Friday, February 19, 2010

EU Revises Model Contract Clauses for Data Transfers

The EU Data Protection Directive restricts transfers of personal data of EU residents to non-EU countries. A common approach for complying with this obligation is for the EU data transferor and the transferee abroad to adopt model contract clauses approved by the European Commission. The European Commission earlier this month adopted a decision approving a new set of model contract clauses for the transfer of personal data from a data controller to a foreign processor (controller-to-controller clauses were previously approved). The new clauses permit the foreign processor to re-transfer data to a sub-processor (the previous version did not permit this), and delete an arbitration provision from the previous version that had never been applied in practice.

© Copyright 2010 Steptoe & Johnson LLP

Friday, February 12, 2010

European Commission urges social-networking service providers to improve child safety policies

The European Commission is urging social-networking service providers to improve their child safety policies. In February 2009, 17 social-networking service providers such as Bebo, Facebook, Google and Microsoft signed an agreement on "Safer Social Networking Principles for the EU" (see Legal update, Social-networking service providers sign agreement on child online safety). The Commission has published a report, in which it says that most of these companies had empowered minors to tackle online risks by making it easier to change privacy settings, block users or delete unwanted comments and content. However, Viviane Reding, Commissioner for Information Society and Media, said more needed to be done. Less than half of social-networking providers made profiles of under-18 users visible only to their friends by default and only one third replied to user reports asking for help. Source: European Commission press release, 9 February 2010.

Court Muddies the Water on Electronic Signatures in New York

In Prudential Ins. Co. v. Dukoff, et al., a federal district court in New York has left unclear whether state regulators can add requirements for electronic signatures that go beyond those defined in the state’s electronic signatures law. While the court suggested that the state insurance department’s requirements were inconsistent with the statute, it nonetheless deferred to the department’s opinion that an electronic signature on an insurance application is valid only if the insurer can verify the identity of the person signing the application.

© Copyright 2010 Steptoe & Johnson LLP

Is the UK Moving Toward A De Facto Data Breach Notification Requirement?

The UK's Information Commissioner's Office recently warned companies that they could face tougher sanctions if they don't report data security breaches to the ICO. Although notification is not strictly required by the ICO, a recent statement by the ICO suggests that the agency may be seeking to establish a de facto notification requirement for serious data breaches. This warning is yet another sign that more countries, particularly in Europe, are moving toward expressly requiring notification of government agencies and/or affected individuals in the event of a data breach.

© Copyright 2010 Steptoe & Johnson LLP

Friday, January 22, 2010

Court Refuses to Enforce Take-Down Injunction Against Website

USA: A federal district court in Illinois has ruled in David Blockowicz, et al., v. Joseph David Williams, et al., that a website is not required to remove defamatory remarks despite an injunction against the persons who posted the remarks on the site. Wishing to avoid the immunity provision of the CDA, the plaintiffs sued the actual authors of the defamatory remarks rather than the websites that posted the remarks. The court issued an injunction requiring the plaintiffs to remove the remarks, but the plaintiffs were unable to contact the defendants. The plaintiffs therefore moved for third-party enforcement of the injunction against the website, ripoff.com. But the court was unpersuaded that the website – despite Terms of Service that included a copyright claim to all posted comments, a statement that comments would never be removed, and an indemnification clause – should be considered an aider and abettor of the defamatory remarks, and therefore refused to enforce the injunction against it.

© Copyright 2010 Steptoe & Johnson LLP


UK: Court reject copyright infringement and breach of confidence

The High Court has rejected a claim by a computer games designer, Mr Burrows, that a director of a company called Circle Studio Limited (Circle) which had previously employed him, had infringed copyright in a game called "Traktrix" which Mr Burrows had proposed to them, or breached confidence, by trying to exploit a substantially revised version of the game. Norris J found that there was no breach of confidence because the proposal for "Traxtrix" was not disclosed in circumstances importing an obligation of confidence; in disclosing the idea to Circle, Mr Burrows was doing what he was paid to do as a games designer, and there was no evidence that he told Circle that it was an idea that he had thought up before joining Circle. Norris J rejected the copyright claim because, among other things, Mr Burrows argued that Circle had copied significant parts of his original document recording the concept for the game in a later design document relating to it. However, since nobody at Circle knew of the original document, if the design document incorporated parts of it, it was because Mr Burrows himself incorporated them. This was not a grant of an implied licence by Mr Burrows, but a unilateral act requiring no agreement on Circle's part.

