{
  "node_id": "ae-cybercrime-law-2021",
  "title": "United Arab Emirates Federal Decree-Law No. 34 of 2021 on Combating Rumours and Cybercrimes",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-04-27",
  "bluf": "Federal Decree-Law No. 34 of 2021 Concerning Combating Rumours and Cybercrimes (the UAE Cybercrime Law) was issued on 26 September 2021 and entered into force on 2 January 2022, replacing Federal Law No. 5 of 2012 on Combating Cybercrimes. The Telecommunications and Digital Government Regulatory Authority (TDRA) is the primary regulatory authority, working alongside the UAE public prosecution and federal courts. UAE federal criminal law applies throughout all seven emirates and within the special economic zones - including the Dubai International Financial Centre (DIFC) and Abu Dhabi Global Market (ADGM) - for criminal matters, regardless of those zones' independent civil and commercial court jurisdiction. The UAE Cybercrime Law creates offences across two main categories: electronic access and data offences, and content offences including rumours and false information. Unauthorised access offences: Art. 2 criminalises basic unauthorised electronic access (imprisonment minimum one year and/or fine AED 100,000-300,000); Art. 3 criminalises access with intent to obtain, modify, disclose, destroy, or alter data (fine AED 200,000-500,000); Art. 4 imposes aggravated penalties for unauthorised access to government, banking, financial system, or critical infrastructure systems (imprisonment plus fine AED 500,000-3,000,000). Art. 6 criminalises destruction or disruption of electronic systems or data (fine AED 200,000-2,000,000 and/or imprisonment). Art. 7 criminalises illegal interception of electronic communications (imprisonment and/or fine AED 500,000-3,000,000). Electronic fraud and identity crime: Art. 9 criminalises electronic fraud - obtaining financial benefit by deception through electronic means - with imprisonment up to 10 years and fine AED 250,000-1,500,000; aggravated penalties apply where the fraud targets financial institutions or involves organised crime. Art. 12 criminalises electronic impersonation and identity fraud (imprisonment and/or fine AED 250,000-1,000,000). Art. 13 criminalises phishing and data theft by deception (imprisonment and/or fine AED 500,000-1,000,000). Content offences: Art. 26 criminalises electronic harassment and cyberbullying (imprisonment and/or fine AED 250,000-500,000). Art. 29 criminalises publication of content violating public order, public morals, or Islamic values. Art. 34 criminalises publication of false information or rumours via electronic means that is likely to harm public order, religious values, public decency, or the privacy of others (imprisonment and/or fine AED 100,000-500,000). Art. 35 imposes aggravated penalties where published false information affects the state's interests or national unity. Art. 40 provides that use of information technology to commit any other crime attracts enhanced penalties. Extra-territorial jurisdiction: Art. 43 establishes that the UAE Cybercrime Law applies to offences committed outside the UAE where: (a) the offence targets a UAE person or organisation; (b) the offence is committed via UAE information infrastructure; or (c) the offence has effects within the UAE. The UAE has extradition treaties with a number of states and can request extradition of suspected offenders. The TDRA operates the ecrime.ae portal for cybercrime incident reporting. UAE courts have applied the Cybercrime Law to social media posts, business communications, and news articles accessible to UAE audiences. Organisations with any UAE-facing digital presence must implement content moderation, access security, and incident response frameworks aligned with this law.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "nist_framework",
      "iso_standard",
      "industry_mapping",
      "ai_overlay_2026"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "nist-cybersecurity-framework-2-0",
    "iso-27001-2022"
  ],
  "primary_citations_count": 7
}