Tuesday, February 14, 2017

Data Security Negligence


Data security responsibilities are, at times, not met with the requisite level of diligence for compliance.  Standards for compliance, for many businesses, institutions, and service entities, are not as specified as one would be drawn to believe.  The disjuncture between responsibilities and efforts are becoming more evident with passing days as cyber incidents leave alarming concerns with consumers and business establishments.

Commonly prescribed is that personal data embedded in digital record transmissions must be transferred securely.  However, the level of confidence that a service consumer, medical patient, loan customer, or even a student at an ATM demonstrates daily with their every swipe and approval is in the unseen information processing that the venue operates with, in order to provide the desired service.  If that confidence is shaken with the notion that the private information is not being handled securely, the digital transactions will experience a hick-up and the public consumer will seek other means to transact, and back to cash and brick-n-mortar, we go.  The integrity of the secure appearance of the merchant is held questionable and tenable.

At the point of transaction, the consumer is left with the confidence that the banking information provided to the institution is securely being transmitted and that the data is accurately being recorded, especially as balances are verified.  But what if the measures are not followed by the merchant?  How should a cyber incident be considered when negligence is involved in the cyber mishap? Who is to be held accountable for needing to demonstrate meeting the duty of care?

Negligence was an issue in In re Hannaford Bros.[1]  This Maine District Court case involved the data security incident arising from a third party stealing the consumer data from grocery transactions.  The question raised in the case was whether a customer can recover from the grocer for loss resulting from the third party’s data theft? It is conceivable that from the consumer point of view there will be the tendency to enjoy the convenience of the digital transaction by use of credit card at a store.  Yet, with the convenience, there is also the risk of fraud and misuse of the account information, i.e., PII.[2]  The average consumer believes that the law should address and protect their PII in circumstances where confidential information is stolen and allow for redress against the merchants and financial institutions. But how negligence should be analyzed in cyber incidents is a bouncing question dealt with traditional tort concepts of duty, breach, and causation with the ultimate tangible injury.  Long have been the treatment of analysis under Article III to settle in each case the criteria of requisite case and controversy.

Negligence, however, seems to stand on an island in cyber incidents.  To the individuals who have been affected by a cyber incident, the risk of fraudulent use of their account information is very real.  So, the argument goes that the law should provide some form of protection. How that protection is conceived is still debatable.  The grocery establishment in Hannaford Bros, typically argued that the law already provides protection to consumers by agreement.  For instance, by the provision of the Electronic Fund Transfer Act, which limits a consumer's liability for fraudulent debit card transactions to no more than $50 (or, if the consumer fails to notify his bank "within two business days after the consumer learns of the loss or theft," no more than $500). 15 U.S.C § 1693g(a).  Defendants usually argue that as well, the industry provides similar limits through contractual agreements with credit vehicles and associations such as Visa, MasterCard, etc. The store merchants will always seek to have the courts impose responsibility on the banks that issue the cards in order to facilitate any recourse to the consumer. So the cyber incidents that pertain to the misappropriation of digital transaction data pivot the consumer against the financial institutions to the liking of merchants or against the merchants to the liking of the financial institutions.

In the Hannaford case, the plaintiffs found themselves pivoted as such towards the merchant to determine the level care that the merchant undertook to care for the digital data of the credit and debit card transactions. The Plaintiffs argued that “... [they] made use of debit cards and credit cards issued by financial institutions to access their bank accounts or create credit relationships." Furthermore, that the merchant “provided electronic payment services," but failed "to maintain the security of private and confidential financial and personal information of ... credit and debit card customers" at supermarkets in . . .” in several states, including Florida.  Hannaford did not argue that it was not subject to a reasonable duty of care consideration, but what was pointed out was that it believed that it was not subject to an economic loss consideration arising out of the traditional personal injury and property damage considerations.  The court stated that “in a grocery transaction where a customer uses a debit or credit card, a jury could find that there is an implied contractual term that Hannaford will use reasonable care in its custody of the consumers' card data, the same level of care as the negligence tort . .”  Hence, the conclusion was that consumers can recover when payment data are stolen, against a merchant, if the merchant's negligence is the direct cause of the loss in the customer’s account.  In this case, the negligence analysis was drawn to delineate breach of a duty of care and causation of the loss of data security.