Monday, October 12, 2009

ISPs Ordered to Pay $32 Million to Louis Vuitton for Contributory Trademark and Copyright Infringement

A federal jury in California has found two Internet service providers, Akanoc Solutions, Inc., and Managed Solutions Group, Inc. ("MSGI"), and their owner, Steven Chen, guilty of contributing to trademark and copyright infringement for hosting websites selling counterfeit Louis Vuitton goods, and has awarded Louis Vuitton $32 million in damages. As we previously reported, Louis Vuitton sued Akanoc, MSGI and Chen for "knowingly allow[ing] and encourag[ing] certain websites to use" their Internet hosting services to infringe Louis Vuitton's "valid trademarks and copyrights." Louis Vuitton successfully demonstrated that both ISPs knew of the infringing websites but failed to take "simple measures" to shut them down.

© Copyright 2009 Steptoe & Johnson LLP

Monday, September 28, 2009

Keyword advertising vs. trade mark infringement

Advocate General (AG) Poiares Madura has provided a detailed opinion concerning Google's keyword advertising system, following references to the ECJ from France in three sets of proceedings brought by trade mark owners against Google. The AG considered (among other things) that Google, by displaying advertisements in response to keywords corresponding to trade marks, established a link between those keywords and the sites advertised, which sold goods or services. However, such a link did not constitute trade mark infringement as the mere display of relevant sites in response to key words was not enough to lead to confusion. The AG's opinion provides some much-needed clarification of trade mark law in relation to keyword advertising, although it remains to be seen whether it will be followed by the ECJ when it gives its decision. Brand owners will doubtless be disappointed with the opinion, but the references only concerned the use of keywords which corresponded to trade marks, not the use of the trade marks in advertisements, or in the products sold via the sites advertised. The AG also considered that the liability exemption for hosts in Article 14 of the E-Commerce Directive (2000/31/EC) should not apply to the content featured in Google's AdWords. Case: Google France and Google Inc. v Louis Vuitton Malletier, Google France v Viaticum Luteciel, and Google France v CNRRH and others, Joined Cases C???236/08, C???237/08 and C???238/08, 22 September 2009.

©Legal & Commercial Publishing Limited

Friday, September 11, 2009

Facebook Capitulates in Privacy Law Face-Off

Facebook, Inc. has reached agreement with the Office of the Privacy Commissioner of Canada regarding privacy controls on the social networking website. As we previously reported, the Office found that several of Facebook's practices violated Canada's Personal Information Protection and Electronic Documents Act. The Office gave Facebook 30 days to address the concerns or face court action. Facebook has now consented to several significant changes, including a more forthcoming description of its Privacy Policy; more granular privacy settings; a permissions-based model for third-party applications (e.g., games and quizzes) that allows users to select the information they share with third parties; and the clear option to either "deactivate" or entirely "delete" an account.

© Copyright 2009 Steptoe & Johnson LLP.

Friday, August 28, 2009

Information Commissior Office (UK) publishes guidance on changes to notification fee

The Information Commissioner's Office (ICO) has published a guidance note, which will come into effect on 1 October 2009, on changes to the notification fee system for data controllers under the Data Protection Act 1998. Under the two-tier notification fee system for data controllers due to be introduced under the Data Protection (Notification and Notification Fees) (Amendment) Regulations 2009 (SI 2009/1677), a data controller with an annual turnover of £25.9 million and 250 or more members of staff, and public authorities with 250 or more members of staff, will have to pay initial and annual renewal notification fees of £500, while other data controllers will continue to pay a £35 fee (see Legal update, New data protection regulations introduce two-tier notification fee structure). Among other things, the ICO's guidance explains the criteria used to determine which tier a data controller is in; provides details of certain organisations, such as charities, which will always be deemed fall into the lower tier, regardless of their size or turnover; and explains the rationale for the fee changes.

Source: ICO guidance, Notification fee changes.

