Cloud Computing Liability

Cloud Computing Liability

1. Meaning and Introduction

Cloud Computing Liability refers to the legal responsibility arising from the provision, use, management, storage, processing, transmission, or protection of data and applications through cloud-computing infrastructure.

Cloud computing generally involves three principal service models:

  1. Infrastructure as a Service (IaaS) – the provider supplies computing infrastructure, storage, networking and related resources.
  2. Platform as a Service (PaaS) – the provider supplies a platform on which customers deploy applications.
  3. Software as a Service (SaaS) – the provider supplies software applications through the internet.

Cloud liability is complicated because responsibility is normally shared between the cloud provider and customer. UNCITRAL's guidance similarly recognizes that liability depends upon which party controls the relevant component of the service, what the contract provides, applicable data-protection law, and the nature of the breach.

Thus, a cloud provider is not automatically liable merely because an incident occurs in its cloud environment.

2. Parties Who May Face Liability

Potentially liable parties include:

A. Cloud Service Provider

Examples include providers of:

  • IaaS
  • PaaS
  • SaaS
  • cloud storage
  • cloud databases
  • cloud security services
  • backup services

Liability may arise from failure to provide contracted services, security failures, unauthorized disclosure, data loss or negligence.

B. Customer

The customer may be responsible for:

  • passwords and credentials;
  • access permissions;
  • encryption;
  • application security;
  • configuration;
  • data uploaded to the cloud;
  • backups where contractually assigned;
  • unlawful use of the cloud.

C. Subcontractors

A cloud provider may employ:

  • data-centre operators;
  • cybersecurity companies;
  • software vendors;
  • infrastructure providers;
  • cloud-management companies.

Their conduct may create liability for themselves and, depending on contract and applicable law, for the principal cloud provider.

D. Employees and Administrators

Unauthorized access, intentional disclosure, negligent configuration or misuse of administrative privileges may generate liability.

3. Major Forms of Cloud Computing Liability

A. Contractual Liability

The cloud-service agreement is normally the most important source of liability.

Typical contractual obligations include:

  • uptime;
  • availability;
  • security;
  • data preservation;
  • backup;
  • disaster recovery;
  • confidentiality;
  • incident notification;
  • data deletion;
  • service levels;
  • compliance with applicable law.

If the provider promises 99.9% availability but repeatedly fails to meet that standard, the customer may have a contractual claim.

Similarly, if the provider promises particular security controls and fails to implement them, liability may arise.

4. Data-Loss Liability

Cloud customers may suffer substantial losses because of:

  • accidental deletion;
  • ransomware;
  • system failure;
  • inadequate backups;
  • corruption;
  • unauthorized modification;
  • failure of disaster recovery;
  • provider insolvency.

A major question is who had responsibility for backups.

UNCITRAL specifically notes that responsibility can differ between SaaS, PaaS and IaaS. In IaaS and PaaS, the provider may be responsible primarily for infrastructure/platform components while the customer retains responsibility for applications and data.

Therefore:

“The data was stored in the cloud” does not by itself establish provider liability.

The court must examine the contractual allocation of responsibility.

5. Cybersecurity and Data-Breach Liability

A cloud provider may face liability when it:

  • fails to implement reasonable security;
  • ignores known vulnerabilities;
  • fails to patch systems;
  • improperly configures servers;
  • permits unauthorized access;
  • fails to monitor suspicious activity;
  • fails to notify customers;
  • improperly exposes confidential information.

However, cybersecurity liability depends heavily on the applicable statute, contract, and facts.

6. Privacy and Personal-Data Liability

Cloud systems frequently process:

  • medical information;
  • financial information;
  • biometric data;
  • employee information;
  • consumer information;
  • government records.

A cloud provider may therefore become subject to privacy and data-protection obligations.

The important legal distinction is between:

Data Controller → determines purposes and means of processing

and

Data Processor → processes data on behalf of the controller.

UNCITRAL emphasizes that contractual labels do not necessarily determine statutory responsibility; actual processing activities may determine which legal obligations apply.

7. Negligence Liability

A negligence claim generally requires:

  1. Duty of care;
  2. Breach of duty;
  3. Causation;
  4. Actual damage.

For cloud services, the alleged breach could involve:

  • inadequate cybersecurity;
  • negligent system design;
  • negligent maintenance;
  • failure to warn;
  • inadequate employee controls;
  • failure to protect customer information.

The claimant must ordinarily establish that the provider's conduct caused the legally recognized loss.

8. Service-Outage Liability

Cloud outages can cause:

  • loss of business;
  • inability to access records;
  • interruption of online services;
  • lost transactions;
  • reputational damage;
  • contractual penalties.

