twitter
    Follow Forde Campbell on Twitter

Thursday, 20 January 2011

Naomi wins and loses: What price for privacy?

In 2004, following the House of Lords ruling that photographs of supermodel Naomi Campbell leaving a drug rehabilitation unit breached her privacy, Mirror Group Newspapers were obliged to pay £500k in costs and success fees. On Tuesday, the European Court of Human Rights held on appeal six votes to one that there had been no violation of the applicant’s Article 10 rights.

The applicants largely relying on the HOL dissenting comments of Lord Nicholls and Lord Hoffman, argued that their freedom of expression under Article 10 was weightier than Article 8’s respect for Campbell’s private life. Strasbourg followed a line of reasoning that is well established in Human Rights law when determining whether an interference of a right is justified. It was concluded that the interference with the freedom of expression was prescribed by law for a legitimate aim and was necessary in a democratic society.

The applicant noted that the House of Lords had failed to put sufficient weight into the editor’s assessment. While the European Court did refer to the press and its preeminent role as a “public watch dog” it did take note of the private nature of drug addiction and its possible detriment to Campbell resulting from its release into the public domain. Strasbourg concluded that the press do have a right to release information for public interest, even if it conflicts with Article 8. The facts were distinguished in this case that Naomi Campbell’s private life was only an interest to society to the extent that she was a famous figure of interest to the public. The judgement today remarked that the House of Lords were in fact unanimous on these main principles but differed in narrower issues.

Interestingly, the partly dissenting opinion of Judge David Thor Bjorgvinsson disagreed with the decision that Article 8 took precedence over freedom of expression in this instance. The judge found the distinction between justifying the use of the original story and the supplementary material (photographs etc) unconvincing. He stated that although Campbell may have found the story “annoying” the supplementary material did not reveal any fundamental information, it merely “added colour to the conviction”.

MGN won their second ground at Strasbourg, as it was decided unanimously that 100% success fees in Conditional Fee Agreements for privacy and defamation cases violate freedom of expression prescribed by Article 10. It was found that the cost regime did follow a legitimate aim, primarily offering claimant’s with little money but deserving causes access to justice. However, referring mainly to the Jackson Review, the court highlighted that the cost system was not necessary in a democratic society. Qualifying requirements for claimants to enter into a conditional fee agreement (CFA) were absent, secondly there was no incentive for the claimant to control legal costs incurred as they would not be obliged to pay if the case was lost, thirdly this system had a “blackmail,” as Lord Hoffman put it, effect on parties who were often driven to settle cases quickly.

This case will have an impact on civil actions not covered by legal aid. The decision is binding on government but only persuasive in the domestic courts. The Jackson Review is largely supported by the government and implementation of its suggestions are a likely outcome for the future. However, the extent of the review’s efficiency is still uncertain in light of the recent proposals for legal aid cuts.

Friday, 3 December 2010

SAP ordered to pay largest fine on record for software piracy

A federal jury in California has ruled that software giant, SAP, has to pay $1.3 billion in damages for illegally downloading customer support documents and software belonging to its rival, Oracle. The scheme apparently involved setting up fake customer accounts to access instruction manuals and software information.

The case began in 2007, when Oracle filed a suit against TomorrowNow (TN) alleging the it had made thousands of illegal downloads over a three year period. Oracle claimed that SAP, which acquired TN in 2004, did so in full knowledge of the ongoing piracy. SAP admitted liability, however contested Oracle’s claim that the damages amounted to $1.65 billion. The recent decision turned on the question of how to evaluate the worth of the intellectual property TN illegally downloaded.

Under US copyright law, money can be recovered for statutory damages or for actual damages caused by the infringement, along with any additional profit amassed by the infringer through its wrongdoing. Actual damages can be assessed by considering the “fair market value” of the plaintiff’s work. This approach requires a jury to assess “what a willing buyer would have been reasonably required to pay to a willing seller for the plaintiffs’ work,” Frank Music Corp v Metro-Goldwyn-Mayer Inc (1985). An alternative method to prove actual damages is to indirectly prove the plaintiff’s lost profits.

Using the loss of profit method, SAP argued that Oracle had lost 358 customers as a result of the piracy, and evaluated actual damages at around $40 million. Unsurprisingly, Oracle opted for the “fair market value” option, reaching a figure over 40 times larger. After an 11 day trial, the jury panel decided on an award representing the fair market value of the licence that SAP should have agreed with Oracle.

For further reading:

Bloomberg


by Katey Dixon

Tuesday, 16 November 2010

Google eyed by European Parliament Report on misleading and aggressive advertising

The European Parliament has approved a report recommending that the European Commission introduces new legislation to combat misleading and aggressive advertising. Although the Unfair Commercial Practices Directive already regulates this area, the Juvin Report highlights the danger of the growth of new, more pervasive forms of advertising being used on the internet.

