Student Blog: Can Computer Data Constitute an "Object" under International Humanitarian Law?

 By Rohan Vashisht 
LL.M. Candidate International Human Rights & Humanitarian Law 
Europa University Viadrina, Germany

Introduction 

Imagine an international armed conflict in which a State conducts a military cyber operation that erases an adversary's logistics database. The operation achieves its military objective but the same malware also deletes the electronic health records of civilian hospitals sharing interconnected digital infrastructure. Here, no conventional weapon has been fired, no buildings have been destroyed and no medical equipment is damaged. Yet emergency medical care collapses because doctors can no longer access essential patient information, resulting in preventable civilian deaths. 

None of this seems like violence that international humanitarian law (IHL) was originally built to regulate. Yet it brings one of the most contested questions in contemporary IHL: Does computer data qualify as an "object", and if civilian in character, a protected civilian object under IHL? 

The novelty of cyber warfare does not place it outside the scope of IHL. In its Advisory Opinion on the Legality of the Threat or Use of Nuclear Weapons, the International Court of Justice affirmed that the fundamental principles of humanitarian law apply to "all forms of warfare and to all kinds of weapons, those of the past, those of the present and those of the future". The real legal question, therefore, is not whether IHL applies to cyber operations, but how its existing rules apply when the target is intangible computer data rather than physical infrastructure. 

Before considering principles such as distinction, proportionality or precautions in attack, a prior issue must first be resolved: Can computer data be regarded as an "object" under IHL at all? Only if the answer is yes does the law governing attacks on civilian objects become applicable. This article examines the legal approaches to that threshold question and considers whether existing interpretations remain adequate for warfare in the digital age. 

The Legal Framework 

Article 49(1) API defines attacks as ‘‘acts of violence against the adversary, whether in offence or in defence.’’ Traditionally, attacks involve death, injury, damage or destruction by use of force and it is established that this is not limited to kinetic force such as electromagnetic and other non-physical means of warfare have long been understood to fall within IHL's scope. Also, the Tallinn Manual 2.0 reflects a majority view that cyber operations reasonably expected to cause death, injury, damage or destruction meet the threshold of an attack regardless of the means employed. 

The difficulty arises with cyber operations that alter, delete or encrypt data without touching physical infrastructure. Whether cyber operations causing only digital damage amount to an attack within the meaning of IHL would thus depend on whether data constitutes an "object" which may be damaged or destroyed. Article 52(1) API defines civilian objects as "all objects which are not military objectives"; Article 52(2) defines military objectives as those which by their nature, location, purpose or use make an effective contribution to military action and whose destruction, capture or neutralization offers a definite military advantage. Neither provision was drafted with intangible things in mind. 

This is the threshold through which all further analysis must pass. If data is not an "object" in the IHL sense, then interfering with it, however disruptive, does not engage Article 52 at all and the questions of proportionality, distinction and precautions in attack simply do not arise with respect to the data itself. Only if data can be an object, does the second question follow: does an interference amount to an "attack" and if so, how does targeting law regulate it? 

The Traditional Position 

The most comprehensive analysis of this threshold question is provided by Ori Pomson's 2023 analysis in the Journal of Conflict & Security Law, which applies the customary rules of treaty interpretation codified in the Vienna Convention on the Law of Treaties to both the English and French authentic texts of API. Working through the ordinary meaning of "object", Pomson shows that the term, in its treaty context, implies a material thing that can be seen and touched, a reading confirmed by every concrete example API itself gives of an "object" such as places of worship, dwellings, schools, dams, dykes and the like. All are tangible. None is data. 

Pomson also rejects the argument that an "evolutive" interpretation should extend "object" to cover data given technological change since 1977. Drawing on the ICJ's reasoning in the Navigational Rights case, he argues that evolutive interpretation permits a term's application to develop as its underlying category evolves. What it does not permit is expanding a term to a fundamentally different category of thing altogether and intangible signals, including radio and electromagnetic transmissions, existed and were regulated by states well before 1977, meaning the drafters were not unaware of non-physical phenomena when they chose "object" rather than a broader term. 

Turning to customary international law, Pomson links the historical development of the term "object" from the 1923 Hague Rules of Air Warfare through later codification efforts, concluding that negotiating states consistently understood the term to refer to material things. State practice since is thin but revealing: Denmark, Chile and Israel have each stated that data does not qualify as an object because it is intangible, while only a handful of states such as Norway, France, Germany and Romania have taken the contrary position and even among those there is no shared rationale. Pomson concludes that existing state practice is insufficient to establish a customary rule recognizing data as an object which is also consistent with the majority position reflected in the Tallinn Manual 2.0 and the U.S. Department of Defense's Law of War Manual both of which tie cyber attack to physical damage or injury rather than interference with data alone. 

