Articles Posted in Technology

The expansion of social media networks has helped connect people and ideas all over the world. However, it has also raised substantial privacy concerns as more people store personal information on the web. Congress has enacted legislation in an effort to circumvent the dangers associated with online networks–for example, the Electronic Communications Privacy Act, the Child Online Privacy Protection Act, and the Stored Communications Act. States have also passed their own legislation to help protect cyber activity within their jurisdiction. For example, California passed “Do Not Track” legislation in November 2013 requiring websites to disclose their tracking practices. These laws, along with several others, work to protect individuals, entities, and their related private information as they continue to operate and conduct business over the Internet. Recently, a federal court applied the Stored Communications Act and found that it is applicable to a user’s wall posts.

What Are The Provisions of the Stored Communications Act?

In 1986, Congress passed the Stored Communications Act (“SCA”) which is codified under 18 U.S.C. §§ 2701 et seq.  The SCA aims to protect privacy interests implicated throughout electronic communications. Various court holdings have interpreted the SCA to apply to non-public electronic communications that take place over electronic communication services in an electronic storage medium. Violations of the SCA may carry potential criminal penalties, including serving time in prison. The penalties and liabilities will generally depend on the circumstances of the violation. The SCA does allow Internet service providers to share “non-content” with another person or entity. This includes log data and recipients’ email addresses. Still, this is a limited exception to the general rules and the SCA is still prohibited with sharing any information with a government entity. The government may compel Internet service providers to provide stored information. For electronically held communications, the government is required to have a probable cause and obtain a search warrant. For communications stored remotely, the government only needs a subpoena or a court order. Hence, remotely stored data enjoys a lower level of protection since it is easier to submit a subpoena rather than to obtain a search warrant.

In recent years, electronic spam has become a public nuisance. In response, several states, including, but not limited to, California, have enacted statutes to prevent electronic spam. As with most legislation that deals with the constantly-changing nature of the web, these statutes struggle to define the extent of their application while staying current with trends. Therefore, courts are charged with the responsibility of interpreting the intent of these laws.

What Are The Provisions of California’s Anti-Spam Statute?

In fact, California’s Business and Professions Code section 17529.5 prohibits any person or entity from sending commercial email advertisements, or spam, in three defined circumstances. First, spam is prohibited if an email advertisement uses a third-party domain without the third-party’s permission. Second, the statute prohibits email advertisements that use misrepresented information in the header. Finally, it is unlawful to use a subject line that is reasonably likely to mislead a recipient about the content or subject of the message. This section applies if the email is sent from California or if it is sent to a California email address. Accordingly, the reach of California’s legislation into other jurisdictions is also an issue for courts to interpret. Furthermore, a party bringing suit may recover both actual damages and liquidated damages. Liquidated damages are limited to $1,000 for each unlawful email and may go up to $1,000,000.

In general, both copyright and patent laws provide different levels of protection for computer software. Additionally, depending on the aspects of software that an owner wants to protect, these two areas of law will apply differently. Furthermore, securing a patent is a more rigorous process. However, a patent does provide a greater degree of protection. On the other hand, obtaining a copyright is less difficult, but it also provides a thinner veil of protection.

What Protection Does Copyright Law Provide For Computer Software?

The Copyright Act of 1976 is codified under 17 U.S.C. sections 101 et seq. Traditionally, copyright has been the common form of protection for computer software. However, copyrights only protect the expression of a work, and not its underlying idea. Copyrights have been instrumental in preventing software piracy and infringement of related works. The protection applies to software because the underlying computer code is similar to the types of writings the law protects. So, copyright holders can protect their software much like other literary works (e.g., books, scripts). Copyright protection essentially provides broad protections for software. It grants the typical copyright authority depending on the nature of the software. The courts have grouped software with other literary works and provided copyright protection accordingly. There also exist inconsistencies in court decisions applying the Copyright Act to software. This difficulty arises because the legal community often lacks the technical expertise necessary to properly classify software. For instance, where a judge cannot understand the program’s code, he or she cannot determine whether another infringing program’s code is substantially similar. It is necessary to establish substantial similarity to find copyright infringement. Therefore, the lack in technical background has led to unclear definitions as to what constitutes software copyright infringement.

