Monday, December 28, 2015

Cloud Use and Having an Exit Strategy


Cloud service uses, methods and liability considerations are involved in an appropriately devised exit strategy for any enterprise.  This could be in the form of a backup method for establishing redundancy.  For many businesses, the cloud use transitioning process is key for being able to maintain reliable services.  Minimizing disruptions, goes without saying, is and should be a major concern for any enterprise to reduce its liability exposure.
Identifying the entities service points or relationships, whether they are internal to the organization or external, is likely the initial step to devising an exit plan for purposes of activating an alternative system.  Assessing the cloud service used as either IaaS, PaaS, or SaaS is needed in this step as well.  Each will require different activation steps and process for an exit strategy, keeping in mind that the replacement for either one of the three is not the same application and may raise different regulatory considerations.   Understanding its own cloud service methods and delivery system and its result, along with knowing its legal contractual terms is intrinsically pivotal for any enterprise transitioning their cloud business process.
 Also, the regulatory requirements must also be attended to in order for an enterprise to devise a transitioning plan for its cloud service, especially when the service is uniquely designed for its industry or service class.  A company that uses SaaS may experience that its replacement during a transition cannot be operative with an IaaS, though they may appear similar technologically.  The process is key to note for considering the compliance requirements and the service delivery method that is required, in order to reduce unintended consequences of the service adaptation.
 Moreover, the cloud service exit strategy and its implemented transitioning process should inherently have security as its heightened goal.  During any transitioning service period exiting a cloud service there will be the inevitable migration of data where confidentiality is critical.  Having the ability of continuing secure reliable service delivery must be considered including applying encryption and data retention.  The fear of the unknowns should always trigger careful assessment of the list of transitioning technical, legal, and regulatory compliance considerations to ensure limited disruption of the service that is provided to customers and the general public and that also relies on the featured services that are delivered by the cloud service provider or its ultimate service replacement.  While this may not be an exhaustive note on cloud service exit plan, that plan must also weigh the obvious availability options for alternative cloud replacements, way before there is ever the need for a transitioning strategy to be put in place.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."

Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  
 

Sunday, December 27, 2015

Indentity Theft Event Responses

Identity theft laws in states may vary by state but a notice requirement is common among them.  The frequency and extent of data breaches is staggering with the Identity Theft Resource Center (ITRC) recording over 700 breaches so far recorded in 2015 affecting roughly 200 million records.  The previous year, the ITRC recorded for 2014 over 780 data breaches.  The numbers include inadvertent breaches along with data theft events.

As companies look for ways to prevent data breaches and be compliant with identity theft laws, it is fundamentally productive to as well focus on enhancing an incident rapid response process.  This concern is shared by the private sector as well as the public sector.  The aspect of immunity is a commonality among industries and sectors. The data breach events have affected the healthcare industry with Anthem’s February 2015 incident affecting over 70 million healthcare customer records, approximately 20m at the U.S. Office of Personnel Management in June, as well as Georgia’s Department of State registered voter records were affected with over 6 million potentially determined to have been disclosed.  The breach disclosed social security numbers as well as private information as a result of a claimed clerical error.

According to Georgia law, the Georgia Department of State is required to share voter registration data upon request from political parties and the media.  As a result of several disks containing social security numbers and private information being received by the recipients under the law’s requirement, two-class action suits have been filed.  The breaches were publicized after the suits were filed and the claimants are asserting that the responses were inadequate.

States like South Carolina, since its 2012 Dept. of Revenue data breach incident affecting nearly 4m individual social security numbers, are providing credit monitoring, mitigation services, plus credit protection to their affected citizens.  All these incidents underscore the need to enhance rapid response processes in addition to protection mechanisms and personnel training.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Saturday, December 26, 2015

Anti-Slapp in Florida


Anti-Slapp in Florida was put to the test in Roca Labs, Inc. v. Consumer Opinion Corp.(Pissed Consumer). In its original lawsuit, Roca Labs argued that the defendant’s consumer review website was fostering defamation, effectively causing tortuous interference, committing unfair competition.  The defense argued immunity under Section 230 of the Communication Decency Act, formally known as Internet Freedom and Family Empowerment Act.

 
The court determined that defendant’s posting of just excerpts of the post placed by the user were not actionable.  It followed the Roommates.com case where the court there reasoned that trimming user’s posts for space purposes is not illegal nor does it constitute defamation.  The court distinguished when a post is made by a third-party user.  The court went further in that it cleared the use of tweet aliases and the links to original posts.  Also, it cleared user feedback and rating systems under Section 230.  The court noted that plaintiff’s assertions that defendant allowed for menus selections and drop down buttons were not convincing to sway against triggering immunity under Section 230.  The court acknowledged that posters can be paid to place testimonials on defendant’s website.

