Showing posts with label cyberlaw. Show all posts
Showing posts with label cyberlaw. Show all posts

Thursday, November 21, 2013

Samsung Fined by Taiwan’s Fair Trade Commission for Astroturfing


On October 24, 2013, Taiwan’s Fair Trade Commission announced that Samsung was being fined 10 million New Taiwan Dollars for paying others to post negative comments about a business competitor on the Internet.  This act of masking paid content under the guise of Internet comments, blog posts, tweets, and other "grassroots" communications is known as “astroturfing.”  The fine equals roughly 340,000 U.S. Dollars.

Taiwan’s Fair Trade Commission opened its investigation of Samsung in April of 2013 amid allegations that the company was implementing deceptive advertising practices.  In particular, Samsung was alleged to have hired students to post negative reviews of rival handset-producer HTC while posting positive reviews of Samsung’s products.  At the time the investigation was announced in April of 2013, Samsung posted the following statement on its Facebook page, apologizing for any illegalities possibly committed by the company:

Samsung Electronics remains committed to engaging in transparent and honest communications with consumers as outlined in the company’s Online Communications Credo. We have encouraged all Samsung Electronics employees worldwide to remain faithful to our Credo. The recent incident was unfortunate, and occurred due to insufficient understanding of these fundamental principles.

Samsung Electronics Taiwan (SET) has ceased all marketing activities that involve the posting of anonymous comments, and will ensure that all SET online marketing activities will be fully compliant with the company's Online Communications Credo.

We regret any inconvenience this incident may have caused. We will continue to reinforce education and training for our employees to prevent any future recurrence.

As expected, the ensuing investigation found the allegations of astroturfing to be true with Samsung hiring a large number of writers to post negative comments about competitors in Taiwanese forums while heaping false praise on Samsung.  Taiwan’s Fair Trade Commission also levied fines on two Taiwanese marketing firms for a combined total of $100,000 for their part in the scheme.

This is not the first time Samsung has been implicated in astroturfing. In fact, this past August Samsung was accused of paying developers to promote an upcoming developer competition on the online community Stack Overflow.  However, Samsung claimed they were unaware that a public relations firm was offering cash on their behalf and the PR firm corroborated Samsung’s claim.


(Blog entry written by Alex Diamond, IBLT/Carter DeLuca Entrepreneurship Support Fellow for the Fall 2013 semester)


Thursday, January 31, 2013

Bird Watching: Twitter's Transparency Report


Following in the example of Google, Twitter is also releasing a semi-annual Transparency Report disclosing the number and type of user information requests it receives from various governments, and the percentage of the requests to which Twitter responded positively. In its most recent report, covering July through December 2011, Twitter stated that it had received 1,009 information requests, 42 content removal requests, and 3,268 takedown and related notices regarding alleged copyright infringement on the service. The former two numbers were up substantially from the preceding six month period; the copyright notices declined slightly (from 3,378 to 3,268) in that time.

Twitter additionally broke down the data by country, and specifically focused on its home country, the United States. According to Twitter, requests from governmental bodies within the United States from July through December 2012 included the following:

User Information RequestsPercentage where some or all information producedUser / Accounts SpecifiedSubpoenasCourt OrdersSearch WarrantsOthers
81569%114560%11%19%10%

As with that of Google, Twitter's transparency report is a useful reminder both of the attractiveness of social media services to governmental information gathering, as well as the overall privacy issues arising out of social media use. Law enforcement and other government officials understand how much information people share on social media services; it's crucial for users to understand this as well.

