Qatar
Official access turned into a criminal charge
Acquittal of two employees at a major investment entity upheld on appeal and at the Court of Cassation
His working hours at the office were over, but the work was not. An employee emailed a document from his work account to his personal one so he could finish what he had started at the office. He did not send it to a competitor, nor did he leak it to an outside party; he sent it to himself. What he did not know was that this email would lead him, along with a colleague, to a criminal charge and 109 nights behind bars.
The case was not about breaking through security or infiltrating a system from the outside. It turned on one decisive question: how can official access become a charge of unauthorised entry? That is where the defence began, tracing dates, system logs and information security policies, then confronting the entity's witnesses with what its own documents said.
From an Email to a Criminal Complaint
The case began when the information security system flagged those emails. One of the two employees behind them was a digital transformation specialist who in 2018 designed a dedicated application for senior management, work that contributed to his promotion. The other was a systems and solutions architect who had spent eleven years with the entity.
No administrative investigation was held with either of them before the complaint was filed. When the entity's representative was asked in court why, he said it was "due to the surrounding risks". He meant the fear that the two might flee the country.
The file was referred to the criminal authorities, and the two employees were charged with unlawfully accessing the electronic system for investments and financial data, and obtaining confidential data, under Law No. 14 of 2014 on Combating Cybercrimes.
The charge was framed in complex technical language, but lawyer Abdullah bin Hamad AlAthbah did not answer it with a blanket denial. Instead, he put the case file through three decisive tests. Did the emails actually belong to the two employees? Was their access to the data within their authorisation? And were the legal elements of unauthorised access actually met? With each test, part of the case against them began to crumble.
This is where AlAthbah's background made the difference. A lawyer with extensive experience in fintech, information systems and cybersecurity, he did not read the law alone. He read the system's architecture, its access logs and user permissions, its information security policies and the investment technology behind it. Digital evidence can look conclusive when it is wrapped in technical language, but it can collapse under a single legal question once the defence understands how it was built. In AlAthbah's hands, fintech expertise was not an added skill; it was the defence tool that won his clients back their freedom and their future.
Emails That Were Never His Exposed the Truth
One of the strangest elements of the file was that the Information Security Director and his team attributed to one of the employees emails dating back to 2011.
The first test began with a small detail the technical examination had overlooked: the date of the emails. They dated back to 2011, when the employee was working in Singapore. He had not yet signed his contract with the entity now accusing him, and he had not even come to Qatar. Exposing the contradiction required no complex technical analysis. It required a lawyer who checks the dates before accepting the story.
An examination of the senders and recipients produced the same result. The employee's name did not appear in the emails, nor did any email address belonging to him. Yet they were attributed to him.
And so an employee was linked to emails that bore neither his name nor his email address, and that predated his joining the entity. The outcome shows the danger of treating a technical examination as final truth before it has been tested in court.
A Late Policy Puts the Past on Trial
Most of the correspondence attributed to one of the employees dated back to 2018 and was linked to an application he had developed for senior management.
The defence set the date of the correspondence against the date of the internal policy. The emails dated back to 2018, but the policy they allegedly breached was not adopted until 2022 or 2023, as the Information Security Director acknowledged. With a gap of four or five years, the flaw became clear: the accusation measured an old act against a rule created after it.
What kind of accountability digs years into the past, judges an old action by a policy that did not exist when it occurred, and turns it into a criminal charge? A later policy may regulate the future. It cannot redefine the past or turn earlier conduct into a "crime" simply because someone wishes it so.
He Had the Access, Yet Was Charged With Unauthorised Entry
The defence then turned to the access rights themselves. The entity's representative told the court that one of the employees had access to the programme in question until September 2025. The referral order, however, placed the alleged offence in April 2026. The gap between the two dates was not the decisive issue. The real question was whether his access had actually been revoked.
The defence asked whether his access to the programme had been blocked after he moved to the Finance Department. The witness replied that it was "supposed" to have been blocked, then said: "I don't know!"
