All NotesCivil LawLaw of Torts

Law of Torts

Torts in the Digital Environment: Online Wrongs, Negligent Data Security, and Intermediary Liability

There is no separate law of cyber torts. A cyber tort is an ordinary tort committed through a digital medium, and the principles that govern it are the principles examined throughout this series. What changes is not the doctrine but the circumstances in which it operates: the scale of the harm, the speed at which it spreads, the anonymity of the wrongdoer, the jurisdiction in which the wrong occurred, and the presence of an intermediary who carried the material without composing it. Those changes affect remedies and enforcement far more than they affect liability.

The online wrongs, negligent data security, and the intermediary safe harbour

1. The Traditional Torts Applied Online

The wrong

How the ordinary law reaches it

Online defamation

A post, comment, forward, review or caption is a publication in a permanent form. Publication occurs where the material is downloaded and read. Every forward is a republication and a fresh cause of action: TORT 067 to 071

Invasion of privacy

Unauthorised collection, use or publication of personal information, actionable as intrusion into seclusion or as public disclosure of private facts, where truth is no defence: TORT 088

Appropriation of identity

Use of a name, image, likeness or voice without consent, reached through personality rights and passing off: TORT 089

Harassment and stalking

Persistent abusive messaging, impersonation, non consensual sharing of images, doxxing. Reached through privacy, defamation, personality rights, and negligence where the harm was foreseeable

Injurious falsehood

A false and malicious online review or statement disparaging goods or business, causing special damage: TORT 077

Passing off

A deceptively similar domain name, handle, app or storefront: TORT 077

  • Intentional infliction of emotional distress is not an established nominate tort in India, and the same facts are ordinarily reached by the torts above.
  • The elements are unchanged. A defamatory online post must still be defamatory, refer to the plaintiff, and be published; the medium affects none of that.
  • What the medium changes is the quantum. The scale and permanence of online circulation is relevant to damages, and an imputation that reaches thousands in an hour will attract a higher award than the same words in a private letter.

2. Jurisdiction

  • Publication occurs where the material is downloaded and read, and not merely where it was uploaded, so a single article may be actionable in many places.
  • That produces forum shopping, and courts have responded by asking whether the defendant targeted the jurisdiction: whether the material was directed at readers there, in their language, about their affairs.
  • Enforcement is the harder problem. A decree against a defendant outside the jurisdiction, or against an unidentified one, is worth what it can be executed for, which is why the practical relief sought is a take down order against an intermediary within the jurisdiction.
  • Global take down orders are contested, since an order that material be removed everywhere applies one country's standards to the whole world.

3. Negligent Data Security

  • The duty. A person who collects and holds the personal data of another assumes a measure of responsibility for it. The duty arises most readily where the relationship is one of service: a bank, a hospital, an insurer, an employer, a platform.
  • The standard is reasonable care, measured against the sensitivity of the data held and the state of security practice at the time.
  • The breaches alleged are typically storing data unencrypted, failing to patch a known vulnerability, retaining data beyond the purpose for which it was collected, inadequate access controls, and failing to notify those affected once a breach is discovered.
  • Compliance with a regulatory standard is evidence of reasonable care and is not a defence, on the ordinary principle that a standard is a floor and not a ceiling.
  • The difficulty is damage. The loss is frequently pure economic loss, or no measurable loss at all, and distress alone is not ordinarily compensated in negligence. A claimant whose data was exposed but who suffered nothing recovers nothing.
  • Causation is the second difficulty. The claimant must connect the breach to the fraud or the harm he actually suffered, which is hard where his data was available from several sources.

4. The Data Protection Statute Does Not Supply a Remedy

  • The Digital Personal Data Protection Act, 2023 imposes obligations on a data fiduciary: to process personal data only for a lawful purpose with consent or for a legitimate use, to implement reasonable security safeguards, to notify the Board and affected data principals of a breach, and to erase data when the purpose is served.
  • It provides penalties enforced by a Data Protection Board, and the penalties for a failure of security safeguards are substantial.
  • It does not create a private right of action in damages for the data principal. The penalties are payable to the State and not to the person whose data was exposed.
  • So the civil remedy remains the ordinary law of torts, and the statute supplies the standard of care rather than the cause of action. A breach of the statutory obligations is powerful evidence of negligence, and the failure of a claim in breach of statutory duty under the principles in TORT 078 is unsurprising where the statute has provided its own enforcement machinery.

