Monday, November 24, 2008

Has the Internet Governance Forum really been a success?

In the run up to the third Internet Governance Forum (IGF) in Hyderabad it's worth asking how successful the IGF has been since its establishment. "Not very" is the view of Jeremy Malcolm, who has argued that the IGF is compromised by the fact that many issues (such as copyright enforcement and the oversight of ICANN) have been essentially excluded from its consideration, with the result that policy is being made in other fora which privilege the views of particular vested interests:
Internet-related public policy issues continue to be addressed primarily in an ad hoc, isolated manner in individual stakeholder silos, outside the IGF, rather than in collaboration between stakeholder groups through the IGF...

Across a number of jurisdictions, organisations representing copyright owners have been privately negotiating with Internet Service Providers (ISPs) to limit or terminate the Internet access of customers suspected of illegally sharing copyright material online, without such alleged infringements having been proved to a court or other authority. Such negotiations take place in the shadow of the threat of government regulation, for which these organisations have also been strongly lobbying (so far with success in France). However because such discussions have taken place outside a multistakeholder policy body such as the IGF, they have been dominated by the voices of intellectual property holders, without the opportunity for Internet consumers to interject with balancing perspectives...

As another example of parallel initiatives in multistakeholder Internet governance that have bypassed the IGF, ICANN, although notionally an institution with a purely technical mandate, has continued to attempt to determine issues of public policy such as the balancing of privacy interests in the WHOIS service that identifies the ownership of Internet domains, and in setting non-technical specifications for the introduction of new top-level generic domain names (gTLDs).
The full paper, with suggestions for reform, is well worth reading. It's based in part on his PhD thesis - "Multi-Stakeholder Public Policy Governance and its Application to the Internet Governance Forum" - which is now also available online.

(Via the Internet Governance Project blog)

Tuesday, November 11, 2008

Sunday, October 26, 2008

SABAM v. Scarlet: Belgian ISP released from obligation to filter network for illegal downloads

Significant news from Belgium where it's being reported that ISP Scarlet has succeeded in overturning the injunction requiring it to monitor users and filter out illegal peer to peer filesharing of music. That injunction, granted in June 2007, was the first in a series of attempts by the music industry to oblige ISPs to police their users, and was granted on the basis of evidence by SABAM (representing the industry) that monitoring downloads and filtering infringing content was both technically feasible and cost effective. Since then, however, Scarlet has demonstrated to the court that even the system of filtering suggested by SABAM - produced by Audible Magic - was technically unworkable and that SABAM had deceived the court by falsely representing that the technology had been used elsewhere (automatic translation). On that basis the trial court has set aside the order against Scarlet.

This is far from an end of the matter - it seems (though the reports are unclear) that the trial court still proposes to require Scarlet to filter if an effective solution can be found, an appeal against the original decision remains scheduled for the Court of Appeal in Brussels next year (automatic translation) and ultimately it looks likely that the ECJ will have to decide whether in principle ISPs can be obliged to filter user connections in this way. In the meantime, though, it's a significant blow for the music industry insofar as it undermines their argument that filtering is a technically viable solution. It also couldn't come at a better time for Eircom who will be defending an Irish rerun of the SABAM v. Scarlet litigation in the High Court in Dublin in the near future.

Edited to add (8.02.10): The Belgian courts have now made a prelimary reference to the European Court of Justice, which promises to be one of the most important cases yet on the scope of the E-Commerce Directive.

Monday, October 06, 2008

National Identity Fraud Prevention Week


Normally I'm not a fan of press releases dressed up as news stories. You know the type - "163% of Irish adults are Vitamin X deficient" (survey sponsored by manufacturers of Vitamin X). But I had to make an exception for this story on National Identity Fraud Prevention Week as the sponsors Fellowes (who unsurprisingly make shredders) have produced a very good site with tips on identity fraud, phishing and more. While I'm sure the savvy readers of this blog wouldn't dream of replying to that plausible looking email from PayPal, there are more subtle risks which are pointed out in an accessible way. Recommended.

Friday, October 03, 2008

European Court of Human Rights to hear case on whether online victims have a right to identify internet users

In K.U. v. Finland the European Court of Human Rights has decided to hear a potentially very significant case considering whether victims of online activity may have a right to identify the internet users alleged to be responsible.

In this case the applicant, who was then aged 12, was the victim of a fake personal ad giving his name, phone number, date of birth and his picture and claiming that he was looking for a homosexual relationship. The applicant learned of this when he received a phone call from an older man. Although that man was eventually identified and charged with an offence the person who placed the ad remained unidentified. The police sought to find out (from the ISP) the name of the subscriber behind the dynamic IP address used to place the ad. The service provider however was advised that it was bound by the duty of the confidentiality of telecommunications and could not reveal the user's identity. The Finnish courts ultimately agreed, holding that the law as it stood provided for this information to be revealed only in respect of specified criminal offences - and although defamation ("calumny") was a criminal offence, it was not a sufficiently serious offence to fall within the scope of the legislation.

