Friday, February 19, 2010

EU Revises Model Contract Clauses for Data Transfers

The EU Data Protection Directive restricts transfers of personal data of EU residents to non-EU countries. A common approach for complying with this obligation is for the EU data transferor and the transferee abroad to adopt model contract clauses approved by the European Commission. The European Commission earlier this month adopted a decision approving a new set of model contract clauses for the transfer of personal data from a data controller to a foreign processor (controller-to-controller clauses were previously approved). The new clauses permit the foreign processor to re-transfer data to a sub-processor (the previous version did not permit this), and delete an arbitration provision from the previous version that had never been applied in practice.

© Copyright 2010 Steptoe & Johnson LLP

Friday, February 12, 2010

European Commission urges social-networking service providers to improve child safety policies

The European Commission is urging social-networking service providers to improve their child safety policies. In February 2009, 17 social-networking service providers such as Bebo, Facebook, Google and Microsoft signed an agreement on "Safer Social Networking Principles for the EU" (see Legal update, Social-networking service providers sign agreement on child online safety). The Commission has published a report, in which it says that most of these companies had empowered minors to tackle online risks by making it easier to change privacy settings, block users or delete unwanted comments and content. However, Viviane Reding, Commissioner for Information Society and Media, said more needed to be done. Less than half of social-networking providers made profiles of under-18 users visible only to their friends by default and only one third replied to user reports asking for help. Source: European Commission press release, 9 February 2010.

Court Muddies the Water on Electronic Signatures in New York

In Prudential Ins. Co. v. Dukoff, et al., a federal district court in New York has left unclear whether state regulators can add requirements for electronic signatures that go beyond those defined in the state’s electronic signatures law. While the court suggested that the state insurance department’s requirements were inconsistent with the statute, it nonetheless deferred to the department’s opinion that an electronic signature on an insurance application is valid only if the insurer can verify the identity of the person signing the application.

© Copyright 2010 Steptoe & Johnson LLP

Is the UK Moving Toward A De Facto Data Breach Notification Requirement?

The UK's Information Commissioner's Office recently warned companies that they could face tougher sanctions if they don't report data security breaches to the ICO. Although notification is not strictly required by the ICO, a recent statement by the ICO suggests that the agency may be seeking to establish a de facto notification requirement for serious data breaches. This warning is yet another sign that more countries, particularly in Europe, are moving toward expressly requiring notification of government agencies and/or affected individuals in the event of a data breach.

© Copyright 2010 Steptoe & Johnson LLP

Friday, January 22, 2010

Court Refuses to Enforce Take-Down Injunction Against Website

USA: A federal district court in Illinois has ruled in David Blockowicz, et al., v. Joseph David Williams, et al., that a website is not required to remove defamatory remarks despite an injunction against the persons who posted the remarks on the site. Wishing to avoid the immunity provision of the CDA, the plaintiffs sued the actual authors of the defamatory remarks rather than the websites that posted the remarks. The court issued an injunction requiring the plaintiffs to remove the remarks, but the plaintiffs were unable to contact the defendants. The plaintiffs therefore moved for third-party enforcement of the injunction against the website, ripoff.com. But the court was unpersuaded that the website – despite Terms of Service that included a copyright claim to all posted comments, a statement that comments would never be removed, and an indemnification clause – should be considered an aider and abettor of the defamatory remarks, and therefore refused to enforce the injunction against it.

© Copyright 2010 Steptoe & Johnson LLP


UK: Court reject copyright infringement and breach of confidence

The High Court has rejected a claim by a computer games designer, Mr Burrows, that a director of a company called Circle Studio Limited (Circle) which had previously employed him, had infringed copyright in a game called "Traktrix" which Mr Burrows had proposed to them, or breached confidence, by trying to exploit a substantially revised version of the game. Norris J found that there was no breach of confidence because the proposal for "Traxtrix" was not disclosed in circumstances importing an obligation of confidence; in disclosing the idea to Circle, Mr Burrows was doing what he was paid to do as a games designer, and there was no evidence that he told Circle that it was an idea that he had thought up before joining Circle. Norris J rejected the copyright claim because, among other things, Mr Burrows argued that Circle had copied significant parts of his original document recording the concept for the game in a later design document relating to it. However, since nobody at Circle knew of the original document, if the design document incorporated parts of it, it was because Mr Burrows himself incorporated them. This was not a grant of an implied licence by Mr Burrows, but a unilateral act requiring no agreement on Circle's part.

Monday, October 12, 2009

ISPs Ordered to Pay $32 Million to Louis Vuitton for Contributory Trademark and Copyright Infringement

A federal jury in California has found two Internet service providers, Akanoc Solutions, Inc., and Managed Solutions Group, Inc. ("MSGI"), and their owner, Steven Chen, guilty of contributing to trademark and copyright infringement for hosting websites selling counterfeit Louis Vuitton goods, and has awarded Louis Vuitton $32 million in damages. As we previously reported, Louis Vuitton sued Akanoc, MSGI and Chen for "knowingly allow[ing] and encourag[ing] certain websites to use" their Internet hosting services to infringe Louis Vuitton's "valid trademarks and copyrights." Louis Vuitton successfully demonstrated that both ISPs knew of the infringing websites but failed to take "simple measures" to shut them down.

© Copyright 2009 Steptoe & Johnson LLP

Monday, September 28, 2009

Keyword advertising vs. trade mark infringement

Advocate General (AG) Poiares Madura has provided a detailed opinion concerning Google's keyword advertising system, following references to the ECJ from France in three sets of proceedings brought by trade mark owners against Google. The AG considered (among other things) that Google, by displaying advertisements in response to keywords corresponding to trade marks, established a link between those keywords and the sites advertised, which sold goods or services. However, such a link did not constitute trade mark infringement as the mere display of relevant sites in response to key words was not enough to lead to confusion. The AG's opinion provides some much-needed clarification of trade mark law in relation to keyword advertising, although it remains to be seen whether it will be followed by the ECJ when it gives its decision. Brand owners will doubtless be disappointed with the opinion, but the references only concerned the use of keywords which corresponded to trade marks, not the use of the trade marks in advertisements, or in the products sold via the sites advertised. The AG also considered that the liability exemption for hosts in Article 14 of the E-Commerce Directive (2000/31/EC) should not apply to the content featured in Google's AdWords. Case: Google France and Google Inc. v Louis Vuitton Malletier, Google France v Viaticum Luteciel, and Google France v CNRRH and others, Joined Cases C???236/08, C???237/08 and C???238/08, 22 September 2009.