Cloud contracts frequently address these risks through:

  • Service Level Agreements (SLAs);
  • service credits;
  • uptime guarantees;
  • exclusions of consequential damages;
  • liability caps.

Cloud contracts commonly limit liability and exclude consequential damages, although such limitations may be challenged in circumstances such as gross negligence or other legally protected categories.

9. Limitation-of-Liability Clauses

Cloud providers commonly include provisions stating that:

  • liability is capped at a specified amount;
  • consequential damages are excluded;
  • lost profits are excluded;
  • loss of business opportunity is excluded;
  • service credits are the exclusive remedy for downtime.

For example, a contract might limit total liability to the fees paid during the previous 12 months.

But such provisions are not necessarily absolute.

Their enforceability depends on:

  • applicable law;
  • wording;
  • bargaining power;
  • nature of the breach;
  • gross negligence;
  • willful misconduct;
  • statutory restrictions;
  • public policy;
  • whether the excluded loss is direct or consequential.

UNCITRAL specifically observes that certain liability exclusions may be restricted or invalid, particularly for gross negligence, intentional harm, personal injury, core contractual obligations and regulatory violations.

10. Indemnification

Cloud agreements frequently contain indemnification provisions.

For example:

Provider indemnity

The provider may indemnify the customer against:

  • intellectual-property infringement;
  • certain third-party claims;
  • specified security incidents.

Customer indemnity

The customer may indemnify the provider for:

  • unlawful content;
  • violation of acceptable-use policies;
  • misuse of the service;
  • infringement caused by customer-uploaded material.

11. Intellectual-Property Liability

Cloud computing creates IP risks involving:

  • software;
  • databases;
  • copyrighted content;
  • trade secrets;
  • source code;
  • customer-created materials.

Liability can arise where:

  • the provider uses customer data without authorization;
  • software infringes another person's copyright or patent;
  • customer uploads infringing material;
  • confidential information is disclosed;
  • AI systems trained on cloud-hosted information improperly use protected material.

12. Third-Party Liability

Cloud arrangements often involve multiple entities.

For example:

Customer → Cloud Provider → Data Centre Operator → Subcontractor

A major legal question is whether the customer can sue a subcontractor with whom it has no direct contract.

Generally, this depends upon:

  • privity;
  • third-party beneficiary principles;
  • tort law;
  • agency;
  • statutory duties;
  • contractual indemnification.

UNCITRAL notes that subcontractors are normally not parties to the primary provider-customer contract, but applicable law may impose liability or the contract may create direct rights.

13. Important Case Laws

1. Clark Street Wine & Spirits v. Emporos Systems Corp., 754 F. Supp. 2d 474 (E.D.N.Y. 2010)

This is an important technology-security liability case.

Emporos supplied and supported electronic point-of-sale systems. Plaintiffs alleged that customer information was stolen because of weaknesses associated with the system.

The court permitted claims including:

  • gross negligence;
  • negligent supervision;
  • conversion;
  • breach of contract.

The court recognized the seriousness of security failures in computer systems and refused to dismiss the claims at the preliminary stage.

Principle

Technology providers may face negligence liability where they undertake security-related responsibilities and allegedly fail to exercise appropriate care.

It is particularly relevant to cloud providers because cloud services similarly involve the protection of customer information and computing infrastructure.

2. In re Zappos.com, Inc. Customer Data Security Breach Litigation

The Zappos litigation concerned a cyberattack involving approximately 24 million customer records.

Plaintiffs alleged that Zappos failed to adequately protect customer information.

The court allowed negligence theories concerning inadequate electronic safeguards to proceed, although certain contractual theories were dismissed because the alleged website security statements did not necessarily constitute contractual promises.

Principle

A technology company may owe a duty to exercise reasonable care in protecting personal information, but a statement about security is not automatically a contractual guarantee.

Importance to cloud computing

The case demonstrates the difference between:

  • contractual liability;
  • tort liability;
  • representations concerning cybersecurity.

3. In re Marriott International, Inc. Customer Data Security Breach Litigation

The Marriott litigation arose from a massive breach involving the Starwood reservation database.

Customers alleged:

  • negligence;
  • breach of contract;
  • consumer-protection violations;
  • inadequate cybersecurity.

Importantly, Accenture, an external IT provider involved in managing Starwood's systems, was also sued.

The district court allowed several tort claims against Accenture to proceed, while addressing standing and other issues.

The Fourth Circuit subsequently considered the class-certification proceedings involving Marriott and Accenture.

