Friday, May 23, 2014

US: Protection of Personal Information

HHS Announces Record HIPAA Settlement


New York-Presbyterian Hospital (NYP) and Columbia University have agreed to pay a combined $4.8 million – the largest HIPAA settlement ever involving a single incident – to settle charges that they violated the HIPAA Privacy and Security Rules by accidentally making the electronic protected health information of their patients accessible to Internet search engines.  The Department of Health and Human Services’ Office for Civil Rights (OCR) launched its investigations after the entities – which operate a shared data network and firewall – notified it of the breach.  As part of the settlement, NYP will pay $3.3 million, and Columbia will pay $1.5 million. The entities also agreed to undertake risk analyses, develop risk management plans, revise their existing policies and procedures, and provide training on privacy and security awareness. 

(c) Steptoe & Johnson LLP

Wednesday, May 21, 2014

EU: Search engine results to be removed where they affect privacy rights

ECJ confirms right to have search engine results removed where they affect privacy rights
The ECJ has ruled on three questions concerning the interpretation of the Data Protection Directive (1995/46/EC) with regard to the data processing activities of search engine providers, their status as data controllers and the existence and scope of a right to be forgotten, in a reference from a Spanish court. The proceedings had been brought by a Spanish citizen, who had asked that Google remove from the list of search results based on his name links to two announcements in a Spanish newspaper from 1998. The announcements concerned a real-estate auction connected with attachment proceedings prompted by the applicant's social security debts. The ECJ held that a search engine provider is the data controller in respect of the locating, indexing, storing and making available of information accessible on the internet, and that the applicant has a right to rectification, erasure or blocking of that information, and a right to object to the processing of the information in certain circumstances.
The ECJ made it clear that while the search engine's commercial interests in processing the information will not, as a rule, override the data subject's rights to privacy and data protection, a balancing of the data subject's fundamental rights and the interests of other internet users in accessing that information must be carried out. The interest in the continued accessibility of personal information may override the data subject's interest in cases where the data subject plays a prominent role in public life and the accessibility of the information is in the public interest. The ECJ further clarified that the data subject's right to request removal of the relevant links may also apply if the information is true and where its original publication was lawful. This is particularly the case where the information has since become inadequate, irrelevant or excessive.

The ECJ's decision has sent shock waves not only through the online industry but also through the loose collection of groups concerned with the protection of digital rights. While the strengthening of the EU's right to apply its data protection framework to non-EU data controllers in certain circumstances is broadly welcomed (within the EU, if not in the US, where many of the largest, most popular search engines are based), the importance that the court has afforded to the data subject's right to privacy, compared to the right of individuals to access to information, has led to accusations that the decision legitimises individual reputation management, the falsification of historical records and ultimately, censorship. (Google Spain SL and Google Inc. v Agencia Española de Protección de Datos (AEPD) and Mario Costeja González, Case C-131/12, 13 May 2014.)
© 2014 Thomson Reuters. All rights reserved

Friday, January 24, 2014

Protection of Personal Information

Do you think behavioural data collected by third party cookies should be considered personal data, even where it is not connected to information directly identifying an individual?

Thursday, September 19, 2013

Like = freedom of Speech

“Liking” something on Facebook is a form of speech protected by the First Amendment, a federal appeals court ruled Wednesday, reviving a closely watched case over the extent to which the Constitution shields what we do online

Friday, September 06, 2013

What Happens In Social Media Stays In Social Media

Nevada has joined the club of states that bar employers from requiring or requesting that current or prospective employees provide access to their personal social media accounts.  Twelve other states (Arkansas, California, Colorado, Delaware, Illinois, Maryland, Michigan, New Mexico, Oregon, Utah, Washington, and, most recently, New Jersey) have placed similar restrictions on employers.  Comparable legislation is pending in at least 35 other states.  Importantly, Nevada’s A.B. 181 does not affect an employer’s right to comply with “any rule of a self-regulatory organization.”  Securities firms affected by rules promulgated by the Financial Industry Regulatory Authority (FINRA) have sought exemptions from social media laws to ensure that they can comply with FINRA’S rules, which may affect social media accounts.  The Nevada law takes effect on October 1, 2013. 

Monday, June 03, 2013

3D mark as a Trade Mark?

