Monday, January 08, 2007

Media and Libel Laws - patchwork can be dangerous [International]

As sports fans around the globe became transfixed last summer by the World Cup, a U.K. libel case featuring Ashley Cole, a top British footballer, captured the attention of many of the world's media lawyers. Cole reached a settlement in a libel suit against two British publications that never actually mentioned him by name: Cole's attorneys argued that readers could easily surmise his identity from Web sites that picked up the story and provided further detail.

Meanwhile, in late August, The New York Times finally came to grips with the conflicting patchwork of laws that allow Internet publication in one country, but may raise liability in others. In reporting about the arrest of Islamic terrorists in London, the Times added facts that, under the United Kingdom's Contempt of Court Act, are considered prejudicial to the fair-trial rights of the accused. In the face of violations of British law, the Times' solution was to prevent U.K.-based Internet addresses from accessing the story. The need for this work-around underscores the deepest philosophical infirmity in U.K. and E.U. law (and, indeed, the laws of most other jurisdictions worldwide): Free press is just not as valued as a foundation of democracy as it is here. While the U.S. First Amendment allows only narrowly tailored restrictions on such speech, in the United Kingdom the public's right to know is often first on the chopping block.

The practical application of this distinction is obvious: In the era when electronic communication can circle the globe instantly, every company that communicates globally can be liable under defamation and privacy law -- and just as liable in the United Kingdom, or in India, or China, as they are in the United States.

That's a daunting prospect for U.S. lawyers representing media companies that maintain Web sites with the potential to reach thousands of readers worldwide. Indeed, those who do business globally might find themselves subject to libel or privacy claims in diverse corners of the world for material on their Web sites, blogs and message boards, or for press materials distributed via e-mail, the Web or commercial newswires.

FAIRNESS AND OTHER FACTORS

What is a lawyer to do when advising as to Web site content and other electronic communications? What is a blogger to do when deciding whether or not to break a story? Lessons drawn from international newsgathering offer a useful guide to operating in the global media environment. Consider fairness, for example. Fairness not only means presenting both sides, but also giving your subject an adequate opportunity to respond. In 2003, The London Daily Telegraph was successfully sued in Britain for publishing an article alleging that a British member of Parliament was a paid agent of Saddam Hussein. Even though the reporter had telephoned the politician the evening before the story went to print, the court ruled that adequate opportunity for comment had not been given.

Also consider whether the story in question is serving the public interest. This is the single most consistent element that protects journalists and publishers around the world in libel cases. What is of interest to the public is not the same thing as what is in the public interest -- which may be news to many a celebrity gossip blogger.

And remember cultural distinctions: A simple word can make the difference between accurate reporting and slander. Seemingly inoffensive language in one country can be a very expensive mistake in another. For example to be "fired" in the United States is not in itself defamatory, but in France or Japan, this word could land you in court. If someone loses his or her job for economic reasons in Japan, where being fired is considered shameful, that person is reported as being "made redundant." Similarly, it's almost impossible to be fired in France, so when that word is used, it is assumed that the subject was in violation of duty.

Finally, in fairness to our global cousins in the United Kingdom, the rest of the European Union and other jurisdictions: There is some value to the higher standards of reporting required. Although it is sacrilegious to say it in the United States, the greatest fear of all media lawyers is to run across that one overworked or burnt-out reporter or editor who believes that because the "public figure" and "actual malice" standards are next to impossible to surmount, careful reporting and clear writing are optional. By requiring a higher degree of care and accuracy, clarity and fairness rise commensurately.

It is clear that the days when only the largest global media companies had to worry about international libel and privacy issues are long gone. Internet publishing makes understanding international libel laws every lawyer's problem. It is often said that there is a reason why our First Amendment is first: that the right to speak freely is the right from which all other freedoms flow. But while this may be a cornerstone of American libel and privacy law, U.S. lawyers cannot let it lull us into a false sense of security when representing clients whose Internet posts are read not just in their hometown, but on computers across the globe.

Numly - for Digital Works [International]

Numly is a concept for tracking the use of digital works. Says the Numly website:
"Numly assigns Numly Numbers (Electronic Serial Numbers/ESNs) for all things digital. These unique identifiers enable rights statements to be associated with digital content as well as third-party, non-repudiation measures for proof of copyright via real-time verifications.

Numly Numbers are simple to generate and serve as an electronic timestamp of submission. They also allow you to track who is viewing your content and when it is accessed, monitor ratings, and can be used as permalinks ie. http://go.numly.com/27200-060121-189140-97! Another cool outcome of Numly is that your copyrighted content is consolidated no matter where you publish your work. We provide authors and artists with a dynamic Numly Page (or N-Page) that tracks all digital works".

Friday, January 05, 2007

Bluetooth Technology: Patent Suit [US]

US Research Body Says Mobile Phone Makers Using Bluetooth Technology Without Paying Royalties

A US research institute has sued Nokia, Samsung Electronics and Matsushita-owned Panasonic for violating a patent for Bluetooth technology, potentially putting the free wireless standard at risk. The Washington Research Foundation, which markets technology from the University of Washington, is seeking damages from the three mobile-phone makers for using a radio frequency receiver technology without paying royalties, according to court papers obtained by Reuters on Wednesday.

A University of Washington scientist Edwin Suominen was awarded a patent in 1999 for “simplified high frequency broadband tuner and tuning method”. Bluetooth was invented as a wire replacement by Ericsson engineer Jaap Haartsen in the mid 1990s and developed by engineers at Ericsson and four other companies which made it available at no cost through the Bluetooth Special Interest Group (SIG). Haartsen told Reuters that others had previously tried unsuccessfully to claim part of the Bluetooth technology. “We’ll have to see how this one pans out,” he said before looking at the claim in detail.