Principle

An outsourced IT/cloud-related service provider can potentially owe an independent duty of reasonable care concerning cybersecurity.

Significance

This is especially important where organizations argue:

“The data breach occurred in our vendor's system, so we are not responsible.”

Outsourcing technology does not necessarily eliminate legal responsibility.

4. Dinerstein v. Google LLC, 73 F.4th 502 (7th Cir. 2023)

The case concerned the sharing of de-identified medical information from the University of Chicago Medical Center with Google for purposes associated with healthcare technology and research.

The plaintiff alleged privacy and contractual violations.

The Seventh Circuit addressed whether the alleged de-identification and use of medical records supported the asserted legal claims.

Principle

The use of supposedly de-identified information does not automatically eliminate every legal issue.

Courts may examine:

  • contractual promises;
  • privacy interests;
  • representations concerning data;
  • actual identifiability;
  • permitted purposes of data use.

Cloud relevance

Cloud computing increasingly involves secondary processing of medical and other sensitive information, including AI processing.

5. In re Marriott International, Inc., Customer Data Security Breach Litigation — Accenture Liability

A particularly important aspect of the Marriott litigation was the claim against Accenture as a technology-service provider.

Accenture had undertaken significant IT responsibilities involving:

  • application management;
  • server and storage management;
  • data-centre management;
  • network management;
  • related IT functions. 

The Fourth Circuit recognized that the litigation could proceed against the technology provider on negligence-related theories and ultimately addressed class-certification issues concerning liability.

Principle

A technology provider's contractual relationship with a business customer may create a factual basis for determining whether it assumed responsibilities giving rise to tort duties.

6. Maldini v. Marriott International / In re Marriott, 78 F.4th 677 (4th Cir. 2023)

The Fourth Circuit's decision is significant for cloud and outsourced-IT liability because it involved claims against Accenture, a third-party IT service provider.

The court considered class certification involving negligence claims against Marriott and Accenture.

Issue classes were permitted concerning questions such as:

  • duty;
  • breach;

while individualized questions concerning:

  • causation;
  • injury;
  • damages

could be addressed separately.

Principle

Large-scale technology-security litigation may involve different liability questions at different stages, particularly where thousands or millions of customers are affected.

7. Fadullon v. Capital One Financial Corp. / Amazon Web Services Litigation

The Capital One breach litigation generated claims involving Amazon Web Services (AWS) because Capital One used AWS infrastructure.

The litigation illustrates an important cloud-computing principle: the presence of a cloud provider in the technical architecture does not automatically mean that every data-security failure is legally attributable to the cloud provider.

The precise allocation of responsibility depends upon:

  • contractual duties;
  • system configuration;
  • access controls;
  • customer responsibility;
  • provider responsibility;
  • causation.

The AWS-related claims appeared in the broader Capital One customer-data breach litigation.

Principle

Cloud infrastructure and application/security configuration can involve different layers of responsibility.

14. Indian Legal Position

India does not have one comprehensive statute called the “Cloud Computing Liability Act.”

Cloud liability can instead arise from several legal regimes.

Important sources include:

  • Information Technology Act, 2000;
  • Information Technology Rules;
  • Digital Personal Data Protection Act, 2023;
  • Indian Contract Act, 1872;
  • Consumer Protection Act, 2019;
  • Copyright Act, 1957;
  • Patent Act, 1970;
  • law of torts;
  • sector-specific regulatory requirements;
  • contractual obligations.

15. Indian Contractual Liability

A cloud-service agreement can impose obligations concerning:

  • uptime;
  • data security;
  • confidentiality;
  • data localization;
  • disaster recovery;
  • backup;
  • incident reporting;
  • deletion;
  • audit;
  • subcontracting;
  • indemnification.

A breach can give rise to:

  • damages;
  • specific contractual remedies;
  • termination;
  • indemnification;
  • service credits;
  • injunctions, where appropriate.

16. Data Protection Liability in India

Cloud providers may process personal data on behalf of organizations.

The legal analysis may involve:

  • purpose of processing;
  • authorization;
  • security safeguards;
  • breach notification;
  • contractual allocation;
  • processor/controller responsibilities;
  • statutory duties under applicable data-protection law.

The critical principle is:

Moving personal data into the cloud does not eliminate the obligations attached to that data.

17. Indian Cloud-Computing Case Law

1. Commissioner of Income Tax v. Amazon Web Services, Inc. (Delhi High Court, 2025)

The Delhi High Court considered the tax treatment of payments received by Amazon Web Services for cloud-computing services.

The dispute involved whether amounts received from Indian customers constituted royalty or fees for technical services under Indian domestic law and the India-US DTAA.