[1]In re Hannaford Bros. Co. MDL Docket No. 2:08-MD-1954. United States District Court, D. Maine. May 12, 2009.

[2] Personal Identifying Information
Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2017, all rights reserved Lorenzo Law Firm, P.A.
 

Wednesday, January 25, 2017

Internet Mugshot Publishing Curtailed

Internet mugshots published online haunt many for years with embarrassment.  For many, as well, the mugshots do not bear a meaningful purpose for others throughout the Internet to know.  What remains is the ill circumstance of having future employment out of reach or present employment terminated, for the inadvertent past event. The harm lingers for years.  For years’ individuals who have had a mugshot taken for a past event, have been solicited by mugshot publishers to offer their removal or correction for a fee and have been pressured into having to pay a mugshot publisher for its removal or correction.  The concern is over this business practice by Internet mugshot publishers of seeking payment for removal or correction, essentially extorting individuals.

Now Florida is joining California, Colorado, Oregon, Georgia, and several others seeking to regulate the mugshot publishing business.  The Florida legislature is considering a provision to amend Sec. 943.0585 Florida Statutes.   This amendment provides restrictions on businesses that publish on the Internet booking photographs.  They are not to solicit or receive a fee for removal.  This fee prohibition also applies for correction requests or modifications of such photographs. During the 2017 legislative session, the Florida Senate in SB 118, will place a provision long awaited by individuals who have had the grief of their photo being propagated on the Internet for a fee.

The amended provision by the Senate states as follows: “(1) Any person or entity engaged in the business of publishing or otherwise disseminating arrest booking photographs of persons who have previously been arrested through a publicly accessible print or electronic medium may not solicit or accept a fee or other form of payment to remove, correct, or modify such photographs.  The provision also states that there is a time limit by which requests are to be responded and handled by the mugshot publisher.  The provision states “Upon receipt of a written request from a person whose booking photograph is published or otherwise disseminated, or his or her legal representative, the person or entity who published or otherwise disseminated the photograph shall remove the photograph without charge within calendar days after receiving the request for removal.

The legislative effort is not without teeth in that it provides for enforcement.  Such enforcement allows for civil remedy.  The provision states “The person whose arrest booking photograph was published or otherwise disseminated in the publication or electronic medium may bring a civil action to enjoin the continued publication or dissemination of the photograph if the photograph is not removed within 10 calendar days after receipt of the written request for removal.”  If the mugshot publisher does not timely comply with the request to remove or correct the publication from a person whose arrest booking photograph was published or otherwise disseminated in the publication or electronic medium, a civil remedy of $1,000 for each day of noncompliance will be imposed along with an injunction.  Attorney fees are as well provided along with court costs related to the issuance of the injunction.

Compounding the strength of the provision is the allowance for the consideration that if the request for removal by a person whose arrest booking photograph was published or otherwise disseminated in the publication or electronic medium is refused after there has been a written request, such refusal will be deemed as an unfair or deceptive trade practice in accordance with part II of Chapter 501, Florida Statutes. The caveat to note is that this provision does not apply does not apply to any person or entity that publishes or disseminates information relating to arrests unless the person or entity solicits or accepts payment to remove the information.  Nevertheless, the concerns shared by many about their past and having the need to correct a record or to remove a digital online publication of a mugshot, are being now addressed in Florida.

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2017, all rights reserved Lorenzo Law Firm, P.A.
 
 

Monday, January 9, 2017

Internet and Deceptive Advertising Vindicates the FTC

Internet advertising has become intricate and keen.  Internet advertising may involve multiple participants.  The purpose is essentially to sway readers to purchase products by making representations that at times appear too good to be true.  That is what the Federal Trade Commission and the State of Connecticut determined prior to suing  LeanSpa.  The claims embraced issues of false information to convince consumers on the legitimacy of the product.  Consumers were drawn to LeanSpa’s online sales site using story lines about users who did not actually use the product.  Shipping and handling costs were passed down to the consumer while representing the that the consumer was receiving free trial.  This story is all too common on television infomercials.

