← Insights

DIFC Courts Release New Electronic Evidence Practice Direction

The DIFC Courts' latest Practice Direction on Electronic Evidence sets clear rules for preserving, authenticating, and admitting emails, instant messages, and cloud-based data in DIFC litigation.

The article explains the DIFC Courts' Practice Direction on Electronic Evidence, detailing the steps parties must take to preserve electronic data once litigation is anticipated, including litigation hold notices, native format collection, metadata capture, and hash generation. It outlines how to authenticate emails and chat messages through witness testimony, metadata reports, hash value comparison, and chain-of-custody logs, and notes the potential sanctions for non-compliance.

Reviewed by Mohamed Noureldin, Founder, Managing Partner & Senior Legal Consultant

The DIFC Courts' Practice Direction on Electronic Evidence sets out how parties must preserve, authenticate, and admit emails, instant messages, and cloud-based data in DIFC litigation, applying the DIFC Courts Law and the DIFC Courts Practice Direction on Electronic Evidence.

Related Services: Explore our Courts Litigation Services and DIFC Courts services for practical legal support in this area.

WHAT STEPS MUST I TAKE TO PRESERVE ELECTRONIC EVIDENCE ONCE LITIGATION IS ANTICIPATED?

You must issue a litigation hold notice to all relevant custodians, suspend routine deletion policies, and preserve native formats of emails, chats, and cloud files as soon as you reasonably anticipate proceedings. The Practice Direction requires that the hold be documented, communicated in writing, and monitored for compliance, with any failure to preserve potentially leading to adverse inferences or sanctions under the DIFC Courts Law.

Developing this obligation, the Practice Direction explains that a litigation hold should identify the specific categories of data (e.g., Outlook PST files, Slack exports, Google Drive folders) and the custodians responsible for each. It advises counsel to work with IT teams to place legal holds on backup systems and to disable automatic archiving or deletion features that could overwrite relevant content. The direction also notes that parties should preserve metadata because it can be crucial for establishing authenticity and integrity. Costs associated with forensic collection and storage are generally borne by the requesting party unless the court orders otherwise, and the Practice Direction encourages parties to agree on a proportionality protocol early in the case to avoid disputes over excessive preservation burdens.

How should a litigation hold be structured?

A well-drafted hold typically contains:

  1. Scope statement - a concise description of the matters under investigation, the time period covered, and the types of communications sought (e-mail, instant messaging, VoIP recordings, shared drives).
  2. Custodian list - names, job titles, and contact details of every employee, contractor, or third-party who may possess relevant data, together with the specific data sources each custodian controls (personal mailbox, shared mailbox, mobile device, collaboration platform).
  3. Preservation instructions - clear directives to suspend auto-delete rules, disable retention-policy overrides, and place legal holds on archiving systems, tape backups, and cloud-service snapshots.
  4. Documentation requirements - a log-sheet that records when the hold was issued, who received acknowledgment, and any follow-up reminders; this log becomes evidence of good-faith compliance if the court later examines spoliation claims.
  5. Monitoring mechanism - assignment of a compliance officer or external vendor to verify that custodians have not altered or deleted data, with periodic attestations signed by each custodian.

What technical steps support preservation?

  • Native format collection - exporting e-mail as PST/MBOX, chat logs as JSON or XML, and cloud files preserving original folder structures and file extensions.
  • Metadata capture - extracting header information (From, To, CC, BCC, Sent-Date, Received-Date), message-ID, thread-ID, and device fingerprints; for cloud objects, retaining object-ID, version-ID, ETag, and storage-class metadata.
  • Hash generation - calculating SHA-256 (or stronger) hash values at the point of collection and storing them in a tamper-evident log; these hashes later serve as proof of integrity.
  • Chain-of-custody logs - recording every transfer (e.g., from custodian laptop to forensic workstation, from workstation to secure storage) with timestamps, operator names, and transfer medium (encrypted USB, secure FTP).

Failure to follow any of these steps can expose a party to the sanctions outlined in DIFC Courts Law Article 17(4), including adverse inferences, monetary penalties, or even striking of pleadings.

HOW DO I AUTHENTICATE AN EMAIL OR CHAT MESSAGE FOR ADMISSION AT TRIAL?

To authenticate electronic communications, you must show that the item is what it purports to be by presenting reliable evidence of its origin, integrity, and lack of alteration, such as witness testimony, metadata analysis, or hash values, in accordance with the DIFC Courts Practice Direction on Electronic Evidence.

