The TMCA
Advertising
Leaning Toward Commonality: States Enact New Comprehensive Consumer Data Privacy Laws
The year 2023 will likely go down in history as a major inflection point in the enactment of comprehensive consumer data privacy laws in the United States. At the beginning of the year, only five states (California, Virginia, Colorado, Utah, and Connecticut) had enacted comprehensive consumer data privacy laws. And, of these, only the California and Virginia laws are currently in effect. The privacy laws in Connecticut and Colorado go into effect on July 1, 2023, and Utah’s law becomes enforceable on December 31, 2023. Recently, however, the states of Indiana, Iowa, Tennessee, and Montana have also enacted new state consumer data privacy laws. In addition, state legislatures in Florida and Texas have passed bills to enact consumer data privacy laws; the governors of these states are widely expected to sign these bills into law. Most privacy professionals anticipate that many of the remaining states will also enact privacy laws in the next few years. It is likely that, barring preemptive federal law-making, most or all of the remaining states will eventually enact privacy laws of their own. (The state of Washington also recently enacted a landmark privacy law specific to consumer health data this year that also has some overlap with these comprehensive consumer data privacy laws.) Many businesses and other organizations have expressed concern about the compliance burdens of dealing with these emerging privacy laws, particularly since they can be subject to the laws of each jurisdiction in which they do business. Nevertheless, there is significant commonality among the laws that have passed so far. It is reasonable to assume that laws enacted in the future will continue to have these comment elements. By focusing on these common elements, businesses can design their privacy program with the confidence that it will be well positioned for the future. These common elements include the following features: Applicability thresholds. Although the specific thresholds vary, each of the state laws has applicability requirements that exempt many small and medium businesses that are not heavily involved in personal data collection or sales. Iowa and Indiana’s laws are typical in this respect. For either of those states’ laws to apply, the business or organization must process the personal data of 100,000 or more residents of the state or, if the business derives 50% or more of its gross revenue from the sale of personal data, process the data of 25,000 or more residents of the state. And, except in Colorado, non-profit organizations are exempt from compliance. Each law also has broad exemptions for organizations or personal data that is already protected under existing federal sectoral privacy laws like the Health Information Portability and Accounting Act (HIPAA) and the Gramm Leach Bliley Act (GLBA). Exclusion of personal data of employees, applicants, and former employees. With the exception of California, no state has applied its consumer data privacy law to individuals in their role as members of their employers’ workforces. Emergency contact information and personal data used for benefit administration is often also exempted from the laws’ requirements. Data subject rights. All states provide individuals in the state with rights relating to their personal data. These rights generally include the right to deletion of personal data, the right to correct inaccurate data, the right to know what data the business holds regarding the individual, and the right to receive a portable copy of the individual’s personal data. Most states also give individuals the right to opt out of the selling of their personal data or sharing of their personal data for behavioral advertising. A few states even give individuals the right to opt-out of certain kinds of processing of consumer data. Privacy notice requirements. Each of the states has requirements for privacy-related disclosures. Every state privacy law currently enacted requires businesses to state the categories of personal data that they collect and the purposes for the collection. Some states also require additional disclosures about the sharing and selling of personal data and place limits on the processing of personal data for purposes in excess of what was disclosed at the time of collection. And, all states require that privacy notices (often called privacy policies) explain the rights individuals have regarding their personal data. Sensitive data rules. Many states designate a category of personal data as “sensitive data” to reflect the higher risk of harm that could be associated with its use. Montana’s definition is typical and defines sensitive data as including: “(a) data revealing racial or ethnic origin, religious beliefs, a mental or physical health condition or diagnosis, information about a person’s sex life, sexual orientation, or citizenship or immigration status; (b) the processing of genetic or biometric data for the purpose of uniquely identifying an individual; (c) personal data collected from a known child; or (d) precise geolocation data.” Some states require consent from the individual to process sensitive data, while others allow individuals to opt out of the processing of sensitive data. Security requirements. All of the state privacy laws require organizations to protect personal data with reasonable information security safeguards. Data protection agreements. Most of the state privacy laws require businesses that engage processors (e., third parties that process personal data on their behalf) to have a contract with the processor that contains specific requirements, such as instructions for the personal data processing, the nature and purpose of the processing, the type of data subject to processing, the duration of the processing, return or deletion of the personal data at the end of the relationship, and assisting in demonstrating compliance with the law. Data protection assessments. Many of the state privacy laws have provisions that require businesses that engage in processing of personal data involving a high risk to the data subject to thoroughly analyze the processing, weigh the risks and benefits, consider ways to mitigate risks, and possibly consider alternatives and safeguards. (This assessment is sometimes also called a data protection impact assessment or privacy impact assessment.) Most of these laws consider the processing of personal data for targeted advertising or selling personal data to be activities for which an assessment is required. Similarly, the processing of sensitive data requires an assessment in many states. No Private Enforcement. In general, state privacy laws allow only governmental enforcement, and do not grant individuals a private right of action to sue for damages. California is the sole exception, but even in California, an individual can sue only if the individual was a victim of a data breach. Cure periods. Many laws provide that, prior to enforcement, a business is entitled to notice of an alleged problem and a right to cure the violation within a certain specified period. Civil penalties. All of the laws provide for civil penalties, often of $7,500 or more per violation. The following table describes how Iowa, Indiana, and Tennessee have addressed these common elements. Feature Iowa Indiana Tennessee Montana Applicability threshold Process personal data of 100,000 residents or Process personal data of 25,000 residents and receive 50% or more of gross revenue from sale of personal data Process personal data of 100,000 residents or Process personal data of 25,000 residents and receive 50% or more of gross revenue from sale of personal data Have $25 million or more worldwide annual gross revenue and process personal data of 175,000 residents or Process personal data of 25,000 residents and receive 50% or more of gross revenue from sale of personal data Process personal data of 50,000 residents or Process personal data of 25,000 residents and receive 25% or more of gross revenue from sale of personal data Data subject opt-out rights Sale of personal data, targeted advertising, sensitive data processing Targeted advertising, sale of personal data, profiling with significant consequences Sale of personal data, targeted advertising Targeted advertising, sale of personal data, profiling with significant consequences Other data subject rights Confirm processing, deletion, receive a copy, appeal Confirm processing, correction, deletion, receive a copy, appeal Confirm processing, correction, deletion, receive a copy, appeal, request information about data sales Confirm processing, correction, deletion, receive a copy Exclusions for data covered by HIPAA and GLBA and for institutions of higher education Yes Yes Yes Yes Requirement for a privacy notice required that is organized by categories and purposes and including information on rights Yes, and it must also list categories of personal data shared with third parties and categories of third parties Yes, and it must also list categories of personal data shared with third parties and categories of third parties Yes Yes, and it must also list categories of personal data shared with third parties and categories of third parties Privacy notice serves as a processing limitation (i.e. the law limits processing personal data for purposes other than those described at collection) No Yes Yes Yes Data protection assessments required No Yes Yes Yes Reasonable data security requirement Yes Yes Yes Yes Data processing agreement requirements Yes Yes Yes Yes Private right of action No No No No Right to cure Yes, 90 days Yes, 30 days Yes, 60 days Yes, 60 days, but it expires on April 1, 2026. Effective date Jan. 1, 2025 Jan. 1, 2026 July 1, 2024 Oct. 1, 2024 Civil penalty Up to $7,500 per violation Up to $7,500 per violation Up to $15,000 per violation Yes, with no explicit cap By building a privacy compliance program that can effectively deal with these common elements, business and other organizations can feel confident that their program will also satisfy many of the elements that will be present in future state data privacy laws. Here at the TMCA, we will continue to keep stakeholders updated on further developments in the fast-moving area of consumer privacy legislation.
