain a favorable resolution of the dispute in only a few days. Based on our experiences with the ELA, we would not hesitate to use its many resources for future employment law needs.

American University in Bulgaria

In my career I have been a practicing attorney, counsel to the Governor of Maine, and CEO of a major public utility. I have worked with many lawyers in many settings. When the American University in Bulgaria needed help with employment litigation in federal court in Syracuse, New York, we turned to Pierce Atwood, the ELA member we knew and trusted in Maine, for a referral. We were extremely pleased with the responsiveness and high quality of service we received from Bond Schoeneck & King, the ELA's firm in upstate New York. I would not hesitate to recommend the ELA to any employer.

David T. Flanagan
Member of Board of Trustees 

Arcata Associates

I really enjoyed the Conducting an Effective Internal Investigation in the United States webinar.  We are in the midst of a rather delicate employee relations issue in California right now and the discussion helped me tremendously.  It also reinforced things that you tend to forget if you don't do these investigations frequently.  So, many, many thanks to the Employment Law Alliance for putting that webinar together.  It was extremely beneficial.

Lynn Clayton
Vice President, Human Resources

Barrett Business Services, Inc.

I recently participated in the ELA-sponsored webinar on the Employee Free Choice Act.  I was most impressed with that presentation.  It was extremely helpful and very worthwhile.  I have also been utilizing the ELA's online Global Employer Handbook.  This compliance tool is absolutely terrific. 

I am familiar with several other products that purport to provide up-to- date employment law information and I believe that this resource is superior to other similar compliance manuals.  I am delighted that the ELA provides this free to its members' clients.

Boyd Coffee Company

Employment Law Alliance (ELA) has provided Boyd Coffee Company with a highly valued connection to resources, important information and learning. With complex operations and employees working in approximately 20 states, we are continually striving to keep abreast of specific state laws, many of which vary from state to state. We have participated in the ELA web seminars and have found the content very useful. We appreciate the ease, cost effectiveness and quality of the content and presenters offered by these web seminars.  The Global Employer Handbook has provided our company with a very helpful overview of legal issues in the various states in which we operate, and the network of attorneys has helped us manage issues that have arisen in states other than where our Roastery and corporate headquarters are located in Portland, Oregon.

Capgemini Outsourcing Services GmbH

As an international operating outsourcing and consulting supplier Capgemini has used firms of the Employment Law Alliance in Central Europe. We were always highly satisfied with the quality of employment law advice and the responsiveness. I can really recommend the ELA lawyers.

Hirschfeld Kraemer

As an employment lawyer based in San Francisco, I work closely with high tech clients with operations around the globe. Last year, one of my clients needed to implement a workforce reduction in a dozen countries simultaneously. And they gave me 48 hours to accomplish this. I don't know how I could have pulled this off without the resources of the ELA. I don't know of any single law firm that could have made this happen. My client received all of the help they needed in a timely fashion and on a cost effective basis.

Stephen J. Hirschfeld
Partner 

Hollywood Entertainment Corporation

As the Vice President for Litigation & Associate General Counsel for my company, I need to ensure that we have a team of top-notch employment lawyers in place in every jurisdiction where we do business. And I want to be confident that those lawyers know our business so they don't have to reinvent the wheel when a new legal matter arises. With more than 3400 stores and 35,000 employees operating in all 50 U.S. states and across Canada, we rely on the ELA to partner with us to help accomplish our objectives. I have been delighted with the consistent high quality of the work performed by ELA lawyers. I encourage other in-house counsel to use their services, as well.

Ingram Micro

Ingram Micro is the world's largest technology distributor, providing sales, marketing, and logistics services for the IT industry around the globe. With over 13,000 employees working throughout the U.S. and in 35 international countries, we need employment lawyers who we can count on to ensure global legal compliance. Our experience with many multi-state and multi-national law firms is that their employment law services are not always a high priority for them, and many do not have experts in many of their offices. The ELA has assembled an excellent team of highly skilled employment lawyers, wherever and whenever I need them, and they have proven to be an invaluable resource to our company.