On September 23, 2013, Governor Jerry Brown signed Senate Bill 568 (“SB 568”) into law, which requires social media sites to permit children to permanently erase online posts. These websites, including, but not limited to, Facebook, Twitter, and Tumblr, will have to provide options for users under the age of 18 to delete texts, photos, and videos. However, this option will not extend to content that a third party uploads regarding the minor. Hence, as California works to implement this new law, public debate circles around its effects and whether it will actually be helpful in protecting children online.

What Are The Provisions Of California’s New Digital Erase Law?

The law addresses websites that are directed to minors and have actual knowledge that a user is a minor. The websites include ones created specifically for the purpose of targeting minors rather than adults. These websites must provide a method for underage users to remove public posts about them. Alternatively, these users may ask the website to remove the content. However, if a minor received any compensation (i.e., marketing benefits, rewards) for a post, then the post is not subject to this law. In theory, websites may provide minimal compensation to minors to circumvent this law and avoid having to take down any posts. Furthermore, the law is ambiguous in some areas. For example, it is unclear whether minors are required to erase the content while they are still minors or whether they retain the right to erase any content they posted as minors. These details will need to be clarified to ensure proper enforcement.

In a recent case, Petronas v. Godaddy.com, the Ninth Circuit held that “contributory cybersquatting” was not a valid theory for relief. This case addressed the issue of whether the Anti-Cybersquatting Consumer Protection Act (“ACPA”) allows for secondary liability.

What Are the Facts?

Plaintiff, Petroliam Nasional Berhad (aka “Petronas”) is a Malaysian government-owned entity. Petronas holds the American trademark “PETRONAS.” The entity also owns the Petronas Towers in Malaysia. Defendant, Godaddy.com, is the world’s largest domain name registrar. The case revolves around a third party who registered the domain names petronastower.net and petronastowers.net in 2003. In 2007, the party began using Godaddy’s domain forwarding services to direct the domain names to an adult website. Petronas sued Godaddy for cybersquatting and contributory cybersquatting. In general, cybersquatting is the act of holding a trademark hostage in the form of a domain name and forcing the trademark owner to negotiate an unreasonable price for the domain. Although Godaddy did investigate the alleged cybersquatting, ultimately, they did not take any action.

In 2013, Edward Snowden, a former CIA employee, and National Security Agency (“NSA”) contractor, leaked top secret documents to the public. These documents detailed the NSA’s controversial electronic surveillance practices and procedures, sparking a debate about wiretapping and privacy laws. Snowden revealed that the government employed questionable electronic surveillance programs. The controversy circles around the potential privacy violations surrounding government agency practices to monitor communications. Since then, the Obama Administration has been under pressure to address individual privacy concerns. Last month, President Obama addressed the nation and introduced proposed changes to current electronic surveillance practices.

What Are the Current Wiretapping Laws, Before President Obama’s Proposed Amendments?

Wiretapping has been possible since the invention of the telephone. The procedure gets its name from earlier methods, which required officials to physically place electrical taps on telephone lines. Wiretapping is a constitutional and legal practice. In most cases, officials must secure a warrant from a judge beforehand. However, federal intelligence agencies can apply to the Foreign Intelligence Surveillance Court (“FISA”), under secret proceedings, for court approval. In some circumstances, these agencies can proceed with approval from the United States Attorney General, without court approval. In the event that the agency does need to secure a warrant before wiretapping, courts typically apply a very strict standard of review before granting approval. For instance, the judge will look to ensure there are no other less intrusive methods to gather information. In general, the courts look at wiretapping as a last resort. Alternatively, if a party who is participating in a call, records the call and produces it to a government agency, the agency does not need prior court approval. The agency is then at liberty to use the contents of the recorded phone call for its purposes.