©Legal & Commercial Publishing Limited

Friday, September 11, 2009

Facebook Capitulates in Privacy Law Face-Off

Facebook, Inc. has reached agreement with the Office of the Privacy Commissioner of Canada regarding privacy controls on the social networking website. As we previously reported, the Office found that several of Facebook's practices violated Canada's Personal Information Protection and Electronic Documents Act. The Office gave Facebook 30 days to address the concerns or face court action. Facebook has now consented to several significant changes, including a more forthcoming description of its Privacy Policy; more granular privacy settings; a permissions-based model for third-party applications (e.g., games and quizzes) that allows users to select the information they share with third parties; and the clear option to either "deactivate" or entirely "delete" an account.

© Copyright 2009 Steptoe & Johnson LLP.

Friday, August 28, 2009

Information Commissior Office (UK) publishes guidance on changes to notification fee

The Information Commissioner's Office (ICO) has published a guidance note, which will come into effect on 1 October 2009, on changes to the notification fee system for data controllers under the Data Protection Act 1998. Under the two-tier notification fee system for data controllers due to be introduced under the Data Protection (Notification and Notification Fees) (Amendment) Regulations 2009 (SI 2009/1677), a data controller with an annual turnover of £25.9 million and 250 or more members of staff, and public authorities with 250 or more members of staff, will have to pay initial and annual renewal notification fees of £500, while other data controllers will continue to pay a £35 fee (see Legal update, New data protection regulations introduce two-tier notification fee structure). Among other things, the ICO's guidance explains the criteria used to determine which tier a data controller is in; provides details of certain organisations, such as charities, which will always be deemed fall into the lower tier, regardless of their size or turnover; and explains the rationale for the fee changes.

Source: ICO guidance, Notification fee changes.

IPO rejects opposition to YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME mark for telecoms

A hearing officer of the Intellectual Property Office has dismissed Virgin Enterprises Limited's opposition to an application to register YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME for, among other things, telecommunications in class 38. Virgin Enterprises relied on its earlier registrations of VIRGIN for identical services in class 38 to oppose the mark under section 5(2)(b) of the Trade Marks Act 1994 (TMA). The hearing officer held that there was very little similarity between the marks, and that the average consumer would not assume that there was an economic association between the parties so as to give rise to a likelihood of confusion. The hearing officer also dismissed Virgin Enterprises' opposition under section 5(3) of the TMA, which was based on its earlier mark VIRGIN MOBILE in classes 9 and 38. He held that, although the name VIRGIN MOBILE had acquired a reputation as a trade mark in relation to mobile phones and telecoms, the relevant public would not make a link between the respective marks on account of their lack of similarity. The hearing officer did not consider that the applicant's ordinary English-language use of the word "virgin" amounted to taking advantage of the VIRGIN mark. Case: Application no. 2466095 to register the trade mark YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME and opposition no. 96472, BL 0-216-09, 23 July 2009.

©Legal & Commercial Publishing Limited; Practical Law Company Limited 2009

High Court upholds claim for misuse of confidential information, breach of database right and passing off against ex-employee

The High Court has held that an ex-employee who copied and retained various documents and information belonging to his ex-employer, including thousands of contact details and sales figures, had acted in breach of confidence. Peter Smith J said that the claimant's database was an important tool as it provided an immediate base which the ex-employee could use to start up his rival business of organising conferences. He held that the ex-employee's activities amounted to a classic springboard operation. The judge also held that the ex-employee's acts in extracting a large amount of information from the claimant's database was a breach of article 16(1) of the Copyright and Rights in Database Regulations 1997, as it was clear that the database had been created with substantial investment in obtaining, verifying and presenting its contents. The judge also upheld a claim in passing off as the ex-employee had suggested that the conference his company was organising was a follow-up to the conference the claimants had held the previous year. Case: First Conferences Services Limited & another v Richard Bracchi & another [2009] EWHC 2176 (Ch), 26 August 2009.

Thursday, August 20, 2009

Argentine Court Holds Yahoo!, Google Liable for Defamatory Third-Party Content

They say a picture is worth a thousand words, but an Argentine court recently ruled that a picture can also be worth thousands of dollars in damages. Virginia Da Cunha sued Yahoo! and Google for damages after photos of her that were posted on sex-trade websites, without her consent, appeared in the results of Internet searches for her name. A civil court in Buenos Aires ruled for Da Cunha and awarded her $26,248 in damages, finding that the search engines actively amplified the harm of the defamatory third-party postings by making the sex-trade websites more accessible than they would otherwise be. The court also held that neither company was doing enough to guard against such harm to individuals.

© Copyright 2009 Steptoe & Johnson LLP

Friday, August 14, 2009

District Court “Backs Up” from Ninth Circuit’s Ruling on Access to Stored Email

A district court in Illinois recently determined that opened, web-based emails held by an Internet Service Provider are not in “electronic storage” within the meaning of the Stored Communications Act (SCA). Accordingly, the government could obtain such emails with a mere subpoena rather than a search warrant. The district court came to this conclusion despite the Ninth Circuit’s contrary ruling in Theofel v. Farey-Jones which, as we previously reported, reached a broader interpretation of “electronic storage” and thus affords greater privacy protection for emails.

© Copyright 2009 Steptoe & Johnson LLP

Payment Card Industry Issues Data Security Guidance for Wireless Networks

The Payment Card Industry Security Standards Council released a new set of recommendations on how organizations subject to the PCI Data Security Standard (DSS) should address the data security concerns raised by wireless networks. The DSS requires all participating “merchants, banks, [and] POS [point of sale] vendors” -- as well as their service providers and other contractors -- to implement six sets of security requirements: build and maintain a secure network, protect card holder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. As we have previously reported, the latest version of the DSS added a requirement that covered entities ensure that "wireless networks transmitting cardholder data or connected to the cardholder data environment [CDE] ... use industry best practices (for example, IEEE 802.11i) to implement strong encryption for authentication and transmission." The guidance issued last month by the Standards Council offers suggestions on how to comply this requirement.

Is There Such a Thing as an Honest Hacker?

According to the Second Circuit, there just might be. In reviewing a district court’s denial of a preliminary injunction against an alleged computer hacker accused of insider trading, the court drew a distinction between two types of hackers: one who misrepresents her identity to gain access to a computer, and another who takes advantage of a security glitch to achieve the same end. The court suggested that the latter conduct might not be “deceptive” within the meaning of section 10(b) of the Securities and Exchange Act of 1934.

Friday, July 31, 2009

British Court Finds Google Not Liable for Defamatory Search Results

A court in the United Kingdom ruled that Google is not liable for defamatory material that appears in its search results because it is not a "publisher" of such material. The court equated Google to a library catalogue, which would not be held liable for the content of the books it lists. The UK has traditionally been friendly to libel claimants, so this decision -- though consistent with rulings in the US and EU -- is an important precedent for search engines.