June 14, 2023
First Amendment
Supreme Court’s Jack Daniel’s Decision Clarifies That Traditional Trademark Use “Does Not Receive Special First Amendment Protection,” Even When it Has Expressive Message
Humor matters, but it’s not the most important thing when considering a trademark infringement or dilution claim. In a decision with references to The Hangover Part II, Aqua’s song “Barbie Girl” (good luck not getting that stuck in your head if you grew up in the 90’s…), Tommy Hilfiger, and Harley-Davidson, the Supreme Court clarified the interaction of First Amendment protections, on the one hand, and trademark infringement and dilution claims involving “expressive works,” on the other hand. The bottom line is this: where an accused infringer uses a trademark like a trademark (i.e., to designate the source of its goods or services), the traditional likelihood of confusion analysis applies, even if the mark is also used in an expressive manner. First Amendment considerations like parody and commentary might impact that analysis, but there’s no threshold First Amendment consideration (like the Rogers test discussed below) that would prevent or bar this traditional analysis. Further, marks used in connection with commentary, criticism, and parody are not exempt from dilution claims when the mark is being used to designate the source of goods or services. As discussed in a prior TMCA blog post, this case arises out of Jack Daniel’s trademark infringement and dilution claims against VIP Products based on its “Bad Spaniels” dog toy. The Jack Daniel’s bottle and VIP dog toy are shown here: Beyond the similarities in the bottle and label, VIP’s product contained other clear nods to Jack Daniel’s, including using “Bad Spaniels” instead of “Jack Daniel’s” and the wording “The Old No. 2, on Your Tennessee Carpet” instead of “Old No. 7 Brand Tennessee Sour Mash Whiskey.” The packaging also included a disclaimer, stating, “This product is not affiliated with Jack Daniel Distillery.” VIP claimed the dog toy was an obvious parody of Jack Daniel’s products and, thus, entitled to First Amendment protection under the Rogers test for the infringement claim and also entitled to a statutory exception to the dilution claim as a parody of a famous mark. When an “expressive work” is involved, the Rogers test requires dismissal of a trademark infringement claim unless the plaintiff can show that either (1) the challenged use of a mark has no artistic relevance to the underlying work or (2) the work explicitly misleads as to the source or the content of the work. See Rogers v. Grimaldi, 875 F.2d 994 (2d Cir. 1989). The District Court ruled in Jack Daniel’s favor, rejecting application of the Rogers test because VIP used the mark to identify its own goods. It further concluded that the dilution exception did not apply for essentially the same reason. VIP appealed to the Ninth Circuit, which reversed and remanded, holding that: (1) the infringement claim could not stand because the “Bad Spaniels” dog toy is an expressive work entitled to First Amendment protection under the Rogers test since it “communicate[d] a humorous message,” and (2) VIP’s parody shielded it from liability for dilution under the non-commercial use exception. VIP Prods. LLC. V. Jack Daniel’s Props., 953 F.3d 1170 (9th Cir. 2020). On remand and given the Ninth Circuit’s directive, the District Court concluded that Jack Daniel’s could not satisfy the Rogers test and granted summary judgment to VIP. The Ninth Circuit summarily affirmed, and the Supreme Court granted Jack Daniel’s writ of certiorari to determine: Whether humorous use of another’s trademark as one’s own on a commercial product is subject to the Lanham Act’s traditional likelihood-of-confusion analysis, or instead receives heightened First Amendment protection from trademark infringement claims. Whether humorous use of another’s mark as one’s own on a commercial product is “noncommercial” under 15 U.S.C. § 1125(c)(3)(C), thus barring as a matter of law a claim of dilution by tarnishment under the Trademark Dilution Revision Act. In the Supreme Court’s majority opinion authored by Justice Kagan (the decision was unanimous, but with two concurrences), the Court first addresses the question, “Should [Jack Daniel’s] have had to satisfy the Rogers threshold test before the case could proceed to the Lanham Act’s [the U.S. trademark law] likelihood-of-confusion inquiry?” The Court found it should not have, stating: Without deciding whether Rogers has merit in other contexts, we hold that it does not when an alleged infringer uses a trademark in the way the Lanham Act most cares about: as a designation of source for the infringer’s own goods… When a mark is used as a mark (except, potentially, in rare situations), the likelihood-of-confusion inquiry does enough work to account for the interest in free expression. The Court parts ways with the Ninth Circuit’s previous holding, making it clear that a mark’s expressive content does not result in automatic application of the Rogers test. Despite fulsome briefing on the topic, the Court does not actually rule on the validity of Rogers. However, it certainly spends quite a bit of time considering the case’s history and application over the last 30+ years since its inception, citing to cases such as Mattel, Inc. v. MCA Records, Inc., 296 F. 3d 894 (9th Cir. 2002) (finding the song “Barbie Girl” did not use Barbie’s name in a source-identifying capacity and, thus, First Amendment protection was warranted) and Louis Vuitton Mallatier S. A. v. Warner Bros. Entm’t Inc., 868 F. Supp. 2d 172 (S.D.N.Y. 2012) (finding that mention of “Louis Vuitton”—pronounced “Lewis” in the film The Hangover Part II—satisfied the Rogers test because the film did not use the trademark as its “own identifying trademark.”). These courts (including the home of the Rogers test in the Second Circuit) have routinely declined to apply the Rogers test when the marks in question are being used as true trademarks (i.e., to designate source rather than for commentary or pure expression). This aligns with the primary purpose of the Lanham Act, which makes explicitly clear that, when another party uses a mark in a way which confuses consumers as to the source of the goods, infringement has occurred. 15 U.S.C. § 1114(1). The Court emphasizes that applying the Rogers test in all instances where a mark conveys other expressive content (such as a humorous message) could result in “Rogers [taking] over much of the world. For trademarks are often expressive in any number of ways.” The Court also cites to every trademark attorney’s best friend, McCarthy on Trademarks and Unfair Competition, which agrees that the Ninth Circuit’s expansion of Rogers “potentially encompasses just about everything” because names, phrases, symbols, designs, and their varied combinations often “contain some ‘expressive’ message” unrelated to source. 6 McCarthy on Trademarks and Unfair Competition § 31:144.50 (5th ed. 2022). Because VIP conceded it was using the BAD SPANIELS trademark and trade dress to “identify and distinguish [VIP’s] goods” and to “indicate [their] source,” the Court concluded that Rogers does not apply. Though VIP attempted to backtrack on those comments during oral arguments, the Court was not persuaded, pointing to the below hangtag that clearly shows the BAD SPANIELS mark situated similarly to the company’s registered SILLY SQUEAKERS Logo. Despite the inapplicability of Rogers, the Court explained that, on remand, the lower courts should still consider the thrust of VIP’s argument because “[a] trademark’s expressive message—particularly a parodic one, as VIP asserts—may properly figure in assessing the likelihood of confusion.” In other words, where a trademark is truly used as a trademark, expression must be considered in the context of the normal likelihood of confusion analysis rather than as a threshold question. It will be interesting to see whether this directive results in amendment of the infringement factors used by the various circuits, such as the Sleekcraft factors in the Ninth Circuit. In the second portion of the opinion, the Court swiftly dispatches the Ninth Circuit’s holding that the use of humor and parody constitute noncommercial use, which is excluded from dilution liability under the Lanham Act. See 15 U.S.C. §1125(c)(3)(C). The Lanham act provides an exclusion for a claim of dilution when use of a mark constitutes “fair use”, which specifically covers uses “parodying, criticizing, or commenting upon” a famous marks owner. Id. at §1125(c)(3)(A)(ii). Critically, however, this exclusion does not apply when the use is “as a designation of source for the person’s own goods or services.” Id. In line with its analysis of the first question presented, the Court concludes that, given “the fair-use provision’s carve-out, parody (and criticism and commentary, humorous or otherwise) is exempt from liability only if not used to designate source.” The Ninth Circuit’s expansive view of the non-commercial use exclusion does not align with Congress’s express limit placed on the fair-use exclusion, the Court found. The concurrences also contain some interesting tidbits. Although the majority opinion declined to rule on the validity of Rogers, the concurrence by Justice Gorsuch (joined by Justices Thomas and Barrett) directly calls into question Rogers, stating that it is “not entirely clear where the Rogers test comes from” and that “it is not obvious that Rogers is correct in all its particulars.” It warns lower courts that they “should be attuned to that fact.” The concurrence by Justice Sotomayor (joined by Justice Alito) warns that courts should “treat the results of surveys with particular caution” where “trademark infringement involves a parody” since “there is a particular risk in giving uncritical or undue weight” to these surveys. It points to one survey answer in this case that will give most IP attorneys instant heartburn: “The bottle is mimicked after the Jack Daniel BBQ sauce. So they would hold the patent therefore you would have to ask permission to use the image.” In the coming months, the lower courts will likely hear from Jack Daniel’s and VIP as they hash out the likelihood of confusion and dilution aspects of this case, and other courts will continue to refine the Rogers test (so long as it stands) and likelihood of confusion analysis articulated in this case. Keep an eye out on the TMCA blog for further coverage.
June 9, 2023
Trademarks
Supreme Court Will Review TRUMP TOO SMALL Trademark Registration Dispute
The Supreme Court granted certiorari and will review the Federal Circuit’s opinion that Section 2(c) of the Lanham Act is unconstitutional as applied to a trademark for the term TRUMP TOO SMALL. The TRUMP TOO SMALL trademark is a callback to an exchange between Senator Marco Rubio and then presidential candidate Donald Trump during the 2016 presidential primaries. As we previously reported, the Trademark Trial and Appeal Board initially rejected the trademark application under Section 2(c) of the Lanham Act because it comprises the name of a living individual—President Trump—without that individual’s consent. The Court of Appeals for the Federal Circuit reversed the TTAB’s decision. The applicant for the trademark plans to sell t-shirts with the phrase TRUMP TOO SMALL to criticize President Trump; specifically, to convey “that some features of President Trump and his policies are diminutive.” The Federal Circuit viewed this criticism as speech protected by the First Amendment and found that Section 2(c) is unconstitutional as applied to the TRUMP TOO SMALL trademark because the government does not have an interest “in restricting speech critical of government officials or public figures.” The Federal Circuit did not address whether Section 2(c) is unconstitutional in all cases, but did suggest that it may be “impermissibly overbroad” because it does not leave the trademark office any discretion to permit registration for trademarks that advance First Amendment interests. The Supreme Court previously found that portions of Section 2(a) of the Lanham Act, which prohibits registration of “immoral, deceptive, or scandalous” trademarks and trademarks that “may disparage . . . any persons, living or dead,” are unconstitutional in all cases. It remains to be seen whether Section 2(c) is destined for the same outcome. The Supreme Court will likely hear oral arguments in the fall. Stay tuned to the TMCA Blog for an update when the Supreme Court issues its opinion.
