The TMCA
Trademarks
Don’t Get Duped: The Rise of “Dupe” Litigation in the United States
If you’ve scrolled on social media, set foot in a popular retailer, or have a teenager in your life, it’s likely you’ve heard the term “dupe” (short for “duplicate”) to describe affordable alternatives to high-end products such as handbags, makeup, and even furniture. Indeed, one need only conduct a cursory search on Amazon or the TikTok Shop to find a cheaper alternative for any luxury product imaginable. For brand owners, however, the rise of dupes can be a serious problem. “Dupes” vs. Counterfeits The major difference between dupes and counterfeit goods is that counterfeit goods purport to be authentic, often using a business’s trademarks in an attempt to deceive consumers into believing they are receiving legitimate goods. Conversely, while a dupe may be visually similar in terms of design, packaging, ingredients, and overall product aesthetics, it does not typically copy any third-party trademarks, and consumers generally recognize the goods to emanate from a different source than its higher-end inspiration. And, while the selling of counterfeit goods is blatantly illegal under both federal and state laws, the sale of dupes is a gray area which has just begun to be explored in U.S. courts. Lawsuits While recent cases in the United Kingdom and Australia involving dupes have provided helpful precedent on which brand owners can rely, the jurisprudence in the United States is much sparser. Recent lawsuits filed by big name brands have gained media attention for asking courts to rule on whether dupes are lawful, or if there are grounds on which brand owners may be able to rely to combat being “duped”. In Deckers Outdoor Corporation v. Last Brand, Inc., No. 3:23-cv-04850 (N.D. Cal.), Deckers Outdoor Corporation (“Deckers”), the owner of the well-known Uggs shoe brand, alleges, in part, trade dress infringement and unfair competition against competing consumer products brand, Quince, based on Quince’s “dupe” version of Uggs’ Class Ultra Mini Boot. Based on the visual similarities between the boots, Deckers claims Quince has infringed its trade dress in an effort to exploit Deckers’ goodwill and the reputation it has acquired in its Classic Ultra Mini. In Sol De Janeiro USA, Inc. et al. v. MCoBeauty Pty Ltd et al., No. 1:24-cv-08862 (S.D.N.Y.), the popular beauty brand Sol De Janeiro (“Sol”) filed suit against MCoBeauty (“MCo”), a company founded on providing “dupes” of well-known beauty brands. No stranger to lawsuits, MCo has faced multiple lawsuits in both its home country of Australia as well as in the United Kingdom. It has generally prevailed in defending against trademark infringement claims though, as the brand creates its own trademarks for its products. In the United States, however, brands have the unique ability to rely on trade dress rights, which is exactly what Sol alleges infringement of in its November 20, 2024 Complaint. Sol alleges false advertising, trade dress infringement, and unfair competition against MCo, noting, “[t]o sell its knockoff fragrances [MCo] publishes, endorses, sponsors, hosts, and/or supports” on its social media and website that its “fragrances are copies or duplicates of four of” Sol’s popular products. In its Answer, MCo denies each of the claims against it, adding affirmative defenses that Sol’s trade dress design is ornamental, functional, non-distinctive, and generic. In a busy year for MCo, it is also facing claims of trade dress infringement in Aramara Beauty LLC v. Mco Beauty Pty Limited et al., No. 1:25-cv-04808 (S.D.N.Y.), from owner of the Glow Recipe beauty brand, Aramara Beauty, LLC (“Aramara”). Aramara claims one of MCo’s facial serums features a similar bottle shape, bottle color scheme, serum color, and product packaging to its popular “Watermelon Glow Dew Drops”. Aramara’s Complaint points to MCO’s social media and advertising for its product which feature similar taglines and color schemes, and even go so far as to claim “‘It’s not a dupe. It’s a dupé!’” Trade Dress Protection Each of these lawsuits relies on trade dress rights in product design and packaging. In the United States, product design trade dress and product packaging trade dress are evaluated differently. Product designs themselves can never be inherently distinctive and will always require a showing of acquired distinctiveness and evidence the product is not merely functional in order to be accorded trade dress protection. Conversely, product packaging may be inherently distinctive, though it also requires a showing that the packaging is not merely functional. When a trade dress does more than just identify its source (i.e., it offers some sort of utilitarian or operative function as well), it loses its eligibility for trade dress protection, on the basis that it is functional. To prove distinctiveness for product design or non-inherently distinctive product packaging, owners must make a showing that the design/packaging has acquired distinctiveness and functions as a source indicator. Given the extensive evidence often required to make a claim of acquired distinctives, it’s not surprising that brand owners often have a difficult time enforcing their rights against dupes absent a commercially strong brand. With the increase in media attention and legal proceedings involving dupes, brand owners may wish to explore obtaining federal trade dress registrations to better combat falling prey to being the next “duped” brand. Moreover, given the hurdles with proving acquired distinctiveness in many instances, owners may wish to get a head start on this process by having a discussion with their trademark counsel.
September 4, 2025
Trademarks
When it Comes to the View, Will the Cubs Play Ball?
Watching a Cubs game from a nearby rooftop sounds like an ideal afternoon. At Wrigley Field, it became a business. For years, rooftop owners near the stadium sold tickets, served food and drinks, and offered fans a unique vantage point to watch the Cubs play. If the neighborhood business started like a friendly game of catch at the backyard, the legal battle that followed has been more like an extra-inning game. After a twenty-year agreement between the Cubs and rooftop owners expired in 2023, one business—Wrigley View Rooftop—continued to sell rooftop tickets and use the Cubs’ trademarks. The Cubs responded with a lawsuit. Now, the battle over who controls the view of the game raises important questions about trademark rights, property use, and what happens when a view becomes a product. A History of Tension: Cubs and Rooftop Businesses To understand the current dispute, it is essential to look at the long and sometimes tense relationship between the Cubs and the rooftop businesses that surround Wrigley Field. Since 1914, the Chicago Cubs have played their home games at Wrigley Field. Just across from the ballpark, the Wrigley View Rooftop (“the Rooftop”) offers ticketed packages that include views of the game along with all-inclusive food and drinks. With eleven rooftop venues along Waveland and Sheffield Avenues, these businesses provide bleacher-style seating and suite-level experiences. In the early 2000s, the Cubs sued thirteen rooftop businesses, including the Rooftop, asserting claims for copyright infringement, trademark infringement (unfair competition), misappropriation, and unjust enrichment. The parties ultimately resolved the dispute through a license agreement. Under that agreement, rooftop businesses could continue operations and use the Cubs’ trademarks but had to share their revenue. The Cubs reportedly received over $2 million per year from the rooftops for the duration of the 20-year deal. Beginning in 2012, the Cubs installed large scoreboards that obstructed several rooftop views. In response, a group of rooftop owners sued the team, alleging antitrust violations and breach of contract. These lawsuits were unsuccessful in both district and circuit courts. The Seventh Circuit Court affirmed the lower court’s decision to dismiss the monopolization claims partly because the “Major League Baseball antitrust exemption applies to the Cubs.” The Seventh Circuit also agreed to dismiss the breach-of-contract claim because “the plain language of the contract did not limit expansions to the seating capacity of Wrigley Field.” When the license agreement expired at the end of 2023, the Rooftop did not renew but continued to sell tickets and use the Cubs’ trademarks. Other rooftop businesses did extend their agreements with the Cubs. The Current Dispute: Cubs v. Wrigley View Rooftop In June 2024, the Chicago Cubs filed a lawsuit in the U.S. District Court for the Northern District of Illinois, Eastern Division, against the Rooftop and its owner, Aidan Dunican. The complaint alleges misappropriation, unjust enrichment, and multiple trademark violations under the Lanham Act. Although the complaint also includes claims under Illinois state law for deceptive trade practices and unfair competition, this blog post focuses on the Lanham Act claims, misappropriation, and unjust enrichment. Trademark Infringement, Unfair Competition, and False Advertising A central argument in the Cubs’ case is trademark infringement under the Lanham Act. The team asserts ownership of several federally registered trademarks, including “CHICAGO CUBS,” “CUBS,” and the Cubs logo. According to the complaint, the Rooftop continues to use these marks on its website, advertisements, and social media without authorization. The Cubs argue this use is likely to confuse consumers into believing that the business is affiliated with or endorsed by the team—constituting infringement and unfair competition. They also claim to suffer from reputational harm and diminished ticket sales. Additionally, the Cubs allege false advertising, asserting that the Rooftop either explicitly or implicitly suggested that its services are sponsored or approved by the Cubs, thus misleading customers. In response, the Rooftop denies any infringement and raises several defenses, including fair use, nominative use, implied license, acquiescence, and innocent infringement. The Rooftop also argues there is no likelihood of consumer confusion and denies making any false or misleading claims. Misappropriation The Cubs claim that they hold exclusive property rights to the live performance of MLB games at Wrigley Field—rights in which they have invested millions. They accuse the Rooftop of commercially exploiting those performances without compensation or proper licensing. This, they argue, constitutes misappropriation and has harmed their goodwill and economic interests. The Rooftop responds that the Cubs do not "own" the view or the sounds emanating from Wrigley Field. The Rooftop claims the right to operate under an implied license acquired when the parties negotiated for a continuation of the prior license agreement. Furthermore, it notes that its current rooftop no longer has a direct view of the field due to new obstructions installed by the Cubs in May 2024. Unjust Enrichment The Cubs argue that the Rooftop is using the team’s property to divert revenue for the Rooftop’s own profit. Since the Rooftop no longer pays royalties, the Cubs claim these profits are improper and should be disgorged. The Rooftop again challenges the Cubs’ exclusive right to the view and the sound of the Wrigley Field. The Rooftop counters that there is no unjust enrichment because it has a legitimate right to operate its business and to use the view and sounds of the game. It further argues that any claim is moot since the view has been obstructed. Case Status and Next Steps In April 2025, the court denied the Rooftop’s motion to compel arbitration, finding that the arbitration clause had expired along with the license agreement in 2023. As of now, all factual discovery is ongoing and must be completed by August 11, 2025. Once discovery concludes, the court will likely evaluate the Rooftop’s defenses—especially: Whether use of the Cubs’ marks is nominative fair use or falsely implies endorsement. Whether there was any form of implied license or permission. Whether continuing use after failed renewal negotiations constitutes willful infringement. Based on the pleadings, the Rooftop is more likely the underdog, having continued to use the marks without renewing the agreement. While a settlement remains possible, the Cubs currently appear to be the heavy favorites, holding a stronger legal position. Whether this ends in a courtroom win or a negotiated walk-off, one thing is clear: the Cubs are not letting anyone steal home when it comes to their brand. Takeaways for Trademark Practitioners For trademark lawyers, it is important to consider and outline an exit strategy in a license what a licensee must immediately stop doing once the agreement ends. Without clear language, former licensees may potentially continue using trademarks and other branding, triggering costly disputes.
August 7, 2025
Trademarks
Federal Circuit Finds Sua Sponte is Not a Good Vintage
Legal decisions, like fine wine, should be balanced. The Federal Circuit recently corked a non-precedential TTAB decision that ECHO D’ANGÉLUS was not confusingly similar to ECHO DE LYNCH BAGES, where both were used for wine, because the TTAB relied on a concept that no party to the case had argued. In deciding the opposition, the TTAB’s analysis initially followed standard DuPont factors to find the goods were similar and sold through the same channels of trade, favoring Chateau Lynch-Bages (“Opposer”). The Board also found ECHO somewhat diluted based upon Chateau Angelus S.A.’s (“Applicant”) evidence of thirteen third-party registrations for ECHO-formative marks covering wine and other alcoholic beverages, which favored Applicant. The Board then made the pour decision to consider the non-ECHO portions of the marks as house marks, which neither party had argued. The Board based the house mark finding on Applicant owning four registrations that included ANGÉLUS and Opposer using LYNCH BAGES in its letterhead. A “house mark” serves a different function than a trademark. Rather than identifying the source of a particular good or service – the function of a trademark – a house mark identifies a company that provides a wide range of goods or services. House mark registrations list the goods or services as a “full line of _____,” thus conferring broader rights than a typical trademark registration. To obtain these broader rights, an applicant must provide evidence that the mark functions as an identifier for an entire line of goods in addition to evidence that the mark is used in commerce for the mark to register. The Board raised the house mark concept in its discussion of each mark’s meaning. It found that Opposer’s mark meant “echo of Lynch Bages,” conjuring the fact that Opposer used the mark for a second wine offered by the vintner. Applicant’s mark was found to mean “echo of Angélus,” evoking a reverberation of Applicant’s other wines. Had the Board bottled its decision there, relying on consumer confusion being unlikely given the disparate meanings of each mark, the Federal Circuit may have agreed. Instead, the Board proceeded to analyze the case in the context of infringement precedents involving house marks. The Board concluded that “ECHO” combined with each party’s house mark created a unitary expression with a significantly different commercial impression, making confusion unlikely. On appeal, the Federal Circuit found that while the Board may have had its Rieslings for such sua sponte reasoning, the result was not supported by substantial evidence. Not only had neither party argued that its mark included a house mark, but the Board’s independent investigation did not support such a finding. The Board had cited no precedence for finding that four registrations or use on letterhead were sufficient to evidence that a mark is a house mark. Notably, it is unlikely the USPTO would grant a house mark registration based on such sparse evidence. Moreover, the Federal Circuit indicated the house mark analysis was unnecessary and the Board probably could have found confusion unlikely based on traditional weighing of the DuPont factors. The Federal Circuit’s decision to remand the case is curious. The court could have relied on the Board’s finding that the marks were “visually and aurally different” to uphold the general finding of no likely confusion and admonished the Board for decanting the house mark concept as inappropriate. As is, the consequence is likely little more than a rewrite with the same outcome, particularly given the court’s clear indication that it does not believe confusion is likely. Nonetheless, the Board’s overall approach in this proceeding signals it is willing to find confusion unlikely where marks incorporate house marks, even if the house mark portions are not registered as such. Where such arguments are appropriate, parties should take care to provide sufficient evidence to support finding that a mark serves as a house mark.
