← Insights

Bank Secrecy in UAE: Confidentiality and Disclosure Obligations

Bank confidentiality in the UAE rests on the Central Bank Law and yields only where the law says so: a valid court order, a supervisory or FIU request, a suspicious transaction report, or exchange under tax transparency commitments.

The Central Bank Law bars a bank from disclosing a client's accounts or transactions without the client's authorisation or a legal mandate. What the article maps is where that duty gives way: court orders, requests from the Central Bank and the Financial Intelligence Unit, suspicious transaction reports under the 2025 AML decree law, and cross-border tax exchange.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

A company opens an account with a bank in the UAE. Nobody raises the subject of confidentiality. No secrecy clause is negotiated, no non-disclosure agreement is signed, nothing is said at the counter about who may later be told what. The account is opened, money moves, and the relationship runs for years without either side giving the question a moment's thought.

Silence is still the default. The Central Bank Law prohibits a bank from disclosing information about a client's accounts or transactions unless the client has authorised the disclosure or the law mandates it. The duty attaches because the account exists, not because anyone asked for it. A client who never mentions confidentiality has exactly the same protection as one whose lawyers spent a fortnight drafting around it.

That matters in both directions. It means a client does not have to bargain for secrecy, and it means a bank cannot treat client information as its own commercial property simply because no contract says otherwise. It also means the two ways out of the duty are the two the statute names. The client can release the bank. Or the law can. There is no third route that runs on commercial convenience, group policy, reciprocity with a correspondent institution, or the fact that the person asking sounds official on the telephone.

A bank that gets this wrong is exposed on two fronts at once. Improper disclosure can found a civil claim by the client for damages, and it can attract regulatory sanction from the Central Bank. Neither route cancels the other. A bank can settle with an aggrieved client and still face the supervisor, because the duty is not merely a private promise between two commercial parties. It is embedded in the regulation of the banking sector as a matter of public policy, and reinforced by the UAE Civil Code and by ministerial resolutions issued under the framework.

Related Services: Explore our non-disclosure agreement compliance and confidentiality drafting services for practical legal support in this area.

What the duty actually covers

The protected category is wider than the number at the bottom of a statement. Confidentiality under the Central Bank Law reaches account details, transaction histories and customer identity data — and, in practice, the material that sits around those things. Knowledge of a client's credit facilities, investment portfolio or payment patterns is confidential client information. So is anything that would reveal a client's identity or business operations indirectly, which is where most avoidable breaches happen: not in handing over a statement, but in confirming a fact that appears harmless on its own.

A useful test for staff is whether the answer tells the listener something they did not already know about a named person's relationship with the bank. Confirming that an individual is a customer does that. Confirming that a payment "went through this morning" does that. Explaining to a caller why a facility was declined does that. None of these look like disclosure of an account, and all of them are.

Records, not just conversations

The obligation follows the data rather than the format. Emails, digital records and telephone conversations sit inside the protected category alongside paper files, which is why access control and encryption are legal controls and not merely IT housekeeping. A bank that has classified its client data, restricted access to the staff who need it, and can show who saw what and when, is in a materially better position when a client alleges leakage than one relying on a general assurance that its systems are secure.

Outsourcing does not move the duty

Banks routinely give third parties access to client data — processors, technology vendors, outsourced service providers. The confidentiality obligation extends to those parties, who are bound contractually to uphold it. What the contract cannot do is relocate the bank's own exposure. The client's relationship is with the bank, and a supplier's failure is not a defence the bank can put to its own regulator. Vendor agreements are worth drafting on the assumption that the bank will answer for whatever the vendor does with the data.

What a breach looks like in practice

Take a bank employee who, because internal controls are loose, passes a client's account information to an unauthorised third party. The disclosure was careless rather than deliberate; nobody sold anything. It is still a violation. The bank faces potential fines from the Central Bank and a civil claim for damages from the client, and the remedial work — notifying the affected party, retraining staff, closing the systems gap that allowed it — begins after the harm rather than instead of it. Intention is not the operative question. Disclosure without authorisation or legal mandate is.