June 6, 2023
Data Protection and Privacy
Federal Agencies Set the Pace for Employers Using AI in the Workplace
It is safe to say that the use of artificial intelligence (AI) went mainstream in 2023. With the widening acceptance of AI, dozens of industries have raced to adopt the technology into various operations at a staggering pace – including adopting AI in human resources (HR) processes in the workplace. But, employers and HR departments should keep pace with federal agencies seeking to mitigate risks associated with AI in the workplace. Last week’s released guidance from the Equal Employment Opportunity Commission (EEOC) illustrates how federal agencies seek to keep up with technological advances. AI in the Workplace AI in the workplace is moving at a fast clip. According to the EEOC, as many as 83% of employers, and as many as up to 99% of Fortune 500 companies, are using some form of AI to screen or rank candidates for hiring. The use of AI in the workplace is not new from an HR perspective. Employers have long been able to use AI to perform certain HR functions in the recruiting process, such as resume screening. But now, employers can use AI for other recruitment functions, such as administering personality and aptitude tests or analyzing video interviews. Once workers are on-boarded, employers can use AI to help with worker safety, protection, management, and productivity through real-time locating systems and other technologies. Federal Agencies’ Guidance While business use of AI can involve great benefits, federal agencies seek to reduce potential negative consequences by issuing guidance, requesting information, and devising plans for AI in the workplace in the following ways: On January 26, 2022, the federal Occupational Safety and Health Administration (OSHA) issued a trade release announcing an update and expansion of a chapter in the OSHA Technical Manual on Industrial Robot Systems and Industrial Robot System Safety. The update notes that advances in AI boost the abilities and uses of robot systems in industrial applications. The revisions add current “technical information on the hazards associated with industrial and emergent robot applications, safety considerations for employers and workers, and risk assessments and risk reduction measures.” On May 12, 2022, the EEOC issued its guidance on AI “discuss[ing] how existing ADA requirements may apply to the use of [AI] in employment-related decision making and offers promising practices for employers to help with ADA compliance when using AI decision making tools.” The same day, on May 12, 2022, the Department of Justice issued guidance that “outlines issues that employers should consider to ensure that the use of software tools in employment does not disadvantage workers or applicants with disabilities in ways that violate the ADA.” On October 31, 2022, the National Labor Relations Board (NLRB) General Counsel issued a memorandum recommending that the NLRB “apply the Act to protect employees, to the greatest extent possible, from intrusive or abusive electronic monitoring and automated management practices that would have a tendency to” interfere with protected concerted activity. On January 10, 2023, the EEOC issued a draft strategic enforcement plan which announced that the agency would focus “on employment decisions, practices, or policies in which covered entities' use of technology contributes to discrimination based on a protected characteristic. These may include, for example, the use of software that incorporates algorithmic decision-making or machine learning, including artificial intelligence; use of automated recruitment, selection, or production and performance management tools; or other existing or emerging technological tools used in employment decisions.” On May 1, 2023, the White House Office of Science and Technology Policy (OSTP) announced that it will be releasing a public request for information (RFI) “to learn more about the automated tools used by employers to surveil, monitor, evaluate, and manage workers.” The OSTP states that responses to the RFI “will be used to inform new policy responses, share relevant research, data, and findings with the public, and amplify best practices among employers, worker organizations, technology vendors, developers, and others in civil society.” On May 18, 2023, the EEOC issued its guidance explaining the application of Title VII to an employer’s use of automated systems, including AI, noting that the scope of the guidance “is limited to the assessment of whether an employer’s ‘selection procedures’—the procedures it uses to make employment decisions such as hiring, promotion, and firing—have a disproportionately large negative effect on a basis that is prohibited by Title VII.” Employers should expect to see more federal guidance on AI as technologies continue to develop. What Employers Can Do to Stay in the AI Race With federal agencies’ guidance in mind and an expectation of more regulation to come, employers should take proactive steps to ensure the use of AI in the workplace keeps pace with developing law. These steps include: Understanding that AI in the workplace is governed by several different laws, including privacy laws, data security laws, and anti-discrimination laws at the state and federal levels. Considering including references to the use of AI in the recruiting, hiring, and employment process in employment policies and notices. Partnering with HR, IT, and legal counsel to ensure that AI practices remain competitive while compliant with local and federal law. The idea that AI can create several benefits in the workplace seems to be gaining traction. Federal guidance issued in 2022 and 2023 signal that regulation of AI in the workplace will strive to keep up with the strides made in technological advances. Employers and HR can stay ahead of the curve by keeping abreast of, and following, regulations applicable to their company. A version of this article was published on Dorsey's Employment blog, Quirky Questions. EEOC, Other Federal Agencies Set the Pace for Employers Using AI in the Workplace | Quirky Questions (quirkyemploymentquestions.com)
June 1, 2023
Trade Secrets
Inevitable Disclosure Theory Helps Plaintiff Overcome Standing Hurdle
Earlier this month, a federal court judge in the United States District Court for the Central District of Illinois denied a defendant’s motion to dismiss a plaintiff’s amended complaint for, among other claims, trade secret misappropriation, based on a theory of inevitable disclosure in the future. The plaintiff had admitted at oral argument that, after three years or so of discovery, it had no direct evidence of actual disclosure of its trade secrets by the defendant, and that it was instead relying in its amended complaint on the threat of future disclosure. The Court rejected the defendant’s position that a future disclosure threat as pled by plaintiff was insufficient to give the plaintiff standing to proceed, because the plain language of both the federal Defend Trade Secrets Act (“DTSA”) and the Illinois Trade Secrets Act (“ITSA”) expressly provide that actual or threatened misappropriation may be enjoined. The decision provides a useful illustration of the applicability of the doctrine of inevitable disclosure in the realm of trade secret litigation. The plaintiff Marquis ProCap System, LLC (“Marquis”) is a renewable energy company based in Illinois, and alleges that it operates the largest dry-mill ethanol facility in the United States. Marquis has developed proprietary processes, technology, and systems for processing the co-products of corn-to-ethanol production at the alleged cost of more than $30 million. For over a decade, defendant Novozymes North America, Inc. (“Novozymes”) had been a supplier to the Marquis companies, providing enzymes and microbes that Marquis used in its processes. For over a year or so, the parties explored forming a partnership. As part of this process, they entered into a mutual confidentiality agreement and, as claimed by Marquis, Novozymes was provided with Marquis’ trade secret information. Marquis alleged that, without any notice to it, and just four days after a knowledge-sharing meeting, Novozymes publicly announced that it was entering into an exclusive partnership with Green Plains, Inc. (“Green Plains”), Marquis’ competitor. Marquis claimed that the same Novozymes’ scientists worked on both the attempted partnership with Marquis and the partnership with Green Plains, and that Novozymes would not have been able to proceed with its partnership with Green Plains without misusing Marquis’ trade secrets. As a result, Marquis asserted trade secret misappropriation by Novozymes in violation of the DTSA, the ITSA, and the parties’ confidentiality agreement. After three years of discovery, Marquis amended its complaint to add allegations that Novozymes poses a future threat that it will inevitably use or disclose Marquis’ trade secrets, and Marquis even admitted during oral argument that it had no direct evidence that Novozymes had already shared its trade secrets with Green Plains. Rather, the plaintiff acknowledged that its focus was on the threat of future breach. Novozymes moved to dismiss the amended complaint arguing that Marquis lacked standing because of lack of evidence of actual misappropriation and because allegations of future threats of misappropriation are insufficient for establishing standing. The Court denied the motion, finding that Marquis had standing under both the ITSA and DTSA as both statutes allow the enjoining of not only actual but also threatened misappropriation. Relying on the Seventh Circuit decision in PepsiCo, Inc. v. Redmond, 54 F.3d 1262 (7th Cir. 1995), the Court recognized that a trade secret misappropriation claim could be established where a defendant’s new employment will inevitably lead him or her to rely on a plaintiff’s trade secrets. When determining if a defendant will inevitably disclose trade secrets in his or her new position, courts consider (1) the level of competition between the former and the new employer; (2) whether the employee’s new position is comparable to the position she or he held with the former employer; and (3) the new employer’s actions to prevent the employee from using or disclosing trade secrets of the former employer. The Court held that Marquis pointed to sufficient evidence at the motion to dismiss stage on each of these factors that: (1) Green Plains is Marquis’ direct competitor, (2) Novozymes is in a similar position of assisting Green Plains in improving its processes as when Novozymes was collaborating with Marquis, and (3) Novozymes failed to sufficiently protect Marquis’ trade secrets. In reaching its decision, the Court pointed to evidence that, while pursuing its partnership with Green Plains, Novozymes sent the same group of scientists who worked on the Green Plains project to learn about Marquis’ trade secrets and that Green Plains’ subsidiary filed a patent application pursuing protection for the same technology as Marquis without any explanation by the inventor as to how he came up with the invention, among other facts. The Court concluded that the facts as presented by Marquis at the motion to dismiss stage reflected that Novozymes would inevitably use Marquis’ trade secrets when partnering with Green Plains. The Court’s decision serves as a useful reminder of the importance of considering not just actual but also threatened misappropriation of trade secrets while asserting misappropriation claims, including the applicability of the inevitable disclosure doctrine. However, it is important to remember that the inevitable disclosure doctrine is applied differently (if at all) in various jurisdictions. In 2019, an Oregon federal court judge surveyed the status of the inevitable disclosure doctrine between the various states at the time, and found that: (a) seventeen (17) states appear to have adopted the inevitable disclosure doctrine in one form or another: Arkansas, Connecticut, Delaware, Florida, Indiana, Illinois, Iowa, Minnesota, Missouri, New Jersey, New York, North Carolina, Ohio, Pennsylvania, Texas, Utah, and Washington; (b) five (5) states appear to have rejected the doctrine: California, Colorado, Louisiana, Maryland, and Virginia; and (c) the remaining twenty-eight (28) states had not yet decided whether to follow the inevitable disclosure doctrine. Phoseon Tech., Inc. v. Heathcote, No. 3:19-cv-2081-SI, 2019 U.S. Dist. LEXIS 221633, at *30-31 (D. Or. Dec. 27, 2019). Since then, a Florida federal court has indicated that Florida has not adopted or declined to adopt the inevitable disclosure doctrine and an Oregon federal court has opined that Oregon would be unlikely to adopt the doctrine. Thus, an up-to-date canvassing of which jurisdictions recognize the inevitable disclosure doctrine is critical.