Thursday, January 24, 2013

The Other Google Search: 8438 Data Requests by U.S. Gov't


Google has released the latest version of its Transparency Report, covering the period from July 1 through December 31, 2012. In the report, Google states that the U.S. government made 8,438 requests of user data from Google during the period, covering a reported 14,791 users/accounts, and that Google responded fully or partially to an aggregate of 88% of those requests, broken down as follows:

July to December 2012

Records Requested

Users/Accounts

Percentage Fully/Partially Complied With

Search Warrant

1,896

3,152

88%

Subpoena

5,784

10,390

88%

Other 

758

1,249

90%

The number of of these requests, particularly from the U.S. government, has been steadily increasing over the past few years; the U.S. government made only 3,580 total requests in the same period in 2009. Google states in the introduction to its report, "We review each request to make sure that it complies with both the spirit and the letter of the law, and we may refuse to produce information or try to narrow the request in some cases." It also attributes some of the increase to its own growth: "Usage of our services have increased every year, and so have the user data request numbers."

While Google is to be commended for its efforts to disclose (some of) the requests for information it receives, the report and the increases it shows serve as a reminder of the size, scope and value of Google's collection of data about its users. Given how many products Google owns, many of which may not bear obvious Google branding (such as the Zagat Restaurant Guide) but may still be feeding user data into Google's central servers (Zagat's privacy policy is the Google shared one, as is that of its fellow non-obvious Google acquisition, the Frommer's Travel Guides site), one may legitimately question whether all users are able to provide truly informed consent to Google's data collection, which is increasingly a governmental resource as well.

Wednesday, December 12, 2012

Peter Fleischer, Other Google Execs Still May Face Jail in Italy Privacy Case

AP Image of trial court via KLEWTV.com
 In the latest installment in a case that highlights both the legal risks and absurdity of the cross-border nature of the Internet, the Milanese prosecutor in the case against Peter Fleischer and two other Google executives has asked an appeals court to uphold the six-month jail sentences they received in a criminal privacy case. The case arose out of a 2006 posting to Google Video by Italian teenagers of a short video of a learning-disabled classmate. Although none of the executives had any involvement with the posting or its prompt removal by Google Video after notification, they were still charged (along with another colleague, later acquitted) of violations of Italian privacy law. Fleischer, who was then Google's chief privacy counsel in Europe, was arrested when he traveled from his Paris office to Italy to give a lecture in January 2009. After the case came to trial, Fleischer and two of his colleagues (including Google's chief legal officer, David Drummond) were convicted in February 2010 and given six month sentences, automatically suspended under Italian law. The case was then appealed, leading to the latest development.

Fleischer, in a recent blog entry about the appeal, describes both the facts and the illogical nature of the case against him, given that he and his colleagues had nothing to do with the incident:

Under European law, hosting platforms that do not create content, such as Google Video, YouTube, Bebo, Facebook, and even university bulletin boards, are not legally responsible for the content that others upload onto these sites. But in this instance, a public prosecutor in Milan decided to charge us with criminal defamation and a failure to comply with the Italian privacy code.  None of us, however, had anything to do with this video. We did not appear in it, film it, upload it or review it. None of us knew the people involved or were even aware of the video's existence until after it was removed.
 This case, similar in many ways to the action in Germany against Compuserve's Felix Somm in 1996, serves as a stark reminder that those associated with companies doing business online may find themselves facing personal liability or even prosecution based on the laws of other countries, even when the individuals had no connection with the activity in question, and even when the activity was fully legal under the laws of the jurisdiction in which the company is based. While it is impossible to research and be certain of compliance with every relevant law in every possible country with access to the Internet, those who work for high-profile businesses, especially companies whose activities may potentially violate particular nations' cultural norms, should at the least be aware of these risks when considering business or personal travel to other regions. Companies, for their part, must include these risks in their overall assessments when choosing to do business online.