August 1, 2025
Trademarks
Spotlight or Lawsuit? Strategic Brand Use in Film and Media
A. Blue Devil in the Details: When Logos Steal the Scene When The White Lotus returned to HBO for its third season, it came with the usual dose of dramatic tension, along with one unexpected intellectual property wrinkle. [WARNING - Potential Plot Spoiler Ahead!] In a particularly intense scene, a character wearing a Duke University T-shirt contemplates suicide. The scene sparked concern at Duke, which issued a statement clarifying that it had not authorized the use of its marks. As a university spokesperson explained, “Duke appreciates artistic expression and creative storytelling, but characters prominently wearing apparel bearing Duke’s federally registered trademarks creates confusion and mistakenly suggests an endorsement or affiliation where none exists.” Yet, as of today, Duke has not filed an action against HBO for trademark infringement. The scene raises a question increasingly relevant not just for filmmakers, but also for content creators across platforms like YouTube, Instagram, TikTok, and Facebook. Can you use a real brand in your video, skit, short film, or story post? Whether it is a college logo, a soda can, or a smartphone, what are the legal risks when someone else’s trademark shows up in your work? The answer lies at the intersection of trademark law (Lanham Act) and the First Amendment. Here, the rules focus less on traditional consumer confusion and more on creative boundaries. For decades, courts have applied the Rogers test, first outlined in Rogers v. Grimaldi, 875 F.2d 994 (2d Cir. 1989). This test allows the use of a trademark in an expressive work if the use has (1) some artistic relevance to the underlying work and (2) is not explicitly misleading as to source or endorsement. The threshold for relevance is intentionally low. The trademark must add meaning to the story or message, and it cannot falsely suggest that the brand sponsored or approved the content. That standard generally works in favor of creators. A T-shirt worn by a fictional character, even in a dramatic or negative scene, is unlikely to make viewers believe the brand was involved in or sponsored the production. The same is true for creators filming a comedy sketch in a grocery store or doing a product parody on YouTube. The use is part of the narrative, not a commercial endorsement. But use of a trademark as an expressive work under the Rogers test isn’t always allowed. In 2023, the U.S. Supreme Court narrowed the test’s reach in Jack Daniel’s Properties, Inc. v. VIP Products LLC, 599 U.S. 140 (2023), holding that Rogers does not apply when someone uses another’s trademark as a trademark—that is, to indicate the source of their own goods. The case involved a squeaky dog toy mimicking a bottle of Jack Daniel’s. Because the toy’s branding functioned as a source identifier for the toy maker (not just a joke or artistic nod), it had to face the usual trademark infringement test based on likelihood of confusion. In short, Jack Daniel’s reaffirmed that expressive use is protected, but only when the mark isn’t being used “as a mark,” i.e., to identify the source of the user’s own goods. In those cases, First Amendment protections do not override the Lanham Act. Jack Daniel’s also limited expressive use permitted under the Rogers test to situations where the accused infringer is not using the mark to identify its own products. In general, for both filmmakers and digital creators, most incidental brand appearances—on T-shirts, background signage, or product packaging—are not about source identification for the creators. They are part of telling a story, setting a scene, or adding authenticity. For instance, a university T-shirt may be used to convey the educational background of a character or a designer handbag may be used convey that a character indulges in luxury or seeks to convey their societal status. As long as the content does not suggest affiliation or sponsorship, or amount to defamation, the First Amendment likely protects the use. That said, a legally defensible position is not always a litigation-free one (see below examples). Brand owners may still object on principle or for public relations reasons. Brand owners may even sue, not necessarily because they will win, but because they want to send a message or chill future uses. Given the fact-intensive nature of the Rogers analysis, cases involving the use of another’s brand are not always straight-forward. And even a weak claim can impose substantial costs if it leads to discovery or public backlash. Moreover, both brand owners and content creators should consider the effects of product placement to incentivize, or disincentivize, use of trademarks in a particular way. B. When the Brand Isn’t the Star: Unauthorized Use, Product Placement, and Strategic Exposure A common theme among cases brought by brand owners is that their product is being depicted in an unflattering manner. After all, brand owners have an obligation to monitor and police the unauthorized use of their marks or risk losing their trademark rights. But, in general, a brand owner will have an uphill battle in trying to prevent others from using their products on video when the user is not attempting to drive sales by leveraging the trademark and is, in fact, treating the brand owner consistently as the source of the product. When used in this manner, consumers are likely to continue to associate the brand with the brand’s products, even if the brand owner did not expressly authorize the featuring of its products. For example, many will instantly recognize Slip ‘N Slide as the flexible plastic waterslide of their childhood. Slip ‘N Slide is a registered trademark of Wham-O, Inc. and served as the creative backdrop of a gag in the movie Dickie Roberts: Former Child Star when Dickie Roberts attempts to reclaim his lost childhood by learning to use the slide. The slide is correctly referred to as a Slip ‘N Slide twice in the movie, which was reasonably necessary to identify the popular toy. Anxious to experience the slide, Dickie’s first attempt fails as he painfully skids to a halt after failing to add water. His second attempt is a success, and he comes to a halt after the end of the slide. But this spurs him to try again, this time coating the slide with cooking oil, which causes him to slide at full speed beyond the end of the slide and through a neighboring fence. The cooking oil slide gag was featured prominently in the movie’s promotional materials. Wham-O sued Paramount Pictures, claiming that use of the Slip ‘N Slide trademark would cause confusion as to whether it was the source of the movie, had endorsed or sponsored the film, or had otherwise approved of the use of its product in this manner. Wham-O also argued that the misuse of the slide, which resulted in injury, may cause consumers to view its mark in a negative light. The Court disagreed. It found that, despite the obvious misuse of the slide, the Slip ‘N Slide mark would be no less distinctive as a mark and the mark was not highlighted in a way that exploited its value. As summarized by the Court, the movie “use[d] the marks and product in a specific and unique descriptive sense: to evoke associations with an iconic child’s toy.” In a similar instance, Caterpillar sued the Walt Disney Company for violating its trademark rights after the film George of the Jungle 2 highlighted villains using Caterpillar bulldozers to threaten George’s jungle. The bulldozers were Caterpillar products bearing Caterpillar’s trademarks, and nothing suggested the products were of shoddy or low quality. The narrator even referred to them as “maniacal machines.” Caterpillar contended that this was unauthorized use of its trademarks and also cast the company in “an unwholesome or unsavory light.” Caterpillar Inc. v. Walt Disney Co., 287 F.Supp.2d 913 (C.D. Ill. 2003). But Caterpillar was unsuccessful in obtaining a temporary restraining order to halt the release of the movie because the court found no evidence that Disney was attempting to use the fame and goodwill of Caterpillar’s trademarks to drive sales of its DVDs. The court further explained that “it appears unlikely ... that any consumer would be more likely to buy or watch George of the Jungle 2 because of any mistaken belief that Caterpillar sponsored this movie.” Likewise, the court found it unlikely that viewers would hold the bulldozers responsible for the attempted destruction of George’s home, instead noting that they were clearly being operated by the villains. In short, the movie depicted the bulldozers in their unaltered state and consumers would still associate the Caterpillar trademark with the equipment it identifies. While brand owners are constantly monitoring for unauthorized use of their marks, many are taking a more active approach. In some instances, brands will offer to supply or loan products for use in films so long as filmmakers abide by the brand owner’s guidelines. If filmmakers disregard the brand owner’s guidelines, their access to relevant products for future projects may be cut off. Others go a step further and pay for product placement in movies or social media content to ensure that their products are featured in a positive light. When promoted effectively, these associations can be subtle and pay dividends many times over. For example, according to film, if you want to travel like Tony Stark, drive an Audi; if you want to travel like James Bond, drive an Aston Martin; and if you want to travel to Europe like Spider-Man (without the aid of your webslingers), then fly on United Airlines. Perhaps the most famous example of product placement is Reese’s Pieces. For over 40 years, audiences viewing Steven Spielberg’s E.T. have seen Reese’s Pieces, not M&M’s, used to lure E.T. into Elliot’s home. But that was not in the original script. When the production failed to receive permission to use M&M’s, they instead secured a product placement deal for Reese’s Pieces. As a result, Reese’s Pieces saw a tremendous sales bump due to the popularity of the movie. Product placement need not be direct either. F1 The Movie is reported to have secured over $40 million in brand sponsorship for the fictional racing team APXGP. Many of the brands’ logos are displayed on the racing suits of the main characters, even though the brands’ products themselves never appear on screen. In addition to providing exposure for the brands, this has also caused a secondary effect, where the characters of the movie are featured wearing their branded racing suits while promoting unrelated products. For instance, in a Heineken advertisement, Brad Pitt and Damson Idris can be seen sharing a drink while logos for companies such as Intensify, Geico, EA Sports, and others are prominently displayed on their racing suits. By engaging in product placement and sponsorship, brand owners are able to actively control how their brands are used, and production teams are provided with access to valuable capital for their project. When possible, brand owners should look for opportunities to promote their brands and actively control how those brands are used. Whether by product placement, creative borrowing, or visual cues in the background, content featuring real brands is not going anywhere. But the risks and incentives vary depending on the medium and the message. On social media, where sponsored content is ubiquitous, content creators must tread carefully when integrating real-world marks into their work, especially when sponsorships, endorsements, or commercial gain are involved. C. Likes, Lawsuits, and Logos: Trademark Risks in Influencer and Creator Content Today, most of the public consumes media through social media platforms like Instagram, TikTok, YouTube, and Facebook. These platforms have created an ecosystem that allows content creators, or “influencers,” to monetize their content through brand ambassadorships or by building their own brand. But content creators, and their employees, must be vigilant when using others’ intellectual property and when protecting their own intellectual property. Some brands actively embrace influencer marketing. For example, Stanley’s now-iconic tumblers saw a massive surge in popularity thanks to organic and sponsored posts by content creators, turning the 110-year-old brand into a viral hit. But not every company is as welcoming. For example, in Petunia Products, Inc. v. Rodan & Fields, LLC and Molly Sims, a social media blogger posted a sponsored blog entry promoting a Rodan & Fields eyebrow product called “Brow Defining Boost.” However, Petunia Products has a competing product that uses the trademark BROWBOOST®. Petunia Products not only sued Rodan & Fields but also sued the blogger. The United States District Court for the Central District of California declined to dismiss the blogger from the lawsuit because the blogger’s promotion of the product “crossed from protected consumer commentary to commercial use” as a paid advertisement. To minimize the risk of infringement liability, content creators should be careful when using existing trademarks and consider the context in which the mark is used. If the mark is being used for a commercial purpose, content creators may obscure or blur out trademarks—a practice known as “greeking” that is often seen in reality TV—to avoid any infringement. Greeking may also be an option when seeking to prevent free product placement, thereby encouraging brands to sponsor or pay for future placement. But where greeking is not an option, content creators should perform due diligence before endorsing a brand, and should consider entering into a defense and indemnity agreement with the brand owner before agreeing to post. D. Conclusion Trademark law isn’t about shielding brand owners from discomfort. It is about preventing consumer confusion and protecting marks from being used to sell someone else’s goods. In today’s world of content creation, from television to smartphone videos, understanding where the legal lines are, and how far they bend for expressive works, helps creators stay creative without unnecessary legal headaches. But a good legal argument is not immunity. Brands may still bring claims, especially when reputation is on the line. Knowing the law is step one. Preparing for a challenge, even when you are right, is just as important. In an era where monetization, sponsorships, and influencer marketing are the norm, the legal risks can scale as fast as your audience. The First Amendment offers strong protection for expressive works, but it is not a free pass. Strategic decisions about trademark use, clearance, and registration can make the difference between a viral moment and a legal one.
July 28, 2025
Trade Dress
Labubu and La-No-No: Navigating Trade Dress in Plush Toys
Most companies would love to have their product become a viral sensation, but in the age of viral media and “internet dupes,” companies are forced to fire on all cylinders to successfully secure and defend the intellectual property rights when one of their products takes off unexpectedly. Just look at the newest internet-sensation plush toy: Labubu. Labubus are fuzzy, monster-like toys that have gained popularity among a variety of ages, finding a large fanbase on TikTok. These toys are the creation of Kasing Lung, the illustrative artist of the book series, “The Monsters.” Following the publication of this series, Lung released a toy version of the “monsters.” And in 2019, Lung teamed up with POP MART, a Chinese toy company, to take this toy line to the next level. POP MART did exactly that, although its success did not occur overnight. This new monster collection toy line received the name—“Labubu.” Despite Labubu’s launch in 2019, POP MART did not seek trademark rights until after the beginning of the toy’s viral success in 2024. And even then, POP MART filed only for the registered word mark “Labubu.” Since 2024 Labubu replicas have been popping up all over the internet, including dupes touting the name "Lafufu." Obtaining registered trademarks for these internet sensation toys pose challenges, especially when filing after going viral, like POP MART. While there are well-established rules in U.S. trademark law that the first to use the mark in commerce has trademark priority, this is does not completely curtail the filing frenzy. Not to mention, securing trademark rights early can help companies enforce their rights after the inevitable “dupes” surge the market. Labubu 3-D Printed Look-Alike One option for POP MART may be to assert trade dress claims. Squishmallows, a different internet-viral plush toy, have also faced widespread copyright and trademark issues from internet dupes. Squishmallow’s manufacturer, Kelly Toys Holdings, filed for trademark protection of the word mark “Squishmallow” in 2018, several years before the peak of its internet fame in 2023. However, like POP MART, Kelly Toys did not file for trade dress protection for its plush, egg-shaped line of toys. But with its rise in internet fame (and therefore dupes), Kelly Toys has taken an active stance in the enforcement of its trade dress rights. In February 2024, Kelly Toy sued Build-A-Bear Workshop, Inc. in Kelly Toys Holdings, LLC v. Build-A-Bear Workshop, Inc., 2:24-cv-01169, alleging that Build-a-Bear’s new line of plush toys had the same distinctive trade dress as Squishmallows. For a trade dress infringement claim in California to succeed, the plaintiff must “clearly articulate” its claim to give the defendant adequate notice of the total image, design, and appearance of the trade dress. In its complaint, Kelly Toys described the Squishmallow trade dress to include: egg-shaped plush toys depicting various characters, simplified Asian style Kawaii faces with repeating rounded graphics, embroidered facial features, short-pile velvety velour-like fur, and a squeezable marshmallow feel. Build-A-Bear moved to dismiss the complaint, arguing that the Plaintiff’s description of its trade dress was overbroad, vague, and included “generic and functional features commonly found in plush products.” However, the California Central District Court disagreed with Build-A-Bear, concluding that the focus of a trade-dress analysis is not about the individual features but rather the “overall visual impression that the combination and arrangement [] those elements create.” The court also disagreed with Build-A-Bear’s argument that to assert a protectable trade dress, Kelly Toys must allege a trade dress that is “common to all items in the series or line.” Build-A-Bear argued that because Kelly Toys’s trade dress description could not apply to its over 3,000 product line of Squishmallows, it could assert no trade dress whatsoever. The court held that this sort of fact-intensive, product-by-product analysis is inappropriate at the pleading stage, but the court noted that it could revisit the consistent-overall-look test at the summary judgment stage with a developed factual record. A trade dress claim by Labubu may face similar opposition. Like the Squishmallows in Kelly Toys, Labubu’s signature features—its expressive eyes, oversized head, and mischievous expression—taken together may create a recognizable aesthetic associated with the Labubu brand. However, also like Squishmallow’s range of plushies, there are distinctive features across the iterations of Labubu’s expanding product line. POP MART has already taken some legal action. Earlier this year, a Chinese court ruled in favor of POP MART, finding the sale of 3D printed Labubu duplicates to be a violation of Chinese copyright laws. Time will tell if POP MART uses other tools to protect Labubu products and whether they can do so before the market moves on to the next fad.
July 17, 2025
Copyrights
ER and The Pitt-falls of a Frozen Rights Provision
Michael Crichton, author, director, and visionary created works that resonate today like Jurassic Park, Twister, Westworld, and ER. Now, his estate is suing the production team and leading actor of the newly released medical drama known as The Pitt for being a knock-off of ER. The lawsuit alleges a breach of contract action against Warner Bros. Television, claiming that the underlying concepts behind The Pitt mirror too closely to the original screenplay of the television series known as ER. The original show, ER, aired on NBC with Noah Wyles as a lead actor playing Dr. John Carter. John Wells was hired as the initial showrunner on ER, later joined by R. Scott Gemmill in the series' sixth season who held the title of supervising producer. After negotiations with the Crichton estate to reboot ER failed, Warner Bros. announced the debut of The Pitt, a medical drama based in a Pittsburg emergency room, starring… none other than Noah Wyles. Wyles plays Dr. Michael “Robby” Rabinovitch, an entirely different character from his role in ER, but there are some noticeable similarities between The Pitt and ER. First, Wyles’ character in The Pitt is a doctor in the emergency room but 30 years older and more experienced. Second, The Pitt's production team is similar to that of ER. Wells holds the position of executive producer. Gemmill holds the title of showrunner and is also one of the executive producers. Lawsuits regarding unauthorized derivative artistic works often focus on copyright claims, but this is a contract case. Although Crichton assigned the copyrights of ER to Warner Bros. in the original 1994 agreement, the contract contained a “Frozen Rights Provision,” in which they agreed that "any sequels, remakes, spin-offs and/or other derivative works . . . shall be frozen, with mutual agreement between [the parties] being necessary in order to move forward . . ." Crichton’s estate alleges that Warner Bros.' creation of The Pitt is a clear breach of the Frozen Rights Provision in the 1994 agreement. In other words, the Frozen Rights Provision in the 1994 agreement transformed what might more commonly be a copyright claim into a breach of contract claim, putting both parties in a unique position. If this were a copyright infringement case, Crichton’s estate would not only have to show that The Pitt is derivative of ER, but also meets the “substantial similarity test.” Proving substantial similarity can be difficult given the subjective nature of the analytic framework. Warner Bros. could also argue in defense that despite some similarities, they aren’t substantial because The Pitt takes on an entirely new setting, pace, and plot than that of ER. With the breach of contract claim, Crichton’s Estate must prove that Warner Bros. breached the Frozen Rights Provision—which covers any “derivative work”—in their creation of The Pitt. However, proving that a work is derivative and overcoming the substantial similarity test are not the same thing. A work can be derivative but still fall short of the similarities required to prove copyright infringement. Thus, in the context of a breach of contract claim, Crichton’s estate need only prove that The Pitt is a derivative work to support their breach of contract claim, rather than meeting the burden of proof required of a copyright infringement claim. IP rights are often covered in contracts, and it is worth considering the advantages and disadvantages of creating a specific contract provision like the “Frozen Rights Provision” here to limit future IP use. If The Pitt can convert Dr. Carter to Dr. Robby, then perhaps you can convert an IP claim into a breach of contract claim.