The applicant applied to the European Court of Human Rights, claiming simply that the fake ad constituted a violation of his right to a private life under Art. 8 of the ECHR, and that as he could not identify the person responsible he had been denied an effective remedy for that violation under Art. 13 ECHR. The case is currently pending.

So why does the case matter? Although the facts are narrow, the implications may be quite wide and may require states to introduce much more extensive rules for identifying internet users. In particular (and I'm obliged to Patrick Breyer for these points) the action presupposes that an effective remedy for a victim requires the identification of (alleged) wrongdoers. But this overlooks the fact that other effective remedies (such as notice and takedown procedures and host liability) already exist and were provided for in Finnish law. In addition, the claim that access to this information must be available even in respect of minor crimes ignores the principle of proportionality - respected even in the Data Retention Directive - under which access to communications data should generally be limited to cases of serious crime. Similarly, most national caselaw has required a showing of proportionality before courts will order users' identities to be disclosed. I've written before about the issues involved in identifying internet users.

Mandatory reporting of missing data considered

According to the Irish Times, the Minister for Justice is now considering introducing mandatory reporting of missing data in Ireland. I've written more about these proposals - and why they might be too narrow - on the Digital Rights Ireland blog.

Tuesday, September 23, 2008

How to be sued by space cadets - Regtel, text messages and "Ireland's first astronaut"

Tom Higgins is a space cadet. Literally. He has signed a contract with Virgin Galactic for their forthcoming space tourism service and claims the grandiloquent and somewhat premature title of Ireland's first astronaut.

He's also the owner of Realm Communications, a company which runs premium text and chatline services such as Irish Psychics Live and which has, to say the least, a patchy record when it comes to sending spam text messages. In fact, the Data Protection Commissioner (DPC) is currently prosecuting Realm for sending these messages, something which Realm is seeking to head off by claiming in the High Court that the DPC is "obliged to seek an amicable resolution" before prosecuting an offender.

Now Realm is also suing Regtel - the industry self-regulatory body for premium rate telecommunications services. Why? After multiple complaints (e.g. 1, 2, 3) about Realm's Foneclub / MobileMania services, RegTel decided that Realm was operating in breach of its Code of Practice and decided to impose a 12 month suspension during which it would be unable to send premium messages. From the Irish Times:
ONE OF Ireland's best-known premium mobile phone text providers claims that its business would be 'wiped out' if a 12-month suspension from sending messages is imposed by the independent regulator (RegTel).

Realm Communications Ltd, Castle Drive City West business Park, Dublin, has brought High Court proceedings arising out of a finding by the Regulator of Premium Rate Telecommunications Services (RegTel) that its mobile phone credit service, FoneClub/ Mobile Mania, had breached the terms of its code of practice.

Realm was founded by businessman Tom Higgins and provides other services such as Irish Psychics Live, WebTarot, Century Psychics and Great Irish Breaks, as well as a live weather forecasting service. It argues that the findings made by RegTel following alleged complaints are unlawful.

Realm is seeking to have RegTel's adjudication and proposed sanctions, including the suspension of its services, quashed.
This case will, if it proceeds, be the first time that this industry self-regulation has been examined in the courts. (Realm Communications has, apparently, sued RegTel before, but that action doesn't seem to have made it to trial.) Ironically, this dispute comes just after the Minister for Communications announced his belief that self-regulation has failed and promised to amend the Broadcasting Bill 2008 to have RegTel's functions transferred to Comreg. In light of its apparent imminent demise, how keen will RegTel be to fight this particular battle?

Eoin O'Dell has more on how RegTel and the Data Protection Commissioner have been cooperating to stop mobile phone spam.

Update (4.11.08): Imminent demise or otherwise, RegTel appear to be keen to have the matter determined and have had the case transferred to the Commercial Court in order to "fast track" it.

Monday, September 22, 2008

Back to the future? Applying the Press Code of Practice retrospectively to online archives

Eoin's post on the statistics for the first six months of operation of the Press Ombudsman prompted me to browse the summaries of each case on the Ombudsman's site. There are a variety of issues in those cases, but one interesting feature was the apparent willingness of the Ombudsman and newspapers to apply the Code of Practice retrospectively. When initially established, the Press Ombudsman indicated that complaints would not be accepted in respect of material published prior to November 2007 - and in any event, the complaint must be made within three months of the material being published. Despite this, however, in two cases resolved by the Ombudsman newspapers were willing to take down material published by them between 2001 and 2004 but still available on their websites. Is this significant in itself? Probably not. The cases were resolved by conciliation - the Ombudsman doesn't seem to be asserting any formal power to comb over the archives. But it is indicative of an ongoing problem for editors, who increasingly have to stand over not just what they publish but also (via the online archives) what their predecessors might have published.