Nokia declined to comment. “We are currently studying the claims,” said spokeswoman Eija-Riitta Huovinen. Samsung and Panasonic were not immediately available to comment.

Bluetooth was given away by Ericsson and others to create a global wireless standard to connect mobile phones, laptops, headsets and other electronic gadgets wirelessly. Since the first standard was set in 1998 it has become hugely popular and is now put in hundreds of millions of devices every year. “As they say, ‘Where there is a hit, there is a writ’,” said analyst Neil Mawston at market research group Strategy Analytics.

The claim appears to restrict itself to Bluetooth devices sold or used in the United States, which means any ruling will impact around 15 to 20% of total global Bluetooth mobile phone and headset sales in the near-term, Mawston said.

“The mobile Bluetooth market in the US is relatively immature and it is not yet as important to vendors as, say, western Europe with 30 to 40% of total,” he said.

But Ben Wood, a mobile telecoms consultant at CCS Insight, said the implications for the standard could be more serious if the foundation’s claim is successful. “A standard which everyone assumes to be royalty free is now at risk of becoming a chargeable element inside mobile phones and other devices,” he said.

Although the complaint, filed in the United States western district court of Washington state at Seattle, was filed against the three companies, it targets products containing Bluetooth chips from British chip maker CSR, which has a world market share of more than 50%. A spokesman for CSR, which was not sued by the research group as it does not sell the chips directly in the United States, said the firm was looking closely at the legal documents and declined to comment further.

Shares in the Cambridge-based firm lost as much as 6.6% before clawing back some of the early losses. They were down 3.6% at 635 pence Wednesday, underperforming a 0.2% dip in the European technology index. Nokia shares were off 0.7%.

The suit set apart CSR rival USbased Broadcom, which has acquired a licence to use the radio technology, the Washington Research Foundation said. The foundation said it had informed the three mobile phone makers about Broadcom’s licence, and that they could have bought their chips from Broadcom and avoided a legal battle. “The document is positive news for Broadcom, but negative for CSR. These two are the main global players in the Bluetooth chip market,” Mawston said.

Bluetooth marketing director Anders Edlund said he could not yet comment on the validity of the court case. — Reuters

Source : Economic Times, January 4, 2007


Tuesday, January 02, 2007

The eye-test for novelty of designs [India]

The eye-test for novelty of designs

In a recent appeal case, Gopal Glass Works Ltd v AC of Patents & Designs Ors 2006 (33) PTC 434 (cal), Kolkata High Court examined the grounds for cancelling a registered design.

According to Section 19 of the Indian Designs Act (amended) 2000, "prior publication" anywhere in the world and prior registration in India are valid grounds for cancelling a registered design. In Gopal, the High Court provided further insights into what constitutes a "prior publication" as well as the test of novelty in general.

Gopal Glass Works held a design registration for embossed glasswork. Leveraging on the registered design, Gopal managed to obtain an injunction against an alleged imitator named IAG.

The aggrieved party (the respondent), in retaliation, applied for cancellation of the design under Section 19(2). The respondent relied on a prior design registered in the UK in 1992, by a German company. The Assistant Controller (AC), relying on Caron International's Design application (1981) RPC 179 p184, held that novelty alone is not sufficient; there must be sufficient originality. Based on the similarity of the two designs, the AC allowed cancellation on grounds of "prior publication". Gopal appealed.

The case focused on what constitutes a "prior publication". The UK design was similar to that of the appellants design but it was not the same. The design in question was never embossed on glass before Gopal did so. Should a prior design which was never embossed on glass be accepted as a novelty-destroying publication for a glasswork article?

The decision

The High Court, while overturning the cancellation, re-affirmed the cardinal rule for evaluating novelty of designs: the so-called eye-test. The Court held that when the novelty of an article is tested against a prior publication, the primary factor is the visual effect and appeal of the article. If the prior publication does not share the visual effect and appeal of the article, the publication does not destroy novelty.

The UK registered design, although similar, lacks the visual effect and appeal of the design embossed on glass. Accordingly, the UK design is not a valid "prior publication" (Rosedale Associated Manufacturers Ltd v Airfix Ltd (1957) RPC 239 was cited).

The High Court reinforced the "visual effect" doctrine established by Rosedale. It also clarified the test of novelty and set out that a mere registration is not sufficient to destroy novelty.

Source : http://www.managingip.com/

Friday, December 29, 2006

First Line of Defense Against Data Security Breaches: Employees [International]

As headlines continue to report data security breaches at an alarming rate, discussion often focuses on the need for enhanced technical controls, such as two-factor authentication and encryption, to protect sensitive, personally identifiable information. The role of the company employee, both as the cause of, and the first line of defense against, security breaches is often lost in the analysis. Yet developing law is increasingly requiring administrative or procedural controls, particularly those directed at employees, as a component of a legally compliant security program.

Employees can be the source of major threats to a company's data security. They need not be bad actors in order to compromise their company's data security. Often it is the innocent actions of employees (e.g., losing a laptop with key data unprotected or succumbing to a third party's social engineering techniques) that leave a company facing a breach situation. At the same time, employees are key to a company's successful compliance with various legal and administrative requirements involving data security.

A recent survey of the IT departments in 461 U.S. organizations conducted by the Ponemon Institute reported that the average annual cost of managing insider threats to data security is $3.4 million per organization. Further, more than 78 percent of respondents reported one or more unreported insider-related security breaches within their company. Latest Ponemon Institute Study Ties Lack of Awareness in Corner Office to Insider Threat Challenges, available at www.arcsight.com/solutions_insider_threat.htm, Sept. 12, 2006.

