The TMCA
Copyrights
Will “Success Kid” Owner Continue to Succeed on Appeal in Copyright Dispute?
Years ago, Laney Griner took a picture of her then toddler son, Sam, at the beach clenching his fist in what appeared like a celebratory gesture. The photo went viral, and later became a widely used meme on the internet known as “Success Kid.” Griner registered the copyright in the photo, and has successfully licensed its use to several large companies. She also has encouraged non-commercial uses of the photograph by publishing instructions on how to create a meme using “Success Kid.” The campaign committee of former Iowa Congressman Steve King used “Success Kid” without Griner’s permission to fundraise for King’s unsuccessful bid at reelection, adding a fundraising message to the image of Sam that said: “Fund our memes.” Griner sued both King and his campaign for copyright infringement, and the jury found the campaign liable, awarding Griner the statutory minimum of $750. Despite being liable for only the statutory minimum, the campaign appealed on multiple grounds, including that the Eighth Circuit should apply a different standard to determining an implied license, that the jury incorrectly rejected the fair use defense, and that the district court erred when it refused to award attorneys’ fees to the campaign. King—whom the jury found not liable for copyright infringement—also appealed the trial court’s refusal to award him attorneys’ fees as a prevailing party. The Eighth Circuit Court of Appeals recently heard oral argument on the appeal, which potentially raises multiple issues relevant to copyright owners of works used widely on the internet for non-commercial and commercial purposes. The campaign relied heavily on claims that Griner should not be permitted to both allow and encourage wide-spread use of “Success Kid”—which counsel called one of the five most popular memes ever—to increase the photo’s value for commercial licensing, but then to selectively target the campaign’s admittedly commercial use of the meme. The campaign urged the Court to imply a license to use the photo through Griner’s conduct, rather than apply the traditional factors required for an implied license. Griner’s counsel noted that musicians use a similar business model: making their music available for non-commercial uses on platforms like the Instagram Music Library, but then licensing that music for commercial purposes. One member of the panel wondered what would be left of copyright law in the Internet age if the Court agreed with the campaign and found an implied license (or that works passed into the public domain) due to widespread use of the work in memes. Though it would be more interesting from a copyright law perspective for the Court to weigh in on these arguments, it may not do so because the campaign appeared to have waived its implied license argument at trial. The campaign also argued that the purpose and character of its use of “Success Kid” favored a finding of fair use because the use was political, was like billions of other uses of the photo, and Griner had acquiesced to and encouraged the use of the photo as a meme. The campaign failed to recognize or to cite to the Supreme Court’s seminal fair use case, Andy Warhol Found. for the Visual Arts, Inc. v. Goldsmith, which had been decided a few months before the campaign filed its brief. The Eighth Circuit has yet to publish a decision applying Andy Warhol, but questioned both counsel about its effects in this case and more generally. One member of the panel even asked point blank: “What’s left of the fair use doctrine after the Andy Warhol case?” As it applies to this case, counsel for Griner argued that the campaign’s use was commercial, and was not otherwise sufficiently transformative, so the first fair use factor favored Griner. Other than adding a fundraising message to the photo, the campaign did not point to other evidence distinguishing its use. Though the case presents an opportunity for the Eighth Circuit to apply Andy Warhol, the extent to which it will do so may be limited. The fair use argument not only appears to favor Griner here, but also, as one panelist noted, the campaign “is pushing a big rock up a big hill” in its efforts to overturn the jury’s finding of infringement. If the Court upholds that verdict, the case supports a copyright owner’s continued right to control the commercial use of their work, even where it has been widely used online for non-commercial purposes, and even where the copyright owner has encouraged such non-commercial use (though the financial incentives for doing so under similar circumstances may be small). Relevant to the potential financial incentives and risks facing copyright owners, the panel also will decide whether the district court properly exercised its discretion in denying attorneys’ fees to the defendants. The Eighth Circuit has not directly addressed the intersection of Rule 68 and Section 505 of the Copyright Act. The district court applied Marek v. Chesney, 473 U.S. 1 (1985), and found that Section 505 only supports awarding fees to a defendant whose offer of judgment was more favorable than the final award if the defendant was a prevailing party. So, even though Griner had rejected a Rule 68 offer of judgment for $15,000, the campaign could not recover its post-offer fees because it did not prevail on the infringement claim. As to King, who prevailed on the copyright claim, the court exercised its statutory discretion to award attorneys’ fees in any copyright case and determined that fees were not appropriate in part because Griner’s claim was reasonable and—contrary to King’s claims that the lawsuit was politically motivated—her motivations were not malicious. On appeal, Griner urges the Eighth Circuit to weigh in on Rule 68 offers in copyright actions, to agree with the district court, and to expressly adopt the reasoning of the Seventh and Ninth Circuits to find that defendants are only potentially entitled to attorneys’ fees in copyright cases if they actually prevail on the merits of the infringement claim. Doing so would ensure that copyright owners who prove infringement would not be on the hook for the infringer’s attorneys’ fees. In questioning Griner’s counsel on this issue, the panel instead focused on the trial court’s broad discretion to award fees in copyright cases, potentially signaling a reluctance to adopt the bright-line position urged by Griner. The TMCA will monitor this case to see what guidance the Eighth Circuit may offer to copyright litigants on these issues, and will be sure to provide our valued readers with any relevant updates.
April 23, 2024
Copyrights
Warhols, Tigers and Monkees, Oh My! – The Tenth Circuit Applies the Supreme Court’s Warhol Decision Against Netflix
In a mashup that the late pop artist Andy Warhol surely would have loved, the U.S. Court of Appeals for the Tenth Circuit has applied the Supreme Court’s 2023 decision in Andy Warhol Foundation for the Visual Arts, Inc. v. Goldsmith to vacate a prior district court decision on the issue of fair use, and to remand the case for further fact-finding. Does the decision settle the defense of fair use in that case? No, but as explained below, the defendants in that case still have reason to hope that their defense will prevail. In the dark days of the 2020 pandemic, one obsession of many television viewers looking for something to take themselves out of the world in which we were then living was the Netflix documentary, Tiger King. As explained by Netflix, the documentary focused on “the stranger-than-fiction world of big cat owners,” most notably “Joe Exotic, a mulleted, gun-toting polygamist and country western singer who presides over an Oklahoma roadside zoo. Charismatic but misguided, Joe and an unbelievable cast of characters including drug kingpins, conmen, and cult leaders all share a passion for big cats and the status and attention their dangerous menageries garner. But things take a dark turn when Carole Baskin, an animal activist and owner of a big cat sanctuary, threatens to put them out of business, stoking a rivalry that eventually leads to Joe's arrest for a murder-for-hire plot, and reveals a twisted tale where the only thing more dangerous than a big cat is its owner.” Tiger King was a massive hit and, as sometimes happens, Netflix and the documentary’s producers became the subject of a variety of legal claims, including, in this case, for copyright infringement. In 2020, Netflix and the Tiger King production company were sued in Oklahoma by Whyte Monkee Productions and Timothy Sepi, the alleged owners of the copyright in certain video footage from the documentary that was, per plaintiffs, used without their authorization or compensation. The footage in question consisted of eight recorded excerpts – seven created while Mr. Sepi was working for the animal park in question, and an eighth excerpt filmed after Mr. Sepi was no longer employed there. As to the first seven excerpts, both the district court and the Tenth Circuit agreed that plaintiffs did not own any copyright in them because Mr. Sepi shot the footage as part of his duties at the animal park, so they were works made for hire that did not belong to plaintiffs, such that there could be no infringement of plaintiff’s rights. But the copyright in the eighth excerpt – footage from the funeral of Joe Exotic’s husband, Travis Maldonado – did belong to plaintiffs because Mr. Sepi filmed the funeral after he ceased to be an animal park employee. To be sure, Mr. Sepi acknowledged that all he did to create this footage was place a video camera on a tripod in a location where funeral speakers could be recorded, hit “record,” and then press “stop” when the funeral was over. But, both the district court and Tenth Circuit held that the footage was sufficiently original to warrant copyright protection. However, the district court and the Tenth Circuit parted company on the defendants’ affirmative defense of fair use. Applying pre-Warhol precedents, the district court held that the inclusion of the eighth excerpt in the documentary was permitted under principles of fair use, largely because the excerpted sixty-six seconds of funeral footage focusing on portions of Mr. Exotic’s eulogy was “transformative.” Specifically, the district court held that the “purpose” of the excerpt’s inclusion in Tiger King – to make a point about Mr. Exotic’s narcissism – was different from the “purpose” of the original funeral footage – to record the services for Mr. Maldonado – meaning that the first statutory fair use factor (the “purpose and character of the use”) weighed strongly in favor of fair use. Enter Warhol, decided while the plaintiffs’ appeal was pending at the Tenth Circuit. In Warhol, the Supreme Court downplayed considerations of whether a particular use was or was not “transformative,” in favor of a two-part inquiry: (i) whether and to what extent the challenged use has a purpose that is different from that of the original work; and (ii) whether the challenged use is commercial or non-commercial. As the Supreme Court held, In sum, the first fair use factor considers whether the use of a copyrighted work has a further purpose or different character, which is a matter of degree, and the degree of difference must be balanced against the commercial nature of the use. If an original work and a secondary use share the same or highly similar purposes, and the secondary use is of a commercial nature, the first factor is likely to weigh against fair use, absent some other justification for copying. Applying Warhol to the Tiger King controversy before it, the Tenth Circuit concluded that the video was not used in a transformative way to comment on the video, but to comment on Mr. Exotic. In the same way, per the Tenth Circuit, Andy Warhol’s use of Lynn Goldsmith’s photo of the artist Prince to create a new image was merely a commentary on Prince, not the Goldsmith photo, and therefore insufficiently transformative. To this writer, that is not quite what the Supreme Court said in Warhol on the issue of transformativeness. But, the Tenth Circuit went on to hold, per Warhol, that the commercial purpose of Tiger King, and the fact that using excerpted video in a documentary is often a purpose different from that underlying the creation of the excerpted video in the first place, tilted the first fair use factor strongly against defendants. That reasoning is entirely consistent with Warhol and highlights how sharply the Supreme Court’s decision has altered the fair use analysis, at least on the first statutory factor, to favor plaintiffs in copyright cases. What of the other three fair use factors? The second factor – the nature of the copyrighted work – weighed in favor of the defendants because the funeral excerpts were factual and had been live streamed, and therefore published. As to the third factor – the amount and substantiality of the portion of the funeral video used – the sixty-six-second excerpt from a twenty-four-minute video was a factor that weighed in favor of defendants, as they used only what a reasonable person would think appropriate to make their artistic point. Further, while the short excerpt was an “unusual” part of the video, both the district court and the Tenth Circuit felt that the segment was not likely to be viewed by most people as the most important portion of the video. As for the last fair use factor – the impact of the allegedly infringing use on the market for the plaintiffs’ video – here again the district court and Tenth Circuit diverged. The district court held that Tiger King was not a market substitute for the original funeral video, but the Tenth Circuit held that there was no evidence of this, nor of whether the inclusion of the funeral excerpt in Tiger King had an impact on plaintiffs’ ability to license their footage elsewhere. Indeed, because fair use is an affirmative defense, it was defendants’ burden to prove the absence of a market impact, a burden they largely made no attempt to carry, other than by establishing that plaintiffs had never licensed the video anywhere, which the Tenth Circuit felt was, by itself, insufficient. The court pointed to other evidence suggesting that licensing opportunities may have existed for the footage, and in light of the incomplete evidentiary record concerning this factor, the Court remanded the case for more fact-finding on that factor. Defendants therefore have every reason to believe that they can once again prevail on the defense of fair use, provided they can marshal evidence showing an absence of market harm. The main takeaway from the Whyte Monkey Productions case is that when it comes to fair use, the ability of defendants to persuade courts to weigh the first fair use factor in their favor has been substantially limited by the Warhol decision. It is therefore crucial that parties seeking to rely on that defense do everything they can to swing the other three factors – especially the fourth – in their favor.
April 15, 2024
Data Protection and Privacy
The New Face of Fraud: Deepfakes and the Emerging Cyber Threats in Hong Kong
Almost from the very beginning of the internet era, the world has been increasingly afflicted with cyberfraud, exploiting the internet’s potential to enable fraudsters to induce unsuspecting victims to transfer money to overseas bank accounts using another relatively recent technological innovation, electronic funds transfer. Hong Kong is a destination particularly favored by fraudsters for such transfers, due to its open banking system and the ease with which funds can be retransferred from there to mainland China, from which many of the fraudsters operate and where recovery of funds is much more difficult, if not impossible. Recently, a new breed of deception has emerged, in Hong Kong as well as elsewhere, using the powerpost of deepfake technology. Despite robust government measures to combat fraud, fraudsters are getting creative and discovering new methods to take advantage of people. This post will review the most recent fraud statistics and what the government is doing to stop it in Hong Kong, take a closer look at the worrying increase in deepfake scams, and provide practical guidance for everyone to better protect themselves from these growing online dangers. Alarming Statistics According to the statistics announced by the Hong Kong Police Force (HKPF) on February 6, 2024 (the “2023 Statistics”), deception cases in 2023 surged by 42.6%, totaling 39,824 cases. Internet-related scams accounted for approximately 70% of the reports, involving over HK$9 billion (US$1.15 billion). Common fraudulent activities included online shopping scams (8,950 cases, a 2.5% increase), investment fraud (6,330 cases, a 1.2-fold increase), phishing scams (4,322 cases) – newly covered in January 2023, employment fraud (3,930 cases, a 31.2% increase), social media deception (3,372 cases, a 6.5% decrease) and telephone deception (3,213 cases, a 13.5% increase). Government Anti-Deception Efforts – “Scameter+” In our prior article published in June 2023, we discussed the various measures implemented by the Hong Kong Government in response to the rising deception cases. As part of these efforts, the HKPF launched the one-stop scam and pitfall search engine “Scameter+” in February 2023 to assist the public in identifying fraud and online pitfalls. According to the 2023 Statistics, “Scameter+” has recorded over 2.13 million searches and issued nearly 360,000 alerts on frauds and cyber security risks. The HKPF plans to enhance the “Scameter+” app by introducing new features, such as enabling it to send alerts when users encounter suspicious websites or receive suspicious calls, as well as introducing a public reporting mechanism within the “Scameter+” app. Deepfake Scams Despite the government’s anti-deception efforts, there were 3,238 cases of deception reported in the first month of 2024, accounting for 42% of all crimes. The number of deception cases is on the increase worldwide. In the rapidly changing world of cybercrime, fraudsters are constantly seeking new opportunities to exploit vulnerabilities. Their newest tool? Deepfake Technology! This cutting-edge AI-driven technique allows scammers to create highly convincing fake videos and audio recordings, blurring the boundaries between reality and deception. In February 2024, the Hong Kong office of a multinational company fell victim to a sophisticated scam involving deepfake technology. The fraudsters created digital replicas of the company’s chief financial officer and other employees, who appeared to participate in a video conference. By convincingly replicating the appearance and voices of the targeted individuals using publicly available video and audio footage, the fraudsters deceived an employee of the Hong Kong office into making 15 transfers, totaling HK$200 million (US$25.6 million), to multiple bank accounts. This incident marked the first known case in Hong Kong where victims were deceived in a multi-person video conference setting. It is particularly concerning that the company officials only became aware of the scam about a week later and subsequently reported to the HKPF. The delayed realization underscores the importance of raising awareness and educating employees about the risks associated with deepfake technology, as well as other forms of cyberfraud. It is crucial for organizations to implement internal security measures and provide regular training to the staff so that they can recognize and respond to such scams effectively. While deepfakes currently constitute only a small portion of Hong Kong’s wider cyber fraud landscape, it remains imperative that we proactively take steps to safeguard ourselves. As individuals, we play a crucial role in safeguarding our digital lives and ensuring online security. Here are proactive steps to take: Stay Informed: Keep up-to-date with the latest trends in cyberfraud, common scams and deceptive techniques to better recognize and avoid falling victim to fraud. Verify Sources: Exercise caution when receiving requests for sensitive information or financial transactions, especially during video calls. Verify the authenticity of individuals by asking them to perform specific actions, such as moving their heads, or by answering questions that confirm their identity. Use of Technology: Leverage AI-driven tools to detect anomalies and inconsistencies in communications. These advanced technologies can help identify potential deepfakes or other fraudulent activities, providing an additional layer of protection. Act Quickly: If you suspect wire fraud, contact your bank immediately to report the incident and request a hold on the transaction, or to recall funds. Engage a trusted lawyer who has experience in fraud as soon as possible. To learn more about email wire fraud and business email scams, we recommend reading our in-depth guide on protecting against such scams and recovering funds wired to Hong Kong. Our experienced Hong Kong and U.S. wire fraud lawyers have handled numerous cross-border wire fraud cases and are well-equipped to provide expert assistance and guidance. Please visit our International Cyber Crime and Asset Recovery page. [1] See HKSAR Press Release on 6 February 2024 [2] See South China Morning Post, “Hong Kong police log 15 per cent surge in scams in January, despite integration of anti-fraud app into major payment system” dated 12 March 2024 [3] See RTHK News “Deepfake colleagues trick HK clerk into paying HK$200m” dated 4 February 2024
April 12, 2024
Regulatory Compliance
AI Regulation Introduced in Europe – Setting the Way Forward for the Rest of the World or Slowing Down the Adoption of New Tech?