What was critical to the analysis undertaken by the court was that the charges assailed against LeanSpa and its principals involved the violations of several regulatory provisions, i.e. as for Connecticut, the Connecticut Unfair Trade Act and federally, the Electronic Funds Transfer Act (EFTA) and Sections 5 and 12 of the FTC Act.  The findings revealed that there were misleading claims made about the weight-loss potential of the product being advertised.  There was also the enticing method of stating ot the public that they can received free trials of the product but that they had to pay a shipping and handling.  This sales method had a reoccurring function that was difficult to cancel.  The consumers were trapped with monthly shipments.  That triggered the EFTA which states conditions for transfers and consumer right to notifications and process.

The FTC, LeanSpa and principals entered a settlement that set requirements for disclosure about terms of refunds, endorsements, and of the trial promotion itself, involving the charges and the ability of cancelling.  The defendants had to provide disclosure that the endorsements were actors and not actual users.  They also had to engage in clinical trials that would substantiate their claims for the effects of the product being sold and to also substantiate that their product had undergone clinical trials.  The FTC was imposing the requirement of having competent and reliable scientific evidence.  

Subsequently, the FTC amended its complaint  asserting claims on an affiliate marketing network operator LeadClick that allegedly swayed shoppers to LeanSpa’s web store.  The news appearing presentations appeared realistic to consumers about the weight loss benefits and experiences.  The news appearing statements were never clarified to consumers for them to learn that they were actors and not independent news outlets.

The function and roles between product company and marketers distinguished, revealed elements of liability that the FTC could not ignore and that the court noted.  A program called HitPath was used by LeadClick. This program would register the clicks and would recognize to which account it would be attributed. The system would recognize the affiliate that was responsible for the lead in by the consumer to the product.  This information allows the marketers to allocate appropriate compensation to the affiliate, i.e., commission.  The marketing campaign was deemed suspect by the FTC and essentially the court in its decision.[1]

The Second Circuit determined that LeadClick’s marketing campaign was liable for systematically conducting a program that deceived consumers noted levels of transactions.  While defenses were raised, the discussion dealt with the depiction of the defendant’s role on the marketing process with affiliates, placements of ads and sales, creation of ads, and potential immunities under Section 230 of the Communications Decency Act.  The court looked into the revenue stream between the merchant clients, the affiliates, LeadClick, and LeanSpa.  The court also determined the creation of the ads via false news representations.

What the court determined demonstrated that while creation of the news sites did not originate with the defendant, there were other pertinent aspects that drew liability to the defendant.  The court found that the defendant knew that affiliates were using fake news to sell the LeanSpa product.  The court also became aware that the defendant approved the ads, as well, the defendant provided content for the ads. These three aspects drew direct liability to defendant and demonstrated direct involvement on the marketing plan toward consumers.  The defendant, per the court, was aware of the deception and did not curtail it nor stop it.  Hence, the defendant was deemed directly liable under the FTC Act.  The defendant in response claimed that its actions were so similar to aiding and abetting liability. Yet the court determined that the defendant’s actions contributed to the deception on consumers and it was not tantamount to eh exception under the FTC Act.   By the defendant purchasing ads and providing content it is liable.   Having knowledge that the third-party marketers were using false information,[2] attributed liability to the defendants.  The Second Circuit noted that the Eleventh Circuit, previously found the FTC to have provided the requisite evidence to demonstrate liability by virtue of the defendant’s knowledge of third-parties’ false statements to consumers. It as well found that the Ninth Circuit, in FTC v. Neovi, Inc.[3] had determined liability of the defendant by it having caused the harm not just aiding.

While defendant defended by claiming to be immune under Section 230 of the Communications Decency Act (CDA), the court artfully informed that defendant that “grant of immunity applies only if the interactive service provider is not also an ‘information content provider’ of the content which gives rise to the underlying claim.”    The court also stated that an information content provider within the CDA is “any person or entity that is responsible, in whole or in part, for the creation or development of information provided through the Internet or any other interactive computer service.”  Since the defendant was the content provider and writer exerting discretion, it was not immune from liability. The court deemed the defendant as participating in the placement and publishing of the content. LeadClick’s participation was ‘material’ to the deceptive content.