© Copyright 2009 Steptoe & Johnson LLP

Canada Joins Europe In Scrutinizing Social Networking Sites' Privacy Practices

The Office of the Privacy Commissioner of Canada has found that some of Facebook's most popular features -- including third-party applications and the tagging of photos with names and email addresses -- violate the data protection principles of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Those principles require organizations that use the personal information of Canadians to, inter alia, implement procedures to protect such information; identify the purposes for which it is collected; collect and retain it only where necessary for these purposes; and obtain the data subject's consent prior to its "collection, use, or disclosure." In its report, the Privacy Office found that Facebook failed to abide by these principles, citing several unresolved violations of PIPEDA. The Office stated that it would reassess Facebook's compliance with PIPEDA and the report's recommendations in 30 days. Along with a recent EU Article 29 Data Protection Working Party opinion (on which we previously reported) advising all social networking sites that handle the personal data of EU residents that they must comply with the EU Data Protection Directive, this report indicates that the increasing scrutiny of social networking sites' data protection policies around the world could force significant changes in the way such sites operate.

© Copyright 2009 Steptoe & Johnson LLP

Friday, July 24, 2009

Court fines owner of construction-worker database

The Information Commissioner's Office (ICO) has issued a press release indicating that Ian Kerr, owner of a firm trading as the Consulting Association, has been fined £5,000 by Knutsford Crown Court for breaching the Data Protection Act 1998 (DPA), and has been ordered to pay costs of £1,187. Mr Kerr had pleaded guilty to failing to notify as a data controller at Macclesfield Magistrates Court, which transferred the case for sentencing to the Crown Court (see Legal update, Owner of construction-worker database pleads guilty to data protection offences). An ICO investigation revealed that Mr Kerr had been operating a database for over 15 years containing details on 3,213 construction workers, including information about their trade union activity and employment history, which was used by over 40 construction companies to vet individuals for employment. The ICO also indicated in its press release that it intends to serve enforcement notices on 17 construction companies who were involved in using the database maintained by Mr Kerr. It said preliminary enforcement notices had been sent out, with formal enforcement action to follow shortly, subject to any representations made by the companies. Source: ICO press release, 16 July 2009.

©Legal & Commercial Publishing Limited

Friday, July 17, 2009

MySpace Wins CDA Immunity in Assault Cases

A California Court of Appeal recently upheld a lower court's ruling that the Communications Decency Act (CDA) immunized MySpace against claims stemming from "its decision not to implement reasonable, basic safety precautions with regard to protecting young children from sexual predators." In four consolidated cases, several girls aged 13 to 15 who were sexually assaulted by men they met through MySpace (the Julie Does) and their parents or guardians sued MySpace for negligence, gross negligence, and strict product liability. The appellate court held that these claims were barred by section 230(c)(1) of the CDA, which states that "[n]o provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider" and has generally been interpreted as immunizing websites against claims stemming from information posted by third parties. Finding that it was "undeniable that appellants s[ought] to hold MySpace responsible for the communications between the Julie Does and their assailants," the appellate court concluded that "section 230 immunity shields MySpace" from liability. Along with the Lori Drew ruling discussed above, the court’s dismissal of these claims against MySpace suggests that both users and providers of social networking websites may be able to skirt liability for some of the sites' more unsavory uses – at least for now. But if courts continue to throw out cases where social networking websites have been involved in incidents of stalking, bullying, or assault, the public backlash could lead Congress to narrow the scope of CDA immunity.

© Copyright 2009 Steptoe & Johnson LLP

UK: High Court considers role of search engine operator as publisher

The High Court has held that Google Inc. could not be regarded as the publisher of words alleged to be defamatory which appeared in search results. The search engine operator had been joined in proceedings for defamation because internet searches on certain terms, including one of the claimant's trading names (Train2Game), brought up a thread "Train2Game new SCAM for Scheidegger" from a bulletin board which the claimant said was defamatory of it. Eady J found that, given that the search results were generated automatically, and that Google Inc. had blocked access to specific URLs identified by the claimant, but had no control over formulating search terms, so that it could not otherwise remove offending material, it was unrealistic to attribute responsibility for publication to Google Inc., whether on the basis of authorship or acquiescence. Eady J also considered various arguments regarding the application of section 1 of the Defamation Act 1996 to the facts, and the potential relevance of the Electronic Commerce (EC Directive) Regulations 2002 (SI 2002/2013) to providers of search engine services. Case: Metropolitan International Schools Limited v (1) Designtechnica Corporation, (2) Google UK Limited, (3) Google Inc. [2009] EWHC 1765 (QB), 16 July 2009.

(source: practical law)

WIPO proposes paperless UDRP proceedings

ICANN has launched a 30-day consultation on a proposal from WIPO to allow for paperless UDRP proceedings by amending the UDRP implementation rules. In its proposal, WIPO explains that abolishing the requirement for hard-copy pleadings, in its view, will result in significant time and costs savings. However, it is proposing that notification of the proceedings is still sent by post to a respondent in case its e-mail address is incorrect or inactive. WIPO does not propose any changes to the UDRP itself. The consultation closes on 12 August 2009. Source: ICANN announcement, 13 July 2009

(source: practicallaw)

Wednesday, January 21, 2009

IP crime data for 2007 published

The Intellectual Property Office (IPO) has published an interim report covering intellectual property (IP) crime data for 2007. The last IP crime report, which was published in December 2007, included IP crime data from 2006 (see Legal update, Government publishes 2007 intellectual property crime report). The IPO is to change the reporting period for the annual crime report from a calendar year basis to April to March, to follow the financial year, and this interim report will be included as an annex to the 2008/09 report. The interim report contains data from a number of sources, including a UK survey on film and television piracy, a study on the amount of unlicensed software in the EU, UK court statistics on IP cases, and data from a European Commission report on customs activities in relation to counterfeiting and piracy. Source: IPO press release, 9 January 2009.

EDPS issues second opinion on amendment of E-Privacy Directive

The European Data Protection Supervisor (EDPS) has published a second opinion on the proposed amendments to the E-Privacy Directive (2002/58/EC). The opinion analyses and compares the positions put forward by the European Council, the European Parliament and the European Commission, and includes a number of recommendations. Among other things, the EDPS continues to support the adoption of a security breach notification scheme under which national regulators and individuals will be notified when individuals' personal data has been compromised. He also reiterates many of the suggestions made in his first opinion relating to the scope of the Directive and the right of legal persons (including consumer associations) to bring legal action against service providers for infringement of the Directive. Compared to his original opinion, the EDPS has taken great care to spell out in more detail the specific reasons for his original recommendations, taking on board many of the points that have been made by the three European legislators since the first opinion was published. Read more.