Raising the stakes further, a growing number of legal and industry guidelines governing data security are in place across multiple industry sectors, requiring companies to implement data security controls directed at their employees. Failing to satisfy such obligations can leave a company vulnerable to lawsuits filed by third parties as well as enforcement actions by federal and state government agencies.

However, employees need not be viewed as an expensive companion threat to outsiders. Instead, if companies properly focus on key employee-related security controls and implement those controls in a reasoned and responsive manner, employees can be powerful assets to data security. Employees can assist companies with compliance requirements and, at the same time, help serve as an important line of defense from insider and outsider threats.

LEGAL AND INDUSTRY REQUIREMENTS FOR EMPLOYEE CONTROLS

When designing a security program, developing law generally requires that companies address certain categories of security controls. Typically, that list includes employee procedures and controls designed to ensure employee honesty, education and proper job performance, and to prevent employees from compromising system security. The need for such controls is outlined in several federal statutes, regulations, administrative enforcement actions and industry guidelines spanning multiple industry sectors.

Implementing regulations for the Gramm-Leach-Bliley Act (GLB) requires covered financial institutions to identify reasonably foreseeable internal and external risks to the security, confidentiality and integrity of customer information. That assessment, at a minimum, must include employee training and management. See, e.g., FTC Safeguards Rule, 16 CFR 314.4(b)(1).

Likewise, implementing regulations for the Health Insurance Portability and Accountability Act requires covered entities to take a number of actions regarding employees under the heading of "administrative safeguards." The regulations require covered entities to (among other requirements):

"(1) apply appropriate sanctions against workforce members who fail to comply with the security policies and procedures of the covered entity; (2) identify the security official who is responsible for the development and implementation of the policies and procedures required; (3) implement policies and procedures to ensure that all members of its work force have appropriate access to electronic protected health information and to prevent those members who do not have access from obtaining access to electronic protected health information." HIPAA Security Regulations, 45 CFR 164.308(a)(1)(ii)(C), (a)(2) and (a)(3)(i).

The Purchase Card Industry Data Security Standards (PCI Standards) require companies to "[m]aintain a policy that addresses information security for employees and contractors." Purchase Card Industry Data Security Standards, Version 1.1, Requirement 12. Under PCI Standards Requirement 12, companies must, for example, "develop usage policies for critical employee-facing technologies (such as modems and wireless devices) to define proper use of these technologies for all employees."

The FTC, in an enforcement action against Nationwide Mortgage Group Inc., found that the company violated the GLB Safeguards Rule in part by "stor[ing] customer information on a computer network accessible to all employees" and failing to "train employees on information security issues, or oversee the collection and handling of customer information by its loan officers." In the Matter of Nationwide Mortgage Group, Inc. and John D. Eubank, File No. 042-3104, Docket No. 9319 (FTC 2005).

In a similar GLB Safeguards Rule action brought against Sunbelt Lending Services Inc., the FTC found that Sunbelt failed "to implement reasonable policies and procedures in key areas, such as employee training and appropriate oversight of the security practices of loan officers working from remote locations." In the Matter of Sunbelt Lending Services, Inc., File No. 042-3153 (FTC 2005).

The Federal Financial Institutions Examination Council (FFIEC), a formal interagency body of the five key federal banking regulatory agencies empowered to prescribe uniform principles and standards for the federal examination of financial institutions, has created an IT Examination Handbook for use by examiners when evaluating a financial institution's risk management process. The handbook addresses the requirements for employee security in multiple areas. See Federal Financial Institutions Examination Council IT Examination Handbook, July 2006, available at www.ffiec.gov/ffiecinfobase/booklets/information_security/information_security.pdf. Likewise, ISO 17799, an international standard for information security, requires multiple employee-related security controls. See BS ISO/IEC 17799: 2005.

CRITICAL EMPLOYEE-RELATED CONTROLS

In light of the above requirements, companies across a broad array of industry sectors should implement appropriate security controls aimed at the employee. These controls will form part of the foundation of a company's legal compliance effort and will become an integral part of that company's overall information security program. A review of the foregoing regulations, enforcement actions, and standards provides a good overview of best practice requirements likely to apply to any company seeking to satisfy its legal obligations to implement appropriate security. Below is a summary of some of the key employee-focused controls a company should consider.

Pre-hire background checks

Before an employee is hired, companies should consider whether background checks are appropriate, and if so, what information should be verified. For instance, the Handbook requires that all financial institutions, at a minimum, verify the information provided on job applications. Further, depending on the sensitivity of the job at issue and the access level to sensitive data that will be granted, the Handbook recommends a deeper investigation, including background and credit checks. According to the Handbook, the following checks are typically conducted as a matter of course: 1) character references, 2) criminal background checks, 3) confirmation of prior experience and education level and 4) confirmation of identity. Handbook, at p. 71. Likewise, ISO 17799 requires that "background verification checks on all candidates for employment ... [are] carried out in accordance with relevant laws, regulations and ethics, and proportional to the business requirements, the classification of the information to be accessed, and the perceived risks." BS ISO/IEC 17799: 2005, at p. 23.

Background checks are an important first line of defense, especially for companies hiring employees that will have high-level access to sensitive data. While every company may not be required to conduct such a check, addressing whether one is necessary is an important consideration.

