A statutory tort is a legal cause of action created by legislation rather than common law. In privacy contexts, it allows individuals to sue directly for serious harm, which changes the burden on organisations from regulatory compliance to evidential defence and demonstrable control in production.
Expanded Definition
A statutory tort is a legislated civil cause of action, not a judge-made common law tort. In privacy and data protection settings, that matters because the claimant’s right to sue is created by statute, so the organisation’s exposure depends on the wording of the law, the threshold for harm, and the remedies the statute permits.
The concept is narrower than “any legal claim” and broader than a regulator-only enforcement model. It can exist alongside regulatory fines, injunctions, and contractual remedies, but it changes the defensive posture: organisations may need to show what controls were operating, what evidence exists, and how the relevant duty was met. Where the statute uses terms such as “serious harm” or similar thresholds, the practical meaning is sometimes contested and may depend on jurisdiction and case law rather than a single universal rule.
For privacy practitioners, the common boundary mistake is to treat statutory tort risk as equivalent to policy compliance. The legal test is usually tied to statutory elements, not just whether an internal policy was adopted.
Examples and Use Cases
Statutory torts appear in practice when legislation gives individuals a direct private right of action for a defined wrong. That can reshape how organisations document controls, preserve evidence, and assess exposure.
- A privacy law creates a direct claim for unlawful disclosure of personal data, so a control failure can become private litigation rather than only a regulator matter.
- An employee or customer alleges that a statutory threshold for harm has been met, forcing the organisation to defend the evidential record around access, processing, and notification.
- A business with outsourced processing faces claims tied to how the statutory duty applied across controller and processor responsibilities, not just to contractual allocation.
- Legal teams assess whether internal incident handling, retention, and audit logs are sufficient to support a production defence if a claim is filed.
A useful way to think about the tradeoff is that the more directly a statute enables civil claims, the less safe it is to rely on policy language alone as proof of compliance.
Security Implications
Statutory tort exposure turns privacy and security control failures into potential civil liability. The risk is not only that an event occurred, but that the organisation cannot demonstrate that access controls, data handling, monitoring, or retention practices were strong enough to satisfy the legal duty created by statute.
That creates concrete consequences: incident records become evidence, missing logs can weaken a defence, and ambiguous control ownership can make it hard to show who was accountable for the breach of duty. In practice, the blast radius can extend beyond the initial data event because claimants may argue that the harm flowed from poor governance, not just from the disclosure itself.
Where statutory tort language is broad or evolving, organisations can also face uncertainty about whether harm must be material, how causation is established, and what proof is needed at each stage. The practitioner reality is that legal defensibility often depends on operational traceability, not on a retrospective explanation after the fact.
Domain and Governance Relevance
Statutory torts matter most in privacy, data protection, and regulated digital services because they shift the question from “was there a breach?” to “can the organisation defend its conduct under the statute?”. That is a governance issue as much as a legal one, since accountability, evidence retention, and control ownership all become part of the risk position.
For identity and access-heavy environments, the relevance is indirect but important: if a statutory tort claim follows unauthorised access, weak privilege control, or mishandled personal data, the quality of access governance becomes part of the evidential record. In that sense, the term reinforces the need for controls that are not only implemented, but also observable and provable.
NHIMG treats this as a reminder that compliance posture is not the same as litigation posture. A control that looks adequate in policy may still be difficult to defend if logs, approvals, and operational evidence are incomplete.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and CIS Controls v8 set the technical controls, while NIS2, DORA and PCI DSS v4.0 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | GV | Statutory tort exposure is an accountability and governance issue. |
| Recommendation: Establishes oversight and evidence discipline for legally defensible security decisions. | ||
| CIS Controls v8 | 8 | Claims often hinge on whether controls and events were recorded. |
| Recommendation: Supports evidential traceability when litigation depends on proving what happened. | ||
| NIS2 | Article 21 | Statutory liability often arises from failure to meet mandated security measures. |
| Recommendation: Links legal duties to demonstrable operational controls and accountability. | ||
| DORA | Article 5 | Direct liability questions often turn on accountable governance and control ownership. |
| Recommendation: Requires clear governance so statutory obligations can be defended and evidenced. | ||
| PCI DSS v4.0 | 10 | Where claims follow data misuse, logs are central to defending control effectiveness. |
| Recommendation: Preserves monitoring evidence needed to substantiate security and compliance claims. | ||
Related resources from NHI Mgmt Group
- Who is accountable when consumer connected products fail to meet statutory security requirements?
- How should organisations implement digital signature certificates for statutory e-filing without creating avoidable access and custody risk?
- What breaks when digital signatures are not used for statutory e-filings?
- Statutory Excuse
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org