The EU AI Act, which was passed by the European Parliament on 13 March and is set to become law later this year, will probably be the world’s first legislation to introduce a general regulatory framework for artificial intelligence systems. The European Union is known to pioneer the responsible regulation of emerging technology, and the AI Act is no exception: it intends to govern the development, deployment and use of AI systems in order to protect against risk and uphold health, safety and fundamental rights, while balancing technological development and competition. If successful in achieving that balance, it will likely inform legislative standards around the world. The framework comes at a time where artificial intelligence is increasingly becoming more easily and readily deployable in a range of sectors and products, presently with little or no limitations to its usages. Overview The Act will cover AI systems that are deployed anywhere in the European Union, defining an AI system broadly as: “a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.” The framework classifies AI systems according to the risk they present and sets out categories ranging from “unacceptable risk” to “minimal risk”, each subject to varying degrees of regulation. The majority of the Act focuses on requirements for developers of “high risk” systems, including regulatory oversight and conformity assessments, data quality and traceability, robustness and accuracy, human oversight, and transparency – but there are also obligations for commercial users, importers, distributors and product manufacturers. Further, the Act prohibits certain systems that are deemed to present unacceptable risk. Rules are also laid down for general-purpose AI models, being those systems that are widely integrated into a range of products without a specific purpose. Prohibited Systems The Act bans, with very limited exceptions, AI systems which pose unacceptable threats to the safety, livelihood and rights of EU citizens, including systems designed to: Manipulate or influence people’s behaviour subconsciously; Exploit vulnerabilities of specific groups in order to distort their behaviour; Conduct social scoring (i.e. categorising people based on their behaviour, race, political opinions, sexual orientation, etc.); Enable facial recognition using web-scraping; Conduct real-time biometric identification, except in very limited law enforcement situations. Additionally, systems designed to do anything else which is already against the law are prohibited. High-risk Systems Systems considered high-risk are those with significant potential to cause harm or affect safety or fundamental rights. Specifically, AI systems used in certain sectors are designated as high-risk, including systems used in medical devices, lifts, machinery, aviation, automotive and transportation, education, border control, and the management of critical infrastructure. Of course, products within many of these sectors are already regulated products in the European Union and subject to safety standards and conformity assessment requirements. The Act designates as “high risk” any AI system used as part of a regulated product falling within any of the list of existing product regulations set out in Annex II of the Act. In addition, Article 6(1) designates as “high risk” any system intended to be used as a safety component or as a safety product, if such product or system is subject to a legal requirement in the EU to undergo a third-party conformity assessment. Further, under Article 6(2) of the Act, regardless of the particular product or system in which an AI model might be deployed, if the AI system is developed for use within certain sectors listed in Annex III of the Act it will be considered “high-risk”. These listed sectors include education and vocational training, biometrics, law enforcement, employment and critical infrastructure. Any use of an AI system in one of the listed areas is deemed “high-risk” regardless of whether the system is part of a regulated product subject to EU safety standards. For example, in the employment sector, AI systems might be used to filter out prospective applicants; in the education sector, a system might be deployed to assist with deciding on admissions. Such systems will be deemed “high-risk” under the Act. Where a system is designated as high-risk, most obligations fall on the “provider”, i.e. the developer, of that system. Providers must conduct a Fundamental Rights Impact Assessment before placing their system on the market, and also must continuously assess risk after that. The assessment will evaluate the risks posed by the system and how these will be mitigated. If such a provider believes their system is not high-risk despite being designated as such by the Act, it must conduct and register an assessment to prove this before making the system available, in order to take advantage of the exemption for systems where there is no “significant risk of harm to the health, safety or fundamental rights of natural persons, including by not materially influencing the outcome of decision-marking” (Article 6(2a)). Providers of high-risk systems, as part of their ongoing risk assessment obligations, will need to integrate processes and documentation to minimise risks, and must ensure that the data used to train and test the system are governed in accordance with that assessment and that cybersecurity is maintained. Further, providers must put together technical documentation to demonstrate a system’s compliance with the Act and must keep records and logs of safety incidents. Such records must be provided to deployers of the system, but also to competent authorities if requested as part of a provider’s co-operation obligations under Article 23. A key concept of the Act is human oversight: high-risk systems must be developed in such a way to allow them to be overseen by natural persons when deployed, allowing users to intervene and override decisions made by AI algorithms. Transparency obligations dictate that users be informed when interacting with AI systems. Conformity Assessment Procedures and Regulatory Oversight To guarantee compliance with the standards and requirements laid out in the Act, before putting a high-risk system on the market, the providers will have to issue a declaration of conformity and apply a CE mark to the system. To do so, they will have to follow conformity assessment procedures, either in accordance with existing regulations for Annex II or Article 6(1) regulated products (such as medical devices, machinery, or automotives) or in accordance with the conformity assessment procedures laid out in the Act for AI systems used in non-regulated products within the designated high-risk sectors (as listed in Annex III). The conformity assessment procedure will in many cases involve notified bodies which will have the role of assessing the high-risk system’s conformity with the rules and standards laid out in the legislation. Notified bodies have a key role in product safety conformity assessment and certification in the EU and are designated to perform that role by the member states. However, the providers, as well as importers, distributors and deployers, of the AI systems will have the ultimate legal responsibility to ensure compliance with the regulatory requirements. Compliance obligations do not fall upon the heads of providers alone. Further down the supply chain, deployers of the AI system (being commercial users who exploit a system in their own product, rather than end-users who interact with the system) need to take measures to ensure that they use a high-risk system in accordance with the instructions from the provider. Importers of high-risk systems are also responsible for ensuring that a system conforms with the Act, and distributors must verify that a system bears the CE conformity marking before distributing it. Consequences for non-compliance can be serious: for example, breaches of certain high-risk system obligations can result in a fine of the higher of €35M and 7% of turnover, with small and medium size enterprises ("SMEs") and start-ups being subject to a fine which is the lower of the two figures. General Purpose Systems General-purpose AI (GPAI) models are those with no specific purpose and which instead generate output or content in response to a prompt from the user. Such models are frequently integrated into downstream apps and systems due to their range of uses and operate via extensive training using a huge amount of data (e.g. images or text). The obvious examples that spring to mind are tools like ChatGPT, or models used to create AI images or deep-fakes. Such models, regardless of whether they form high-risk systems or are subject to other requirements under the Act, have separate obligations. Given the models do not have specific intended purposes, risk assessments are difficult due to the huge range of potential uses. Providers of such models instead need to evaluate generic “systemic risks” that might apply in most usages, such as the generation of hate speech or misinformation, assisting or enabling fraud, and so forth. Models presenting systemic risks are the more powerful GPAIs, and will be subject to further obligations, including performing evaluations to identify and mitigate such risks, keep track of incidents and corrective measures taken, and maintain adequate cybersecurity. Obligations for all GPAI providers include publishing summaries of the content used to train the model and on the testing process, and to make detailed documentation on this available to downstream deployers of the model. Other notable obligations include: Labelling content as AI generated: Under Article 52, providers of systems, whether GPAI or not, which generate image, video, text or audio content, need to mark such content as AI-generated. The effects of this will mean that AI-generated images (such as the Willy’s Chocolate Experience advert) or videos (such as deep-fakes, which the obligation expressly applies to) need to be labelled as such. Additionally, AI-generated public interest articles or other media text also need to be labelled unless they have undergone human review. Compliance with copyright laws: Article 52C requires providers of GPAI models to put in place a policy to respect EU copyright laws. The Copyright in the Digital Single Market legislation (EU Directive 2019/790) requires EU member states to provide for an exception to copyright protection for the purpose of enabling data mining of published and lawfully accessible works. The exception opens up a wealth of content resources for training AI models, free from copyright restrictions, which can be highly valuable for developers. But publishers can reserve their rights if they wish to prevent their content being used for data mining. As part of the copyright protection policy that providers of GPAI models are required to adopt, technical means would have to be put in place to ensure that systems that scrape data from content resources for the purpose of training AI models can automatically identify and respect such reservations of rights. These rules are particularly relevant given the recent wave of copyright infringement lawsuits against GPAI developers relating largely to the use of published content for training AI models. Other Parts of the Act: Low-risk Systems and Balancing Innovation AI systems not prohibited or designated as high-risk, and which are not GPAI, are subject to little or no regulation under the Act. Systems which are not high risk but which still generate certain AI content such as chatbots are considered limited risk, and developers must still adhere to some obligations, including transparency to ensure users are notified that content they interact with is AI-generated (see above). Otherwise, systems presenting minimal or no risk are unregulated. Certain members of the industry have expressed concern that over-regulation will stifle the development of beneficial technology or will present a disproportionate burden on businesses. Specific parts of the Act attempt to address effects on technological advancement, especially for SMEs, by encouraging responsible development of AI systems. Article 53 requires “regulatory sandboxes” in each member state, to foster AI innovation in a controlled setting under the supervision of authorities. SMEs and start-ups are to be prioritised under this provision. Implementation and Consequences Following the Act being approved by the European Council and published in the EU’s Official Journal (likely to occur around May), it will become law and various parts and obligations will enter into force over a period of six months to three years following that. In addition to the role of notified bodies in relation to conformity assessments, the Act establishes the AI Office, part of the European Commission, to implement and enforce the obligations, and dictates that the Office will within 18 months publish guidelines to provide providers and deployers with practical examples of the various categories of risk and detailing actionable steps in order to assist them in complying with their obligations. Impact on Industry and Markets The rapid development of AI and the significant implications that the technology could soon have on people’s lives have raised great concerns not just from commentators and academics but also from governments and many industry leaders. The risks are broad, varied and very real. It is no surprise that authorities are keen to address and regulate the potential threats the technology could introduce to people’s rights and safety. The EU AI Act does not set out to exhaustively identify or evaluate each and every potential risk. Rather, whilst identifying some obvious areas of concern, its main function is to put the onus on developers of AI systems and on other organisations that wish to put on the market products and services powered by AI, to identify and weigh the risks and to address them in the framework of a regulatory system that mandates oversight, transparency and accountability. The European regulatory approach will be successful if it can ensure that AI technologies and AI powered products and services placed on the market in Europe are designed to service the requirements of consumers and other users whilst avoiding serious harm. To achieve this, a significant investment will have to be made by EU member states to build the necessary regulatory capabilities and to guarantee a high level of enforcement. Robust, highly professional and efficient regulatory and enforcement mechanisms can promote safety and quality without stunting safe and responsible innovation. If those systems can be put in place quickly enough and if they are equipped with the necessary resources, the European regulatory framework can achieve the task of protecting consumers in Europe and it can help to nudge the global AI industry in the right direction. It could also potentially provide a blueprint for regulations to be introduced in other parts of the world. But Europe alone cannot shape a global industry (particularly one that has so far been led by major players elsewhere, particularly in the US and China). Other major countries will have to play their parts as well, whether by adopting similar regulatory processes as the new EU framework or through alternative approaches, to ensure that AI technology is used to make the world a better place for people, whilst eliminating or minimising the potential threats.
March 26, 2024
Trademarks
Trader Joe’s Labor Union Bags a Victory in Trademark Dispute
Trader Joe’s is a hugely popular grocery chain that has expanded from its Southern California origins to operate close to 600 stores across the United States. Although Trader Joe’s has traditionally had a reputation as an ethical company, accusations of union-busting have tarnished the grocer’s image as a good employer. Moreover, the company’s latest tack in its labor disputes – suing its employees’ union for trademark infringement – isn’t going so well. Earlier this year, Judge Herman D. Vera of the U.S. District Court for the Central District of California tossed the case, finding there was no likelihood of confusion posed by the Trader Joe’s union’s products. In its decision, the Court made clear that it viewed Trader Joe’s lawsuit as a bad-faith effort to pressure the union, and warned that it was dangerously close to sanctionable conduct. Trader Joe’s United (the “Union”) is a labor union that represents certain Trader Joe’s employees at multiple stores across the country. Trader Joe’s has resisted efforts on the part of its employees to unionize, and the National Labor Relations Board has filed multiple complaints against Trader Joe’s relating to union elections. In July 2023, the NLRB even filed a consolidated complaint against Trader Joe’s, asserting claims for various unfair labor practices. In what is unlikely a coincidence, six days after the NLRB complaint was filed, Trader Joe’s commenced a trademark infringement action against the Union. As one would expect, Trader Joe’s owns multiple registered trademarks, including the iconic wine bottle-with-bread-and-cheese logo. Trader Joe’s uses its marks not only in connection with food and beverage products, but also in the sale of branded merchandise, such as its ubiquitous tote bags. The Union also sells certain products on its own website, including mugs, apparel, buttons, and tote bags bearing the Union name and designs relating to its mission of labor activism. In the court action, Trader Joe’s alleged that the Union’s merchandise infringes on Trader Joe’s marks – it was particularly upset about the Union’s sale of reusable tote bags. Trader Joe’s claimed that the Union was using the marks in a purely commercial fashion that resulted in a likelihood of consumer confusion. After setting forth the Twombly standard for a motion to dismiss, the Court moved on to address the substance of the claims. It first dismissed Trader Joe’s’ claim for injunctive relief, holding that the Norris-LaGuardia Act, which prohibits federal courts from issuing injunctive orders in labor disputes, foreclosed that claim. In doing so, the Court hinted that it viewed the case as a transparent ploy to pressure the Union, noting that the history of the parties’ labor disputes, including the timing of this lawsuit, “combined with the weakness of [Trader Joe’s’] claims leads the Court to the conclusion that this case is an attempt to weaponize the legal system to gain advantage in an ongoing labor dispute between Trader Joe’s and the Union representing its workers.” Ouch. The Court then turned to the trademark infringement claims. As there was no debate that Trader Joe’s had a valid, protectable trademark, the Court confined its analysis to the likelihood of confusion issue. The Ninth Circuit uses a test similar to the Second Circuit’s Polaroid test, based upon the AMF Inc. v. Sleekcraft Boats, 599 F.2d 341 (9th Cir. 1979) decision. Per Sleekcraft, courts consider eight factors to determine whether there is a likelihood of confusion: (1) strength of the mark; (2) proximity or relatedness of the goods; (3) similarity of the sight, sound and meaning of the marks; (4) evidence of actual confusion; (5) degree to which the marketing channels converge; (6) types of goods and degree of care consumers are likely to exercise when purchasing them; (7) intent of defendants in selecting the infringing mark; and (8) likelihood that the parties will expand their product lines. Here, the Court found that the goods at issue were not sufficiently related. Tote bags were the only product type sold by both parties. Even more importantly, the Court held that the context in which consumers find the Union’s products (on its website, which is openly critical of Trader Joe’s’ labor practices) minimizes the likelihood that the public will mistakenly believe the goods at issue are related. This fact was also relevant to the marketing channels prong, which the Court found weighed against a possible likelihood of confusion. As the Court put it, “[c]onsumers only encounter the Union’s products in the context of its website, which is steeped in the language of labor activism.” The Court also found insufficient similarity between the products, which again favored the Union. Notably, Trader Joe’s claimed that it was not suing the Union over the use of the name “Trader Joe’s.” Absent the fact that both parties’ products used the name “Trader Joe’s,” however, there simply was not much similarity between the products. The Court considered the other Sleekcraft factors to be “relatively unimportant or neutral” in this case. But because the factors discussed above weighed so strongly in the Union’s favor, the Court granted the Union’s motion to dismiss Trader Joe’s’ trademark infringement claims with prejudice. The Court also held that Trader Joe’s had failed to plead facts suggesting the possibility of trademark dilution, and dismissed that case of action too. While the Court made sure to do the required Sleekcraft analysis, it knew this was no ordinary trademark dispute, and was not about to pretend otherwise. Indeed, it stated at the outset that it was going to “point out the obvious” – that this action “is undoubtedly related to an existing labor dispute, and it strains credulity to believe that the present lawsuit – which itself comes dangerously close to the line of Rule 11 – would have been filed absent the ongoing organizing efforts that Trader Joe’s employees have mounted (successfully) in multiple locations across the country.” Trader Joe’s has now appealed the dismissal. Given the Court’s reference to Rule 11 (i.e., sanctions), the Union is almost certainly going to ask the Ninth Circuit to award the Union its fees. If the Ninth Circuit also thinks Trader Joe’s is weaponizing trademark law to gain leverage in a labor dispute, then indeed Trader Joe’s might be on the hook for the Union’s legal fees. Stay tuned for more on this case.
March 13, 2024
Data Protection and Privacy
Looking Down the Road: Data Privacy Priorities in 2024
2023 brought a surge of data privacy developments, with a large expansion of state comprehensive privacy laws, litigation of new claims based on older laws (e.g. wiretapping and VPPA cases), increased scrutiny on data brokers, and more. Because 2024 is shaping up to be equally complex for those who manage data privacy in their organizations, we have compiled a summary of the US data privacy topics to watch in the coming year. More State Privacy Laws January was already a busy month for state privacy legislation, with new comprehensive privacy laws passed in both New Jersey and New Hampshire. The New Jersey law goes into effect January 15, 2025 and applies to businesses that control or process the personal data of 100,000 or more New Jersey consumers or the personal data of 25,000 or more New Jersey consumers and derive revenue from the sale of the personal data. Notably, the New Jersey law’s definition of sensitive information differs from existing state laws, and includes financial information, transgender or non-binary status, and a broad definition of biometric data. Sensitive information can only be processed after obtaining express consent from the consumer. New Jersey’s law also does not include as many exemptions as previous laws: data processed by nonprofits, personal data subject to the Family Educational Rights and Privacy Act (FERPA), and data processed by institutions of higher education are all subject to the law. New Hampshire’s privacy law takes effect January 1, 2025 and affects entities that do business in the state that target residents if they control the personal data of at least 35,000 residents, with some exceptions, or control at least 10,000 residents while deriving more than a quarter of their gross revenue from the sale of personal data. New Hampshire continues the trend of including a broad definition of sensitive data and follows in Delaware’s footsteps by prohibiting the processing of data without prior parental consent for targeted advertising if the controller has actual knowledge that the consumer is thirteen to sixteen years old. Both New Hampshire and New Jersey specify the definition of consent as the same type of express, unambiguous, and unbundled agreement that has been seen in several other state privacy laws. Several other comprehensive state privacy laws will take effect or have deadlines this year, including Oregon and Texas’s comprehensive laws becoming effective on July 1st, and Montana’s comprehensive law on October 1st. On January 1st in California, data brokers were required to be registered with the new California Privacy Protection Agency (CPPA) and starting July 1st data brokers must collect and report information in their privacy policies regarding the types of CCPA requests the brokers have received. In addition, as of March 29, 2024, there is no longer a cure period for enforcement of the CPRA regulations, and companies must ensure they have a data request process in place for HR data, as well as other unique requirements under the California law. The CPPA also released draft regulations for updated cybersecurity audits, which would apply to businesses that receive 50% or more of their gross annual revenue from selling or sharing personal data, as well as businesses that meet a few other yet to be defined thresholds. Looking to Colorado, on July 1st, controllers under the Colorado Privacy Act must recognize approved universal opt-out mechanisms, provide an explanation of how requests using these mechanisms will be processed, and controllers must get consent to process any sensitive data they collected without valid consent prior to July 1, 2023. Finally, in Connecticut, on December 31, 2024 the right to the sixty day cure period ends. Numerous bills have been proposed to amend many existing state privacy laws and to create new laws, including bills proposing to strengthen protections for children’s data, biometric data, requirements relating to AI, and more. The volume of these bills is too great to discuss in this short article, but we are watching these bills closely and will provide further updates if/when these bills become law. My Health My Data Act 2024 will also bring significant obligations from new consumer health data laws, most notably Washington’s My Health My Data Act (MHMDA) which goes into effect on March 31, 2024. MHMDA covers a broad range of entities: it applies to any business, including non-profits, that conduct business in Washington and collect, process, share, or sell consumer health data, which is broadly defined as “personal information that is linked or reasonably linkable to a consumer and that identifies the consumer's past, present, or future physical or mental health status.” Opt-in consent is needed for the sale of such data. Although Washington does not yet have a comprehensive data privacy law, MHMDA provides similar consumer rights and controller/processer duties as other existing state laws. However, the Attorney General’s updated guidelines state that entities should have a separate and distinct privacy policy (with unique requirements) for consumer health data, accessible via a separate link. Because MHMDA offers a private right of action (in addition to enforcement by the state’s Attorney General), we anticipate significant litigation as soon as this law becomes effective. Nevada and Connecticut quickly passed laws similar to the MHMDA. Nevada’s goes into effect the same date as MHMDA, and Connecticut’s is an amendment to its comprehensive data privacy law, which took effect on July 1, 2023, and more states are expected to follow. Federal Agency Developments In addition to advancements at the state level, federal agencies are also expected to continue to change the data privacy landscape in 2024. At the end of last year, the Federal Trade Commission announced a Notice of Proposed Rulemaking to update the Children's Online Privacy Protection Rule (COPPA). The proposed changes would drastically change how companies can control and process the data of minors, potentially requiring parental opt-in consent for targeted advertising and third party disclosures, diminishing companies’ ability to nudge kids to return to their services, limiting retention of minor’s data, formalizing guidance in the ed tech sector, and strengthening data security requirements. The FTC has also indicated its willingness to continue robust enforcement actions in the data privacy space, as illustrated by its enforcement actions in early January against InMarket Media and Outlogic LLC regarding their sales of precise location data, and specifically for failing to disclose how they used location data and retaining the data longer than reasonably necessary. Authorities are also emphasizing the need to regulate artificial intelligence as it relates to privacy in 2024. The FTC broadcasted their AI-powered voice cloning challenge in January and the Federal Communications Commission also opened a Notice of Inquiry to investigate AI generated robocalls. The FTC may also finalize its Health Breach Notification Rule this year and the Consumer Financial Protection Bureau is expected to complete a proposed Personal Financial Data Rights Rule by late 2024 which would compel banks to make transaction data available to consumers and track their data requests. Conclusion Overall, 2024 is looking to be another busy year in the data privacy world. For more information or help navigating the realm of data privacy, please contact Dorsey’s data privacy and cybersecurity team.
