18 Aug Is Computer Data an ‘Object’ Under IHL? The Debate in Armed Conflict Involving Cyber Operations
[Kenaw Akililu is currently a MAS candidate in the Master of Advanced Studies in Transitional Justice, Human Rights and Rule of Law at the Geneva Academy of International Humanitarian Law and Human Rights, and a former law lecturer at Bahir Dar University]
Introduction
Cyber operations and targeting of cyber infrastructure, including data centres, are increasingly employed during armed conflict and can cause severe civilian harm, including through interconnected, indiscriminate, and hard-to-attribute effects. For example, in the recent US-Israel and Iran conflict, Iran targeted Amazon Web Services (AWS) data centres in the United Arab Emirates, which disrupted cloud-based services relied upon by civilian users and businesses, rather than exclusive military uses. The applicability of International Humanitarian Law (IHL) to such operations has been less contentious and well established under international law. Article 36 of the 1977 Additional Protocol I to the 1949 Geneva Conventions (AP I) contemplated the possibility of acquiring new weapons, means, and methods of warfare non-existent at the time and obligates states to review their lawfulness. The International Court of Justice (ICJ) indicated in its Nuclear Weapons (para. 86) advisory opinion that IHL applies “to all forms of warfare and to all kinds of weapons, including those of the future.” This position has been reaffirmed several times, both at the UN (paras 24, 28) and at the level of individual states, by experts and the International Criminal Court (para. 82).
Despite such a general consensus , certain particulars, mainly whether computer data constitutes an ‘object’ within the meaning of Article 52 (2) of AP I, have been subject to a two-decade-long divide among scholars and practitioners. This post argues that data should be interpreted as an ‘object’ based on modern, teleological, and supplementary interpretation techniques.
Does the Definition of ‘Military Objective’ under IHL include Computer Data?
Article 52 (2) of AP I resorted to a residual and negative approach in defining civilian objects as “all objects which are not military objectives.” Then the second paragraph defined military objectives as:
In so far as objects are concerned, military objectives are limited to those objects which by their nature, location, purpose or use make an effective contribution to military action and whose total or partial destruction, capture or neutralization, in the circumstances ruling at the time, offers a definite military advantage.
The major interpretive problem that arises is what constitutes ‘objects’ under this provision in the cyber context. Although “the computers, computer networks, and other tangible components of cyber infrastructure” are broadly recognized as such, scholarly views remain divided about whether data should be considered as an object.
Arguments Against and for Recognition of Computer Data as an Object Under IHL
Contradictory views regarding the issue can be categorized into two. The first group includes the majority of the Tallinn Manual developers, the International Group of Experts (IGE), and some states, who reject the recognition of data per se as an object and adopted a conservative approach regarded as “emerging orthodoxy” by an opposing viewer. Though firmly arguing that the lex lata of IHL precludes data as an object, this group rarely denies the de lege ferenda validity of the opposing view that data should be considered as an object.
The justification for most advocates of this position, particularly the majority of the IGE, is that data “neither falls within the ‘ordinary meaning’ of object” nor comports with the meaning of the notion object given in the 1987 ICRC commentary on AP I (para. 2008) as something “visible and tangible”. Michael N Schmitt, the director of IGE, revealed an additional functional equivalence rationale (paras 93-94): including data as an object would be over-inclusive in the sense that traditionally legal operations, such as psychological, could be turned unlawful for their mere actualization through cyber means (such as deleting data).
The second group of viewers includes ICRC and minorities of IGE, and many states who insisted that some or all types of data should be considered as objects based on the modern understanding of the ordinary term of the notion and/or teleological consideration, as well as contextual interpretations as permitted in Article 31 of the Vienna Convention on Law of Treaties (VCLT). Kubo Mačák (pp. 67, 71) argued that modern meaning should be given to the object, considering the evolving and emerging present-day reality, when armed conflict can take place in cyberspace, which would not be contemplated by the developers of the 1987 ICRC commentary. Schmitt, director of the IGE (p. 94), countered this argument that the evolution of reality can not change lex lata; it may warrant de lege ferenda. Mačák (p. 68) and Heather A Harrison Dinniss (p. 43) further contested the majority of IGE members’ reference to the 1987 ICRC commentary that employed “visible and tangible” to mean objects. They insisted that the commentary uses such terms to distinguish objects from “abstract notions such as the goals and aims of the parties to the conflict, rather than specifically excluding intangible objects from the definition.” Though Schmitt (p. 93) accepted their premises, he rejected their conclusion. He argued that the reference to abstract notions “did not detract from the fact that those who drafted the Article understood objects as those entities that were visible and tangible.” In substantiating his argument, he also referenced the drafting history of AP I, which “includes a discussion of objects that reference ‘inanimate objects’.”