PLC IPIT&Communications weekly

Monday, February 18, 2008

MySpace obtains transfer of myspace.co.uk

MySpace Inc. has succeeded in having the domain name myspace.co.uk transferred to it using Nominet's dispute resolution procedure. The respondent had registered the domain name in 1997, long before MySpace launched its social-networking site. The Nominet expert's main reason for finding the registration abusive was that after MySpace became a household name, the respondent posted links to various social-network site links on a pay-per-click "parking" site accessible via the domain name, enabling it to profit from the success of the MySpace site and also creating a risk of confusion between MySpace's services and those of other sites. This decision is a reminder that even if a domain name is registered in all innocence, the respondent's subsequent use of it may render the registration abusive.Source: MySpace Inc. v Total Web Solutions Limited, Case 04962, January 2008.

© Legal & Commercial Publishing Limited

Friday, August 31, 2007

ICASA guns for unlicensed WISPs

The Independent Communications Authority of SA (ICASA) has vowed to crack down on wireless Internet service providers (WISPs) that operate without a licence or allocated spectrum.

Click on link above to read more

For opinions and advice on above topic - call us at Van Gaalen Attorneys

Mobile subscriber registration almost law

The National Assembly yesterday passed amendments to the monitoring of communications law.The amendments mandate cellular operators to register all prepaid customers within one year and that all visitors must register their cellphones. SA's estimated 38 million cellphone subscribers largely consist of prepaid users.

Click on link above to read more

Monday, August 20, 2007

Who Knows What Evil Lurks in the Hearts of Disloyal Employees?

The Shadow may know, but some courts couldn't care less. Employers increasingly use the Computer Fraud and Abuse Act (CFAA) to seek redress against former employees that pilfered company data. Courts have split, however, on whether a former employee's improper use of company information is enough to make out a CFAA claim. As we have previously reported, several courts have held that an employee who accessed information for an improper purpose -- such as his personal benefit or that of his employer's competitor -- acted "without authorization" or "exceed[ed his] authorized access" within the meaning of the Act. But a few courts have gone the other way. Most recently, a federal court in Pennsylvania ruled in Brett Senior & Associates v. Fitzgerald that a former employee's allegedly unauthorized use of client files did not establish that the employee exceeded his authorized access when he took the files.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, August 10, 2007

German Court Rules that Skype Violated Open Source License

Open source software (OSS) is big right now. Part of what makes OSS so attractive is its licensing structure. OSS licenses require that software source code (i.e., the version that can be read and changed by human programmers) must be made publicly available, and most OSS licenses -- including the most popular, known as the GNU General Public License (GPL) -- require anyone who distributes a program based on OSS must likewise make their changes publicly available. Many companies have discovered that using OSS code in their products makes good business sense. But using OSS software in a commercial product can also create legal complications. A case in point is a German court ruling (see case summary) that distribution of an OSS mobile phone using the Skype software without a copy of the GPL or source code violated the license's terms.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, August 03, 2007

Amendments – Notices required

In the first U.S. appellate court decision to address the issue, the Ninth Circuit has ruled that a provider of long distance phone service may not change the terms of its service contract "by merely posting a revised contract on its website." Since the provider did not show that it had given the subscriber any notice other than the posting, the Ninth Circuit struck down a lower court's order to compel arbitration based on a clause of the modified contract. The court's ruling sets an important precedent, and highlights the importance of giving subscribers clear and prompt notice of all contractual revisions.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, July 27, 2007

ISPs to prevent copyright infringement

The Belgian Court of First Instance in Brussels ruled late last month that a local Internet service provider must take certain proactive measures to block or filter peer-to-peer downloading of pirated audio and video files. The court's ruling was based on the European Union's Information Society Directive, which requires member states to "ensure that rightholders are in a position to apply for an injunction against intermediaries whose services are used by a third party to infringe a copyright or related right." The ISP must begin using technology to prevent copyright infringement within six months of the ruling, or face fines of €2,500 a day for non-compliance. While recording and movie industry groups have cheered the decision, it could greatly increase in liability for Internet service providers -- especially if other courts follow Belgium's lead.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, July 13, 2007

Court Mandates Music Filtering for ISP

The Court of First Instance in Belgium issued a decision two weeks ago in a copyright infringement case brought by the Belgian music collecting society SABAM against Scarlet, an ISP formerly known as Tiscali. In the decision, the court ordered Scarlet to implement filtering within six months in order to remove copyrighted music from its network. An unnamed court-appointed expert identified several technologies -- including Audible Magic's acoustic fingerprinting -- that Scarlet could use to meet the court's requirements.

Friday, June 22, 2007

Temporary storage may not be so temporary


Data privacy and data retention are hot issues these days. While American and European legislatures and regulators wring their hands over how to balance the interests of privacy, law enforcement, and commercial imperatives, courts are not hesitating to step into the breach in unexpected ways. Last month, in
Columbia Pictures Indus. v. Bunneli, a federal magistrate judge in California ordered TorrentSpy, a website that offers dot-torrent files for download by users, to preserve and produce information about users' interaction with the site, even though this information is purposely not logged but only stored temporarily in the RAM of either the TorrentSpy server, located in the Netherlands, or of servers controlled by a third-party middleman, located around the world. The ruling was based on the Federal Rules of Civil Procedure, which require litigants to retain and produce "electronically stored information" relevant to a case. The court rejected the defendants' various arguments for why retention and production should not be required – including costs, the website's privacy policy, the Stored Communications Act (SCA), the Wiretap Act, the pen register statute, the First Amendment, the potential loss of users' good will, and conflicts with Dutch data protection law. If this ruling becomes the norm in discovery, it could lead to much greater retention and production of communication records, website logs, and search terms during litigation. More broadly, if courts routinely order data retention during discovery, even where such retention is not part of a company's normal business practices, the slope leading to a broad data retention mandate seems likely to get a lot more slippery.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Monday, April 16, 2007

Inconsistent Enforcement of Email Policies: the Employer's Hobgoblin?