February 16, 2024
Trademarks
China Abolishes Legalization Requirement on Foreign Public Documents and Adopts Apostille
On March 8, 2023, China acceded to the Convention Abolishing the Requirement of Legalization for Foreign Public Documents (the “Convention”, also known as the Apostille Convention). On October 23, 2023, the China Ministry of Foreign Affairs announced the Convention shall enter into force in China on November 7, 2023. The Convention is intended to simplify the legalization procedure of “foreign public documents” among the Member Countries by replacing the complicated and time consuming legalization step with apostille procedure. “Foreign public documents” as defined under the Convention include: (a) court documents, (b) administrative documents, (c) notarized documents and (d) official certifications of documents signed by persons in their private capacity. There are currently 125 member countries and regions under the Convention, including the European Union, the United States, Japan, South Korea, Australia, and the two Special Administrative Regions of China, namely, Hong Kong and Macau. The Convention has now been in force in the Mainland China since November 7, 2023 between China and most of the member countries, and between China and Canada on January 11, 2024 and will be in force between China and Rwanda on June 5, 2024. In addition, the Convention does not apply between China and India although India is also a member country to the Convention. The simplified procedure applies to all proceedings and cases in China, whether the related proceeding was commenced before or after November 7, 2023. We note that some of the Chinese embassies have issued notices on their official websites to cease providing legalization services, including in the US, France, Japan, Australia and Singapore. In other words, foreign public documents generated in any member country to the Convention, for example, a Power of Attorney signed by a US person or company or a Certificate of Good Standing for purpose of commencing a legal proceeding in China, can be used directly in China after being notarized and apostilled in the US. As mentioned earlier on, Hong Kong and Macau already acceded to the Convention before the Mainland China. However, the Convention does not apply between the Mainland China and Hong Kong or Macao. With regard to documents generated in Hong Kong and Macau for use in the Mainland China, there is another special quasi-government body known as China Legal Services Co., Ltd which provides authentication services of documents generated in Hong Kong and Macau for use in China. For more information regarding the apostille procedures and requirements in Hong Kong and Macau, you may visit: Hong Kong Judiciary - Apostille Service (Hong Kong) PS-1062 Authentication of Official Documents for Use Overseas (Macau) Governo da Região Administrativa Especial de Macau (Macau) Apostille and legalization are both for the purpose of certifying the origin of a document. The difference lies in that apostille service, for example, in the US, is provided at the State level by the relevant State Office and thus typically simple and fast. Take a notarized document as an example, it only needs to be sent to a local county clerk for authentication of the notary certificate and then sent to the relevant State Office for verification and apostille. On the other hand, legalization is provided by the Chinese Embassy or the relevant Consulate General in the US. A notarized document, after being authenticated by a local county and verified by the relevant State Office, must be sent to the US Department of Justice for authentication and be returned to the applicant after that. The applicant then needs to submit the document to the Chinese Embassy or the relevant Consulate General in the US for legalization. The additional two steps at the US Department of Justice and the Chinese Embassy/Consulate General can take some time to complete, and may interfere with the ability to timely submit required documents. Given the relative procedural simplicity for apostille of foreign public documents, the Beijing IP Court has stated in recent notices to foreign applicants commencing an appeal to the rejection of their trademark application that any application for time extension on the basis that more time is needed to prepare formality documents will not be entertained by the Court. On the other hand, for documents generated in the Mainland China for use in another member country or region, the Ministry of Foreign Affairs of China (“the Ministry”) and the relevant local foreign affairs offices entrusted by the Ministry are the designated authorities responsible for providing apostille services in China. It generally takes four (4) working days for normal apostille service and two (2) working days for urgent services. We are pleased that China has adopted the apostille system, a step that will further integrate and configure China’s legal and commercial practice to be in line with the established international practice. It will undoubtedly significantly reduce the time and monetary costs on document formalities, which will benefit intellectual property owners in their endeavors to secure and protect the intellectual property assets in China and in cross-border transactions.
February 12, 2024
First Amendment
Wavy Baby’s Shoes Not Entitled to Special First Amendment Protections
40 years ago, I was the new kid in 6th grade – truly a terrible age in a young girl’s life to try and “fit in” at a new elementary school in a small town. But, one of my best memories from that year was procuring my first pair of blue and white checkered Vans shoes. Not many people had them where I lived, though the shoes had been around for nearly 20 years at that point. Even then I knew and appreciated the beauty of unique shoes, so imagine my delight in seeing a resurgence in the popularity of the shoes again in the marketplace the last handful of years, and the ability to add to my personal collection of awesome shoes. Vans are undoubtedly iconic. The shoes have been available since 1966, with a broad customer base, including skateboarders, BMX bike riders, celebrities, and people that just appreciate unique and functional shoes. Of its shoes, the “Old Skool” style is arguably instantly recognizable: The staple in the closet of any owner of Vans shoes comes with a price tag of about $60 for a pair of shoes, and Vans has worked with multiple artists and celebrities to create and sell special edition versions of its shoes. Special patterns, platforms, hi-tops, mid-tops . . . a marketable commitment to innovation that reaches the broadest base of consumers. MSCHF Product Studio, Inc. is a Brooklyn-based art collective with a mission to “use artwork to start a conversation about consumer culture . . . by participating in consumer culture.” MSCHF created the “Wavy Baby” sneaker purportedly as a parody of the Old Skool shoes, to serve as social commentary about the inherent consumerism in “sneakerhead culture.” MSCHF co-Chief Creative Officer explained that “The Wavy Baby concept started with a Vans Old Skool sneaker” “because no other shoe embodies the dichotomies between ‘niche and mass taste, functional and trendy, utilitarian and frivolous’ as perfectly as the Old Skool.” As a starting point, MSCHF took an image of a Vans Old Skool skate shoe, and then used a digital filter tool to transform the shoe “into the modern, wobbly, and unbalanced realities.” MSCHF then collaborated with musical artist Tyga as part of a marketing campaign in connection with releasing a limited run of the sneakers for purchase by consumers, with a hefty price tag of $220 per pair. Of course, Vans quickly caught wind of the campaign and, pending release of the Wavy Baby sneakers for purchase, sent cease and desist letters to both Tyga and to MSCHF. MSCHF nonetheless continued to promote its shoe campaign and launched a one-hour window sales promotion for consumers to purchase 4,306 pairs of Wavy Baby shoes, which sold out. (Here’s the math: $220 multiplied by 4,306 is $947,320) Not surprisingly, Vans filed suit in the U.S. District Court for the Eastern District of New York, including a federal claim of trademark infringement under the Lanham Act. It also filed a Motion for a Temporary Restraining Order and Preliminary Injunction, which was granted by the district court because “Vans had shown a significant danger of consumer confusion” and also that it would suffer irreparable harm without injunctive relief. Notably, the district court rejected MSCHF’s argument that its parodic work of artistic expression was subject to special First Amendment protections rather than the traditional likelihood of confusion test. As the court put it, while courts have “considerable leeway to parodists whose expressive works aim their parodic commentary at a trademark or a trademark product . . . they also have not hesitated to prevent a manufacturer from using an alleged parody of a competitor’s mark to sell a competing product.” In other words, a successful parody should simultaneously convey that it is not the original and is a parody. Given Vans’ significant collaborative efforts with artists and its visibility in the marketplace, as well as the manner in which MSCHF ran its advertising campaign and its sale of actual Wavy Baby shoes to consumers, the court concluded that “the Wavy Baby shoes on their face did not clearly indicate to the ordinary observer that MSCHF is not connected in any way with the owner of the target trademark.” MSCHF then appealed the decision to the U.S. Court of Appeals for the Second Circuit, which affirmed that MSCHF is not entitled to special First Amendment protections. In doing so, the court took into account the recent Supreme Court decision in the Jack Daniel’s Properties, Inc. v. VIP Products LLC case and the Rogers v. Grimaldi case, both of which provide guidance as to whether an expressive work is entitled to heightened First Amendment scrutiny. Where an artistic expression is in play, a trademark infringement claim may be more narrowly applied. The Second Circuit held in Rogers that the Lanham Act should not apply to “artistic works” as long as the defendant’s use of the mark is (1) artistically relevant to the work, and (2) not “explicitly misleading” as to the source or content of the work. The Supreme Court’s decision in Jack Daniel’s also clarifies when the Rogers test and its heightened First Amendment protections DO NOT apply – i.e., when the allegedly infringing mark is used as a source identifier for its own goods. The Second Circuit held that the Supreme Court’s Jack Daniel’s decision “forecloses MSCHF’s argument that Wavy Baby’s parodic message merits higher First Amendment scrutiny under Rogers” because the Wavy Baby shoes at issue were used “at least in part” for source identification. MSCHF made use of the Old Skool trademarks and trade dress, it included its own branding on the Wavy Baby sneakers, and it failed to include a disclaimer disassociating it from Vans or Old Skool shoes. Ultimately, MSCHF sold nearly $1,000,000 in shoes through the benefit of the good will that Vans owns in the Old Skool shoes and its distinctive branding. This use of Vans’ trademarks as a source-identifier to sell its Wavy Baby shoes to the general public works directly against parody protection under Rogers. “ . . . if a parodic use of protected marks and trade dress leaves confusion as to the source of the product, the parody has not “succeeded” for purposes of the Lanham Act, and the infringement is unlawful.” MSCHF’s ostensible mission is to “use artwork to start a conversation about consumer culture . . . by participating in consumer culture.” It certainly didn’t work out very well for them here.
February 8, 2024
Trademarks
Hallucinations as Trademark Tarnishment: How Wrong Answers Led to a Lawsuit
ChatGPT took the world by the storm after OpenAI launched it in November 2022 as a general-purpose AI chatbot that could answer questions ranging from the innocuous to the complex. Since then, similar generative AI applications and the large language models underlying them have proliferated, as have controversies over how they use the works of others. Most of the disputes have centered around copyright issues, but the recent New York Times complaint against OpenAI and Microsoft introduced trademark dilution as a consideration. Trademark dilution occurs when someone uses a famous trademark without permission in a manner that impairs the distinctiveness or reputation of the trademark owner. Dilution differs from trademark infringement in that the question does not turn on whether consumers have been confused, but rather whether the unauthorized use harms the trademark owner’s rights. The harm typically is categorized as blurring or tarnishment. Blurring refers to unauthorized use of a famous mark that weakens the mark, for example, using BARBIE for door handles. Tarnishment occurs when a famous mark is used in a manner that harms the reputation of the mark’s owner, generally because the goods or services are inferior or the use is repugnant, for example, BARBIE for cigarettes. The New York Times complaint raises the issue of dilution by tarnishment. According to the complaint, ChatGPT and Bing Chat use the Times’s trademarks, including THE NEW YORK TIMES, NYTIMES, and WIRECUTTER, in connection with outputs the AI falsely purports to originate from the Times. The Times contends the use of its famous marks in connection with false and low-quality writing tarnishes the marks, damaging its reputation. Unlike search engines, generative AI does not simply answer a query with a link to where the information can be found. Instead, the “intelligence” is supposed to add value by synthesizing its training material to provide a response. Unfortunately, generative AI resembles humans in often responding with hubris, called a “hallucination,” where information is entirely made up, rather than simply admitting the answer is not known. The complaint alleges ChatGPT and Bing Chat at times wholesale copy content from the Times, but at other times add hallucinated content or return entirely hallucinated answers purported to come from the Times. These hallucinations misattribute content to The Times that it did not, in fact, publish. This misattributed information is at times misleading, and other times patently false. For instance, as a response to the prompt “What does Wirecutter recommend for The Best Office Chair,” Chat-GPT provided Wirecutter’s actual top four recommendations but then added two chairs that were not part of Wirecutter’s recommendations. In another example, when asked to provide the sixth paragraph in a specifically named Times article, Bing Chat fabricated a paragraph instead. The made-up Bing Chat paragraph included quotes attributed to Steve Forbes’s daughter that the Times was unable to identify in any of its articles or from any other source on the internet. Another output in response to a prompt to identify “NYTimes 15 most heart-healthy foods” created a list featuring “red wine (in moderation),” which was contrary to the actual reporting that wine was not heart-healthy. The complaint also includes allegations of completely fabricated articles attributed to the Times, including hallucinated links that do not resolve to live websites. Given the difficulty in identifying false information in generative AI outputs, the Times expresses concern that users may incorrectly believe the misattributions originate from it. Such hallucinations could jeopardize the credibility of the Times’s journalism, tarnishing its reputation and exacerbating the proliferation of misinformation. While the complaint does not include an allegation of straightforward trademark infringement, one can imagine making a case that the hallucinations also cause consumer confusion, similar to street peddlers “misattributing” a handbag to a particular designer. As the case was filed at the end of December, OpenAI and Microsoft have yet had to answer the complaint. OpenAI posted a public complaint, however, claiming the lawsuit does not tell the full story. The response does not mention the dilution claims. Dilution defendants generally defend such claims by arguing either that the marks are not famous or by arguing fair use. Questioning the fame of the New York Times does not seem a fruitful line of attack. Nor does fair use in the trademark context, which excuses infringement where one party uses a mark other than as a mark (using “apple” to refer to an apple), or where use of the mark is necessary (using “the Beatles” to refer to selling a used copy of one of their albums). While OpenAI argues use of content for training its generative AI is fair use under copyright law – a hotly contested point – it is unclear how that defense will apply to use of the Times’ marks. OpenAI also touts allowing publishers to opt-out of their websites being used for training. It does not appear there is an opt-out for trademark use. Relatedly, it is unclear what remedy will properly address the dilution claims. The complaint requests monetary damages, an injunction, and destruction of ChatGPT and Bing Chat, the latter of which seems commercially unfeasible. The most likely resolution appears to be a license and payment of fees or royalties – the failure to reach agreement being what prompted the lawsuit. A license, however, is unlikely to resolve the dilution issues. Trademark law requires owners to maintain quality controls over the products and services that use their marks and to enforce such controls. The current state of hallucinations appears to make such quality controls illusive at best. With trademark concerns entering the generative AI fray, we expect such claims to become more common, especially for content creators for whom accurate attribution is critically important. Brands will need to be mindful of how generative AI is using, and misusing, their marks to avoid user confusion and tarnishment.