July 9, 2025
Copyrights
Sharing the Stage: How Tempo Music Investments LLC v. Miley Cyrus et al Reinforces Copyright Co-owner Rights
A recent ruling from the United States District Court for the District of Central California in the lawsuit against Miley Cyrus and others for the song “Flowers” highlighted the power that a single copyright co-owner holds in protecting their interest. The Court denied a motion to dismiss brought by Cyrus and her co-defendant song writers (the “Songwriter Defendants”), rejecting their argument that the plaintiff lacked standing to bring suit as the successor-in-interest of a copyright co-owner. The Songwriter Defendants’ motion turned on a key principle of copyright law: a single co-owner, even without the consent of other co-owners, can sue for infringement. The Court’s decision reinforced that copyright co-ownership includes not only the benefit of royalties—but also remedies. In February 2024, Cyrus left the Crypto.com Arena with not one but two Grammy Awards for her 2023 smash hit “Flowers,” triumphing Record of the Year and Best Pop Solo Performance. However, “Flowers” proved not to be all sunshine and roses for Cyrus, as it also brought her a federal lawsuit alleging unlawful copying of the 2013 Hot 100-Charting song “When I Was Your Man” performed by Bruno Mars. Mars, Ari Levine, Andrew Wyatt, and Philip Lawrence are the co-writers of “When I Was Your Man,” with Tempo Music Investments LLC (“Tempo”) acquiring Lawrence’s interests in the song in 2020. On September 16, 2024, Tempo sued Cyrus and others for copyright infringement in Tempo Music Investments LLC v. Miley Cyrus et al., 2:24-cv-07910, with Central California District Court Judge Dean D. Pregerson presiding. In its Complaint, Tempo claimed that any Mars fan would recognize that “‘Flowers’ duplicates numerous melodic, harmonic, and lyrical elements of ‘When I Was Your Man,’ including the melodic pitch design and sequence of the verse, the connecting bass-line, certain bars of the chorus, certain theatrical music elements, lyric elements, and specific chord progressions.” Tempo also included side-by-side comparisons of the songs’ respective melody, harmony, and lyrics to allege intentional similarities and meaningful connections. An example is the following lyrical comparison: “When I Was Your Man” “Flowers” That I should have bought you flowers And held your hand Should have gave you all my hours Take you to every party cause all you wanted to do was dance I can buy myself flowers And I can hold my own hand Talk to myself for hours I can take myself dancing Fans on social media noticed that while “When I Was Your Man” features a man lamenting his failure to treat his lover better, “Flowers” appears to celebrate a woman’s embrace of independence. The Songwriter Defendants moved to dismiss the case, arguing Tempo lacked standing because it does not own the exclusive copyright to “When I Was Your Man.” The Songwriter Defendants contended that Tempo’s Complaint suffered a “fatal flaw” because Tempo “br[ought] this copyright infringement action alone — without any of that musical composition’s co-authors or other owners[.]” The Songwriter Defendants interpreted Section 501(b) of the Copyright Act to mandate dismissal under these facts, because only an exclusive legal or beneficial owner of a copyright right may sue for infringement, with Tempo being neither. The Songwriter Defendants asserted that, in the Ninth Circuit, the law is that the assignee or licensee of one co-author’s interest in a joint work’s copyright lacks the requisite standing to bring a copyright suit. In so doing, the Songwriter Defendants primarily relied on Tresóna Multimedia, LLC v. Burbank High Sch. Vocal Music Ass’n, 953 F.3d 638 (9th Cir. 2020) and Sybersound Records, Inc. v. UAV Corp., 517 F.3d 1137 (9th Cir. 2008). The Songwriter Defendants interpreted these authorities for the proposition that a single co-author of a copyright interest, acting alone, cannot assign or license exclusive rights, because those rights are also owned by the assignor’s or licensor’s co-authors. The Songwriter Defendants further reasoned that a co-author can only grant non-exclusive rights because such co-owners are akin to tenants in common, each of which owns shares of an undivided whole. Tempo opposed, arguing that Section 201 of the Copyright Act makes clear that “copyright interests are divisible and can be sold just like any property interest” such that co-owners can unilaterally transfer their copyright interests without permission from the other co-owners. Likewise, Tempo asserted it is black letter law that a co-owner of a copyrighted work can sue a third-party for infringement without joining the other co-owners in the action or otherwise obtaining their permission to proceed with litigation. Thus, upon acquiring Lawrence’s interest to “When I Was Your Man,” Tempo maintains it stepped into Lawrence’s shoes as his successor-in-interest with the right to bring any claim for copyright that Lawrence (or any other owner of “When I was Your Man”) could bring. Judge Pregerson agreed with Tempo, and denied the motion to dismiss, ruling that, under the Copyright Act’s provisions for divisibility and alienability of copyright ownership, a co‐owner may sue a third party for infringement without joining the other co‐owners. The decision reasoned that the Songwriter Defendants misunderstood case law from the Ninth Circuit that stems from the word “exclusive,” because “[o]wnership of ‘exclusive rights’ is not to be conflated with ‘exclusive ownership’ of rights.” Indeed, each co‐owner of a copyright owns an interest in the exclusive rights that make up the copyright, and these exclusive rights are exclusive to the co‐owners collectively as against the rest of the world. Judge Pregerson emphasized that neither Tresóna nor Sybersound limited a co‐owner’s ability to transfer his/her ownership interest in a copyright. He underscored that in Corbello v. DeVito, 777 F.3d 1058 (9th Cir. 2015), the Ninth Circuit made clear the distinction between exclusive rights and exclusive ownership, reasoning that “[t]ransferability of a copyright is no different for a co-owner than it is for a sole owner.” If a co‐owner’s right to sue for infringement was otherwise lost upon transfer, that would diminish the value of jointly-owned copyrights, which in turn would undermine Congress’ intent in allowing copyrights to be divided and its acknowledgment of co-ownership of joint works. In rejecting the Songwriter Defendants’ lack of standing argument, Judge Pregerson clarified several other fundamental rights that copyright co-owners hold: A co‐owner may transfer his/her ownership interest without obtaining permission from the other co‐owners; A co‐owner cannot grant an exclusive license to a third party without the consent of all co‐owners, because a co‐owner cannot transfer more than he/she owns; A co‐owner cannot limit the independent right of the other co‐owners to use and exploit the copyright without their consent; A co‐owner, when acting alone, may only grant a non‐exclusive license to a third party; and Each co‐owner of a copyright owns an interest in the exclusive rights that make up a copyright, and these exclusive rights are exclusive to the co‐owners collectively as against the rest of the world. This reiteration of rights serves as an important reminder that copyright co-owners should be mindful of the parties with whom they share their rights and when they do (or do not) need permission to act independently of the other co-owners.
June 9, 2025
Data Protection and Privacy
23andMe Sparks Lawmaker Race to Protect Genetic Data in Bankruptcy
When direct-to-consumer genetic testing company 23andMe Holding Co. and its affiliates (together, “23andMe”) filed for chapter 11 bankruptcy on March 24, 2025, they possessed data from over 15 million customers. Specifically, 23andMe possesses genetic data obtained from analysis of DNA in saliva samples customers provide for analysis and interpretation of their ancestry traits and genetic health risks. 23andMe uses data from certain consenting customers – about 80 percent of those eligible – for research and extrapolates even more information from customer DNA. Genetic data in 23andMe’s possession is no doubt valuable. Indeed, in collaboration with GlaxoSmithKline, it has been used to develop drugs, and it can also be used to study diseases. In 2023, however, a data breach exposed the vulnerability of 23andMe’s data and customers. The perpetrator accessed information for about 7 million customers. Media outlets reported that information obtained through the breach was used to compile and publish online lists of customers with specific types of ancestry. Upon entry into bankruptcy, 23andMe announced efforts to sell all or portions of its assets, including its databases of genetic information. The Office of the United States Trustee (a division of the Department of Justice) and dozens of state attorneys general raised an alarm, stressing the need for privacy protection in connection with the sale of genetic data and personally identifiable information. The attorneys general point out in filings that 23andMe’s records are not subject to HIPAA, though a variety of state laws apply to health information in 23andMe’s possession. On April 29, 23andMe agreed to the appointment of a consumer privacy ombudsman (“CPO”) to assist the bankruptcy court in evaluating proposed sales or leases of customers’ genetic data, health, and personal information. The CPO is tasked with understanding 23andMe’s privacy policies and whether proposed uses of assets violate those policies or applicable laws, evaluating the privacy policies and cybersecurity programs of potential purchasers, and evaluating a proposed sale or lease in light of customer privacy concerns. On May 19, 23andMe announced that Regeneron Pharmaceuticals, Inc. is the successful bidder for substantially all of 23andMe’s assets, for a purchase price of $246 million. A hearing for the bankruptcy court to consider approval of the sale is currently scheduled for June 17, and a report by the CPO regarding the proposed sale is currently due on June 10. 23andMe’s bankruptcy has spurred a bipartisan effort to protect consumer genetic information in bankruptcy cases. On May 22, Senators John Cornyn (R-TX), Amy Klobuchar (D-MN), and Chuck Grassley (R-IA) introduced the “Don’t Sell My DNA Act.” The bill proposes to amend the Bankruptcy Code to: (1) include genetic information as personally identifiable entitled certain protections in bankruptcy cases; (2) require the affirmative consent of consumers regarding the sale, use, or lease of their genetic information in bankruptcy; (3) require provision of notice regarding proposed use, sale, or lease of genetic information in bankruptcy; and (4) require the destruction of genetic information a bankruptcy estate does not sell, lease, or dispose of during bankruptcy. If enacted, the Don’t Sell My DNA Act would make selling genetic data in bankruptcy more difficult, because any transaction would require affirmative consent, such as electing in writing to “opt in” to a sale, from individuals whose genetic information is proposed to be sold. Additionally, provision of notice to all such individuals would add expense to bankruptcy sale processes. These measures, if made law, could mean that, like DNA, 23andMe’s proposed sale of genetic data in bankruptcy will be one-of-a-kind.
June 4, 2025
Advertising
INTA in Sunny San Diego: A Quick Wrap-Up
Photo by Sarah Robertson The Dorsey Trademark, Copyright + Advertising team is back from the 2025 International Trademark Association Meeting. It was one for the books. We mixed and mingled with old and new colleagues and as well as our friends from around the world. In between all the meetings and social events, we did manage to attend a few of the important panels and of course, our committee meetings. Here are the highlights: AI-Driven Advertising: Copyright Issues in the New Frontier – This was a lively and engaging panel that focused on managing the chaos that the burgeoning use of AI by companies and independent contractors has caused relating to ownership and authorship of AI-created content. The panel several times reiterated the mantra: Be Fair, Be Bold, Be Reasonable. They encouraged companies to ask whether they actually need to own the content that is created. They also discussed contract clauses “from the wild” and pointed out what works and what can be unreasonable. The most important takeaway was to make sure that whoever is using AI to create content is documenting the process carefully, regardless of whether it is a vendor or an employee. This is because the Copyright Office will require an explanation as to the use of AI to determine whether, and how much of, a work is registrable. USPTO Update: Fireside Chat with Acting Under Secretary of Commerce for Intellectual Property and USPTO Acting Director Coke Morgan Stewart – Acting Director Stewart answered questions about the PTO’s direction under the current administration. She indicated that the USPTO has explained to the administration that as a fee generating agency – rather than a taxpayer funded agency – the USPTO should not be subject to current cost-cutting measures. Despite this, Acting Director Stewart believes the agency can continue to reduce pendency and maintain quality without filing open positions. She also indicated the USPTO is looking into the use of AI to help with review of design marks and to detect fraud. Our neighbors to the North, the Canadian Intellectual Property Office (CIPO), also provided updates about the examination process and efficiency, indicating that they hoped to clear their backlog in just a few months. Greenwashing, Greenhushing and Sustainably: INTA’s Brands and Sustainability Committee met at this year’s conference to discuss the hot topics of greenwashing and greenhushing. If you are not familiar, greenwashing is essentially the false marketing of green/environmental or sustainable claims. Most recently, we’ve seen a lot greenwashing in the context of aspirational claims, namely brands striving to be carbon neutral or reduce their emissions by a certain year. Greenhushing, on the other hand, is when brands do good for the environment, but don’t publicize it. Greenhushing can occur for various reasons including, fear of accusations of greenwashing, consumer perception that “green” products are more expensive or inferior, or even for political reasons. While we didn’t make any promises or claims, the committee was proud to support a digital business card initiative and encourage the use of reusable water bottles to help make the conference more sustainable for all. Crafting Successful Agreements with Branding Agencies: A roundtable discussion took place between practitioners from Canada, the UK, and US on how brands can best partner with their creative agencies and areas of best drafting practices for agreements between the two. Discussion of the scope of services and consideration of AI-generated work product dominated the conversation, including how best to allocate risk created by the use of AI particularly where this work product is specifically contemplated or where influencers are involved. Discussion of the extent of preliminary clearance work members of the group were carrying out on behalf of agencies, or that agencies were otherwise expected to conduct, also took place. An overall downward trend in full, in-depth trademark search orders more generally, as shared by the one of the leading search companies present, was also covered. The unique risks attached to working with smaller agencies, including the absence of enterprise software licenses, was also discussed. Law and Policy | Rules of the Road in Engaging with Celebrities, Influencers, and Fans: This session brought a global perspective to how companies interact with and negotiate with celebrities and influencers in relation to the promotion of their brands. The panelists focused on how they prioritize and make use of time and resources depending upon the nature and length of a promotion, as well as the potential impact of the promotional activities on their brands. Interestingly, in Argentina, many companies create specific scripts that must be used by influencers to help minimize regulatory and legal risks. Aside from potential pitfalls in agreements, the panelists also discussed deepfakes and artificial intelligence and the impact on their promotional activities and on their brands, as well as issues with poor influencer behavior and even taxation issues. Truly, an ever-evolving area as technology becomes even more intwined in the influencer landscape. Successfully Mediating IP Disputes: Key Insights and Practical Tips – INTA’s ADR Committee hosted a panel discussion on trademark mediation, highlighting the growing value of mediation in resolving IP disputes. Panelists emphasized its advantages over litigation, including lower costs, reduced risk, and the opportunity for creative, business-focused solutions. They discussed the qualities of effective mediators, such as neutrality, communication skills, and business acumen, and considered whether mediators should propose solutions or simply facilitate dialogue. The consensus favored a balanced approach that maintains neutrality while offering constructive suggestions. The discussion also addressed the importance of preparation, confidentiality, and having decision-makers present. Challenges of virtual mediation were noted, including distractions and reduced engagement, as well as the supportive but limited role of AI. Real-world examples illustrated the need for mediators to guide the process while allowing parties to retain control over outcomes. Annual Review of Trademark Cases: Always an attendee favorite, this session featured an overview of trademark decisions over the last 12 months lead by Theodore Davis of Kilpatrick Townsend and John Welch of The TTABlog fame. Notable decisions include those upholding the validity of the Lanham Act’s “names clause” (requiring written consent to register a mark containing a person’s name) under the First Amendment (Vidal v. Elster, 602 U.S. 286 (2024)), confirming that inaccurate patent claims may provide grounds actionable false advertising claims (Crocs, Inc. v. Effervescent, Inc., No. 22-2160 (Fed. Cir. 2024)), holding mere use of a party’s name in a judicial proceeding is not actionable under Lanham Act (Dieujuste v. Sin, No. 24-1522-cv (2d Cir. 2025)), confirming that the TTAB’s “something more” doctrine applies only to the relatedness of goods to services and not to goods to goods (In re Samsung Display Co., Ltd., No. 90502617 (T.T.A.B. 2024)), and clarifying that product color resulting from practicing an expired patent cannot also have trademark significance because the color is functional under the expired patent (CeramTec GmbH v. Coorstek Bioceramics LLC, No. 2023-1502 (Fed. Cir. 2025)). John Welch also recounted his top losing TTAB arguments, with the number one slot belonging to arguments that attempt to impart in real-world limitations to goods/services in an application/registration (since the TTAB typically only considers the goods/services as listed), and listed some of his pet peeves, such as using the word “trademark” as a verb (ironically used as such by the Supreme Court in its Elster decision).
May 27, 2025
Advertising
New Guidance on Fake Reviews in the UK—What Consumer Businesses Need to Know Under the DMCC Act 2024
The UK Government has issued important guidance on fake reviews, clarifying new obligations for businesses under the Digital Markets, Competition and Consumers Act 2024 (the “DMCC Act”). The Competition and Markets Authority (CMA) now has enforcement powers to act directly against violations of the legislation, including imposing significant financial penalties (without having to act through the courts). Businesses with presence in the UK involved in the collection, management, or publication of consumer reviews are advised to take steps to ensure compliance. Overview of Prohibited Practices Under the DMCC Act and accompanying guidance (CMA208), the following practices are now expressly prohibited in the UK: Commissioning or submitting fake reviews: This includes writing or arranging reviews that are fabricated or misleading, whether by internal staff, third-party providers, or automated tools. Publishing incentivised reviews without disclosure: While incentivising reviews is not banned outright, the CMA requires any material connection (such as discounts or free products) to be clearly disclosed. Failure to do so may constitute a misleading omission under applicable consumer law. Manipulating review presentation: Selectively displaying only positive reviews or suppressing negative ones, including through algorithms or manual curation, is likely to be considered deceptive conduct. Facilitating or selling fake reviews: Platforms and intermediaries that enable or promote the sale of fake review services may also be liable under the new regime. Compliance Expectations for Businesses Businesses are expected to adopt robust internal systems to prevent and detect the use of fake or misleading reviews. Specifically, the CMA expects businesses to meet the following requirements: Develop and maintain clear internal policies and procedures on how reviews are collected, moderated, and published, with particular attention to transparency and fairness. Regular monitoring and auditing of published reviews to identify suspicious activity, such as repetitive language or unverified users. Training for staff and third-party providers to ensure awareness of legal obligations, particularly in marketing, customer service, and IT functions. Transparent disclosures whenever reviews are incentivised. Disclosures must be prominent and understandable to a typical consumer. Enforcement and Penalties The CMA now has the power to issue fines of up to £300,000 or 10% of a business’s global turnover (whichever is higher) for breaches. In addition, individuals involved in unlawful practices may face personal liability, including director disqualification in serious cases. Next Steps We recommend all businesses engaging with online reviews conduct an immediate compliance review in light of this guidance. Particular attention should be paid to contracts with third-party review providers, website review mechanisms, and any incentives offered to customers. Here is a full PDF of the CMA’s Fake Reviews guidance.