Wednesday, December 5, 2012

FTC Settles With Online Marketer Over "History Sniffing"



The Federal Trade Commission ("FTC"), the chief federal agency for consumer protection, has announced a proposed settlement with online marketer Epic Marketplace, Inc., over what the Commission called a "deceptive" use of a technology called "history sniffing." According to the FTC's release:

Epic Marketplace is a large advertising network that has a presence on 45,000 websites.  Consumers who visited any of the network’s sites received a cookie, which stored information about their online practices including sites they visited and the ads they viewed.  The cookies allowed Epic to serve consumers ads targeted to their interests, a practice known as online behavioral advertising.   
In its privacy policy, Epic claimed that it would collect information only about consumers’ visits to sites in its network.  However, according to the FTC, Epic was employing history-sniffing technology that allowed it to collect data about sites outside its network that consumers had visited, including sites relating to personal health conditions and finances. 
According to the FTC complaint, the history sniffing was deceptive and allowed Epic to determine whether a consumer had visited any of more than 54,000 domains, including pages relating to fertility issues, impotence, menopause, incontinence, disability insurance, credit repair, debt relief, and personal bankruptcy.
The technique used by Epic apparently combined two methods enabled by its cookie-placing network: seeing whether a user's browser program colored particular links to indicate they had been previously clicked, and accessing the cache (temporarily stored files) of the browser.

The proposed settlement order bars Epic from futher history sniffing, mandates full and accurate disclosure of Epic's information collection practices, and places restrictions and retention requirements on Epic's data collection and sharing. It does not, however, contain any financial penalties for Epic's conduct.

Tuesday, December 4, 2012

Blogger Settles Case with Former Employer Over Twitter Follower Ownership

Noah Kravitz' Twttter Statistics


The social media and technology blog Mashable reports that blogger Noah Kravitz has settled the lawsuit filed by his former employer, mobile tech blog PhoneDog, over the Twitter followers Kravitz kept when he left PhoneDog in October 2010 and changed his Twitter account from @phonedog_noah to a more personal @noahkravitz. The original complaint filed in the Northern District of California in July 2011 alleged that Kravitz' keeping the Twitter followers constituted misappropriation of trade secrets, intentional interference with prospective economic advantage, and other business torts. According to Mashable, the case has been settled through mediation.

The issue of ownership of a company's online resources, particularly those created and built by former employees on their own initiatives, is not new; in the mid-nineties, the New York Post had a dispute over the NYPost.com domain name with Farhan Memon, a former freelancer who had registered it during his work for the Post, and MTV had a similar conflict with its former VJ Adam Curry over the MTV.com domain Curry had registered. The Kravitz case, though, serves as a reminder that whenever an organization is being represented through an online presence, it needs to create and enforce clear guidelines in advance over who controls that presence, which should include ensuring that a single employee's departure (willing or otherwise) does not impede the organization's online efforts.

Sunday, December 2, 2012

Australian Federal Police Shut Down Romanian Cybercrime Ring

Australian Federal Police flag


The Australian Federal Police announced on November 29th that it had charged seven people in Romania for "the largest credit card data theft in Australia's history." According to the release, the investigation began in June 2011 based upon a referral from an Australian financial institution, and ultimately involved "numerous international law enforcement partners" including Romanian authorities.

The scope of the data theft is substantial: more than 500,000 credit cards were potentially accessible, with approximately 30,000 being used for "fraudulent transactions amounting to more than $30 million" Australian dollars. The cost of the fraud was apparently not borne by Australian consumers; instead, as in the United States, the issuing banks reimbursed the cardholders for the fraudulent transactions, which were performed throughout the world, including in Europe and the United States.

The case highlights the borderless nature of the Internet and the resulting challenges for law enforcement officials, as well as the significant financial exposure by companies and consumers for international (and local) data breaches and theft.