Thursday, August 14, 2008

US court upholds free / open source licences

Great news for the free software / open source world - in Jacobsen v. Katzer the US Court of Appeals for the Federal Circuit (a leading US IP court) has upheld a free software licence in a way which makes it much easier for the authors of free software to prevent its misuse. (The particular licence is the Artistic licence, but the principles apply across the board).

This is hugely significant as it resolves what has, until now, been a major dispute as to the effect of free software licences in US law.

The mainstream view - that of the proponents of free software (1, 2) - has been that free software licences set conditions on the use of the software. Breach those conditions (e.g. by modifying and then distributing code under a proprietary licence, or by failing to attribute) and the licence evaporates so that you are then infringing the copyright of the author. The full force of copyright law can then come into play - you can, for example, have an interlocutory injunction awarded against you restraining you from using the code.

Some, though, have argued that a free software licence amounts to a general licence to copy, modify, etc. with mere contractual restrictions on what the licensee can do. (E.g.) If true, this would mean that breaching the terms of the licence would merely be a breach of contract, not a breach of copyright. This would, for example, make it more difficult for the author to obtain an injunction against the infringer. It might also cast doubt on the enforceability of free software licences, for example by requiring authors to show that the elements of a contract were present before they could enforce restrictions against infringers.

Jacobsen v. Katzer resolves this argument conclusively in favour of the mainstream view, and holds that while free software licences may also have a contractual element, the restrictions they impose are conditions and not merely contractual restrictions. It also contains a striking judicial endorsement of the objectives and legitimacy of open source / free software generally.

Lessig and Groklaw have more.

Friday, August 08, 2008

Judge: Bulletin board users "say the first things that come into their heads"

In Smith v. ADVFN Plc & Others Mr Justice Eady of the English High Court recently showed a keen insight into the world of bulletin boards by noting that users are prone to reacting in the heat of the moment, not thinking about what they are doing, and saying the first thing that comes into their heads. A statement of the blindingly obvious? Perhaps. But the underlying point is important.

A perennial problem with defamation on the internet has been that of tone. Casual conversations - on bulletin boards or blog post comments - can feel as though they are transient and ephemeral. People write in a way which they would never use in a more formal setting such as a newspaper's letters page. But this perceived informality may clash with the approach taken by libel lawyers and courts, who are used to parsing newspaper articles closely for any possible defamatory meaning and who may apply this approach to turn the loose language of a post into something defamatory.

Offline, casual conversations also benefit from the more relaxed rules of slander, where oral (as opposed to written) communications generally don't give a person a right to sue for defamation unless they have suffered actual damage as a result. Online, though, the distinction between slander and libel evaporates so that (in most jurisdictions) an internet posting - however casual - will be treated as libel rather than slander, giving a person a right to sue irrespective of whether they have suffered any actual harm.

Significantly, however, in Smith v. ADVFN Mr Justice Eady took the informal nature of bulletin boards into account in deciding whether a claimant had a chance of succeeding in a defamation action, holding that these cases should often be treated as closer to slander so that the casual nature of posts should be taken into account when interpreting them. His summary of "the nature of bulletin boards" is worth quoting in full:
13. It is necessary to have well in mind the nature of bulletin board communications, which are a relatively recent development. This is central to a proper consideration of all the matters now before the court.

14. This has been explained in the material before me and is, in any event, nowadays a matter of general knowledge. Particular characteristics which I should have in mind are that they are read by relatively few people, most of whom will share an interest in the subject-matter; they are rather like contributions to a casual conversation (the analogy sometimes being drawn with people chatting in a bar) which people simply note before moving on; they are often uninhibited, casual and ill thought out; those who participate know this and expect a certain amount of repartee or “give and take”.

15. The participants in these exchanges were mostly using pseudonyms (or “avatars”), so that their identities will often not be known to others. This is no doubt a disinhibiting factor affecting what people are prepared to say in this special environment.

16. When considered in the context of defamation law, therefore, communications of this kind are much more akin to slanders (this cause of action being nowadays relatively rare) than to the usual, more permanent kind of communications found in libel actions. People do not often take a “thread” and go through it as a whole like a newspaper article. They tend to read the remarks, make their own contributions if they feel inclined, and think no more about it.

17. It is this analogy with slander which led me in my ruling of 12 May to refer to “mere vulgar abuse”, which used to be discussed quite often in the heyday of slander actions. It is not so much a defence that is unique to slander as an aspect of interpreting the meaning of words. From the context of casual conversations, one can often tell that a remark is not to be taken literally or seriously and is rather to be construed merely as abuse. That is less common in the case of more permanent written communication, although it is by no means unknown. But in the case of a bulletin board thread it is often obvious to casual observers that people are just saying the first thing that comes into their heads and reacting in the heat of the moment. The remarks are often not intended, or to be taken, as serious.
More on this case - including the way in which the claimant attempted to use defamation actions to silence his critics - at The Register.