Comprehensive training and retraining

Once an employee is hired, proper training on the company's security policies and procedures is critical. Such training is an important component to any company's effort to implement reasonable security measures and is a requirement under the GLB Safeguards Rule. FTC Safeguards Rule, 16 CFR 314.4(b)(1). Similarly, the HIPAA regulations require companies to "implement a security awareness and training program for all members of its workforce (including management)." HIPAA Security Regulations, 45 CFR 164.308(a)(5)(i). Further, ISO 17799 requires companies to ensure that employees "are properly briefed on their information security roles and responsibilities prior to being granted access to sensitive information or information systems" and that they "are provided with guidelines to state security expectations of their role within organization …" BS ISO/IEC 17799: 2005, at p. 25.

Employees should not be hired and simply handed a thick security manual to digest. Instead, the employee should be offered comprehensive education programs that specifically relate to an employee's day-to-day security-related responsibilities. For example, if an employee has high-level access to sensitive data, procedures for accessing that data, processing that data, transferring that data and ultimately closing the access point to that data should be discussed and practiced. Further, employees should be trained on how to handle outsider threats such as social engineering, third party vendors and vulnerable locations such as airports. In addition, training should include a discussion of how to properly handle a breach once it has been discovered. Finally, training should not merely be a first day of work activity. Employees must also be continually retrained as technology and threats to that technology continue to evolve.

Contractual obligations

Ensuring that employees are contractually subject to appropriate obligations regarding confidentiality, nondisclosure and access to sensitive data, and that they clearly understand those obligations, is another important control. Contracts send a strong message to employees that security is an integral part of a company's operations and that they themselves are being held accountable. A company should consider using contracts that require employees to keep confidential their knowledge of key security information, including passwords and other access codes, remote access procedures and security vulnerabilities.

ISO 17799 recommends that such agreements address: 1) the type of information to be protected; 2) how long that information should be protected; 3) what occurs when the agreement terminates; 4) who will have access to the confidential information; 5) which party owns the confidential information; 6) how the confidential information may be used; and 7) how use of the confidential information can be monitored. ISO/IEC 17799: 2005, at p. 11.

Acceptable-use agreements that limit how an employee may use critical systems, and provide disciplinary consequences for noncompliance, are also important. According to the FFIEC, an acceptable-use policy often includes the following elements: "(1) the specific access devices that can be used to access the network; (2) hardware and software changes the user can make to their access device; (3) the purpose and scope of network activity; (4) network services that can be used and those that cannot be used; (5) information that is allowable and not allowable for transmission, using each allowable service; (6) bans on attempting to break into accounts, crack passwords, or disrupt service; (7) responsibilities for secure operation; and (8) consequences of noncompliance." Handbook, at p. 25.

Access control and monitoring

Proper employee access control limits the accessibility to a particular company asset to only those that require access on a need-to-use or event-by-event basis. According to the PCI standards, systems must be set to "deny all" except for those employees who do have a need-to-use. Purchase Card Industry Data Security Standards, Version 1.1, Requirement 7.2. HIPAA, in general terms, requires companies to implement policies and procedures that appropriately limit access to health information. HIPAA Security Regula-tions, 45 CFR 164.308(a)(3)(i). According to the Handbook, financial institutions should control access by: "(1) assigning users and devices only the access required to perform their required functions; (2) updating access rights based on personnel or system changes; (3) reviewing periodically users' access rights at an appropriate frequency based on the risk to the application or system; and (4) designing appropriate acceptable-use policies and requiring users to agree to them in writing." Handbook, at p. 22.

Monitoring of employee activities also helps to ensure that the access controls are in place and working effectively. ISO 17799 requires companies to monitor their systems and record information security events. Further, ISO 17799 calls for companies to: 1) "[use] operator logs and fault logging … to ensure information system problems are identified;" 2) "comply with all relevant legal requirements applicable to its monitoring and logging activities"; and 3) "[use] system monitoring … to check the effectiveness of controls adopted and to verify conformity to an access policy model." ISO/IEC 17799: 2005, at p. 55. Finally, GLB's regulations also weigh in on access control and monitoring, requiring financial institutions to design information safeguards that regularly test or monitor the effectiveness of security controls, systems and procedures. FTC Safeguards Rule, 16 CFR 314.4(b)(3)(c).

Proper use of remote devices

Employees who work out of the office may utilize devices that if used improperly or left unattended can create significant security threats. For example, employees may travel with laptops or USB hard drives that contain sensitive data available to anybody who picks up the device. Employees may also complete sensitive tasks while utilizing an unsecured home computer. It is important to provide employees with detailed policies and procedures on how to securely use technology outside of the office.

According to ISO 17799, a company's mobile computing policy should include requirements for physical protection, access controls, cryptographic techniques, backups and virus protection. In addition, the policy should include "rules and advice on connecting mobile facilities to networks and guidance on the use of these facilities in public places." ISO/IEC 17799: 2005, at p. 74.

Remote access can also mean that an employee is transferring data over a network connection. A company's remote access policies should address this potential vulnerability. HIPAA specifically addresses this component, requiring entities to implement security measures that guard against unauthorized access to electronically transmitted data. HIPAA Security Regulations, 45 CFR 164.312(e)(1). The handbook requires financial institutions to use strong authentication and encryption methods to secure communications (Handbook, at p. 50), and the PCI Standards require entities to utilize two-factor authentication before employees can gain remote access to systems. Purchase Card Industry Data Security Standards, Version 1.1, Requirement 8.3.

Employee policies should also be in place regarding how to handle the loss of such a device, including how to isolate the data loss to the greatest extent possible and how to properly report the loss.