Most of the proponents of the second position rely on teleological considerations, according to which the notion ‘object’ should be interpreted in light of the object and purpose of AP I—the protection of victims of armed conflicts. If essential civilian data cannot be counted as an object, it could be left without IHL protection when the attack targets the data alone without physical consequences, which could be against the purpose and object of AP I. This rationale is summed up in the ICRC’s position paper, which states:
Deleting or tampering with essential civilian data — could cause more harm to civilians than the destruction of physical objects. The assertion that deleting or tampering with essential civilian data would not be prohibited by IHL in today’s data-reliant world seems difficult to reconcile with the object and purpose of IHL.
Why Should Data be Counted as “Object” Under Article 52 of API?
In the interpretation of the notion ‘object’ under Article 52 of AP I, it would be appropriate to apply the relevant provisions of VCLT. Article 31 (1) of this treaty provides that “a treaty shall be interpreted in good faith in accordance with the ordinary meaning to be given to the terms of the treaty in their context and in the light of its object and purpose.”
The phrases “ordinary meaning” and “in their contexts” denote the textual and contextual methodology of treaty interpretations, respectively. These are the methods the first group relies on. However, it seems irresistible that even the ordinary meaning of things can evolve through time. This is akin to “the living instrument” doctrine, where regional courts interpreted treaties as dynamic and evolving to reflect present-day conditions and societal developments (Tyrer v United Kingdom, para.31; Mayagna (Sumo) Awas Tingni Community v Nicaragua, para.146). Additionally, due to digitalization, intangible things, including digital assets and cryptocurrency, have been increasingly recognized as objects of property in domestic laws.
The logic that drafters of AP I did not intend to include intangible things is hardly justifiable to preclude data as objects. The drafters could not contemplate the possibility of cyberwarfare in 1977, when even computers were barely known. That they did not contemplate it, however, does not mean they would not intend to govern it, had they been aware of the new reality. This interpretation is logically appealing when seen from the point of view of the purpose of the IHL and the emerging developments in the field. That is why the IGE and other experts are interpretively applying IHL to cyberwarfare, which was completely unknown during its development. It is analytically difficult to justify intangible things, such as ‘Stuxnet’, recognized as weapons, yet hesitating to acknowledge intangibles (data) as protected objects, though both are products of the cyber world, neither imagined nor intended in the traditional IHL.
The 1987 ICRC commentary’s interpretation of the object as “visible and tangible” would no longer have the same weight it had previously. Firstly, it is not a binding source of law and could be challenged by sources of law of equivalent status, including works of the second group. And most importantly, the same body, ICRC, that authored the commentary, has lately followed a different interpretation considering the new development, stating that “civilian data [intangible] is protected by these [IHL] rules.” It makes sense to give weight to the latest interpretations over earlier ones.
While the second group largely relies on it, the first group does not deny the validity of the teleological interpretation, provided under article 31 (1) of VCLT as “shall be interpreted–in the light of its [AP I] object and purpose”. For one thing, as explained above, even the textual and contextual methods would not support the position fully. Secondly, even if we accept the position of the first group based on these methods of interpretation, the teleological method cannot be ignored because both have at least equal weight. In a dilemma as to which methods should prevail, , Article 52 of AP I hints that protection of civilians must be prioritized. This can be derived from (i) the residual approach to civilian objects, and (ii) the principle that any doubt should be interpreted in favour of the protection of civilians and civilian objects.
The other methodology of interpretation, overlooked by most of the experts, is “the supplementary means” that allows deviation from the ordinary meaning of the treaty terms when doing so leads to a “manifestly unreasonable or absurd” conclusion under Article 32 of VCLT. It is reasonable to believe that precluding data from the notion of object under Article 52 (2) of AP I in the current cyber-reliant societies is manifestly unreasonable, if not absurd. Firstly, in many cases, digital assets and data could be more valuable than tangible objects. Secondly, the consequences of failure to protect essential civilian data—such as “medical data, biometric data, social security data, tax records, bank accounts, companies’ client files or election lists and records”—are far-reaching. Thirdly, from a technical standpoint, computer data has at least equal relevance with other cyberinfrastructures, if not more. Data is the end, at least in the cyber world, while the rest are the means to produce, transfer, or keep it.
Conclusion
The nature of cyber tools, particularly those not designed or used in compliance with IHL,” coupled with the civilian dependence of cyber infrastructures, necessitates IHL protection whenever they are employed in armed conflict. Although the application of IHL rules in general is less debated, whether computer data per se should be counted as an object has been contentious for decades, now. This post argues that excluding data from the definition of object in the ever-digitalized world could be manifestly unreasonable and hardly comply with the protection purpose of AP I and IHL in general, as required under Articles 31 and 32 of VCLT.

Leave a Reply