Showing posts with label internet law. Show all posts
Showing posts with label internet law. Show all posts

Friday, August 28, 2009

Tata Sons wins case against travel portal

Tata Sons, the holding company of the Tata Group firms, has won a case at the World Intellectual Property Organisation against the travel portal, MakeMyTrip, which has been using the term 'tata' in one of its website, 'oktatabyebye.com'. Gurgaon-based mmt admin (commonly known as MakeMyTrip) has been using the domain name 'oktatabyebye.com'.
Tata Sons has contended that it is confusingly similar to its 'Tata' brand and the travel portal runner has no rights or legitimate interests to use it. In May, Tata Sons had moved the Geneva-based WIPO Arbitration and Mediation Center demanding transfer of disputed domain name. The company had argued that the site infringed the right of its registered trademark/service mark 'Tata'. The WIPO has now ordered the transfer of domain name to Tata Sons. "The impugned website incorporates the Tata's orporate name and registered trademark in full and it proves that it is identical in part and confusingly similar to its well-known brand in which the company has a statutory right," Tata Sons had said in its complaint. Replying to the charges, MakeMyTrip had said the usage of the word 'tata' as a gesture finds its mention in the origin of a place called Ta Ta Creek as far back as in the year 1860 and denied that the domain in question is confusingly similar to the trade mark 'Tata' of the complainant. The Gurgaon-based firm stated that "the impugned domain name is derived from the common parlance 'OK Ta Ta Bye Bye' since it signifies travel, journey and related activities. But in its argument at the WIPO, Tata Sons said, 'it is apparent that the sole purpose of registering the disputed domain name is to misappropriate the reputation associated with the complainant's well-known and famous trademark Tata.'
The Internet site owner has registered a separate domain name (makemytrip.com). According to Tata Sons, both the sites offer similar services. However, MakeMyTrip says both cater to separate class of persons. While makemytrip.com offers discounts and easy access to travel plans, oktatabyebye.com lets these travelers make an online records about their journey. The WIPO is a specialised agency of the United Nations for developing a balanced and accessible international system in the field of intellectual property rights. As per details available with the WIPO, Tata Sons during the case had made an effort to settle the issue with the MakeMyTrip, which refused to accept the just demands on the grounds on 'vague reasons.'
This story was sent to us by Shri Siddharth Kumar, Press Trust of India.

Wednesday, April 01, 2009

Cyber crimes record 50 percent rise in India

With India being home to the fourth highest number of internet users in the world, cyber crimes under the the Information Technology (IT) Act recorded a whopping 50 percent jump in 2007 over the previous year. What's more, the majority of offenders were under 30 years of age.


Cyber crimes have emerged as a new class of crimes, rapidly increasing due to extensive use of the internet and IT enabled services. The maximum cyber crime cases, about 46 percent, were related to incidents of cyber pornography, followed by hacking. In over 60 percent of these cases, offenders were between 18 and 30, according to the "Crime in 2007" report of the National Crime Record Bureau (NCRB).

Cyber crimes are punishable under two categories - the IT Act 2000 and the Indian Penal Code (IPC). The report says that 217 cases of cyber crime were registered under the IT Act in 2007 compared to 142 in 2006 - an increase of 50 percent. Under the IPC too, 339 cases were recorded in 2007 compared to 311 cases in 2006.

"Seventeen out of 35 mega cities have reported nearly 300 cases of cyber crimes under both categories, thereby recording an increase of 32.6 percent in a year," the report says. The report indicates that cyber crimes are no longer limited to metro cities. "Bhopal in Madhya Pradesh has reported the highest incidence of cyber crimes under IPC sections, thus accounting for 87.8 percent of the total crimes in the country," the report says.

Tuesday, April 01, 2008

EU Debates Cybercrime Law Enforcement [International]




One of the beauties, if you can call it that, of organized crime is that while the criminal organizations of the world respect none of the boundaries that we call jurisdictions and countries, and by definition, the rule of law must respect those boundaries. These criminals, whether they are the traditional mob that we all know and love or the terrorist organizations bent on the destruction of civilization as we know it, have for more than a decade or two have known about and exploited this fact.

Two groups working separately to boost Europe's defenses against online crime will present proposals this week, almost a year after most of the nation of Estonia's links to the Internet were disrupted for days or weeks. At a two-day conference starting today in Strasbourg, France, the Council of Europe will to review implementation of the international Convention on Cybercrime and discuss ways to improve international cooperation.

Cyber defense also will be on the agenda when heads of state from NATO's 26 member nations gather in Bucharest Wednesday for three days. The leaders are expected to debate new guidelines for coordinating cyber defense.

The Convention on Cybercrime, a binding treaty ratified by most members of the 47-nation Council of Europe, provides guidelines to protect computer users against hackers and Internet fraud.

The controversial agreement also covers electronic evidence used in prosecution of such offenses as child sexual exploitation, organized crime and terrorism. At this week's conference, the council will discuss guidelines to bolster the convention to improve cooperation between investigators and Internet providers, according to the council's Web site.

Participants and speakers at the conference — including police officials and representatives of technology companies such as Microsoft Corp., eBay Inc., McAfee Inc. and Symantec Inc. — also will address training.

NATO's three-day summit, which is to focus on enlarging the treaty organization and on its operations in Kosovo and Afghanistan, will include a special briefing on cyber defense, according to the treaty organization's Web site.

Some cybercrime experts are casting current Internet security challenges in terms of terrorism, while others remain focused on data loss, identity theft and fraud.