May 30, 2023
Copyrights
Supreme Court’s Warhol Decision Transforms Law of Fair Use by Emphasizing Importance of the “Purpose” of the Works at Issue
The Supreme Court’s decision in Andy Warhol Foundation for the Visual Arts, Inc. v. Goldsmith issued earlier today is chock full of references to famous artists, famous works of art, famous musicians and famous celebrities dating back centuries. Given Andy Warhol’s focus on the famous during his prolific career, he’d have to be pleased to see his name and works mentioned with such celebrated company, and in a Supreme Court decision no less. But stripped of its many pop culture and artistic references, the Warhol Foundation decision is the most important fair use decision in the past two decades, with ramifications that will reverberate far longer than the fifteen minutes Warhol envisioned. To recap the basic facts, the core question in the case is whether the use of a copyrighted photograph taken of the artist Prince by the photographer Lynn Goldsmith, subsequently modified by the artist Andy Warhol to create what was referred to as the “Orange Prince,” qualifies as a fair use under Section 107 of the U.S. Copyright Act. Goldsmith had licensed her 1981 photo of Prince, below left, to Vanity Fair magazine, published by Conde Nast, with the understanding that it would be modified by an artist, who turned out to be Andy Warhol. Warhol’s version of the work, below right, was published in 1984. Goldsmith Warhol Unbeknownst to Goldsmith, Warhol created a series of works based on her photo called the “Prince Series,” most of which were sold to collectors, with four now held by the Andy Warhol Museum in Pittsburgh. In 2016, Conde Nast licensed from the Warhol Foundation another work from the Prince Series – called the “Orange Prince” – that appears below. The “Orange Prince” was used by Conde Nast on the cover of a commemorative magazine published after Prince’s death. The Warhol Foundation received $10,000 as a licensing fee for this use of the “Orange Prince,” but Goldsmith received neither compensation nor credit for this use of her work. When Goldsmith asserted that the unauthorized 2016 use of her copyrighted photo was infringing, the Warhol Foundation sued her in New York for a declaratory judgment, asserting that the use of her photo in the “Orange Prince” qualified as a fair use. The district court granted summary judgment to the Foundation on its fair use defense, holding that all four factors set forth in 17 U.S.C. § 107 bearing on the issue of fair use favored the Foundation, in that the Prince Series was: (1) “transformative” because, while Goldsmith’s photo portrayed Prince as “not a comfortable person” and a “vulnerable human being,” the Prince Series portrayed Prince as an “iconic, larger-than-life figure”; (2) although Goldsmith’s photo was both creative and unpublished, which would traditionally weigh in Goldsmith’s favor, this was “of limited importance because the Prince Series works are transformative works”; (3) in creating the Prince Series, Warhol removed nearly all of the Goldsmith photo’s protectable elements; and (4) the Prince Series was not a market substitute that harmed or had the potential to harm Goldsmith. On appeal, the U.S. Court of Appeals for the Second Circuit reversed – twice – holding that the Prince Series was neither transformative nor a fair use as a matter of law, and also concluding that the Goldsmith photo and Prince Series were substantially similar as a matter of law. Even after the Supreme Court’s decision in Google LLC v. Oracle America, Inc., 141 S. Ct. 1183 (2021), reaffirmed the principle that a new work is transformative if it “adds something new . . . [by] altering the copyrighted work ‘with new expression, meaning or message’” (quoting Campbell v. Acuff-Rose Music, Inc., 510 U.S. 569, 579 (1994)), the Second Circuit stuck to its guns and held that the Prince Series of works were not transformative. Subsequently, the Supreme Court agreed to hear the Warhol Foundation’s appeal, but in today’s 7-2 decision authored by Justice Sotomayor, it agreed almost entirely with the Second Circuit’s holding. Today’s decision in Warhol Foundation is both narrow and broad at the same time. The decision is narrow in that it addresses only: (i) the licensing to Conde Nast of the “Orange Prince” in 2016 and subsequent publication of that work in a commemorative magazine; and (ii) whether the first statutory fair use factor – the purpose and character of the use – favors the Warhol Foundation. The Court expressed “no opinion as to the creation, display, or sale of any of the original Prince Series works,” and did not consider any other statutory fair use factor except to note how they can relate to the analysis of the first. Indeed, the concurrence from Justices Jackson and Gorsuch noted that all other issues, including whether the “Orange Prince” as licensed by the Warhol Foundation to Conde Nast actually infringes the Goldsmith photo, remain to be addressed during further proceedings. That said, the Court’s ruling is quite broad in a number of respects. In terms of assessing the first fair use factor (the purpose and character of the use), the question of whether a challenged use is “transformative” is now of secondary importance. Indeed, the entire body of case law that has focused the fair use inquiry on the issue of whether a challenged use is or is not transformative is now of questionable validity. So what is of primary importance now to the assessment of the first fair use factor? Two things: (i) whether and to what extent the challenged use has a purpose that is different from that of the original work; and (ii) whether the challenged use is commercial or non-commercial. To sum up the Court’s holding, in its own words: In sum, the first fair use factor considers whether the use of a copyrighted work has a further purpose or different character, which is a matter of degree, and the degree of difference must be balanced against the commercial nature of the use. If an original work and a secondary use share the same or highly similar purposes, and the secondary use is of a commercial nature, the first factor is likely to weigh against fair use, absent some other justification for copying. In this case, the Court held that the purposes of the Goldsmith photo and the “Orange Prince” were substantially the same – to depict the artist Prince. In reaching this conclusion, the Court emphasized the importance of Goldsmith’s extensive licensing of her famous portfolio of works for commercial purposes – not just the same photo of Prince – and the fact that Goldsmith had herself licensed her images of Prince for appearances in commemorative publications issued after his death. Since Conde Nast also published the “Orange Prince” to commemorate Prince’s death, the purposes of Goldsmith’s photo and the “Orange Prince” were substantially the same as far as the Court was concerned. And to the Court, when the purpose of two works is substantially the same, then the prospect that the junior use will substitute for the senior work – characterized as copyright law’s “bête noire” – looms large. The Court contrasted the use of the “Orange Prince” with Andy Warhol’s use of the famous Campbell’s Soup can logo, shown in the image below. This use of a copyrighted commercial logo had a purpose (commenting on consumerism) different from that of the original work (selling soup), and therefore the first statutory factor would favor a finding of fair use in this instance, according to today’s decision. Likewise, the use of a copyrighted work for purposes like parody, newsgathering, criticism, commentary and education would all likely support a finding of fair use because those purposes would, in most cases, differ from those of the original. The Court repeatedly emphasized in its decision that “the first fair use factor . . . focuses on whether an allegedly infringing use has a further purpose or different character, which is a matter of degree, and the degree of difference must be weighed against other considerations, like commercialism.” And on the issue of commercialism, Conde Nast’s commercial exploitation of the “Orange Prince” under license from the Warhol Foundation was of great importance to today’s ruling. Indeed, the Court emphasized that a use of the “Orange Prince” for non-commercial purposes might qualify as fair, but that Conde Nast’s use of that work was not fair insofar as the first factor was concerned, in part because the work was used for commercial purposes. So what about the question of whether a challenged use is transformative? Well, that still matters, but not nearly as much to the fair use analysis as it did before. Under today’s ruling, while the question of whether a later work has transformed a prior work by adding new meaning or message remains relevant, such additions will not by themselves tilt the first factor in favor of fair use, as most cases had held previously. Indeed, under today’s ruling, the first factor will only favor fair use if the newly added material rises to such a sufficiently transformative level that the new work achieves a different purpose than that of the prior work, and therefore does not supersede it. In the Court’s words: “Many secondary works add something new. That alone does not render such uses fair. Rather, the first factor (which is just one factor in a larger analysis) asks ‘whether and to what extent’ the use at issue has a purpose or character different from the original. Campbell, [510 U.S. at 579] (emphasis added). The larger the difference, the more likely the first factor weighs in favor of fair use. The smaller the difference, the less likely.” Indeed, one major takeaway from today’s decision is the Court’s concern that a focus on whether a challenged use is transformative is both difficult to apply in a consistent manner from case to case, and simultaneously permits copying on a such a large scale that the purposes of copyright are subverted. “[A]n overbroad concept of transformative use, one that includes any further purpose, or any different character, would narrow the copyright owner’s exclusive right to create derivative works. To preserve that right, the degree of transformation required to make ‘transformative’ use of an original must go beyond that required to qualify as a derivative.” In this regard, the Court’s majority opinion differed sharply from the dissent penned by Justices Kagan and Roberts, which lamented that today’s decision “will stifle creativity of every sort. It will impede new art and music and literature. It will thwart the expression of new ideas and the attainment of new knowledge. It will make our world poorer.” The majority shot back that the dissent was rife with “misstatements and exaggerations, from the dissent’s very first sentence, post, at 1 (“Today, the Court declares that Andy Warhol’s eye-popping silkscreen of Prince . . . is (in copyright lingo) not ‘transformative’”), to its very last, post, at 36 (“[The majority opinion] will make our world poorer”). The majority opinion characterized today’s decision as upholding the purpose of copyright – to protect the rights of creators in their original works – without preventing the uses of such works in circumstances long permitted by law, like when an unauthorized use qualifies as fair. Whether today’s decision actually achieves the balance the majority sought to strike will be a subject of extensive debate for many years to come. And whether subsequent decisions applying Warhol Foundation are effective in achieving that balance will be equally unclear until sufficient time has passed. But what is clear, now, is that the importance of Warhol Foundation to the fair use analysis in many artistic contexts is undeniable.