Fake Facebook profile case - Full decision now available

Remember the libel action brought by a businessman against a former friend who created a false Facebook profile under his name? The full text of that decision is now available on BAILII as Applause Store Productions Ltd and Firsht v. Raphael. The bulk of the decision is unremarkable and deals with the (unconvincing) attempts by the defendant to deny that he was responsible for creating the page, but there are some interesting comments showing how judges are putting a figure on damages where material is only available for a short period of time to a relatively small number of people:
Ultimately, I have to approach the question of damages in the same way as a jury would, giving a verdict without a reasoned judgment. I bear in mind, of course, that the profile and group were only available on Facebook between 19th/20th June and 6th July 2007, when Facebook appears to have taken the material down at Mr Firsht's request. Given the times when the material was put up and taken down, that is a period of 17 days (for the profile) and 16 days (for the group). I bear in mind also the limited extent of proved publication, but I accept that Facebook is a medium in which users do regularly search for the names of others whom they know, and anyone who searched for the name Mathew Firsht during those few days will have found the false group without difficulty. In my view, a not insubstantial number of people is likely to have done so. By that I have in mind a substantial two-figure, rather than a three-figure, number. I also accept that the Defendant has increased the hurt and upset of Mr Firsht by the allegations which he rashly made in his original Defence and by his persistence in a defence which I have founded to be built on lies, which has compelled Mr Firsht to give evidence and face lengthy cross-examination in a public trial.

The libel is, as Ms Skinner rightly said, not at the top end of the scale, although it is serious enough to say of a successful businessman that (as I have found the words to mean) he owes substantial sums of money which he has repeatedly avoided paying by lying and making implausible excuses, so that he is not to be trusted in the financial conduct of his business and represents a serious credit risk. I do take into account also the effect on Mr Firsht of the unpleasant allegations against him which the Defendant made in his original Defence, and the fact that the Defendant has persisted to trial in a case which I have found to be no more than a lie. It seems to me that a proper award for the libel of Mr Firsht, to include an element for aggravation of damage, is £15,000. The pleaded meaning in the case of the company - against which the allegations of debt and dishonest prevarication are not directly made - is just the consequential meaning, that as a result of Mr Firsht's conduct the company is not to be trusted in the financial conduct of its business and represents a serious credit risk. It seems to me that a substantially lower award should be made in respect of the company, and in my judgment the right figure is £5,000.

Friday, July 25, 2008

Funniest name for a firm of solicitors in Ireland?

When I read that an Irish firm of solicitors was named "Argue and Phibbs" I assumed that this was an urban legend. Apparently not:
Sligo Town on the Net has more on this wonderfully named firm.

Wednesday, July 23, 2008

Bebo, bullying and the law

The Irish Independent recently carried a story about what may be the first Irish case involving social networking to reach court:
A man has been prosecuted for putting offensive and obscene messages on social networking site Bebo in what is believed to be the first case of its kind to come before the Irish courts.

Paul Anthony Matthews (27) posted what a judge described as "outrageous" messages on a teenage girl's site on January 31 this year.

Matthews, of Carnbeg, Doylesfort Road, Dundalk, agreed to pay the victim €3,000 instead of going to jail.

The pioneering case was brought under Section 13 (1) of the Post Office Amendment Act 1951 for sending offensive or indecent material by means of telecommunication.

Matthews, a father of one, admitted posting explicit and abusive messages on the teenager's site. The victim cannot be identified because of a court order.

Dundalk District Court was told that Matthews had a previous disagreement with the then 16-year-old and posted the messages on her Bebo page. The teenager had made a complaint about Matthews to gardai regarding another matter and the Bebo messages were investigated.

Matthews was arrested and admitted when questioned that he had put up the messages on her site.
So what's the significance of this case? It's certainly not the first time that internet harassment has come before the courts in Ireland - as far back as 1999 a man was convicted of criminal libel for online postings (Mac Ruairí, “Man Jailed for Libel on the Internet”, Irish Examiner, December 21, 1999.) But it does seem to be the first time that this particular section has been applied to the internet, so it might be worth looking at it in more detail.

Section 13 has been heavily amended since it was enacted. (For the tortuous details see the Fourth Schedule of the Postal and Telecommunication Services Act 1983, section 7 of the Postal and Telecommunications Services Amendment Act 1999 and Regulation 4(8) of SI 306/2003.) The most recent change was brought about by the Communications Regulation (Amendment) Act 2007, which substitutes the following for section 13:
Offences in connection with telephones.
13.—(1) Any person who—
(a) sends by telephone any message that is grossly offensive, or is indecent, obscene or menacing

or

(b) for the purpose of causing annoyance, inconvenience, or needless anxiety to another person—
(i) sends by telephone any message that the sender knows to be false, or
(ii) persistently makes telephone calls to another person without reasonable cause,
commits an offence.