Privacy advocates, the American Civil Liberties Union and others are concerned that the Cybercrime Convention presses businesses and individuals to aid law enforcement in new ways and subjects them to surveillance that violates the U.S. Constitution.

President Bush signed the treaty in 2003 and the U.S. Senate ratified it in 2006. The convention has been ratified by 21 other nations.


Useful Links:
http://www.google.com/url?q=http://www.coe.int/cybercrime&usg=AFQjCNFRIQBFwSOvy5Gpd8lfTfoYxSix-g
http://www.google.com/url?q=http://www.nato.int/docu/update/2008/04-april/e0402b.html&usg=AFQjCNEsZbPAK5f7EORqcFz-SlqBBAKqbw

Friday, March 28, 2008

The Pirates of the Arabian? In a first, Bollywood and Hollywood versus the Pirates [India]

According to the first Bollywood-Hollywood collaborative study conducted by the US-India Business Council (USIBC) and the US Chamber's Global Intellectual Property Centre, piracy and counterfeiting is depriving the Indian entertainment industry of approximately Rs 16,240 crore every year. This is almost 40 per cent of potential annual revenue, and, according to some analysts, is only a conservative estimate of the actual losses faced by the industry.

While India's entertainment and media industry is the fastest growing among BRIC nations, it is also the smallest. Many believe that stricter control on piracy could give the industry the impetus it needs to become truly global. Aside from the loss of revenue, the report also estimates that over eight lakh people lose their jobs due to piracy each year.
Though India is badly affected by piracy, it is certainly not the only country facing this problem. The US entertainment industry, it is estimated, loses about $6 billion a year in movie revenues alone. The Motion Picture Association of America's efforts notwithstanding, attempts to regulate piracy in the US have not achieved much.
In India's case, the music industry seems to have suffered the worst, with piracy resulting in a 64 per cent loss in total potential revenues, while the movie industry loses about 31 per cent. Industry officials in both countries hope to be able to use the study to pressure the government into adopting stringent anti-piracy measures and protecting intellectual property through strict legislation.
Piracy is, of course, not a new phenomenon. Every new medium is accompanied by intellectual property theft, which is almost impossible to regulate. Copyright was violated routinely in the US in the 18th and 19th centuries. The VCR was viewed with panic in its initial years of release. And so it is with the internet. However, digital media complicates the matter because no physical medium is required to transfer and distribute content. The ease and reach of distribution is also unprecedented. Perhaps the best way to fight piracy is via the same channels through which it has prospered — new technology. A host of innovations, from region-encoded DVD players and coding preventing the copying of digital data, to one-time view DVDs, can be utilised to combat piracy. Another way to fight piracy could be to reduce the prices at which content is sold. Because of the low cost of the medium, high quality content can be sold on disks that cost almost as little as the pirated versions. Such innovative solutions could be the answer to piracy and counterfeiting that the Indian industry is searching for.

Friday, March 14, 2008

AOL pays $850m for Bebo in cash deal [International]


AOL has bought social networking site Bebo for $850 million in cash. The Time Warner-owned web services company said that the Bebo network would be a valuable place for it to sell advertising.

AOL began in the internet access business, but has expanded to offer instant messaging software AIM and ICQ. Social networking sites have been a phenomenon, with tens of millions of internet users keeping in touch and posting information about their lives on sites such as Bebo, Facebook and MySpace. Traditional business has been keen to buy into the phenomenon and instead of launching their own platforms, business giants have tended to buy into existing sites.

Bebo rival Facebook received $240 million in funding from Microsoft last October in a deal that valued the company at $15 billion. MySpace was bought by Rupert Murdoch's News Coproration in 2005 for $580 million.

Tuesday, February 26, 2008

New Net neutrality bill discourages ISP 'favoritism' [International]

Comcast, AT&T, and other network operators would be expected to refrain from "unreasonable discriminatory favoritism" of content on their pipes under a recrafted Net neutrality proposal introduced Wednesday in the U.S. House of Representatives.
"The bill contains no requirements for regulations on the Internet whatsoever," Markey said in a statement upon introducing the bill. "It does, however, suggest that the principles which have guided the Internet's development and expansion are highly worthy of retention, and it seeks to enshrine such principles in the law as guide stars for U.S. broadband policy."

Rep. Charles "Chip" Pickering (R-Miss.), who has argued against Net neutrality regulations in the past, is now co-sponsoring the rewritten measure, which is being called the Internet Freedom Preservation Act.
The modified approach is an apparent attempt to address the howls of protest from network operators, who have argued that previous Net neutrality bills in Congress amount to unnecessary Internet regulations.
The old bill decreed that broadband operators have certain duties: not blocking or degrading content, not prioritizing some applications over others, and not imposing "surcharges" for premium placement, to name a few. Violators would have been subject to penalties. A pending Senate bill, which hasn't yet seen any action in this session of Congress, takes a similar approach.
The new Markey-Pickering bill, by contrast, proposes adding four broadband policy statements to existing federal communications law. Those statements build upon a set of broadband policy principles that the Federal Communications Commission adopted years ago, including recommendations that the government allow consumers to reach the lawful content and applications of their choice and hook up whatever devices they please, provided that they don't harm the network.
Violation of those principles would not carry any penalties under the new bill, according to a Markey aide. The bill does, however, leave open the possibility of tougher rules later. One principle dictates that the government should adopt and enforce "baseline protections to guard against unreasonable discriminatory favoritism for, or degradation of, content by network operators based upon its source, ownership, or destination on the Internet."