May 18, 2023
Data Protection and Privacy
Parents Retaking Control? New Utah Social Media Laws
This spring, Utah legislators gave parents new legal tools to control use of social media by children and teens, including introducing a private right of action with statutory damages. To comply, social media companies will need to fundamentally redesign their systems by March 1, 2024, unless they fit within one of the laws’ exceptions. Tech-savvy kids will surely attempt to defeat or work around the new restrictions. Utah Governor Spencer Cox signed into law two sweeping bills designed to restrict minors’ usage of social media in Utah on March 23, 2023. Senate Bill 1521 and House Bill 3112 are the first laws of their kind in the United States. The Utah Social Media Regulation Act, SB 152, requires certain social media companies to, among other things, verify the age of all current and future users, limit the hours of access for minors, and obtain parental or guardian consent when users under the age of 18 seek to open an account or use an existing account on their platforms. Failures can expose companies to regulatory enforcement and lawsuits by users seeking statutory damages. Concurrently, Utah HB 311 prohibits social media companies from using any practice, design, or feature on the company's social media platform that causes a Utah minor account holder to have an addiction to the social media platform.3 Following Utah’s enactment of its new laws, Arkansas followed suit with its Social Media Safety Act, signed by Arkansas’ governor on April 11, 2023, which also requires age verification of social media users, requires parental consent for use by minors, and enables a private right of action with statutory damages.4 Background Lawmakers have long sought to protect children online. Since the passage of the Children’s Online Privacy Protection Act (“COPPA”) in 1998, the Federal Trade Commission (“FTC”) and state attorneys general have brought multimillion dollar actions against the likes of Google and YouTube5 for illegally collecting personal information from children without their parents’ consent. Most recently, the FTC finalized an order requiring Epic Games, the maker of the video game Fortnite6 (which has been popular among teens and preteens), to pay $245 million for tricking players into making unwanted purchases by using “dark patterns.” The FTC alleged in the case that Epic’s confusing and counterintuitive design made it easy for children to make one-click, in-game purchases without requiring any parental consent. Nevertheless, the new Utah bills are the first state laws aimed at specifically regulating minors’ access to social media platforms (although they conceptually overlap somewhat with California’s Age-Appropriate Design Code). Utah lawmakers say that the bills are required to combat the negative effects of social media on youth mental health.7 To comply, social media companies will likely need to make sweeping changes to the operations of, access to, and advertising on their respective platforms if they seek to remain operational within the state. Scope Utah SB 152 and HB 311 apply to “Social Media Companies,” which are defined as a person or entity that: provides a social media platform that has at least 5,000,000 account holders worldwide; and is an interactive computer service.8 A “Social Media Platform” under the new law is defined as an online forum that a Social Media Company makes available for an account holder to: create a profile; upload posts; view the posts of other account holders; and interact with other account holders or users.9 Certain online services, websites, and applications such as email providers, e-commerce, and streaming services, among others, that meet defined exceptions are excluded from the bills.10 Even if initially excluded, companies will want to regularly re-evaluate whether they are within scope if minor users begin to use their platforms for new purposes. Requirements To comply with SB 152 and HB 311, which can be enforced on March 1, 2024, Social Media Companies will be required to: Verify the age of all existing or new Utah social media account holders using a government-issued ID card and, if the existing or new account holder is a minor, confirm that the minor has consent of a parent or guardian; Grant parents or guardians access to view all posts made and messages sent to and from their child’s social media account; Hide minors’ accounts from public search results and only allow minors to receive messages from accounts with which they are linked “through friending”;11 Prohibit the display of advertising as well as “targeted or suggested groups, services, products, posts, accounts, or users”12 in the minor’s account; Stop collecting or using any personal information from the posts, content, messages, text, or usage activities of the minor’s account other than information that is necessary to comply with, state or federal law (such as birth date and the parent or guardian's name); Prohibit minors from accessing their social media account during the hours of 10:30 p.m. to 6:30 a.m., unless granted by a parent or guardian; Permit parents and guardians to limit the number of hours per day the minor may use the account; and Discontinue the use of any practice, design, or feature that the social media company knows, or should reasonably know, causes Utah minor account holders to have an addiction to the social media platform. The Utah Division of Consumer Protection is tasked with drafting rules on age verification, identification, parental consent, and other aspects of the new law. Penalties SB 152 contains a private right of action through which a Utah resident may file suit against a Social Media Company for violations as of March 1, 2024. If a court finds that a violation has occurred, plaintiffs may receive: an award of reasonable attorney fees and court costs; and an amount equal to the greater of $2,500 per each incident of violation; or if the court determines that the harm is a direct consequence of the violation actual damages for financial, physical, and emotional harm incurred by the person bringing the action. HB 311 provides for additional civil penalties of: $250,000 for each practice, design, or feature shown to have caused social media addiction in minors; and $2,500 for each Utah minor account holder who is shown to have been exposed to the practice, design, or feature found to have caused the addiction or actual damages, whichever is greater. For Utah minors under the age of 16 seeking recovery of damages, the law introduces a rebuttable presumption that the alleged harm occurred and that the harm was caused “as a consequence of using or having an account on the social media company’s social media platform.” The Utah Division of Consumer Protection will also enforce the new laws and may impose administrative fines of $2,500 per violation or bring cases in Utah courts against companies that violate the new laws. With the technological development burdens of the new legal requirements, the loss of advertising revenue based on use by minors, and the potential statutory damage exposure, some social media companies may decide to ban use by those under 18 in Utah. However, even if they do so, they will still need to verify user age and will need to wait for regulations from the Utah Division of Consumer Protection on how to do so. 1 Senate Bill 152 2 House Bill 311 3 HB 311, Sec. 13-63-201(2). 4 Arkansas Act 689, SB 396. 5 Google and YouTube Will Pay Record $170 Million for Alleged Violations of Children’s Privacy Law | Federal Trade Commission (ftc.gov) 6 FTC Finalizes Order Requiring Fortnite maker Epic Games to Pay $245 Million for Tricking Users into Making Unwanted Charges | Federal Trade Commission 7 The Impact of Social Media on Teens' Mental Health | University of Utah Health | University of Utah Health 8 SB 152, Sec. 13-63-101(8). 9 SB 152, Sec. 13-63-101(9)(a). 10 SB 152, Sec. 13-63-101(9)(b). 11 SB 152, Sec. 13-63-103(1)-(2). 12 SB 152, Sec. 13-63-103(5).
May 10, 2023
Trademarks
Striking Out at the TTAB – All Rise for Consumer Recognition
What qualifies as the United States’ current favorite sport may be a subject for heated debate, but “America’s Pastime” and its biggest stars still have significant power over the public—and, apparently, the Trademark Trial and Appeal Board (“TTAB”). By 2017, New York Yankees right-fielder Aaron Judge had become a fan favorite, reaching such popularity that the team officially designated a section of its home stadium “The Judge’s Chambers.” Attendees wholeheartedly embraced the theme, with some showing up in judge’s robes, white wigs, and holding large signs bearing phrases such as “ALL RISE” and “HERE COMES THE JUDGE.” Not one to waste a good merchandising opportunity, Judge’s union, the Major League Baseball Players Association (“MLBPA”), licensed the use of these phrases, with Judge’s permission, to various third parties in exchange for royalties. Also in 2017, Long Island resident Michael P. Chisena filed applications to register the trademarks “ALL RISE,” “HERE COMES THE JUDGE,” and a design of a baseball diamond incorporating a gavel and scales of justice. Judge and the MLBPA filed oppositions of the applications before the TTAB. Purportedly unaware of throngs of screaming baseball fans wearing merchandise in reference to Judge just a few miles away, Chisena asserted that his applied-for marks did not refer to the right-fielder, and that the MLBPA simply uses “ALL RISE” and “HERE COMES THE JUDGE” as part of merely informational expressions to celebrate Aaron Judge’s baseball prowess. Traditionally, slogans or phrases that are common expressions or that simply convey information are not registerable as trademarks (e.g. “AMERICA’S FRESHEST ICE CREAM” for ice cream). Just a few months ago, the TTAB addressed similar arguments in its review of Lizzo LLC’s attempt to register “100% THAT BITCH.” In a precedential decision, the TTAB considered the possibility that the phrase was a merely informational expression that conveyed female self-confidence and independence. The singer Lizzo even admitted that the phrase originally came from an Internet meme. However, because Lizzo had popularized the phrase, the public had come to predominantly associate it with the singer, rendering it a valid trademark that identified her. And so, the TTAB allowed the mark to register. As with Lizzo, the TTAB sided with Judge and the MLBPA in a precedential decision, shutting down Chisena’s arguments and pointing out consumer recognition of “ALL RISE,” “HERE COMES THE JUDGE,” and the judicial baseball design logo as unmistakably referring to the Yankees player. Reliance on public perception therefore appears to be on the rise, spurring the TTAB to look outside of the application at issue and, at least in the case of celebrity singers and athletes, to rely on public perception as a measure of validity for trademarks.