 
The court was not convinced that the defendant was liable under the Fair Trade principles as Roca seeks to impose liability under Florida Deceptive and Unfair Trade Practice Act (FDUTPA).   The plaintiff argued that the posts had an effect and that the defendant refused to remove the posts.  As the court followed the reasoning in Ascentive v. Opinion Corp. it concluded that the liability posed by these claims were specifically precluded by the effect of Section 230’s intention.  Moreover, on the tail end with defendant seeking attorney fees, the court reasoned that by virtue of it ruling that defendant was immune under Section 230, it does not automatically constitute that the plaintiff raised a frivolous suit nor can it find that plaintiff presented a case in bad faith to award attorney fees under the court’s inherent sanctioning power.
Roca Labs, Inc. v. Consumer Opinion Corp., 2015 WL 6437786 (M.D. Fla. Oct. 21, 2015)


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Wednesday, December 23, 2015

Crowdfunding and New Conditions

Crowdfunding, an Internet based means of raising capital is getting a lot of attention.  The attention it has garnered is not only from businesses resorting to it but from the SEC as well.  Crowdfunding is instrumental for startups and small business, but it has originally been a vehicle for fund raising for worthy and charitable causes.  The function has been through for a variety of methods and purposes, for instance, by donations for charitable purposes, by issuing rewards; by providing a lending process in exchange for the promise to pay timely with accrued interest; and by equity interest based contributions. Crowdfunding and its new limits are addressing the function when the operation is to embed a securities-based crowdfunding offering. This is a variation from what traditionally is being done by businesses where raising capital is by virtue of seeking a commercial loan.
 
The SEC has stated that any offering or sale of a security must be registered unless there is an applicable exemption.  The requirement of disclosures are a key element to qualifying for an exemption from the registry requirement.  Additionally, small businesses seeking funding have to meet other federal and state laws that regulate offers and sales of securities.  Yet, because of the burgeoning interest in raising needed capital in this novel internet based vehicle, the SEC this October depicted crowdfunding and its new limits regarding securities based offering through online platforms.
 
Under its Jumpstart Our Business Startups (JOBS) Act section 4(a)(6) to the Securities Act of 1933, the SEC allows offerings through internet network platform without registering and preempts the state registration requirement. It addresses those crowdfunding vehicles of companies seeking security-based capital, but it established a cap of 1 million a year (12 months) with an individual investor limit of $2,000 or 5% of investor’s income if the investor’s net worth is less than $100,000.  The personal investment limited inches higher the higher the net worth of the investor.  The company issuing the offer will have to file electronically its disclosures and details for public viewing (form c).  The account opened by an investor will be done through an intermediary and its rules, where it may decline an issuer on its internet platform for reasons that may include fraud and is tasked to provide issuer’s disclosures.  As these conditions take form in 2016, small business have a greater chance of raising the necessary capital through crowdfunding.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Tuesday, December 22, 2015

Cybersecurity Buzz in Washington

Cybersecurity is at issue and a buzz in Washington with a bit of urgency and cluelessness.  From addressing anti-hacking methods to cyber security threat sharing, Congress, federal agencies, and the White House are trying to flatten their learning curve.  Private companies have been drawn in to give their two-bits and compare notes on cyber security threats.
 
Now with the House passing of the Protecting Cyber Networks Act (H.R.1560) (“PCNA”) and the National Cybersecurity Protection Advancement Act (H.R. 1731) (“NCPAA”) the dialogue on cyber threat sharing has covered both the concern for privacy and the manner in which to report cyber threats.  Additionally has been the query of designating the role of “portal” companies that would be tasked to report cyber threats.  The additional consideration is with the assigned role of the Department of Homeland Security as it could be earmarked as the portal for civilians.  The notion is not to house the reporting auspices within an agency having prosecutorial responsibilities.   But the weakness considered by privacy advocates is the inherent provision allowing the President the opportunity to appoint an alternate civilian portal, which could essentially open the door for government surveillance.   
 
Within the Cybersecurity buzz is as well the anti-hacking topic floating around as a result of the House Cybersecurity Caucus members urging the White House to change its draft regulations on ‘hacking tools.’   The private sector view is that the regulations are not based on a well-founded understanding of the distinction between defensive and offensive cyber tools.   While the stated goal is to prevent technology from getting in the hands of countries with undemocratic governments, the differing roles noted for the vying federal agencies, could instead impinge the efforts of U.S. private companies striving to protect their technological infrastructure and networks.
 