The bill would direct the FCC to study broadband providers' current practices and whether "enforceable" rules governing Internet openness are necessary. The FCC would also be required to stage at least eight public "broadband summits" at "geographically diverse locations" around the United States to discuss the state of competition, consumer protection, and consumer choice in broadband.
The bill's introduction arrives amid a recent stepped-up focus in Washington on network management practices. The FCC is weighing whether it's "reasonable" for companies to slow down peer-to-peer traffic on their networks, as Comcast has admitted to doing in what it argues is an attempt to keep all its subscribers surfing smoothly.
The same consumer advocacy groups that support Net neutrality legislation have asked the FCC to declare that such practices aren't, in fact, "reasonable," and should be forcibly stopped.
The FCC also announced on Tuesday that it's holding a February 26 public hearing at Harvard Law School in Cambridge, Mass., to hear from experts on network management issues.
Fans of Net neutrality laws--including Amazon.com, Google, and a number of consumer advocacy groups--support Markey's latest proposal, heaping praise on the new language before the congressman had even formally introduced it. They have long argued that without strong Net neutrality principles enshrined in law, there will be nothing to stop network operators from, say, charging YouTube additional fees to be delivered to consumers faster than a rival video-sharing Web site.
The Markey bill is "an important step in ensuring the Internet remains open for consumers and innovators," said Markham Erickson, executive director of the Open Internet Coalition, whose members include major search engines, electronic retailers, librarians, and public-interest groups.
Network operators, by contrast, have long opposed Net neutrality regulations because they argue that they need the freedom to manage their networks as they see fit and that new obligations could discourage investments in building out their pipes.
Scott Cleland, the chairman of NetCompetition.org, a group whose members include all the major cable, telephone, and wireless companies, said Markey's new approach doesn't blunt those concerns. While the "letter" of the new Markey bill may not include those new regulations, he said, the "spirit" of it does, creating the same heartburn for opponents as the earlier version.

The U.S. Telecom Association, which represents large Internet service providers like AT&T and Verizon Communications, blasted the new bill. Group president Walter McCormick said it would "blindly legislate a new national broadband policy, without regard to its implications, and then require the FCC to spend the next year determining whether the Internet is being constructed, managed, and operated in conformance with this new government mandate."

Thursday, February 14, 2008

E-commerce: new ruling will affect taxability of foreign firms [India]

The issue of permanent establishment in India remains a vexed one.

In a decision which would have significant ramifications for foreign companies in general, and Computer Reservation Service (CRS) majors in particular, the Delhi Income-tax Appellate Tribunal, in a recent ruling of Galileo International Inc., has held that payment of arm’s length remuneration to the Indian agent would absolve a company from any further liability to pay tax in India. This decision is in line with the principles laid down by the Supreme Court in the Morgan Stanley case and would surely comfort foreign companies, especially those engaged in e-commerce.
CRS companies specialize in providing electronic global distribution/ticketing services to airlines, hotels, cab operators, etc., by connecting them to travel agents. The issue before the tribunal was related to the taxability of Galileo in India. While rendering this decision, the tribunal made several observations which could impact the taxability of foreign companies operating in India. Also, the tribunal’s conclusions on profit attribution would be of particular importance.
The backdrop
The concept of permanent establishment is one of the most important in international tax treaty law. Virtually all modern tax treaties use it as the key tool to establish taxing jurisdiction over a foreigner’s business activities in the host country. It could be constituted either by having a fixed place of business, or a sustained presence of employees, or even an agent in the other country. So, the focus of this article is to explain the impact of the said ruling and analyse the principles it lays down to constitute permanent establishment in India and attribute profits to it.
The broad facts are as follows: Galileo is a US-based CRS company. CRS firms receive, process, store and disseminate data about flight schedules, seat/room availability, fares, etc. Galileo entered into agreements with various airlines to provide these services. To market and distribute CRS in India, it appointed a distributor in India, who in turn entered into subscription agreements with travel agents across the country. Further, to facilitate CRS operations, computers were installed at the premises of the subscribers.
Galileo was remunerated outside India by the airlines, while it paid fees to its Indian distributor for providing marketing and communication services, at the rate of 33.3% of the booking income from the country. It is against this backdrop that the issue of Galileo’s taxability in India arose.
In most countries, including India, the legislation has not kept pace with the rules of doing trade in the borderless world of e-commerce.
For instance, even the US treasury department has no specific guidance on e-commerce trade, except for a report it issued in 1996, which discussed the emerging trade challenges posed by the Internet economy.

Monday, February 04, 2008

India to Adopt Data Privacy Rules

Two powerful players in India’s outsourcing industry are drafting a data protection law designed to quell growing privacy concerns from their offshore clients. India’s Ministry of Information Technology and the National Association of Software and Service Companies (Nasscom) in New Delhi expect the legislation to be in place early next year. It would provide legal safeguards to ensure data privacy protection in India, according to Nasscom President Kiran Karnik.