The direction outlines a two-step approach: first, establish the chain of custody from collection to presentation, documenting who accessed the data, when, and how it was transferred; second, provide technical proof that the file has not been changed, for example by comparing SHA-256 hash values taken at collection with those presented at trial. Witness testimony from the IT administrator who performed the collection or from the custodian who sent or received the message can satisfy the first step, while forensic reports detailing metadata (timestamps, sender/receiver addresses, device identifiers) support the second. The Practice Direction cautions that mere printouts without accompanying metadata may be insufficient, and it encourages parties to negotiate stipulations on authenticity where possible to streamline proceedings.

What specific evidence satisfies the authenticity test?

Evidence TypeHow It Supports AuthenticityTypical Source
Witness testimonyConfirms who created, sent, or received the message and that the presented file matches the original.Custodian, system admin, help-desk staff.
Metadata reportShows unchanged header fields, timestamps, and routing information; can reveal tampering if values deviate.Forensic e-mail parser, chat-log extractor.
Hash value comparisonDemonstrates bit-for-bit identity between the collected exhibit and the version offered at trial.SHA-256 (or SHA-3) computed at collection and re-computed before trial.
Chain-of-custody logProvides a documented trail proving the exhibit never left controlled hands.Signed log sheets, electronic tracking system.
Provider certification (for cloud-sourced data)Attests that the exported dataset is a complete, unaltered copy of the requested records.Cloud service legal compliance team, third-party auditor.

If any of these elements are missing, the court may deem the evidence inadmissible or give it reduced weight. Parties often resolve authenticity disputes by entering into a stipulation of authenticity under DIFC Evidence Law Article 22, which saves time and reduces evidentiary hearings.

WHAT IS THE ADMISSIBILITY TEST FOR CLOUD-STORED DATA UNDER THE NEW PD?

Cloud-stored data is admissible if the party seeking admission demonstrates that the data is relevant, authentic, and not excluded by any rule of evidence, and that the method of collection complies with the preservation and authenticity requirements set out in the Practice Direction.

Specifically, the direction requires that the party produce evidence of the cloud provider's data retention policies, the exact query or export used to obtain the relevant files, and a certification from the provider or a forensic examiner confirming that the exported dataset is a complete and unaltered copy of the requested information. The Practice Direction also notes that hearsay objections may arise if the content of a cloud file is offered for the truth of the matter asserted; in such cases, the proponent must fit the data within an exception, such as business records under DIFC Evidence Law Article 24, and must show that the record was made in the regular course of business and that the source of the information had personal knowledge. Costs for obtaining cloud data through legal process (e.g., a preservation letter or court order) are generally allocated to the requesting party unless the court orders sharing, and the Practice Direction encourages early cooperation to reduce disputes over accessibility and format.

Practical checklist for cloud evidence

  1. Identify the cloud service (e.g., Microsoft 365, Google Workspace, Dropbox, AWS S3) and the specific application (OneDrive, SharePoint, Gmail, Slack).
  2. Issue a preservation request to the provider, citing the DIFC Courts Practice Direction and requesting a legal hold on the relevant accounts or objects.
  3. Obtain a data export using the provider's native export tool or a certified forensic collection method that preserves object-level metadata and version history.
  4. Secure a provider affidavit or third-party forensic report stating that the export is a true and complete copy, that no alteration occurred during transfer, and that the export includes all requested date ranges and folders.
  5. Generate hash values for each exported file or archive and record them in a chain-of-custody log.
  6. Prepare a relevance memorandum linking the cloud data to the pleaded facts, and anticipate hearsay objections by aligning the data with the business-records exception (showing regularity, custodian knowledge, and contemporaneous creation).
  7. Meet and confer with opposing counsel to agree on format (native vs. PDF), redactions, and cost-sharing before filing any motions.

Following this checklist not only satisfies the PD but also builds a robust evidentiary foundation that can withstand challenges at trial.

HOW DOES THE PRACTICE DIRECTION ADDRESS PROPORTIONALITY AND COST ALLOCATION?