(2) A person found guilty of an offence under subsection (1) is liable on conviction—
(a) if tried on indictment, to a fine not exceeding €75,000 or to imprisonment for a term not exceeding 5 years, or to both, or (b) if tried summarily, to a fine not exceeding €5,000 or to imprisonment for a term not exceeding 12 months, or to both.
(3) A contravention of this section is an offence under the Post Office Act 1908.
(4) On convicting a person for an offence under subsection (1), the court may, in addition to any other penalty imposed for the offence, order any apparatus, equipment or other thing used in the course of committing the offence to be forfeited to the State.
(5) In this section, ‘message’ includes a text message sent by means of a short message service (SMS) facility.”.
This is, however, quite a narrow section. It is limited to messages sent by "telephone" (which, while it might be stretched to cover the use of dial up, probably excludes the use of e.g. cable modems). Although it includes text messages it does not mention email or other internet messages and wouldn't seem to be wide enough to include them (a point also made by Kelleher & Murray - Information Technology Law in Ireland (2nd ed.) at 690). In fact, the legislative history on this point indicates that "cyber bullying" was expressly excluded from its scope, with the Minister for State (John Browne) rejecting an amendment extending the section to cyber bullying, stating:
The purpose of amending the Post Office (Amendment) Act 1951 was to increase fines to deter nuisance calls to the emergency call answering service, ECAS. The change proposed by the Senators is a wider offence and I understand from the debate on Tuesday that they are particularly concerned about tackling cyber bullying. The issues were raised again today by the Senators. This type of regulation falls outside the remit of the Bill. The sole intention of this provision is to address nuisance calls to the emergency services. I have listened carefully as did the Minister, Deputy Noel Dempsey, to the points raised by the Senators. The purpose of the Bill is to deal with the regulation of a service. The areas raised by the Senators would be more appropriate to the Department of Justice, Equality and Law Reform.

To respond to Senator Terry, it is an offence under section 10 of the Non-Fatal Offences against the Person Act 1997 to harass a person by use of any means, including by use of a telephone. Therefore, the issue is already dealt with to a certain extent.
Consequently (though bearing in mind we only have media reports to go on) it's hard to see how this section was applied to the defendant's conduct in this case.

(It may be, however, that the prosecution mistakenly had in mind the previous version of section 13(1) which appeared to be substantially wider in that it prohibited the sending of any grossly offensive etc. message "by means of the telecommunications system operated by [any authorised undertaking]" - a formula which may have been wide enough to include internet connections.)

Instead, one would expect this type of situation should be dealt with (if criminal charges are necessary) by the offence of harassment under section 10 of the Non Fatal Offences Against the Person Act 1997, which explicitly includes communication with a victim "by any means".

At this point one might wonder - so what? Does it matter whether this conduct is dealt with under one of these offences rather than the other? I'd suggest that it does. Section 13 is designed to deal with nuisance telephone calls. These are peculiarly direct, immediate, personal and invasive of one's privacy. Consequently the law applies a low threshold - a single instance of gross offensiveness - before these become criminal. But this is very unusual. The law doesn't generally criminalise mere offensiveness, even gross offensiveness, nor should it. But if section 13 were extended to all internet communications then it would have just that effect - prohibiting a great deal of speech on the basis that some readers might find it grossly offensive. (Something which would, for example, make criminals of those who post the Danish cartoons portraying Mohammed.) Indeed, as Eoin O'Dell recently reiterated "It is precisely to allow the expression of offensive opinions that the right to freedom of expression is necessary."

Having said that, there may be a case for extending section 13 or a similar provision to some internet communications. For example, nuisance emails and instant messages share many of the characteristics of text messages, and in some circumstances messages left on a person's social networking page might be as invasive. But any extension of the law must be carefully limited to avoid damage to freedom of expression.

Update (10 May 2010): - I've now been informed that after being alerted to these issues the original trial judge accepted that there was a flaw in the proceedings, declared a mistrial and reentered the matter. Last week, on the matter again being listed in Dundalk Judge Hamill considered this point and ruled that the charge was inappropriate.

Tuesday, July 08, 2008

Free books on technology and the law - A reader's guide

A 19th Century Irish judge (Sir James Mathew) once said that "In England, justice is open to all – like the Ritz Hotel." Unfortunately, litigation has not become much cheaper in the meantime. But other aspects of the law have. In particular, there has been an explosion in the number of high quality books on law and technology available for free download - both free as in beer and free as in speech. Here are some of my favourites.

It's almost obligatory to start with Lawrence Lessig, who was one of the first lawyers to make his work freely available and was instrumental in setting up the Creative Commons movement to enable others to do likewise. Three of his books are available:
Free Culture is one of the more influential books on the use and abuse of intellectual property law and at the same time manages to be both readable and entertaining.

http://www.lessig.org/content/books/code2.gif
Code 2.0 scarcely needs an introduction. Lessig's analysis of how code can be used as a form of regulation, and the risks this presents, was an instant classic when first published in 2000 and this second edition confirms that many of his insights have become increasingly relevant in the meantime.