Importance

Although primarily a tax case rather than a negligence case, it demonstrates that courts must examine the actual technological nature of cloud services rather than treating cloud computing as a generic service.

2. M/s Water India Pvt. Ltd. v. Union of India, Karnataka High Court, 2025

The court considered the GST treatment of data-hosting services supplied to cloud-computing providers.

The issue included whether a data-hosting provider was an “intermediary” between a cloud provider and its end users.

The material emphasized that data-hosting providers may supply infrastructure directly to cloud providers without dealing with end users.

Importance

The case illustrates the legal distinction between:

  • cloud provider;
  • data-centre provider;
  • intermediary;
  • end customer.

This distinction can be important when determining contractual and regulatory responsibility.

3. Thoughtsol Infotech Pvt. Ltd. v. Union of India, 2025

The Allahabad High Court considered a dispute concerning the award of a government contract for cloud services for upgrading the National Data Repository.

The case demonstrates that cloud procurement may be subject to:

  • tender law;
  • public procurement principles;
  • contractual requirements;
  • administrative law.

 

18. Shared Responsibility Model

A very important concept is the shared responsibility model.

AreaProviderCustomer
Physical data centrePrimarily responsibleUsually not
Physical infrastructurePrimarily responsibleUsually not
Network infrastructurePrimarily responsiblePartly dependent on architecture
Operating systemDepends on IaaS/PaaS/SaaSOften customer in IaaS
ApplicationsOften customerOften customer
User credentialsUsually customerPrimarily customer
Data classificationSharedPrimarily customer
Access permissionsSharedOften customer
EncryptionSharedShared
BackupsContract dependentContract dependent
Regulatory complianceSharedShared
Incident notificationContract/statute dependentContract/statute dependent

Thus, liability must be determined layer by layer.

19. Cloud Service Model and Liability

IaaS

In IaaS, the provider generally controls:

  • physical servers;
  • storage infrastructure;
  • networking;
  • virtualization.

The customer generally controls:

  • operating systems;
  • applications;
  • user access;
  • customer data.

Therefore, a vulnerability in the physical infrastructure may implicate the provider, while an insecure customer application may implicate the customer.

PaaS

The provider controls more of the technological environment.

Liability may therefore extend to:

  • platform vulnerabilities;
  • middleware failures;
  • platform availability;
  • security failures within provider-controlled components.

But the customer remains responsible for its own applications and data to the extent allocated by contract and law.

SaaS

The provider generally controls most of the application environment.

Consequently, the provider may assume greater responsibility for:

  • application availability;
  • application security;
  • data storage;
  • updates;
  • software defects.

However, the customer may remain responsible for:

  • account management;
  • passwords;
  • user authorization;
  • lawful use;
  • uploaded content.

20. Causation in Cloud Liability

Causation is often one of the hardest elements.

Suppose:

Customer's data is stolen from a cloud platform.

The claimant must establish:

  1. What security obligation existed?
  2. Who was responsible for it?
  3. Was that obligation breached?
  4. Did the breach cause the unauthorized access?
  5. What legally compensable damage resulted?

If the breach occurred because a customer's employee disclosed an administrator password, provider liability may be significantly reduced.

21. Damages

Potential damages include:

Direct damages

  • cost of restoring systems;
  • data restoration;
  • replacement infrastructure;
  • incident-response expenses;
  • reasonable investigation costs.

Consequential damages

  • lost profits;
  • business interruption;
  • reputational losses;
  • loss of customers;
  • downstream contractual penalties.

Regulatory consequences

A breach may also result in:

  • regulatory fines;
  • compliance orders;
  • mandatory notification;
  • corrective measures.

Whether these are recoverable from the other contractual party depends heavily on the contract and applicable law.

22. Limitation of Liability vs Gross Negligence

One of the most important legal questions is whether a liability cap protects a cloud provider after serious misconduct.

In Clark Street Wine & Spirits v. Emporos Systems, the court allowed serious negligence allegations concerning security failures to proceed despite contractual limitations being asserted.

Therefore, parties should carefully distinguish:

  • ordinary negligence;
  • gross negligence;
  • reckless conduct;
  • intentional misconduct;
  • fraud;
  • statutory violations.

Many sophisticated cloud agreements carve some of these categories out of ordinary liability caps.

23. Incident Notification Liability

Cloud contracts frequently impose incident-notification obligations.

After a security incident, the parties may need to:

  1. identify the incident;
  2. contain the incident;
  3. investigate;
  4. preserve evidence;
  5. notify relevant parties;
  6. conduct root-cause analysis;
  7. implement remediation.