IPO rejects opposition to YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME mark for telecoms

A hearing officer of the Intellectual Property Office has dismissed Virgin Enterprises Limited's opposition to an application to register YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME for, among other things, telecommunications in class 38. Virgin Enterprises relied on its earlier registrations of VIRGIN for identical services in class 38 to oppose the mark under section 5(2)(b) of the Trade Marks Act 1994 (TMA). The hearing officer held that there was very little similarity between the marks, and that the average consumer would not assume that there was an economic association between the parties so as to give rise to a likelihood of confusion. The hearing officer also dismissed Virgin Enterprises' opposition under section 5(3) of the TMA, which was based on its earlier mark VIRGIN MOBILE in classes 9 and 38. He held that, although the name VIRGIN MOBILE had acquired a reputation as a trade mark in relation to mobile phones and telecoms, the relevant public would not make a link between the respective marks on account of their lack of similarity. The hearing officer did not consider that the applicant's ordinary English-language use of the word "virgin" amounted to taking advantage of the VIRGIN mark. Case: Application no. 2466095 to register the trade mark YOU CAN'T BE A VIRGIN ALL YOUR LIFE ITS TIME and opposition no. 96472, BL 0-216-09, 23 July 2009.

©Legal & Commercial Publishing Limited; Practical Law Company Limited 2009

High Court upholds claim for misuse of confidential information, breach of database right and passing off against ex-employee

The High Court has held that an ex-employee who copied and retained various documents and information belonging to his ex-employer, including thousands of contact details and sales figures, had acted in breach of confidence. Peter Smith J said that the claimant's database was an important tool as it provided an immediate base which the ex-employee could use to start up his rival business of organising conferences. He held that the ex-employee's activities amounted to a classic springboard operation. The judge also held that the ex-employee's acts in extracting a large amount of information from the claimant's database was a breach of article 16(1) of the Copyright and Rights in Database Regulations 1997, as it was clear that the database had been created with substantial investment in obtaining, verifying and presenting its contents. The judge also upheld a claim in passing off as the ex-employee had suggested that the conference his company was organising was a follow-up to the conference the claimants had held the previous year. Case: First Conferences Services Limited & another v Richard Bracchi & another [2009] EWHC 2176 (Ch), 26 August 2009.

Thursday, August 20, 2009

Argentine Court Holds Yahoo!, Google Liable for Defamatory Third-Party Content

They say a picture is worth a thousand words, but an Argentine court recently ruled that a picture can also be worth thousands of dollars in damages. Virginia Da Cunha sued Yahoo! and Google for damages after photos of her that were posted on sex-trade websites, without her consent, appeared in the results of Internet searches for her name. A civil court in Buenos Aires ruled for Da Cunha and awarded her $26,248 in damages, finding that the search engines actively amplified the harm of the defamatory third-party postings by making the sex-trade websites more accessible than they would otherwise be. The court also held that neither company was doing enough to guard against such harm to individuals.

© Copyright 2009 Steptoe & Johnson LLP

Friday, August 14, 2009

District Court “Backs Up” from Ninth Circuit’s Ruling on Access to Stored Email

A district court in Illinois recently determined that opened, web-based emails held by an Internet Service Provider are not in “electronic storage” within the meaning of the Stored Communications Act (SCA). Accordingly, the government could obtain such emails with a mere subpoena rather than a search warrant. The district court came to this conclusion despite the Ninth Circuit’s contrary ruling in Theofel v. Farey-Jones which, as we previously reported, reached a broader interpretation of “electronic storage” and thus affords greater privacy protection for emails.

© Copyright 2009 Steptoe & Johnson LLP

Payment Card Industry Issues Data Security Guidance for Wireless Networks

The Payment Card Industry Security Standards Council released a new set of recommendations on how organizations subject to the PCI Data Security Standard (DSS) should address the data security concerns raised by wireless networks. The DSS requires all participating “merchants, banks, [and] POS [point of sale] vendors” -- as well as their service providers and other contractors -- to implement six sets of security requirements: build and maintain a secure network, protect card holder data, maintain a vulnerability management program, implement strong access control measures, regularly monitor and test networks, and maintain an information security policy. As we have previously reported, the latest version of the DSS added a requirement that covered entities ensure that "wireless networks transmitting cardholder data or connected to the cardholder data environment [CDE] ... use industry best practices (for example, IEEE 802.11i) to implement strong encryption for authentication and transmission." The guidance issued last month by the Standards Council offers suggestions on how to comply this requirement.

Is There Such a Thing as an Honest Hacker?