The wrinkle to addressing this is that the Department of State, the Department of Commerce and the Department of Homeland Security have different views on how the 2013 Wassenaar Agreement should be amended.  The Agreement has an expanded list of restrictions on dual-use technologies, including Internet-based surveillance systems and intrusion software.   Such technologies would be used to pressure and restrict journalists and governmental critics.  As is, the defined scope of ‘intrusion software’ appears too broad which will serve to prohibit U.S. companies from exporting technology they use to test their vulnerabilities and assists them on discerning where to implement cyber security improvements in their networks.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Monday, December 14, 2015

Idea Patent


Many consider having an idea into a patent and living the entrepreneurial dream.  For those who enjoy abstractions that is the beginning of something that could be valuable for all to use.  Many clients have the same query, “I have an idea and would like to know how to protect it.”  Ideas are not expressions that can be covered under the Copyright Act.  Ideas are not inventions for them to be covered by the Patent Act.  While all start from an idea per se, it is the kernel of what make it ‘intellectual property.’  Without that ‘kernel’ there would not be the exclusive right that would be attributed to the resulting item.   

The struggle for many clients is how to take the idea into a patent and draw it to the point of it being concrete so that it is no longer a concept.  So while an idea cannot be protected that should not be the final step.  The idea merits functional description and descriptive application and implementation.  Hence, the preliminary juncture toward a patent, i.e., an invention.
 

Business methods and ideas have gotten an outside corner 92 mph slider since the Alice decision* where the court weighed that a  computer service for financial transactions was abstract and not sufficiently tangible for it to be considered a patentable subject matter.  The take away from the Alice decision was that business methods or software were to be considered the same as was the computer service in Alice.  The conceptual turn that shines a bright light is the language from the decision in the Finjan case, whereas Finjan claimed, its invention was not abstract because it is based on computer technology and it seeks to address a tangible problem that occurs in computers.  It also argued that its claim was essentially a technical function for protecting computer networks.

In its argument, Finjan resorted to the Patent Office’s Interim Guidance on Patent Subject Matter Eligibility” of 2014.  In the Guidelines, there was a similar hypothetical to the actual claim that Finjan was seeking to establish in the case which related to detecting and removing malicious code from communications.  The court, while noting the stated guidelines and the similarity, therefore reasoned that what Finjan was claiming was not an abstraction nor was it an abstract idea.  It determined it to be a ‘function’ of software to ‘achieve’ the elimination of malicious code in electronic communications.  The court decided that the claimed patent had described identifiable steps to the claimed performance that as identified was to recognize the intrusive malicious code, remove it, and create a security file.  This, the court stated, has meaning nowhere else but within computer technology.  The lesson to be drawn from this case was that the initial idea was coupled with a descriptive functionality that achieved an identifiable result.  
 Finjan, Inc. v. Blue Coat Systems, Inc., Case No. 13-cv-03999 (11.20.15) (NDCA)
 *Alice Corp. v. CLS Bank International, 573 U.S. __, 134 S. Ct. 2347 (2014).


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.  

Saturday, December 12, 2015

Internet Product Listing Infringing on Trademark


 
Internet product listing was argued to be infringing on the trademark of a watch manufacturer.  The watch manufacturer argued that it did not sell its watches to Amazon for resale nor did it authorize resale through the online retailer. The plaintiff in this case, Multi Time Machine (MTM), argued that the online retailer, Amazon was creating customer confusion.  It further elaborated that the search result format would confuse the potential customers.

Online retailer, Amazon, was sued for trademark infringement because it argued that Amazon was placing the MTM product online in a manner for when customer would search for their product watches.


The record showed that Amazon would display an image list with product names under a certain class of product.  By clicking on the image, the potential customer would be directed to the product page with the customers search term request remaining active in the search box.  The court noted that Amazon did not disclose to the potential customer that it did not carry the MTM product.  Evidence was introduced demonstrating that defendant's competing online retailers did disclose that they did not carry the plaintiff’s product. Question was posed as to why the defendant did not disclose it.


As the court weighed the evidence and expert testimony to determine the extent of potential confusion, it examined ‘initial interest confusion’ and not necessarily how customers purchase.  The court reasoned that initial interest confusion in and of itself is a trademark infringement in the goodwill associated with the plaintiff’s mark.  The online retailer would then benefit from the value and reputation of the plaintiff’s product through the effect of search results being ‘ambiguous, misleading, and confusing.’

The court also weighed into the relative strength of the plaintiff’s mark of its product.  In that analysis, coupled with the assessment of factors leading to the likelihood of confusion, the 9th Circuit on appeal reasoned that a jury could find the likelihood of confusion due to the fact that the plaintiff and defendant sell military-style watches.  More importantly, it concluded that that the jury would find that the defendant could confuse the potential customers. Multi Time Machine, Inc. v. Amazon.com, Inc. Case No. 13-55575 (9th Cir. July 6, 2015)
 
Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web."
Copyright 2015, all rights reserved Lorenzo Law Firm, P.A.