BREACH RESPONSE

Should a breach occur, it is important to have rules and procedures in place for employees while reporting and responding to security incidents. Considerations should include: 1) ensuring that the right personnel are notified and available to take action; 2) determining who is responsible for restoring systems and how that will be accomplished (including when it is appropriate to return sensitive data to the network); 3) how to maintain evidence of the breach; 4) how to respond to law enforcement, supervisory agencies, customers, service providers, potential victims, the press and others; and 5) when to involve outside experts. Further, many state laws require companies to report security breaches of a certain magnitude to the public. It is important to analyze these laws in light of the breach and determine whether it is necessary to inform the public.

The Handbook specifically instructs financial institutions to determine: "which personnel have authority to perform what actions in containment of the intrusion and restoration of the systems." Further, the Handbook requires the creation of escalation policies that address when different personnel within an organization will be contacted about a security incident and what their responsibilities will be. Handbook, at pp. 91-92. Moreover, according to ISO 17799:

"A formal information security event reporting procedure should be established, together with an incident response and escalation procedure, setting out the action to be taken on receipt of a report of an information security event. A point of contact should be established for the reporting of information security events. It should be ensured that this point of contact is known throughout the organization, is always available, and is able to provide adequate and timely response. All employees, contractors and third-party users should be made aware of their responsibility to report any information security events as quickly as possible. They should also be aware of the procedure for reporting information security events and the point of contact." ISO/IEC 17799: 2005, at p. 90.

POST-BREACH

When a company does identify an employee whose conduct has caused or is likely to cause a security issue, the company must take affirmative steps to address the situation, sanction the appropriate employee and move toward a resolution. These steps should include: 1) a thorough investigation of the employee activities at issue, including a look at that employee's past performance and disciplinary history; 2) proper discipline of the employee involved; and 3) retraining of the involved employee (if that employee remains with the company) as well as other employees with similar responsibilities or roles. If an employee is released, that employee should be required to return all company assets in his or her possession.

According to the HIPAA security regulations, entities must apply appropriate sanctions against employees that fail to comply with security policies and procedures. HIPAA Security Regulations, 45 CFR 164. 308(a)(1)(ii)(C). Further, ISO 17799 states that breaches should be a source of learning for companies and an occasion to implement policies and procedures that absorbs lessons-learned to address recurring or high-impact security incidents. ISO/IEC 17799: 2005, at p. 93.

BUILDING A CULTURE OF SECURITY

Finally, in light of all the evolving legal requirements and technological threats to security discussed above, it is important for companies to ground security in the culture of their organization. This begins with the training process, but also requires an ongoing emphasis on the importance of security.

European Commission makes sweeping changes to codified law [EU]

European Commission makes sweeping changes

European Commission makes sweeping changes to codified law
* Directive 2006/114 of 12 December 2006 concerning misleading and comparative advertising (codified version) - in force from 12 December 2007

* Directive 2006/115 of 12 December 2006 on rental right and lending right and on certain rights related to copyright in the field of intellectual property - in force from 16 January 2007 (ie 20 days from the date of its publication of the Official Journal)

* Directive 2006/116 of the European Parliament and of the Council of 12 December 2006 on the term of protection of copyright and certain related rights (codified version) - in force from 16 January 2007 (ie 20 days from the date of its publication of the Official Journal)

Thursday, December 21, 2006

Registrar Refuses 'Rare Blend' Application [India]

Under the World Trade Organization Agreement on Trade-Related Aspects of Intellectual Property Rights wines and spirits are categorized separately and enjoy a higher level of protection than other products. Scotch is a well-known type of whisky and the Scotch Whisky Association, which is responsible for protecting Scotch whisky, registers the product worldwide. The association is vigilant in safeguarding and protecting the interests of its members, and has successfully challenged the registration of a number of brands worldwide, including in India.

Facts

In Srilab Breweries Pvt Ltd v Scotch Whisky Association (2006 (33) PTC 527 (Reg)) Srilab Breweries Pvt Ltd filed an application to register the mark RARE BLEND with the Trademarks Registry. The Scotch Whisky Association filed an opposition on the grounds that the term 'rare blend' is devoid of any distinctive character and thus is not registrable.

The association's main argument was that the word 'blend' is used to describe a whisky that is a mixture of two or more whiskys. Further, the term 'rare blend' is regularly used to indicate the quality of the product; therefore, it is common to trade and devoid of any distinctive character. The association also submitted that as early as 1860 it had used the word 'blend' in its trade. It also stressed that the word 'rare' is a common English word meaning excellent or uncommon. The association argued that the term 'rare blend' is internationally used as a descriptive term and thus cannot be termed a trademark under Section 2(1)(zb) of the Trademarks Act.

Decision

The deputy registrar of trademarks held that the term 'rare blend' is highly descriptive and characteristic of the goods in question, and thus cannot qualify for registration. It is a prevailing practice in the whisky trade to use 'rare blend' or 'blend' to describe the characteristics and quality of the goods. It is left open for other traders to use the term to describe their goods; therefore, no monopoly can be awarded to the words 'rare blend'. The deputy registrar further observed that as the mark had not yet been used by the applicant, no harm was likely to be caused to the applicant. In light of these observations, the registrar refused registration of the mark.

Comment

This decision shows that a mark which is devoid of any distinctive character or which is incapable of distinguishing the goods of one party from those of another constitutes grounds for refusal under Section 9 of the Trademarks Act. Further, any mark that indicates, for example, the quality or quantity of the goods is liable to be refused registration. The deputy registrar correctly observed that it is left to other traders to describe the nature and quality of their goods legitimately. An application for any mark that would hinder such freedom is liable to be refused.