The Practice Direction expressly acknowledges that preservation and collection of electronic evidence can be costly, especially when large volumes of cloud data or legacy backup tapes are involved. It therefore encourages parties to meet early-often at the first case management conference-to discuss a proportionality protocol. This protocol should outline:

  • Scope limits - defining date ranges, custodian groups, and data types that are truly relevant to the claims or defenses.
  • Collection methodology - agreeing on whether to use targeted keyword searches, date-range filters, or full-scale forensic imaging.
  • Cost-sharing formula - specifying whether the requesting party bears all expenses, whether costs are split proportionally to the volume of data each party seeks, or whether the court will intervene if agreement cannot be reached.
  • Review platform - selecting a shared e-discovery review tool (e.g., Relativity, Logikcull) with agreed-upon security protocols to avoid duplicate processing fees.
  • Timeline - setting milestones for hold implementation, collection, processing, and production to prevent unnecessary delays.

If the parties cannot reach consensus, the Practice Direction empowers the DIFC Courts to issue an order allocating costs based on reasonableness, the proportionality of the request, and the conduct of the parties during the meet-and-confer process. Courts have, in recent cases, shifted costs to the requesting party when preservation requests were deemed overly broad or when the requesting party failed to cooperate in narrowing the scope.

WHAT ROLE DOES EXPERT TESTIMONY PLAY IN ESTABLISHING AUTHENTICITY?

Yes, expert testimony from a qualified forensic examiner is expressly permitted by the Practice Direction to explain hash values, metadata, and chain-of-custody procedures, thereby satisfying the authentication requirement.

An expert can:

  • Explain technical concepts in plain language for the judge, detailing how hash algorithms work and why a matching hash requires bit-for-bit identity.
  • Interpret metadata - pointing out anomalies such as impossible timestamps, mismatched time-zones, or signs of file-system tampering.
  • Validate the collection process - describing the forensic imaging tool used, the write-blocker configuration, and the logging mechanisms that provide integrity.
  • Rebut opposing claims - demonstrating that alleged alterations are inconsistent with the observed hash values or metadata patterns.

The Practice Direction notes that the expert must be independent, qualified under DIFC Evidence Law Article 23 (demonstrating knowledge, skill, experience, training, or education), and must provide a written report that complies with the DIFC Courts' expert witness rules. Parties should disclose expert reports well in advance of trial to allow for adequate cross-examination preparation.

HOW SHOULD I HANDLE SOCIAL-MEDIA AND INSTANT-MESSAGING EVIDENCE?

Although the Practice Direction focuses on e-mail and cloud data, its principles extend to social-media platforms (LinkedIn, Facebook, Twitter) and instant-messaging apps (WhatsApp, WeChat, Telegram). The same preservation, authenticity, and proportionality rules apply:

  • Issue a litigation hold that directs custodians to export chat histories in a format that retains metadata (e.g., JSON export from WhatsApp, HTML archive from Facebook).
  • Preserve device-level data - if messages reside only on a mobile phone, a forensic image of the device may be necessary, with attention to preserving application databases and associated logs.
  • Authenticate via metadata - sender IDs, timestamps, device IDs, and message-IDs serve the same function as e-mail headers.
  • Address hearsay - many social-media posts are offered for the truth of the matter asserted; they may fall under the business-records exception if posted in the regular course of a company's social-media strategy, or under the statement-of-a-party-opponent exception if authored by the opposing party.

Failure to preserve such evidence can lead to the same sanctions as with e-mail, especially when the content is central to claims of harassment, defamation, or breach of non-disclosure agreements.

WHAT ARE THE CONSEQUENCES OF NON-COMPLIANCE WITH THE PRESERVATION OBLIGATION?

Failure to preserve relevant electronic evidence may lead to adverse inferences, monetary sanctions, or, in serious cases, dismissal of claims or defenses, as authorized under the DIFC Courts Law Article 17(4) concerning spoliation of evidence.

The DIFC Courts have increasingly shown willingness to impose sanctions that reflect the degree of culpability:

  • Negligent loss - a warning or modest monetary fine, coupled with an adverse inference instruction that the missing evidence would have been unfavorable to the defaulting party.
  • Reckless or intentional destruction - higher financial penalties, potential striking of pleadings, and in extreme cases, entry of default judgment against the spoliating party.
  • Repeated violations - the court may issue a pre-emptive sanctions order requiring the party to pay the opposing side's costs for forensic recovery efforts, or to undergo a court-supervised audit of its data-retention policies.

The Practice Direction emphasizes that sanctions are not automatic; the court considers the party's culpability, the prejudice suffered by the opposing side, and the availability of less-restrictive remedies (e.g., allowing the opposing party to seek alternative evidence). Nevertheless, the risk of sanctions creates a strong incentive to implement rigorous preservation procedures from the moment litigation is reasonably anticipated.