The decision out of the Second Circuit sends signal to marketers to beware of the its content and affiliates representation.  The effort to be at arm’s length may not be enough to shield it from liability under the FTC Act or to claim immunity under the CDA.  Disclosures are becoming more of the norm in consumer protection regimes with endorsements clarified as to their identity to avoid misrepresentations.




[1] Federal Trade Commission v. LeadClick Media, LLC, (2nd Cir. 2016).
[2] See FTC v. IAB Mktg. Associates, L.P., (11th Cir. 2014).
[3] See FTC v. Neovi, Inc., (9th Cir. 2010).

Wednesday, December 28, 2016

Cyber Security Claims


Cyber security claims are seldom tempered with an entities acknowledgement of its insecurity of electronically stored information (ESI) and handling of consumer personal identifying information (PII).  The efforts and planning executed, though they may be diligent, they cannot anticipate cyber incidents and breach incidents nor should their efforts to prevent them be overstated.  All attention by entities appears to be dedicated on external caused anticipated incidents and little is focused on the internally sourced events.  Seldom do entities envision the internally sourced incident, such as human error, theft, or neglect.  Balance is required and much care is needed before publicly claiming the quality of its data security.  For instance, the risk from internal unauthorized access to trade secrets leading to misappropriation is realistic, yet under appreciated.  This is not to spawn an environment of distrust in the workplace.   Of course, it is difficult to swallow that employees would pilfer company knowledge, designs, formulas, or even the companies R&D new software specs for self-gain.  Word to the wise if you are a business, swallow it fast and be ready.  Since the vulnerability can arise from external as well as from internal actors any claims to the public of the quality of handling data securely is being assessed as a possible business representation.  Such cyber security claims should consider internal vulnerabilities to data handling and as well as the externally sourced causes that we read too much in the news.

From an internal point of view, a business’s or agency’s imminent vulnerability is through personnel and their mishaps, forgetfulness, or deliberate sabotage.  This of course is in addition to external concerns.  Always the employee with the increasing frequent absences draws a cause for concern and some form of a query, especially an employee who has access to critical company information.  This concern is so realistic that it has motivated states to promulgate their own version of a uniform rendition on trade secrets and provisions addressing computer crimes.  Some promulgation allows for civil and monetary remedies when business data is compromised because of someone exerting unauthorized access either internally or externally sourced.

With the ease of ESI transmission, unauthorized access becomes all too prevalent for the business insurance companies to fathom the risk.   This reality is augmented by the anonymous activity through shadow bots, exchanges and other means that leave the business owner holding client data, innovative plans, beta testing new processes, without protective leverage.  Backdoor access is always a possibility especially among those of trust who have a mutual gain in the prosperity of the enterprise.  Worst case events are what gave rise to FUTSA and CADRA in Florida[1]  and many other states that appreciated the seriousness.

The insecurity of data security in the cyber world, unfortunately, is by the nature of storing ESI and transmitting ESI in our day-to-day business endeavors.  Customer information, as well as business assets, are at play in the realm of cyber insecurity.  Security is only as secure as the weakest link in the chain of transmission.  As vulnerability is realized in its present state, the urgency then is to focus not only on firewalls and other aspects but on internal employee training, policies, non-disclosure agreements, vendor contracts, vendor’s due diligence to cyber security, cyber insurance policies (vendors cyber insurance) and their coverage reviews, and vetting vendors’ cyber liability coverage before inking a deal.

Can a business claim safeguarding its data assets to engender public confidence in the security of ongoing credit card transactions, storage of its personal account information, the transfer of its customers’ medical records, or the updating of financial records, if it has not properly vetted its vendors' cyber security practices?  The qualified claim itself draws also the risk of misrepresentation before the regulatory eyes of the Federal Trade Commission.  ESI is business as usual and the role of risk management is to realize not only the external aspect of cyber intrusion but to also balance that attention with internal constructs to anticipate the unpredictable.