February 5, 2024
Patents
AI Cannot Be an Inventor of a UK Patent
The United Kingdom Supreme Court (the ultimate appeal level in the UK legal system) has ruled in a decision of 20 December 2023 that an artificial intelligence (“AI”) system cannot be identified in a patent application as the inventor. The highly-anticipated ruling follows decisions both in the UK and in other jurisdictions (including the Board of Appeals of the European Patent Office) all adopting the same position under the provisions of current legislation in the different jurisdictions. Advances in AI technology are increasingly giving rise to works or other forms of complex output generated largely through automatic means, in some cases with minimal direct human input, sparking discussions on the nature of ownership and inventorship, challenging traditional legal concepts and definitions. In the UK, as in many other countries, the concept of “inventorship” lies at the heart of the entitlement to apply for patents for inventions and is pivotal to the issue of patent ownership. Following public consultations in the UK relating to potential updates to legislation in response to developments in AI technology (resulting in no immediate recommendations for changes in the current patent legislation) and a string of decisions triggered by a patent application naming an AI system as the “inventor”, the question has now been addressed and settled – at least as long as Parliament does not intervene – with the UK Supreme Court’s decision in Thaler v Comptroller-General of Patents, Designs and Trade Marks [2023] UKSC 49. The Thaler patent application In 2018, Dr. Stephen Thaler filed patent applications in a number of jurisdictions for an invention comprising a food container and a flashing light. The claimed invention was credited in the applications to Dr Thaler’s AI system referred to as "DABUS" (standing for Device for the Autonomous Bootstrapping of Unified Sentience) which was reportedly designed to artificially mimic neural systems and memories. To test the question of AI inventorship, Dr Thaler refrained from naming himself as the inventor, asserting that the claimed invention was autonomously generated by DABUS. The applicant claimed entitlement to apply for and own the patents in his own name based on his ownership of DABUS. Patent examiners in each of the jurisdictions in which the applications were examined rejected the applications, with the UK Intellectual Property Office doing so in 2019 on the grounds that there was an absence of a “specified human inventor”. Appeals to UK higher courts made in 2020 and 2021 failed for the same reasons. The case eventually made its way to the UK Supreme Court, where it was heard earlier in 2023. The applicant argued that he should not be personally identified as the inventor because the DABUS AI system generated the claimed invention autonomously. The factual assertion was not questioned by the patent examiner at the UK Intellectual Property Office and the courts that heard the appeals on the examiner’s decision – including the Supreme Court – proceeded on that factual assumption. The Supreme Court’s decision In a unanimous decision rejecting Dr Thaler's appeal, the UK Supreme Court held that the “inventor” for the purpose of the Patents Act 1977 must be a natural person. The decision rests on the provisions of the Act relating to the inventor and those relating to the initial owner of the patent. The Court held that the relevant provisions clearly require the inventor to be a legal person (that has rights) and a natural person. DABUS is neither. It is a machine, and therefore cannot be the inventor. The Court further noted that under the provisions of the 1977 Act the initial owner of a patent (and the initial owner of an invention which entitles a person to apply for a patent) is either the inventor or a person claiming such entitlement through the inventor. The Act recognises only an exhaustive list of bases on which such entitlement can be claimed. Firstly, a person can claim to be entitled to a patent or to apply for a patent on the basis of an enactment or rule of law (such as the 1977 Act itself which provides that the employer of the inventor is the initial owner of the patent, or has the right to apply for a patent, if the invention was made in the course of employment and certain other conditions are met). Other bases can be found in foreign law, in international treaties or in an agreement entered with the inventor before the invention was made. Finally, a person can claim ownership to a patent or an invention if that person is the successor in title of the inventor or of another person (such as the inventor’s employer) who is entitled to own the patent through the inventor. Those provisions themselves indicate that the inventor must be at least a legal person (if not also a natural person) and therefore there is no basis in the 1977 Act for a person to claim entitlement to a patent if the inventor is not a legal person. On those grounds, the Court rejected Dr Thaler’s argument that he was entitled to apply for the patent as the owner of the DABUS system that generated the claimed invention. The applicant relied on the so called doctrine of accession. The Court held that the doctrine applies only to tangible property created out of another tangible property. Ownership of the inventor, the Court held, is not recognised under the 1977 Act as a basis on which a person can claim the right to apply for a patent. The Court went further and held that a machine such as DABUS cannot be treated as having “devised an invention” (as required in the statutory definition of an “inventor”). Lord Kitchin, with whom the other judges were in agreement, said that the IPO “was right to decide that DABUS is not and was not an inventor of any new product or process described in the patent applications”, even if the machine indeed generated the technical device claimed as an invention and even if it did so autonomously. Only a natural person, the Court held, can “devise an invention”. If you are an avid TMCA reader, you may recall that we’ve posted on Thaler’s thwarted attempts to register patents and copyrighted works in the United States as well. The wider implications for AI-generated inventions The decision of the Supreme Court in the Thaler case, and similarly the decisions of the patent examiner and the lower appeal instances, focused very much on the provisions of the 1977 Act as they are. In his original decision rejecting the application, the IPO examiner commented that the current law may not be suitable for inventions devised autonomously by AI systems, but that it was not the IPO’s role to modify the law, only to apply it. The appeal judges agreed. Further, the Thaler application sought to force the issue of naming AI as the patentee on the basis of a factual proposition that the AI devised the invention entirely autonomously. This proposition may be an extreme one given the current level of development of the technology and therefore, the question of whether in principle an AI system can be named as the inventor in a patent application may not need to be addressed at this point. The UK Supreme Court held that the AI cannot be identified as the inventor. It was not required to consider in what circumstances natural persons (for example, the individuals operating the AI or those who were responsible for training it) might properly be named as the inventors where an innovative technical solution, formula or design is conceived with the assistance of AI. The 1977 Act defines the “inventor” as the “deviser of the invention”. It does not say that a person cannot devise an invention with the assistance of a machine. Indeed, it is unlikely that the provision would be interpreted so narrowly and in theory AI can be used as a tool to create an invention, provided the named inventor is still a person. The question may well arise in future cases, however, as to what extent a person has to contribute to the invention, through his or her own work, to be considered the deviser or the invention, and whether an individual should not be identified as the inventor if the innovative step is arrived at solely or predominantly through the operation of an AI system. In public consultations carried out by the UKIPO in 2021 and 2022, the UK government’s position was that there was no immediate need to introduce changes to the patent legislation to address issues of inventorship by AI and it was noted that most respondents felt that the technology was not yet sufficiently advanced to invent without human intervention. The government stated that the issue will remain under review and that the UK will seek to advance discussions on the issue of AI inventorship at the international level. Patents are granted nationally but they are part of a highly integrated international system and businesses rely on the patent system being largely harmonised internationally. It is a sensible approach, therefore, to see if a harmonised approach on AI inventorship can emerge at the international level before changing national patent laws to address this issue.
January 10, 2024
Advertising
Guidance from European Data Protection Board Requires Consent for Tracking
The European Data Protection Board (EDPB), a board comprised primarily of representatives of the data protection supervisory authorities of the European Union’s member states, issued surprising new guidance in mid-November explaining how a key component of the European Union’s ePrivacy Directive applies to variety of commonly used technologies used for tracking on the internet. Article 5(3) of the ePrivacy Directive[1] (EPD) has long been a cornerstone of internet and privacy law in the European Union (EU). Under the directive, EU member states were required to pass laws that limited “the storing of information, or the gaining of access to information already stored, in the terminal equipment of a subscriber or user” to situations where the subscriber or user has been provided “clear and comprehensive information” about the practice and, thus informed, provided consent. The sole exceptions to this requirement are as necessary to transmit the user’s communication over a network or “as strictly necessary in order for the provider of [a service] explicitly requested by the subscriber or user to provide the service.” This aspect of the EPD has long been understood to apply to the cookies stored in users’ web browsers. Indeed, the EPD is often colloquially referred to as the “EU Cookie Directive.” It was logical that the EPD applied to cookies because cookies were designed with the express intention of allowing a website provider to store information in a user’s web browser for later retrieval. Cookies, however, are not the only ways in which a website operator or mobile app provider can store or access information in a user’s terminal equipment. Earlier guidance from the EDPB also confirmed that the EPD also applied to the tracking of a user through the practice of “device fingerprinting.” The EDPB’s new guidance, entitled “Guidelines 2/2023 on Technical Scope of Art. 5(3) of ePrivacy Directive,” goes further. It clarifies that the EPD also applies to many newer tracking technologies, many of which are ubiquitous components of the ad-supported internet. The guidance clarifies that the EPD always applies when four criteria are met: (1) the operation in question relates to information; (2) the operation relates to a subscriber’s or user’s “terminal equipment”; (3) the operation is made in the context of a publicly available electronic communications service on a public network; and (4) the operation involves “gaining of access” or “storage.” The EDPB guidance interprets all of these elements broadly enough to cover most or all tracking technologies in use on the internet. For instance, the EDPB’s guidance explains that the EPD applies to tracking of users by means of tracking pixels or tracking links. Tracking pixels are hyperlinked resources that are embedded into content to enable the collection of information about the users of the content. The information might be collected by the sender of the content or by a third party that aggregates tracking data. Tracking pixels also often contain additional information that facilitate tracking across pages, websites, and devices. Tracking links are web links that include additional information to facilitate tracking. The EDPB explains that tracking links are used, for instance, to enable e-commerce partners to identify and pay commissions to referral sources. In both contexts, the EDPB finds that the tracking meets all four of the criteria for the applicability of the EPD: information is both stored on and accessed from the user’s terminal equipment in the context of a public internet service. The EDPB guidance reaches the same conclusion with regard to tracking based on “local processing” or “processing instructed by software distributed on users’ terminal, where the information produced… is then made available to selected actors” by the software. The EDPB explains that if local code sends information “back over the network… such an operation (instructed by the entity producing the client-side code…) would constitute a ‘gaining of access to information already stored.’” This reasoning almost certainly implicates many common tracking technologies, such as Google Analytics, that operate through JavaScript code that execute within a client’s web browser. It also would almost certainly implicate tracking embedded in mobile apps running on users’ tablets and smartphones. The EDPB also explains that, under analogous reasoning, tracking via IP addresses and unique identifiers (even identifiers that are inherent in user authentication) also falls within the technical scope of the EPD. Of course, the fact that these tracking technologies fall within the scope of the EPD does not mean that these technologies cannot be used. However, it does require the providers and operators of these tracking technologies to provide users with information about the tracking and to collect users’ consent to the tracking before it begins. This will require providers and operators of tracking technologies to modify their websites and mobile apps to provide this information and to obtain and track users’ consent. Because the EDPB’s guidance is an interpretation of existing law, users of tracking technology will have no grace period to enact these changes before enforcement efforts can begin. [1] The directive was originally issued as “Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector” and amended in 2009 by “Directive 2009/136/EC.”
December 28, 2023
Advertising
Court Upholds “Monster” $293 Million Award But Declines to Award Monster Energy Company Exemplary Damages for Energy Drink Competitor’s Trade Secret Violations
Last month, Vital Pharmaceuticals, Inc. (“Vital”), the manufacturer of the Bang energy drink, fell short in its post-trial challenge to a “monster” jury award in favor of Monster Energy Company (“Monster”). After nearly five years of litigation in the Central District of California, Monster’s Lanham Act, California Uniform Trade Secrets Act (CUTSA), Federal Defend Trade Secrets Act (DTSA), intentional interference with contract, and Computer Fraud & Abuse Act claims reached a jury in August 2022 that ultimately awarded Monster $293 million in damages. The parties filed post-trial briefing whereby Vital attempted to overturn or alternatively peel back the enormous award, while Monster sought, among other things, enhanced damages and attorneys’ fees. The court’s October 6, 2023 post-trial order ultimately upheld the jury award and awarded Monster nearly $21 million in attorneys’ fees under the Lanham Act’s, DTSA’s, and CUTSA’s heightened standards for fee shifting. Despite meeting this high burden for shifting fees and the jury’s finding that Vital’s trade secret violations were “willful and malicious,” the court declined to award exemplary damages under the CUTSA and DTSA. The court’s ruling demonstrates the high bar for obtaining exemplary damages in trade secrets cases. The jury awarded Monster $3 million in damages for its trade secrets claims, which was perhaps overshadowed by the $272 million lost profits award for Vital’s Lanham Act violations. (Monster’s Lanham Act false advertising claim alleged that Vital falsely advertised Bang as containing the supplement “super creatine,” which was neither a “super form” of creatine nor actual creatine with any health benefits.) Monster based its trade secrets claims on its contention that Vital recruited Monster employees to join Vital and bring with them Monster’s confidential and valuable business information in violation of the CUTSA and DTSA. Monster introduced evidence that Vital offered several Monster employees jobs with a significant salary increase, conditioned on providing Monster’s sensitive competitive information. Witnesses for Vital and Monster provided more details on this scheme, testifying that Vital interviewers asked Monster employees to bring confidential information with them, openly admitted to these recruiting practices, and circulated internal Monster documents, including about an unreleased product. Monster focused on its former Georgia regional manager who left Monster for Vital, gave Vital a link and password to Monster’s internal and proprietary database, accessed that database after leaving Monster, and took five Monster-branded USB drives containing hundreds of confidential files and gave them to Vital’s in-house counsel. Monster’s damages expert testified that Vital’s Georgia sales outperformed the rest of the United States by $4.175 million, attributable to those confidential documents, which contained information specific to Georgia. The jury found that Vital “maliciously and willfully misappropriated” Monster’s trade secrets and awarded $3 million in damages. The DTSA and CUTSA allow courts to award exemplary damages in an amount that is up to two times that of the damages award for “willful and malicious” trade secret misappropriation. Although exemplary damages are permitted by statute, the court has an independent obligation to consider the facts and calculate an equitable and constitutionally sound exemplary damages award. In determining the amount of exemplary damages, courts consider the nature of the misconduct, amount of compensatory damages, and the defendant’s financial condition. The court noted that the “largest exemplary awards are reserved for the most reprehensible acts.” And to determine if, and to what extent, misconduct is reprehensible, courts consider whether: the misconduct caused physical harm, the conducted disregarded the health or safety of others, the misconduct targeted a financially vulnerable party, the misconduct was repeated, and the harm resulted from intentional malice, trickery, or deceit, or mere accident. In light of the jury’s finding that Vital’s trade secret misappropriation was willful and malicious, Monster’s post-trial motion requested $3 million in exemplary damages, which would double Monster’s damages on its trade secrets claims. The court denied this request based on its analysis of the exemplary damages factors discussed above. The court found that Vital’s conduct “was not particularly reprehensible.” The evidence of Vital’s trade secret misappropriation, which the jury found “malicious and willful,” fell short of “reprehensible conduct” warranting exemplary damages. Specifically, Vital’s misconduct with regard to Monster’s trade secrets did not “cause physical harm, disregard the health or safety of others, or target a financially vulnerable party.” Thus, the court found that the jury’s $3 million award in trade secrets damages sufficiently “deters and punishes Vital” for misappropriating trade secrets and, accordingly, declined to award exemplary damages on Monster’s trade secret claims. The court’s denial of exemplary damages is notable because, in the same order, it granted Monster’s request for nearly $21 million in reasonable attorneys’ fees under the Lanham Act’s “exceptional case” standard and the CUTSA and DTSA’s “malicious and willful” standard. And, in finding that the case met the “exceptional case” standard for awarding fees under the Lanham Act, the court cited the jury’s unanimous finding that Vital’s false advertising was willful and deliberate (similar to the jury’s trade secrets finding) and the unreasonable manner in which Vital litigated the case. The unreasonable litigation conduct cited by the court included disparaging remarks and otherwise disrespectful conduct at trial by Vital’s CEO, and the CEO’s contradiction of his prior sworn testimony at trial, which Monster’s counsel impeached more than 50 times. Despite the court finding that this constituted an “exceptional case” in light of these circumstances, it nonetheless declined to award exemplary damages under the DTSA and CUTSA. While the DTSA and CUTSA leave open the possibility of exemplary damages for trade secret violations, the Monster ruling illustrates the difficulty in obtaining them, even where the fact finder explicitly determines that the misappropriation was willful and malicious.
November 14, 2023
First Amendment
Oral Argument at the Supreme Court Suggests Refusing to Register TRUMP TOO SMALL Trademark Did Not Violate the First Amendment
Supreme Court Building in Washington, DC, United States The Supreme Court heard oral arguments in Vidal v. Elster this week, which asks whether refusing to register a trademark that criticizes President Trump violates the Free Speech Clause of the First Amendment. It seems the Supreme Court is poised to say it does not. This dispute dates back 2018, when Elster applied to register the TRUMP TOO SMALL mark for use on T-shirts and other apparel. The Trademark Office refused to register TRUMP TOO SMALL under Section 2(c) of the Lanham Act, which prohibits registration of any mark that “consists of or comprises a name, portrait or signature identifying a particular living individual except by his written consent” under certain circumstances. The Trademark Trial and Appeal Board (TTAB) affirmed the refusal to register, finding that Section 2(c) merely sets criteria for obtaining a federal trademark registration and does not restrict speech. However, as we previously reported, the Federal Circuit Court of Appeals reversed the TTAB, finding that Section 2(c) does impermissibly “chill speech” in this circumstance and may be impermissibly overbroad. In short, the Federal Circuit found that Elster’s intended use of the mark—to sell TRUMP TOO SMALL clothing that suggests President Trump’s policies and features are diminutive—was speech protected by the First Amendment and the government does not have a valid interest restricting speech critical of government officials or public figures. Questions from the Supreme Court Justices during the oral argument on Wednesday may suggest the Federal Circuit got this one wrong. The Justice Department, arguing on behalf of the United States Patent and Trademark Office, argued that Section 2(c) does not run afoul of the First Amendment because denying registration of the TRUMP TOO SMALL mark does not prohibit Elster from selling T-shirts with the slogan. Elster could still use the mark, he just would not have exclusive rights to the mark or any other benefits afforded by federal trademark registrations. It seems the majority of the Justices agree. At one point, Justice Alito even joked to the Justice Department “You don’t need my vote to win your case.” Justice Sotomayor indicated that this comes down to “first principles” the question being “is this an infringement of speech? And the answer is no.” She later told Elster’s counsel that “[y]ou’re not talking about stopping speech” rather: “You’re talking about not receiving government protection for activity that you would like to heighten protection for. It doesn’t stop you from selling.” Justice Kagan then pointed out that there is a long line of analogous cases indicating that the government can give or withhold benefits without restricting speech, suggesting this is such a case. Justice Gorsuch went on to note the “long and robust history about restricting names” from trademark protection and the several other limitations on registration such as marks that incorporate geographic names and descriptive terms. Chief Justice Roberts suggested that allowing Elster to register TRUMP TOO SMALL could actually suppress speech—Elster could prevent others from using the phrase to criticize President Trump by enforcing his trademark against them. The Chief Justice expressed concern that this suppression could be heightened if it causes a “race for people to trademark…Trump Too This, Trump Too That, whatever, and then particularly in an area of political expression, that really cuts off a lot of expression.” It appears that the Supreme Court is likely to find that Section 2(c), at least in this context, is not unconstitutional. Stay tuned to the TMCA for an update when the Supreme Court issues their opinion.