May 20, 2025
Advertising
If Approved, Employers May See AI Employment Discrimination Regulations in California Go into Effect this Summer
California workplaces may finally see new regulations addressing the use of artificial intelligence (AI) – specifically automated-decision systems (ADS) –in the employment context go into effect this summer. After years of proposed legislation fizzling out and proposed regulations undergoing several revisions, one agency – the California Civil Rights Council (CRC) – voted on March 21, 2025, to approve the final and modified text of the "Employment Regulations Regarding Automated-Decision Systems" (ADS Regulations). If approved by the California Office of Administrative Law and published by the California Secretary of State, the ADS Regulations could become effective as early as July 1, 2025. The CRC’s approval of the ADS Regulations comes after Assembly Bill (AB) 2930, as previously discussed, died in the California Senate in 2024, following AB 331 failing to pass the previous year. AB 2930, entitled “Automated Decision Tools,” tried to prohibit the use of any ADS tools – systems or services that use AI to make consequential decisions, such as those impacting employment – that resulted in discrimination. The CRC, which issues regulations implementing California’s civil rights laws, takes a different approach in accomplishing what California legislators set out to do: the CRC’s ADS Regulations update California’s existing anti-discrimination laws to include prohibitions against discrimination caused by ADS use in recruitment, screening, hiring, promotion, pay, leave, and other employment decisions. Key Provisions of the New Regulations Should the ADS Regulations be effective on July 1, employers will need to note that California’s anti-discrimination regulations will include the following key provisions: The definition of "Automated-Decision Systems": ADS tools are defined as: A computational process that makes a decision or facilitates human decision making regarding an employment benefit, as defined in section 11008(i) of these regulations. An Automated-Decision System may be derived from and/or use artificial intelligence, machine-learning, algorithms, statistics, and/or other data processing techniques. The ADS Regulations provide examples of common HR tasks that ADS performs, such as (a) using computer-based assessments or tests to make predictive assessments about an applicant or employee; (b) using computer-based assessments or tests to measure an applicant’s or employee’s skills or personality traits; (c) directing job advertisements to targeted groups; (d) screening resumes; (e) analyzing facial expressions, word choice, or voice; and (f) analyzing employee or applicant data acquired from third parties. An explicit ban on discrimination resulting from ADS use: The ADS Regulations specifically state that it “unlawful for an employer or other covered entity to use an [ADS] or selection criteria a (including a qualification standard, employment test, or proxy) that discriminates against an applicant or employee or a class of applicants or employees on a basis protected by the [California Fair Employment and Housing] Act [FEHA], subject to any available defense.” An emphasis on the importance of anti-bias testing: The ADS Regulations provide that the evidence, or lack of evidence, of anti-bias testing or similar proactive efforts to avoid unlawful discrimination will be relevant to any such ADS-related discrimination claim or available defense. An expansion of FEHA liability to include “Agents”: The ADS Regulations define “agent” to include “any person acting on behalf of an employer, directly or indirectly, to exercise a function traditionally exercised by the employer or any other FEHA-regulated activity, which may include applicant recruitment, applicant screening, hiring, promotion, or decisions regarding pay, benefits, or leave, including when such activities and decisions are conducted in whole or in part through” ADS use. The ADS Regulations make clear that the for the purposes of FEHA, “agents” are also an “employer.” Enhanced recordkeeping requirements: The ADS Regulations require employers and covered entities to preserve personnel and other employment records for four years, rather than two years. This mandate to preserve records extends to ADS data, which the ADS Regulations define as any data used in or resulting from ADS use and/or any data used to develop or customize an ADS for use by a particular employer or other covered entity. Looking Ahead If the ADS Regulations are approved by the Office of Administrative Law and become effective on July 1, then employers should continue to take proactive efforts to ensure their use of AI, including ADS, complies with anti-discrimination laws. With the definition of “employer” expanded to include “agents,” employers using ADS will need to closely review vendor agreements. And, as previously discussed, employers should continue building processes and designating personnel to perform impact assessments, perform bias audits, and report any adverse findings from the assessments and audits to relevant internal stakeholders. Dorsey continues to monitory new developments in the AI employment and workplace privacy space. Contact Melonie Jordan or your preferred Dorsey attorney for guidance in this fast-evolving area.
May 19, 2025
Data Protection and Privacy
Reintroducing the No FAKES Act
A bipartisan Bill aiming to protect individuals from having their voice and visual likeness used without their consent was reintroduced in Congress earlier this month. The Nurture Originals, Foster Art, and Keep Entertainment Safe (No FAKES) Act, was first introduced last year as a response to various celebrities having their image and voice used by generative artificial intelligence (AI) without their consent. The Bill is currently still in committees of both houses of Congress. If passed, the Bill would be historic, as it would create the first ever federal right of publicity. The federal right of publicity would allow individuals to hold other individuals and companies liable if they distribute any unauthorized digital replicas of an individual’s voice or image likeness. This legislation would also act as a carve out to Section 230 of the Communications Decency Act, thus allowing platforms to be held liable for failing to remove unauthorized digital replicas quickly when they have had sufficient notice of a deepfake. The recent reintroduction of the No FAKES Act coincided with GRAMMYs on the Hill Advocacy Day, hosted by the Recording Academy, on April 9th. This is a day for music makers and industry leaders to meet with lawmakers in Washington, D.C. to advocate for musicians’ interests. The Bill was reintroduced and sponsored by Senators Chris Coons (D-DE), Marsha Blackburn (R-TN), Amy Klobuchar (D-MN), and Thom Tillis (R-NC) and Representatives Madeleine Dean (D-PH) and Maria Salazar (R-FL). The legislation has been endorsed from various stakeholders from the music and movie industries including the Recording Industry Association of America, Motion Picture Association, SAG-AFTRA, the Recording Academy, Warner Music Group, Universal Music Group, among others. Perhaps more notably, the Bill has also been supported by technology platforms such as YouTube and OpenAI. The No Fakes Act was originally introduced in the Senate on July 31, 2024, and in the House of Representatives on September 12, 2024, as an attempt to respond to a growing number of deepfake creations. A deepfake is an artificial image or video of a person where their face, body, or voice appears real but has been created and/or manipulated with AI. Deepfakes can appear in various ways. In January 2024, a deepfake of Taylor Swift advertising Le Creuset Cookware appeared online. Drake and The Weeknd appeared to release a viral song titled “Heart on My Sleeve,” only for the music community to later find out the song itself was a deepfake. In the past two years, there has been an increasing number of stories where celebrities have had their visual and vocal likeness used in sinister ways. For example, various celebrities were the targets of visual deepfake photographs, that had the celebrities wearing a shirt that endorsed hate speech. Other celebrities have unknowingly been subjected to deepfake pornography being released. The legislation does not require a deepfake to involve a celebrity or notable figure for a person to have protections. The legislation would entitle every individual to a federal right of publicity so as to have control over their voice and image. For example, the press release for the Bill’s reintroduction discusses how a Maryland athletic director was arrested and charged after creating a deepfake voice recording of his boss, the high school principal, that included racist and derogatory comments that the school’s principal never actually made. This demonstrates how everyday individuals could be impacted and protected by the legislation as well. A draft of the Bill was circulated in late 2023 and at the time there was concern that the Bill could incidentally inhibit free speech rights. Critics voiced concerns that by holding platforms liable for hosting deepfakes, the Bill could incentivize over-removal of content and stifle creativity. Critics voiced further concern that content creators would not know when the Bill applied versus when it did not. For example, if an individual created a parody of a popular figure, critics were concerned this could violate a celebrity’s voice and visual likeness. Many of these concerns were addressed in the version of the Bill that was introduced in 2024, carving out exclusions for digital replicas that are consistent with the public interest such as commentary, criticism, satire, or parody. Following its introduction in July 2024, the Senate Bill went to the Senate Committee on the Judiciary. After the House Bill was introduced in September 2024, it went to the House Committee of the Judiciary. Currently, the No FAKES Act is still before both committees with an uncertain timeline for review. The Bill’s reintroduction is not due to changes to it or the Bill making it out of committee. Rather, the reason for the Bill’s reintroduction was likely two-fold. First, announcing the reintroduction of the bill on GRAMMYs on the Hill Advocacy Day helped to underscore its importance to artists and celebrities. Second, the reintroduction came with the newly announced support of technology companies like YouTube and OpenAI. While the legislation was largely supported by the music industry when it was first introduced, the support from key players in the technology sector could propel the Bill forward this year.
April 21, 2025
Copyrights
To Recuse or Not to Recuse? An Update.
Given that litigation in the United States can take years from start to finish, we rarely see a conclusion to the cases we follow. In a prior blog post, we looked at the potential recusal requirements of the U.S. Supreme Court when one—or even six—Justices have a personal, professional, or financial interest in the parties arguing before it. Although our ultimate question of whether a Justice would, or should, recuse themselves will remain unanswered, a long-standing copyright infringement case has concluded and warrants a final review. To refresh, in a September 2024 decision, the Second Circuit affirmed a lower court’s decision that defendant Internet Archive had infringed the copyrights of 127 books by facilitating the unfettered lending of digitized copies during the COVID-19 pandemic. In light of libraries shutting down across the country, Internet Archive created its “National Emergency Library,” which provided thousands of digital copies of books to people around the country who did not otherwise have access to such resources. However, the plaintiff book publishers argued that while Internet Archive had a right to loan out copies of the printed books it had lawfully acquired, it went too far by digitizing those same books and allowing upwards of 10,000 digital loan outs. These acts through the National Emergency Library, the plaintiffs argued, amounted to blatant copyright infringement. The courts agreed. Internet Archive had until December 7, 2024 to file a writ of certiorari with the U.S. Supreme Court. In a press release dated just three days prior, Internet Archives stated that it had decided not to pursue Supreme Court review of the appellate court’s decision. Although lamenting the opinion, Internet Archive vowed to continue advocating for a future in which “libraries can purchase, own, lend, and preserve digital books” as part of its ongoing mission to provide individuals with access to knowledge they might not otherwise have. But as a result of the Second Circuit’s decision, it would continue to work with the Association of American Publishers (“AAP”) to remove digital copies of the AAP’s member publishers’ books from Internet Archive’s repository upon request. The AAP celebrated Internet Archive’s decision, which effectively ended five years of combative litigation. In its own press release, the AAP proclaimed that “publishers have achieved a decisive and broadly applicable victory for authors’ rights and digital markets.” Such authors’ rights include further protection against online piracy, as well as unlawful use by artificial intelligence developers, who collect voluminous amounts of material to train their generative systems. As we have seen in numerous other cases working their way up through the courts, copyright owners, authors, and news outlets argue that AI systems feed on digitized copyrighted materials for training purposes, and the output is, allegedly, copyright infringing material. Permanently enjoining Internet Archive from digitizing printed books and loaning them out en masse is just one more step in protecting authors’ work from widespread, unrestricted dissemination, the AAP’s logic follows. So the Internet Archive lawsuit will not be the case that tests the Supreme Court’s recusal standards. But this is only the beginning. Outside of the intellectual property world, there continue to be calls for Supreme Court Justices to step down from cases before them if they have a conflict with, or an interest in, any involved party. But until the Code of Conduct for Justices of the Supreme Court of the United States is amended to add clarity to its vague terms, such as “financial relationship” or “private interest,” recusals will continue to be based on an honor system.
April 8, 2025
Advertising
Tips on How to Shape Up Your Influencer Advertising Program: The NAD Reviews Skims’ Instagram Posts for Proper Disclosures
For years now we’ve been blogging about how much the FTC and even the SEC on occasion love scrolling Instagram posts to see what influencer are up to. This post is about another three letter organization who likes to scroll to confirm advertiser and influencer compliance with the FTC’s now very well-known Endorsement Guides. If You Don't Know Now You Know - The National Advertising Division or the NAD was founded in 1971 as an independent self-regulatory, non-profit organization, whose mission it is to ensure adverting claims are truthful and accurate. The NAD is part of the BBB National Programs, an independent non-profit organization that oversees more than a dozen national industry self-regulation programs. Advertisers can bring challenges against one another and the NAD also initiates its own challenges. Participation is voluntary (this is not a court of law) and there is no possibility for fines or damages, but the NAD is friends with the FTC and refers cases on occasion. With that introduction out of the way, we are here to update you on a recent case filed by the NAD itself against Skims, the underwear, lounge wear and shapewear brand. While this blog probably won’t make you look slimmer, this post might just give your brand’s influencer advertising a clearer and more conspicuous look . Like many brands, Skims hires celebrities to promote the brand on social media. The case focused on whether social media posts by Lana Del Ray and Brittany Mahomes adequately disclosed the financial relationship between the influencers and the brand. At the outset, the NAD noted that: The FTC’s Endorsement Guides state that when there exists a connection between the endorser and the seller of the advertised product that might materially affect the weight or credibility of the endorsement, and that connection is not reasonably expected by the audience, such connection must be disclosed clearly and conspicuously. With that in mind, the NAD reviewed Instagram posts by Lana Del Ray that show her wearing Skims products, which either mentioned the brand by name or tag @skims in the caption of the post. The Brittany Mahomes’s posts feature her and her family wearing Skims products, but no specific mention of the brand in the caption of the post and while she tagged the brand in the picture, she did not tag @skimms in the caption. The NAD found that neither influencer had complied with the FTC Endorsement Guides. In reference to Lana Del Ray’s posts with the tag, the NAD stressed that: The FTC has further made it clear that tagging a brand you are wearing in a social media post is an endorsement of the brand. However, tagging a brand does not constitute a sufficient material connection disclosure, as an influencer could be tagging a brand simply because they like it and want their followers to be able to find it. The FTC makes it clear that just like any other endorsement, a social media post tagging a brand may require a material connection disclosure if the influencer has a relationship with that brand. As for Brittany Mahomes, the NAD put itself in the shoes of a reasonable consumer and found that even though the photos show the celebrity and her family with hair and makeup done, they are not so highly stylized that a consumer would understand them to be a paid advertisement campaign on direct viewing. Disclosures are still necessary. So we’ve told you what the influencers did and did not do (and you can see above how Brittany Mahomes corrected her post), but what about Skims? For their part, Skims followed three key practices that all brands should follows: Skims contractually required its influencers to comply with the Enforcement Guides. Skims provided its influencers with instructions on how to comply – suggesting the use of #ad and/or #sponsored Skims monitored their influencers and in the case of Lana Del Ray, contacted her team when they saw that she was not providing adequate disclosures. None of the three letter organizations that spend time on social media expect your brand’s influencers to be perfect, but the brand is ultimately responsible for its influencers’ behavior and engaging in these three best practices will go a long way to clearer and more conspicuous disclosures.
April 4, 2025
Trademarks
Compassion in Registration: A Lesson in Filing Narrow Trademark Applications
Identical trademarks can coexist, as the Trademark Trial and Appeal Board once again emphasized when it overturned the refusal of a COMPASSION IN ACTION mark. The Board’s decision is both a lesson in strategically narrowing an application’s services and a cautionary tale of how to build out the record for an appeal. Namchak Foundation filed an application for the mark COMPASSION IN ACTION in Class 45.[1] Namchak’s application originally covered “Religious and spiritual services, namely, providing gatherings and retreats to develop and enhance the spiritual lives of individuals.” However, Namchak narrowed its services further to “Religious and spiritual services, namely, providing gatherings and retreats to develop and enhance the spiritual lives of individuals interested in the teachings and practices of the Namchak Tibetan Buddhist Fellowship” (amendment in bold), after the trademark office initially refused its application. Despite Namchak’s efforts to narrow its application, the trademark office once again refused the application based on an alleged likelihood of confusion with The Salvation Army’s COMPASSION IN ACTION registration for “Religious and charitable services namely providing meals for indigent people, residential care for homeless men, gifts for elderly shut-ins, gifts for patients in hospitals, rest homes and infirmaries, gifts for imprisoned persons, and gift packages to members of the armed forces” in Class 42.[2] After several rounds of arguments and subsequent refusals, Namchak appealed the trademark office’s decision. The crux of the case, and the primary reason the Board disagreed with the trademark office, is the Board’s conclusion that there was no evidence suggesting Namchak’s and The Salvation Army’s services were related. The trademark office bears the burden of showing services are related. To meet this burden, the trademark office cited six websites allegedly showing other religious organizations providing both Namchak’s and The Salvation Army’s services. The Board, however, was not swayed by this evidence for two main reasons. First, the trademark office did not accurately interpret the parties’ services. Namchak deftly sidestepped potential unhelpful website evidence because it limited its description specifically to services for individuals interested in Namchak’s Buddhist fellowship. The trademark office incorrectly focused on the beginning of Namchak’s and The Salvation Army’s services description, without taking into account the descriptions as a whole. At best, the evidence showed Christian organizations holding gatherings and providing charitable services. But it did not show Buddhist religious gatherings, let alone those related to the Namchak Tibetan Buddhist Fellowship, and definitely not Buddhist organizations that also provide meals for indigent people, housing for homeless men, gifts for the elderly, or any of the other services provided by The Salvation Army. Second, the Board noted that pointing to only six websites is insufficient and does not meet the trademark office’s burden of proof. In other words, the trademark office should have cited more evidence in the various refusals issued prior to Namchak’s appeal. The Board acknowledged that a more developed record might have showed the parties’ services were related. The Board’s decision demonstrates that a strategically narrow description of goods/services can be enough to overcome a likelihood of confusion refusal. Namchak was particularly successful here because its narrow identification not only eliminated overlap between the parties’ services on their face, but also rendered the trademark office’s evidence moot. Ultimately, The Salvation Army and Namchak are both free to continue practicing COMPASSION IN ACTION without confusion on the trademark register. [1] The Board’s Final Decision, issued March 6, 2025 incorrectly indicated Namchak’s services were in Class 30. However, the Board issued a Notice of Correction on March 12, 2025, correcting this clerical error. [2] This was an ex parte proceeding. The Salvation Army did not oppose Namchak’s application or otherwise participate in the application’s examination or appeal.
March 26, 2025
Copyrights
Generative AI and the Copyright Office – Part 2 of Long-Awaited Guidance, But Will It Continue?