UNCITRAL recognizes that security-incident notification can arise from both law and contract.

Failure to notify may itself constitute a breach even where the original cyberattack was not preventable.

24. Defences Available to Cloud Providers

A provider may argue:

1. No contractual breach

The contract did not impose the alleged obligation.

2. Customer negligence

The customer caused the incident through:

  • poor configuration;
  • weak passwords;
  • unauthorized users;
  • failure to enable security features.

3. Force majeure

The incident resulted from an extraordinary event outside reasonable control.

4. Liability limitation

The contract caps damages.

5. Exclusion of consequential loss

The claimed losses fall within excluded categories.

6. Lack of causation

The provider's conduct did not cause the claimant's loss.

7. Lack of standing

The claimant cannot demonstrate legally cognizable injury.

25. Defences Available to Customers

Customers may argue:

  • the provider controlled the relevant system;
  • the provider promised specific security measures;
  • the provider failed to meet SLA requirements;
  • the provider knew of vulnerabilities;
  • the provider failed to notify the customer;
  • the provider retained control over backups;
  • the provider's subcontractor caused the failure;
  • the liability exclusion is invalid or does not cover the particular misconduct.

26. Regulatory and Contractual Liability Compared

IssueRegulatory LiabilityContractual Liability
SourceStatute/regulationCloud agreement
ClaimantGovernment/data subject/authorized personCustomer/contracting party
StandardStatutoryContractual
Liability capUsually restricted by lawOften expressly negotiated
Security obligationsStatutory minimumContractual standards may be higher
PenaltiesRegulatory sanctionsDamages/service credits
IndemnityGenerally not automatically availableFrequently negotiated

27. Key Legal Principles

The major principles governing cloud computing liability can be summarized as follows:

  1. Cloud computing does not eliminate legal responsibility.
  2. Liability follows control and contractual responsibility.
  3. The cloud provider is not automatically responsible for every customer security failure.
  4. The customer remains responsible for matters allocated to it.
  5. Cybersecurity obligations can arise in both contract and tort.
  6. Data-protection law may impose obligations independently of contractual allocation.
  7. Limitation clauses must be interpreted carefully.
  8. Gross negligence and intentional misconduct may receive different treatment from ordinary negligence.
  9. Subcontracting does not necessarily eliminate responsibility.
  10. Causation and actual damage remain essential to many liability claims.
  11. Cloud outages may produce contractual rather than tortious liability.
  12. Data breaches can generate simultaneous contract, tort, statutory and regulatory claims.

28. Exam-Oriented Case Law Summary

CaseCourt/YearMain Principle
Clark Street Wine & Spirits v. Emporos Systems Corp.E.D.N.Y., 2010Technology/security provider may face negligence liability
In re Zappos.com Customer Data Security Breach LitigationD. Nev.Failure to protect customer information can support negligence theories
In re Marriott International Customer Data Security Breach LitigationD. Md.Data-security obligations can produce contract and tort claims
Maldini v. Accenture LLP4th Cir., 2023Outsourced IT provider may face cybersecurity negligence claims
Dinerstein v. Google LLC7th Cir., 2023Cloud/data processing raises privacy, contractual and data-use questions
Fadullon v. Capital One/AWS litigationU.S. federal litigationCloud infrastructure does not automatically transfer all security responsibility to provider
CIT v. Amazon Web Services, Inc.Delhi HC, 2025Legal characterization of cloud-computing services depends on their actual nature
M/s Water India Pvt. Ltd. v. Union of IndiaKarnataka HC, 2025Data-hosting provider and cloud provider can constitute legally distinct actors
Thoughtsol Infotech Pvt. Ltd. v. Union of IndiaAllahabad HC, 2025Cloud procurement can generate public-law and contractual disputes

29. Conclusion

Cloud Computing Liability is fundamentally an issue of allocation of technological, contractual, regulatory and operational risk.

The central question is not simply:

“Who hosted the data?”

but rather:

“Who had the legal and practical responsibility for the particular system, data, security control or service that failed?”

Modern cloud disputes therefore require examination of the cloud architecture, service model, contract, SLA, security responsibilities, data-protection obligations, subcontracting arrangements, causation and limitation-of-liability provisions.

The most important lesson from the cases is that outsourcing computing infrastructure does not automatically outsource legal responsibility. At the same time, a cloud provider cannot automatically be held responsible for every failure occurring in a customer's cloud environment. Liability generally follows the combination of control, undertaking, contractual allocation, statutory duty, negligence and causation.

 

LEAVE A COMMENT