Friday, December 11, 2015

Internet Freedom of Speech at Risk

Internet freedom of speech is not given the attention it merits while the EU ponders on its EU Data Protection Regulation.  Many rightfully fear that censorship is looming near and is nearer than one imagines.  While the General Data Protection Regulation (GDPR) has lingered since the 1990s, many countries have followed the EU aspiration of enhancing data protection to the extent of elevating the notion for fundamental right consideration.  Even the EU Charter underscores the notion by stating that individuals have the ‘right to protection of personal data as a separate and equal right to privacy.
This notion has had push back from companies that consider such pursuit of privacy to be inconsistent to business practices relying on marketing and other means for customer generation and profiling.  But the process for protecting personal information has had a negative impact on right to freedom of speech. By enforcing measures for the deletion of information that another individual may post on someone else, regardless of its public interest value, or about issues and policies, it effectively is denying the right of free expression.  The control and denial of the right of expression is also denying readers from being informed and forced to be informed only on future limited scope of information, hence, online censorship disguised.
Freedom of speech will be at risk of being limited as EU enforces its data protection by implementing directives to have information in the form of statements deleted from online sources.  The scope of such measures has surpassed just private information held by a company, but has now reached information that according to the Google Spain v. Mario Costeja González right to be forgotten case, is deemed to be inadequate, irrelevant or excessive about a person.
One critical concern, among others is how the GDPR’s July 2015 Draft version reads, it appears that it will exceed by implication the scope of the Google Spain’s court ruling.  There is a stated role for an internet intermediary to be tasked to asses and respond to the individual requesting the removal of online information.  This intermediary does not have the obligation to provide notice to the poster of the information. This is in contrast to Digital Millennium Copyright Act process that provides for notice and for an assessment of the legitimacy of the request by the search engine.
Another critical concern with the GDPR’s version is that while the intermediary may elect to have the content deleted without informing the poster, but still inform the downstream publishers and recipients of the otherwise posted content, the intermediary is responsible to provide the posters information to the individual requesting the content removal.  In essence, the GDPR provisions do in fact allow for personal information to be shared.
With the high penalties assessed on the poster/writer of the online posts if the EU authorities subsequently determine that it should have been removed, an intermediary tasked to assess will be most likely inclined not the take the risk of being penalized and out of caution direct removal of the posted content, provided the absence of countervailing public interest value of the posted content, and at the same time be obliged to provide the requester the personal information of the poster.  So, while the EU provision claims to seek the protection of privacy it allows for the personal information of the author of the post to be shared to the individual requesting the deletion, or claiming a right to be forgotten.  Internet freedom of speech may be at risk in the EU.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Thursday, December 10, 2015

Internet Technology and Encryption

Internet technology and encryption is placed at the forefront of the debate about how to process, store, secure, report, you get the picture, of communication that are otherwise deemed private.  The discussion embraces the ideas of using back-door means for law enforcement to peruse and search for possible suspects of the terror and their plots before a catastrophe engulfs us all.
The critical issue is the absence of a discernible policy on the idea of enhancing detection of terrorist intents.  On the long-term is the question how to administer the gathered information, if not differently from information in ‘transit’ that is detectably suspect.  In all points of concern, privacy relaxed for the greater is conceptually prevailing in intelligence and law enforcement discourse.  The crux of the concern with internet technology and encryption is the application of encryption of a device as opposed to the encryption used in communications between the use of devices.
By using the means of encryption an encoded message is created where only the reader with the key so-to-speak will understand the message.   A process of key specific means without backdoors is the problem that is being discussed.  Depending on the encryption system created backdoors are inept to discern the context of a communication.
While some argue for standardized encryption systems as we utilize in the financial and medical industries that are devoid of back doors, the broad use of encryption poses security vulnerabilities and creates a dark world or ‘dark web.’  The debate is about striking a balance between policy (law) and technology where there is the growing need to either know the contents of a device (cell, computer, tablet, etc.) or  to know the context of an ongoing communication (wiretap).  The former is a process involving law enforcement and the latter is a process of intelligence and information gathering.
Major software companies provide a mobile operating system that allows the user to be the only one possessing the key.  Law enforcement is stumped after the operating systems were changed from the provider housing the key to the user possessing the key.  The terrorist events are reigniting the debate toward seeking to have the software companies to possess the keys and rely on user.  But the debate is trumped by the existence of community-developed operating systems devoid of a company that can be forced to design a suitable operating system allowing for backdoors and numerous available software that provides encryption in a varied operating environments.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Trade Secret Act Update

Trade secret law and practice is about to change if Congress pursues the "Defend" Trade Secrets Act with the current provisions.  Not only will the practice change, rights as well as competition, may be affected for the worse.  The attention that this legislative activity is getting regarding trade secrets is scant to say the most.   Those larger entities holding a long list of trade secrets are pushing for its passing.  Yet the fact that the bill has issues has not driven the attention it needs in order to address the glitches that will affect industries, innovation, competition, and it practice.  To this day few are aware of the consequences of what the bill intends to do with regard to how courts will address trade secret misappropriation or theft.
Because the litigation involved in trade secret cases is murky where claims cross so commonly, the bill will have a chilling impact in the litigation process and could very well lead to a more anti-competitive environment.  The bill proposes to provide a procedural ‘fast lane’ allowing trade secret owners to prosecute claimed trade secrets takers through a newly created ‘ex parte’ step.  The bolder that crushes the process is the absence of notice that would otherwise inform the individual ‘defendant’ that its assets are going to be seized and that a court proceeding is going to adjudicate its rights to the claimed trade secrets.
This is without precedent in the field and most importantly, due process for defendants is rendered nil due to the fact that the bill proposes to not allow adequate notice of judicial proceedings regarding the claims against them nor provide them adequate opportunity to argue their position in court over the trade secrets in question.   More discussion and review is needed before its passing.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Tuesday, December 8, 2015