Though there is no explicit mention of Google Inc, it is obvious that the proposals target some of the services offered by the internet giant. With a clear reference to Google’s AdWords service, the Report calls on the Commission to condemn the practice of allowing companies to bid for keywords associated with brand names in search engines. When an internet user enters a purchased keyword into a search engine, that company’s advertisement is displayed alongside the ‘natural’ search results. Since 2000, when AdWords was first released, Google has faced countless lawsuits in the US and across the EU over its service. Despite claims that selling brand names as keywords encourages acts of parasitism and counterfeiting, the European Court of Justice has upheld the practice as lawful so long as the associated ads do not mislead the user as to the identity of the advertiser. The Report proposes that keywords associated with registered trademarks should only be available if the owner of the trademark authorises such use of the brand in question.

Targeted advertising is also flagged up as an unfair advertising practice. With significant implications for Google’s Gmail service, the Report recommends the complete prohibition of third parties reading private emails for advertising purposes. It is suggested that such practices are intrusive and constitute an attack on the privacy of individual consumers. Besides Google, websites such as Trip Advisor could also come under fire if the proposals are taken up. The Report warns of the danger of ‘hidden advertising’ which takes place in forums where consumers post comments to one another about various goods or services. It recommends the creation of forum moderators, and suggests running a campaign to alert consumers about this form of advertising.

The Report is scheduled for a full vote in December.

Further reading

Read the Juvin Report

Internal Market and Consumer Protection Committee press release

By Katey Dixon

Friday, 15 October 2010

Nominet orders ‘ihateryanair.co.uk’ to be handed over to the airline

Internet registry, Nominet has held that the privately owned website, ‘Ihateryanair.co.uk’ takes unfair advantage of the airline’s trademark, and should therefore be handed over to them. The website was set up in 2007 by Robert Tyler- a dissatisfied Ryanair customer. Its primary purpose was to create a forum for people to share their negative experiences of flying with the no-frills airline.

Ryanair complained to Nominet that Tyler’s use of their Community trademark in his website’s domain name constituted ‘abusive registration’. Although the judgment found in favour of Ryanair, expert Jane Seager clearly emphasised the importance of the continued existence of criticism websites, such as Tyler’s, in a democratic society. Nominet’s finding was not determined by Tyler’s use of a trademarked word for his domain name, but rather turned on the fact that he had received an income from the commercial links included on the site. Although the amount was insubstantial (£322), and despite the fact that making a profit was evidently not Tyler’s primary intention behind the site, Nominet concluded that using the trademark almost certainly increased the level of traffic to the website, and therefore constituted abusive registration. It was irrelevant that the domain name in its entirety made it clear that the website was not affiliated with the airline.

Nominet controls domain names with the co.uk ending. Its Dispute Resolution Service assesses registered websites in light of its policy of use, rather than undertaking an examination into legal issues. Wings clipped, but undeterred, Tyler has moved his website into the .org domain.

By Katey Dixon

Further Reading:

http://www.nic.uk/disputes/drs/decisions/decisionssearch/?searchText=i+hate+ryanair&x=0&y=0

http://www.guardian.co.uk/business/2010/oct/12/i-hate-ryanair-website-closed

Monday, 4 October 2010

UK to be tried by European Court for Failing to Implement Data Protection Rules

The European Commission has commenced ‘infringement proceedings’ against the UK government, alleging it has breached EU data protection laws. The decision follows a year-long investigation into whether UK law provides sufficient safeguards against the interception and surveillance of internet traffic.

Concerns were initially raised when the EC received complaints from citizens about a British telecom firm’s use of behavioural advertising. In 2006-2007, BT tested behavioural advertising technology on its broadband users, without the consent of the customers involved in the trial. The advertising system, known as Webwise, was invented by Phorm – a US-based company which specialises in advertising software. Once an ISP has signed up to the service, Webwise is able to ‘trawl’ sites visited by its users in order to build up a profile of the users’ interests and habits. The information can be exploited by advertisers who are then able to target customers on the sites they visit thereafter. What sets Phorm’s technology apart from other behavioural advertising systems, is that it works in conjunction with ISPs, rather than simply relying on data shared between associated websites. Although BT later rejected the technology, and no other UK ISPs are known to have used it since, the UK government failed to give a satisfactory verdict on the legality of the BT trials. It did, however, conclude that the technology itself is legal so long as users have actively given their consent, and web-sites can easily opt out of the system.

Having considered the situation in the UK, the Commission concluded that data protection in the UK is not sufficiently robust to fulfil its obligations under the e-Privacy Directive 2002/58/EC and the Data Protection Directive 95/46/EC. The Commission identified three areas of potential infringement:

(1) The UK has failed to establish an independent national authority to supervise the interception of internet communications.

(2) Current UK law authorises the interception of communications, not only where the persons involved have given their consent, but also where the person intercepting has “reasonable grounds” for believing that consent has been given.