Such safeguards are required for all data leaving the European Union, which is a result of the EU Data Protection Directive and is what prompted India to act. But the regulations could prove beneficial for American companies as well.
No U.S. law currently prohibits information—such as Social Security and driver’s license numbers, employment histories, and medical records—from being shipped to or accessed from other countries, says William Bierce, attorney and president of New York City-based law practice Bierce and Kenerson. However, the number of U.S. companies required to comply with industry-specific and state laws is growing. Laws such as the Health Insurance Portability and Accountability Act (HIPAA), Gramm-Leach-Bliley Act, and California’s pending SB 1386 identity-protection law regulate what data companies can share. With offshore outsourcing deals, data protection provisions are usually written into service contracts.
Some CIOs worry whether a data protection law would have any teeth in India’s courts. But competition for offshore business should keep the courts on the straight and narrow. "Nasscom and India understand how vital a clear policy on data protection and privacy are to the trust and confidence of foreign clients," says Bierce, adding that the rules will most likely be enforced by a special appellate court established under India’s Information Technology Act of 2000.
Nonetheless, CIOs must remain diligent about Indian vendors to ensure the privacy and security needs of their companies. "India’s privacy legislation is positive, but much more important is for CIOs to ensure that their outsourcing agreements contain detailed and precise contractual specifications regarding data privacy and protections," says Hank Zupnick, senior vice president and CIO of GE Real Estate, who works with several Indian IT services companies. Specific remedies for noncompliance should be spelled out in the contract, adds Zupnick, and the contract should have legal jurisdiction in the state or province where the CIO’s company is headquartered.

Sunday, February 03, 2008

Virtual Worlds Draw Real World Lawyers [International]

Businesses setting up outposts in virtual worlds such as Second Life may find they still have plenty of real world legal minefields to navigate. Second Life is the best known of a number of virtual worlds that are attracting a lot of interest from real world businesses. That's partly because commerce is one of the fundamental building blocks of Second Life.

Residents - as well as flying from place to place and fashioning outlandish avatars - can create, buy and sell goods. And the money they make from these businesses in Linden dollars, the currency of Second Life, can be turned into a quantity of real world cash - a sum that depends on the current exchange rate.
With the six million residents spending around £1.5m per day, it's not surprising big brands want to get a foothold in this booming economy, and access to its slightly outlandish consumers.
As such, companies including ABN Amro, IBM and Nissan have set up operations already (see this Business Week Second Life photo story for more businesses).
David Naylor, partner in law firm Field Fisher Waterhouse (FFW), explained: "The thing Second Life does that differentiates it from others is it allows residents to own the intellectual property in things that they create. As a result, it's an environment that a lot of businesses have become involved in."
But the legal issues it brings into play are about as varied as the avatars and buildings you come across as you traverse the virtual landscape.
Transactions such as buying, selling and even employing staff in a virtual world may all have real world legal implications. And other issues such as gambling in virtual casinos and offering financial services through virtual banks can raise even more regulatory issues. And, of course, whenever you have people - or avatars - making money, then you have the taxman interested too.
Throw in other issues - such as competition, intellectual property exploitation and infringement - and there's little wonder the lawyers are getting interested. Speaking at a conference organised by FFW and E-Commerce Law & Policy, Naylor said: "It's going to get more popular and the legal rules are going to come to the fore as people want more certainty."
Taking just commerce as an example shows the potential complications - in Second Life business-to-business, business-to-consumer and consumer-to-consumer commerce are all possible. And transactions can happen in-world, such as buying a building, or in the real world, such as selling Second Life assets on an auction site. But what you might think of as a commodity - say a building - in Second Life, is likely to be seen in English law at least as a service. This matters because law tends to treat contracts for services differently to contracts for goods in terms of implied warranties.

And which - and whose - law is applicable is also open to debate. Naylor said, as a practical approach, European businesses should assume that unfair contract terms, consumer protection, ecommerce and distance selling obligations will apply to transactions in virtual worlds - unless European customers can be filtered out of the sales process.
Of course, complicating this further is the anonymity of the avatars - making it harder to find out who you should be taking legal action against, and the potential unwillingness of local courts to exercise extra-territorial jurisdiction.
Considering all this legal uncertainty it was only a matter of time before law firms themselves started moving into Second Life - FFW is building an office at the moment. Presumably it won't be too long before Second Life has virtual courts and prisons too.

Friday, February 01, 2008

UK High Court backs software patent [International]

Some software can be patented in the UK and the UK Intellectual Property Office (UKIPO) is wrongly rejecting applications, according to a new ruling in the High Court. The UKIPO is considering appealing against the verdict.

The patenting of software is a complex and controversial issue which has been the subject of a number of court reversals and refinements in recent years. UKIPO policy is currently at odds with that at the European Patent Office (EPO), which the High Court judge has said is "highly undesirable" and should be changed by this new decision.

Mr Justice Kitchin delivered the ruling in an appeal hearing covering six separate software patent applications. Each concerned software which had been refused a patent by the UKIPO.

The software in question was in each case a part of a wider system of computer program implemented inventions involving methods or apparatus to achieve a result, and those systems were in every other respect patentable, said a spokesman for the UKIPO. The ruling is specific to those and does not mean that all software can be patented. Applications for 'computer programs as such' will continue to be rejected; the dispute is over the meaning of that term.

UK patent law comes from the European Patent Convention (EPC), but a crucial provision governing what can and cannot qualify for a patent has been interpreted differently by the EPO and the UKIPO, formerly the Patent Office.

Article 52 of the EPC lists subject matter that is not eligible for a patent. Programs for computers are excluded; but Article 52 goes on to limit that exclusion to programs for computers 'as such'.

The reference to 'as such' has been a source of confusion for many years. The EPO and later the UK Patent Office decided to allow patent claims to a computer program if, when running on a computer, the program is capable of bringing about a technical effect which goes beyond the normal physical effects which result from the running of any program. The EPO gradually became more lenient in its interpretation of 'technical effect' and thus granted more software patents than the UK Patent Office.