On January 29, the U.S. Copyright Office released Part 2 of its planned 3-part report on the legal and policy issues related to copyright and artificial intelligence (AI). Part 1 of the report, which was published in July 2024, addressed the topic of digital replicas. Part 2 now addresses issues related to the copyrightability of generative AI model outputs. The highly anticipated Part 3 is slated to address copyright infringement and fair use issues involving generative AI. Generative AI Models (Generally) Generative AI models are machine learning models that, when given an instruction or request (a prompt), can generate new content such as text, images, videos, and sounds. Prompts are often textual, but can be other input, such as images. These models learn the underlying patterns and structures of their training data and use them to produce new data based on the prompt. Examples include Meta’s Llama models, OpenAI’s ChatGPT models, and Google’s Imagen 3 model. The creation of prompts themselves has developed into its own category of computer technology—many in the field have begun using generative models to develop large amounts of prompts or to develop optimized prompts. Due to the rising use of these generative AI models, the Copyright Office is publishing guidance addressing issues of copyright law uniquely applicable to AI models. Historical Copyright Law Gives Some Guidance The Copyright Office began Part 2 of its report by explaining how copyright law has kept up with changes in technology, particularly with the inventions of photography, movies, and video games. As technology evolves, the Copyright Office and courts must decide to what extent technology can be involved in works of authorship that can still claim copyright protection. Because technology has always been permitted to be used in generating copyrighted works, the Copyright Office explained that there cannot be a bright-line rule “that registration will be denied merely because a computer may have been used in some manner in creating the work.” Instead, the analysis involves a case-specific sliding scale: “Where AI merely assists an author in the creative process, its use does not change the copyrightability of the output. At the other extreme, if content is entirely generated by AI, it cannot be protected by copyright.” As discussed by the TMCA in the past, the U.S. Supreme Court and the Copyright Office have long held that authorship requires the involvement of human creativity. The crucial question is “whether the ‘work’ is basically one of human authorship, with the computer [or other device] merely being an assisting instrument, or whether the traditional elements of authorship in the work (literary, artistic, or musical expression or elements of selection, arrangement, etc.) were actually conceived and executed not by man but by a machine.” U.S. Copyright Office, Report to the Librarian of Congress by the Register of Copyrights (1965). The Copyright Office also analogized the generative AI model issues to other topics already decided in the law. For example, cases involving commissioning works, where courts have analyzed what level of contribution is necessary to qualify as authorship, seem applicable. A person who merely describes to an author what the commissioned work should do or look like is not a joint author for purposes of the Copyright Act, because such contributions constitute unprotectible ideas. Likewise, a person who provides high-level guidance to a generative AI model would also have difficulty proving sole or co-authorship. Specific Examples Provided by the Copyright Office The Copyright Office offered a few examples to illustrate the boundaries of copyright protection for material produced (at least in part) by generative AI models. Prompts On one end of the spectrum, prompts alone do not provide sufficient human control to make users of an AI system the authors of the output. “Prompts essentially function as instructions that convey unprotectible ideas.” The Copyright Office provided its own generative example to illustrate its point: While this prompt is very descriptive, and the resulting image reflects some of the instructions, it does not reflect all of them (there is no “highly detailed wood”). The generative AI model also uses its own content to fill in gaps (the cat’s breed, clothes beneath the robe, human hands, etc.). The Copyright Office noted that identical prompts can generate multiple different outputs, which further underscores the lack of human control. This reality may change as technology evolves. “There may come a time when prompts can sufficiently control expressive elements in AI-generated outputs to reflect human authorship. If further advances in technology provide users with increased control over those expressive elements, a different conclusion may be called for.” But for now, the Copyright Office’s position is clear: prompts are not copyrightable. Expressive Inputs Expressive inputs are inputs of copyrighted works into generative AI models with instructions to modify those works. For example, a human author may create a drawing, input that work into an AI system, and instruct the system to modify color or scale. Or a user could upload a copyrighted story written in the first person point of view, and instruct the model to re-write the story from that of a third person. These inputs are different from prompts because they contribute more than just an intellectual idea. The Copyright Office again provided its own example: Here, the Copyright Office appears more inclined to provide protection, though that protection would not cover the entire output. Instead, “copyright in this type of AI-generated output would cover the perceptible human expression.” Modifying or Arranging AI-Generated Content Finally, the Copyright Office addressed situations where a generative model is used as an initial step, but the author further modifies the output. The Copyright Office noted that whether or not such modifications rise to the minimum standard of originality, that is, whether the work is the product of creative choices with respect to the selection of the images and/or text that make up the work and the placement and arrangement of the images and/or text on each of the work’s pages. The copyright would extend to the material the human author contributed but would not extend to the underlying AI-generated content itself. The inclusion of elements of AI-generated content in a larger human-authored work does not affect the copyrightability of the larger work as a whole. “For example, a film that includes AI-generated special effects or background artwork is copyrightable, even if the AI effects and artwork separately are not.” Key Takeaways The key takeaways from Part 2 of the report include how the Copyright Office interprets the human authorship requirement as it relates to the use of models. The Copyright Office explained that “[c]opyright protects the original expression in a work created by a human author, even if the work also includes AI-generated material,” but “[c]opyright does not extend to purely AI-generated material, or material where there is insufficient human control over the expressive elements.” Whether the human interaction with the generative AI model is sufficient to constitute authorship should be decided on a case-by case basis. In the words of the Copyright Office: “prompts do not alone provide sufficient control.”
March 19, 2025
Trademarks
John Wick Targets Jane Wick with Trademark Opposition
John Wick is a highly successful film franchise starring Keanu Reeves as a hitman who reluctantly emerges from retirement to avenge the killing of his pet beagle (among other offenses committed by a group of not-very-nice Russian gangsters). The first movie in the series came out in 2014 and was a surprise hit, grossing over $80 million at the box office. That initial success led to three sequels, a prequel TV series, and an upcoming spin-off film. John Wick is one of the rare franchises that has achieved greater success with each installment, and ticket sales for the series now exceed $1 billion. To capitalize on this remarkable success, the owner of the franchise, Summit Entertainment, LLC, registered the mark JOHN WICK with the U.S. trademark office for a host of goods and services, including movies, video games, accessories, and entertainment services. Summit has also licensed the right to use the JOHN WICK mark to others, including in connection with backpacks, T-shirts, mugs, and duffle bags. All appeared to be going well for the John Wick brand – until Jane Wick entered the scene. No, John did not get married; nor did an estranged older sister suddenly appear at John’s doorstep. Rather, in February 2024, a company called Jane Wick LLC filed a trademark application for the use of the mark JANE WICK in connection with ammunition bags, leather bags, and athletic apparel. Jane Wick aims to capture the women gun owner market – its vision is to “revolutionize women’s shooting by making it functional and beautiful.” It’s unclear if John Wick would think that a fancy leather bag can make shooting “functional and beautiful.” What we do know is that Summit, the franchise owner, is not at all happy about the use of the JANE WICK mark. In fact, last month Summit filed a Notice of Opposition with the Trademark Trial and Appeal Board, claiming that it would be damaged by issuance of a registration for the JANE WICK mark. The Opposition details the success of the JOHN WICK franchise, noting its total box offices revenues of over $1 billion, the list of awards the films have won, and Summit’s use, promotion, and licensing of the JOHN WICK mark. The Opposition also includes descriptions and photographs of JOHN WICK branded products, including backpacks, duffle bags, T-shirts, coffee cups, and figurines. The Opposition goes on to note that, in addition to common law rights in the JOHN WICK mark, Summit has three registered trademarks for the mark. Given there is no dispute about priority (the first John Wick movie came out ten years before Jane Wick filed her trademark application), the key issue here will be likelihood of confusion. The facts here would seem to be in Summit’s favor. JANE WICK uses the same last name as JOHN WICK, and it similarly uses the generic female name (i.e., Jane Doe). The fact that John Wick is a hitman – and there is a great deal of shooting in his movies – may also make confusion likely, as Jane Wick is not just selling bags – it’s selling ammunition bags. Hard to believe that the name Jane Wick was a completely random choice and not meant to relate in some way to John Wick, the renowned fictional gunman. Finally, while JOHN WICK is primarily a film franchise, the mark is also used with goods similar to Jane Wick’s products such as backpacks and clothing. All in all, Jane Wick may have an uphill battle. It’s too early to say how this will pan out. The parties presumably had communications prior to Summit’s filing of an Opposition but apparently weren’t able to resolve their differences. And if Summit succeeds in shooting down Jane Wick’s trademark application, would it be content or would it up the aggression and sue Jane Wick for trademark infringement? John Wick didn’t go out looking for a fight but he wasn’t one to back down either. It looks like the same can be said for the film franchise’s owner.
March 14, 2025
Copyrights
What Makes an AI Generated Work “Original”?
The emergence of generative artificial intelligence (AI) products in the past couple of years has significantly increased the capacity for individuals, businesses, and organisations to utilise AI to produce a wide range of content at great speed and low cost for personal, professional, and business purposes. ChatGPT, DALL-E, Midjourney, Claude, and Grok are a small number of prominent generative AI tools that are increasingly being used by business and the general public in an ever-growing range of use cases, producing literature, music, images, and art. The rapid rise of generative AI has drawn attention to a number of copyright issues, including the question of copyright protection for content generated by those tools. In the United Kingdom, a provision of the Copyright, Designs and Patents Act 1988 (CDPA) (section 9(3)), part of a broader set of rules regarding the authorship of different categories of works) provides that “in the case of a literary, dramatic, musical or artistic work which is computer-generated, the author shall be taken to be the person by whom the arrangements necessary for the creation of the work are undertaken”. On its face, s. 9(3) appears to proceed on the basis that copyright ought to subsist in literary, dramatic, musical, and artistic works which are created by a computer, which would seem to include works created by generative AI. In fact, Parliamentary records (Hansard) indicate that the proponents of the CDPA, which was enacted in 1988, “[believed] this to be the first copyright legislation anywhere in the world which attempts to deal specifically with the advent of artificial intelligence.” The legislature, therefore, envisaged that literary, dramatic, musical, or artistic works may be generated by computers – indeed by “artificial intelligence” – and it specifically provides that the authorship of such works should be attributed – as a matter of law – to the person making the arrangements for the creation of the work. There may be a question in specific cases which person exactly should be identified as the person who made those ‘arrangements,’ but the principle seems clear that the question of authorship itself does not come into question merely because a work is computer-generated. However, the correct legal effect of s. 9(3) CDPA has increasingly been drawn into question, particularly in view of a significant shift that took place in the past few years in the understanding of the concept of originality under the law. Changes in the concept of originality in UK copyright law Under the CDPA, copyright subsists in the following types of works: original literary, dramatic, musical or artistic works; sound recordings, films or broadcasts, and the typographical arrangement of published editions. Authorship and originality are two related concepts. Under the CDPA, literary, dramatic, musical, and artistic works (sometimes known as “authorial works”) require originality to attract copyright protection. Under Section 9 of the CDPA, with the exception of computer-generated works, the author of such works is their creator. With regard to the types of works that do not require originality to enjoy copyright protection (sound recordings, films or broadcasts, and typographical arrangements), other provisions were made in s. 9 attributing authorship to persons by reference to their responsibilities in relation to the generation of the work (for example, the authors of a film are deemed to be the producer and principal director and the author of a sound recording is its producer). However, the rule under s. 9(3) is the only rule of deemed authorship that applies to types of works which are protected in copyright subject to a requirement of originality. This raises the question of how deemed authorship can be reconciled with originality. The context in which this question falls has changed significantly in the past few years, not necessarily as a result of technological developments, but rather due to legal ones. At the time the CDPA was enacted, and until recently, the test for originality under English law was the ‘skill and labour’ test which considers whether a sufficient degree of skill, knowledge, mental labour, taste, or judgement were expended by the author in creating the work. The traditional rule required only a minimal degree of skill and labour (more than an insubstantial amount). Under this test of originality, the English courts had historically been able to recognise originality in works that were generated in circumstances where there was no human author (for example, in Nova Productions Ltd v Mazooma Games Ltd [2006] EWHC 24 (Ch) the Court accepted the subsistence of copyright in artistic images produced by a computer game in the course of play). However, since the decision in 2010 of the European Court of Justice’s in Infopaq International A/S v Danske Dagblades Forening (Case C-5/08) EU:C:2009:465, the question has been debated in a number of subsequent cases by the English courts, and it has now been established by the Court of Appeal in its decision in THJ Systems Ltd v Sheridan [2023] EWCA Civ 1354 that the traditional common law test for originality in copyright is no longer applicable. Through its interpretation of EU copyright legislation, the Infopaq decision adopted a uniform test of originality which defines an original work as one which is “the author’s own intellectual creation.” Although the UK (following its withdrawal from the EU) is no longer subject to the jurisdiction of the EU courts, the Court of Appeal in THJ Systems treated the EU test of originality as a test that had already been incorporated into UK law before Brexit through past cases that applied the Infopaq test. As summarised by the Court of Appeal in THJ Systems, the test of originality of the “author’s own intellectual creation” considers at its core whether “the author was able to express their creative abilities in the production of the work by making free and creative choices so as to stamp the work created with their personal touch.” This test is widely considered to set a higher standard than the traditional common law ‘skill and labour’ test. Although the Court of Appeal emphasises that the EU test is an objective one and not one of “artistic merit” and the court will not seek to assess the artistic quality of the work, it is still more than the minimalistic test previously applied by the English courts. The work must be an expression of the author’s creativity, choice, or judgment. Can a computer generated work meet the test of originality of the “author’s own intellectual creation?” Computers (including so called “artificial intelligence” software) do not possess an intellect and the works generated by AI do not express the “intellectual creative choices” of the software. In fact, the process by which AI generated content is produced is as far removed as possible from the idea of an intellectual creation. However, this does not necessarily mean that works created by AI cannot meet the originality test of the “author’s intellectual creation.” The aforementioned THJ Systems case, although it did not deal with an AI-generated work, can provide some guidance. The dispute concerned “risk and price charts” that were generated by a business software application. The case focused on the authorship (which dictated the ownership) of the works generated through the use of the software, although the question of subsistence of copyright was also considered. The claimant, the creator of the software, argued that the outputs it generates where his copyright works. The defendant denied there was copyright in the charts and argued that if there was, then under s. 9(3) CDPR, authorship ought to be attributed to the user of the software, the defendant, not to the software developer. At trial it was established that the graphical works in which the claimant claimed rights protected by copyright and which were reproduced by the software every time it was used were created by the claimant in developing the software. Although the user’s use of the software resulted in different figures being populated in the charts, those figures were not the copyrighted work in question, but rather it was the structure of the charts and other design elements displayed on the screens that attracted copyright and those were not the result of any choice or action taken by the user. On the question of the subsistence of copyright, the Court of Appeal held that the trial court misapplied the law by considering the matter against the now-discarded “skill and labour” test, rather than the Infopaq test of the “author’s own intellectual creation”. However, the Court of Appeal did not interfere with the trial court’s conclusion that there was sufficient originality in the structure and arrangements of the charts to justify copyright protection. Instead, the functionality of the software was held to be irrelevant to the question of originality. The enquiry concerned the visual appearance of the graphical works. Even though the charts were generated by the software each time it was used, the Court found that they were carefully arranged by the software designer who applied judgment and choice to achieve a certain visual result. It was not suggested that the particular way in which the charts were organised was dictated by technical requirements such that would exclude a finding of originality and copyright protection. The Court held that the degree of originality was clearly low (with the result being that only an identical copy could amount to an infringement) but the resulting artistic work was still the expression of the author’s (that is, the human software designer’s) intellectual creation and choices and that the works were sufficiently stamped with his personal touch, so that they can attract copyright protection. Accordingly, a graphical work can be at the same time a computer-generated work for the purpose of s. 9(3) CDPA whilst originality can be assessed by reference to the work carried out by the human designer who was responsible for making the relevant choices or judgments which resulted in the work being created (by the computer) in a certain way. The analysis with regard to AI-generated works could proceed along very similar lines. Although the charts in the THJ Systems case were directly arranged by a human developer (and not automatically by an AI), the Court of Appeal emphasised that the functionality of the software does not matter and, at least with regard to artistic works, a key element of evidence as to originality is the work itself. If a graphical work is generated through an AI tool and looks, on its face, like an original artistic work, a court would look at the creative choices and judgments made by the user (the author) and the extent to which the work reflects those choices and whether it is stamped by the author’s personal touch. It should not matter in principle that the graphical output itself is generated automatically by the software. It should not be a determinative factor whether the user applied any brushwork or drew any lines (virtual or otherwise). It would seem contrary to the intention of Parliament in enacting s. 9(3) CDPA to exclude copyright in an artistic work purely because it was generated by a computer. As long as it can be demonstrated that a human author has made sufficient free creative choices or applied sufficient judgment so that the resulting work expresses his own “intellectual creativity,” that should be sufficient for finding originality in the work. But the decision in the THJ Systems case leaves important questions unresolved. The question can be taken to the extreme, such as in the case of a work that is generated by AI with minimal user input. Here, a court might find insufficient authorship to amount to ‘creative choices or judgments’ or making the work a reflection of the author’s “own intellectual creation” – for instance an image produced by an AI tool based on the instructions: “flowers in a vase; natural style; green, red, yellow.” It would be difficult to argue that such banal instructions amount to creative choices that make the resulting work a reflection of the user’s creative free choices and judgment. But given the provision of s. 9(3) CDPA – which suggests that copyright should not be denied from an authorial work merely because it is computer-generated, perhaps in such a case authorship of the resulting work should be attributed (as in the THJ Systems case) to the designer of the software tool, rather than the user, and the creative choices and judgment can be said to have been those made by the developers who trained and developed the AI tool. After all, without their work the computer-generated image could not have been created. As long as the image is not a copy of images that were used to train the AI, perhaps it is the creative efforts of the software developers that should justify protecting the resulting image in copyright? On the other hand, can it seriously be argued that the unlimited number of different images that an AI image-generating tool can produce are all the reflection of the software developers’ creative choices and judgment? Can it be said that all such works (as long as they are not sufficiently moulded and individualised by the user of the tool) are stamped with the “personal touch” of the software developers? It seems doubtful. It is perhaps more likely that courts in the UK would take the approach that s. 9(3) CDPA does not mean that all computer-generated works must necessarily attract copyright. It is still necessary to show in each case that the work is original in the sense that it reflects its author’s free creativity and intellectual choice and judgments – whether that author is the user of the software or its creator. That would be a highly factual investigation and may depend on the nature of the AI tool, how it was developed, what it does, and the way it was used by humans to generate a particular output. Potential legislative reform The UK Government is currently conducting a public consultation on copyright issues related to AI. One issue under consideration is the special rule of authorship for computer-generated works. The consultation paper invites feedback from the public and relevant stakeholders, but also expresses an initial view that it may be preferable to abolish section 9(3) CDPA on the basis that the provision creates more uncertainty than it resolves. In forming that initial view, the Government took note of the fact that other major legal systems such as the European Union and the United States did not adopt a similar rule of deemed authorship regarding computer-generated works. The Government’s view (which is not binding on the courts) is that even without the special statutory rule of authorship under s. 9(3) CDPA, literary, musical, artistic, and dramatic works which are computer-generated but which exhibit human creativity (that is, works created by humans with the assistance of AI tools) would be protected in copyright on the basis of the general rule of originality. It is also noted that computer-generated films, videos, sound recordings, and broadcasts will enjoy copyright protection in any event since the requirement of originality does not apply to those types of works. It is yet to be seen if s. 9(3) CDPA is to be abolished or if any further clarifications might be made in legislation regarding the copyright protection of AI-generated works. As long as the law remains unchanged, courts are likely to consider each case on its facts with a focus on the degree of individual creativity that contributed to the creation of each work.