It is obvious that consumer data security claims by many businesses seek to settle the fears and doubts of many consumers engaging in electronic payments.  however, those representations should be tempered with an accurate description of its practices to keep consumer information and transaction data secure.  Such claims if proven to lack implementation, the claimed training, diligent assessment and evaluation, investment in reasonable resources, or even testing, will be scrutinized.   Several agencies have been tasked with a different scope of authority to do that.  It is important to note that data security has been allocated to be under the auspices of the Dodd-Frank Act.[2]  Information protection regarding consumer confidential information has been the responsibility of the Federal Trade Commission under Gramm-Leach-Bliley Act. Deceptive business practices of covered financial institutions fall under the Consumer Financial Protection Bureau (CFPB), section 1031(a) and 1036(a)(1) of the Consumer Financial Protection Act of 2010, for the purposes of enforcing federal consumer financial laws.

The veracity of business claims of protecting consumer data and payment processing is a candidate for scrutiny.   Failure to meet the security claims will be deemed as a deceptive business practice.  The CFPB has stressed the importance of attending to the integrity of digital payment system security.  It has as well emphasized the growing reliance and trust that consumers are displaying entrusting their private information and financial information as they execute electronic transactions. In a recent press release, it has stated: “It is crucial that companies put systems in place to protect this information and accurately inform consumers about their data security practices.”

While the FTC, Office of the Comptroller of Currencies (OCC) and other federal banking agencies are authorized to police the handling of data security, the CFPB which is tasked to review consumer information of financial institutions, reviews the processes of online payment platforms.  One incident worth noting in this post, is the CFPB's review of the claims made by Dwolla, Inc.  Dwolla is an online payment transaction platform that had provided payment processing services through the Department of the Treasury’s payment portal.  In an Order issued in CFPB's administrative proceeding, Dwolla  was determined to have committed deceptive data security representations to the public.  The consent order states that Dwolla’s communications made false statements about its data safety processes, e.g., of its use of encryption, that its practice surpassed the Payment Card Industry (PCI) standards.  Conversely, the CFPB asserts that Dwolla did not do several of the following, though Dwolla claimed to do so: provide acceptable data security training to its employees, establish acceptable and appropriate date security policies and practices, timely and regular risk assessments, and use encryption. These aspects are considered crucial in the pursuit of providing data security and claiming a level of quality to the cyber security in place.

The order also outlined a list of actions required to address the findings with a five-year horizon within which Dwolla is ordered to comply with the stipulated items, report the actions taken to remedy the findings, and to record all implementations and findings, and continuously submit as scheduled monitoring compliance reports.  From this case financial technology businesses involved in payment processing should carefully screen their representations on their communications, websites, advertisements, and press releases, related to their practices and standards.  Failure to apply what is claimed to be in practice and failure to not exercise due diligence in safeguarding confidential financial consumer information will be punishable devoid of there ever being consumer harm.  Advertisements and marketing efforts in this competitive and growing payment processing industry should be tempered with a sober realization of what is implemented in the daily cycle of transactions and in the keeping of records.   Thus, a fine was imposed on Dwolla, that had to be paid within ten days of the order and they will be monitored for the next five years.

The lessons about handling data security are hard to learn when an entity becomes subject to a cyber incident or a regulator seeks to audit processes.  What can be said about cyber security and any claims about how it is employed, is that upon a cyber incident hitting one's business or entity, all will be scrutinized by outside individuals claiming damages and by the regulators asserting that reasonable diligence was not employed to secure ESI and secure consumer personal identifying information (PII).  Transparency will soon be forced upon to the chagrin of the business or entity that experiences a cyber incident whether internally or externally sourced, or is found after an audit that it is out of compliance. Hence, cyber security efforts need to be assessed before there are any claims and such efforts must be evaluated, tested, and improved upon.

 

[1] Florida Uniform Trade Secrets Act (FUTSA), Chapter 688, Florida Statutes; Sec. 812.081, Florida StatutesComputer Abuse and Data Recovery Act, Sec. 668.801, Florida Statutes (“CADRA”).

 

[2] The Dodd–Frank Wall Street Reform and Consumer Protection Act (Pub.L. 111–203, H.R. 4173; commonly referred to as Dodd-Frank) was signed into federal law July 21, 2010.