Another critique relates to the implications of treating this data as an object for the purpose of conducting operations such as incapacitating enemy communications or degrading systems related to the enemy's economy. Many argue that the expansion of the doctrine would make many military operations illegal or impractical. It is likely that it would also be difficult to consistently create effective distinctions and practical application of rules for distinction and proportionality in cyberspace, because it is difficult to categorize data flows in cyberspace as purely military or civilian when shared infrastructure is being utilized for military and civilian purposes. 

The Functional Approach 

The fact that data may fall outside the definition of an “object” does not mean that IHL has nothing to say about operations affecting it. The stronger version of the contrary argument is not that data is generically an "object" but that specific rules of IHL already protect certain categories of data independently of that classification. The clearest example is medical data. Article 19 of the First Geneva Convention and Article 12 of Additional Protocol I require medical units and establishments to be respected and protected. The ICRC's updated Commentary on Article 19 states the obligation to respect medical units as extending beyond a mere prohibition on attack, interference with their work and specifically extending to disruption of a unit’s ability to communicate or access to its vital resources such as electricity and water. The commentary does not talk about cyber operations directly but supports the view that disabling a hospital’s digital system would fall within the same protection. In modern armed conflicts, hospitals are inseparable from their digital infrastructure. Electronic health records, diagnostic software, laboratory databases and treatment histories are indispensable to the delivery of medical care. A cyber operation that deletes or corrupts these records may leave the hospital building, generators and medical equipment physically intact while rendering the hospital incapable of treating patients. The humanitarian consequences may be no different from those resulting from an attack on a hospital's electricity supply or essential medical equipment, both of which are clearly protected under IHL because disabling them would prevent the provision of medical care. If IHL protects the power source that enables a hospital to function, it is difficult to ignore the role played by the medical data without which that same hospital cannot effectively operate. This reasoning suggests that certain categories of civilian data may already receive indirect protection because of the humanitarian function they enable. It does not, however, establish that computer data as a whole qualifies as an "object." Rather, it demonstrates that the protection of medical data derives from the special legal protection afforded to medical services, not from the legal status of data itself. The ICRC Geneva Academy report similarly emphasizes that certain civilian entities enjoy heightened protection in cyberspace. Medical services, humanitarian operations and objects indispensable to civilian survival must not be interfered with through cyber means, regardless of whether the interference qualifies as an attack. This aligns with the broader humanitarian function these rules are designed to safeguard. The same logic extends, indirectly, to any physical storage medium such as a hard drive, a server or a printed file which remains a tangible object entitled to protection in its own right, quite apart from the data it happens to hold. 

An effects based approach is not foreign to IHL. Methods of warfare that do not physically destroy an object, but affect its function such as electronic warfare, jamming and electromagnetic interference, have long been regulated by IHL. The operations described above would be subject to the rules on distinction and proportionality, even if they do not cause any visible harm. From that point of view, if computer data were subjected to protection under IHL, then recognizing that would not be so much a radical interpretation as it is a logical extension of existing law. 

The infrastructure-dependency argument that concerns air traffic control, power grids and financial networks requires similar care. When a cyber operation corrupts the data controlling a power grid and the grid stops functioning, the better legal characterization is that the physical infrastructure has suffered a loss of functionality equivalent to damage and not that the data itself has become a legally protected "object". Several states, including Ecuador, Guatemala, Japan and Italy, have indicated that loss of functionality can suffice for an "attack" in certain circumstances even without data being independently classified as an object, that is a distinct and more defensible route to protection than characterizing the underlying data as the protected object. 

Where a genuinely minority position persists, reflected in the Tallinn Manual 2.0's dissenting experts, is the claim that data whose destruction produces effects functionally equivalent to physical destruction should be treated as an object regardless. The functional‑equivalence view is intuitively appealing, but it collapses at the technical level because binary code does not permit a principled distinction between “content” and other data. As Pomson notes, any such test risks sweeping in almost everything or nothing. 

Implications for the Conduct of Hostilities 

Even accepting that data itself falls outside Article 52, the practical consequences of the classification debate remain significant. Cyber operations against dual-use infrastructure such as cloud servers, shared networks, data centres hosting both civilian and military traffic, still implicate the principle of distinction with respect to the physical infrastructure and any data properly protected by independent rules (medical and objects indispensable to civilian survival). Proportionality assessments must still account for foreseeable incidental damage to civilian infrastructure caused by cyber means, even where the "damage" manifests digitally before it manifests physically. Also, precautions in attack such as verifying targets, choosing means that minimize incidental harm, remain fully applicable wherever an operation is reasonably expected to cause physical effects, cyber or otherwise. 

Conclusion 

Whether computer data can ultimately be recognised as an "object" under IHL remains contested. Yet modern day warfare increasingly targets information rather than physical infrastructure, so the question is no longer theoretical. The law will have to inevitably confront whether humanitarian protection depends on physical form or humanitarian consequence. Until then, the debate over the legal status of computer data remains the defining question of modern warfare. 

Next
Next

Student Blog: Understanding the “Anthropic Moment”:An Impossible Trinity of Military AI and the Opportunities Behind