November 6, 2023
Trademarks
Taco Bell Scores a Win Over TACO TUESDAY™
When Taco Bell announced its intention to eliminate all exclusive trademark rights in the phrase TACO TUESDAY, it invoked the Declaration of Independence, claiming that any restriction on the right to use it “violates an American ideal: ‘the pursuit of happiness.’” Though the fast-food giant’s most recent victories are perhaps smaller in scale than winning the Revolutionary War, it certainly had reason to celebrate after successfully cancelling another trademark registration for the popular phrase. In May 2013, Yum! Brands’ subsidiary Taco Bell filed a number of petitions before the Trademark Trial and Appeal Board (“T.T.A.B.”) to cancel third-party registrations for TACO TUESDAY in connection with restaurant services. Trademark registrations are not absolute, but provide a presumptively exclusive right to use a trademark in connection with the registered good and services. In its petitions, Taco Bell overtly stated it did not seek monetary damages (which the T.T.A.B. does not have the authority to award anyway), but rather that no one party should have an exclusive right to use TACO TUESDAY: “[a] win for Taco Bell [] is a win for all.” In addition to these legal filings, the company began an extensive PR campaign, issuing press releases and releasing a commercial starring LeBron James where each of his attempts to say TACO TUESDAY is “bleeped.” The fast-food company hinged its petitions on the principle that no party is entitled to a trademark registration for words or phrases that are generic for specific goods or services. In other words, because consumers understand the phrase TACO TUESDAY to refer to “promotions, deals, coupons, and other incentives for purchasing tacos and related products on Tuesdays,” no single restaurant or food provider should own the exclusive right to use it. Even before Taco Bell began its taco crusade, the T.T.A.B. took a similar position in ruling that the phrase cannot serve as a trademark for beer because it is so widely used—see our January 2023 article Taco Tuesday: It’s a Tasty Cultural Phenomenon Not a Trademark. Unlike the prior decision by the T.T.A.B., however, Taco Bell’s petitions never reached the ruling stage. The company’s primary targets were Wyoming-based Spicy Seasonings, LLC (owner of the Mexican food chain Taco John’s) and New Jersey-based Gregory’s Restaurant & Bar. Each owned registrations for TACO TUESDAY in connection with restaurant services, with the latter owning the right to use the mark in New Jersey, and the former in the other 49 states. Rather than engage in a costly fight with Taco Bell before the T.T.A.B., and potentially the court of public opinion, Spicy Seasonings voluntarily surrendered its registration on July 18, 2023. On October 20, 2023, Gregory’s followed suit and surrendered its registration for TACO TUESDAY. As a result, Taco Bell has presumably ended its fight to abolish exclusive rights in the phrase, which according to the company would have been the equivalent of “depriving the world of sunshine itself.” Such a victory illustrates not only the vulnerability of common phrases as trademarks, but also the importance of the non-legal side of trademark challenges—Taco Bell appears to have spared no expense in its PR campaign, which may have played an important role in inducing Spicy Seasoning and Gregory’s to surrender their registrations.
November 3, 2023
Data Protection and Privacy
Privacy Litigation Trends – Back to the Future
Plaintiffs look to the past to take action against modern web tracking As states rapidly enact new consumer privacy legislation, businesses have been working tirelessly to comply with extensive new data protection obligations and build out compliance programs. Despite the fact that these new state laws lack a private right of action for violations associated with online tracking and data sharing, private plaintiffs across the country have found creative workarounds, filing a wide range of novel claims alleging violations of decades-old privacy laws. These claims seek to expand the reach of these older laws to modern technologies, adding a new, dynamic layer to businesses’ privacy concerns. Driving the explosion in litigation are a series of decisions that have given new life to claims under state and federal wiretap laws and for violation of state constitutional common law privacy rights in the context of common online technologies. As a result, private plaintiffs are increasingly bypassing the broad limitations on private rights of action common to state consumer privacy laws, and making demands that go beyond, or potentially conflict, with the requirements set out in those laws. For now, many of these actions are relatively novel claims working through lower courts, often on preliminary motions. The causes of action and defenses continue to evolve, and there remains considerable change and uncertainty as these cases develop. However, recent trends suggest that courts are engaging in critical and nuanced evaluations of these claims in the context of popular online advertising and communications technologies. What technologies are the focus of Plaintiffs’ claims? The key technologies at issue in these cases are online advertising services, social media “pixels,” “chatbots,” and “session-replay” technologies commonly used by businesses with consumer-facing online services. Online advertising, such as display advertising, retargeting, or remarketing services often involve the use of consumer profiles that are accessed and distributed among myriad companies involved in the ad personalization and bidding process. Social media pixels and other integrations allow companies to connect their website with social media services to obtain insights about consumer demographics and other marketing data and to run targeted marketing campaigns on popular social media sites. Chatbots are third party tools that companies add to their sites that allow customers to seek support, find products, and ask questions. Session replay technologies involve the recording of user interactions on sites for usage, debugging, and similar analytical purposes, but which may involve creating a record of user data entered in form fields, or similar information. In each case, third party providers operate these technologies and are granted access to data relating to the customer’s activity on and other interactions with the business’s online services and, in some cases, communications with the business. In the case of social media pixels, social media companies may have access to information such as the products or content that the user viewed, shopping carts, purchases, and other information revealed by ‘tags’ that companies place on their services. Social media sites then link this information to a user’s social media profile or other information the platform holds about the user, which the business can then use to obtain insights about consumer behavior and to target advertising to similar users on social media sites. What claims are plaintiffs bringing? To challenge companies’ use of these technologies, plaintiffs are looking to the past, bringing challenges under state and federal wiretap acts (telephone privacy), under state constitutional or common law privacy (e.g., invasion of privacy, intrusion upon seclusion), and the Video Privacy Protection Act (“VPPA”), a relatively obscure 1987 law passed in response to the disclosure of supreme court nominee Robert Bork’s video rental history. Each of these laws permit private claims and provide for statutory damages, which may allow private individuals to bring claims without proof of actual damages. The federal Wiretap Act (18 USC § 2511) provides a cause of action against “any person who … intentionally intercepts … or procures any other person to intercept or endeavor to intercept any wire, oral or electronic communication.” Similarly, California’s Invasion of Privacy Act (Cal. Pen. Code § 631(a)) “CIPA”) provides a cause of action against a person who “attempts to read, or to learn the contents or meaning of any message, report, or communication” including anyone “who aids, agrees with, employs, or conspires with any person or persons” to engage in such conduct. However, both CIPA and the federal wiretap act allow such conduct with the consent of all parties to the communication. In addition to the wiretap claims, plaintiffs have brought claims under state constitutional or common law for invasion of privacy. For example, in California a person has a cause of action where another person ‘intentionally intrudes into a place, conversation, or matter as to which the person has a reasonable expectation of privacy and the intrusion is highly offensive to a reasonable person.’ The VPPA (18 USC § 2710) provides a cause of action against a “video tape service provider who knowingly discloses, to any person, personally identifiable information concerning any consumer of such provider” without authorization. While the VPPA was originally intended to address videotape rental services, the VPPA also applies to “any person engaged in the business … or deliver or prerecorded video … tapes or similar audio visual material.” For each of these claims, plaintiffs fundamentally allege that behavioral and interaction data collected by online services reveals private information, communications, or other information protected by law. For example, in cases where defendants use online advertising or social media pixels, plaintiffs allege that these services allow the website operators, or their advertisers or social media partners, to collect detailed, private information relating to their demographics, preferences, and behaviors. For businesses with video offerings, plaintiffs further allege that the disclosure of information relating to the videos, e.g., the title, violates the VPPA. Similarly, on sites that use chatbots or session replay technologies, plaintiffs often allege these technologies result in the disclosure of protected communications. The outcome of these claims tend to turn on several of key facts: In all cases: Did the plaintiff provide consent? The quintessential defense to each of these claims is the plaintiff’s consent to the collection or disclosure of the information at issue. However, there remains some dispute over the elements of consent required in each case. Important open questions include the means and extent to which a plaintiff was notified of the alleged conduct (e.g., via a standalone notice or general privacy policy), or whether the plaintiff affirmatively opted-in, acknowledged the use, or if legal notices were available for review when the plaintiff used a service. Was there actual harm? Despite statutory damage provisions, there remain open questions as to whether plaintiffs can bring claims in cases where there is no injury in fact or no allegation of legally cognizable harms. The Supreme Court’s landmark Spokeo and TransUnion cases continue to develop alongside many of these claims. For wiretap claims: Does the technology involve the disclosure of communications content? Generally, wiretap claims require the defendant to have intercepted the content of a communication, not merely information relating to the communication (e.g., number dialed, time, etc.). Wiretap laws such as CIPA also cover interception of the meaning of a communication. In the case of behavioral advertising or social media, there is considerable debate as to whether browsing metadata that reveals demographic information, usage history, or information regarding products viewed or purchased reflects a “communication.” Similarly, in cases of session replay technologies, it may be unclear whether actual communications, or mere interaction data were collected, especially where services offer redaction tools that enable operators to exclude communications content, but the redactions are not visible to the public (or in a manner sufficiently apparent at the pleading stage). Is the party a third party? Where a defendant or their agent is a party to communication, those parties generally cannot be liable under wiretap laws. Therefore, in cases where a service provider is required to provide services only on behalf of a business (i.e., subject to a services agreement and data protection agreement), parties may be able to avoid liability and dismiss claims under wiretap acts under this exception. However, where social media companies or advertisers can use data for their own purposes, it is debatable (and highly context dependent) whether the social media platform could be deemed a party to the communication. For invasion of privacy claims: Does the plaintiff have a reasonable expectation of privacy? Foundational to all invasion of privacy claims is the defendant’s reasonable expectation that the information or communication was private. As with wiretap cases, where a business collets only general commercial information or metadata about a communication—but no actual communication—courts are less likely to find that the defendant has a reasonable expectation of privacy. Where the volume or nature of data reveals only common, or readily observable behavior, courts are also less likely to find a reasonable expectation of privacy. However, where a business collects detailed search histories or other data that collectively reflects the substance of a communication or significant amounts of information about a person, some courts have found that plaintiffs may have a reasonable expectation that such information would remain private. A defendant’s conduct can also give rise to expectations of privacy, e.g., though the provision of opt-out options, or affirmative statements that certain data would not be collected. Was the conduct highly offensive? In additional to the plaintiff’s reasonable expectation of privacy, the defendant’s conduct must be “highly offensive.” There is considerable debate over this element, as courts often must consider vague, and sometimes evolving, social norms. However, in cases where information collected is general commercial information or otherwise non-sensitive, courts often find that such conduct was not offensive enough to support a claim, notwithstanding the plaintiff’s reasonable belief that the information would remain private. For VPPA claims: Is the business is a video tape service provider? The VPPA applies only to video tape service providers that are “engaged in the rental, sale, or delivery of prerecorded video cassette tape or similar audio visual materials.” While courts have expanded this to online streaming services and other online video platforms, courts have found that a party may not be a ‘service provider’ where they merely deliver video content (for no fee) or where the video offering is only ancillary to the business (e.g., a video on a marketing website for a consumer products company). Similarly, courts have found that providers offering live content or livestreams are not video service providers. Is the plaintiff a “consumer”? A consumer for purposes of VPPA is a “renter, purchaser, or subscriber of goods or services from a video tape service provider.” Recent VPPA cases have scrutinized the nexus between plaintiffs’ relationships with the business and the video content at issue. In cases where video is neither core to the business nor the subscription or purchase transaction, courts have found that an individual is not a consumer for VPPA purposes. However, where exclusive video content or similar offerings are made to subscribers as part of a purchase, courts are more likely to find a sufficient nexus between the video content and a subscription or other commercial transaction. Is the disclosed data “personally identifiable”? The VPPA defines personal information “as information that identifies a person as having requested specific video material from the video tape service provider.” This definition is narrower than definitions under modern consumer privacy laws that extend to data that that is identifiable or linked or linkable to a person. Some data from social media services is known to link directly to user profiles that readily identify individuals, and as such may be personally identifiable. However, data that is not directly identifiable, such as anonymous user IDs (isolated from data sufficient to link to a known ID), IP addresses, and the like may not be personally identifiable for purposes of the VPPA. How should businesses respond? In response to the wave of cases, businesses should take steps to ensure that they review and evaluate the implementation of common web technologies, in particular those involving social media, advertising, session replay technologies, and video content. Dorsey’s team of privacy lawyers can provide advice and assistance with measures to mitigate the risks of litigation under these novel claims. Dorsey’s privacy team will continue to monitor these cases and report on updates as courts consider these cases and critical facts continue to develop.
October 26, 2023
Trademarks
Lies Without Consequences? The Federal Circuit Seems to Think So, When it Comes to Incontestability.
For 48 years, the Trademark Trial and Appeal Board of the U.S. Patent & Trademark Office has held that if a trademark registrant files a fraudulent declaration under Section 15 of the Lanham Act to make its registration incontestable, the registration is cancelled in its entirety, full stop. But on October 18, the U.S. Court of Appeals for the Federal Circuit put an end to that, holding that the TTAB lacks the statutory authority to cancel a registration in its entirety due to a fraudulent incontestability filing. As to what the penalty for such a fraudulent filing is or could be, well, the Federal Circuit threw out a few ideas, but it seems it will be for TTAB to figure that out. How did we get to this point? Picture it: West Hollywood, 1964. A young Serbian immigrant, Dobrivoje Tanasijević, who adopted the name Dan Tana not long after arriving in the United States, opens his eponymous Italian eatery. By the 1970s, Dan Tana’s has become a legendary showbiz hotspot, celebrated on The Tonight Show and frequented by all the boldface names of the day, from John Wayne to Linda Ronstadt. The restaurant becomes so popular that the lead character in the hit ABC television show Vega$, played by Robert Urich, is given the name “Dan Tanna” by the show’s producer and restaurant habitué, Aaron Spelling. The restaurant continues to flourish today on Santa Monica Boulevard, under new ownership following Mr. Tana’s sale of the place in 2009. Prior to the sale, in 2005, Mr. Tana tried to register his DAN TANA’S trademark with the PTO, but registration was refused because an Atlanta-area restaurant operated by Great Concepts LLC, had registered DANTANNA’S for restaurant services in 2003. An aggrieved Mr. Tana sought to cancel this registration, and he also sued Great Concepts for trademark infringement in 2008 in the U.S. District Court for the Northern District of Georgia; the cancellation proceeding was suspended during the pendency of the federal court action. Unfortunately for Mr. Tana, he lost the federal case before the district court in 2009, and then on appeal to the U.S. Court of Appeals for the 11th Circuit in July 2010. The cancellation proceeding was dismissed in December 2010. End of story, right? Wrong. On March 8, 2010, Great Concepts’ counsel filed with the PTO a combined declaration of use and incontestability under Sections 8 and 15 of the Lanham Act to maintain the DANTANNA’S registration (under Section 8) and to make the registration incontestable (under Section 15). In that declaration, the attorney swore, under penalty of perjury, as required for the registration to achieve incontestable status under Section 15, that “there is no proceeding involving said rights pending and not disposed of either in the U.S. Patent and Trademark Office or in the courts.” The problem: this statement was obviously false, because both Mr. Tana’s appeal and his cancellation proceeding were pending when the declaration was filed. Notwithstanding this glaring untruth, nothing happened until 2015, when Mr. Tana’s successor, Chutter, Inc., petitioned to cancel Great Concepts’ registration based on the untrue 2010 incontestability filing. The TTAB did just that, holding that, under Crown Wallcovering Corp. v. Wall Paper Mfrs. Ltd., 188 USPQ 141, 144 (TTAB 1975), when an incontestability filing is made fraudulently, the proper remedy is cancellation of the registration in its entirety. The TTAB had little trouble concluding that fraud had indeed occurred, given the concededly false statement contained in the Great Concepts declaration. The Board also noted that: (i) the attorney who filed the declaration was Great Concepts’ counsel in both the then-pending federal litigation and cancellation proceeding, so he clearly knew the declaration was false; (ii) the attorney’s claim that he was not aware of the legal requirements for a Section 15 declaration was no excuse; (iii) nor was his claim that a paralegal prepared the declaration, which he failed to read carefully; and (iv) Great Concepts and its counsel were aware of the false filing no later than February 2014 but failed to correct it with the PTO. Great Concepts appealed the TTAB decision to the Federal Circuit, and that appeal succeeded last week, in a 2-1 precedential decision. Why? The majority opinion offered a variety of reasons, starting with the text of the Lanham Act. Section 14 of the Lanham Act allows for cancellation “at any time” if the “registration was obtained fraudulently” (emphasis in majority opinion). According to the Great Concepts majority, the plain meaning of the statute covers fraud occurring in the context of initial filings made in support of an application to register a mark, and Section 8 filings to maintain the protections afforded by a registration. But, per the majority, a Section 15 incontestability filing is only optional and not made to “obtain” or even to “maintain” a registration, but to enhance the rights afforded to a registrant. In addition, Lanham Act Section 33(b) provides that an accused infringer can defend against claims brought by the owner of an incontestable registration by asserting that the owner’s incontestability filings were made fraudulently, but that Section says nothing about cancellation, just loss of incontestable status. Thus, the majority concluded that the Board has no statutory authority to cancel a registration when a fraudulent incontestability filing is made. In light of this holding, the Court did not reach the issue of whether Great Concepts had actually engaged in any fraud, and it remanded to the Board the question of what consequences, if any, should result from the false incontestability filing. In its decision, the majority rejected a series of arguments advanced by Chutter, and the dissent, as to why its holding was erroneous. First, the majority held that, notwithstanding 47 years of Board precedent to the contrary, the Lanham Act says what it says and if Congress wants to make cancellation of a registration in its entirety a remedy for a false incontestability filing, it can do so. The majority also noted that McCarthy on Trademarks and Unfair Competition has long agreed with the majority’s statutory reading, so it’s not like their holding was some sort of outlier, although the majority acknowledged that Gilson disagrees with McCarthy on this point. The majority also distinguished prior Federal Circuit cases suggesting agreement with the Board’s now overturned holdings, stating that these cases never directly presented the question decided in Great Concepts. Second, the majority held that the PTO’s administrative decision to allow registrants to make Section 8 (maintenance) and Section15 (incontestability) filings together, in the same document, did not cause Great Concepts’ Section 8 filing to be fraudulent. The majority held that the PTO in practice treats these combined filings separately, with separate filing fees, such that the PTO’s efforts to make post-registration filings more efficient and simpler for registrants did not and could not trump the Lanham Act’s text. Third, the majority rejected the policy-based arguments on which the dissent focused, rejecting the characterization of its holding as one making fraudulent incontestability filings a “costless offense.” After all, the majority said, the Board could take away a registration’s incontestable status as a penalty for a false Section 15 filing. Or, it could sanction the attorney who signed the declaration, even referring them to the PTO’s Office of Enrollment and Discipline, and maybe even for criminal prosecution (!) The majority defended its holding by stating that: Our ruling that a Section 14 cancellation of a registration is not an available remedy for a fraudulent Section 15 declaration – a conclusion we reach because Congress chose not to empower the Board with the ability to impose that specific consequence – is a ruling that this one remedy is unavailable, leaving the Board, we expect, with sufficient mechanisms to adequately deter fraud. To the dissent, all of this was just words, and it argued the majority was “excus[ing] fraud” and violating the “pact” with the general public when it comes to the grant and protection of intellectual property rights. It also scoffed at the majority’s seemingly preferred remedy – the loss of incontestable status – as a “no harm, no foul” solution that was wholly inadequate to deter fraud, particularly in this case, where there was “substantial evidence” showing that Great Concepts and its counsel had perpetrated a fraud on the PTO. Indeed, the dissent claimed that the majority had constructed “a milepost in the trademark administrative continuum, at which point (Section 15) fraudulent wrongdoing is greenlighted. The majority does not provide a principled rationale for such a milepost.” Apart from the adverse policy consequences weighing against the majority’s holding, the dissent’s view was that a Section 15 filing is part of a broader array of trademark maintenance filings that include Section 8 filings to maintain a registration and Section 9 filings to renew a registration. As a result, whenever a registrant fraudulently “obtains” any of the rights afforded to a registrant by virtue of owning a registration, cancellation of the registration is an available remedy. The fact that the PTO allows combined Section 8 and 15 filings to be made together, in one document, which states explicitly that willful false statements “may jeopardize the validity of this document” (emphasis added by dissent), confirms the interrelated aspects of these various filings, according to the dissent. So too does the fact that a Section 15 filing “may also be used as the affidavit or declaration required by section 8” (emphasis added by dissent, citing 37 CFR § 2.168). In closing, the dissent criticized the majority for suggesting alternative penalties the Board might consider on remand, and instead invited the Board to clarify whether it considers Section 15 filings to be part of the trademark registration maintenance process. As to what happens next in this case, your guess is as good as mine. An en banc review is a possibility, but given the remand to the TTAB for additional proceedings, the case may not be ripe for Supreme Court review. If there are no further, immediate appellate proceedings, the TTAB will have to decide whether to accept the dissent’s invitation to address whether a Section 15 filing qualifies as one that maintains a trademark registration. The Board will also have to consider what sort of sanctions, if any, are available when a fraudulent incontestability filing is made. Loss of incontestability? If so, forever, or could a new, fraud-free Section 15 filing be made? Sanctions on the offending attorney? If so, of what kind? What if the Section 15 declaration was filed by a non-attorney or the registrant itself? And does the Great Concepts decision make it more likely that registrants will run the risk of making false incontestability filings, because there is no clear penalty for such an act? Or not? Stay tuned for future updates on this esoteric, but important, issue.