HOW CAN I PREPARE MY ORGANIZATION FOR FUTURE DIFC ELECTRONIC-EVIDENCE DISPUTES?

Proactive preparation reduces both the likelihood of spoliation findings and the associated costs. Consider implementing a standing electronic-evidence readiness program that includes:

  1. Data-map inventory - maintain an up-to-date register of all electronic communication systems, storage locations, and retention policies across the organization.
  2. Standardized litigation-hold template - a pre-approved hold notice that can be customized quickly, complete with custodian-identification checklist and IT-liaison instructions.
  3. Training regimen - regular workshops for employees, HR, IT, and legal staff on preservation duties, the importance of not deleting relevant data, and how to acknowledge hold notices.
  4. Technical safeguards - deploy automated legal-hold capabilities within e-mail and collaboration platforms (e.g., Microsoft 365 eDiscovery, Google Vault) that can suspend deletion policies with a single administrative action.
  5. Incident-response playbook - a step-by-step guide for the legal team to follow when litigation is anticipated, including immediate notification to IT, collection of forensic images, and initiation of chain-of-custody logs.
  6. Periodic audits - test the hold process annually by simulating a litigation scenario, verifying that holds are correctly applied, metadata is preserved, and hash logs are generated.

By embedding these practices into corporate governance, organizations not only comply with the DIFC Courts Practice Direction on Electronic Evidence but also demonstrate to the court a culture of diligence that can mitigate sanctions and strengthen evidentiary positions.


This article provides a general overview of the DIFC Courts' Practice Direction on Electronic Evidence and is intended for informational purposes only. It does not constitute legal advice for any specific situation.

FREQUENTLY ASKED QUESTIONS

What steps must be taken to preserve electronic evidence once litigation is anticipated?

You must issue a litigation hold notice to all relevant custodians, suspend routine deletion policies, and preserve native formats of emails, chats, and cloud files as soon as you reasonably anticipate proceedings. The hold must be documented, communicated in writing, and monitored for compliance; failure can lead to adverse inferences or sanctions under DIFC Courts Law.

How should a litigation hold be structured to comply with the Practice Direction?

A well-drafted hold includes a scope statement, custodian list, preservation instructions, documentation requirements (log-sheet of issuance and acknowledgments), and a monitoring mechanism assigning a compliance officer or vendor to verify that custodians have not altered or deleted data, with periodic attestations.

What technical steps support the preservation of electronic evidence?

Technical steps involve collecting data in native format (e.g., PST/MBOX for email, JSON/XML for chats), capturing metadata (header fields, timestamps, message-ID, device fingerprints, cloud object-ID, version-ID, ETag), generating SHA-256 (or stronger) hash values at collection and storing them in a tamper-evident log, and maintaining chain-of-custody logs documenting every transfer with timestamps, operator names, and transfer medium.

How can an email or chat message be authenticated for admission at trial?

Authentication requires showing the item is what it purports to be by establishing a chain of custody and providing technical proof of integrity, such as comparing SHA-256 hash values taken at collection with those presented at trial, supplemented by witness testimony from the custodian or IT administrator and forensic metadata reports.

What specific evidence satisfies the authenticity test for electronic communications?

Acceptable evidence includes witness testimony confirming creation/receipt, metadata reports showing unchanged header fields and timestamps, hash value comparisons demonstrating bit-for-bit identity, chain-of-custody logs documenting control, and provider certifications for cloud-sourced data attesting to a complete, unaltered copy. Missing any element may render the evidence inadmissible or give it reduced weight.

If your matter involves difc electronic evidence in the United Arab Emirates, you are welcome to request a consultation with Nour Attorneys. Our team can assess your position under the law currently in force and outline the options available to you. Request a consultation

This article is provided for general informational purposes only and does not constitute legal advice. Reading this article or contacting Nour Attorneys through this website does not create an attorney-client relationship; such a relationship arises only after a conflicts-of-interest check and a signed engagement agreement. Do not send confidential information through this website; information submitted before engagement is not protected by legal privilege. Past results do not guarantee future outcomes. The firm's lawyers practice in the jurisdictions stated in their individual profiles; this article addresses the law of the United Arab Emirates only.

DISCLAIMER

This article is for informational purposes only and does not constitute legal advice.

DIFC Courts Release New Electronic Evidence Practice Direction
Call Us NowChat With Our Team On WhatsApp