The Future of Ideas is another classic - covering much of the same ground as Code and Free Culture, it looks at what he calls the corruption of the values of the early internet, an internet counterrevolution which threatens to stifle creativity and innovation.

http://img.skitch.com/20080424-phm7tqu9m99sd9enkascq43w3p.preview.jpg
Building squarely on Lessig's work, Johnathan Zittrain's The Future of the Internet - And How to Stop It is a perceptive discussion of how the innovation and freedom permitted by an open internet is under threat from increasing restrictions both on the network itself and the devices which connect to it.


On a similar topic is Matthias Klang's doctoral dissertation, Disruptive Technology. He argues that new technologies "disrupt the, previously established, social norms that make large parts of our democratic social interaction" while simultaneously the regulation of new technologies may undermine democratic participation, for example by imposing contractual restrictions on speech online which would not apply offline.

http://www.lessig.org/blog/archives/0300110561.01._SCLZZZZZZZ_.jpg
The Wealth of Networks by Yochai Benkler covers some of the same ground, but has a different focus in arguing that a networked environment and a growth in the sharing of information (such as via Creative Commons licences) brings about deep, structural changes in society - notably a shift from markets to non-market social behaviour - which face resistance from a variety of entrenched incumbents who stand to lose out.

Turning specifically to privacy, Daniel Solove's The Future of Reputation is a superb look at the interaction of privacy, reputation and freedom of expression on the Internet, and takes a broad view of how social mechanisms such as shaming might develop online.

http://blog.lib.umn.edu/writ/dept/images/peerspiratespersuasion.jpg
John Logie's Peers, Pirates and Persuasion is an interesting and enjoyable look by a non-lawyer at the growth of a maximalist copyright system and specifically the rhetoric used by each side in the "filesharing wars". (That link appears to be unreliable, but the book is also available on Scribd.)

http://mitpress.mit.edu/images/products/books/0262062461-medium.jpg
Perspectives on Free and Open Source Software, edited by Joseph Feller and others, is a collection of essays covering a wide range of issues such as: the motivation of contributors to open source software, the security issues it presents, the business model underlying it, the challenge of open source for the legal system and the application of open source / free software principles in the world of science. This remains possibly the best introduction for anyone (lawyer or not) curious about free / open source software.


The OSCE Media Freedom Internet Cookbook is another must read. This collection of essays by various authors offers some very interesting perspectives on the challenges of reconciling individual and media freedom with regulation of the internet while also covering a variety of topics from "hate speech" to internet hotlines to education for media literacy. In particular, Gus Hosein's piece on the Open Society and the Internet is a perceptive look at the promises of and threats to internet freedom.

http://ecx.images-amazon.com/images/I/51NKFQVQCSL._SL500_AA240_.jpg
Last, but certainly not least, is a collection of essays by the individual who started many of these debates about opening software, knowledge and society. Free Software, Free Society: Selected Essays of Richard M. Stallman includes classic pieces such as "The right to read" and "Why software should be free".

Sunday, July 06, 2008

Ireland's first case on the legality of screen scraping?

The Sunday Business post reports that Ryanair has started proceedings in the High Court against Bravofly seeking to prevent it from screen-scraping the Ryanair site in order to provide users with a portal through which they can compare fares across airlines.

Ryanair have been trying to block screen scrapers for some time now. Most recently they were rapped on the knuckles by the ASA for placing advertisements telling consumers that:

"IF YOU BUY A RYANAIR TICKET THRU AN ONLINE AGENT YOU'RE BEING RIPPED OFF... *THEY OVERCHARGE BY 100% OR MORE *THEY DON'T PROVIDE CORRECT TERMS AND CONDITIONS *THEY DON'T NOTIFY SCHEDULE CHANGES *THEY DON'T PROVIDE WEB CHECK-IN OR PRIORITY BOARDING"
This seems to be the first time, though, that they have resorted to legal proceedings and the first time that the Irish courts will consider the legality of screen scraping. From the report in the Sunday Business Post it would seem that Ryanair is primarily relying on the restrictions imposed by its terms of use, but presumably we'll see argument as to whether screen scraping violates their rights under the Database Directive (though whether this claim will stand up in light of the British Horseracing Board caselaw is another matter). OUT-LAW have some analysis of the uncertain position under English law, while this article in the Loyola Consumer Law Review gives an up to date summary of the position under US law.

Update 8.07.08 - The Irish Independent and Irish Times have more details. From the Irish Times:
Ryanair has claimed the alleged "screen-scraping" activities of Bravofly breach provisions of the Trademarks Act and the Copyright and Related Rights Act, amount to "passing off" and also breach the conditions for accessing the Ryanair website.