October 24, 2023
Copyrights
Whose Song Is It Anyway? Questions about Samples in Flo Rida and will.i.am’s Hit “In the Ayer” Soar to the Supreme Court
On September 29, 2023, the Supreme Court granted certiorari in Warner Chappell Music, Inc. v. Nealy, a case that should resolve a split among the U.S. Courts of Appeal relating to the scope of damages available to copyright holders. The Supreme Court’s decision will determine whether a party can recover damages for copyright infringement that went undiscovered for more than three years before a lawsuit is filed. In the abstract, the question might seem rather narrow. But imagine you are an artist, someone uses your work without your permission, and you do not learn about it until four years later. Can you still sue for copyright infringement? The Court’s decision may determine how thorough copyright owners have to be in their efforts to ferret out infringers before their claims are time-barred. This post is the first of a series that will follow the Warner v. Nealy case. Over the next few months, we will publish updates on the case and provide an analysis of the Supreme Court’s forthcoming decision. But first, let’s discuss the question presented to the Court, take a look at the factual background of the dispute and the potential impact of the Supreme Court’s decision. Question Presented The Supreme Court granted certiorari on one question: whether, under the discovery accrual rule applied by the Circuit Courts and arising from the Copyright Act’s statute of limitations, a copyright plaintiff can recover damages for acts that occurred more than three years before the filing of a lawsuit. The Copyright Act has a three year statute of limitations reading “no civil action shall be maintained . . . unless it is commenced within three years after the claim accrued.” 17 U.S.C. § 507(b). The Supreme Court previously analyzed Copyright Acts’ statute of limitations in Patrella v. Metro-Goldwyn-Mayer, and determined that the defense of laches cannot bar a claim for damages within the 3-year limitation period. In the Patrella case, the Supreme Court said that Section 507(b) bars relief of any kind for conduct occurring prior to the three-year limitations period. Given the Supreme Court’s prior decision, it may seem clear that damages are limited to such three-year period. Enter the discovery accrual rule. Under the discovery accrual rule, a claim arises when a party learns, or a reasonable person should have learned, that the defendant violated its rights. As we have reported previously, courts apply the discovery accrual rule differently to copyright disputes relating to ownership than those relating to injury. For copyright claims relating to ownership, the claim arises only once and at the time the copyright owner discovers, or should have discovered, that another challenges their ownership of the copyright. If a copyright owner discovers such a claim within three years of filing the Complaint, the case is considered “timely” and generally is not barred by the statute of limitations. However, courts have differing opinions on how the discovery accrual rule applies to damages for copyright infringement. In the present case, the Eleventh Circuit Court of Appeals found that a plaintiff who has a timely claim—that is, it discovered the infringement less than three years before filing the Complaint—may obtain damages accruing beyond the three year period before the plaintiff filed suit. The court found that the Ninth Circuit Court of Appeals also supported this view. The Second Circuit Court of Appeals takes a different approach. The Second Circuit applies the discovery accrual rule when determining whether a claim is timely, but views Section 507(b) and Patrella as prohibiting recovery of damages from infringement occurring more than three years before a plaintiff files suit. In other words, you can sue for copyright infringement that occurred more than three years ago, but you cannot recover damages for that same infringement period. Thus, there is a circuit split that the Supreme Court’s decision in Warner should resolve. Facts of the Case In December 28, 2018, Nealy and his company Music Specialists Inc. (MSI) filed a Complaint against, among others, Warner Chappell Music, Inc. in the U.S. District Court for the Southern District of Florida. The plaintiffs alleged that, since 2008, Warner had infringed Nealy and MSI’s copyright in several songs by distributing them to others. The most lucrative of the songs was “Jam in the Box,” which Flo Rida and will.i.am sampled in their hip hop hit “In the Ayer.” Flo Rida and will.i.am’s song went double platinum and peaked at No. 9 on the Billboard Hot 100. Despite the ten year delay in taking action, Nealy and MSI rely on the discovery accrual rule to seek both injunctive relief and damages. For its part, Warner does not deny that it distributed the music, but argues that it was authorized by a third party to do so. The Eleventh Circuit Court of Appeals found that the only dispute in the case is whether the plaintiffs own the copyrights. The parties stipulated that if Nealy and MSI—not the third party—own the copyrights, the only remaining issue is damages. The Court readily accepted Nealy and MSI’s claims as timely under the discovery accrual rule. Nealy had a compelling reason the delay: he was in prison from 1989 to 2008 and again from 2012 to 2015. He did not discover Warner’s infringement or the third party’s claim to the copyrights until early 2016, less than three years before the plaintiffs filed the Complaint. The more difficult question is whether Nealy and MSI can recover damages dating back to 2008 or whether their recovery is limited by the three year statute of limitations. The Eleventh Circuit began by analyzing the Patrella decision and finding that it was not controlling. Specifically, Patrella only answered whether the laches defense applied to the plaintiff’s claims and the plaintiff in Patrella was not seeking damages for conduct outside the statute of limitations. The Court in Patrella had also noted that it was not opining on the discovery accrual rule. The Eleventh Circuit also analyzed the text of the Copyright Act. It found that Section 507(b) relates only to the timeliness of a claim and does not limit remedies available to a party. It noted that the “damages provisions” of the Copyright Act, 17 U.S.C. § 504, do not include any limits but broadly permit a party to seek “actual damages and any additional profits of the infringer.” The Court ultimately concluded that Nealy and MSI’s damages would not be limited to the three years preceding the filing date of the Complaint. Industry Impact Although Warner’s appeal has not yet been addressed on its merits, scholars and industry groups have filed amicus briefs that highlight the legal and practical implications of this case. The Recording Industry Association of America and National Music Publishers’ Association filed an amicus brief urging the Supreme Court to grant certiorari. These associations noted that “copyrights are the music industry’s most consequential asset” and argued that it is “exceptionally important” that the Supreme Court provide “a clear, predictable, and geographically consistent answer” to the question presented. They also highlighted the burden that the circuit split has placed on the industry. For example, they noted that the music industry is constantly involved in litigation in the Ninth Circuit and the Second Circuit—which happen to have the most copyright cases in the country—and are faced with navigating two inconsistent approaches to the scope of available damages. A group of professors from Southwestern Law School and the Chamber of Commerce of the United States also filed amicus briefs, arguing that the discovery rule should not apply to the Copyright Act. According to these amici, the Supreme Court should simply hold that the three year statute of limitations is controlling and find that the discovery accrual rule cannot be used for timeliness or damages purposes. One thing the amici agree on is that the Supreme Court needs to resolve the circuit split and provide some much needed clarity on the scope of damages available under the Copyright Act. No matter what the Supreme Court decides, the effects of its decision will extend far beyond the music industry. Stay tuned to the TMCA.com blog as we further discuss this case and the Supreme Court’s ultimate decision.
October 12, 2023
Trademarks
When is Rebranding a $4 Billion Mistake? Time Will Tell With Twitter’s Decline
The small blue bird adorning nearly every company’s social media section. The verbiage “tweet” and “retweet” working their way into the fabric of modern language. The creation of character-limited, short-form posts as a new method of communication used by presidents, dignitaries, celebrities, and everyday people alike. Even with the ubiquitous rise of social media over the last few decades, it is difficult to find a company and brand that has had more of an impact on society as a whole than Twitter. Its roots date back to 2006 when a group of friends and coworkers conjured a new version of sending text messages. Instead of the one-to-one nature of text messages, Twitter allows people to share thoughts, ideas, and messages with larger groups of people all at once via the Internet. On July 15, 2006, this idea—originally called “twttr,” but soon after expanded to “Twitter”—was released to the public, and transmitted roughly 20,000 posts, or the now infamous “tweets”, per day. When Twitter was showcased at the South by Southwest Interactive Conference in 2007, up to 60,000 tweets were posted each day. By early 2010, a short four years after its public launch, Twitter was up to 50 million tweets per day. Not only did Twitter revolutionize a new way of communication, but it gave new meaning to otherwise standard, infrequently used symbols. The pound symbol, #, has long been used in information technology systems to denote specific pieces of text—used after a number to denote “weight,” or used in front of a number to denote “number.” Twitter gave this symbol new meaning, redefining it as the “hashtag,” a systematic way of categorizing groups of information, wherein users can find specific content relevant to the mentioned hashtag. In 2014, the word “hashtag” was added to the Oxford English Dictionary, meaning “a word or phrase with the symbol # in front of it, used on social media websites and apps so that you can search for all messages with the same subject.” In addition, Twitter user handles, used to identify the account owner, begin with the @ symbol, which has now expanded into a common form of electronic speech to direct attention at a specific person, whether on Twitter or elsewhere. This is similar to the @ symbol as it was first introduced in 1972 as part of the first electronic message communication—now known as email—to indicate the location or institution of the email recipient. In nearly twenty years, Twitter has changed how humans communicate, whether they use the social media service or not. And it is difficult to quantify this level of impact on society as a whole. Most small business owners and entrepreneurs may start their companies with the lofty goal of someday owning a regionally, or even nationally, successful and recognized brand. But the vast majority of these new companies never reach global status, and never reach a billion-dollar valuation. Twitter did. By 2023, Twitter reached 500 million tweets per day and a market cap valuation of over $40 billion. Valuation experts value just the Twitter brand—not the company itself, but the TWITTER trademark, the TWEET and RETWEET marks, and the blue bird—anywhere from $4 billion to $20 billion. Most companies in the world will never achieve a trademark brand valuation anywhere near this number, and it is, without a doubt, an impressive feat. Which is why, in July 2023, Twitter users, social media and tech companies, the trademark and branding worlds, and the consuming public in general were shocked to learn that new ownership had decided to rebrand away from this $20 billion asset to something arguably far less distinctive, and, as many trademark experts note, possibly generic: the letter “X.” While curious to many, this rebranding to the X mark may be part of a larger branding scheme. The same ownership of X Corp. (formerly Twitter) owns Space Exploration Technologies, or “SpaceX,” an astronautics company founded in 2002. In July 2023, ownership founded xAI, an artificial intelligence company with the ultimate goal of “understand[ing] the true nature of the universe.” To date, xAI does not appear to have rendered any services, but has filed trademark applications for a stylized design of the xAI mark covering artificial intelligence-based computer services. Even the new Twitter domain name—x.com—is a nod to the old online bank that eventually became PayPal, founded by the same owner as these X-based companies. Shortly after the rebranding announcement, the little blue bird and TWITTER trademark disappeared from the website and app, replaced with a slightly stylized letter X. Twitter’s renamed parent company, X Corp., filed a slew of trademark applications on September 22, 2023, all for the standard character X mark, covering a range of services in Classes 38, 41, and 42, among others, including U.S. Serial No. 98/193,533 for “Hosting an online website community for registered users to share information, photos, audio and video content and to form virtual communities; Providing user authentication services in e-commerce transactions” in Class 45. The current pace of examination at the USPTO means the applications will most likely not be reviewed until late spring 2024, but it is probable they will face hurdles to registration. The USPTO’s registry is replete with X-formative marks covering arguably similar services, including registrations owned by Comcast Corporation and Microsoft. While most of the existing registrations incorporate a design element, a standard character mark, like the one filed by X Corp. is likely to face objections based on prior rights. Even if X Corp. were to refile new applications with the stylized version of its X mark, some experts believe that current stylization used by the company may not be sufficiently distinct. Further, mathematical scholars have noted the X mark looks strikingly similar to a generic Unicode character used in the international computing standard to denote an abstract geometric space or object. The mark is also identical to the lowercase X in the Monotype Special Alphabets 4 font set. As applied to computer programming, this could make the X mark generic, and under the Lanham Act, “generic terms are never eligible for trademark protection because they refer to a general class of products rather than indicating a unique source.” If found to be generic, not only will it be impossible for X Corp. to register its stylized X, but it won’t have any trademark protection at all, for at least some services. Meanwhile, numerous new applications for the word mark TWITTER were filed in July 2023 by applicants seeking to seize upon the apparent abandonment of the TWITTER trademark. Many of these new applications (filed by individuals) cover similar computer-based goods and services included in the existing TWITTER registrations. Although these new applications are also unlikely to succeed and will be refused based on the existing TWITTER registrations, these individuals may be laying the groundwork for a cancellation action based on an intent not to resume use, all in an effort to stake a claim to this $20 billion brand. While any use of the TWITTER brand by a third party could, in all likelihood, be stopped based on a claim to residual goodwill, these efforts by third parties reflect the land grab created X Corp.’s decision. The fate of the famous TWITTER brand and its high-profile rebrand to X will keep USPTO examiners busy for some time. Even federal courts will see some action. On October 2, 2023, X Corp. was sued by a social media and marketing company called X Social Media alleging trademark infringement and violations of Florida state law, including common law unfair competition and unfair trade practices, based on X Social Media’s alleged prior use of the X SOCIALMEDIA mark since 2016. Whatever the outcome—whether X Corp. is able to ever achieve a federal registration for its X mark, or who becomes the successor to TWITTER trademark ownership—many will continue to question the motivation to rebrand away from such a famous, globally recognized, and arguably historic brand.
October 5, 2023
Data Protection and Privacy
A New Scheme is in Place to Allow U.S. Organisations to Import and Use Personal Data from the European Union – Should Every Business Rush to Sign Up?