May 8, 2023
Data Protection and Privacy
A Deepfake App Could Be in Deep Trouble with California Celebrities
A deepfake is an image or video of a person, often a celebrity, who has been digitally altered using an artificial intelligence (“AI”) application to appear to be someone else. Deepfake technology has the potential to be either a boon or a bane to celebrities. As a boon, celebrities can use deepfake technology to extend their professional opportunities. For example, Bruce Willis licensed his likeness to AI-based content creation company, Deepcake, to create a “digital twin,” which was used in a Russian telecom commercial. Even though Willis might have health issues that limit some activities, his digital twin effectively allows Willis to continue his professional career indefinitely, regardless of his health or age, and without the need for his physical presence. Deepfake technology can also be a bane to a celebrity when used to exploit their likeness without compensation or authorization, which is the alleged situation in Kyland Young v. NeoCortext, Inc., No. 2:23-cv-02496-DSF-PVC (C.D. Cal.). Defendant NeoCortext’s deepfake app, Reface, allows a user to swap their face with someone else, including a celebrity, but the celebrity has not necessarily authorized NeoCortext or the user to show or manipulate their likeness. Reface uses the likeness of former Big Brother contestant, Kyland Young, among others, without authorization. Consequently, Young filed a complaint against NeoCortext on April 3, 2023 asserting a single cause of action—violation of the California Rights of Publicity Statute (Cal. Civ. Code § 3344). Young filed the case as a putative class action on behalf of an indefinite number of other similarly situated citizens of California. California’s Right of Publicity Statute protects individuals from having their likenesses used by others, knowingly and without permission, on products or to advertise or sell goods and services. Young claims that NeoCortext has violated this statute by using his likeness, and the likeness of other celebrities, to encourage users to pay to upgrade their version of the app. The basic version of Reface is free. It includes access to the Reface “Pre-sets catalogue” which, according to Reface’s Terms of Use, is a library of images and videos to use for face swapping that may include third party content from a variety of publicly available sources, such as mybestgif.com, Google Video, and others. Young alleges that the Pre-set catalogue contains images and videos of himself and many other celebrities, often including their most famous and recognizable scenes and appearances. This suggests that in addition to rights of publicity claims like Young’s, NeoCortext might also be at risk of copyright infringement claims from whoever owns the rights to those scenes and appearances. Young alleges that when a user initially opens the app, it shows them a background video of a user swapping his face with several celebrities and well-known fictional characters. Next, the app provides the user with access to the Pre-sets catalogue, which the user can search until they find an individual they want to become. They then upload their own image or video to the app. Reface scans the user’s uploaded image or video and generates a new image or video swapping the face of the individual in the Pre-set catalogue with the face from the user’s uploaded image or video. An image generated by the free version of the app contains a prominently-displayed, irremovable watermark stating “made with reface app.” The free version of the app also has a button labeled “Watermark” that shows a picture of a water drop crossed out. Clicking that button prompts the user to upgrade to the “Pro Version” of Reface for a monthly subscription fee or a single lifetime payment, which allows the user to generate deepfakes without watermarks. Young alleges that NeoCortext commercially exploits his likeness and the likenesses of other class members to promote paid subscriptions in two ways: (1) allowing users to pay to remove watermarks which detract from the images; and (2) using watermarks as free advertising to attract new users to Reface. This case is in its very early stages and remains pending. This case is a reminder that creators and users of deepfake apps and other generative AI technology should be mindful of third party rights, especially when they exploit those rights for their own commercial benefit. An image or video is not in the public domain merely because it is available on a public website, and different rights in a work (e.g., rights of publicity and copyright) might have different owners and restrictions. Moreover, while the face swapping by apps like Reface appears to go only one way (i.e., replacing the face of an individual in the Pre-set catalogue with a face in an image uploaded by the user), creators whose apps allow face swapping in the other direction (i.e., putting a celebrity’s face onto someone else’s body), could give rise to even more issues.
May 3, 2023
Copyrights
Do Copyright Owners Have to Show What Elements of Their Software are Protected by Their Registrations? A Split Federal Circuit Suggests Yes.
In a recent decision, the Federal Circuit approved the use of “Copyrightability Hearings.” Not sure what that means? Read on to find out. The case involved a dispute between two parties, SAS Institute, Inc. (“SAS”) and World Programming Limited (“WPL”). SAS created and markets a suite of software used for data access, management, analysis, and presentation, while WPL markets a competing system. Both systems generally allow users to input data in a specified format, then perform various functions depending on the users’ needs, and output resulting data. In the case, SAS alleged that WPL infringed several copyright registrations covering SAS’s system. The Federal Circuit decision is the latest development in a lengthy and contentious relationship between the parties, who have been suing each other since at least 2009. In its decision, the Federal Circuit considered whether nonliteral elements of SAS’s system are protected by SAS’s copyright registrations. The nonliteral elements at issue here include input formats—the vocabulary and syntax that dictate how users input their data—and output designs—the format and type of data that is generated and displayed to the users. The case began in the U.S. District Court for the Eastern District of Texas, where both parties moved for summary judgment on the eve of trial. SAS sought an order that the nonliteral elements are protected by copyright, while WPL sought an order that the nonliteral elements are not protected. In the District Court Decision, Judge Gilstrap noted that this put the Court in a tough position. The Court either had to grant one party’s motion or it had to deny both motions and let the copyrightability issue to go to trial. As copyrightability is a question of law for the Court to decide, letting it go to trial would risk “injecting copyrightability into the jury trial” and risk confusing the jury during its infringement analysis. To solve this issue the District Court conducted a “Copyrightability Hearing” to determine what the “core protectable expression” of each of SAS’s works is. Specifically, each party was asked to submit briefing and evidence in support of its position as to the copyrightability of the nonliteral elements. Following the hearing, Judge Gilstrap found that WPL showed that nonliteral elements of SAS’s system were not protected by copyright because some elements are present in SAS’s earlier system, SAS 76, and are now in the public domain, others are open-sourced and available to the public, and still others are well-known, conventional, or not original to SAS. The Court then found that SAS failed to show which nonliteral elements are protectable and instead argued that all of the elements are “creative.” Accordingly, the District Court found the nonliteral elements are not protected and dismissed SAS’s claims. On appeal, SAS argued that the Copyrightability Hearing was a novel procedure that was contrary to the Federal Rules of Civil Procedure. The Federal Circuit disagreed. It cited the well-settled rule that district court judges have discretion to manage their cases and to conduct reasonable pre-trial procedures to narrow the issues in dispute for trial. The majority opinion also relied on an analogy to patent law, citing Markman v. Westview Instruments, Inc., the case that spawned the now-standard Markman hearing designed to ascertain the scope and meaning of patent claims before trial. In short, the majority ultimately viewed the Copyrightability Hearing as nothing more than a pre-trial conference within the District Court’s discretion. SAS also argued that the District Court improperly placed the burden on SAS to prove that the nonliteral elements of its system are protected by SAS’s copyright registrations. SAS instead believed its copyright registrations entitled it to a presumption that the elements are protected. The Federal Circuit was split on this issue. The majority opinion, authored by Circuit Judge Reyna, affirmed the District Court’s decision, while the dissenting opinion, authored by Circuit Judge Newman, would reverse and remand. The majority opinion clarified that while copyright registrations establish a threshold showing of protectability, if the accused infringer presents evidence that elements of the work are not protected, the burden then falls on the copyright holder to rebut that evidence. Here, after WPL showed that several of the elements are not protectable, SAS failed to show that any of the nonliteral elements of its system are protected by its copyright registrations. The dissenting opinion expressed concern that the majority’s analysis is a “far-reaching change” to the question of copyrightability that would have a significant impact on the software industry. In that regard, the dissent cited a litany of cases finding that nonliteral elements of software programs, even those that may be well-known or pre-existing, are copyrightable when selected and arranged in a creative or original way. The opinion then faulted the District Court and the majority opinion for requiring the parties to engage in “filtering”—isolating protected and non-protected elements—which is “developed for determinations of infringement.” In the dissent’s view, because SAS has valid copyright registrations and had a non-frivolous argument that the selection and arrangement of its system was sufficiently creative, this case should have proceeded. It remains to be seen whether the majority’s opinion will bring “far-reaching change” to the protectability of software programs. It also remains to be seen whether “Copyrightability Hearings” become standard practice for courts faced with similar issues. In view of this decision, however, plaintiffs should be prepared to clearly explain what is – and what is not – protected by their copyright registrations. This may not be the last word on this dispute. Given the decades of litigation between the parties, the novel issues, and a split opinion from the Federal Circuit, an appeal to the Supreme Court may be forthcoming.