It was against this background that the combined case of Aerotel and Macrossan came before the Court of Appeal. In its aftermath the UKIPO issued new guidance on patentability.

"Whilst examiners will continue to assess each case on its merits, it seems likely that few claims to programs in themselves (or programs on a carrier) will pass the third test [i.e. whether the claim falls solely within the excluded subject matter]," says UKIPO guidance on the issue.

The guidance makes reference to "few claims" surviving but appears to stop short of banning software patents. However, Mr Justice Kitchin was hearing an appeal against a UKIPO Hearing Officer's decision (12-page / 66KB PDF) which stated that since the publication of that guidance "it has been the usual practice of examiners to disallow such claims."

Mr Justice Kitchin interpreted the UKIPO's guidance as excluding all computer programs. That was an incorrect interpretation of the Aerotel/Macrossan ruling, he reasoned.

"The question I must now consider is whether the decision prohibits the patenting of all computer programs and, in particular, those which under the old approach would have been considered to make a conventional computer operate in a new way so as to deliver a relevant technical contribution," he wrote. "UKIPO has apparently concluded that it does and so has reverted to its previous practice of rejecting all computer program claims…"

"I do not detect anything in the reasoning of the Court of Appeal which suggests that all computer programs are necessarily excluded," he wrote.

Mr Justice Kitchin said that in fact he thought that the decision in that case was consistent with the EPO Board of Appeal's ruling in two IBM patent cases, bringing UK rulings further into line with those in Europe.

"It is highly undesirable that provisions of the EPC are construed differently in the EPO from the way they are construed in the national courts of a Contracting state," he said. "The new approach can be interpreted to produce a result consistent with that obtained by applying the reasoning of the Boards of Appeal in IBM/Computer Program Product… and IBM/Computer Program Product II… - decisions which, I would add, are still followed in the EPO."

In order to be successful, a software patent claim must still satisfy the tests laid out in Aerotel/Macrossan, which Mr Justice Kitchin said were themselves laid out in an earlier case involving Merrill Lynch.

That test sets out how an examiner is to judge an application. It tells examiners to: "i) properly construe the claim; ii) identify the actual contribution; iii) ask whether it falls solely within the excluded subject matter; iv) check whether the contribution is actually technical in nature."

Four of the six companies involved in the case had argued that the UKIPO's practices were dangerously at odds with European practice. The hearing officer in that case agreed but said that he was bound to follow the precedent set in Aerotel/Macrossan.

"I observe that in the area of inventions excluded from patentability, the question of EPO practice was exhaustively considered by the Court of Appeal in Aerotel," said the ruling. "They found recent developments in Board of Appeal decisions inconsistent with one another, and as a result felt it necessary to take an independent view pending any clarification of the matter by the Enlarged Board of Appeal. I am consequently obliged to follow the reasoning and guidance in the Aerotel judgment."

"Although there is no direct guidance in Aerotel as to how program claims should be treated, the requirement to consider the scope of the monopoly in step one of the test, coupled with the direct comparison between the contribution and the excluded fields, suggests that such claims should be excluded," it said.

Google and Data Privacy Day

A year after the first Data Protection Day in Europe, Google will be part of the celebration of the now-renamed Data Privacy day, aimed at educating people about their data and how to manage it.

Today is Data Privacy Day, but apparently cake isn't involved, and forget about having a paid holiday, either. We wonder if Hallmark has a card for this?
Though we may take the idea of a day of privacy awareness talked up by Google with a shot of cynicism, the concept remains sound. People have valuable personal information to control, other people would love to steal it, and still more people wish to use it for various reasons. What's an online consumer to do? Well, he could watch a privacy video, Google's third in a series. Or read a handy privacy booklet.
A trio of notables at the search advertising giant discussed Data Privacy Day 2008 (woo hoo!) at the official Google blog. Among the highlights: Google will participate in a data privacy conference at Duke University today.

Speakers from the US and abroad tackle the topic of consumer data privacy. Differences between European and US privacy laws should be a focal point; we see the difference as privacy being mandated in Europe, but largely left up to private industry in the US.
Google also backed the creation of educational materials on teen online privacy. One slide advises teens to "think about tomorrow when acting today."

"Data Privacy Day": Bush Admin Launches Internet Monitoring Initiative

Monday, January 28 has been designated "Data Privacy Day" in North America and in 27 European countries in conjunction with the International Association of Privacy Professionals. Google's privacy counsel Jane Horvath says the company is joining in an international privacy conference being held at Duke University in Durham, North Carolina.