March 7, 2025
Trademarks
SCOTUS Holds Affiliate Profits Not Available Under One Lanham Act Provision, But Leaves Door Open for Other Theories
The United States Supreme Court issued a unanimous decision in Dewberry Group, Inc. v. Dewberry Engineers Inc., vacating a nearly $43 million profits award and remanding the case for further consideration. The Court concluded that the Lanham Act’s provision allowing plaintiffs to “recover [a] defendant’s profits” did not permit the lower courts to include profits generated by Dewberry Group’s affiliate entities that were not parties to the case. Under the plain statutory language, those profits are limited to named defendants. The Court declined to consider, but did not rule out, alternate theories supporting the award, including the Lanham Act’s “just-sum” provision and corporate veil-piercing, leaving the door open to those theories on remand. Rather unsurprisingly, the roots of this case stem from the parties’ use of the name DEWBERRY. The parties reached a settlement in 2007 governing use of the name in the real estate sector, but things took a turn in 2017 after Dewberry Group rebranded in a way that Dewberry Engineers contends violated the agreement and infringed its rights in various DEWBERRY-formative marks. Dewberry Engineers sued and ultimately prevailed. While calculating damages, Dewberry Group argued that no disgorgement of profits was appropriate because it operated at a loss for decades. Dewberry Engineers, on the other hand, argued successfully that the profits generated by Dewberry Group’s affiliated entities should form the basis of a profits award since the entities were all owned by the same person and serviced one another. For example, Dewberry Group provides various financial accounting, human resources, and legal services to its affiliated sister entities, which in turn leased commercial property to commercial tenants for a profit. The district court totaled the profits from all of these affiliated entities, producing an award of nearly $43 million. The Fourth Circuit agreed and affirmed the district court’s award. In defending the award before the Supreme Court, Dewberry Engineers effectively abandoned the theory that the award could be supported by the Lanham Act’s profits provision and instead contended the award was proper under the Lanham Act’s just-sum provision (which permits a court to adjust a recovery if found to be inadequate or excessive) and corporate veil-piercing theories. As foreshadowed by the tenor of oral arguments, the Court easily concluded that profits under the Lanham Act are limited solely to those generated by named defendants in a case and that “affiliates’ profits are not . . . statutorily disgorgable.” Because Dewberry Group’s affiliates were not named defendants, Dewberry Engineers could not access those affiliates’ profits under the Lanham Act’s profits provision. The Court also declined to consider Dewberry Engineers’ alternate arguments based on the Lanham Act’s “just-sum” provision and corporate veil-piercing theories because they were not raised or considered below, sending the case back for further consideration on these points. The Lanham Act’s just-sum provision permits courts to “enter judgment for such sum as the court shall find to be just. . . [i]f the court shall find that the amount of the recovery based on profits is either inadequate or excessive.” 15 U.S.C §1117(a). Dewberry Engineers contended the district court properly followed a two-step process to support the award under this theory: first, the court assessed the adequacy of the award and then, second, considered relevant evidence in order to adjust the award. The Court disagreed, concluding that the district court never relied on the just-sum provision or engaged in any two-step process. Rather, the district court simply calculated the defendant’s profits by including profits attributed to affiliate entities. The Court’s opinion closes with a detailed discussion of what it does not decide, leaving much for the lower courts to consider on remand. First, it expresses no view on the applicability of the just-sum provision; it merely concludes that it was not properly invoked. Second, the Court does not take any view on the Government’s amicus position regarding when courts can “look behind a defendant’s tax or accounting records” to identify “true financial gain.” Finally, the Court has no opinion whether corporate veil-piercing theories may be considered on remand. In her concurring opinion, Justice Sotomayor writes separately to “underscore that principles of corporate separateness do not blind courts to economic realities.” She provided examples in which a defendant’s profits under the Lanham Act could properly include revenues assigned to an affiliate or diverted through anticipatory assignment schemes to an affiliate, or indirect compensation from the infringing activities of affiliates. She also notes that, on remand, the courts below “may explore that important issue and consider reopening the record if appropriate,” perhaps nudging the courts to delve into these issues. So, with one theory for damages eliminated, this nearly 20-year legal battle trudges on with many questions left unanswered. The TMCA will continue to track the case as it winds its way back through the courts.
February 26, 2025
Trademarks
From the Gold Coast to the Golden State: A Trademark Battle Over Cozy Boots
A long legal battle over the right to use the “UGG” mark may result in the end of a company’s right to the word “UGG” in connection with sheepskin shoes and accessories outside of Oceania. The brand “UGG Since 1974” has agreed to only use the wording “Since 1974” when selling their products outside of Australia and New Zealand after being locked in a legal battle with Deckers Outdoor Corporation, which owns the U.S. brand “UGG Australia” for boots. As the name suggests, UGG Since 1974 in an Australian-based company that has been selling ugg-style boots since 1974. In Australia, “ugg” refers to a type of sheepskin and leather boot, so coined for their “ugly” appearance. However, they became popular in the 1960s and 1970s when they emerged as the favorite footwear of the surfing community. The style eventually traveled from the Gold Coast of Australia to the Golden State of California. Brian Smith, an Australian surfer, was the first to trademark the term “UGG” in connection with sheepskin boots in the U.S., and eventually sold his U.S. business along with the trademark rights gained to Deckers Outdoor Corporation in 1995. The “UGG Since 1974” brand predates the adoption of the U.S. mark, at least in Australia and New Zealand. However, given the generic connotation of the mark in Australia, the UGG Since 1974 entity did not seek trademark filing protection in Australia until 2010, and never filed applications for registration in other countries beyond Oceania, despite shipping their products internationally. Meanwhile, the American UGG brand now owns trademark registrations for UGG-related marks in 130 countries. Although the two competing UGG brands have been engaged in a legal battle for many years now, Deckers Outdoor Corporation filed a new lawsuit in April 2024 against Wolverine Group Pty Ltd before the U.S. District Court for the Northern District of Illinois Eastern Division for trademark infringement and infringement of their design patents based on the identical names and similar logos, and similar style boots of the two entities. Deckers Outdoor’s UGG boot source: www.ugg.com Since 1974 Ugg boot source: www.uggsince1974.com.au The Australia owner of UGG Since 1974 announced in this TikTok video on January 13, 2025 that they are done fighting the lawsuit and have agreed to change all branding of their products that are shipped outside of Australia and New Zealand. The new branding will feature the mark “SINCE 1974” only and have no reference to “UGG” on their packaging. The company also has the following disclaimer on their website: “UGG Since 1974™ has no affiliation with UGG®. Our boots are made in Australia, from 100% genuine sheepskin. For customers shopping outside Australia and New Zealand, your products will be labelled Since 74™ given trademark issues.” It appears that the Australian brand has changed some, but not all of their social media outlets to also reflect this brand change to SINCE 1974. However, despite the Since 1974 owner’s announcement on TikTok, Deckers Outdoor filed a Second Amended Complaint on February 13, 2025, with some amendments to address the attention the “UGG” trademark is receiving on social media, including from the above mentioned TikTok video. It will be interesting to see how the rest of the dispute unfolds. The dispute highlights the importance of filing for foreign trademark protection where businesses plan to ship their products internationally as well as the benefits of creating an international strategy for trademarks. While marks may be considered generic or refused in certain jurisdictions, including in an entity’s domicile or home base, these refusals may not extend to all jurisdictions and foreign rights should be considered carefully.
February 25, 2025
Regulatory Compliance
Artificial Intelligence Launching Agentic AI in an Uncertain U.S. Regulatory Landscape
Are you ready to begin adding AI Agents to your human teams? You will soon be getting requests to do so. While business teams will be wowed by what AI Agents and their subagents can do, the artificial intelligence regulatory environment is increasingly uncertain, and we advise caution. Within its first few days, the new administration revoked the 2023 Executive Order on Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (the “Old AI Executive Order”) – which had been intended to mitigate risks associated with AI technologies by imposing safety guidelines such as a watermarking system for AI-generated content. Next, the president issued a new executive order Removing Barriers to American Leadership in Artificial Intelligence (the “New AI Executive Order”), providing White House staff 180 days to develop a plan “to sustain and enhance America’s global AI dominance in order to promote human flourishing, economic competitiveness, and national security.” Under the New AI Executive Order, federal agencies are required to immediately review and suspend, revise, or rescind any prior governance and safety measures undertaken to comply with the Old AI Executive Order that are not consistent with the New AI Executive Order. Meanwhile, on January 21, the president announced a new $500 billion private sector deal, “The Stargate Project,” which is a new joint venture that relies on SoftBank, OpenAI, Oracle, and MGX as initial equity funders in a bid to rapidly expand U.S. AI infrastructure by building massive new data centers, first in Texas then in other potential sites across the country. In the same week, leading big tech companies including Oracle and OpenAI each announced the next phase of the AI revolution with the release of new AI Agents designed to autonomously handle specific tasks and ultimately “join the workforce and materially change the output of companies.” What Are AI Agents? While traditional AI chatbots using large language models (“LLMs”) are designed to respond to users within the AI system, the latest generation of advanced AI Agents (aka AI Super-Agents or Agentic AI) are now empowered to interact with computer, network, and internet environments to automate tasks. Open AI states that its new AI Agent, Operator, “can be asked to handle a wide variety of repetitive browser tasks such as filling out forms, ordering groceries, and even creating memes.” Accordingly, Operator “can ‘see’ (through screenshots) and ‘interact’ (using all the actions a mouse and keyboard allow) with a browser, enabling it to take action on the web without requiring custom API integrations.” By combining the power of LLMs with new technologies such as the Oracle Cloud Infrastructure and retrieval-augmented generation, Oracle’s AI Agents can interact with enterprise data and can apparently be used by companies to recruit qualified job candidates, perform complex customer data analytics, optimize call centers, and expedite legal, financial, and academic research tasks. AI Agents can be trained or instructed to follow the values of a user or business. Whether that can be consistently implemented remains to be seen. In testing, some AI systems have been shown to engage in “scheming” where they change results or take unexpected actions toward an ultimate goal set by the user. Although the usefulness of these technologies is undeniable, companies looking to deploy AI Agents should be aware of the legal risks and pitfalls that may accompany the use of these revolutionary new tools. Legal Challenges and Mitigation Strategies AI Agency Liability. In July 2024, a California district court allowed a case against HR and finance platform Workday to proceed, stating that an employer’s use of Workday’s AI-powered HR-screening algorithm may create direct liability for both the employer and Workday under the theory of agency liability. In this hiring discrimination case, the plaintiff alleged that his prospective employer delegated “traditional hiring functions, including rejecting applicants, to the algorithmic decision-making tools provided by Workday.” The court found that by designing an AI technology to make decisions that would normally be made by a live employee, Workday should be treated as an agent of the employer for purposes of liability so long as the employer actually relied on the AI technology in its hiring process. While this case is still making its way through the courts, AI Agent vendors and deployers could subsequently be exposed to both civil and criminal liability based on the actions of the AI Agent, a theory that had previously only been applied by the courts to the actions of live humans. AI Product Liability. Given the increased responsibility and autonomy being granted to AI Agents, it is possible that developers and deployers of AI Agents could also be required to contend with product liability claims. Manufacturers and sellers can be held responsible for injuries caused by defective or unreasonably dangerous products. If an AI Agent makes a poor and costly decision, a plaintiff may claim that the AI Agent was defectively designed and/or that the developer failed to adequately warn the plaintiff of the AI Agent’s limitations. This theory of liability is currently being tested in cases against AI-chatbot platform Character.AI. In the fall of 2024, the mother of a deceased minor in Florida brought a product liability case against the developers of Character.AI – an AI-chatbot role-playing platform that allows users to create and converse with AI-powered characters – alleging that her son died by suicide after becoming harmfully dependent on his relationship with his Character.AI companion “Dany.” In December, parents in Texas brought additional product liability claims, stating that, without warning, Character.AI chatbots exposed their children to hypersexualized content, self-harm, and violent behaviors, with one chatbot allegedly encouraging a child to kill his parents when they tried to limit his screen time. AI Contractual Considerations. Businesses seeking to onboard AI Agents should implement clear contractual provisions to allocate and manage risk. When reviewing warranties, limitations of liability, and indemnification clauses, companies should want to know if and to what extent the AI Agent vendor will indemnify the company for an AI Agent’s decision making, especially if those decisions are illegal or cause harm to end-users or others. Businesses should also consider who is responsible for training employees to use AI Agents safely and whether that training relates to the AI provider’s contractual liability. In addition to requiring compliance with emerging state and international AI regulations such as the Colorado AI Act and the EU AI Act, companies should also carefully contemplate intellectual property (“IP”) and data ownership, rules for algorithmic training inputs, and customization of standard liability shifting terms. Whereas typical software-as-a-service contracts usually address ownership of software and/or underlying data, AI Agent vendor contracts should also address IP-ownership of AI-generated content such as images, text, and even new software. Regarding algorithmic training inputs, companies must decide whether the AI Agent’s algorithm can train on company data, and if so, how such company data must be protected and stored. In addition, businesses should be wary of AI Agents violating third party terms of service which may prohibit access and use by bots. In non-negotiated use of Agentic AI, such as when a company deploys an off-the-shelf AI Agent from one of the major providers, companies should similarly review the provisions outlined above and weigh the ultimate risk of deploying this novel technology. AI Privacy and Cybersecurity Considerations. Using an AI Agent may result in the processing of enormous amounts of personal information as defined by state, federal, and international data privacy laws. For example, AI Agents designed to read and prepare automated responses to emails may digest any personal information contained in a user’s inbox, while an AI Agent designed to make investment decisions will process sensitive financial information about the user. By collecting such large amounts of personal information, companies may grow their cybersecurity attack target, as bad actors are typically attracted to companies known to collect large amounts of detailed and/or sensitive personal information. Furthermore, by deploying an AI Agent, a company in scope for comprehensive state privacy laws, such as the California Consumer Privacy Act, may be required to offer consumers the opportunity to opt-out of the AI-Agent’s automated decision making, while also disclosing to its consumers how their personal information is collected and used by the AI Agent, including whether their personal information subsequently trains the AI Agent’s algorithm. AI Agents that are not adequately directed and supervised could also perpetrate scams, develop vulnerable software code, or cause cybersecurity incidents, so human supervision and real-time monitoring will be essential to reduce legal risk, especially with initial uses of AI Agents. With the launch of AI Agents, concerns about AI scheming have become immediate. Adding AI Agents to your teams may have serious, unintended consequences and should involve significant testing and implementation of controls prior to and during use. Businesses will soon be training AI Agents in their corporate values and adding AI Agents to their teams. The way we work will never be the same.