April 26, 2023
Copyrights
AI Researcher Prompts Unexpected Output in Federal Court: Copyright Policy
In 2018, the U.S. Copyright Office denied the registration of a 2-D work of art “A Recent Entrance into Paradise” generated by artificial intelligence (“AI”). The programmer behind the AI, Dr. Stephen Thaler, sued the Copyright Office sued the Copyright Office in Federal Court in D.C. in June 2022. We covered Thaler’s initial suit and his attempts to patent an AI-generated invention in previous TMCA articles. Thaler moved for summary judgment in January 2023 as to the legal issue alone – whether an AI-generated work is copyrightable . The Copyright Office cross-moved for summary judgment in February, and Thaler filed a reply brief on March 7th. In support of these dueling summary judgment cross-motions, the parties doubled down on their initial arguments. Thaler offered a creative view of how copyright law could adapt to accommodate AI-generated works. Specifically, Thaler argued that a programmer is analogous to an employer and is therefore the owner of the artwork created by the employee-like AI under the work for hire doctrine. The AI was like an employee, according to Thaler, because Thaler controlled the AI, directed the AI to create the 2-D artwork, and owned the AI. In its brief, the Copyright Office restated that copyright protection requires human authorship of the expressive elements of the work. In other words, a work of art is not registrable if a human merely typed a command into an AI program to create it. Rather, the human must direct the creative contents of the work. Perhaps the most surprising element of the motions was the Copyright Office’s hint at the end of its motion that more guidance on AI was forthcoming. Not long after, on March 10, 2023, the Copyright Office unveiled a Statement of Policy regarding works incorporating AI generated content, further articulating the lines drawn in its brief. We covered the intricacies of the policy in our recent TMCA post. The good news is works generated using AI can be registered with the Copyright Office, but only by virtue of a human author’s creative additions to the AI-generated content. The central inquiry is whether the human author (and not the AI) had creative control over the expressive elements of the work. The policy is likely cold comfort for Thaler, who claimed the artwork “A Recent Entrance into Paradise” was autonomously created by the AI, i.e., without control from Thaler. The policy statement also did not give any credence to Thaler’s work for hire analogy. The Copyright Office’s guidance might bring the landscape into focus for prospective applicants, but it may be too late for Thaler’s current masterpiece. The summary judgment motions are still pending before the district court. We will continue to monitor this developing issue, including the Copyright Office’s promise to hold a public comment period later this year.
April 11, 2023
Advertising
When is Swiss chocolate Swiss enough? Toblerone Chocolate Recently Found Out, and it Didn’t Make the Cut.
The crinkle sound of the gold foil. The rich smell of honey and almond. The unique design of peaks and valleys. And the delicious taste of Swiss chocolate. There is little doubt that since its creation in 1908, Toblerone-branded chocolate has made a name for itself in the chocolate world. But one of its original and defining characteristics has recently been cast into doubt—its “Swissness.” In 1868, Jean Tobler opened a confectionery shop in Bern, Switzerland that was an immediate success and grew into a chocolate factory by 1899. A decade later, Jean’s son, Theodor Tobler and his cousin, Emil Baumann, invented a unique and innovative chocolate bar, a special recipe of milk chocolate, almond-based nougat, and honey formed into a distinct triangular shape. Theodor named this new confection “Toblerone,” a combination of his last name, “Tobler,” and “Torrone,” the Italian word for honey and almond nougat. The chocolate bar’s popularity and international recognition only grew from there, including a feature at the 1964 World’s Fair in New York City and the Expo in Montreal in 1967. In 1969, different varieties of the chocolate where introduced, and in 1970, the now infamous packaging was changed to add a depiction of the Matterhorn in the Swiss Alps, Switzerland’s highest and most famous mountain. Since this time, packages of Toblerone has included various indicators that the chocolate bars were manufactured in Switzerland, including the Matterhorn icon and statements like “of Switzerland,” and “Swiss milk chocolate.” Until recently, Toblerone was undoubtedly “Swiss,” as every chocolate bar bearing the Toblerone name since 1908 has come from Switzerland. But in late 2022, Mondelez International, the now owner of Toblerone, announced that some—but not all—of the chocolate bar’s production would be moved from its location in Bern, Switzerland to Bratislava, Slovakia in July 2023. And this decision has cost it its “Swissness.” Effective January 1, 2017, the Swiss government enacted legislation to protect the “Swissness” of the goods and services emanating from the country, with the goal of protecting the “excellent reputation” Swiss indicators of source enjoy both domestically and abroad. The legislation regulates the “Made in Switzerland” statement, the Swiss cross designations, and images of the iconic Matterhorn mountain, all of which the Swiss government views as part of the overarching Swiss brand. The Swiss government notes that “Swiss products and services are associated with exclusivity, tradition and quality, with their goods reputation inspiring confidence in the product or service in question and ultimately influencing the consumer’s buying decision.” As an added benefit, strict regulation surrounding these Swiss designations provide a clear competitive advantage for manufacturers and service providers who are able to demand a higher price for their “Swiss”-branded fares. This law stems from an intellectual property principal recognized in Europe and elsewhere in the world, but not in the United States, known as “geographic indicators.” Geographic indicators, which we have previously written about, are used to label products that directly specify a product’s particular geographic origin, like “champagne” from France or “parmigiano reggiano” from Italy. Technically speaking, sparkling wine from California cannot bear the “champagne,” “prosecco,” or “cava” labels, nor can cheese from Wisconsin be called “gouda” or “feta.” Certain geographic indicators can be registered under the European Community regulations, which in turn confers certain exclusive rights to the registered owner and protects the association of certain food and beverage characteristics within that particular geographic region. The 2017 “Swissness” law falls under this geographic indictor of intellectual property protection. Anyone wishing to use a “Swiss” designation on products or in connection with rendered services must meet strict criteria in proving they are “Swiss” enough. As is relevant to Toblerone’s confections, to qualify as “Swiss,” at least 80% of the raw materials used to create foodstuffs must originate in Switzerland. However, for milk and dairy products in particular—under which chocolate falls—the weight of milk as the raw material must equal 100%. Further, essential processing for milk products must be done inside the country, with few exceptions. In short, milk products must be made exclusively in Switzerland in order to use Swiss designations. Mondelez International’s decision to move its production of Toblerone chocolate to Slovakia defies this exclusivity, and therefore, is no longer deemed “Swiss.” Although some Toblerone chocolate will still emanate from the Bern factory, in order to comply with this “Swissness” law, Mondelez International announced plans to replace the Matterhorn with a more generic mountain-shaped icon, and will instead state that the chocolate was “established in Switzerland 1908,” instead of being “of Switzerland.” Some may view this Swissness law as overly strict, but others, including the Swiss government, see it as necessary to protect the strength and reputation of its brand. Citing consumer surveys, the Swiss government as justified this legislation by claiming the value Swiss branding adds to goods is as much as 20% of the sales price, and nearly 50% for luxury goods. While the benefit to companies and goods manufacturers is clear, it is equally as strong for consumers, who can rest assured that products bearing the Swiss cross or “made in Switzerland” statements are, in fact, Swiss. Despite the fact its product packaging is changing and it may not be “Swiss” anymore, Mondelez has reassured Toblerone fans and chocolate connoisseurs alike that the recipe, taste, and distinctive product shape of the famous chocolate bars will stay the same.