It claims that Bravofly, without permission from Ryanair, has offered detailed information on Ryanair's flight services and had also used Ryanair's name and harp device logo in presenting that information.

It also claims that Bravofly has established and maintains hypertext links from its websites to the Ryanair website, without Ryanair's authorisation.

Ryanair claims it had written to Bravofly asking for undertakings that the screen-scraping activities would cease but no such undertakings had been received.

Ryanair is seeking court orders restraining the alleged activities and also wants damages, including exemplary damages, and/or an account of profits for alleged negligence and/or wrongful interference with Ryanair's economic interests and contractual relations.

The airline contends the matter is of real commercial significance as its website is at the heart of its marketing and sales strategy and some 98 per cent of its flight bookings are transacted via the website. Any action which wrongfully impinges on the effectiveness of the Ryanair website has an impact on sales and marketing activities and the attractiveness of the website as a platform for the advertising and sale of third-party goods and services, it says. It claims the activities of Bravofly are diverting potential business from Ryanair.

Wednesday, June 25, 2008

Symposium - Privacy v. Publicity in the Virtual World

The Darklight Film Festival is hosting what should be a very interesting symposium on Privacy v. Publicity in the Virtual World this Friday, June 27th in the Film Base, Curved Street, Temple Bar at 10am:
For a new generation of 'digital natives' privacy is no longer a requirement. Web 2.0 has brought with it a transformation in how we view the need for privacy and engage with the public realm - but at what cost? The discussion will be prefaced by a keynote address from Daniel J. Solove, Associate Professor of law at the George Washington University Law School, and author of The Digital Person: Technology and Privacy In the Information Age. Chaired by Irish Times writer Karlin Lillington, the panel will also feature Irish blogging guru Damien Mulley and solicitor/digital rights expert Caroline Campbell.

Issues to be considered include:

* Can bloggers say what they like?

* What's wrong with having nothing to hide?

* Who is really stalking you on Facebook? .. Does anyone care anymore?

* Is there a generation gap in approaches to online privacy?

Monday, June 23, 2008

Civil servants' illegal disclosure of personal information is "routine and very comprehensive"

The Independent has an update on the Data Protection Commissioner's investigation into the Department of Social and Family Affairs:
FOURTEEN employees of the Department of Social and Family Affairs are being investigated for allegedly passing comprehensive personal information to insurance companies on a regular basis.

The Irish Independent has learned that some of the alleged breaches -- which came to light in April 2007 -- involve "one of Ireland's largest insurance companies" and date back to 2006.

The allegations involve the passing of personal and sensitive information, contained on data systems within the Department of Social and Family Affairs (DSFA), to third parties for commercial benefit.

The DSFA carries all personal details on all individuals in the state including PPS numbers, dates of birth, addresses as well as earnings details.

Private investigators work for the insurance companies to compile cases against drivers. But there is concern about the level of information that the inspectors for the insurance companies are obtaining.

Protection Commissioner Billy Hawkes said in an email to the DSFA last June: "I inspected five investigator files yesterday during a planned call back to X (large insurance company).

"This revealed very-worrying levels of disclosure from the DSFA to private investigators. From what I could discern, such disclosures are routine and very comprehensive."
I've blogged before about other examples in this Department of disregard for citizens' privacy.

Thursday, June 19, 2008

Data protection and bulletin boards

John Breslin of (amongst other things) Boards.ie has an interesting post on a data protection complaint from a banned user. The complaint? After the banning, all the posts he had previously made appeared with the word "Banned" next to them (which is the default setting for many forum software packages). The view of the Data Protection Commissioner was that this was an unauthorised disclosure of personal information (i.e. the user's status on the site), apparently on the basis that the username was very close to his real name:

Quite apart from the narrow data protection aspect of this particular case, it raises an interesting issue about the social dynamics of social software and whether the law might hinder effective moderation.

One of the way in which moderators on forums discourage certain behaviour is by putting users into a sin bin or banning them. Going one step further by naming and shaming - i.e. publicising the sanction by labeling posts from those users - has a social effect in two ways. At a general level it may help to reinforce the norms of the site by publicly reinforcing the message that certain types of behaviour are unacceptable and at the individual level it may also act as a deterrent to the user who knows that any sanction against them will be publicised.

If this sounds familiar it's because this argument mirrors, on a much smaller scale, the role of publicity in the criminal justice system. It also mirrors the increasing tendency in other areas for public bodies to "name and shame", whether it be young offenders in England or the list of tax defaulters in Ireland who settle with the Revenue.

The broader issue this raises is whether naming and shaming is an acceptable option - and if acceptable in (e.g.) the context of tax defaulters, why not in the context of troublesome users? Should it matter whether it's a public or private body naming and shaming? Should it matter that the gravity of the "offence" is much greater in one case than the other? If bulletin boards / forums can't publicly reveal which users have been banned or sin-binned, will this make the life of moderators more difficult?