Saturday, October 22, 2016

Trade Secrets in Databases


Database as a Trade Secret

Trade secrets in database records fall victim to many who seek the potential value of stored records from a variety of entities, either from government agencies and competitor businesses, to also include medical and financial enterprises, and even from their own employer or client.  Intruding into another’s database is becoming too common in our economy and database intrusion was a pivotal issue in a landmark Ninth Circuit case, United States v. Nosal.  While the case largely engaged discussion on the scope of the Computer Fraud and Abuse Act (“CFAA”), 18 U.S.C. § 1030, the case also addressed the issues of trade secrets under the Economic Espionage Act (“EEA”), 18 U.S.C. § 1831 et seq.[1]  As the Ninth Circuit notes in its Order, Nosal was convicted on two counts of trade secret theft under the EEA.  Nosal was charged with unauthorized downloading, copying and duplicating of trade secrets and unauthorized receipt and possession of stolen trade secrets which violated §§ 1832(a)(2) & (a)(4) of the EEA.

The key to the analysis of the handling of the trade secret intrusion issue of the case was the sufficiency of the evidence to support a finding.  The Court weighed into the Economic Espionage Act and determined that the EEA requires that there be intent to convert a trade secret and intending or knowing that the offense will injure [an] owner of that trade secret.  In so doing it saw that the requirement of Nosal knowing that the receipt or possession of a trade secret with knowledge that it was “stolen or appropriated, obtained, or converted without authorization, was instrumental in laying the foundation for establishing the condition for a violation.  Though Nosal challenged the sufficiency by raising that the information culled was sourced from public records and that it could not be deemed as a misappropriation of a trade secret, or for that matter, a trade secret.

The Court made a clear distinction by analogizing the subject before it to other trade secret cases involving technical drawings, scientific formulas, specimens and data results in research, or aeronautical assessments in engineering designs. The Court reasoned that the EEA’s scope is not limited to select segments of the industry, but that the EEA encompasses financial and business information.[2]  While it cited the definition of trade secrets under the Act, it emphasized technical as well as financial and business information that is intended by the owner to be kept secret because of the economic value import of the secret itself.  Furthermore, the Court reasoned that its value was engendered by it not being generally known to the public.[3]  The Court opined that what Nosal sought and acquired was “classic examples of a trade secret that derives from an amalgam of public and proprietary source data”  and that the “data came from public sources and other data came from internal, confidential sources.”[4]  The Court gave import to the effort and system of research and algorithm employed to compose the record database that made it unique and not commonly searched information.

As the Ninth Circuit so clearly articulated about the characteristic of the data record sought by Nosal, “Instead, the nature of the trade secret and its value stemmed from the unique integration, compilation, cultivation, and sorting of, and the aggressive protections applied to, the Searcher database.”[5]  Its analysis borrowed from an Eight Circuit case, Conseco[6] and a Tenth Circuit case, Hertz[7] where customer lists were taken by employees.  The customer lists in question were unique by their form, manner of cataloging, and analysis that was involved in the list’s composition.  The Eight Circuit stated that they were trade secrets as they are ““specialized” computer program that was “unique” to Conseco.””  Similar to the Hertz case, the process involved to gather and organize the data made it a trade secret.

In essence, the purported value of a data record to be become and be considered a trade secret originates in the manner in which the owner pursued its composition, characteristic, cataloging, purpose, use, and its intended unique use and storage from others to use and see.  Its custodial handling is as well important to analyze, especially how it is dealt with in personnel policies and employment manuals for employees to follow and management to enforce.

[1] Computer Fraud and Abuse Act of 1986, Pub. L. No. 99-474. , § 2(g)(4), 100 Stat. 1213-15.  CFAA was later expanded to protect any computer “used in interstate or foreign commerce or communication.” Economic Espionage Act of 1996, Pub. L. 104-294, § 201(4)(B), 110 Stat. 3488, 3493 (codified as amended at 18 U.S.C. § 1030(e)(2)(B)).
[2] Order, Ninth Circuit, #14-10037, at p. 32.