Internet Privacy – Florida Privacy Protection Act

Internet Privacy Law - Florida Internet Privacy Law
The flow of information from internet usage and ' Internet of Things'  is easily accompanied with its collection and systemic use for other purposes. Digital profiles are created with every online user’s key stroke, site visited, and key word used. In 2015, the Florida Legislature addressed many aspects of privacy.  It addressed systemic data gathering; data breaches; law enforcement use of RFID technology, school records privacy, portable electronic devices; and the use of identifiers by electronic communications services.
The 2015 Florida Legislature promulgated the Florida Privacy Protection Act.  The Act establishes Section 934.60, Florida Statutes, prohibiting electronic communications providers providing third parties with information that reveals the IP of users without the express permission of the subscriber or customer. Each violation will entitle the person to recover $10,000 penalty and civil actions must commence within 2 years of the date of the disclosure.  The Act construes digital data as property that is constitutionally protected from unreasonable search and seizure.
Specifically, the Act establishes the following: Section 933.41, Florida Statutes, relating to prohibition against searches using wall-penetrating radar device;  Section 934.60, Florida Statutes, pertaining to IP address privacy and the identification of users without their express consent;  Section. 934.70, Florida Statutes, regarding PEDs “portable electronic device” privacy; and  Section 1002.227, Florida Statutes, addressing contract requirements relating to student data usage.   The FPPA also places restrictions on the use of RFID by the Department of Highway Safety and Motor Vehicles. The Act became effective July 1, 2015.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Social Media Information in Litigation

Social media use and its information is telling of someone and it is increasingly sought after in court cases where we see social media information used in litigation. Many times social media accounts are a well-spring of vital information that can tip a case on its head. The information can reveal truthfulness or the lack thereof or even a possible smoking gun on liability. Gathered SNS information has at times revealed information discrediting the plaintiff’s damage claims.
While the balance is the pursuit of what is relevant, the predominance of social activity in “SNS” (social network sites) is drawing a need for revisiting discovery rules where social media information used in litigation is raised. The extreme efforts to discover – intrusively – personal information that is only available amid a person’s SNS network is also causing the court to reassess how the rules will address such discovery pursuits; particularly, when a party requests the court to approve the discovery request for passwords and login credentials of the opposing party.
The ultimate question wrestles with what is the inevitable discovery boundary. Absent a third party product that when applied sifts through a SNS account for relevant information, all discovery in SNS depends on the discretion of the information provider vis-à-vis the requester. The latter always deems all posted in SNS by the opposing party as fair game to be discoverable.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Trade Secrets and Employee Misappropriation

Employers overwhelmingly experience theft of trade secrets and employee misappropriation of employer intellectual property.  Employees transferring company confidential communications, business information, and items normally considered trade secret to a thumb drive or personal drives and accounts, could face being sued for a sundry of claims, including misappropriating trade secrets (violating the Uniform Trade Secrets Act), breach of fiduciary duty to the employer, and breach of non-disclosure agreement.
The Utah Supreme Court in InnoSys, Inc. v. Mercer2015 UT 80, over turned the state district court which had held in favor of the employee stating that “there was no objectively reasonable basis to believe that Mercer [employee] had harmed InnoSys or was threatening to do so.”
On appeal, the issue hinged on whether, as the lower district court determined, if the employer provided sufficient evidence of experiencing harm or the threat of it from the employees misappropriation of company trade secrets. The higher court determined differently, in that the element of the existence of harm was not important.
The Utah Supreme Court stated that when an employer demonstrates a prima facie case of misappropriation of trade secrets under the UTSA, there is a presumption of irreparable harm.  Based on this analysis, employers are not required to demonstrate damages and there is the presence of threatened harm of disclosure that supports injunctive relief.  On many levels, theft of trade secrets and employee misappropriation is irreparable to a business. 


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

 

IP Address and You

The use of an IP address is central to how the Internet functions.  The IP address reveals information about you, your trends, location, and a whole lot more.  By use of an email, say sending an email, the recipient can learn your location.  Through the IP address your internet service provider can be learned as well.  While the information may be limited to your location and your ISP, the online activity through a particular IP address can decipher more about the user.
Studies have been conducted to learn the extent of the information that is discernible from an IP address.  Network specific studies are easier to conduct and have revealed alarming information.  The Canadian Privacy Commission (CPC) sought to conduct a study within its network using a search vehicle to learn about the users of the internet through their network.  CPC was able to learn a variety of the following:  search history of the person to reveal interests, activity on sites to reveal purpose of use, sites visited to reveal a more detailed level of interest of the user, posting of comments on sites, online purchases, and even future vacation plans before they ask for the leave.
Advertisers pay handsomely for this information to enhance their directed marketing efforts. Employers may use this data to monitor their employees.  Government can use this data to anticipate security risks. Indeed, the IP address reveals much that many users do not realize.



Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.