TM: You can register a '3D mark' as trade mark, e.g. Coke's 500ml bottle. However, you must be able to demonstrate that its destintive character departed significantly from the norms and customs of the sector. A distinctive character is imperative.For more information contact Gerrie van Gaalen

Friday, May 24, 2013

High Court rules Marks & Spencer's use of advertising keywords infringed Interflora's trade marks


The High Court has applied the ECJ's ruling on various questions it referred in proceedings brought by Interflora against Marks & Spencer (M&S) in relation to M&S's use of the word INTERFLORA as an advertising keyword leading Google internet search engine users to advertisements for M&S flower delivery services. The ECJ said that "double-identity" infringement would only be made out if there is an adverse effect on one of the functions of the trade mark. Arnold J found that M&S had infringed the trade mark under Article 5(1)(a) of the Trade Marks Directive (89/104/EEC, now replaced by consolidated Directive 2008/95/EC) and Article 9(1)(a) of the Community Trade Mark (CTM) Regulation (40/94/EEC, now replaced by 207/2009/EC) because a significant proportion of consumers who searched for "interflora", and then clicked on M&S's advertisements displayed in response to those searches, were wrongly led to believe that M&S's flower delivery service was part of the Interflora network, so that the mark's origin function was adversely affected. The judgment includes a detailed analysis of ECJ case law and establishes a number of interesting points, including clarifying the meaning of the "investment function" of a trade mark, substantial interference with which the ECJ found could constitute infringement of the mark. The decision that M&S had infringed Article 5(1)(a) and Article 9(1)(a) will be welcomed by Interflora. However, it is not clear to what extent other trade mark owners will be able to draw comfort from the decision, since it turned on its facts, in particular the fact that the Interflora network included numerous and diverse separate undertakings. (Interflora Inc and another v Marks and Spencer plc and another [2013] EWHC 1291 (Ch), 21 May 2013.)

© Practical Law Publishing Limited

Thursday, May 09, 2013

IP Symbols - shortcut


IP: Symbol short cuts for IP
Alt + 0153..... ™... trademark symbol
Alt + 0169.... ©.... copyright symbol
Alt + 0174..... ®....registered ­ trademark symbol
If you want to know the meaning of each of the above symbols and when to use them, then call Gerrie

Monday, April 22, 2013

Internet Browsing: copyright infringement or not with reference to caching

what do you think - should the mere viewing of copyright material on the internet amount to copyright infringement, taking into consideration the caching function on your browser?

Friday, July 27, 2012

Bank's "Commercially Unreasonable" Security Practices to Blame for Cyber Theft


The First Circuit earlier this month held that a bank could be liable for the theft of nearly $600,000 from a company’s bank account because the bank’s online security systems were not “commercially reasonable” under the Uniform Commercial Code.  This ruling, in Patco Construction Company v. People’s United Bank, indicates that banks cannot entirely shift risk to their customers through contractual provisions, and that courts will scrutinize a bank’s security practices to determine whether they are adequate


© Copyright 2012 Steptoe & Johnson LLP

Friday, May 25, 2012

French Court Narrows the Scope of Workplace Privacy


The Bordeaux Court of Appeals in France has ruled, in Pierre B. v. Epsilon Composite, that a company was justified in reviewing emails sent by an employee using a workplace computer, since the employee had not identified the messages as personal.  The employer was also justified in firing the employee when it discovered that he had emailed confidential work files from his work email to his personal email account, in violation of company rules and a confidentiality agreement he had signed.   As we previously reported, the Cassation Court’s 2001 decision in Nikon France SA v. Frédéric O. established that employees have a right to privacy in personal messages transmitted using a workplace computer, even where an employer has banned non-business use of the computer.  But, since then, French courts have refined the Nikon decision in ways that narrow employees’ privacy rights in the workplace in favor of employers.  This decision continues that trend.


© Copyright 2012 Steptoe & Johnson LLP

Thursday, April 05, 2012

Launch of the ICC Cookie Guide

For all the website developers out there, see the useful cookie guide just released by the International Chamber of Commerce

Friday, February 24, 2012

FCC - landline robocalls to require prior written consent

The Federal Communication Commission (FCC) approved - on 15 February 2012 - changes to the Rules and Regulations Implementing the Telephone Consumer Protection Act of 1991 (TCPA) - which will require telemarketers to obtain 'prior express written consent' from individuals before placing an autodialed or prerecorded marketing call ('robocall') to residential landline phones.

Threat from Loss of Personal Data Insufficient to Establish Standing

The U.S. District Court for the Eastern District of California has dismissed a class action lawsuit arising out of the loss of server drives containing the personal and medical information of over 800,000 California residents. The plaintiffs in Whitaker v. Health Net of California, Inc., alleged that they were likely to suffer future harm as a result of the loss of their information. The court, however, found the threat of future harm alleged by the plaintiffs to be “wholly conjectural and hypothetical,” and therefore held that the plaintiffs’ allegations were insufficient to establish standing under Article III of the Constitution.

