Book an appointment with us, or search the directory to find the right lawyer for you directly through the app.
Find out more
Deal by Design
Welcome to this edition of Law Update, focusing on the evolving M&A landscape across the MENA region. With deal activity and value continuing to grow, the region is seeing increased investor interest alongside a changing regulatory environment.
This edition explores key legal and market developments affecting M&A transactions, including regulatory reforms, foreign investment, governance, due diligence and deal structuring across the region.
The massive boom in the financial technology (fintech) sector in the UAE has brought about a qualitative shift in facilitating daily transactions and instant transfers through smart-device applications. Despite the strict legislative and regulatory requirements imposed by the Central Bank of the UAE (CBUAE) to ensure the security of these systems, recent practical developments have revealed a serious procedural loophole at the intersection of traditional banking with law enforcement mechanisms.
This dilemma is evident when digital applications are exploited as a façade for executing organised fraud, and where employees of fintech companies and authorised signatories find themselves in the crosshairs of criminal accusation, arrest, and detention. Meanwhile, the real perpetrator flees the country, taking advantage of the time consumed by routine correspondence between the police and banks.
This article elucidates the legal and technical dimensions of this problem, and proposes legislative and procedural solutions to overcome it. The article highlights the pivotal role of early intervention by cybercrime lawyers in protecting innocent parties and ensuring fair trials.
The crisis stems from a gap in characterisation and operational definition between traditional banks and investigative authorities (the police and public prosecution). Technically, funds of digital wallet users are deposited into one large traditional bank account known as an e registered in the name of the application operator, while individual balances are managed through virtual accounts within the software records of the application operator only.
When a digital fraud occurs, the victim would typically immediately report it to the police based on the traditional bank-account number to which the funds were transferred. The authorities would then take action and contact the receiving bank to inquire about the ‘account owner and beneficiary’, and this is where the issue lies. The bank’s response would be limited to the superficial data registered in its core banking system. For example, it would state that the account belongs to company (X), and that the authorised signatories are employees (A) and (B), who work for the application’s operating company.
Based on this traditional response, and in application of the strict general rules in combating money laundering and cybercrime, law enforcement authorities would issue arrest warrants for these employees. They would then refer the employees to the public prosecution on charges of misappropriation of other people’s money (fraud), or the crime of obtaining funds in circumstances that raise suspicion of their illegality. Both crimes are punishable by the provisions of Articles 451 and 456 of the Federal Penal Code and other penal laws in the UAE, such as the Anti-Money Laundering Law and the Law on Combating Rumors and Cybercrimes.
Meanwhile, the real fraudster would have digitally transferred the balance or withdrawn it through other channels. Sometimes, the fraudster would even have managed to leave the country before the investigation authorities had noticed a second technical layer concealing the true identity of the perpetrator.
This scenario not only constitutes a waste of judicial time and effort, but also inflicts significant damage to the reputations of professional personnel, the investment environment of the fintech sector, and law enforcement agencies.
To address this dilemma and protect the UAE’s financial and judicial system, it is advisable to introduce mandatory amendments to the course of correspondence and criminal investigations related to fintech accounts, through two main axes.
Obligating banks to develop and detail the procedural response format
The CBUAE should consider issuing a binding circular to all traditional banks, requiring them to update their response templates for law enforcement and judicial authorities. When responding to an inquiry about a joint account, the bank should not simply state the company name and authorised signatory, but also be legally obligated to include the following phrases and formulations in its official letter.
Imposing procedural restrictions on the arrest and detention decision
Police officers and members of the Public Prosecution should receive training on these cybercrime risks, and if necessary, some police and prosecution personnel with modern technical expertise should exclusively receive these cybercrime case files. The arrest or referral to criminal trial of any employee or authorised signatory in a fintech company should be prohibited if the bank’s response indicates that the account in question is a ‘wallet aggregator’.
To ensure that there is no collusion on the part of any employee of the operating company and to protect bona-fide third parties, the investigating authorities should be required to not undertake any liberty-restricting measures against the company’s management unless the following conditions are met.
Efforts to protect innocent employees from wrongful arrest should not overlook the rights of the victims of fraud. Best practices in comparable judicial and banking systems include the following measures.
Amidst these complex procedural and technical entanglements, none of the parties to the dispute – whether a victim seeking their lost money, or an employee of a fintech company facing a serious criminal risk – should leave the course of the case to chance or routine correspondence.
Early intervention by a cybercrime lawyer from the first hours of submitting the report constitutes the crucial difference between losing rights and protecting them, or between arrest and preventive detention and procedural safety. The lawyer’s pivotal tasks include the following.
Drafting and directing letters with the required technical expertise
Judicial officers do not always have the deep technical background to differentiate between a traditional and a digital account. A cybercrime lawyer could play the role of a technical legal translator by:
Defending the accused and providing necessary clarifications
In the event of an incident and the arrest of an employee or official responsible for the collective account, the cybercrime lawyer should not wait for the traditional documentary cycle of investigation authorities. Rather, the lawyer should move in parallel with the Public Prosecution to push towards issuing the necessary orders and useful correspondence to the concerned parties. The lawyer should also provide clarifications to concerned persons at the Public Prosecution, the CBUAE, or the banks connected to the incident under investigation.
Cybercrime case experience
Al Tamimi & Co has successfully neutralised numerous similar cases where employees of fintech companies operating financial mediation applications and payment operations were on the verge of a conviction, and some of them were actually convicted. However, after our intervention, we were able to obtain acquittals before the higher courts.
Many of these reports ended at the investigation stage before the Public Prosecution
Protecting the UAE’s promising digital economy requires a delicate balance between pursuing cybercriminals with speed and protecting fintech professionals from the consequences of inadequate routine procedures.Requiring banks to detail the nature of pooled accounts in their official responses Legal awareness and professional representation from the beginning remain critical in upholding the rule of law and protecting rights in the digital age.