[3] Footnote 15 of the Order stated as follows: Congress recently amended § 1839, replacing “the public” with “another person who can obtain economic value from the disclosure or use of the information.” Defend Trade Secrets Act of 2016, Pub. L. No. 114-153, § 2(b)(1)(A), 130 Stat. 376, 380.
[4] Order, at p. 34.

[5] Order, at p. 34.
[6]Conseco Finance Servicing Corp. v. North American Mortgage Co., 381 F.3d 811 (8th Cir. 2004).

[7] Hertz v. Luzenac Grp., 576 F.3d 1103, 1114 (10th Cir. 2009) (holding that a customer list may be a trade secret where “it is the end result of a long process of culling the relevant information from lengthy and diverse sources, even if the original sources are publicly available”).

Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.

Tuesday, October 11, 2016

Internet Information the Malady of Doxing, “You’ve been Doxed”

Internet information that is available to read on the Internet about someone or anyone to see is startling.  There is a lot to be said about the amount of information available on the Internet.  Many are surprised on how their information got on the Internet and the ease with which public information and personal information can be retrieved and researched.  It goes without saying about how freely users of social media disclose their personal information.  Some personal information may seem benign and harmless but put together with key identifying credentials and someone’s life is open for all to read on the Internet.  Data brokers play an integral role in the vast amount of aggregated information that floats around the Internet.
What others do with the available information on the Internet about someone presents the malady of doxing.  Why would it be important to anyone to know that a particular individual had a speeding ticket fifteen years ago, other than to a potential employer for employment involving driving? Why would anyone be interested that someone filed bankruptcy, other than an employer or a financial institution resorted to for a home loan?  There is indeed a lot that is unsaid about Internet doxing and where the line crosses into cyber bullying and possible online defamation.
At first blush, one would consider that publicly accessible information is benign and does not have weight to its impact on the person.  Furthermore, one would consider that the reporting of the researched information about someone is as well harmless, especially if the information is considered a public record.  What is missed in that calculus is the use of the information and the motive for sharing the information on the Internet.  What is also missed in that calculus is whether the information posted on the Internet about someone is factual and is it accurate.  This consideration raises defamation and invasion of privacy questions that could very well render the poster of the Internet content liable to the exposed talked about person.  Worse is when the person posting was negligent in posting on the Internet false information about someone.  The careless disregard for the truth by the person posting information and content on the Internet about someone else runs a great risk of facing a solid defamation lawsuit including other defamation related counts. Such careless disregard for the truth is compounded when that person knew or should have known the truth to be other than what was communicated on the Internet.
Simply speaking, retrieving otherwise private information about someone on the Internet may cross the line and essentially be considered a form of harassment or cyber bullying. States across the United States have promulgated such provisions addressing cyberbullying and online harassment.  Both California and New Jersey have vehemently addressed the problem with using the Internet to harass someone and New Jersey has even considered it a crime.  It is also outlandish to collect a person’s home address, date of birth, and other personal information through an unauthorized background check and drop it into the Internet realm without permission.  Such an act could face serious charges.
The damaging impact upon the doxxed individual is compounded by virtue of the Internet.  The original post could be deleted from the Internet but there is also the possibility that the posted content goes viral with hundreds or thousands of views and comments cross-linking sharing the post.  Of course, thus far this post has been referring to the indexed realm of the Internet that is captured by search engines such as Google, Bing, Yandex, Vimeo, Dogpile, and Yahoo, just to name a few.  The far open and far reaching content in the unindexed Internet realm stands to linger for years on the Internet and available for anyone to read.  As this post had briefly commented, the malady of doxing presents an unavoidable issue for everyone to wrestle with for years to come as information lingers on the internet as it is propagated further perpetuating its effect.

Originally posted at http://lorenzolawfirm.com/internet-information-malady-doxing-youve-doxed/.


Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.
 