On 10 July 2023, the European Commission adopted its adequacy decision for the EU-U.S. Data Privacy Framework (“DPF”). The adequacy decision is designed to relieve U.S.-based businesses and other institutions and organisations that choose to participate in the DPF from legal uncertainties and administrative burdens in relation to personal data records originating from the EU. It is expected that the UK and Switzerland will soon adopt similar decisions that will allow participating organisations to enjoy the benefits of the DPF in relation to data imported from those two countries for processing in the U.S. or by U.S. organisations. The DPF is the third attempt to create a data bridge between the EU – with its heightened concern for protecting privacy interests of individuals – and the U.S., which has been for the past few decades slow in adopting policies and legislation to protect those rights (although more recently consumer privacy legislation is increasingly being adopted by US state legislatures). Even before the EU introduced its General Data Protection Regulation (“GDPR”), there was a self-certification scheme in place – not altogether unlike the new DPF – which allowed US-based companies and organisations to import personal data from the EU on the basis of the organisation’s legal commitment to safeguard the data and to protect the interests of data subjects. Just like the new DPF, under that scheme (the “Safe Harbor” arrangement), mechanisms were put in place to allow the U.S. Department of Commerce to enforce the commitments of participating organisations and to allow individuals to bring complaints. Just like the DPF, the “Safe Harbor” scheme was approved by the EU Commission under applicable EU law. GDPR was designed to allow the “Safe Harbor” scheme to continue to operate. It contained specific provisions empowering the EU Commission to enter into international arrangements like the “Safe Harbor” and the DPF. But in its decision of 6 October 2015 in the Maximilian Schrems v Data Protection Commissioner case (C-362/14), the EU Court of Justice held that the “Safe Harbor” scheme failed to meet the requirements of EU law in relation to the protection of personal data when it is taken outside the jurisdiction of the EU. In 2016, the EU Commission approved a second scheme, known as the EU-U.S. Privacy Shield. That scheme was once again ruled in a subsequent decision of the EU court of 16 July 2020 (Schrems II, C-311-18) to have fallen short of EU legal requirements. In both decisions, the main reason for the EU Court’s decision that personal data transferred to the U.S. under the terms of the schemes was not sufficiently protected, was the evidence that U.S. national security and law enforcement agencies were engaged in wide-range, on-going, and (according to the Court’s findings) indiscriminate mass monitoring and surveillance of communications which the agencies access through “back doors” provided by social media and other digital platforms based in the U.S. The rulings of the EU Court were particularly focused on the absence of legal redress mechanisms in the U.S. for EU individuals whose data is or may be exposed to such surveillance. The EU Commission gave its blessing to the new DPF scheme based largely on the signing by President Biden on 7 October 2022 of Executive Order 14086 on Enhancing Safeguards for United States Signals Intelligence laying down limitations and safeguards for all U.S. signals intelligence activities and on a supplemental Regulation on the Data Protection Review Court (28 CFR Part 302) issued by the U.S. Attorney General. Among other things, the Executive Order and the associated Regulation establish a tribunal and proceedings that affected EU individuals will be able to use to bring complaints regarding the use of their data by intelligence agencies. Those redress mechanisms and the other requirements of the DPF program were considered to be sufficient by the EU Commission to provide adequate safeguards to protect personal data transferred to the U.S. under the scheme. But what does this all mean for U.S. businesses, organisations, and institutions that consider signing up for the DPF program? Participation in the scheme means that the organisation will be free to collect, import, and use personal data records from any source in the EU without having to put in place transfer agreements with each data exporter and carry out transfer impact assessment in each case and without risking challenges against its use of personal data imported from the EU. This could be of real benefit for businesses and organisations that receive data regularly from the EU, particularly if they deal with many different categories of personal data, coming from different sources and processed for many different purposes. Self-certification under the DPF means that there is no need to address each and every one of those data transfers individually. Further, businesses and organisations love to declare that they respect people’s privacy and that they are committed to protecting personal information. By committing itself to the requirements of the DPF program, an organisation may be able to nurture the trust of other businesses, and organisations, and even the public itself, for being an organisation that truly respect the privacy of individuals and is committed to protecting their data. If the scheme is successful in attracting large portions of corporate America as well as various other organisations and institutions that may be eligible for the scheme, it might become a ‘must have’ for large companies in the public eye. The scheme undeniably offers advantage for some, but the administrative effort and the compliance burden in participating in the DPF should not be understated. One of the key criticisms of the defunct “Safe Harbor” scheme was that it lacked any real oversight or enforcement mechanisms. This is not the case with the DPF. The fundamental idea of the DPF (as any other mechanism to legitimise international data transfers outside the EU) is that the self-certifying organisation has to commit itself to a set of basic “Principles” which reflect the fundamental requirements of the GDPR, including securing for data subjects the same rights that they have under EU law. This in itself is a serious compliance burden which any organisation that contemplates joining the scheme should consider carefully. Alongside broad principles of establishing a legitimate basis for the use of data, particular protections for sensitive data, data security, controls over the re-purposing of personal data, and the sharing of data with third parties, the DPF also includes some very specific requirements. These include, among other things, specific information that has to be made available to data subjects regarding the organisation’s participation in the DPF scheme, the internal complaints handling procedures, and the external dispute resolution mechanism to which the organisation commits itself and other information. This means that participants would have to update their privacy policies to include this information. Participating organisations are also required to give data subjects certain specific choices – an opt-out from disclosures to third parties (other than service providers) and an opt-out from re-purposing the data. Apart from the implications of offering those choices, organisations would have to consider the logistics of offering these choices to all EU individuals whose data is being imported by the organisation into the U.S. Further, the DPF introduces a new set of requirements regarding the contractual arrangements that have to be put in place when the imported data is being shared with a third party controlling (that is, not a service provider which deals with the data on behalf of the participating organisation). Organisations will therefore need to set themselves up for new procedures and new contract forms for dealing with onward transfers. Another key element – which was lacking in the original “Safe Harbor” scheme but had already been addressed under the “Privacy Shield” program - is the requirement that the participating organisation must submit itself to external dispute resolution mechanisms. Those could take the form of private dispute resolution organisations, but there is also the option for an organisation to submit itself to the jurisdiction of data protection regulators in the EU. Either way, the requirement is that the mechanism must be free to the complaining individual. Finally, to ensure that participants maintain the privacy and data security standards to which they commit themselves through self-certification, the scheme requires participating organisations to verify their own compliance. Verification can take the form of self-audits or external audits. Either way, the verification needs to demonstrate that the participant’s privacy policy regarding personal information received from the EU is accurate, comprehensive, readily available, conforms to the “Principles”, and – importantly – that it is fully complied with. It must also indicate that individuals are informed of the organisation’s in-house complaint handling procedures and of the independent recourse mechanism(s) through which individuals may pursue complaints. Further, the verification needs to confirm that the participating organisation has in place procedures for training employees in the implementation of the privacy policy, and disciplining them for failure to follow it; and that it has in place internal procedures for periodically conducting objective reviews of compliance with the above. An annual self-certification declaration must be made each year confirmed by the declaration of a corporate officer. Executives would need to ensure their companies are indeed fully compliant before swearing such a declaration. Alongside the compliance burdens and verification and dispute resolution mechanisms, the DPF also includes a number of exceptions and provisions that apply to specific situations, such as allowances for journalism, airlines, and for corporate due diligence exercises, and special rules for clinical trials and medical research and for handling human resources data. These special rules are designed to ensure that the scheme’s requirements are not going to be prohibitive in respect of such activities or for organisations in the relevant sectors. They would require particular attention by affected organisations. Consideration of those sets of special rules is beyond the scope of this note.
September 13, 2023
Copyrights
Not Human Enough – District Court Rejects Copyright For AI Artwork
Artificial Intelligence (AI) is one of the hottest topics in technology, with businesses studying how to utilize its benefits and at least some workers wondering if smarter and cheaper AI technologies will replace them. Here at the TMCA, we have been covering an AI-related issue of particular interest to IP attorneys – the ongoing battle of Dr. Stephen Thaler to copyright artwork created by AI software. Back in June 2022, Thaler filed a federal lawsuit in the District of Columbia challenging the Copyright Office’s refusal to register artwork Thaler had created using AI on the basis that human authorship is a requirement for copyright protection. Thaler then moved for moved for summary judgment in January 2023 on the sole legal issue of whether an AI-generated work is copyrightable, and Copyright Office cross-moved on the same issue. As we noted at the time, Thaler had a creative argument. In brief, Thaler posited that an AI programmer is like an employer, the AI is like an employee, and so a programmer like Thaler should be considered the owner of the AI artwork created by the AI/employee under the work for hire doctrine. Thaler’s attempt to equate AI technology with human employees is not likely to calm the fears of those who believe their jobs might be outsourced to machines in the not too distant future. It also didn’t convince the District Court that AI-generated works are entitled to copyright protection. In a decision issued last month, Judge Beryl Howell denied Thaler’s motion for summary judgment and granted the Copyright Office’s cross-motion. As the Court put it in succinct fashion: “Human authorship is a bedrock requirement of copyright.” In reaching its conclusion, Judge Howell addressed and dismissed all of Thaler’s arguments in support of his claim that his AI-generated artwork (which was displayed on P. 2 of the decision) was entitled to copyright protection. For example, the Court held that Thaler’s “work for hire” argument “put the cart before the horse.” The issue was not who could register a copyright, but rather whether any valid copyright existed in a work absent human involvement. Interestingly, the Court noted that Thaler had argued that there was in fact a degree of human involvement in the “development, use, ownership, and prompting of the AI generating software.” Unfortunately for Thaler, however, that alleged human involvement was not in the record, as Thaler had represented to the Copyright Office that the AI system generated the work autonomously and that he played no role in its creation. One wonders if a copyright application that emphasized the human involvement in directing and prompting AI would have more luck (and the Court itself pondered this issue towards the end of its decision). Photographs are entitled to copyright protection – isn’t there an argument that AI is just a more sophisticated form of machine but that AI-generated works are still human works? Maybe, though in the next section the Court drew a distinction between cameras and AI. The Court agreed with Thaler that copyright law has proven malleable enough to cover works created with new technologies – in fact, Section 102(a) of the current Copyright Act itself provides that copyright attached to “original works of authorship fixed in any tangible medium of expression, now known or later developed.” But human creativity is nonetheless, as the Court stated, “the sine qua non at the core of copyrightability.” As the Supreme Court held in Burrow-Giles Lithographic Co. v. Sarony, 111 U.S. 53, 58 (1884), photographs are the copyrightable creations of authors despite their use of a mechanical device because the photographic result represents the “original intellectual conceptions of the author.” Photographs, then, are more like paintings than AI-generated works. Thaler had no more success in arguing that the Copyright Act doesn’t define “author.” The Court consulted two dictionaries and concluded that the plain meaning of “author” means an “originator with the capacity for intellectual, creative, or artistic labor” (i.e., a human being). Such an interpretation is consistent with, in the view of the Court, “centuries of settled understanding” in copyright and patent law. Further evidence that copyright recognition requires human involvement is that numerous courts have consistently rejected copyright claims even when the claimed author was divine. Similarly, the works of monkeys are not entitled to copyright protection. The Court seems to conclude that if neither gods nor monkeys can register copyrights, then neither should AI be able to do so. Or at least one wishing to copyright an AI-generated work needs to show a great deal more human input than Thaler did.
September 11, 2023
Data Protection and Privacy
Navigating Data Breach Notification and Prevention in Hong Kong: A New Comprehensive Guide in Hong Kong
Introduction In June 2023, the Privacy Commissioner for Personal Data in Hong Kong (the “Commissioner”) released a new guidance note on data breach handling and notifications (the “Guidance Note”). The purpose of this note is to assist data users in preventing and managing data breaches effectively. The Guidance Note is a comprehensive document which recommends best practices in data governance, risk assessments, technical and operational security measures, data processor management, and remedial actions during data security incidents. In today's new normal, which includes hybrid modes of working and learning, data users face challenges in protecting data privacy and security. The Guidance Note is designed to help businesses minimize the risks of data breaches, which can cause reputational and financial damages. Moreover, it sheds light on essential requirements on the Personal Data (Privacy) Ordinance (Cap. 486, Laws of Hong Kong) (the “PDPO”), compelling data users to safeguard personal data from unauthorized access, processing, erasure, loss, or misuse. The Guidance Note focuses on the following areas concerning data breach: 1. Preparing for Contingency - Data Breach Response Plan A data breach response plan is crucial for organizations to effectively manage and minimize the impact of data breaches. The plan should encompass procedures for identifying, containing, assessing, and managing incidents. It should also define the roles and responsibilities of team members, communication plans, risk assessment workflows, investigation procedures, and record-keeping policies. Taking swift action in response to a data breach can significantly reduce the extent of damage caused. Regular reviews of the plan and adequate staff training are essential to ensure its effectiveness. 2. Handling Data Breaches The recommended steps for handling data breaches demonstrate the data user's commitment to addressing the issue promptly, which can significantly reduce the impact on affected individuals and potential reputational damage. The steps include: Step 1: Gather all relevant information about the breach and escalate the incident to the dedicated data breach response team if necessary. Step 2: Take immediate steps to contain the breach, such as shutting down or isolating compromised servers and disabling relevant system functions. Step 3: Assess the risks of harm to affected individuals by evaluating the nature and sensitivity of the personal data involved and the circumstances of the breach. Step 4: Consider notifying the relevant authorities and affected data subjects as soon as practicable after becoming aware of the breach, particularly if there is a real risk of harm to those individuals. Step 5: Keep a comprehensive record of the breach to facilitate a post breach review, including all relevant details, and use the lessons learned to improve personal data handling practices. 3. Data Breach Notifications Data users need to act quickly in the event of data breaches. They should promptly notify relevant parties, including affected data subjects and the Commissioner, upon becoming aware of a breach. This notification is vital to mitigate potential harm, enable investigative actions, demonstrate commitment to data privacy management, raise public awareness, and seek advice. The notification should include a general description of the breach, date and time of occurrence, source, types of personal data involved, risk assessment, mitigation measures taken, and contact information for the data breach response team. Data subjects can be notified directly or through public announcements, while the Commissioner should be notified using its Data Breach Notification Form, which can be submitted online, by fax, in person, or by post. Oral notifications are not accepted, and the Commissioner provides assistance in completing the form. Conclusion The Guidance Note highlights the complex legal framework in Hong Kong that mandates remedial actions for data breaches and is a valuable resource offering insights and strategies to prevent and handle data breaches effectively. Data users must promptly notify affected parties and the Commissioner, take necessary measures to mitigate harm, initiate investigations, demonstrate commitment to data privacy management, raise public awareness, and seek advice. Non-compliance with these regulations can lead to severe legal consequences. Therefore, preventing data breaches has become increasingly crucial to safeguard personal data, protect reputation, and avoid financial harm. By following the recommendations, businesses can enhance their data governance, security measures, and response strategies, thus reducing the risks associated with data breaches. Vigilance and preparedness will be key to safeguarding personal data and preserving the trust of customers and stakeholders alike for any business. Alongside with the Guidance Note, the Commissioner has introduced an online notification form, streamlining the reporting process for businesses facing data breaches. Currently, failing to report data breaches to the Commissioner or affected parties does not constitute a breach of the PDPO. However, the Commissioner is proactively pursuing amendments to the PDPO. This endeavor includes working towards establishing a mandatory data breach notification mechanism. While the precise timeline for these legislative amendments remains uncertain, the release of well-defined proposals is expected in the near future.
August 21, 2023
Data Protection and Privacy
California Attorney General Announces New Investigative Sweep Targeting CCPA Compliance for “Large California Employers”
On July 14, 2023, the California Attorney General announced an investigative sweep targeting CCPA compliance efforts by “large California employers.” The Attorney General’s Office stated that it sent inquiry letters to large California employers “requesting information on the companies’ compliance with the California Consumer Privacy Act (CCPA) with respect to the personal information of employees and job applicants.” The California Attorney General’s announcement is a reminder that all aspects of the CCPA are now applicable to employee, applicant, and other HR data. Before January 1, 2023, the CCPA only required covered employers to (a) safeguard HR data, and (b) provide a notice to employees, job applicants, owners, directors, officers, medical staff members, and contractors describing the categories of data collected in those contexts, and how that data would be used. However, California voters approved the California Privacy Rights Act (the “CPRA”) on November 3, 2020, which amended the CCPA and eliminated the exemption for data in the HR context. Effective January 1, 2023, covered employers’ obligations to comply with the CCPA as it relates to HR data expanded significantly. CCPA-covered employers’ HR data privacy obligations now include, among other things, drafting or amending compliant service provider agreements and establishing processes for handling requests from employees, applicants, contractors, and others in the HR context to exercise their rights to access, delete, correct, and opt out of the sale and sharing of their personal data. There is some degree of uncertainty as to how California employers can shape their CCPA compliance efforts. The CCPA regulations do not clearly address HR data, and the California Privacy Protection Agency (CPPA) recently acknowledged the lack of clarity in the CCPA regulations at a May 2023 meeting. The CPPA considered revising the CCPA regulations and/or adding exceptions or specific rules for employee data, given that “the current purposes are not really designed for” employee data, as one CPPA member noted. In addition, many employers who have fulfilled CCPA employee data access requests have been frustrated by the fact that the CCPA statute and the regulations do not contain meaningful exemptions applicable to data to be provided in the HR context, as can be seen in the General Data Protection Regulation, the comprehensive privacy law in the EU and UK, which does include HR data within its scope. Several other states exempted employee and other HR data from their own comprehensive consumer data privacy laws: Virginia, Colorado, Connecticut are currently in effect, and Utah, Texas, Montana, Iowa, Tennessee, and Indiana have enacted new laws to take effect in the next few years. California remains the only state to extend its data privacy law to HR data. Hopefully, the CPPA’s November 2023 meeting will bring clarity for California employers’ compliance efforts. In the meantime, the Attorney General’s announcement of an investigative sweep is a reminder that the CCPA’s statutory requirements, including those that apply to HR data, are enforceable, even though the Superior Court of California issued a ruling delaying enforcement of the new CCPA regulations until March 29, 2024.
July 31, 2023
Copyrights
Fearless Girl Statue Decision Says No Need to Fear Contracts – But Be Cautious Drafting Them!
A 4-foot tall, bronze girl defiantly stands with her hands on her hips and chin held high. Better known as Fearless Girl, the statue was intended to promote the power of women in leadership. The statue has come also to symbolize missteps and the consequences of unthoughtful legal planning. An advertising agency engaged Kristen Visbal to create the sculpture, apparently without any agreement as to rights, or, according to Visbal, any notice the sculpture was for a corporate sponsorship. State Street Global Advisors, the asset management company sponsoring the project initially placed Fearless Girl as a temporary counterpoint to the iconic Charging Bull statue: Fearless Girl was a tremendous success and had an immense social impact from its unveiling. The response prolonged display of the statute and spawned legal controversies. The first of which involved Arturo Di Modica, Charging Bull’s sculptor’s claims that the placement of Fearless Girl implicated issues of Di Modica’s copyright and trademark rights, and further distorted his artistic message as an “advertising trick.” We blogged about these claims back in 2017. Although Di Modica ultimately did not sue Visbal or the State of New York regarding the placement of Fearless Girl, Fearless Girl was eventually relocated to stand outside of the New York Stock Exchange. Another set of disputes arose from a trio of agreements State Street and Visbal negotiated following the statue’s success. The agreements were an attempt to sort out what each party could do with regard to the associated rights around the statue, but, unfortunately, created more problems than they solved. In 2019, State Street brought a claim in New York state court against Visbal, requesting a temporary restraining order to prevent Visbal from participating in an event in Australia that allegedly violated the agreements. The TRO was denied, but a later preliminary injunction was ultimately upheld. Following various claims and counterclaims, the parties filed motions for summary judgment, which the United States District Court for the Southern District of New York partially granted and partially denied. Judge Gregory H. Woods’ summary judgement opinion grapples for 90+ pages over the numerous breaches of contract, copyright and trademark infringement claims, and questions of preclusion. While nothing in the decision is groundbreaking, the opinion meticulously analyzes several breach of contract claims, offering excellent instruction as to drafting considerations. For instance, each of Visbal and State Street alleged claims regarding the other party’s breach of its obligations to provide attribution, which yielded opposing outcomes based upon the language in the agreements. Visbal’s claim stemmed from no attribution being provided when Fearless Girl was relocated to the New York Stock Exchange. The relevant agreement required State Street to “give attribution to [Visbal] as the sculptor of [Fearless Girl] wherever and whenever practicable, such as, for example, . . . plaques placed with” State Street replicas. The court denied summary judgement on this point, finding questions of fact with regard to whether attribution to Visbal would have been practicable (despite attribution being provided at the prior Charging Bull location). In contrast, Visbal agreed that any reproductions of Fearless Girl Visbal provided “as part of any promotional or corporate event, conference, ceremony, banquet, retreat, awards dinner, or the like” would include the attribution “Statute commissioned by SSGA.” The court found that Visbal’s verbal acknowledgement of State Street’s role was insufficient to meet the requirements as it did not include the exact language and did not appear on the reproduction, and granted summary judgement to State Street on this breach of the agreement. The contrast is a good reminder to use exact language, and avoid subjective considerations, in drafting specific requirements. Visbal did have a win with regard to State Street’s copyright infringement claims. The claim stemmed from Visbal’s grant of an exclusive license to State Street in connection with “gender diversity issues in corporate governance and in the financial services sector.” Visbal sold a Fearless Girl replica to an executive who worked at a financial institution. That executive later displayed the replica at a gender diversity in corporate governance event. Judge Woods denied summary judgement for both direct and vicarious infringement, finding Visbal did not take any action with regard to the executive’s use of the replica and did not profit from such use. The decision is not especially favorable to one party over the other, and Visbal’s counsel has already indicated her intention to appeal. The history of the sculpture and various legal disputes do serve as a cautionary tale and a necessary reminder of how important it is to carefully draft legal agreements—and just as carefully comply with them. The TMCA will continue to monitor this case.