(Via @mukimu on ZDNet)

Friday, November 30, 2012

Risk Highlight: Syrian Government Turns Off Internet

In the latest salvo between the Syrian government and opposition forces, the government has reportedly used its control over Syria's telecommunications infrastructure to completely cut off the nation's Internet access. (The shut off can be seen in Renesys' Internet traffic graph for Syria, showing the complete cessation of all globally reachable Syrian networks between 10:20 and 10:30 UTC on November 29th:

Renesys Internet Traffic Graph for Syria

In response, other nations and companies have stepped in to try to provide at least limited connectivity to Syrians. Google has reactivated its Speak2Tweet service, although the limited telephone service in Syria may reduce its usefulness, and the U.S. State Department announced that it had previously provided 2,000 communications kits, with computers, telephones and cameras, that are "designed to be independent from and able to circumvent the Syrian domestic network precisely for the reason of keeping them safe, keeping them secure from regime tampering, regime listening, regime interruption."

Beyond the clear local and geopolitical aspects, this latest governmental cutoff of Internet access, as with the outages caused by recent storms in the United States, highlights that the telecommunications infrastructure on which businesses depend is largely out of their control. Effective risk management, involving backup systems, contracts, insurance and other means, must take that reality (and its potential implications) into account.

Sunday, October 7, 2012

Artist Arena pays $1 Million to Settle FTC COPPA Charges That It Illegally Collected Children’s Information

On October 4th, 2012, the Federal Trade Commission (FTC) and Artist Arena, a company that runs celebrity Web sites for music stars Justin Bieber, Rihanna, Demi Lovato, and Selena Gomez have agreed to settle for $1 million. The FTC charges that Artist Arena violated the Children’s Online Privacy Protection Act (COPPA) by collecting personal information from children under the age of 13, including names, addresses, email addresses, birthdates, and gender without notifying parents and obtaining their consent.

The FTC’s COPPA Rule requires that Web site operators notify parents and obtain their consent before they collect, use or disclose personal information from children under the age of 13. The settlement will impose a $1 million civil penalty on Artist Arena, bar future violations of the rule, and require that Artist Arena delete information collected in violation of the rule. In addition, for the next five years Artist Arena must prominently display a link to the federal Web site, http://www.onguardonline.gov/, in places where they collect personal data. Artist Arena also agreed to strict record keeping and compliance monitoring requirements over the next ten years.

The FTC alleges that Artist Arena, which is owned by Warner Music Group, knowingly registered over 25,000 children under the age of 13 and maintained personal information from almost 75,000 additional children who began, but did not complete, the registration process. The company falsely claimed it would not activate a registration nor collect children’s personal information without prior parental consent. Artist Arena has neither admitted nor denied the allegations but no longer allows children under the age of 13 to register as members of their fan sites.

The FTC Chairman, Jon Leibowitz, said:

“Marketers need to know that even a bad case of Bieber Fever doesn’t excuse their legal obligation to get parental consent before collecting personal information from children. The FTC is in the process of updating the COPPA Rule to ensure that it continues to protect kids growing up in the digital age.”

Businesspeople who want to learn about COPPA and how they can comply can visit You, Your Privacy Policy and COPPA - How to Comply with the Children's Online Privacy Protection Act for more information.

The complaint in its entirety can be viewed here. The consent decree, order for civil penalties, injunction, and other relief can be viewed here.

(Written by Jeff Wells, Fall 2012 IBLT Entrepreneurship Assistance Fellow)

Thursday, October 4, 2012

Recent Trend: States Protect Individuals from Employers' and Universities' Logging into Their Social Media Accounts

California recently passed a law that protects individuals from having to give potential employers their login credentials for various social media accounts. The law also prohibits universities from demanding the information from prospective students. The California law is a recent example of numerous states’ laws designed to protect employees/potential employees and students/prospective students.

The text of the employer law itself gives an incredibly broad definition of social media:
As used in this chapter, ‘social media’ means an electronic service or account, or electronic content, including, but not limited to, videos, still photographs, blogs, video blogs, podcasts, instant and text messages, email, online services or accounts, or Internet Web site profiles or locations.

The student protection bill has a slightly different definition of social media:

As used in this chapter, ‘social media’ means an electronic medium where users may create, share, and view user-generated content, including uploading or downloading videos or still photographs, blogs, video blogs, podcasts, instant messages, or Internet Web site profiles or locations.