Ralph Waldo Emerson famously wrote that "a foolish consistency is the hobgoblin of little minds." But, as a recent Fourth Circuit decision suggests, consistency is a good idea when it comes to enforcement of email use policies. In Media General Operations, Inc. v. National Labor Relations Board, the Fourth Circuit upheld the NLRB's finding that the Richmond Times-Dispatch, a newspaper owned by Media General, had wrongly interfered with employees' union communications. Although Media General had a policy prohibiting personal use of the company email system, the court noted that the company's enforcement of the policy was uneven, allowing a "wide variety of messages unrelated to company business" while prohibiting "union messages." Although this decision dealt with the narrow issue of labor relations, its reasoning could affect how courts treat claims by or against employees where employer monitoring of employees' communications or workers' violations of company computer policies are at issue. The lesson for employers: without uniform enforcement, an email use policy might not be very useful.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, March 02, 2007

Apparently Not All Information "Wants to Be Free"

Hackers (or "crackers") used to justify their computer break-ins with the catchy claim that "information wants to be free." But the last decade's boom in computer crime, identity theft, and digital copyright infringement has tarnished any appeal that motto once held in the popular imagination. Still, people may be surprised at just how restrictive the legal constraints are on unauthorized access to, or sharing of, information. For example, people who inappropriately share an individual user code and password to access an online publication may not only be infringing a copyright, but may also be guilty of a crime. That, anyway, is the upshot of the decision by a federal court in California in Therapeutic Research Faculty v. NBTY, Inc. In that case, the court refused to dismiss civil claims brought against defendants who allegedly abused a limited subscription to a copyrighted medical database. The plaintiff claimed violation of the Copyright Act, the Computer Fraud and Abuse Act, and the Electronic Communications Privacy Act. For companies that use licensing agreements to manage their provision of copyrighted material over the Internet, the ruling may provide additional ammunition for going after unscrupulous licensees. Moreover, since those statutes also provide the basis for criminal liability, the court's reasoning means that those who abuse a subscription to an online publication may not only be civilly liable, but could -- at least in theory -- be subject to prosecution as well.

© Copyright 2007 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, January 26, 2007

Hack Attacks on Mobile Banking to Rise Sharply

This year could see a sharp rise in hacker attacks on Internet-enabled smart phones as a number of new banking and payment initiatives enter the mobile channel, a research group warned Monday.

Friday, January 05, 2007

Court turns back on Antitrust Claims against Verisign and ICANN

Currently, if a company wishes to register a .com or .net domain, the registrar who secures the domain on the company’s behalf must file a registration request with VeriSign, Inc., the registry operator that the Internet Corporation for Assigned Names and Numbers (ICANN) has granted sole rights to those domains. So when VeriSign secured -- without competitive bidding -- a five-year extension to its control over .com domains which permitted price increases for domain registrations, a coalition of Internet domain registrars, registrants and back order service providers known as the Coalition For ICANN Transparency Inc. (CFIT) filed suit against VeriSign and ICANN in federal court in California. The suit alleged that VeriSign had monopolized the markets for the registration of both new and expiring .com and .net domains and that VeriSign had conspired with ICANN to monopolize and restrain trade in these markets. Late last year, the court dismissed these claims, finding that no monopolizable separate market existed for expired domain names, and that CFIT had not shown that an antitrust injury had occurred.

© Copyright 2006 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Aussies and Yanks Agree: Linker Beware

"Caveat emptor" (or "buyer beware") has long been a guiding principle for consumers. But as more business -- and copyrighted content -- moves online, mavens of e-commerce might want to formulate an additional maxim: "caveat linker." As recent decisions in the United States and Australia demonstrate, webmasters -- and, in some cases, the Internet service providers that host their sites -- have several reasons to link with care. In Live Nation Motor Sports, Inc. v. Davis, a federal court in Texas held that by including links to live audio webcasts owned by Live Nation on his website, the defendant had likely infringed upon the plaintiff’s copyright. And in Cooper v. Universal Music Australia Pty Ltd., the Federal Court of Australia upheld a judge’s ruling, on which we reported earlier, that a website operator and his ISP had "authorized" copyright infringement by linking to third-party sites that hosted pirated music files. These two decisions suggest that webmasters and ISPs should be wary when linking to content, particularly if they suspect that it may be copyrighted.

© Copyright 2006 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Wednesday, October 11, 2006

UK to investigate breaches at outsourcing centres

The UK's Information Commissioner is launching an investigation into outsourced data centres after a Channel 4 television programme exposed security breaches at Indian call centres. Channel 4's Dispatches was offered individuals' banking details for as little as £8 by criminal networks in India, Out-Law.com reports. Deputy Information Commissioner David Smith said that dependent on the outcome of the investigation the office would consider whether it should use formal enforcement powers to prevent such incidents. It could potentially prevent some companies from sending their data outside of the UK for processing. Smith said that companies which outsource their data processing or any back office functions are entirely responsible for that data and its security. It is not permissible, he said, for a company to simply pass blame on to a contractor.Full Out-Law.com report

Creative Commons – a new copyright model

With the explosion in self-generated Web sites comes the problem of who owns copyright on content published for global consumption. CDU reports that Professor Brian Fitzgerald’s lecture on the new field of copyright law known as Creative Commons, outlined the enormous potential for copyright infringement where content posted on the Net can be easily accessed, altered and ‘cut and pasted’ into new versions of someone’s creativity. Fitzgerald, who is project leader for Creative Commons investigation in Australia, said those happy to share their content could simply badge their material as Creative Commons: Attribution. This allowed it to be reproduced, so long as the creator of the material was acknowledged. Full CDU report

Friday, August 11, 2006

IT Security: HSBC exposed by flaw

MORE than three million customers of global banking giant HSBC have been left vulnerable while banking over the internet for more than two years because of a security flaw.

Tuesday, July 11, 2006

Employers spying on workers, study suggests

Canadian employers in a wide range of industries conduct surveillance of employees at work, suggests a report to be released on Monday.
The Ryerson study follows a large workplace survey in the United States and Britain, which suggested 40 per cent of employers regularly read employees' e-mails.
The results of the aforesaid study will most probably be exactly the same if such a study would be conducted in South Africa.

It is imperative for organisations in South Africa, when dealing with monitoring of communications, to ensure they comply not only with the Regulation of Interception of Communications and Provision of Communication-Related Information Act 2002, but also the Labour Relations Act and other Privacy related legislation.

For more information on:
  1. eCommunication Policy
  2. Record Management Policy
  3. IT Security Policy
  4. Interception and Monitoring Policy
  5. Awareness programs for employees
  6. In-house training to address the above issue
  7. Correct implementation of a procedure / process to deal with the Interception of Communications
  8. Software to assist with the implementation of Policies,
contact van Gaalen Attorneys:
Tel: 011 782 9511
Fax: 0866318898
email: info@vangaalenlaw.co.za
website: www.vangaalenlaw.co.za

Phishers come calling on VoIP

Cheaply available voice over Internet Protocol numbers and Net calling are helping crooks launch new data-thieving scams, a security company has warned.

Tuesday, June 06, 2006

Companies Read Employee E-mail

Big Brother is not only watching but he is also reading your e-mail.