In general, the federal government enforces privacy rights at the federal level and state governments regulate privacy standards at the state level. Depending on the area of privacy laws at issue, different government agencies have enforcement authority. For example, Office of the Attorney General, Federal Trade Commission, and Department of Health and Human Services have certain enforcement authority.

What are federal privacy rights?

The federal Privacy Act of 1974 applies privacy standards for the information that federal executives and agencies can access and disclose. However, these requirements apply only to information about U.S. citizens and legal alien residents. They do not apply to illegal immigrants or corporations.

Class action lawsuits are a staple in the American court system. The notion that there is strength in numbers is shown in the extraordinarily large settlements that come from these cases. In recent years, there has been a significant increase in class action suits involving internet-based companies (e.g., Facebook, Google, Tumblr, Instagram, or MySpace).

As consumers spend more time on the Internet, sharing their work, preferences, and private information, there is a growing potential for internet law violations. Since numerous consumers engage in same or similar activities, e.g., use email to send/receive information, a single violation implicates the rights of a large group of consumers. In turn, this sparks a class action suit.

How Are Class Action Lawsuits Different From Other Suits?

On December 19, 2013, Target issued a statement confirming a major security breach. According to the statement, approximately 40 million customers were at risk for identity theft because of the breach. Hackers had gained access to customer information, including their names, credit card numbers, debit card numbers, card expiration dates, and security codes. This incident brought light to the ongoing threat of identify theft for customers who use credit or debit cards to make purchases, either in stores or online. With this growing threat, consumers need to take care to protect themselves against potential attacks.

What Is the Extent of the Target Security Breach?

According to Target’s investigations, the hackers began accessing customer information from before Thanksgiving until mid-December. With the information they stole, which is stored on a card’s magnetic strip, the hackers could have made purchases all around the world. Indeed, hackers can also use this information to create new credit or debit cards. Although, there is no evidence the hackers also stole pin numbers, but if they had, they could have withdrawn money from customers’ bank accounts. The United States Secret Service is looking into this massive security breach. In the past, federal and state authorities have held companies liable, even issuing fines, if investigations reveal that a company did not take adequate steps to protect customer information. Analysts predict that here Target may have to spend over $100 million in legal costs to fix the security breach. Costs will increase even more if it’s forced to reimburse credit card companies for fraudulent purchases. However, in the meantime, Target’s first priority has been to act quickly to secure and protect customer information. Although, they have not reached any conclusions, initial investigations suggest the breach could have come entirely from outside hackers, or it could have been achieved with help from its employees. Either way, this level of a security breach suggests that it reached deep within the corporation.

The spread of social media networks and social profiles has, unfortunately, made the potential for cyber harassment more common today. For instance, the phenomenon of revenge porn has sparked controversy in society, prompting California’s Legislature to enact a new law to help deter future acts of involuntary pornography. If you, or someone you know, has been a victim of cyber harassment, including revenge porn, please contact us today to speak to an attorney who can help explain the legal remedies.

What Laws Apply to Acts of Revenge Porn or Cyberharassment?

In October 2013, California’s governor, Jerry Brown, signed Senate Bill 255 (“SB 255”) a law into effect, which made revenge porn a criminal offense, allowing victims to seek legal remedies from perpetrators. Revenge porn, also known as involuntary pornography or “cyber revenge,” is the act of posting pictures and videos that contain sexually-explicit content of a former significant other without their knowledge or consent. Typically, former significant others will post this kind of content to harass or embarrass previous partners. However, in some cases, hackers can get a hold of this type of content and post the pictures on adult websites. And, often times, the party distributing the images will include personal information about the victim (e.g., name, address, and social media accounts). Posting this type of personal information increases traffic through Google and draws more online visitors. However, this information also poses a serious threat to the victims, some of whom have reported the unwanted attention that comes from strangers.