Monday, September 26, 2016

Internet Speech Immunity

Internet speech immunity exceptions are sought frequently by individuals and businesses who are affected by someone else’s comments about them via an online site.  Online sites are today’s marketplace of ideas to enhance the “competition of the market.”[1]  And so, the claim usually asserted is a defamation claim directed to the website from where the content of the comment is displayed.  The assertion is underscored by a belief that the website is responsible for the publication of the statement either slander as it is conveyed verbally in a video or libel in written form displayed on a website.  The issue presented by the amount of social interaction freely exchanging views which may be directed at a particular entity or person is to determine the balance between freedoms of speech, i.e., protected speech and unprotected speech.  The element of having a harmful effect may or may not be pertinent in light of the level of publicity of the plaintiff, the truthfulness of the libel or slander, the public import of the statement, and the political value of the statement rendered to the discourse.
Amid the plethora of defenses that include truth, privilege, lack of malice, illegality, there is the social import or political value defense known as Anti-SLAPP.  The classical meaning of the acronym is to address the events that lead to a strategic lawsuit against public participation (SLAPP).  Anti-SLAPP was garnered by states to address the need to foster free speech and discourse, either in petition form or just free speech rights. The belief is that in the marketplace of ideas, with ideas being exchanged, an element of truth arises.  The expectation is that the process of openness of exchanges will bring to light incorrect conceptions.  The opposition to any light arising is based on this fear that their views may be rendered weak or incorrect in society; hence,  they seek to silence discourse and potential dissident views.
The merit behind the Anti-SLAPP promulgation was to essentially reduce the number of frivolous lawsuits.  Such suits would be driven to prevent or censor the speech or the activity of public display.  The concern among judges and lawyers is that a SLAPP action is always the case responding and opposing an exercise of free speech.  The SLAPP vehicle may be instrumental to challenge a lawsuit that seeks to silence free speech, especially if the targeted speech is one of public import or political value, even from the media.  But, when the targeted speech attempts to convey falsehoods to the public about a private person, the speech loses its protection.
However, the other concern is when the site is used as a platform to organize activity aimed at harming other people, equivalent to using the postal service.  Groups seeking to commit crimes against others, as in the facts described in Fields v. Twitter, use online platforms to carry out their plans.  The idea is that if the platform prohibited such communications, that act, and its involved communicated organization would have been prevented.  That expectation of monitoring conduct touches upon “policing” issues and “privacy” issues that are beyond the scope of this post.
This previous concern leads into the consideration of when a site is used to voice negative comments about someone or a business and it is claimed to be the cause of  harming someone’s social and business reputation.  The argument asserted is that the site could have prevented the comments from posting trying to apply Section 230 under the Communications Decency Act (CDA).  The claim then seeks to establish that the online site is none other than a publisher and should be held responsible, especially when the comments could be fabrications used by the online site.  This was the tone of the claims and discussion in Kimzey v. Yelp.
What stands out in Kimzey is the angle that transcends from allowing a statement or comment to be displayed towards seeking to establish that the comment was a fabrication and that it was instrumentally contrived by the online site itself.  The argument goes that the online site authored the review and used it as a marketing means.  The court stressed that arguing the potential falsity of a comment or review does not lend itself to disallow the online site’s immunity.  Furthermore, any assessment drawn by the online site to evaluate the comment by users is based on user comments providing the information or data that essentially provides the online site to evaluate the comment and establish a measuring or rating of the comments.  While there is a measure of discretion in setting the measuring, it is the users that provide the information that aids the Internet site’s grading of the comment pertaining to the subject who is claiming defamation.
The world of the web is here to stay and will be a part of our lives forever, especially as Internet law evolves.  As we continue to interconnect via mobile apps and the Internet our voices carry with a broader effect.  The uses of Anti-SLAPP to address silencing speech efforts or defamatory claims or the need to resort to Section 230 to immunize an online site from a defamatory claim for comments displayed on its platform are all instrumental in enhancing communication exchange in society.  As Oliver Wendell Homes, Jr. coined in his dissent in Abrams v. the United States, “The ultimate good desired is better reached by free trade in ideas — that the best test of truth is the power of the thought to get itself accepted in the competition of the market.”
[1] Quoted phrase of Justice Oliver Wendell Homes 1919.
Lorenzo Law Firm is “Working to Protect your Business, Ideas, and Property on the Web." Copyright 2016, all rights reserved Lorenzo Law Firm, P.A.