February 11, 2025
Licensing
Repping Your School and How the Penn State Decision Ties In
School merch is big business. Students want sweats, mugs and the like to show they belong at the school. Alums want merch to show they went to the school. Other purchasers want merch as an aspirational statement, or to support the idea of the institution. Great demand naturally begets supply. Schools want to monopolize the market and have built substantial licensing businesses on having strong trademark rights. But recent business models have challenged such models, questioning whether all uses of school names and logos have to be licensed. Vintage Brand is one such business. It offers clothing and other merchandise featuring retro and current school names and logos without licenses. Vintage Brand staked its business on the belief that consumers buy the products to show support of the school, not because they believe the school has approved of the product. Vintage Brand has long defended its model on the basis that (1) many of the names and logos it uses are no longer protected as trademarks, (2) it uses protected marks for decoration, not to identify a source, and (3) it employs disclaimers to make clear the schools have not licensed the products. Unsurprisingly, schools disagreed. More than a dozen universities have filed infringement cases against Vintage Brand. Recall that to function as a trademark, a word, phrase, design or the like must function as a “source identifier.” That is, the mark must identify a source and differentiate the source from competitors. The purpose of requiring that a mark be a source identifier is to protect consumers who rely on the mark as shorthand for the quality of the goods. Words, and designs on a product that serve merely as decoration are not protectable as trademarks. But source identification and decoration are not mutually exclusive. A word or design can be both. A sweatshirt may feature a lion to make the shirt more attractive, the lion may also be a mascot of a school or team and used to identify the school and because the lion is decorative. Courts and experts have differed as to how to parse out what the function of a symbol is, as demonstrated in two recent cases involving Vintage Brand. In 2023, U.S. District Judge Alan Albright granted Baylor University’s summary judgment motion against Vintage Brand with regard to trademark infringement. The finding rested on use of a “per se” test that if consumers associate use of a school’s symbols with the institution, then unauthorized use of such marks is infringing. The parties subsequently entered a Consent Judgment that permanently enjoined Vintage Brand from using Baylor’s marks. In contrast, U.S. District Judge Matthew Brann, in a case brought by Penn State against Vintage Brand, rejected the per se approach, finding a mere mental association between a symbol and a trademark holder insufficient for infringement. Instead, Judge Brann required a fact-intensive inquiry into whether consumers “believe that the trademark indicates that the trademark holder is the source, sponsor, or is otherwise affiliated with the good.” Judge Brann reflected on other cases, and many experts, who believe disclaimers and prominent branding by the seller of the goods can be sufficient for consumers to understand the trademark owner was not the source of the goods. Additionally, Judge Brann questioned whether consumer confusion arose from consumer’s incorrect belief that goods bearing a school’s symbols must be licensed. He indicated data shows support for the belief but pondered if the misconception should be corrected. It is unclear if the reason for the confusion matters. Trademark law does not require consumers understand the legal basis for confusion as to source, only that it be likely. One also wonders how requiring jurors, who are average consumers after all, to engage in extensive fact finding would work to correct any misconceptions as to why they believed confusion was likely. In instructing the jury, Judge Brann did not directly attempt to correct any misconception that all use of a mark must be licensed. He initially explained that confusion as to “affiliation” is sufficient for infringement. Expounding on that, he repeated that the core question of confusion was whether “consumers will be confused as to whether Penn State manufactured, sponsored, or approved Vintage Brand’s goods.” If consumers believe a trademark owner must approve all use of its marks, then the answer seems a foregone conclusion. If so, the “per se” approach seems the far more efficient approach. In answering the question in Penn State, the jury unanimously rejected Vintage Brand’s defenses and found it willfully infringed Penn State’s marks. The verdict sends a clear message that the jury believed Vintage Brand’s goods were made, approved or sponsored by Penn State and that Vintage Brand intended to cause such confusion. The jury awarded Penn State $28,000 in compensatory damages based on Vintage Brand’s sales of 1,269 products bearing Penn State marks, its revenue of approximately $23,000 and the 10% royalty rate Penn State’s licensees typically pay to use the Penn State marks for similar merchandise. Since the verdict, Penn State has filed motions requesting a permanent injunction to halt Vintage Brand’s use and sale of any products with Penn State trademarks and to request attorneys’ fees on the basis that the case was sufficiently exceptional under the Lanham Act (15 U.S.C. Section 1117(a)). Vintage Brand has opposed both motions and indicated it will appeal the decision. Despite the alternative approaches used by the judges, both cases appear to have reached the same conclusion: consumers expect some authorized relationship between the mark’s owner and the seller. Further, the Penn State jury’s willfulness finding indicates that disclaimers are not only insufficient to prevent consumer confusion, but do not mitigate a defendant’s intent to deceive. While neither case is precedential, the decisions send a clear warning that unauthorized use of trademarks is done at great peril, particularly in university and sports markets. We will stay tuned to see if any of the findings change on appeal.
February 5, 2025
Trademarks
Jack Daniel's Remand, Part I: Why Did the Trial Court Give "Little Weight" to a Consumer Survey Showing 29% Confusion?, Op. 1, No. 45
This post was originally published on the Lanham Act Surveys for Lawyers newsletter. Seven years ago today, Jack Daniel's was no doubt riding high. The U.S. District Court for the District of Arizona gave Jack a big shot in the arm with a trademark infringement and dilution victory over Bad Spaniel's mimicry: VIP Prods., LLC v. Jack Daniel's Props, 291 F. Supp. 3d 891, 907 (D. Ariz. 2018). One of the key pieces of evidence relied upon by the trial court was a consumer survey showing 29% of potential purchasers were "likely to be confused" by Bad Spaniels. Id. In fact, the court gave that survey evidence "prevailing weight" and found trademark infringement in favor of Old. No. 7. Id. Fast forward to just last week. After two stints at the Ninth Circuit and one big trip at the Supreme Court, Jack Daniel's and Bad Spaniel's were back before the trial court on remand. This time, though, the trial court gave the survey evidence "little weight" and rejected Jack Daniel's trademark infringement claim (but not its dilution claim). VIP Prods. LLC v. Jack Daniel's Props. Inc, No. CV-14-02057-PHX-SMM, 2025 U.S. Dist. LEXIS 11866, at *75 (D. Ariz. Jan. 21, 2025). Exact same judge. Exact same survey. Exact opposite conclusion seven years later. Was this some sort of judicial variant of the seven year itch? Not exactly. The answer for the trial court's change of heart is this: Justice Sotomayor's concurring opinion back when this trademark tussle was before the U.S. Supreme Court two years ago. As you may recall, Justice Sotomayor wrote a concurring opinion to address Jack Daniel's consumer survey evidence presented at trial. Jack Daniel's Props. v. VIP Prods. LLC, 599 U.S. 140, 164 (2023). She opined that, "[s]urvey answers may reflect a mistaken belief among some survey respondents that all parodies require permission from the owner of the parodied mark." Id. She observed that some of the answers to the survey in this case apparently illustrated this "potential." Id. (citing two survey respondent answers stating, "I’m sure the dog toy company that made this toy had to get [Jack Daniel’s] permission" and "[t]he bottle is mimicked after the Jack Daniel BBQ sauce. So they would hold the patent therefore you would have to ask permission to use the image”). She then expressed this concern: Allowing such survey results to drive the infringement analysis would risk silencing a great many parodies. Well-heeled brands with the resources to commission surveys would be handed an effective veto over mockery. Id. at 164. On remand, the trial court acknowledged Justice Sotomayor's concerns, and found them persuasive. VIP Prods. LLC, 2025 U.S. Dist. LEXIS 11866, * 74. As a result, the trial court concluded that because this same survey "may not have accounted for the fact that 'Bad Spaniels' is a parody," it received "little weight." Are the concerns expressed by Justice Sotomayor and the trial court justified? There are some pretty compelling legal and factual arguments that the answer is "no." We will address those in our next issue, Jack Daniel's Remand, Part II. Stay tuned! Here you will find: the trial court's original decision, Justice Sotomayor's concurrence, and the trial court's decision on remand.
February 3, 2025
Regulatory Compliance
Canada: Updates on Language Requirements for Trademarks in Quebec and Cancellation Pilot Project for Trademark Registrations
Our friendly neighbors in the Great White North are implementing important changes in 2025 with respect to language requirements for trademarks and a new pilot project initiated by the Canadian Intellectual Property Office (“CIPO”) to issue cancellation proceedings against trademark registrations based upon non-use. Language Requirements In connection with the Charter of the French Language, the Quebec government has published the final regulation for Bill 96, the details of the initial draft for which are discussed in our prior post. This final regulation, released on June 26, 2024, lightens the requirements with respect to trademark registration, gives more guidance with respect to definitions of wording, and maintains requirements for signs and sizing. The important takeaways are listed here: The earlier draft limited an exception for using a non-French trademark on products to allow only registered trademarks to appear on a product exclusively in a language other than French. This has now been expanded to include “recognized marks,” meaning registered or unregistered (common law) trademarks may appear on products without a French translation (so long as there is not a French version registered at the Canadian Intellectual Property Office). Clarification has been provided with respect to product descriptions and generic terms. The use of any generic term or product description included with a trademark must be translated into French and permanently displayed on product packaging or on the product itself. a “generic term” is the wording used to describe the nature of a product; a “product description” is the wording used to describe the characteristics of a product. A grace period had been identified to allow for the sale of non-compliant products made before June 1, 2025, to be sold until June 1, 2027. The grace period has been extended also to include products made between June 1, 2025, and December 31, 2025, that were impacted by new federal labeling standards (Food, Drug and Cannabis Regulations). With respect to public signs, posters, and commercial advertising, previously the draft regulation made an exception for only registered trademarks to be used in a language other than French on public signs, posters, and commercial advertising. The final regulation now includes an exception for “recognized marks,” which will allow for both registered and unregistered trademarks to appear on public signs, posters and commercial advertising exclusively in a language other than French. “Marked Predominance” of French on signs visible from the exterior of commercial premises remains in place. The French text on an exterior sign should be twice the size of text that appears in any language other than French. However, it must also have a greater visual impact than the text in another language. That requirement is met if the section of the sign for the French text is at least twice the size of the space for the text in another language, and the legibility and permanent visibility of the French text is equivalent to the text in another language. This amendment gives greater flexibility to business owners in the creation of their signage, based on total area in which the text appears rather than making the French text twice the size of the text in another language. (For dynamic signs, the impact of the French language is considered greater if it will be visible twice as long as any text appearing in another language.) There remains a reasonable period of time to come into compliance. These requirements should be taken seriously, as businesses operating in Quebec face penalties and daily penalties for ongoing offenses, which can be directed at both corporations and their directors individually. Cancellation of Trademark Registrations CIPO has introduced a new pilot project, which started this month (January 2025). On a monthly basis, the Registrar of Trademarks on its own initiative will issue cancellation proceedings for non-use against trademarks. The selection will be random and will only focus on registrations that have been on the register for more than three years. Owners of the trademark registrations will be required to submit evidence of use of their trademarks for each identified product and/or service. Alternatively, the owner of the trademark registration may submit an explanation for any non-use due to exceptional circumstances. If no evidence of use is accepted and there are no exceptional circumstances for non-use, the registration will be cancelled in whole or in part. We encourage those with Canadian trademark registrations to ensure their marks are in use in Canada and to track evidence of such use. Doing so will make the job of providing evidence at the request of CIPO a more manageable endeavor.
January 29, 2025
Data Protection and Privacy
India Draft Digital Personal Data Protection Rules, 2025
This post was written by Indian Law expert, Cyril Abrol, of the law firm Remfry & Sagar and republished with permission from Remfry & Sagar. For more information about Remfry & Sagar and their attorneys, please visit: https://www.remfry.com/. On January 03, 2025, the government released the much awaited draft Digital Personal Data Protection Rules, 2025, (Draft Rules / Rules) for public consultation and invited stakeholder feedback by February 18, 2025 (access the Rules here). The Rules aim to provide an operational framework for the Digital Personal Data Protection Act, 2023 (DPDP Act /Act) which was enacted on August 11, 2023, establishing a framework for protecting digital personal data by regulating its processing in India (read a synopsis here and here). It is also applicable to processing digital personal data outside India, if it involves providing goods or services to data principals (individuals to whom the personal data relates) within the territory of India. Highlights of the Rules include: Notice for consent To obtain informed consent from a Data Principal, a Data Fiduciary must provide it with a clear and standalone notice outlining what data is to be collected, the purpose for the processing, and details of goods /services to be provided or uses to be enabled by the data processing. Additionally, it should contain a direct communication link through which data principals may withdraw consent, file a complaint to the Data Protection Board (‘Board’) etc. Consent Managers The DPDP Act defines a ‘Consent Manager’ as “a person registered with the Board who acts as a single point of contact to enable a data principal to give, manage, review, and withdraw consent through an accessible, transparent, and interoperable platform.” Under the Rules, a Consent Manager must be a company incorporated in India, having a minimum net worth of INR 20 million to ensure financial stability and have a sound reputation and record of fairness, integrity and operational capacity. Security Safeguards Data Fiduciaries must implement measures such as encryption, obfuscation or masking of personal data, access control, monitoring of breaches and unauthorized activities as well as ensure continuity in processing. The Rules set out minimum technical safeguards that include: (i) implementation of access control measures; (ii) maintenance and monitoring of logs of PD access; and (iii) maintenance of back-up data. Data Breach Notification The Rules mandate that all personal data breaches must be reported to both affected users and the Board. Upon becoming aware of a breach, organisations are required to immediately notify affected individuals with comprehensive details including the breach's description, nature, extent, timing, location, potential consequences, risk mitigation and recommended safety measures and contact information for inquiries. Similar information must be concurrently reported to the Board within 72 hours of becoming aware of the breach. Data Retention Policies E-commerce platforms with over 20 million registered users, online gaming intermediaries with over 5 million users and social media intermediaries with over 20 million users must delete user data after 3 years of inactivity. Children's and Disabled Persons’ Data Data fiduciaries must implement measures to ensure that consent for a child’s data is given by their parent and verification is performed to confirm that the consenting party is an adult. Consent for a disabled person is to be obtained from their legal guardian and it must be verified that the guardian has been appointed under applicable guardianship laws. However, there is ambiguity on how it will be established that a Data Principal is a minor or a person with disability. Further, certain Data Fiduciaries, such as healthcare providers or educational institutions, may be exempt from specific obligations when processing children’s data, under defined conditions. For instance, educational institutions are exempt where they track and behaviourally monitor children for educational activities or for safety reasons. Also, processing of personal data for research, archival, or statistical purposes is exempt if it complies with prescribed safeguards (listed in Schedule II to the Rules). Cross-Border Data Transfer Guidelines Restricted /prohibited territories have not yet been notified. Data fiduciaries must ensure compliance with conditions set by the government, through general or special order, for making personal data available to foreign states or entities. Annual Data Protection Impact Assessments (DPIAs) If the Central Government identifies an entity as a Significant Data Fiduciary based on enumerated factors, including volume and sensitivity of the data processing, that entity must conduct annual DPIAs to assess risks associated with their data processing activities and submit their findings to the Board. Once the Rules are finalised, the government will begin appointing members of the Board. Rules meant for businesses /industry will likely take effect in a staggered manner – one report hints at a two year sunrise period for industry to transition to the new law.