In accordance with that appearance and Data Privacy Day, Google has added a new video to its existing series of privacy videos, plus it has developed a privacy booklet (PDF) to educate consumers and parents about online data privacy. Horvath explains:
We've also developed a privacy booklet that you can download to get an in-depth look at our privacy practices and approach, and have co-sponsored the creation of educational materials on teen online privacy for parents and educators. The goal of all these efforts is to help educate you about online data privacy so that you can make more informed choices about how you use online products and services.
Google has in the past been the subject of criticism and complaints about online privacy. And privacy is at the center of the European inquiry into the Google-DoubleClick acquisition. But Google should also be applauded for efforts to educate consumers, who generally don't understand online privacy issues.
And given that the announcement came on Data Privacy Day, it's somewhat ironic that the Bush administration is pushing a cybersecurity initiative that would greatly expand its ability to spy on American online activity and data collection. According to the Wall Street Journal:
President Bush has promised a frugal budget proposal next month, but one big-ticket item is stirring controversy: an estimated $6 billion to build a secretive system protecting U.S. communication networks from attacks by terrorists, spies and hackers . . .
Protecting private computer systems would likely require the government to install sensors on private, company networks, officials familiar with the initiative said. Amid divisiveness about other government-surveillance programs, having the government monitor Internet traffic, even in the name of national security, will be a hard sell to Congress and the public.
In addition, RFID tags and "microchips" will eventually be everywhere, allowing the government, retailers and others to closely monitor consumer behavior and activity even as this technology promises to deliver all kinds of consumer benefits.
Online privacy is becoming an increasingly critical issue for ordinary people as more daily activity shifts to the Internet and consumer behavior, health histories and financial information become subject to unprecedented levels of data collection, monitoring and potential misappropriation.

Tuesday, January 15, 2008

E-mail and Paper: Equated in Law

A recent Massachusetts Appeals Court ruling enforcing an e-mail settlement agreement of a contractual dispute is a reminder to lawyers that e-mail settlements carry the same weight as deals on paper.

The court ruled on Jan. 7 that a midtrial, e-mail settlement between Basis Technology Corp., a Cambridge, Mass.-based company that makes software for multilingual Web sites, and e-commerce giant Amazon.com Inc. was binding.

Associate Justice Mitchell J. Sikora Jr. wrote that the trial judge correctly ruled that a March 23, 2005, e-mail from Basis to Amazon.com was a "sufficiently complete and unambiguous statement as a matter of law, and that both parties intended to be bound by that communication of settlement terms." Basis Technology Corp. v. Amazon.com Inc., No. 06-P-1048 (Mass. App. Ct.).

Thomas J. Gallitano, a lawyer for Basis, said a statement in the e-mail exchange confirming that six different points in the e-mails contained the essential business terms of the settlement agreement was pivotal to the court's decision.

The Power of Paper

Amazon.com spokeswoman Patty Smith said the company wouldn't comment on the case. Basis sued Amazon in May 2003, for alleged breach of fiduciary duty, and violations of the state's consumer protection laws for not paying for work that fell outside the scope of a contract between the two companies. At the time, Amazon was creating an e-commerce system to sell products in Japan. It hired Basis for technical services.

The two companies were also linked through a stock purchase agreement that involved Amazon.com's purchase of Basis preferred stock and a seat on the private company's board of directors. The settlement required Amazon to give up its board seat and relinquish its rights as preferred shareholder. Basis Technology Corp. v. Amazon.com Inc, No. SUCV2003-02246 (Suffolk Co., Mass., Super Ct.).

After the settlement, Amazon tried to rescind a provision that called for it to convert preferred stock to common stock. Amazon.com also objected to a separate Basis request that Amazon retroactively approve Basis' preferred stock issuance to a separate company and approve a new sale of stock to the same company.

Amazon opposed the sales and filed a separate lawsuit in the Delaware Court of Chancery, because it claimed the other stock sales would reduce its ownership stake in Basis. Amazon appealed the Massachusetts case on the grounds that the judge incorrectly ruled that the e-mail exchange "created a complete and unambiguous agreement" and that Amazon had intended to be bound by the terms of the e-mail.

Friday, January 04, 2008

E-Business Patent Infringement Cases: Complex Issues to Unravel

Certainly, Google has already earned its place in history as the most-sued Internet Company. Every novel intellectual property ("IP") cause of action has been filed against the search engine giant. First, we witnessed the copyright infringement round. Google has been sued for every type of copyright infringement on thumbnails, meta-tags, keywords, etc. Concomitant with these copyright infringement lawsuits, Google was also accused of trademark violations in keywords, sponsor links, etc. Now, it is the time for the e-business patent round. Google was sued for business patent infringement and, like in most of the other IP lawsuits, it was triumphant (well, partially) this time.

A United States Court of Appeals recently held that Google is not liable for patent infringement when it uses two methods that link online records and provide users with relevant web pages. The plaintiff, Hyperphrase Technologies, LLC, and Hyperphrase, Inc. ("Hyperphrase"), held two business patents related to some systems and methods that linked online records. The technical process used by these systems and methods is similar to the one used by Google through its "AdSense" and "AutoLink" methods. "AdSense" is an advertising method used by Google that combines the advertiser's content with contextually related websites. AutoLink is an online application incorporated into people's computer browser that that helps Google identify relevant web addresses and information according to some ‘string of characters' that they call tokens. Hyperphrase claimed that Google violated its online linking and patented methods through the use of "Autolink" and "AdSense."

"We're very pleased that the Federal Circuit agreed that AdSense does not infringe any of Hyperphrase's patents. We continue to believe the remaining claims in the lawsuit are without merit, and will vigorously defend against those claims," Michael Kwun, Google's managing counsel for litigation, recently said after the US Court of Appeals held (on December 26, 2007) that Google's ‘AdSense' did not infringe on Hyperphrase's patent. Yet, the case was remanded as to Google's business patent infringement with respect to the use of "Autolink" system.

This intriguing case so far has two significant juridical teachings. First, we learned that business patents and its electronic use are slowly but steadily becoming the object of intellectual property litigation. For the time being, this litigation is centered at a domestic level; but, the legal community must be vigilant of how transnational litigation and jurisprudence on e-business patents evolves. Second, we also learned that business patents, especially e-business patents, create extremely complex litigation cases. E-business patent infringement cases involve highly technical computer methods and systems (some related to mathematical equations) and sharp legal and semantic analysis. In other words, computer/business science and sophisticated legal reasoning merge when dealing with a business patent case.