The Prosecution Witness: Doesn't Know, Doesn't Remember, Didn't Read the Report
As the cross-examination went on, these answers kept recurring:
- Asked whether the documents were classified as "confidential", the witness replied: "I don't remember." Yet the entity has an approved four-level classification system, and no evidence was presented that any document had been classified at any of those levels.
- Asked whether they included financial data, he replied: "I don't know."
- He was shown the technical report stating that an examination of one employee's devices found no document belonging to the entity. He said he "had not seen the report."
- Asked about the technical aspects, he said: "I am not an information systems expert."
A Charge Without Emails, and Two Witnesses Who Can't Agree on the Number
The entity's two witnesses could not even agree on how many emails were at the centre of the charge. One said there were 25; the other said 23. More importantly, the court was not shown a single email whose content, sender or recipient could be examined. The dispute was not over a trivial number. It was over evidence that never itself appeared in the courtroom.
What Did They Send, and What Did the Circumstances Reveal?
The circumstances surrounding the emails revealed four striking facts:
- In one of the two incidents, the document was sent to a personal email account so work could be completed outside the office. Investigators did not find the emails in that account.
- In the other, the material sent was technical training material the employee had prepared himself. It was based on public sources and a development environment classified as "non-sensitive", and he sent it so he could keep working on it before an approved business trip.
- The Information Security Director acknowledged that the password said to give access to the system had been deactivated for a year and no longer worked.
- On top of that, the entity waited fourteen days before filing the complaint. Meanwhile, the employee who sent the email kept coming to work with his access rights intact. So where was the risk that supposedly ruled out an administrative investigation?
The Testimony That Settled the Question of Access
The defence had exposed the contradictions over the emails, their classification and the technical report. It then reached the question on which the whole case rested: was the employee authorised to access the data in question?
The answer from the entity's representative was direct: "Yes, he was authorised to view that data." In that one brief sentence, the entity's own witness undermined the core of its accusation.
The defence pressed further. If this information was confidential, as the charge claimed, why was it available to him?
He replied: "Because he is the programme's developer."
The Information Security Director's testimony reached the same conclusion. He said he had checked with his team, who confirmed that the employee was "entitled to access that data" as a developer. The testimony of the entity's two witnesses thus established that the employees' access to the data fell within the permissions granted to them.
In this way, the defence took apart the technical case. It connected the system's architecture and user permissions to the legal elements of the offence. The file's complex language came down to a clear legal question that left no room for evasion, and the courts answered it at all three levels of litigation.
When the Courts Had Their Say
The Fourth Criminal Circuit examined and scrutinised the evidence in the case and brought the accusation back to its decisive legal question: was the employees' access to the data authorised? The issue was not whether sending a document to a personal email account complied with internal procedures. It was whether doing so met the legal elements of the offence of unauthorised access.
The entity's own witnesses had established that access fell within the permissions granted. On that basis, the Circuit concluded that the material element of the offence was not met. Anything that might be attributed to the employees amounted at most to an administrative violation that did not rise to the level of a crime. The Circuit acquitted them and described the case file as "devoid of proof and poor in evidence."
After the first-instance acquittal, the two employees travelled abroad on leave. According to documents submitted by the defence, they then returned to Doha of their own accord and appeared in court for the appeal proceedings. Their voluntary return was a practical answer to the fear of flight that had been used to justify skipping an administrative investigation.
The Court of Appeal then upheld the Fourth Circuit's ruling, and the acquittal stood. When the ruling was challenged before the Court of Cassation, the court declared the challenge inadmissible, making the acquittal final.
"Before Justice, No One Is Too Big"
On one side of the courtroom stood two employees backed by nothing but their defence and the case papers. On the other stood a major investment institution with its name, weight and standing.
Yet the court looked at the evidence before it, not at the gap in status and resources. When it found nothing in that evidence to prove a crime, the entity's name and standing had no bearing on the outcome.
Lawyer AlAthbah describes what these rulings meant for his clients: