Recognizing Data Loss as an Emerging Damage in the Civil Liability of Autonomous Vehicles: A Comparative Analysis of Iranian and EU Law

Document Type : Research Paper

Authors

1 Assistant Professor, Department of Private Law, University of Mazandaran, Iran

2 Master in Private Law, Islamic Azad University, Sabzevar Branch, Iran

10.22034/law.2026.68830.3526

Abstract

The rapid expansion of artificial intelligence (AI)-based technologies, particularly autonomous vehicles, has posed novel challenges to traditional structures of civil liability. In this context, data have emerged as a foundational element for safety assurance, algorithmic decision-making, and accident reconstruction. The loss or deletion of such data may significantly affect the establishment of causation and the allocation of technological risk. This study employs a descriptive–analytical method with a comparative approach to examine the legal status of “data loss” within the civil liability regimes governing autonomous vehicles under European Union and Iranian law. At the level of the European Union, instruments such as the Product Liability Directive, the General Data Protection Regulation, and the AI Liability Directive demonstrate that data loss is not recognized as an independent category of classical damage. Nevertheless, where the absence of data affects safety or results in demonstrable harm, compensation may be granted within existing liability frameworks. Moreover, certain mechanisms aimed at facilitating proof of causation (particularly in AI-related claims) have been introduced or proposed. Under Iranian law, despite the compensatory capacity of Articles 1 and 2 of the Civil Liability Act and the enactment of the National Data and Information Management Act, the explicit legal characterization of data as a compensable head of damage in the context of autonomous vehicle liability remains underdeveloped. The findings indicate that legislative clarification, either through the incorporation of a specific provision into the Civil Liability Act or the adoption of a dedicated statute addressing liability and safety in autonomous systems, would provide a more coherent framework for victim protection and a more equitable allocation of technological risk.

Keywords

Main Subjects


  1. الف) فارسی

    کتاب‌

    1. حکمت‌نیا، محمود (1386). مسئولیت مدنی در فقه امامیه: مبانی و ساختار .تهران: پژوهشگاه علوم و فرهنگ اسلامی.

    مقالات

    1. ابهری، حمید؛ مافی، همایون و پارسا، ناهید (۱۴۰۰). مطالعۀ تطبیقی ضابطه‌های تشخیص عیب خودرو در حقوق ایران، انگلیس و امریکا .مطالعات حقوق تطبیقی، 12(2)، 397-415.

    Doi:10.22059/jcl.2021.317984.634142

    1. پارسا، ناهید (۱۴۰۳). بررسی مسئولیت مدنی ناشی از نقص نرم‌افزار در خودروهای خودران با نگاهی به حقوق آمریکا .فقه و حقوق اسلامی، ۱۵(۳۴)، 115-147.

    Doi:10.22034/law.2024.55488.3245

    1. جرفی، اسماء؛ صاحب، طیبه و شهبازی‌نیا، مرتضی (۱۴۰۳). مسئولیت مدنی مالک کشتی‌های خودران ناشی از تصادم کشتی. پژوهش‌های حقوق تطبیقی، ۲۸(۲)، 1-31.

    Doi:10.22034/clr.2024.72019

    1. احمدوند، بهناز و جهانشاهی، آرتین (۱۴۰۲). بررسی تطبیقی مفهوم داده‌های شخصی در نظام حقوقی اتحادیه اروپا و ایران. پژوهش‌های حقوق تطبیقی، ۲۷(۱)، 105-132.

    http://clr.modares.ac.ir/article-66499-20-fa.html

    1. کیشانی، مصطفی و اسدی، حسین (۱۳۹۹). ارزیابی اثر خطای انسانی بر اتکاپذیری سامانه‌های ذخیره‌سازی داده. علوم رایانش و فناوری اطلاعات، ۱۸(1)، 42-55.
    2. میرشکاری، عباس؛ پیشنماز، سید امین و رکنی، امیرعباس (۱۴۰۳). تراست داده، سازوکاری برای مدیریت منافع ذی‌نفعان داده؛ رهنمودهایی برای نظام داده در حقوق ایران. مطالعات حقوق تطبیقی معاصر، ۱۵(۳۴)، 279-320.             Doi:10.22034/law.2024.56448.3268
    3. ذاکری‌نیا، حانیه (۱۴۰۲). ماهیت و مبنای مسئولیت مدنی ناشی از هوش مصنوعی در حقوق ایران و کشورهای اتحادیۀ اروپا . حقوق خصوصی، ۲۰(۱)، 135-152.

    Doi:10.22059/jolt.2023.356703.1007186

    1. ولی‌زاده، حسین (1398). اثر قاعدۀ لاضرر در مسوولیت مدنی و نقش قاعدۀ اقدام در اثر رافعیت آن. قانون یار، 3(10)، 331-348.                https://sid.ir/paper/521350/fa

    قوانین و مقررات

    1. قانون مدنی ایران، مصوب مجلس شورای ملی، روزنامۀ رسمی شمارۀ ۹۰۳ مورخ ۱۸ اردیبهشت ۱۳۱۴.
    2. قانون مسئولیت مدنی مصوب ۱۳۳۹، روزنامۀ رسمی جمهوری اسلامی ایران، شمارۀ ۴۰۸۲.
    3. قانون جرایم رایانه‌ای مصوب ۱۳۸۸، روزنامۀ رسمی جمهوری اسلامی ایران، شمارۀ ۱۸۷۴۲.
    4. قانون تجارت الکترونیکی مصوب ۱۳۸۲، روزنامۀ رسمی جمهوری اسلامی ایران، شمارۀ ۱۷۱۶۶.
    5. قانون انتشار و دسترسی آزاد به اطلاعات مصوب ۱۳۸۸، روزنامۀ رسمی جمهوری اسلامی ایران، شمارۀ ۱۸۷۷۳.
    6. قانون مدیریت داده و اطلاعات ملی مصوب ۱۴۰۱، روزنامۀ رسمی جمهوری اسلامی ایران، شمارۀ ۲۲۸۰۷.

    منابع الکترونیک

    1. آوخ، محمد (۱۴۰۱، ۲۵ آبان). درک مفهوم دیتا؛ دیتا دقیقاً چیست؟ اعتمادآنلاین. بازیابی‌شده از https://www.etemadonline.com/ بخش-اجتماعی-23/555143-درک-مفهوم-دیتا-دیتا-دقیقا-چیست.

    ب) منابع انگلیسی

    Books

    1. Anderson, J. M.; Kalra, N.; Stanley, K. D.; Sorensen, P., & Oluwatobi, A. O. (2014). Autonomous Vehicle Technology: A Guide for Policymakers. Santa Monica, CA: RAND Corporation.
    2. Stair, R., & Reynolds, G. (2017). Principles of Information Systems (13th). Cengage Learning.

    Articles

    1. Badue, C.; Guidolini, R.; Carneiro, R. V.; Azevedo, P.; Cardoso, V. B.; Forechi, A., & De Souza, A. F. (2021). Self-driving Cars: a Survey. Expert Systems with Applications, 165, 113816. Doi:10.1016/­J.ESWA.­2020.113816
    2. Calo, R. (2016). Robotics and the Lessons of Cyberlaw. California Law Review, 103 (3), 513–563.
    3. Bhemavarapu, S. V. R. (2025). Cybersecurity for Autonomous Vehicles. https://arxiv.org/abs/2504.20180
    4. Fernández, Llorca, D.; Hamon, R.; Junklewitz, H.; Grosse, K.; Kunze, L.; Seiniger, P.; Swaim, R.; Reed, N.; Alahi, A.; Gómez, E.; Sánchez, I., & Kriston, Á. (2024). Testing Autonomous Vehicles and AI: Perspectives and Challenges from Cybersecurity, Transparency, Robustness and Fairness. arXiv Preprint, arXiv: 2403.14641. Doi10.48550/arXiv.2403.14641
    5. Nolte, M.; Nolte, S., & Menzel, T. (2025). A Review of Conceptualizations of Safety and Risk in Current Automated Driving Regulation. arXiv: 06594.
    6. Pinciroli, R.; Yang, L.; Alter, J., & Smirni, E. (2020). The Life and Death of SSDs and HDDs: Similarities, Differences, and Prediction Models. Conference Paper. https://www.researchgate.net/publication/­356678575
    7. Xu, Y.; Wei, J.; Mi, T., & Chen, Z. (2024). Data Security in Autonomous Driving: Multifaceted Challenges of Technology, Law, and Social Ethics. World Electric Vehicle Journal, 16 (1).

    Laws and Regulations

    1. European Commission. (2023). Regulation (EU) 2023/... on General Product Safety. Brussels: Official Journal of the European Union.
    2. European Commission. (2024). Directive 85/374/EEC on Liability for Defective Products (Consolidated Version with 2024 Amendments). EUR-Lex. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=­CEL­E­X­­%­3A­31985L0374
    3. European Commission. (2024a). Proposal for a Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence (AI Liability Directive). Brussels: COM(2022) 496 final.
    4. European Parliament and Council. (2016). Regulation (EU) 2016/679 (General Data Protection Regulation). OJ L119/1.
    5. European Parliament and Council. (2022). Directive on Adapting Non-Contractual Civil Liability Rules to Artificial Intelligence (AI Liability Directive), COM/2022/496 final.
    6. European Parliament and Council. (2024). Artificial Intelligence Act. Regulation (EU) 2024/1381. OJ L/2024/1381.
    7. ISO/IEC. (2015). ISO/IEC 2382:2015: Information Technology- Vocabulary. International Organization for Standardization/ International Electrotechnical Commission. https://www.iso.org/­standard/­63598.html
    8. National Institute of Standards and Technology. (2004). Standards for Security Categorization of Federal Information and Information Systems (FIPS Publication No. 199). U.S. Department of Commerce. Doi:10.6028/NIST.FIPS.199

    Online Sources

    1. (n.d.). What is Data Loss? Retrieved July 23, 2025, from https://www.hornetsecurity.com/en/knowledge-base/data-loss/
    2. National Institute of Standards and Technology. (n.d.). Computer Security Resource Center glossary. Retrieved July 24, 2025, from https://csrc.nist.gov/glossary

    Court Cases

    1. Court of Justice of the European Union (CJEU). (2014). Google Spain SL, Google Inc. v Agencia Española de Protección de Datos (AEPD), Mario Costeja González, Case C-131/12, ECLI:EU:C:2014:317. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX­%3A620­12­CJ0131