Thursday, December 13, 2007

Five things one should know about Web Sites [General]

1. Who Is The Person Behind the Web Site?
For top level generic domain names such as .com, .net and .org, go to www.internic.net/whois.html or similar web sites like www.betterwhois.com and enter the domain name for the web site into their search/whois functions. They may not give you the name of the person or company who registered the domain name, but they will likely give you the name of the local registrar. If they do, go to the web site of the local registrar and enter the domain name in question into the local registrar's search function. This should produce the name of the person or company who registered the domain name for the web site. For country-specific top level domains (for example, .ca), use Google or another search engine to identify a registrar in the applicable country (for example, to find a registrar in Canada enter the following key words: "Canada", "domain name" and "registrar") and then use the local registrar's search/whois function.
2. Content Can Cause Problems

If the content you are incorporating into your web site is not your original content, you almost always need to get permission to use it. If you use any portion of a popular song (even five seconds) on your web site without getting the appropriate rights, you could be infringing one or more person's rights in the song. Not all clip art is released into the world on the same terms and conditions. For example, some clip art providers prohibit the use of their images for commercial purposes.
3. Linking

Typically, a text-based link to another party's web site which opens the other web site in a new window is not problematic. Still, you should check the terms and conditions of the web site to which you wish to link to make sure that they do not prohibit or restrict links.
Additionally, if you place links to web sites which you do not control on your web site, you should make sure that the terms and conditions for your web site make it clear that you are not responsible for anything related to those web sites.
4. Hosting Agreements Come in Different Shapes and Sizes

At its most basic a hosting agreement requires the service provider to provid server or co-location space and a connection to a network (typically, the Internet). From there, there are many types of services which may also be purchased such as back-ups, on-site assistance, server management or application management. The nature of the materials hosted (for example, do they need to be highly available or could they be down a few hours a month) and the volume of the materials to be hosted also vary from situation to situation.
Basic hosting services for a small web site such as one which provides information about an upcoming family reunion can be acquired for less than $20.00 per month. The hosting agreement for such services will typically be short, non-negotiable and very biased in favour of the service provider. Hosting services for a small business' web site (when the small business does not depend on the web site for any significant portion of its business) will be somewhat more involved, and the hosting agreement should be more detailed and somewhat less biased than a basic hosting agreement. For example, it may include some service level commitments and warranties from the service provider. Hosting agreements for high traffic, high volume, web-based businesses and other web sites which must be available at least 99.999% of the time tend to be long, detailed and aggressively negotiated.

5. Terms and Conditions - One Size Does Not Fit All

Although there are elements which are common to most sets of terms and conditions for web sites, there is no single set of terms and conditions which is appropriate for every web site. There are a number of factors which affect the contents of these documents including: (i) the types of content forming part of the web site; (ii) the ways in which visitors to the web site are encouraged to interact with it; (iii) the target audience for the web site; and (iv) the location of the server on which the web site resides.

The incompatibility problem - General Public License; New Release

The General Public License version 3 (GPLv3), released by the Free Software Foundation on June 29, 2007, is the latest version of the most widely used "open source" license. It is based on the open source movement which is predicated on the "free" sharing of source code. Prominent free software programs licensed under the General Public License include the Linux kernel and the GNU Compiler Collection (GCC).

While the GPLv3 (like General Public License version 2 (GPLv2)) is a license which requires a person who conveys a covered work (either the original program subject to GPLv3 or a work based on the program) to also convey the machine-readable corresponding source code under GPLv3, the GPLv3 differs from the GPLv2 in a number of ways. The GPLv3 includes an express rather than an implied patent license in connection with the open source code being licensed. Additionally, the GPLv3 includes amendments designed to counter certain practices. The first practice is "tivoization", designing a product so that it fails if the user makes any changes to the open source code included in it. Section 11 of the GPLv3 is intended to counter the practice of using "discriminatory patent licenses". A patent license is "discriminatory" if it prohibits the exercise of, or is conditioned upon the non-exercise of, one or more of the rights granted under GPLv3.

It should also be noted that since the GPLv2 contains a clause which requires programs which incorporate code licensed under the GPLv2 to be licensed under the GPLv2, and the GPLv3 does the same, the licenses are incompatible. It is not possible to combine code licensed under the GPLv2 with code licensed under the GPLv3 within a single program.

Friday, November 30, 2007

Change your passwords for Computer Security Day [Data Security]

Most people keep the same password for too long and use it for too many purposes. So if you do one thing to mark Computer Security Day, change your passwords. If you do two things, change your passwords and vacuum your computer.

These are among the tips from the US organisers of the global event, including Security Awareness Inc. and the Information Systems Audit and Control Association. Now in its ninth year, Computer Security Day exists to remind people to protect their computers and information.

The day is on 30th November each year and the organisers list 53 ways that offices can participate.

Suggestions include:

  • Check for viruses
  • Protect against static electricity
  • Vacuum your computer and the immediate area
  • Back-up your data
  • Post 'No drinking' and 'No smoking' signs in computer areas
  • Hold a discussion of ethics with computer users

Passwords-schmasswords

Almost two-thirds of people never change their passwords, according to a survey of 1,800 adults reported by the Department of Trade and Industry in June. One in five people said they use the same password for non-banking websites as well as their online bank. And over one-third recorded their password or security information by either writing it down or storing it somewhere on their computer.