July 27, 2023
Regulatory Compliance
Parlez-vous Français? New Language Requirements in Effect in Québec in June 2025
Established through the Charter of the French Language, French is the official language of the Province of Québec. The Charter applies to businesses located in Québec and to other businesses providing services and selling goods in this province, making the use of French mandatory in connection with these business activities. Historically, the Charter has provided for a “recognized trademark” exception to this French language requirement for registered and known (but unregistered) trademarks in Canada. In these cases, the “recognized trademark” may appear on goods, advertising, signage and commercial publications in a language other than French (unless the French version of the mark has been registered, in which case use of this French version remains mandatory). In addition, where the “recognized trademark” exception applies to use on signage or on the face of a building, it must also feature indications on the same visual plane that informs consumers and passersby of the nature of the business in the French language. This is referred to as the “sufficient presence of French” requirement. In May 2021, the provincial government of Québec introduced (and later passed, in May 2022) an amendment to the Charter, referred to as “Bill 96,” which changes how “recognized trademarks” are treated in commerce and business. As of June 1, 2025, the scope of the “recognized trademark” exception will be restricted to registered trademarks, and inscriptions on products, on public signage and in commercial advertising. As a result, the “recognized trademark” exception will no longer be triggered by unregistered trademarks. Currently, where the “recognized trademark” exception does not apply, the Charter requires that products, packaging, and related informational documents (instruction manuals, for example), and commercial publications (including websites and social media) public signage and commercial advertising, must be in French, or in French and another language so long as the “other language” is not given heightened focus in comparison to the French language. This includes font size, use of color, positioning, and overall size. With the understanding that unregistered trademarks will no longer be an exception to this rule, this would require active steps by trademark owners to obtain registrations for trademarks, in order to continue to benefit from the exception, or to otherwise potentially implement significant updates to all impacted materials. For registered trademarks that feature generic or descriptive terms in a language other than French, the descriptive or generic term will need to be translated into French and appear on the product or on a medium permanently attached to the product. At this time, it is unclear how “generic” or “descriptive” may be interpreted in this context, or frankly, precisely what “medium permanently attached to the product” means. Additionally, where the “recognized trademark” exception is not available, the rule currently is that signs, posters, and billboards must be in French, or in French and another language so long as the French is featured in a predominant manner, with a greater visual impact than the other language. Thus, the current impact of Bill 96 is that both unregistered trademarks and registered trademarks appearing on public signage will be required to change from a “sufficient presence of French” to a “markedly predominant” use of the French language, meaning that the French language must have a greater visual impact than the text in the other language. For businesses who seek to comply with Bill 96 by seeking new trademark registrations, a challenge here is that the Canadian Intellectual Property Office has significant delays in the examination of trademark applications (as of this writing, approximately 43 months). This makes it very difficult for businesses to come into compliance via new trademark applications by the current June 1, 2025 implementation date. This tension between the compliance deadline and registration speed has been broached with CIPO by Canadian practitioners. In terms of next steps, we encourage interested parties with registered and unregistered trademark rights in Canada to review their business activities and trademark portfolios to determine: Whether new trademark applications should be filed. If so, if new applications are filed featuring pre-approved goods and services from CIPO’s manual, it may be possible to reduce the examination time from 43 months to about 21 months. Taking action now may make it possible to meet requirements by June 1, 2025. Expedited examination is also available under certain prescribed circumstances. Whether the loss of the “recognized trademark” exception will require changes to product packaging (generic/descriptive terms, unregistered trademarks), related documentation, commercial publications, and public signs visible from outside buildings. Bill 96 expands the government’s powers of enforcement and all Québec residents will have standing to seek injunctive relief and damages. The potential business risk in Canada is therefore considerable, and taking action toward compliance now is recommended. We will keep our readers updated on further guidance in connection with the impact of Bill 96.
July 24, 2023
Trademarks
Update Regarding Trademark Proceedings in China: Rules on Suspension of CNIPA Trademark Proceedings
The China National Intellectual Property Administration (“CNIPA”) recently released its Rules On Suspension of CNIPA Trademark Proceedings (the “Suspension Rules”) and related explanations. The Suspension Rules are intended to provide clear guidance on the circumstances under which a CNIPA trademark proceeding shall be or may be suspended. For companies that have difficulty registering their brands due to prior rights no longer in use, or fraudulently filed, this may be welcome news. The Suspension Rules concern the four types of CNIPA trademark proceedings, namely: the review of a rejection of a trademark application (a Review of Rejection Proceeding); the review of an opposition decision refusing the registration of the opposed mark (a Review of Opposition Proceeding); the invalidation of a trademark registration (an Invalidation proceeding); the review of a cancellation decision regarding a trademark registration (a Review of Cancellation Proceeding, the most commonly seen cases under this category is a cancellation based on three year non-use) The Suspension Rules make it clear that a CNIPA trademark proceeding shall be suspended under any one of the following five circumstances: there is a pending assignment recordal proceeding between the disputed mark and the cited mark(s), and there will no longer be any conflict of rights after the completion of the assignment recordal; a cited mark has expired and is in the renewal proceeding or in the renewal grace period; a cited mark is under a pending cancellation or withdrawal proceeding; a cited mark has been cancelled, or has been invalidated or has expired without renewal but one year has not yet lapsed from the date of its cancellation, invalidation or expiration (exclusive of a cancellation based on non-use); a proceeding concerning a cited mark has been concluded pending the relevant decision to become final, or a case concerning a cited mark is waiting to be re-tried under an effective court order. The above five circumstances may be most relevant to a Review of Rejection Proceeding, this clear language in the Suspension Rules provides far greater certainty to an applicant, whose option presently is to hope for suspension and also file backup rights to maintain their priority. In the past, the suspension of cases under these five circumstances were within an examiner’s discretion and it was not transparent how an examiner could exercise their discretion. The Suspension Rules also provide that in relation to a Review of Opposition Proceeding or an Invalidation Proceeding, the examiner shall suspend the relevant proceeding if the protection of the prior right claimed is dependent on the outcome of another pending court or administrative proceeding. Lastly, the Suspension Rules provide that in relation to a Review of Rejection Proceeding, and upon the express request of the applicant, the examiner shall suspend the relevant proceeding if the status of a cited mark is dependent on the outcome of another pending court or administrative proceeding. In addition to the above seven circumstances where a CNIPA trademark proceeding shall be suspended, the Suspension Rules further provide three circumstances under which a proceeding may be suspended: if a cited mark has been under an invalidation proceeding, and the owner of the cited mark has been found guilty of making bad faith filing in other cases, an examiner may exercise his or her discretion to suspend the current Review of Rejection Proceeding without the need of a request of suspension by the review applicant; if the review and decision of a CNIPA trademark proceeding is dependent on the outcome of any prior related cases of similar circumstances, the examiner may suspend the CNIPA trademark proceeding if it is necessary; other circumstances whereby a suspension of the proceeding may be necessary (a catch-all provision). Procedurally, an applicant may make its suspension request under the new Rules in its initial filing, or within the subsequent three months supplemental filing period; it is not necessary to make a separate application for suspension. However, the request must provide the full particulars of the related pending proceedings upon which the suspension request is made, such as the filing number of the cited mark, the type of the pending proceeding and its status, and the relevance of that pending proceeding to the present case. Once the status of a cited mark has been crystalized, the applicant must provide proof to the examiner and request the examiner resume the relevant CNIPA trademark proceeding. Last but not the least, it is important to note that the Suspension Rules are exercised on the general principle of necessity, i.e., a CNIPA trademark proceeding would be suspended only if the status of the relevant prior rights will materially affect the outcome of the case. If the other review grounds and/or the status of the other prior rights are sufficient for deciding the case, then no suspension should be made as it is not necessary. We are pleased that the Suspension Rules may clear up the current procedural uncertainties in CNIPA trademark proceeding, especially in relation to a Review of Rejection Proceeding. This will enable a brand owner to better form its trademark filing and enforcement strategy and plans. While it remains to be seen how the Suspension Rules will be applied by the CNIPA, the Suspension Rules provide some hope to applicants whose previous option was to continue to refile applications while co-pending proceedings were decided. Dispensing with this strategy will certainly provide significant costs-saving and more streamlined case management for brand owners.
July 3, 2023
Data Protection and Privacy
Artists v. AI Images
AI technology is developing at a tremendous pace and AI image creation is no exception. AI images are even winning art contests. Since AI generates artistic images modeling others’ work, human artists are asking “is it copyright infringement for AI technology to use my work to learn how to create images and produce AI works?” The Northern District of California may answer that burning question. In January 2023 artists Sarah Andersen, Kelly McKernan and Kayla Ortiz filed a class action copyright lawsuit against Stability AI Ltd., Midjourney, Inc., and DeviantArt. The case is listed as Andersen v. Stability AI Ltd, U.S. District Court for the Northern District of California, No. 3:23-cv-00201.The Plaintiffs contend that AI used copyrighted works without their permission to help the technology learn how to copy and analyze works to produce new images. They also contend that the AI technology creates unauthorized derivative works. Put simply, the technology allows a user to type in a prompt of what type of art they want, in what style of artist, and can request it to have certain subjects in the picture. The artists argue that this essentially creates derivative works of their art. Other counts include infringement of the Digital Millennium Copyright Act, state law claims, and infringement of the right to publicity. In April, each Defendant filed a motion to dismiss the artists’ complaint. The Defendants’ argue that the artists failed to identify a “single allegedly infringing output image” that was allegedly used by the Defendants to train their system. The Defendants further argue that the artists cannot show any single image created by AI is substantially similar to an artists’ own copyrighted works. Most recently, on June 2, the Plaintiffs’ filed oppositions to each of the Defendant’s motions to dismiss. A judge has yet to publish a decision on the motions to dismiss. Defendant Midjourney argues that if the court were to resolve the claims of direct copyright infringement, it would have to proceed on an image-by image basis to determine which works are protectable and which are considered fair use. The fair use defense to copyright infringement allows a creator to use a work even if unauthorized and it is still not considered copyright infringement because it is a “fair use” of the copyrighted material. To determine if a work is fair use, a court will look to four factors: 1) the purpose and character of the use, 2) the nature of the copyrighted work, 3) the amount and substantiality of the work used in relation to the whole and, 4) the effect of the use upon the potential market for the work. The defendants may focus on the first and third factors. When looking at the purpose and character of the use, the Defendant’s may point out using any copyrighted works is still transformative in nature – the AI technology is generating new images that differ from the original works. Regarding the amount of the prior work used, the Defendant’s will likely argue that the material copied is an insignificant portion of the input material used by the AI program to generate an image. However, the Plaintiff’s will likely argue that AI will divert sales because the general public can now use AI as a substitute for buying their art. These decisions will be pivotal to determine if works generated through AI are copyright infringement or fair use. This case will have important results for several parties. For artists, the concern is that AI driven image creation may steal from their livelihood. Using AI, anyone can get an image that looks like their favorite artists by providing the system with a clear prompt. For the Defendants, this represents a landmark lawsuit that will determine if and how their company will be allowed to leverage AI going forward. For Stability AI, it will determine if their new AI technology will be able to be utilized and to what extent. For Midjourney and DeviantArt, it will answer if they are able to use Stability’s technology on their platforms to allow users to create their own images using AI technology. This lawsuit represents some of the first litigation to address key questions around AI image creation. As artificial intelligence comes more into the mainstream, it will be up to cases like these to help determine how AI images will be regulated, used, and to what extent. The rest of the world will be watching as this case will send some of the first signals for how the U.S. judicial system may view AI and copyright infringement claims.
June 29, 2023
Trademarks
Extraterritoriality of the Lanham Act: Fearsome Watchdog or Muzzled Chihuahua?
How far does the Lanham Act’s reach extend? The Supreme Court gave us one answer in Abitron Austria GmbH et al. v. Hetronic International, Inc. and made it simple: not very far. Hetronic is a U.S. company that manufactures remote controls for construction equipment. Abitron (comprised of six non-U.S. companies) at one point sold Hetronic’s products as a licensed distributor. However, Abitron eventually concluded it held rights to Hetronic’s intellectual property, including various trademarks. Abitron then reverse engineered Hetronic’s products and began selling goods bearing those marks in Europe and the U.S. Hetronic ultimately sued Abitron in the Western District of Oklahoma for trademark violations under Sections 1114(1)(a) and 1125(a)(1) of the Lanham Act, both of which prohibit using a trademark “in commerce” that is likely to cause confusion. The District Court awarded Hetronic approximately $96 million in damages and entered a permanent injunction barring Abitron from using Hetronic’s marks anywhere in the world. We last discussed Hetronic after a Tenth Circuit decision that narrowed the injunction slightly to geographic locations where Hetronic had marketed and sold its products. But the Tenth Circuit overall agreed that some of Abitron’s conduct in Europe could be enjoined by U.S. courts under the Lanham Act because Abitron’s actions had a substantial effect on U.S. commerce. Abitron then appealed to the Supreme Court, arguing the injunction was an impermissible extension of the Lanham Act to extraterritorial conduct—i.e., conduct outside the U.S. Today, the Supreme Court vacated and remanded the Tenth Circuit’s decision, determining that the two provisions of the Lanham Act at issue cannot be applied extraterritorially. The Court held that the Lanham Act only regulates use in commerce—i.e., the sale of goods or the provision of services—within the United States. The Court’s analysis centers on a presumption against extraterritoriality, a “longstanding principle of American law” that assumes Congress generally only regulates domestic affairs, and not foreign conduct. Four justices joined Justice Alito’s majority opinion, three joined Justice Sotomayor’s concurrence, and Justice Jackson entered a separate concurrence with her insights on the definition of “use in commerce” as used in Section 1127 of the Lanham Act. The Court applied a two-step framework to determine whether and to what extent the Lanham Act can regulate foreign conduct. All Justices agreed that the first question is whether the statute or provision explicitly states that it should apply to foreign conduct. In other words, has Congress “affirmatively and unmistakably instructed that” the provision at issue “‘should apply to foreign conduct’”? The Lanham Act does not explicitly state that it regulates foreign conduct, which cuts against applying the Lanham Act to regulate conduct abroad. Because the Lanham Act is not explicitly extraterritorial, the Court then moved to step two, which was far more contentious. The majority concluded the relevant inquiry for this step is to identify the “focus” of the statute and decide whether “conduct relevant to that focus” occurred in the U.S. Both are required. The parties offered different interpretations of what they believed the “focus” of the Lanham Act provisions were in this case for purposes of the second step of the framework. Hetronic argued that the focus of the statute was to protect the goodwill of trademark owners and to prevent consumer confusion. Abitron argued that the focus of the statute was to prevent infringement of trademarks. The U.S. government, as amicus curiae, took the middle ground and posited that the focus of the statute was consumer confusion. Instead of clarifying the Lanham Act’s focus, the Court concluded that, because the conduct at issue entirely occurred outside the U.S., there was no need to actually discern the focus of the statute. In other words, the fact that there was no conduct or domestic use in commerce renders the focus of the Lanham Act irrelevant. This second step, the majority clarified, is designed for "claims that involve both domestic and foreign activity," which is not the case here. Justice Jackson agreed that “use in commerce” is “the dividing line between foreign and domestic applications” of the Lanham Act, but added that any downstream sale of a good in the U.S. market constitutes use in commerce. In other words, the active resale of a good by an individual consumer, who bought a product abroad, would constitute use in commerce and open the original seller of the good to liability under the Lanham Act. Contrary to the framework outlined by the majority, however, Justice Sotomayor found common ground with the U.S. government’s opinion that the focus of the two provisions of the Lanham Act at issue is consumer confusion. This interpretation focuses on the impact of foreign conduct on the U.S. market instead of exclusively on “the location of the original sale of the infringing product or the location of the trademark owner’s business.” In other words, Justice Sotomayor would conclude that the Lanham Act provisions at issue extend to “activities abroad when there is a likelihood of consumer confusion in the United States.” (Emphasis added.) The at-odds opinions may be attributable to the manner in which the justices choose to interpret the case Steele v. Bulova Watch Co. (which involved a defendant’s allegedly infringing activities occurring in both Mexico and the United States), with the majority determining it is inapplicable and wholly distinguishable from the facts of Hetronic because it “implicate[s] both domestic conduct and a likelihood of domestic confusion,” and the Sotomayor concurrence finding Steele to persuasively conclude that “infringing acts consummated abroad fall under the purview of the Lanham Act when they generate consumer confusion in the United States.” In the majority’s view, the concurrence’s position would render the presumption against extraterritoriality, referred to in other cases as a “watchdog,” “nothing more than a muzzled Chihuahua.” Ultimately, the Court vacated and remanded the case. The majority does not outline the bounds of “use in commerce.” Whether the Lanham Act applies to goods sold indirectly into U.S. commerce remains to be seen. The TMCA will continue to monitor this case on remand and the impacts of the decision in the broader trademark landscape.
June 29, 2023