Source : http://www.internationallawoffice.com

Notifications concerning submission or transmittal of priority document (Form PCT/IB/304), and recording of changes (Form PCT/IB/306)

PatentScope Search Service now includes, for all international PCT applications filed from January 2006, the following forms:
  • PCT/IB/304: Notifications concerning submission or transmittal of priority document that is to say the date on which the priority document has been received and the indication whether the priority document is in compliance with Rule 17.1(a) or (b) of PCT Regulations.
  • PCT/IB/306: Notifications of the recording of changes (person, name, residence, nationality or address of the applicant, as well as person, name, or address of the agent, the common representative or the inventor) as received by the International Bureau before the expiration of 30 months from the priority date.

Publici Juris – In Pharma Products [India]

"Publici juris" is a Latin word, and in the legal parlance, means, "of public right." The term signifies a thing or a right that is open and exercisable by all persons. It designates things that belong to the entire community, and not to any private party.

Usually, common suffixes or prefixes do not come in the way of distinctiveness. The nature of certain trades may require common suffix/ prefix for the purpose of familiarity. The distinctive nature of the word would then depend on the remaining part of the word attached to these common suffixes and prefixes. A term would be considered as a prefix or suffix only if they are derived from common or generic words. It is in this scenario the case under comment comes into limelight. The Madras High Court in Apex Laborataries Ltd v. Zuventus Health Care Ltd, 2006 (33) PTC 492 (Mad.)(DB) ruled that "Zincovit" and "Zinconia" are two words phonetically dissimilar and the visual impressions are also different and hence, it is hardly likely to cause confusion.

Facts

Apex laboratories Limited (Appellants), the manufacturers of the Pharmaceutical products adopted trademark "Zincovit in 1988. It is their claim that they have at times filed case against infringement of their said mark and secured injunctions. In early 2006, they came to know that the respondents were carrying on trade under the trademark "Zinconioa." It is alleged that the respondents are guilty of infringement and passing off and hence have filed the civil suit and injunction.

The respondents on the other hand resisted the application raising the contention that there are several registered trademark owners registered with the word ‘Zinco." Further, there is no likelihood of confusion as there is no phonetic, visual or conceptual similarity is attached to the said marks. The exparte injunction already granted was vacated on the ground that there is no likelihood of confusion in the minds of the purchaser.

The appeal preferred by the Apex Laboratories is against the vacation of expatre injunction.

Contentions

A catena of cases was cited for substantiating the contentions. The court referred to Ciba Geigy Limited & Hindustan Ciba-Geigy Ltd. v. Croslands Research Laboratories Ltd., 1995 IPLR 375; where the division bench granting the injunction held that EUGEL was strikingly similar to EMULGEL.

Judgment

On the question of similarity, which being the moot issue in this case, the Court relied on Cadila Health Care Ltd. v. Cadila Pharmaceuticals Ltd., 2001 PTC 300(SC), where the apex court held that the drug even if sold under the prescription or only to the physicians cannot itself be considered as a sufficient ground against confusion. The factors to be adequately considered for deciding the question of similarity are

  1. The nature of marks i.e. where it is a word mark or label mark or composite mark;
  2. The degree of resemblances;
  3. The nature of goods;
  4. The similarity in nature, character, performance of rival traders;
  5. The class of purchasers;
  6. The mode of purchasing the goods;
  7. The other surrounding circumstances;

The court for buttressing the conclusion relied on Corn Products Refining Co. v. Shangria Food Products Ltd, AIR 1960 SC 142; where it was held that the question whether the two marks are likely to give rise to confusion or not is a question of first impression.

On the question of generic term and publici juris, the court buttressed the argument by relying on SBL LTD. v. Himalaya Drug Co, 1997 (17) PTC (DB) and Roche & Co. v. G. Manner & Co, AIR 1970 SC 2062; where it was categorically held that no one can claim an exclusive right to a generic term and the customer will not consider the common feature and would pay more attention to the descriptive features. It is common in the pharmaceutical trade that abbreviations for vitamins and chemical names are extensively used. The court observes that if the term is both descriptive and common to the trade, more attention is to be paid to the uncommon element in the two words, and then there would not be any confusion.

The present Court engineered with the above precedents held that as both the medical preparations contains ‘Zinc’ and that the word is common to the trade and hence it is definitely publici juris. The Apex Laboratories have no right to claim ownership over the above word and as both the trade names contain the word ‘Zinc, it would be dangerous to split the word into two and grant injunction. Cardboard cartons were produced before the court to substantiate the claim that there were broad dissimilarities and the court was convinced to the same. The court ruled that ‘Zincovit’ and ‘Zinconia’ are phonetically dissimilar and the visual impressions are also different and hence there is least chance for causing confusion and there by the appeal is dismissed.

Conclusion

The rules regarding deceptive similarity take a special connotation with regard to pharmaceutical trade names. As the drugs are prescribed by registered medical practitioners and dispensed by qualified pharmacists, the chances of confusion arising out of two products being deceptively similar are considerably reduced. To this extent, some similarity is allowed. Further many names are common to the trade and hence fall under publici juris, but it is always a matter of concern for the judiciary, where to draw the line, as whose impression is to be weighed, literates’ or illiterate’s, in deciding trademarks cases. It is clear from the precedents that the matter is not yet crystallized, and judicial mind is required to be exercised in each case according to the facts and circumstances.

"Interested Person" Under The Copyright Act, 1957 [India]

One of the important criteria for obtaining registration under the Copyright Act, 1957 is that, the application must include a statement accompanied by a certificate from the registrar to the effect that no trademark identical or deceptively similar to such artistic work has been registered under the Trademark Act. As per the Copyrights rules 1958, the person applying for the registration is required to give notice to any person who claims or has any interest in the subject matter. Now, the moot question is whether a rival trader is an interested person as per the Act and should notice be sent to him also. Sakthi Kulangara Match Workers Industrial Co-operative Society Ltd v. Arason Match Industries, 2006 (33) PTC 542 (CB); precisely discusses this issue.