According to a new study, about a third of big companies in the United States and Britain hire employees to read and analyze outbound e-mail as they seek to guard against legal, financial or regulatory risk.

Friday, May 26, 2006

Berners-Lee applies Web 2.0 to improve accessibility

Accessibility seminars often begin with a quote by Tim Berners-Lee: "The power of the web is in its universality. Access by everyone regardless of disability is an essential aspect." It's an old quote, but the web's inventor offered fresh ideas the day before yesterday.

Phones4u wins passing off appeal against phone4u

An online seller of mobile phones did not infringe the trade mark of John Caudwell's Phones4u chain when it used the domain name phone4u.co.uk, according to the Court of Appeal. But Friday's judgment concluded that there was passing off.

Dealing with a phishing attack

As phishing attacks have grown, the defences and mysterious counter-measures have evolved. Uri Rivner, Head of New Technologies at RSA Cyota Consumer Solutions, tells a detective's story.

The Business of CANning SPAM

The FTC took a short break from the business of security breach enforcement to remind corporate America that commercial email (a/k/a spam) has its rules, and failing to abide by them has a price. In statement released on May 11, the FTC announced that both Kodak Imaging Network (formerly Ofoto, Inc.) and ICE.com had agreed to settle a series of CAN-SPAM charges brought against them in a pair of FTC complaints. According to the Commission, Kodak allegedly "sent a commercial e-mail message to more than two million recipients that failed to contain an opt-out mechanism, failed to disclose in the email message that consumers have the right to opt-out of receiving further mailings, and failed to include a valid physical postal address, as required by law." Meanwhile, ICE.com purportedly "sent more than 6,000 e-mail messages to consumers who had previously requested not to receive future commercial e-mail messages from the company." Neither company was hit with a very big fine ($26,331 for Kodak, and only $6,500 for ICE.com). But, in addition to agreeing not to violate CAN-SPAM again, both companies agreed to submit themselves to a series of FTC monitoring, record-keeping, and reporting provisions intended to keep them honest.
© Copyright 2006 Steptoe & Johnson LLP

GET YOUR ECOMMUNICATIONS GUIDE NOW
If you want your organisation to be compliant with South African eCommunication legislation then email us (info@vangaalenlaw.co.za ) your details (Fulle Name, name of your organisation, website address, email address and tel. no.) and we will forward you our eCommunications Guide. The eCommunication Guide will include the topic as mentioned above - "how to reflect an 'unsubscribe' opt-out function in accordance with sec. 45 of the Electronic Communications and Transactions Act 25 of 2002"

Thursday, May 18, 2006

Appeals Court says Denial of Service is a crime

A judge made a mistake when he suggested that a teenager using a 'mail-bombing' program to attack his former employer's computer system was not breaching the Computer Misuse Act, according to the Court of Appeal.

Others must learn from Morgan Stanley's missing emails

Morgan Stanley last week agreed to pay $15 million to settle a civil action brought by the US Securities and Exchange Commission for failing to produce tens of thousands of emails requested during SEC investigations from 2000 to 2005.

Friday, May 12, 2006

ISO/IEC standard benchmarks provision of software asset management

A new ISO and IEC standard for managing software assets is expected to result in cost savings for users, whether large or small enterprises, as well as improved efficiency, risk management and customer (internal and external) satisfaction.

Published by ISO (International Organization for Standardization) and IEC (International Electrotechnical Commission), ISO/IEC 19770-1:2006, Information technology - Software asset management - Part 1: Processes will enable organizations to benchmark their capability in delivering managed services, measuring service levels and assessing performance.

Software asset management (SAM) principles apply to the media, installations, licenses, proof of license, and intellectual property associated with the software. Until now the application of these business processes has been arbitrary and relatively few organizations have been able to implement a comprehensive strategy. The implementation of ISO/IEC 19770-1:2006 will standardize the framework making it possible for companies to integrate SAM into their other compliance and best practice models.

ISO/IEC 19770:2006, which is issued in two parts under the general title, Software asset management, will enable service providers to understand how to enhance the quality of service delivered to their customers, both internal and external.


  • Part 1: describes the processes involved in SAM.

  • Part 2: defines a product identification that will simplify the software inventory process*.


The standard is intended to align closely to, and to support, ISO/IEC 20000:2005, issued in two parts under the general title, Information technology - Service management.

If you think it is time to audit your existing Software Assest Management ("SAW") process / practise and amend same to reflect the latest standard, then contact van Gaalen Attorneys who will be able to:-

  1. Execute a SAW audit;
  2. Provide a GAP analysis (incl. recommendations);
  3. Deliver and assist with the implementation of the required process flows, policies, notices etc.to ensure that your organisation is compliant with the ISO/IEC standard

Contact van Gaalen Attorneys for more information: info@vangaalenlaw.co.za or tel: 011 782 9511/2 or fax: 0866318898

Friday, April 28, 2006

UK Data Protection Authority Takes Surprisingly Flexible Approach to Sale of Consumer Data

Upholding its reputation as one of the most flexible EU data protection authorities (DPAs), the Office of the UK Information Commissioner recently released Good Practice Note taking a surprisingly flexible approach to sale of databases containing consumers' personal data. To the initial question "Can databases be sold?," the Information Commissioner gave a qualified "Yes." The first circumstance in which the Information Commissioner notes that consumer databases may be sold is where the consumers included in the database have given their consent. The second, and more controversial, circumstance is the Information Commissioner's statement that if a business is insolvent, bankrupt, going out of business, or being sold, the "[UK Data Protection] Act will not prevent the sale of a database containing the details of individual customers, providing certain requirements are met." The "requirements" relate mainly to using the information for the "same or similar" purposes to those for which the information was gathered, and providing notice to consumers in the database of the sale. But nowhere does the Information Commissioner say that consumers must be given the chance to object to further use of their information upon a sale, and the authorization of "similar" use is quite flexible. Such guidance will certainly raise a few eyebrows at other EU DPAs.

© Copyright 2006 Steptoe & Johnson LLP

IT Security: Hacking law updates are overdue

It's taken some time for MPs to decide how to update the UK's laws against hackers. Nevertheless, the proposals in the new Police and Justice Bill don't look too shabby.

Apple argues that blogger can't protect source

A US appeals court has been hearing arguments in a case that tests the right of a blogger to protect his sources. Apple Computer wants to know who leaked details of a product called 'Asteroid' and expects bloggers to reveal the names.

Wednesday, April 26, 2006

IT Security: What's the Inside Attacker Profile?