(3) Current UK law only provides sanctions where unlawful interception is “intentional”.

If the Court finds in favour of the Commission, the UK will be obliged to implement the measures necessary to comply with the judgment. If the UK subsequently fails to take the steps required, a financial sanction will be imposed by the Court.


For further reading:

Europa

BBC

The Guardian


By Katey Dixon

Tuesday, 28 September 2010

ACS Law, Party Babes and the Information Commissioner: Here’s What’s Happening

ACS Law is a London based law firm specializing in file-sharing infringement cases. The firm’s practice includes acting for copyright holders, whom the firm advises on legal action against individuals allegedly guilty of unlicensed file sharing.

ACS Claim Process

Typically, the story begins with an individual receiving a letter from ACS Law alleging that a file (usually pornographic, the cases we have seen refer to “Party Babes”) belonging to ACS’ client has been illegally downloaded. ACS’ letter states that ACS has used a court order to oblige the relevant ISP to reveal the IP address to which the file was downloaded. The letter then identifies the individual as the owner of the IP address, claims that the owner has infringed ACS Law’s client’s copyright and points out the legal consequences. Letters that we have seen and advised upon contain a settlement offer, whereby in return for a sum (typically around £495) ACS’ client will drop the claim.

ACS has allegedly sent claim letters to thousands of people. Concerns have been raised that many individuals may be mistakenly accused, particularly given the fact that ACS’ case typically relies on identifying an individual via an IP address. An IP address may be used by someone other than the individual to whom the IP address relates, either by someone using the individual’s computer, or by third party access to the IP address via an unsecured wifi connection or a virus. Websites have been set up to offer assistance to genuinely innocent individuals, such as http://beingthreatened.yolasite.com/.

Concerns have grown into outcry on numerous sites and forums, with ACS Law apparently being scrutinized by the Solicitors Regulation Authority. Concerns turned into a full blown attack on ACS Law when hackers obtained details from ACS’ website of over 5,300 individuals the firm was pursuing for unlicensed filesharing.

Data Breach

The disclosure of the details of the individuals’ data, if it contained personal data, would potentially be a breach by ACS of UK data protection legislation: the Seventh Principle of the Data Protection Act 1998 requires that “appropriate technical and organizational measures shall be taken against unauthorized or unlawful processing of personal data”.

The UK’s data protection watchdog, the Information Commissioner, has already expressed his concern about the situation (see interview here), and will want to establish whether ACS had put in place appropriate measures to prevent such disclosure. The Information Commissioner has the power to fine any organisation who breaches the data protection laws up to £500,000. The gravity of this situation, including in particular details of pornography allegedly downloaded by the individuals whose data has been disclosed, means that the ICO will take a particular interest in this case.

Defence

Ultimately, ACS may rely on an argument that the law firm had done everything appropriate and that even the best IT defence can’t protect against a determined hacker. This would be ironic, since many of the denials received by ACS from alleged file infringers rely on exactly the same defence.

By Rory Campbell

Thursday, 2 September 2010

Germany's Facebook Ban

Last week a draft bill was backed by the German government limiting the use of Facebook by employers when hiring new staff. The proposed legislation will still allow employers to consult other social websites that make job information and networking public, such as LinkedIn or Xing. However, if an employer was to “befriend” an employee or hack into their account to access private data, with the intention to use the information against them, the employer could expect a fine of up to €300,000.

This development comes off the back of a number of workplace scandals that have recently surfaced. Deutsche Telekom (telecommunications company), Deutsche Bahn (national railway) and Lidl (retailer) are amongst the highest profile employers involved. The bill still faces a final debate and vote in parliament but is speculated to become law as early as this year.

One issue envisaged with the new proposed law is the difficulty in enforcing it. For example, it will be difficult for any employee to prove that personal information from their page on any private social network has made its way into hiring files.

The bill marks the increasing growth of German government control of data privacy. The same bill plans to restrict the use of video recording employees in places where they are not made aware of such use, despite arguments from opponents claiming that the proposal will affect anti-theft measures and employee corruption.

Separately, the German Data Protection Authority is investigating Google Street View for issues of privacy and allegations of collecting unencrypted wifi data. Google have said that this was a mistake and have stopped this process. Google have also introduced tools for German residents to opt out of their property being displayed on the street image software. Meanwhile, German authorities are also testing Apple on their data collection policies for devices like the iPhone.

The proposed bill for Germany seems to be welcomed amongst politicians. Up until now there has been no such legislation regulating social networking websites in this way. It is hoped that it will provide future guidance for courts in the growing number of cases involving networks such as Facebook. It is unknown at this stage whether the UK is soon to follow in Germany's legislative steps.


This blog was largely contributed by Nicola Mallon, whose copyright and moral rights in the blog are asserted. Many thanks to Nicola from everybody at Forde Campbell.