Facts

The petitioners, Shakti Kulangra Match Association, (SKMWI) are a registered cooperative society, engaged in the business of manufacture and sale of safety matches started its functions from the year 1978. They adopted a trade label of three and four birds sitting on a branch of a tree and with the word marks ‘WE THREE’ and ‘WE FOUR’ respectively. They claim to use the said labels from 1983 onwards with the approval of Central Excise Authorities from time to time. The petitioners received a legal notice in 2001 from the respondents (Arasin Match Industries) alleging infringement of their trademark ‘WE TWO’ and carrying a similar trade label. Arason Match Industries further lodged a complaint before the Deputy Inspector General of Police alleging the violation of copyright under section 63 and 64 of the Act. The petitioners initiated a Writ petition seeking a direction to restrain the police from harassing them. In that Writ, the respondents (respondents here in were also made respondents in the writ), claimed that they are registered owners of the label "WE TWO" under the Copyright Act, 1957.

This being new information, the SKMWI, moved an application for expunging the entry in the register under section 50 of the Copyright Act.

Contentions

SKMWI contended that the picture of the two birds sitting on a branch of a tree is a common picture, it has a limited way of expression and hence it lacks originality. Barring the legal notice in 2001, the SKMWI is using the trademark as well as the trade label uninterrupted. It is further contented that different producers of the matchbox are commonly using the picture of bird representing a family to create an image of household products.

The Arson Match Industries on the other hand contended that they were using the said label since 1956 and that the label of the SKMWI is only an adaptation of their Trademark.

On the question of interested persons the SKMWI submitted that they were very much interested persons and that it was mandatory that a notice about the proposed application for registration be sent to them, and that such concealment was with mala fide intentions. The Arason on the other hand argued that the SKMWI is infact an infringers and hence not entitled to notice.

Judgment

The Court while addressing the question of interested person went into the intricacies of the Section 45 of the Copyright Act which mandates that in respect of an application for artistic works used or capable of being used in relation to any goods, a statement along with the certificate of Registrar of Trademark to the effect that no trademark identical with or deceptively similar to the artistic work has been registered under the act by any person other than the applicant himself. Further, Rule 16(3) make it explicitly clear that the person applying for registration under the Copy right Act shall give notice to every person who claims or has interest in the subject matter of the Copyright or disputes the right of the applicant.

The Copyright Act unlike Trademark Act, places heavy burden on the applicant. The Applicant as per section 45(1) is required to give a statement accompanied by a certificate from the Trademark registrar, about his rivals in the trade, to the effect that notrademark identical with or deceptively similar to his artistic work has been registered under the Act, by any other person other than the applicant himself. The rule has been further reinforced by the amendments brought out in 1992, which cast heavier duty upon the applicant to put his trade rivals to notice.

The court while finding the SKMWI an aggrieved person, buttress the finding by highlighting that as the respondent himself has initiated a complaint, alleging infringement of the copyright. The court ruled that an opponent is necessarily a person interested in the matter in an adversial system of dispensation of justice. The court also relied on the mandatory nature of rule 16(3) of the Copyright Rules, 1958.

It is clear from the provisions of the Copyright Act and Rules that a much heavy burden is cast upon the applicant and his duty to issue notice extends even to rival traders. One of the rationales for providing such stringent measures is to ensure that the applicant himself after obtaining registration faces no further difficulties.

Power Of Registrar To Accept Rectification Application During The Pendency Of Suit [India]

Sec. 57 of the Trade and Merchandise Marks Act, 1958 gives power to registrar to rectify the register. However, the plain reading of this section gives rise to a conflicting situation in light of section 107 of the Act, which puts a bar on power of registrar in this regard. The Intellectual Property Appellate Board, Chennai addressed the question of power of registrar to accept rectification application during a pendency of suit in High Court, in the of Sun Pharmaceutical Industries Ltd v. Stadmed Pvt.Ltd &Ors., 2006 (33) PTC 506 (IPAB).

Facts

The rectification application is filed by Stadmed Pvt.Ltd (respondent) against M/s Sun Pharmaceutical Industries Ltd who is the appellant in this case. The Sun pharmaceuticals are the manufacturers of medicines and medicinal preparations. They are selling the medicines under the registered trademarks ‘ALZOLAM’ and ‘ZOLAM’. . The trademark ‘ZOLAM’ was first applied and registered by a company named FDC Limited during 1986.The mark was later on assigned to one Mr.Harish Uchil who in turn assigned the said mark to the appellant. The petitioners are presently the proprietors of the said mark.

The appellant claims that they have filed an infringement suit against respondent in the High court of Calcutta for the infringement of said marks. However, the injunction granted in that case was ultimately vacated.

Later on, tadmed Pvt Ltd filed an application for rectification on the ground that the trade mark ‘ZOLAM’ is not distinctive and the same was registered without any bonafide intention to use and that there is infact no bonafide use of the said mark for the time being. One month before the date of application or that up to the date of one month before the date of application a continuous period of five years have elapsed during which the trademark ZOLAM was not used and hence, it is liable to be removed from the registrar. It was further pointed out that the application of the Stadmed to the said mark is pending before the registrar.

Respondent further preferred another application for rectification on the ground that the trademark ‘ALZOLAM’ was also not registrable as it is deceptively similar to the basic drug ‘ALPRAZOLAM’ and the registrar decided against respondent i.e. Stadmed Pvt. Ltd.