 While the two definitions are different, they seemingly cover the same types of social media and should be broad enough to cover all forms of social media existing or possibly created in the future.

Maryland was the first state to enact a law of this type, in May of 2012, and the provisions have gone into effect as of October 1, 2012. The law goes about protecting employees by not defining social media, but by protecting employees’ personal accounts.

Several other states have created laws protecting similar employees’ social media accounts, such as Illinois and Delaware. Several other states, including Massachusetts and New York have bills currently in the legislatures or in a committee, waiting to be passed.

The impacts of these new laws on businesses are clear. Businesses can no longer demand that employees hand over username and passwords to personal social media accounts. Therefore, in order to try to find individuals profiles and posts, employers will have to spend significantly more time and resources. The laws also show that states believe that individuals’ social media accounts are something that should be protected from employers and that this is part of a privacy right of citizens.

In addition, to state actions, the National Labor Relations Board has shown that the board is willing to step in and protect employers’ ability to use social media. A September decision by the board struck down a Costco rule that broadly limiting Costco employee use of social media. The board’s decision shows a continued effort by the federal government to protect the right of social media users.

(Written by Brett Alazraki, Fall 2012 IBLT Entrepreneurship Assistance Fellow) 

Wednesday, September 12, 2012

Thoughts on Education and Compliance re: Cookie Consent Law from UK's Information Commissioner's Office

Dave Evans, the Group Manager, Business and Industry for the UK's Information Commissioner's Office ("ICO") has posted a new blog entry discussing the ICO's efforts in both education and enforcement regarding the use of cookies by companies. The UK's law on cookies, passed in compliance with Article 5.3 of the EU's Data Protection Directive as it was revised in 2009, places specific requirements for organizations to obtain consent for placing and using cookie files on users' computers, and the ICO has previously published guidance on how to understand and follow the law.

In his September 10, 2012 blog entry, Evans discusses the two-prong approach the ICO has taken in connection with implementing the cookies law and regulations:

Broadly speaking, there’s two ways we go about this: an education programme to inform the industry, and enforcement work to ensure compliance.

So we’ve issued guidance and press releases, spoken at conferences, held meetings and workshops and even written to 75 of the most visited websites, asking what steps they had taken to achieve compliance and offering our help. We are working through the intelligence we have gathered to see if websites are taking action to increase the visibility of information about cookies, and already a fair number have.

But we’re balancing that with enforcement: for example, some sites have failed to engage with us at all, and they’re now being set a deadline to take steps towards compliance, with formal enforcement action likely if they fail to meet this deadline. Failure to act on an enforcement notice is a criminal offence.
This mirrors the approach taken by the U.S.' Federal Trade Commission ("FTC") in its privacy and data security activities, as with the moving deadlines and business education program around the Red Flags Rule. Both agencies understand that laws and regulations cannot fulfill their purposes if those who must comply with them are unaware of the requirements. In the privacy and data security area, this challenge is especially great for the numerous small and mid-sized businesses which may not have the personnel or other resources to keep abreast of either legal mandates or best practices. To reach those audiences, governmental agencies do well to partner with regional and local trade groups and educational institutions (such as Touro Law's Institute for Business, Law and Technology) to help spread the word.

Tuesday, September 11, 2012

Welcome to the new privacy and technology law blog published by the Institute for Business, Law and Technology (“IBLT”) at Touro College Jacob D. Fuchsberg Law Center in Central Islip, NY. This blog will highlight legal developments and discuss best practices in business privacy, data protection, and the intersection of business, law and technology. Our posts, which will be written by faculty and students at Touro Law Center, including the IBLT’s director, Prof. Jonathan I. Ezor, and the IBLT’s student Entrepreneurship Initiative Fellows. We welcome your thoughts and comments at iblt@tourolaw.edu, and you can also follow the IBLT on Twitter and Facebook.