5. Intermediary Liability

Section 79, Information Technology Act, 2000

An intermediary shall not be liable for any third party information, data, or communication link made available or hosted by him.

The exemption applies where the function of the intermediary is limited to providing access to a communication system over which information made available by third parties is transmitted or temporarily stored or hosted; or where the intermediary does not initiate the transmission, select the receiver of the transmission, and select or modify the information contained in the transmission.

And where the intermediary observes due diligence while discharging his duties and also observes such other guidelines as the Central Government may prescribe.

The exemption shall not apply if the intermediary has conspired or abetted or aided or induced, whether by threats or promise or otherwise, in the commission of the unlawful act; or if, upon receiving actual knowledge, or on being notified by the appropriate Government or its agency that any information, data or communication link residing in or connected to a computer resource controlled by the intermediary is being used to commit the unlawful act, the intermediary fails to expeditiously remove or disable access to that material.

  • The safe harbour is conditional, not absolute. An intermediary that curates, promotes, edits or selects the material is not within it, because it has selected or modified the information.
  • Actual knowledge has been read to mean knowledge of a court order or a government notification, and not a private complaint. The reason is that a platform receiving thousands of complaints cannot be required to adjudicate disputes between its users, and a rule that made it liable on a bare complaint would cause it to remove lawful material on demand.
  • The due diligence conditions are prescribed by rules, and include publishing terms of use, informing users of prohibited content, establishing a grievance mechanism, and appointing officers.
  • The safe harbour is conceptually the descendant of innocent dissemination in the law of defamation, examined in TORT 069, and rests on the same idea: a person who merely carries what others have written should not answer for its content until he knows of it.
  • Its practical importance is that the effective remedy in most online cases is an order for removal, obtained against an intermediary that can be found and served, rather than damages against an author who cannot.

6. What Actually Changes Online

The feature

Its effect on the claim

Scale

Publication to thousands within hours, which goes to the quantum of damages

Permanence

The material persists and resurfaces, and each resurfacing may be a fresh publication with its own limitation period

Anonymity

The author often cannot be identified, so the claim is redirected at the intermediary and at removal

Jurisdiction

Publication occurs wherever the material is read, producing concurrent jurisdictions and difficulties of enforcement

Speed

Interim relief matters far more than final relief, because material not removed within days has already done its work

The intermediary

A defendant who can be found and served, but who is protected by the safe harbour until he has actual knowledge

⚠ Why the doctrine is adequate and the enforcement is not

It is commonly said that the law has failed to keep pace with online harms, and the claim is worth examining rather than repeating. Take the wrongs in this note one at a time. A defamatory post is defamation; the medium is irrelevant to every element. Publishing somebody's private photographs is a disclosure of private facts. Using a person's face to sell a product is an appropriation. Exposing a customer database through careless security is negligence, if damage can be proved. In each case the substantive law already condemns the conduct, and a court asked to decide liability would have little difficulty. What the law has not solved is everything that comes after: finding a defendant who is anonymous, suing one who is abroad, obtaining relief fast enough to matter when the material spreads in hours, and enforcing an order across borders. Those are problems of procedure, jurisdiction and enforcement, and they are the reason the practical response in this field is an urgent injunction and a take down order rather than a suit for damages. Reforms directed at inventing new torts address the part of the problem that was never broken.

7. The Position Stated Shortly

1. There is no separate law of cyber torts; a cyber tort is an ordinary tort committed through a digital medium.

2. Online defamation, invasion of privacy, appropriation of identity, harassment, injurious falsehood and passing off are all reached by the existing torts.

3. Publication occurs where the material is downloaded and read, so a single item may be actionable in many jurisdictions.

4. The scale and permanence of online circulation goes to the quantum of damages and not to liability.

5. A person who collects and holds personal data owes a duty of reasonable care, measured against the sensitivity of the data and the state of security practice.

6. The practical difficulties in a data breach claim are damage, distress alone not being compensated in negligence, and causation.

7. The Digital Personal Data Protection Act, 2023 creates obligations and penalties but no private right of action in damages, so it supplies the standard and not the cause of action.

8. Section 79 of the Information Technology Act, 2000 exempts an intermediary from liability for third party information, subject to due diligence and to acting on actual knowledge.

9. Actual knowledge has been read to mean a court order or a government notification, and not a private complaint.

10. The safe harbour is the descendant of innocent dissemination in defamation, and rests on the same principle.