© Copyright 2012 Steptoe & Johnson LLP

Friday, December 02, 2011

IP Address is protected personal data

The Court of Justice of the European Union (CJEU) clarified that IP addresses are 'protected personal data', on 24 November 2011, in Scarlet v SABAM (Case C-70/10), while ruling that internet service providers (ISPs) cannot be legally compelled to monitor the online activities of their customers.

Thursday, November 24, 2011

Jurisdiction: Home Is Where The Money Is

Following a ruling last month by the European Court of Justice in eDate Advertising GmbH v. X and Olivier Martinez, Robert Martinez v. MGN Limited, plaintiffs who want to sue online publishers in Europe for damaging content are now in a better position than those going after offline media. In both the offline and online contexts, a plaintiff may sue publishers in any and all of the EU member states where the publication was distributed, but can recover only for the damage caused in the jurisdiction where suit is brought. Alternatively, plaintiffs in either context may sue in the state where the publisher is established, and can recover for all the damage caused by the publication in any jurisdiction. As a result of the ECJ’s ruling, plaintiffs in cases involving online content now have a third option: suing in the place where the plaintiff has her “centre of interests,” and recovering for all the damage caused anywhere. The plaintiff’s “centre of interests” may include not only where the plaintiff resides but also any other place to which the plaintiff has “a particularly close link,” such as where she pursues professional activity. This decision makes suing online publishers more convenient for plaintiffs, and thus may lead to more defamation suits against website operators.

© Copyright 2011 Steptoe & Johnson LLP

Privacy Law is No Excuse for Spoliation of Evidence...!!

European Union requirements to delete personal data once it is “no longer necessary” for business purposes do not excuse a company from U.S. law regarding spoliation of evidence. A decision last month by the U.S. District Court for the Northern District of California in IO Group Inc., et al. v. GLBT Ltd., et al., rejected a British website operator’s argument that its intentional destruction of emails relevant to copyright infringement litigation could not be considered spoliation of evidence because it was done per the requirements of the U.K. Data Protection Act 1998. This decision highlights the fact that U.S. courts often will not excuse noncompliance with U.S. law on grounds that complying would result in a violation of foreign law – a conundrum that is increasingly faced by companies that have data stored abroad but are subject to U.S. jurisdiction.

© Copyright 2011 Steptoe & Johnson LLP



Friday, July 22, 2011

eBay Can Be Liable for Trademark Infringements

The European Court of Justice (ECJ) has ruled that eBay can be held liable for the offer for sale by third parties of trademark-infringing goods on its site if it took steps to actively assist those third parties or if it knew or should have known of the infringing activity and did nothing. It also held that eBay could be liable for its own use of trademarks as keyword search terms to generate ads on search engines, if those ads do not allow an Internet user to easily determine whether the goods referred to in the ads are offered by the mark owner or someone else. And perhaps most importantly, the court held that national courts can issue injunctions requiring an online marketplace like eBay to alter their sites to make it easier to identify sellers in order to deter future infringements and give trademark owners an effective remedy. Though the courts of each member state will have to determine how to apply these principles in particular cases, it seems almost certain that Internet marketplaces may be exposed to significant potential liability unless they alter their approach to policing trademark infringements.

© Copyright 2011 Steptoe & Johnson LLP

Friday, April 29, 2011

Friends Don't Let Friends Eat Spam

US Law: Ask your average teenager if Facebook messages or wall postings are emails, and you will probably get a fair amount of eye-rolling. But according to a recent federal district court decision in Facebook v. MaxBounty, such communications may indeed be considered “electronic mail messages” within the meaning of the CAN-SPAM Act. The court’s interpretation of what constitutes email may mean that other forms of Internet advertisements directed at particular individuals may be subject to the Act.

© Copyright 2011 Steptoe & Johnson LLP


Friday, March 04, 2011

HHS Gets Serious About Privacy

The Department of Health and Human Services is getting serious about its privacy enforcement responsibilities, announcing that it has imposed big penalties on two medical centers that violated the Health Insurance Portability and Accountability Act (HIPAA). HHS imposed a fine of $4.3 million on Cignet Health Center for ignoring the requests of patients who wanted access to their medical records and then failing to cooperate with an investigation into the incident by HHS's Office of Civil Rights. And Mass General agreed to pay $1,000,000 to settle charges that it had violated the HIPAA Privacy Rule when an employee accidentally left on the subway documents containing protected health information of 192 patients.

© Copyright 2011 Steptoe & Johnson LLP