According to the Second Circuit, there just might be. In reviewing a district court’s denial of a preliminary injunction against an alleged computer hacker accused of insider trading, the court drew a distinction between two types of hackers: one who misrepresents her identity to gain access to a computer, and another who takes advantage of a security glitch to achieve the same end. The court suggested that the latter conduct might not be “deceptive” within the meaning of section 10(b) of the Securities and Exchange Act of 1934.

Friday, July 31, 2009

British Court Finds Google Not Liable for Defamatory Search Results

A court in the United Kingdom ruled that Google is not liable for defamatory material that appears in its search results because it is not a "publisher" of such material. The court equated Google to a library catalogue, which would not be held liable for the content of the books it lists. The UK has traditionally been friendly to libel claimants, so this decision -- though consistent with rulings in the US and EU -- is an important precedent for search engines.

© Copyright 2009 Steptoe & Johnson LLP

Canada Joins Europe In Scrutinizing Social Networking Sites' Privacy Practices

The Office of the Privacy Commissioner of Canada has found that some of Facebook's most popular features -- including third-party applications and the tagging of photos with names and email addresses -- violate the data protection principles of Canada's Personal Information Protection and Electronic Documents Act (PIPEDA). Those principles require organizations that use the personal information of Canadians to, inter alia, implement procedures to protect such information; identify the purposes for which it is collected; collect and retain it only where necessary for these purposes; and obtain the data subject's consent prior to its "collection, use, or disclosure." In its report, the Privacy Office found that Facebook failed to abide by these principles, citing several unresolved violations of PIPEDA. The Office stated that it would reassess Facebook's compliance with PIPEDA and the report's recommendations in 30 days. Along with a recent EU Article 29 Data Protection Working Party opinion (on which we previously reported) advising all social networking sites that handle the personal data of EU residents that they must comply with the EU Data Protection Directive, this report indicates that the increasing scrutiny of social networking sites' data protection policies around the world could force significant changes in the way such sites operate.

© Copyright 2009 Steptoe & Johnson LLP

Friday, July 24, 2009

Court fines owner of construction-worker database

The Information Commissioner's Office (ICO) has issued a press release indicating that Ian Kerr, owner of a firm trading as the Consulting Association, has been fined £5,000 by Knutsford Crown Court for breaching the Data Protection Act 1998 (DPA), and has been ordered to pay costs of £1,187. Mr Kerr had pleaded guilty to failing to notify as a data controller at Macclesfield Magistrates Court, which transferred the case for sentencing to the Crown Court (see Legal update, Owner of construction-worker database pleads guilty to data protection offences). An ICO investigation revealed that Mr Kerr had been operating a database for over 15 years containing details on 3,213 construction workers, including information about their trade union activity and employment history, which was used by over 40 construction companies to vet individuals for employment. The ICO also indicated in its press release that it intends to serve enforcement notices on 17 construction companies who were involved in using the database maintained by Mr Kerr. It said preliminary enforcement notices had been sent out, with formal enforcement action to follow shortly, subject to any representations made by the companies. Source: ICO press release, 16 July 2009.

©Legal & Commercial Publishing Limited

Friday, July 17, 2009

MySpace Wins CDA Immunity in Assault Cases

A California Court of Appeal recently upheld a lower court's ruling that the Communications Decency Act (CDA) immunized MySpace against claims stemming from "its decision not to implement reasonable, basic safety precautions with regard to protecting young children from sexual predators." In four consolidated cases, several girls aged 13 to 15 who were sexually assaulted by men they met through MySpace (the Julie Does) and their parents or guardians sued MySpace for negligence, gross negligence, and strict product liability. The appellate court held that these claims were barred by section 230(c)(1) of the CDA, which states that "[n]o provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider" and has generally been interpreted as immunizing websites against claims stemming from information posted by third parties. Finding that it was "undeniable that appellants s[ought] to hold MySpace responsible for the communications between the Julie Does and their assailants," the appellate court concluded that "section 230 immunity shields MySpace" from liability. Along with the Lori Drew ruling discussed above, the court’s dismissal of these claims against MySpace suggests that both users and providers of social networking websites may be able to skirt liability for some of the sites' more unsavory uses – at least for now. But if courts continue to throw out cases where social networking websites have been involved in incidents of stalking, bullying, or assault, the public backlash could lead Congress to narrow the scope of CDA immunity.

© Copyright 2009 Steptoe & Johnson LLP