What's the Inside Attacker Profile?
The United States Secret Service and the Carnegie Mellon University Software Engineering Institute's CERT Coordination Center published an insider threats study report in 2005 which offered critical insights into the mind and motivation of the "inside attacker." According to the statistics gathered, the inside attacker is usually:

  • Male
  • 17-60 years old
  • Holds a technical position (86 percent chance)
  • May or may not be married (50/50 chance)
  • Racially and ethnic diverse

Sufficiently broad pool? Absolutely. Here are some additional statistics, again from the same CERT study:

  • In 92 percent of the incidents investigated, revenge was the primary motivator.
  • Sixty-two percent of the attacks were planned in advance.
  • Fifty-seven percent of the attackers surveyed would consider themselves "disgruntled."
  • Eighty percent exhibited suspicious or disruptive behavior to their colleagues or supervisors before the attack.
  • Only 43 percent had authorized access (by policy, not necessarily via system control).
  • Sixty-four percent used remote access to carry out the attack.
  • Most incidents required little technical sophistication.

Worker can't be fired for Web surfing

A New York City employee cannot be fired for surfing the Web from work, an administrative law judge has ruled.

Tuesday, April 25, 2006

High costs hamper domain resolution

The Department of Communications expects progress to be made on the development of an alternative domain name dispute resolution process within the next three months. The absence of an alternative dispute resolution process (ADRP) has led to high costs for businesses, say industry players...

Tuesday, April 18, 2006

ICANN mulls .tel domain for contact info

Reaching out and touching someone used to be as simple as dialing a string of numbers.

But now there are home, cell and work phone numbers from which to choose, and sometimes work extensions to remember. There are also e-mail addresses -- at home and at work -- and instant messaging handles, perhaps separate ones for the various services, some of which now do voice and video besides text.

Some people even have Web pages -- through their employer or Internet service provider, or perhaps a profile or two on MySpace.

To help people manage all their contact information online, the Internet's key oversight agency is considering a ``.tel'' domain name. If approved, the domain could be available this year.

Wireless TV all-clear

Is this something that we will see in South Africa when it comes to the braodcasting of TV over wireless devices or over the internet?

See what was said in Canada:
Cellphone TV services started with hockey clips and news but now the broadcasting regulator has given wireless carriers carte blanche to move beyond traditional television.
Mobile TV services from Telus Corp., Bell Mobility Inc. and Rogers Wireless Communications Inc. are delivered over the Internet and aren't subject to the same rules as those provided by cable operators and broadcasters, the Canadian Radio-television and Telecommunications Commission said Wednesday....

See Canadian Radio-television and Telecommunications Commission's Public Notice on Regulatory framework for mobile television broadcasting services - click here

source: www.theglobeandmail.com

Thursday, April 13, 2006

Court rules that an email address is not a signature

A High Court judge has ruled that the presence of a sender's email address in the header of an email does not amount to a signature – although a typed name would have sufficed to form a binding contract.

Monday, April 10, 2006

Corporate blogs are a liability

EDITORIAL: Many bloggers wear suits, not pyjamas. A recent proliferation of corporate blogs has given numerous workers a new platform for self-expression. But while employers hope to see business benefits, lawyers will see nothing but trouble.

ID thect and fraud - The weakest link - uneffective policy implementation!!!

There's some good news and some bad news to report concerning the fight against identity theft and cyber fraud. The good news is that financial institutions and other companies continue to batten down their information security with high-end tecnological measures such as two-stage identification and multifactor authentication. The bad news is that even the most advanced information security systems often have an Achilles heel -- usually in inadequate, or unenforced, policies covering employees and contractors. The recent spate of thefts of employee or contractor laptops thefts, resulting in the loss of sensitive information, is a perfect example. No matter how much money a company spends on fancy data security measures, these less sexy links in its security chain will continue to be vulnerable to exploitation by clever fraudsters. This doesn’t mean companies should give up on the high-end technological measures. Rather, it means companies need to pay as much attention to the more mundane, less glamorous aspects of security, like establishing and enforcing rules on the handling of sensitive data, and regularly using encryption.

© Copyright 2006 Steptoe & Johnson LLP. Steptoe & Johnson LLP

Friday, March 31, 2006

Do you read the License?

Open Content Movement Finds a Poster Child From MTV
In early March, the District Court of Amsterdam ruled that Dutch gossip magazine Weekend infringed the copyright in four photos which were posted on photography website flickr. Adam Curry, who, among other things, is a former MTV "video jockey," had posted the photos under the Creative Commons Attribution-NonCommercial-ShareAlike license, which allows photos to be used freely (with attribution) for non-commercial purposes, but not for commercial purposes (such as the use by Weekend). Weekend defended Curry's action by arguing that it was misled by the notice "This photo is public" that was posted with the photos, and therefore did not click on the Creative Commons "CC" symbol accompanying a "some rights reserved" notice (also posted with the photos), which led to a summary of the terms of the license. The court rejected this argument, stating that "it may be expected from a professional party like [the publisher of Weekend] that it conduct a thorough and precise examination before publishing in Weekend photos originating from the internet." The Curry decision thus holds (at least under Dutch law) that not only are Creative Commons licenses valid, but more suprisingly that publishers are under a duty to understand and investigate such licenses even in the face of a confusing statement like "This photo is public."

Source: Steptoe & Johnson LLP. Steptoe & Johnson LLP

The first move in the direction of web accessibility standards

Separating coders from cowboys with PAS 78

A guide published earlier this month about how to commission accessible websites will transform web accessibility in the UK, according to Chris Rourke of User Vision. The firm is also seeking your views in a short online survey.

P2P Crackdown - soon in South Africa?

Crackdown on corporate P2P users in Britain - Is your company addressing this risk?!

The Federation Against Software Theft is about to take action against a number of companies in the UK that have been caught making illegal copies of software available for download from their networks – which may come as a complete surprise to the companies.

Thursday, March 16, 2006

IMPORTANT - Cryptography Regulations

As of Friday 10 March 2006, providers of cryptography products or services will have to register at the Department of Communications certain information before they can provide cryptography services and/or cryptography products.

It is important to know that failure to register could lead to fine or up to two years imprisonment.

If you are unclear whether you are a cryptography service / product provider - here are the definitions as per the Electronic Communications and Transactions Act 2002:

This is according to the cryptography regulations published in the government gazette on 10 March in terms of the Electronic Communications and Transactions Act of 2002 (ECT Act):
"cryptography provider" means any person who provides or who proposes to provide cryptography services or products in the Republic.

"cryptography service" means any service which is provided to a sender or a recipient of a data message or to anyone storing a data message, and which is designed to facilitate the use of cryptographic techniques for the purpose of ensuring
a) that such
data or data message can be accessed or can be put into an intelligible form only by certain persons;
b) that the authenticity or integrity of such
data or data message is capable of being ascertained;
c) the integrity of the data or data message; or
d) that the source of the data or data message can be correctly ascertained.