Where the duty gives way: four gateways

Confidentiality under the Central Bank Law is firm but not absolute. The law that creates the duty also creates the exceptions, and there are four routes by which a bank in the UAE lawfully parts with client information in the absence of the client's own authorisation. Each has a different source, a different requester, and a different set of questions the bank has to answer before it hands anything over.

1. A valid court order

The most familiar gateway is a binding order of a court compelling disclosure. Such orders arise out of criminal investigations, out of civil litigation between private parties, and out of arbitration proceedings. Courts in the UAE can compel a bank to produce client information where it is relevant to the administration of justice; in a criminal matter involving fraud or embezzlement, for example, an order may require the bank to produce account statements and transaction records.

The bank's task is narrower than it first appears, and narrower is the point. It has to satisfy itself that the order is genuine, that it comes from a body with authority to make it, and that what is being handed over falls inside the order's scope rather than merely near it. An order about one account does not open the client's other accounts. An order covering a defined period does not license production of the whole file because the whole file is easier to export. Over-production is not compliance with a court order; it is a fresh disclosure with no legal mandate behind it, and the client whose extra records were released has the same complaint as if no order had existed.

2. A supervisory or FIU request

Regulatory authorities can require disclosure under their own supervisory mandates, without a court in the picture. The Central Bank and the Financial Intelligence Unit can each request information from banks in order to monitor compliance with anti-money laundering rules, counter-terrorism financing rules and other regulatory regimes.

These requests are harder to handle than court orders precisely because they arrive with less ceremony. A letter or a portal submission does not announce its own legal basis the way a judicial order does, and the person receiving it in a branch or a back office may not be the person able to assess it. The questions are nonetheless the same: which authority is asking, under what power, about whom, and covering what. A request the bank cannot place inside a recognised supervisory power is not one it should answer by producing records; it is one to escalate. Nor should the sensitivity of the underlying subject matter be allowed to compress the process. Suspicion that a client has behaved badly is a reason for care in what the bank releases, not a licence to release everything.

3. A suspicious transaction report

The third gateway differs from the first two in that nobody asks. Under Federal Decree by Law No. (10) of 2025 Regarding Anti-Money Laundering, and Combating the Financing of Terrorism and Proliferation Financing, banks are obliged to report suspicious transactions. Where the bank suspects, or has reasonable grounds to suspect, that a transaction or funds represent proceeds of crime or are related to it, regardless of their value, the obligation to file a Suspicious Transaction Report with the FIU is triggered. The bank discloses on its own initiative because the law requires it to, and that legal requirement is what makes the disclosure lawful notwithstanding the duty of confidentiality.

This is the gateway most likely to be misread inside a bank, in both directions. Staff who think of confidentiality as the overriding value may hesitate to escalate an internal concern; staff who think of reporting as the overriding value may treat the AML obligation as a general permission to share client information with anyone raising a compliance question. Neither is right. The reporting duty runs to the FIU and is defined by the AML framework. What the bank may or may not say to the client about a report it has filed is itself a legal question to be answered before anyone speaks, not a matter of customer service instinct.

4. Cross-border tax exchange

The fourth gateway operates continuously rather than case by case. The UAE participates in international frameworks for tax transparency, including the Common Reporting Standard and bilateral arrangements under the OECD framework, and banks maintain systems that pass client information to tax authorities. The UAE has also committed to international standards through the Financial Action Task Force recommendations and treaties on the exchange of tax information, which shape how domestic confidentiality and external reporting fit together.

The friction here is one of client expectation rather than legality. A client who understands that a court can reach their records may be genuinely surprised that information moves to a foreign revenue authority through a reporting channel with no case file, no order and no notification of the kind litigation produces. Banks that explain the position at onboarding — that information may be exchanged where tax transparency commitments require it — have far fewer arguments later than banks that leave the client to discover it. Our note on country-by-country reporting covers a related reporting obligation that lands on corporate groups from a different direction.

Handling a request when it arrives

Most of the damage in this area is procedural. The legal analysis of an incoming request is rarely exotic; the failure is that the request reached someone who answered it helpfully. What separates banks that handle disclosure well is that requests for client information travel to one place instead of being resolved wherever they land.

