OUT-LAW ANALYSIS 5 min. read

Navigating privacy applications before the DIFC and ADGM Courts

DIFC Courts reception with illuminated logo

The DIFC Courts operate strict tests for privacy requirements. Photo: DIFC Courts


The principles of open justice and business sensitivity and confidentiality present a recurring challenge in commercial litigation.

However, when the principle of open justice applies from the outset of proceedings, particularly where claims or allegations are yet to be substantiated, the accused party may suffer severe and immediate reputational harm before any findings have been made.

In such circumstances, the affected party may apply for a privacy order, at which point the court is required to conduct a careful balancing exercise, weighing the public interest in open justice against the affected party's legitimate need for confidentiality.

Privacy applications before DIFC Courts

As a starting point, the DIFC Courts assess applications for privacy against a strong presumption of open justice, and strict tests apply. A limited category of hearings, such as applications relating to payment of debts by instalments, charging orders and security for costs, are automatically heard in private in the first instance, though the judge retains the discretion to direct that such hearings be conducted in public instead.

Beyond those categories, parties may apply for any hearing to be held in private, provided that one of the grounds set out in Rule 35.4 of the Rules of the DIFC Courts (RDC) is satisfied. The grounds most commonly relied upon in practice include matters of national security and hearings involving the use of confidential information.

Importantly, Rule 35.4 also provides a broad discretionary ground, enabling the court to order that proceedings be conducted in private where it considers this to be "necessary in the interests of justice." This ground confers considerable flexibility, but that flexibility has its limits.

This wide discretionary ground was tested in a recent fraud-based, multi-jurisdictional dispute before the DIFC Courts, involving the Danish Customs and Tax Administration (SKAT). The court's approach in that case established a number of important principles that will be of direct relevance to parties considering whether to pursue, or resist, a privacy application.

How the case unfolded

Along with its application for a private hearing, the applicant also sought to challenge the jurisdiction of the DIFC Courts. The court was prepared to hear the jurisdictional challenge in private on the basis that an interlocutory application is “not dispositive of the parties’ rights and thus a less rigorous application of the general principle (of open justice) may be justified than would be the case for example where privacy was being sought for the whole of the trial”.

However, after the jurisdictional challenge has been dismissed, the court refused the continuation of the privacy order, allowing the remainder of the trail to be held in public despite the commercial or reputational harm the applicant had alleged it would suffer.

It is therefore apparent that the principle of open justice may supersede - even where serious allegations such as fraud are advanced - unless a privacy order is strictly necessary to “secure the proper administration of justice” and any derogation from open justice extends no further than the minimum required.

Where the circumstances warrant some degree of protection, the court may provide more targeted measures rather than blanket privacy orders. Rule 35.5 of the RDC, for example, permits the DIFC Courts to order that the identity of a party or witness be kept confidential where this is necessary to protect that party's interests.

Separately, Rule 28.8 empowers the court to exclude from production documents of commercial or technical confidentiality where it considers that such confidentiality is compelling. However, even in respect of these more limited forms of privacy relief, the case law establishes that evidence of concrete harm or a significant risk to commercial reputation must be evidenced to justify the order sought.

Privacy applications before the ADGM Courts

The ADGM Courts' Procedure Rules (CPR) and Regulations reflect a broadly similar commitment to open justice, with defined grounds for any permitted departures.

The familiar grounds - national security, use of confidential information, and the interests of justice - all feature in the ADGM framework. However, Section 98 of the ADGM Courts Regulations goes further by expressly allowing parties to apply for hearings to be conducted in private where it is necessary to protect the interests of a party or witness.

This is a distinct ground which is not expressly written into the DIFC RDC and represents a noteworthy distinction between the two frameworks. The ADGM Courts Regulations similarly permit alternative measures, including the anonymisation of a party or witness, the non-disclosure of their identity, and the withholding of information on grounds of confidentiality or commercial sensitivity.

Despite these broad powers, however, the ADGM Courts have demonstrated a clear inclination to exercise them sparingly. In Abu Dhabi Commercial Bank PJSC v Manghat, the court acknowledged that it retains powers to protect legitimate interests of privacy and confidentiality where there is a sufficient basis for doing so, but went on to note that "parties to litigation often have to make disclosure of documents that they regard as confidential in the interests of justice".

This observation captures the tension that pervades privacy applications in both jurisdictions.

A consistent approach was adopted in the more recent ADGM Courts decision of  A17 v B17 & Ors, where the court held that bare assertions that information was "personal", "confidential" or "commercially sensitive" were wholly insufficient without specificity and supporting evidence. The court emphasised that commercial sensitivity cannot be assumed; it must be demonstrated.

What this means for you

Applicants considering whether to seek a privacy order, the message from both the DIFC and ADGM Courts is clear: broad or generalised claims of reputational or commercial risk will not suffice. Specific, evidence-based justification must be presented to demonstrate why privacy is strictly necessary and why more targeted measures, such as anonymisation or redaction, would be inadequate. Counsel should resist the temptation to seek blanket relief that goes beyond what is demonstrably required.

For respondents facing a privacy application brought by an opposing party might want to rely on the body of recent case law which militates against blanket privacy orders.,. The burden on the applicant is a high one, and the courts' consistent rejection of generalised assertions means that any application unsupported by concrete evidence is vulnerable to challenge.

Respondents are, therefore, entitled to maintain the presumption of open justice in their favour, and where a privacy order is granted, they should consider whether to challenge its scope, particularly where it extends beyond what is strictly necessary, or where an alternative privacy measure would have adequately addressed the applicant's concerns.

More broadly, parties operating in the DIFC and ADGM should be alive to the fact that commercial litigation in these jurisdictions is conducted in the public eye unless the court orders otherwise. Sensitive financial information, internal communications, and commercially confidential documents that become relevant to proceedings may be subject to disclosure and, potentially, to public scrutiny.

Where confidentiality is a genuine concern, available procedural protections should be considered from the outset, and the reputational factor is one to consider when deciding whether to settle a claim brought against a party.

Co-written by Suzan Shaban of Pinsent Masons.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.