Such behaviour is asking for trouble, according to US security guru Bruce Schneier.

"People should change their online access passwords regularly," Schneier. "The risk is that a password has been compromised, and changing your password regains security."

Microsoft suggests that a password that is shorter than eight characters should be considered "only good for a week or so," while a password that is 14 characters or longer (provided it follows Microsoft's rules and tips for passwords) can be good for several years. Others suggest that you can safely keep a password for 60–90 days as a general rule of thumb.

The HMRC incident has prompted many individuals to take protective steps. HMRC wrote to the families potentially affected by the data loss. Its letter addressed online banking risks and stated: "If your password uses any of your personal data, for example your child's name or date of birth, you may also wish to consider changing any passwords you use."

According to APACS, the UK payments association, 10% of Child Benefit recipients have since changed their online banking passwords. Six percent changed their PINs.

How to choose a new password

Andrew Moloney, a director at security firm RSA who specialises in the financial services market, offers the following tips:

  • "If your password is linked to personal data – e.g. a date of birth or child’s name – it should be changed.
  • The longer a password, the more difficult it is to crack. Thus, make yours of a decent length, say 10 to 16 characters if possible.
  • Replace words for numbers e.g. For = 4, to/too = 2, add punctuation like exclamation marks and change capitalisation
  • Consider using a phrase that includes both numbers and words and use the first letters/numbers from that. An example would be “On the 12 days of Christmas my true love gave to me = Ot12docmtlgtm”. This has a great combination of being hard to guess but easy to remember. That's the ideal scenario."

Wednesday, November 21, 2007

Harnessing User Content [Legal Technology]

Marketers are tapping into the user-created content phenomenon and running UGC contests and other promotions online, sometimes promising to run the winning video as a television commercial. Marketers are engaging in online promotions within the virtual communities of social networking and massively multiplayer online games (MMOGs). In addition, online promotions frequently encourage certain online user activities, such as recommending products to friends on their blogs and sending e-mails about a product or service to their friends, sometimes by rewarding such activities with cash, coupons, prizes or sweepstakes entries.

UGC presents a host of potential legal problems, such as third-party intellectual property infringement (and in recent years, we have seen a great deal of litigation generated in this area). Sponsors and promoters that engage users in their promotions run the risk that user conduct and content will be attributable to them and that they will be deemed responsible for what the users say and do in connection with the promotion. In addition, the use of Web sites and Internet services are subject to the terms and conditions of each provider, and promotions must follow the rules of the applicable venues.

The combination of the ease in which digital media tools enable content creation and the ability to publish and distribute that content via the Internet has led to a proliferation of UGC. Social networking sites, MMOGs, blogs and UGC sites, such as YouTube, Facebook and MySpace, are immensely popular. Television and cable networks are developing vibrant online sites to create a two screen experience; offering viewers the ability to interact, participate and create via the online offering. For example, on www.current.com, the online offering of Al Gore's youth-oriented cable net Current TV, users can connect with each other, contribute video programming that has the potential to migrate to the cable network and even create commercials for the network's advertisers. Knowing that engaging consumers is more valuable than bombarding them with banner and pop-up ads, online marketers are rushing to get Internet users to directly participate with their brands and are involving bloggers, UGC and social networking sites and other virtual communities as a way to do so. In the MMOG Second Life, for example, dozens of real-life brands have established themselves within the game environment, and ad insertion functionality and product integration are being added to many online games.

An initial area of concern for Web site providers, promotions operators and sponsors with respect to UGC and user participation is the distinct possibility that the user will infringe third-party intellectual property or personal rights. However, there are two laws that provide the possibility that the Web site that hosts such content is not liable for such content.

Friday, October 12, 2007

ASIA Domain Name Registrations Open October 9, 2007

DotAsia, the not-for-profit organisation that has been delegated the responsibility for operating the .Asia top-level domain registry, will open its first sunrise registration period on October 9, 2007 for governmental reserved names, and registered trademarks and service marks:

  • Governments or relevant bodies may “activate” (i.e. register) domains from the Reserved Names list compiled in Pre-Sunrise.
  • Marks must be applied for before March 16, 2004 (SR2a Cut-Off Date)
  • Marks must be issued and valid upon domain registration application
  • Applicant must have demonstrable usage of Mark (in the class if applicable) registered
    Registrant must be owner, co-owner or assignee of Mark
  • Documentary evidence is not mandatorily required, but required upon request
Read more in their "Introduction to the .ASIA Sunrise (pdf)"and "Launch Schedule & Summary (pdf)."

Tuesday, October 09, 2007

Google gets into 'data privacy' hot water

Google's proposed purchase of online ad giant DoubleClick would lead to "a massive violation of data privacy rights", says a German data protection expert.

As reported by web legal experts Out-law.com, the Data Protection Commissioner of the German state of Shleswig-Holstein Thilo Weichert has sent his views to Europe's Competition Commissioner Neelie Kroes saying that the $3.1 billion merger would result in the "fundamental provisions of the European Data Protection Directive [being] violated."

Weichert's views rely on the assumption "that in the event of a takeover of DoubleClick the databases of that company will be integrated into those of Google" he said.

"Such an approach contradicts fundamental data privacy principles of the European Union: limited specific use, transparency, the right to object, the protection of sensitive data and the right to having data deleted," he wrote in the letter.