"cryptography product" means any product that makes use of cryptographic techniques and is used by a sender or recipient of data messages for the purposes of ensuring-
a) that such
data can be accessed only by relevant persons;
b) the authenticity of the data;
c) the integrity of the data; or
d) that the source of the data can be correctly ascertained;


Contact van Gaalen Attorneys today to find out about their special offer to register you / your organisation as a Cryptography Service- / Product provider

Tel: 011 782 9511/2
Fax: 086 631 8898
email: info@vangaalenlaw.co.za (heading - cryptography special offer)

Security 'not a problem' for IT managers

The top two IT-related problems facing companies today are operational incidents and staffing issues, according to a study commissioned by the IT Governance Institute (ITGI).

Communications bill ushers in demise of Telkom’s monopoly

COMPETITION in the telecoms industry will get a major boost from the Electronic Communications Bill now awaiting presidential approval, the chairman of Parliament’s communications portfolio committee believes.

No TV licence fees for IPTV

Those planning to receive TV on their mobile devices or PCs using broadband technology will not have to pay a TV licence fee for this.

OSS: The alternative in digital forensics?

Open source software (OSS) tools can be credible and reliable in digital forensics, says Cobus Venter, senior researcher at The Cyber Security Science Centre, a division of the Council for Scientific and Industrial Research (CSIR).

Monday, February 27, 2006

Morgan Stanley offers $15m to make up for missing emails

Investment bank Morgan Stanley has offered to pay the Securities and Exchange Commission (SEC) $15m to settle an investigation by the regulator into an alleged failure by the firm to produce email evidence during a legal dispute.

Friday, February 24, 2006

Metatags and Trademark Infringement

Any business with an Internet presence wants to increase its website traffic. And one of the best ways to do this is to rely on something web surfers never see -- a bit of HTML coding called a "metatag" that describes the content of a website. Search engines use these small pieces of hidden coding to index web pages according to content so web surfers can be directed to web pages with the content they request. Where things can get problematic, though, is when businesses manipulate hidden metatags to draw more eyes to their websites. One way to do this, for instance, is to use the trademark of a competitor in your metatags to attract that competitor’s customers. But that clever tactic just ran into a roadblock, when a federal court in Ohio ruled that the use of a competitor's mark in metatags to pull consumers to a website constitutes trademark infringement, even if consumers eventually realized that the site was not that of the competitor. This decision could have major -- and negative -- ramifications for Google and other search engines that allow companies to use competitors' marks as keyword search terms, so that their own paid ads (and links) are displayed when someone searches for the competitor's name

Wednesday, February 15, 2006

How to avoid Open Source Licensing pitfalls

Open Source software can offer users greatcommercial advantages when care is taken to address the intellectual property issues andminimise contractual risks.

Open source has long held an imprtant place in fulfilling

Wednesday, January 18, 2006

Why SCO has no case

"IT directors shouldn't worry about SCO Group's latest sallies in its legal war on Linux vendors IBM Corp. and Novell Inc., says attorney Thomas Carey. It's just more posturing, or as Shakespeare said, a tale "full of sound and fury, signifying nothing."

Monday, January 16, 2006

Liable For Your Employee's Porn Addiction??!

With specific reference to our own Films and Publications Act (Amended), employers in South Africa should be aware of similar actions in South Africa - see below, information received from the USA:
Employers' monitoring of their employees' online activity is nothing new. And neither is reprimanding an employee for visiting pornography websites at the office. But thanks to a recent court decision, employers may now have a legal obligation to halt such activity by employees, or they could be liable if that activity "result[s] in harm to innocent third parties." On December 27, in Doe v. XYC Corp., the Superior Court of New Jersey, Appellate Division, ruled that "an employer who is on notice that one of its employees is using a workplace computer to access pornography, possibly child pornography, has a duty to investigate the employee's activities and to take prompt and effective action to stop the unauthorized activity." The court held that no privacy interest of the employee stood in the way of this duty. Although the ruling has serious implications for any company that offers Internet service in the workplace, it may be of special interest to Internet service providers -- who already have their own child pornography notification obligations under 42 U.S.C. § 13032, and who may come across illegal activity not only on the part of their employees but also on the part of their subscribers. And the court's reasoning could extend beyond pornography to any illegal or harmful conduct engaged in by employees from their work computers.

Friday, January 13, 2006

U.S. Government Pushes Banks to Tighten up Online

E-Commerce Times: The Federal Financial Institutions Examination Council, a federal agency that includes the Federal Reserve System, the Federal Deposit Insurance Corp. and the National Credit Union Administration, and oversees banking regulations in the U.S., issued guidelines in late 2005 calling for online banks to implement two-factor identity authentication. Now the agency has announced that it will begin evaluating banks for compliance with the guidelines later this year. The guidelines were issued because the FFIEC felt that single-factor authentication is not secure enough for online banking applications.

Interesting numbers!!

15 percent
Proportion of IT budgets to be allocated toward compliance projects in 2006, up from less than 5 percent in 2004, according to Gartner projections.Source:
CRN
1,031
Number of companies restating their earnings in 2005 as of October, as compared to 650 for all of 2004 and 270 for all of 2001.Source:
International Herald Tribune
90 percent
Proportion of companies that go under within two years of losing data, according to research firm Baroudi Bloor International.Source:
Sarbanes-Oxley Compliance Journal

Wednesday, January 11, 2006

Overhaul of GPL set for public release

A major revamp of the General Public License is scheduled for public release next week, a move that's expected to kick off a long and vocal debate over the key foundation of open-source programming.

Friday, December 16, 2005

Software Thief Admits To Crimes

Nathan Peterson took on some of the world's largest computer software companies, and for a while, he won.

Thursday, December 08, 2005

One-quarter of Internet users targeted in phishing scams monthly

About one in four Internet users are hit with e-mail scams every month that try to lure sensitive personal information from unsuspecting consumers, a study says.

Sunday, December 04, 2005

IM worms up again in November

The number of worms that targeted instant-messaging services hit 62 in November, up 226 percent from October and hitting a new record, Akonix Systems said Tuesday. Of the worms, 58 were variants of previous pests, and four were new. In the same month, a total of 14 attacks hit peer-to-peer networks, such as Kazaa and eDonkey, according to Akonix, which sells security software and appliances.

ISPs may not carry int’l calls over VoIP

The Ministry of Communications has instructed Internet service providers (ISPs) to ensure that their systems do not carry international calls over VoIP, which bypass Israel’s authorized international calls carriers. The ministry sent the instruction following complaints.

EU expects a rush for .eu domain name

The European Union expects a surge of applications next week when its ``.eu'' regional domain name opens for registration.