A centralised compliance function, working with legal and operations, gives consistency: the same questions asked of every request, the same escalation route for the awkward ones, the same treatment whether the request arrives at head office or a branch. Complex matters — several agencies at once, or a request touching more than one jurisdiction — need counsel involved early, while the scope of any response is still open, rather than after a first tranche of records has gone out.

Documentation is the other half. Every request for client information, the basis on which it was accepted or refused, the legal advice taken, the approval given and the precise scope of what was released should be recorded at the time. That file is what allows a bank, months or years later, to show that a particular disclosure sat inside a legal mandate and went no further than the mandate allowed. Without it, a bank defending a client claim is reconstructing its own reasoning from memory, against a client who has a statement in hand and a simple question about how it was released. Where a dispute does develop, the record built at the moment of disclosure is usually the strongest material available in banking litigation or in arbitration.

Contracting around the edges

Account documentation cannot enlarge the exceptions the law provides, and a clause purporting to let the bank disclose whenever it finds it convenient does not create a legal mandate. What documentation can usefully do is set expectations: that confidentiality is maintained to the fullest extent permitted by law, and that disclosures may be made where regulatory or judicial requirements demand them. A client who read that at the outset is a client with a smaller grievance when the day comes.

The same drafting discipline applies inside the group. Where a bank shares client information with affiliates, or gives a parent visibility for risk management, the arrangement needs to be tested against the duty rather than assumed to fall outside it because the recipient carries the same brand. Group structure is not one of the gateways. Careful contract drafting is how banks keep intra-group data flows and vendor arrangements inside the law rather than discovering the gap during an investigation.

DIFC and ADGM

The federal picture is not the whole picture. The Dubai International Financial Centre and Abu Dhabi Global Market operate under common law principles with their own regulatory frameworks. Those frameworks introduce their own requirements, and a bank running businesses on both sides of that line cannot assume a single confidentiality policy answers every question. The practical consequence is that the location of the booking entity, and the framework applicable to it, belong in the analysis of any disclosure request before the substance of the request is considered — not after a response has been drafted on federal assumptions.

People and systems

Technology carries a large part of this obligation now. Classifying and encrypting client data, and restricting access by role so that only staff who need to see information can see it, are the controls that make a confidentiality policy real rather than declared. Monitoring tools, including those built on machine learning, help identify the transaction patterns that may require review and reporting under the AML framework.

Automation has a boundary, though, and it is a legal one. A system that flags a series of transfers to a high-risk jurisdiction has produced a candidate for review, not a decision. Human review before anything leaves the bank is what keeps the eventual disclosure inside the reporting obligation and stops an automated export from becoming an unmandated one. Alongside that sits training: frontline staff who can recognise the behaviour that ought to be escalated internally, and who know that a plausible-sounding request for client information is answered by referral rather than by an answer. Cybersecurity belongs in the same frame, since a breach achieved from outside exposes the same client information the law requires the bank to protect from inside.

Conclusion

Bank secrecy in the UAE begins as a statutory default that neither party has to ask for, and it ends only where the law says it does — a valid court order, a supervisory or FIU request, a suspicious transaction report under the 2025 AML decree law, or exchange under the UAE's tax transparency commitments. The recurring failure is not banks refusing lawful requests. It is banks answering more than was asked, by people who were never in a position to judge the request, without a record of why.

Nour Attorneys advises banks and their clients on confidentiality and disclosure under UAE law: assessing requests as they arrive, defining the scope of a lawful response, and building the documentation that supports it afterwards. Our work in banking and finance, regulatory compliance and dispute resolution covers both sides of the question — the institution deciding what it must disclose, and the client asking whether a disclosure was lawful.

Disclaimer

This article is for informational purposes only and does not constitute legal advice.

Additional Resources

Contact Nour Attorneys

For advice on a specific disclosure request, or on the confidentiality framework governing an account relationship, contact Nour Attorneys through our banking and finance page.

Call Us NowChat With Our Team On WhatsApp