Konami Gaming

Our company, Konami Gaming, Inc., is growing rapidly in a very diverse and highly regulated industry. We are aggressively entering new markets outside the domestic U.S., including Canada and South America. I have had the recent opportunity to utilize the services provided by the ELA. The legal advice was both responsive and professional. Most of all, the entire process was seamless since our Nevada attorney coordinated the services and legal advice requested. I look forward to working with the ELA in the future, as it serves as a great resource to the legal community.

Jennifer Martinez
Vice President, Human Resources

Nikkiso Cryo, Inc.

Until recently, I was unaware of the ELA's existence. We have subsidiaries and affiliates throughout the United States, as well as in Asia, the Middle East and Europe. When a recent legal issue arose in Texas, our long-time Nevada counsel, who is a member of the ELA, suggested that this matter be handled by his ELA colleague in Dallas. We are very pleased with the quality and timeliness of services provided by that firm, and we are excited to now have the ELA as an important asset to help us address employment law issues worldwide.

Palm, Inc.

The ELA network has been immensely important to our company in helping us address an array of human resources challenges around the world. I strongly encourage H.R. executives who have employees located in many different jurisdictions to utilize the ELA's unparalleled expertise and geographic coverage.

Stacy Murphy
Former Senior Director of Human Resources

Rich Products

As the General Counsel for a company with 6,500 employees operating across the U.S. and in eight countries, it is critical that I have top quality lawyers on the ground where we do business. The ELA is an indispensable resource. It has taken the guesswork out of finding the best employment counsel wherever we have a problem.

Jill K. Bond
Senior Vice President/General Counsel, Shared Services and Benefits

Ricoh Americas Corporation

We have direct sales and service offices all over the U.S., but have not necessarily had the need in the past for assistance with legal work in every state where we have a business presence. From time to time, we suddenly find ourselves facing a legal issue in a state where we have no outside counsel relationship. It has been a real benefit to know that the ELA has assembled such an impressive team of experts throughout the U.S. and overseas.

A few years ago, we faced a very tough discrimination lawsuit in Mississippi. We had never had to retain a lawyer there before. I was absolutely delighted with the Mississippi ELA firm. We received an excellent result. They will no doubt handle all of our employment law matters in Mississippi in the future. I have also obtained the assistance of several other ELA firms around the U.S. and have received the same outstanding service. The ELA is a tremendous resource for our company.

Roberts-Gordon LLC

Our affiliated companies have used the Employment Law Alliance in connection with numerous acquisitions, and have always been extremely pleased with our ability to obtain the highest quality legal advice on due diligence issues from jurisdiction to jurisdiction. We have found the Employment Law Alliance firms to be not only first rate with respect to their legal advice but also responsive and timely in assisting us with federal and state law issues critical to our due diligence efforts. We consider the Employment Law Alliance to be an important part of our team.

Rockwell Collins, Inc.

We have partnered with many ELA firms on the development and execution of case management strategies with very positive results. We have been very pleased with the legal advice and counsel provided by the law firms we have utilized who are affiliated with the Employment Law Alliance. The ELA firms we have worked with are customer focused, responsive, and thorough in their approach to handling labor and employment law matters.

Elizabeth Daly
Assistant General Counsel

Sanmina-SCI

Sanmina-SCI has facilities strategically located in key regions throughout the world. Our customers expect that we will provide them with the highest quality and most sophisticated services in the marketplace. We have that same expectation for the lawyers with whom we do business. With operations in 17 countries, we need to be certain that we have a team of lawyers working together to address our employment law needs worldwide. The ELA has delivered exactly what it promised-- seamless and consistent high quality services delivered in each locale around the globe. It has quickly become a key asset for our human resources department.

Starwood

We own, manage, and franchise hotels throughout the U.S. and in more than 90 countries. With more than 145,000 employees worldwide, ensuring that we comply with the complex web of local labor and employment laws in every one of these jurisdictions is a daunting task. The Employment Law Alliance has served as an important resource for us and we have benefited greatly from its expertise and long reach. When a legal dispute or issue has arisen in some far-flung place, Employment Law Alliance lawyers have always provided responsive, practical, and cost-effective assistance.

Wilmington Trust Corporation

Wilmington Trust has used the ELA to locate firms in California, Washington State, Georgia, and Europe. Our experience with the ELA lawyers with whom we have worked has always been one of complete satisfaction and prompt, practical advice.

Michael A. DiGregorio
General Counsel  

Loading...