Tuesday, June 10, 2008

How not to protect a domain name - the D4hotels saga

Remember D4hotels.com - the low cost hotels site which completely failed to protect variants of its name against cybersquatters? Well it now transpires that the ownership of D4hotels.com itself is now contested:
A dispute over ownership of the D4hotels.com domain name and website has come before the Commercial Court.

MJBCH Ltd, the leaseholder of the former Berkeley Court Hotel and the former Jury's hotels in Ballsbridge and The Towers, claims exclusive entitlement to the operation and management of the domain name and website.

It has alleged it had a hotel operation and management agreement with the two defendant companies -- Cloud Nine Management Services Ltd and Beechside Company Ltd, trading as The Park Hotel, Kenmare -- to manage the hotels as the Ballsbridge Inn, Ballsbridge Towers and the Ballsbridge Court hotel, but that agreement was terminated in February.

In those circumstances, it claims the defendants have no entitlement to use the d4 domain name and website.

...

The defendant companies deny the claims and say they at no time abandoned their rights to or property in the domain name, website or business name.

They companies say that, under their agreement with MJBCH of October 2007, they were authorised to act as the exclusive operator and manager of the hotels and that the domain name D4hotels.com was registered by Beechside in September 2007.

They also say the management agreement was summarily terminated by MJBCH in February and that at no stage had it been agreed the D4 domain name and website would become the property of MJBCH.
While there's very little detail in this report, it suggests that there was no explicit agreement as to ownership of the intellectual property in the domain name and the site itself - which if true is one of the most fundamental mistakes one can make when establishing an online business. This, together with the failure to protect domain name variants, means that I will be using this case in class as a cautionary tale.

Update (27.1.09): It now seems that this case has been settled.

NY Attorney General forces ISPs to filter Internet

In another bad day for the end to end principle, the New York Times reports that the Attorney General of New York has succeeded in forcing ISPs to filter their users' internet connections. The expressed motivation is to prevent users from accessing child pornography, though this will be trivially easy to circumvent. There are many problems with internet filtering, and I've written a short summary of them (in a different context) for the Digital Rights Ireland blog. But the New York scenario raises one particular problem - whether this form of censorship, implemented and administered by private actors (who will face an incentive to overblock), can be reconciled with the rule of law. The issues raised are very similar to those presented by the UK Cleanfeed system, about which Colin Scott and myself had this to say at the inaugural TELOS Conference last year:
This presents a number of challenges for the rule of law. Even if an individual ISP’s actions can be described as voluntary, the effect is to subject users without their consent to a state mandated regime of internet filtering of which they may be unaware. The Internet Watch Foundation (IWF), which determines which URLs should be blocked, has a curious legal status, being a charitable incorporated body, funded by the EU and the internet industry, but working closely with the Home Office, the Ministry of Justice, the Association of Chief Police Officers and the Crown Prosecution Service. There is no provision for site owners to be notified that their sites have been blocked. While there is an internal system of appeal against the designation of a URL to be blocked, that mechanism does not provide for any appeal to a court – instead, the IWF will make a final determination on the legality of material in consultation with a specialist unit of the Metropolitan Police.

Consequently the effect of the UK policy is to put in place a system of censorship of internet content, without any legislative underpinning, which would appear (by virtue of the private nature of the actors) to be effectively insulated from judicial review. Though the take-up of the regime may be attributable to the steering actions of government, the way in which the regime is implemented and administered complies neither with the process or transparency expectations which would attach to legal instruments.

There is also cause for concern about the incentives which delegating filtering to intermediaries might create. From the point of view of the regulator, requiring intermediaries to filter may allow them to externalise the costs associated with monitoring and blocking, perhaps resulting in undesirably high levels of censorship. But perhaps more worrying are the incentives which filtering creates for intermediaries. Kreimer has argued that by targeting online intermediaries regulators can recruit “proxy censors”, whose “dominant incentive is to protect themselves from sanctions, rather than to protect the target from censorship”. As a result, there may be little incentive for intermediaries to engage in the costly tasks of distinguishing protected speech from illegal speech, or to carefully tailor their filtering to avoid collateral damage to unrelated content. Kreimer cites the US litigation in Centre for Democracy & Technology v. Pappert to illustrate this point. In that case more than 1,190,000 innocent web sites were blocked by ISPs even though they had been required to block fewer than 400 child pornography web sites.
Orin Kerr has more.

Edit (13.06.08): Richard Clayton indicates that the New York Times coverage may be inaccurate. He suggests that what the ISPs have agreed to is limited to removing certain newsgroups and taking down sites which they host - but does not include filtering of sites hosted elsewhere. There's also some confusion as to just what the effect on usenet will be, with Declan McCullagh reporting that in the case of Verizon all the newsgroups in the alt.* hierarchy will no longer be offered.