January 27, 2025
Data Protection and Privacy
Justice Issues Final Rule Restricting Transfer of Personal U.S. Data to Countries of Concern, Effective in April 2025
The U.S. Department of Justice (“DOJ”) published its final rule (“Final Rule”) on January 8, 2025, that will prohibit or restrict transfer of certain data of U.S. persons to countries of concern, including to China. The Final Rule largely tracks with DOJ’s notice of proposed rulemaking (“Proposed Rule”), which we summarized in a previous eUpdate. The Final Rule therefore adopts the basic structure of prohibiting certain data transactions, while permitting restricted transactions only if security requirements are implemented to protect U.S. personal data. In short, knowing the type of data, the type of transaction, and the location of any person who can access the data is required to determine whether a prohibition or restriction applies to the proposed transaction or transfer of the data under the Final Rule. As explained below, the Final Rule reaches many types of transactions, may cover merely providing access to certain data of U.S. persons, and has a framework of exclusions that may allow companies that would otherwise be regulated by the Final Rule to continue to transfer personal data to countries of concern. The Final Rule is generally effective starting on April 8, 2025, meaning that data transfers after that date will be subject to the Final Rule and the potential penalties for transactions that violate the Final Rule. DOJ delayed the effective date for certain due diligence and auditing requirements to October 5, 2025. In its discussion of the Final Rule, DOJ rejected delaying the effective date further due to what it describes as the need to quickly address transfers of sensitive U.S. personal data to countries of concern. DOJ also holds open the possibility of delaying the effective date of the Final Rule, either in part or in full, through general licenses or regulatory changes. This eUpdate summarizes key aspects of the Final Rule, with a particular focus on changes since the Proposed Rule. The eUpdate does not comprehensively describe the Final Rule. In particular, we note our previous summary of the auditing requirements, due diligence, potential penalties, and other details of the Proposed Rule (see link above), most of which are unchanged by the Final Rule. Legal Background By issuing the Final Rule, DOJ has concluded the rulemaking process to implement Executive Order (“EO”) 14117 dated February 28, 2024. As a basis for regulating international data transfers, EO 14117 and the Final Rule declare an international emergency under the International Emergency Economic Powers Act (“IEEPA”). In particular, President Biden in EO 14117 identified efforts to access and exploit government-related data or bulk U.S. personal data by countries of concern as an unusual and extraordinary threat to U.S. national security. DOJ identifies counterintelligence concerns, the risk of blackmail and ransomware, and the ability to use artificial intelligence (“AI”) tools as justifying action under the Final Rule. DOJ also notes a gap in federal law that currently does not address international data transfers to countries of concern. Who is Impacted by the Final Rule? The Final Rule broadly applies to and regulates the activities of U.S. companies and individuals operating in many industries and markets. The framework for the Final Rule is outlined below. Initially, however, it is worth highlighting some examples of activities that DOJ believes are subject to the Final Rule, which are indicative both of the scope of and priorities reflected in the Final Rule. We note these examples with caution, as the status of these examples under the Final Rule could change depending on the precise facts (e.g., amount of data collected), and the activities described below may be permissible if relevant parties adopt security measures, or if the activities qualify for an exemption. We thus refer to these examples as subject to potential restrictions under the Final Rule, depending on the facts and circumstances of the transactions. A U.S. company develops mobile app games that collect data on U.S. users. The U.S. company hires a CEO from a country of concern, who will be provided access to data on the U.S. users. The hiring of the CEO is subject to potential restrictions under the Final Rule. A U.S. company develops social media apps that systematically collect data of U.S. users. A foreign company from a country of concern purchases a minority stake in the U.S. business. The investment agreement allows the foreign company to access the data of U.S. users. The investment agreement is subject to potential restrictions under the Final Rule. A U.S. company operates an app that gathers geolocation data of U.S. users. The U.S. company enters into a vendor agreement with a country of concern to process and store the data. The vendor agreement is subject to potential restrictions under the Final Rule. A medical facility with health data about U.S. patients contracts with a company in a country of concern to provide IT-related services, including by providing access to the data about U.S. patients. The contract is subject to potential restrictions under the Final Rule. A multinational company maintains data about U.S. persons and contracts with a service provider in a country of concern to process and store the data, including the data about U.S. persons. The service agreement is subject to potential restrictions under the Final Rule. A U.S. company hires a data scientist who is a citizen of a country of concern to develop an AI personal assistant intended for the U.S. company’s financial services customers. The data scientist’s responsibilities require access to data on large numbers of U.S. persons. The employment of the data scientist is subject to potential restrictions under the Final Rule. As is apparent from these examples, the Final Rule applies to and potentially restricts the activities of companies in many industries and in a wide range of common IT and business operations. Below we summarize key aspects of the Final Rule. Key Definitions in Final Rule The Final Rule applies to U.S. persons who process sensitive U.S. government or bulk U.S. sensitive personal data as described below, and in particular those who engage in transactions with or have operations in countries of concern. However, the Final Rule also will significantly impact non-U.S. persons or operations involving countries other than countries of concern, to the extent they may be involved with U.S. government data or bulk U.S. sensitive personal data and there is or may be potential access to personal data in countries of concern. DOJ adopts the following key definitions in the Final Rule, all of which are closely aligned with those in the Proposed Rule. “Bulk U.S. Sensitive Personal Data.” The Final Rule adopts “bulk” thresholds consistent with the Proposed Rule. These categories are summarized in the chart at the end of this eUpdate. In a change from the Proposed Rule, DOJ also established a bulk threshold for epigenomic, proteomic, or transcriptomoic data of U.S. persons. “Countries of Concern.” The Final Rule designates six countries—China (including Hong Kong and Macau), Cuba, Iran, North Korea, Russia, and Venezuela as countries of concern. This list can be expanded upon further designations of countries that pose a risk to U.S. national security. “Covered Person.” The Final Rule prohibits or restricts transfers to a Covered Person in addition to a Country of Concern. DOJ revised the definition of a Covered Person to cover the following: (1) foreign entities that are 50 percent or more owned (individually or in the aggregate) by a Country of Concern, organized under the laws of a Country of Concern, or have their principal place of business in a Country of Concern; (2) foreign entities that are 50 percent or more owned (individually or in the aggregate) by a Covered Person; (3) foreign employees or contractors of countries of concern or entities that are Covered Persons; and (4) foreign individuals primarily resident in Countries of Concern. DOJ also can specifically designate persons, regardless of location, that it determines to be, or to have been, controlled by or under the jurisdiction of a Country of Concern or a Covered Person. “U.S. Person.” A U.S. person includes any individual or entity who is located in the United States; individuals who are U.S. citizens, nationals, or permanent residents, or have refugee or asylee status under U.S. law; and corporations organized solely under the laws of the United States. “U.S. Government Data.” U.S. Government-Related Data includes two types of data, regardless of the volume of the data: (1) geolocation data covering any precise location data within specific longitude and latitude coordinates within areas identified in the Final Rule; and (2) data about U.S. Government personnel marketed as linked to current or recent former U.S. Government employees or contractors. The Final Rule defines “recent employees or contractors” as those who worked for the U.S. Government (including the military and intelligence community) within a two-year period preceding a covered transaction. Prohibited, Restricted, and Exempt Transactions The Final Rule creates a framework of prohibited, restricted, and exempt transactions. Companies will need to consider whether they have transactions of U.S. Government or Bulk Sensitive U.S. Person Data with Countries of Concerns or Covered Persons, and if so, whether those transactions are prohibited, restricted, or exempt. The Final Rule also prohibits facilitating prohibited or restricted transactions, actions taken to circumvent the Final Rule, or causing a violation of the Final Rule. This framework ultimately will allow certain companies to continue working or collaborating with countries of concern. Companies can rely on the categories of exempt transactions to permit sharing of certain data between the United States and a Country of Concern. Alternatively, certain restricted transactions may, however, proceed if companies adopt security requirements specified in the Cybersecurity and Infrastructure Security Agency (“CISA”) rules. The CISA security requirements can be found online and are summarized below. The Final Rule prohibits U.S. persons from engaging in two types of transactions. Data Broker Transactions. The Final Rule prohibits a “Data Brokerage” transaction with a Country of Concern or a Covered Person that involves Bulk U.S. Sensitive Personal Data. A “Data Brokerage” transaction means selling, licensing, or similar commercial transactions where the recipient did not collect or process the data directly from the individuals linked or linkable. By definition, a “Data Brokerage” transaction is not an employment agreement, investment agreement, or vendor agreement as those terms are defined below. These Data Brokerage transactions are defined more broadly than transactions under other data brokerage laws, and the DOJ notes as justification for this broad definition that the operation of ad exchanges, the use of social media, or other “tracking” pixels can allow access to Bulk Sensitive U.S. Personal Data or U.S. Government Data by a Covered Person or in a Country of Concern. Human Genetic Data. The Final Rule prohibits a U.S. person from engaging in a transaction with a Country of Concern or a Covered Person involving bulk human genomic data, or data concerning bulk epigenomic, proteomic, or transcriptomoic as defined below at the end of this eUpdate. The Final Rule makes the following three classes of transaction restricted: (1) employment agreements, (2) non-passive investment agreements, and (3) vendor transactions (collectively, “Restricted Transactions”). Unless the U.S. person adopts CISA’s proposed risk mitigation security requirements, U.S. persons cannot engage in the following Restricted Transactions with Countries of Concern or a Covered Person if they involve Bulk U.S. Sensitive Personal Data. Employment Agreements. Agreements or arrangements where an individual, other than an independent contractor, performs work or job functions in exchange for payment or other consideration, including on a board or committee, executive-level arrangements or services, or employment services at an operational plant. Investment Agreements. The exchange of payment or other consideration for direct or indirect ownership interests or rights in relation to real estate in the United States or a U.S. legal entity. The Proposed Rule excludes from an “Investment Agreement” passive investments such as for publicly traded securities, index funds, or as a limited partner in a venture capital fund. Vendor Agreements. The provision of goods or services, including cloud-computing services, in exchange for payment or other consideration, other than an Employment Agreement. The Final Rule also establishes a framework of exempt transactions that will make many data processing activities and transactions outside of the Final Rule’s prohibitions or restrictions. In particular, the following nine types of activities or transactions may qualify for exemptions under the Final Rule. Personal communications, informational materials, and travel information are exempt under the Final Rule. This exclusion recognizes long-standing exclusions, mandated under the IEEPA statute, from IEEPA-based U.S. economic sanctions administered by the U.S. Department of the Treasury Office of Foreign Assets Control (“OFAC”). Companies will need to carefully consider the scope of these exemptions, which DOJ likely will interpret narrowly, similar to OFAC’s narrow interpretation of them. Activities involving U.S. Government operations. Financial services for banking, capital markets, futures or derivatives, or financial insurance services, e-commerce, and certain investment management services. Corporate group transactions between a U.S. person and its foreign subsidiary or affiliate, if they are ordinarily incident to and part of routine administrative or business operations, such as human resources, payroll, taxes, permits, compliance, risk management, travel, and customer support. Transactions related to certain federal law or international agreements. DOJ cites the following legal instruments as authorizing transactions under this exemption: the Convention on International Civil Aviation (2022); the WHO constitution (1946); various U.S.-China agreements on customs, legal assistance, and taxation; the U.S.-Cuba Extradition Treaty (1905); U.S.-Russia agreements on customs (1994) and legal assistance (1999); the U.S.-Venezuela Legal Assistance Treaty (1997), the International Health Regulations (2005); and certain public health surveillance and response mechanisms. Investment agreements that are subject to mitigation or other action taken by the Committee on Foreign Investment in the United States (“CFIUS”), if CFIUS explicitly designates them as exempt. Transactions that are ordinarily incident to and part of the provision of telecommunications services, including voice and data communications services regardless of delivery method. DOJ lists communications via cable, Internet Protocol, wireless, fiber, or other transmission mechanisms, as well as arrangements for network interconnection, transport, messaging, routing, or international voice, text, and data roaming as potentially qualifying for this exemption. Transactions involving data transfers or access to data with a Country of Concern or Covered Persons involving drug, biological product, device, or combination product approvals or authorizations if such approvals are necessary to obtain or maintain regulatory approval. “Regulatory approval data” means sensitive personal data that is de-identified or pseudonymized under FDA regulations (21 C.F.R. 314.80(i)) and required by a regulatory entity to research or market a drug, biological product, device, or combination product, including post-marketing studies and surveillance. Clinical investigations and post-marketing surveillance data if the transactions are part of clinical investigations regulated by the FDA under sections 505(i) and 520(g) of the Federal Food, Drug, and Cosmetic Act, or to support FDA applications for research or marketing permits for drugs, biological products, devices, combination products, or infant formula, and the data are de-identified or pseudonymized consistent with FDA regulations (21 C.F.R. 314.80(i)). Final CISA Security Rule Under the Final Rule, Restricted Transactions may be permitted on the condition that certain security procedures and controls are put in place to protect U.S. Government Data or Bulk Sensitive U.S. Personal Data (collectively, Covered Data). These security controls must be implemented with respect to any “Covered System” that is used to process Covered Data as part of a Restricted Transaction, regardless of whether Covered Data has been deidentified or encrypted on that system. Further, in a clarification in the Final Rule, the existence of security measures does not affect the application of the Final Rule, in principle, meaning that the existence of comparable security controls (e.g. encryption) does not impact companies’ obligations to comply with other requirements of the Final Rule. Under CISA’s final security rule requirements, there were relatively few changes to the mandatory security processes and controls relative to the proposed CISA rule. However, certain incremental changes were made, and the final CISA rule allows companies to take a slightly more flexible and risk-based approach with respect to certain controls, in particular those relating to vulnerability management, logging, and certain systems documentation. As with the Proposed Rule, CISA’s security requirements borrow heavily from NIST Cybersecurity Framework and Privacy Framework standards. However, the specificity of these requirements, and CISA’s intent to build on the specific national security objectives set out in the Order, mean that these requirements include a number of new and unique obligations for affected organizations. Organizations engaging in Restricted Transactions that must conform to the CISA rules will therefore be required to conduct additional IT system reviews, update applicable policies, and establish additional security controls in order to properly secure Covered Data in Restricted Transactions. Conclusion Companies involved in many industries should consider whether the Final Rule requires adoption of new or revised data policies, including companies involved in cloud computing, e-commerce, education, healthcare, financial services, manufacturing, software design, and others. Summary of Bulk U.S. Sensitive Personal Data Definition “Bulk” Threshold (U.S. persons) Biometric Identifiers Physical characteristics that are measurable or behaviors used to recognize or verify the identity of an individual, including facial, voice, retina or iris, palm, fingerprints, gait, or keyboard usage data that are enrolled in a biometric system and the templates used to create such a system. 1,000 Geolocation Real-time or historical data that identifies the physical location of an individual or a device with a precision of within 1,000 meters 1,000 Human Genomic Nucleic acid sequences that are the entire set or a subset of genetic instructions found in human cells, including the result of an individual’s genetic test and genetic sequencing data. 100 Other Genetic Data (‘omic data) Epigenomic, proteomic, or transcriptomoic data of individuals 1,000 Personal Financial Data about an individual’s credit, charge, or debit card, or bank account, including purchases and payment history; data in a bank, credit, or other financial statement, including assets, liabilities, debts, or trades in a securities portfolio; or data in a credit report or in a consumer report. 10,000 Personal Health Health information about past, present, or future physical or mental health or conditions of an individual; healthcare information about an individual or payment information about healthcare. 10,000 Personal Identifiers Identifiers that in combination with any other listed identifier or other data is linked or linkable to sensitive personal data. This includes names linked to device identifiers, social security numbers, driver’s license or other government identification numbers, and many others. The definition excludes certain data (e.g., demographic data linked only to other demographic data). 100,000
January 22, 2025
Advertising
FTC Finalizes Click to Cancel and Negative Option Rule
On October 16, 2024, the Federal Trade Commission (FTC) announced a revision to its negative option rule. The rule, formally entitled the “Rule Concerning Recurring Subscriptions and Other Negative Option Programs,” is a robust governmental intervention into the marketing and sales of products or services that involve “negative option features.” A “negative option feature” exists if seller provides a contract “under which the consumer’s silence or failure to reject goods or services or to cancel the agreement is interpreted by the [ ] seller as acceptance or continuing acceptance of the offer.” 16 C.F.R. 425.2. Although the revised negative option rule does not prohibit negative option programs, it imposes certain requirements on sellers using them. I. Negative Option Programs The FTC explains that many negative option programs fall into one of four familiar categories: Prenotification plans, such as book-of-the-month clubs, where “sellers provide periodic notices offering goods to participating consumers and then send—and charge for—those goods only if the consumers take no action to decline the offer.” Continuity plans, where “consumers agree in advance to receive periodic shipments of goods or provision of services . . . which they continue to receive until they cancel the agreement.” Automatic renewal plans, common in the magazine subscription context, where sellers “automatically renew consumers’ subscriptions when they expire, unless consumers affirmatively cancel the subscriptions.” Free-to-pay plans, in which “consumers receive goods or services for free . . . for a trial period” but afterward “sellers automatically begin charging a fee (or a higher fee) unless consumers affirmatively cancel or return the goods or services.” II. Requirements for Negative Option Programs Regardless of the form of the negative option program, the FTC’s new rule, which is set to go into effect in part on January 14, 2025, and in full on May 14, 2025, imposes four principal requirements on all negative option programs, whether offered online or via more traditional channels. The FTC considers any negative option program that fails to meet each of the four requirements to be a per se violation of section five of the Federal Trade Commission Act, and the FTC may seek civil penalties for each violation. A. No Misrepresentations; Information Requirements The first two requirements are closely related. The first requirement prohibits the misrepresentation of any material fact related to the transaction, including facts about the negative option feature and the underlying goods or services. The second requirement is that sellers clearly and conspicuously disclose all material terms related to the negative option feature. These material terms include: (1) “[t]hat consumers will be charged for the good or service, or that those charges will increase after any applicable trial period ends, and, if applicable, that the charges will be on a recurring basis, unless the consumer timely takes steps to prevent or stop such charges; (2) [t]he deadline (by date or frequency) by which the consumer must act in order to stop all charges; (3) [t]he amount (or range of costs) the consumer will be charged and, if applicable, the frequency of such charges a consumer will incur unless the consumer takes timely steps to prevent or stop those charges; (4) the date (or dates) each charge will be submitted for payment; and (5) the information necessary for the consumer to cancel the negative option feature.” The prohibition on misrepresentation takes effect on January 14, 2025, while the second requirement relating to the disclosure of material terms (along with the other requirements discussed below) take effect on May 14, 2025. 16 C.F.R. § 425.3 to § 425.4. B. Consent The third requirement is that a seller promoting or offering goods or services with a negative option feature must “obtain the consumer’s unambiguously affirmative consent to the negative option feature offer separately from any other portion of the transaction,” “not include information that interferes with, detracts from, contradicts, or otherwise undermines the ability of consumers to provide their express informed consent,” and to maintain records regarding that consent for three years, unless consumers cannot complete a transaction without providing such consent. 16 C.F.R. § 425.5. C. Click to Cancel The final requirement is the so-called “click to cancel” component of the rule. It requires that a seller offering a negative option program provide a “simple mechanism” for cancellation. 16 C.F.R. § 425.6(a). The cancellation mechanism must be “at least as simple” as the sign-up process and must be offered “through the same medium” as the sign-up. 16 C.F.R. § 425.6(b) and (c). For online negative option programs, consumers cannot be required to “interact with a live or virtual representative . . . to cancel if the consumer did not do so” to sign-up. 16 C.F.R. § 425.6(c)(1). And, for in-person programs, the seller must offer both an in-person cancellation option “where practical” as well as a telephonic or online option. 16 C.F.R. § 425.6(c)(3). III. Challenges The negative option rule has been challenged by a number of industry groups. The litigation challenging the Rule was subsequently consolidated under Custom Communications Inc., v. FTC, 8th Cir, No. 24-3137. The challengers are seeking a stay of the rule prior to certain provisions taking effect on January 14, 2025. Additionally, there has been speculation as to whether the new administration will continue to support the negative option rule. The rule was passed by the FTC on a 3-2 party-line vote, with the recently named FTC Chair, Andrew Ferguson, voting against the rule. Stay tuned for more from the TMCA as the rule progresses through the courts and the Federal Trade Commission under the new administration. IV. More Information The FTC has made a fact sheet about the revised negative option rule available and provided a plain language description of the rule.
January 13, 2025