The case of the Sun Pharmaceuticals is that when the registrar had allowed the rectification of the mark a suit for the infringement of the same was pending before the High Court and, hence the application ought to have been made to the High Court as per Section107 of the Trade and Merchandise Marks Act 1958, and registrar have no jurisdiction to entertain the petition.

The Deputy registrar by his order held that the Act or Rules are silent as to whether the registrar should not deal with the rectification application or whether the same should be withdrawn and refiled while the suit is pending before the High Court, and hence proceeded with the matter and asked appellant to file counter statement. The registrar after recording the evidence, allowed the application for rectification for the trade mark ‘ZOLAM’ and disallowed the rectification application on ‘‘ALZOLAM’. The present appeal is against this order of Deputy Registrar.

Contentions

The specific contention raised by the appellant is that the Deputy registrar had failed to appreciate that section 107(1) provides that in a suit for infringement, where the validity of the registration is questioned by the defendant, he issue of the validity has to be decided by an application made to the High Court. Hence, the deputy registrar ought to have dismissed the application as per the provisions of Section 107(1) of the Act and ought to have been referred the same to the High Court as per the Section 107(2) of the Act.

In order to buttress their argument they relied on the Whirlpool Corporation v. Registrar of Trademarks, Mumbai & Ors, 1998 PTC (18) 717 (SC); where the Court held that " The extent of jurisdiction conferred by the Section 56 of the Registrar to rectify the Register, is however, curtailed by Section 107 which provides that an application for rectification shall, in certain situation, be made4 only to the High court. These situations are mentioned in Sub-section (1) of section 107, namely where in a suit for infringement of the registered Trademark, the validity of the registration is questioned by the Defendant or the defendant, in that suit, raises the defense contemplated by section 30(1) (d) in which the acts which do not constitute an infringement, have been specified, and the plaintiff in reply to this defense questions the validity of the registration of defendant’s trademark. In these situations, the validity of the registration of the Trademark can be determined only by the High Court and not by the registrar".

On the other hand, respondent contented that they are carrying on with the manufacture of medicines and they had applied for the registration of the mark ‘ZOLAM’ which they have invented and adopted for pharmaceutical products since 1991. Further, it was pointed out that the said suit in the Calcutta High Court was stayed on the ground that an application for rectification is pending before the Registrar and this has not been challenged by Sun pharmaceuticals. It is alleged that the Sun pharmaceuticals have approached the court with unclean hands and hence the appeal is to be dismissed. Owing to the above facts, it is contented that the issue cannot be reopened.

Judgment

The court placed its reliance on the Whirlpool Corporation case and held that the registrar have no power to entertain the application for rectification under section 107 of the Trade and Merchandise Marks Act, 1958 when the suit is pending before the High Court.

Comment

Section 107(1) and (2) of the Trade and Merchandise Act, 1958 categorically holds that when a suit for infringement is pending before the High Court the registrar has no power to entertain an application for rectification. The view of the deputy registrar that the Act or rules are not are not clear in this matter is unfounded. If a matter is pending before the higher court, it is the prerogative of that court to decide the matter and the lower court is not expected to make any observations in the same case. The objective is to give finality to the judgment of the Court and this seems to be the rationale for section 107(1) and (2). The case can also be considered as an example of purposive interpretation given to the two provisions.

Though the case is based on the Trade and Merchandise Marks Act, 1958 but the procedure with regard to powers of registrar for accepting a rectification application during Pendency of suit is similar in the Trade Marks Act, 1999 – the present Act in force. The corresponding section to 107 of Trade and Merchandise Marks Act, 1958 is section 125 of the Trade Marks Act, 1999 which states that "notwithstanding anything contained in section 47 or section 57, such application shall be made to the Appellate Board and not to the Registrar".

Sony BMG settles 'rootkit' case [US]

Sony BMG will settle a US lawsuit over its Digital Rights Management software for $750,000. The payment will end the suit brought against the record company by the attorneys general of Los Angeles county and California.

The record company was embroiled in controversy when 12.6 million of its CDs were sold containing software designed to restrict users' use of the music in order to protect the songs from being distributed online.

Users who put the CDs into their computers said that the software damaged their computers and potentially opened the door to hackers to break into their computers.

Some CDs included software known as XCP which installed a so-called rootkit on the user's computer. This is a technique more often used by virus writers hoping to conceal the existence of their software: files are hidden deep in the architecture of a computer's operating system, making them difficult to find and remove.

California and Los Angeles sued Sony BMG for not disclosing any information about the software or about the limit it placed on the numbers of copies consumers could make of the music contained on the CD. The suit also accused the company of false advertising, unfair competition and unlawful computer intrusion.

The settlement promises up to $175 to consumers in California who can provide documentation relating to the damage they say was done to their computers. On top of that the company will pay $750,000 to the attorneys general in fines and to pay legal fees.

The Californian suit was settled almost as soon as it was filed, said newswire AP, and some states, including Texas, still have outstanding suits against the company, though some cases are almost settled, said reports.

A key part of the case was the fact that consumers were not told that the CD they were buying would automatically install software on their PC. Sony BMG has agreed to warn users in future if it ever uses digital rights management technology again.

"They're requiring disclosures to consumers before sale on the CD packaging," Corynne McSherry, a staff attorney with the Electronic Frontier Foundation, told AP. "I think that's really crucial. Part of the whole background of the rootkit fiasco was that consumers just didn't know what they were getting into."

One of the recommendations of the review just conducted in the UK by former Financial Times editor Andrew Gowers was that any CD sold in the UK with digital rights management software on it carry a label clearly outlining that fact.