April 3, 2023
Data Protection and Privacy
FTC Takes First Enforcement Action for Violation of the Health Breach Notification Rule – A Federal Health Privacy Rule Beyond HIPAA
On February 1, 2023, the Federal Trade Commission (FTC) filed a complaint in the U.S. District Court for the Northern District of California alleging that digital health platform GoodRx violated the FTC Act by repeatedly sharing personal health information with advertising companies and platforms, such as Facebook and Google, and failed to report the unauthorized disclosures pursuant to its Health Breach Notification Rule (16 C.F.R. § 318). Though GoodRx maintains that it shared all health information appropriately, according to the proposed stipulated order, the digital health platform has agreed to pay a $1.5 million civil penalty. Once the proposed order is approved by a federal court judge, the monetary penalty, as well as several non-monetary sanctions, will go into effect. This settlement may signal the beginning of a new era of health privacy enforcement, where the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is not the only federal health privacy law for which organizations must ensure compliance. The FTC’s Health Breach Notification Rule is not new—even though the GoodRx complaint marks its first enforcement action. The rule went into effect in September 2009 and was the subject of a 2021 FTC policy statement. Substantively, the Health Breach Notification Rule is very similar to HIPAA’s Breach Notification Rule (45 C.F.R. §§ 164.400-414). Pursuant to both rules, a data holder must notify the subject of any unsecured “individually identifiable health information” and the agency responsible for enforcing the applicable rule in response to a breach of such information. Also pursuant to both rules, if a breach of unsecured personal health information involves more than 500 individuals (and, in the case of the Health Breach Notification Rule, if a breach involves exactly 500 individuals), the data holder must notify the media. The primary differentiating factor between the rules are the types of entities to which they apply. The HIPAA Breach Notification Rule is specific in scope and only applies to Covered Entities and their Business Associates. A Covered Entity is limited to a: (1) health plan, (2) health care clearinghouse, or (3) health care provider, who also electronically transmits health information in connection with transactions for which HHS has adopted standards. A Business Associate is a person or entity who, on behalf of a Covered Entity, performs or assists in performance of a function or activity involving the use or disclosure of individually identifiable health information. The FTC’s Health Breach Notification Rule is broader in scope and applies to all vendors that “offer or maintain a personal health record (PHR).” A PHR is an electronic record of “individually identifiable health information,” as defined in section 1171(6) of the Social Security Act (42 U.S.C. 1320d(6)), that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual. The FTC has stated that an example PHR Vendor might be a health app that collects information from consumers and can sync with a consumer’s fitness tracker. The Health Breach Notification Rule also applies to “PHR related entities” and “third-party service providers.” A PHR Related Entity interacts with a PHR Vendor by either offering products or services through the Vendor’s website, offering products or services through a Covered Entity’s website that offers individual’s health records, or by accessing information in a PHR or sending information to a PHR. The FTC states that an example of a PHR Related Entity might be a company that offers a fitness tracker and sends information to health apps. A Third Party Service Provider is an entity that provides services to a PHR Vendor in connection with the offering or maintenance of a PHR or to a PHR Related Entity in connection with a product or service offered by that entity; and accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured PHR identifiable health information as a result of such services. The FTC states that an example of a Third Party Service Provider might be a company that provides billing, debt collection, or data storage services relating to health information for a PHR. In light of the GoodRx complaint and the FTC’s enforcement of the Health Breach Notification Rule, all entities that utilize or maintain personal health information—and especially those offering healthcare apps, connected devices, and wearables, that often do not fall under the definitions of Covered Entities and Business Associates—should evaluate the applicability of the Health Breach Notification Rule to their organization and its business practices. Entities that fall under the definitions of PHR Vendor, PHR Related Entity, and Third Party Service Provider, should be sure to have an effective privacy and security program in place, including procedures for conducting regular risk assessments and risk management trainings to ensure proper identification of and response to a breach of personal health information. Such entities should also review their privacy policies, both internally and externally-facing, to ensure they reflect current data-sharing practices, and should review their vendor contracts to take inventory of any permissions or restrictions on how personal health information is used and disclosed to ensure they are obtaining the necessary consent. For more information on the Health Breach Notification Rule, the FTC’s Health Privacy webpage offers a variety of resources—including a simplified explainer of the rule, compliance tips, and an interactive tool geared toward mobile health apps.
March 21, 2023
Copyrights
Copyright Office Provides Guidance on Registration of AI-Created Material: Human Authorship Still Necessary
This blog has covered artificial intelligence and copyright protection in the United States on a number of occasions, including It's Alive? and AI Artwork. To date, the Copyright Office has consistently rejected registration of works created using AI technology. The basis is that the Copyright Office and copyright case law have interpreted the term “authorship” from the Copyright Act to exclude non-humans. The current version of the Compendium of U.S. Copyright Office Practices indicates that “to qualify as a work of ‘authorship’ a work must be created by a human being.” The Copyright Office recently signaled a willingness to move away from a rigid approach to AI-created works when it approved registration of a graphic novel named Zarya of the Dawn consisting of human-authored text and AI-generated imagery. The scope of registration, however, was limited only to the human-authored text in the graphic novel. Because AI-generated works will continue to be created and the Copyright Office has seen an influx of applications to register such works, the Copyright Office determined that public guidance is necessary specifically for registration of works created utilizing AI-technology or containing AI-generated content. Accordingly, on March 16, 2023, the Copyright Office released a statement entitled “Copyright Registration Guidance: Works Containing Material Generated by Artificial Intelligence.” In this policy statement, the Copyright Office provides two types of examples of use of AI technology and indicates that “what matters is the extent to which the human had creative control over the work’s expression and ‘actually formed’ the traditional elements of authorship”: When AI technology determines the expressive elements of the output, the work will not be protectable because it is not the product of human authorship. When a human being selects or arranges AI-generated material in a sufficiently creative way, then the work will be protectable as to the human-authored aspects of the work. The Copyright Office affirms that an applicant must disclose the inclusion of AI-generated content in any works submitted for registration. In the “Author Created” field of an application, the applicant must provide an explanation of the human author’s contributions to the work. AI-generated content that is more than de minimis must be explicitly excluded from the application. The AI machine or the company who provided the AI technology does not need to be listed as an author in the application. Applicants are also encouraged to use the “Note to CO” field on the application to provide any additional information that will be useful to an examiner in reviewing the application. If applicants already have applications pending that do not meet the foregoing requirements, they should contact the Copyright Office’s Public Information Office to request that a note be added to the record about the use of AI for the examiner to consider when reviewing the application. If registrations have already been issued that require correction, then the registrant needs to submit a supplementary registration request to correct or amplify the information in the registration record. Finally, the Copyright Office notes that applicants who fail to comply with these policies and obtain registrations risk losing the benefits of the registration and that the Copyright Office may take steps to cancel any non-compliant registrations it discovers. Ultimately, this guidance from the Copyright Office does not change the underlying rules of the game. Works must still have elements of human authorship to be eligible for registration. But use of AI technology to create works of authorship will not be considered a disqualifying factor.
March 17, 2023
Trademarks
Gruyere: Delicious Cheese But Generic Term
When you hear the word “gruyere,” what comes to mind? A bucolic region in the mountains of Switzerland? Perhaps the Gruyère region of neighboring France? Or, more likely, you think of a type of cheese. Not just any old cheese though – according to the Oxford Companion to Cheese, gruyere cheese is “widely considered among the greatest of all cheeses.” In a delightfully cheese-pun stuffed decision, the Fourth Circuit Court of Appeals recently held that U.S. cheese consumers primarily think of “gruyere” as a type of cheese, rather than a product specific to the Gruyère regions of Switzerland and France. As such, the Court found that the term “gruyere” was too generic to warrant a certification mark of geographic origin. As the Fourth Circuit explained, gruyere cheese originated in the district of La Gruyère in the Canton of Fribourg, Switzerland, in 1115 AD. The original area of production expanded to include other areas of Switzerland and certain neighboring areas of France. According to sources the court quoted, Swiss and French gruyere “producers make cheese from the unpasteurized milk of cows that graze on alpine grasses.” As is common in Europe, Switzerland and France have approved “Gruyère” as a protected designation of origin and a protected geographical indication, respectively. Those designations set forth detailed requirements for the gruyere production process, including that the cheese only be produced in specified areas of Switzerland and France. The U.S., however, does not extend similar protections to gruyere cheese. While the FDA has a general standard of identity of “Gruyere cheese,” that standard does not impose any geographic restrictions on where gruyere-labeled cheese can be produced. It’s no surprise that, as a result, cheese from all over the world – as well as from U.S. states such as Wisconsin and Idaho – has been labeled and sold as gruyere in the U.S. for decades. Of course, it’s also not a huge surprise that Swiss and French gruyere producers aren’t terribly keen on (maybe even cheesed off about) what the court termed “the indiscriminate labeling of cheese as gruyere in the United States.” In 2015, a Swiss and a French gruyere consortium (appellants in the Fourth Circuit case) teamed up to file an application with the USPTO to register the word “GRUYERE” as a certification mark. The intended mark would certify that the cheese originates in the Gruyère region of Switzerland and France, and would preclude any cheese produced outside that region from using the “GRUYERE” label. However, a group of U.S. dairy producers/importers (appellees in the Fourth Circuit) opposed the certification mark, arguing that the term “gruyere” was generic as to cheese and therefore not eligible for the certification. The TTAB agreed with the Opposers that “GRUYERE” is generic and could not be registered as a certification mark. After the Consortiums challenged that decision in a Virginia district court, the district court reached a similar conclusion and granted summary judgment for Opposers. The Consortiums then appealed to the Fourth Circuit, which noted that “[l]ike a fine cheese, this case has matured and is ripe for our review.” (Given the number of cheese puns in the decision, one wonders if the judges and their clerks nibbled on some gruyere while drafting the opinion.) The court began with a brief but helpful refresher course on certification marks, including indications of regional origin. The federal Lanham Act, 15 U.S.C. § 1127, defines a certification mark as “any word, name, symbol, or device, or any combination thereof” that is used “to certify regional or other origin, material, mode of manufacture, quality, accuracy, or other characteristics of such person’s goods or services or that the work or labor on the goods or services was performed by members of a union or other organization.” The court explained that, unlike a typical trademark, a “geographic certification mark is not used by the owner of the mark; rather, the owner of the certification mark controls how others use the mark.” Certification marks are, however, registrable “in the same manner and with the same effect as are trademarks.” 15 U.S.C. § 1054. Of course, this means that the same standards apply – including that a generic name (i.e., the name of a class of products or services) is ineligible for registration as a certification mark. The Fourth Circuit noted that the “critical issue in genericness cases is whether members of the relevant public primarily use or understand the term sought to be protected to refer to the genus of goods or services in question.” In this case, the issue was whether the cheese-consuming public primarily understand the term “GRUYERE” as referring to a type of cheese (i.e., generic), rather than indicating that the cheese was produced in the Gruyère region of Switzerland and France (i.e., non-generic). The district court had granted summary judgment to Opposers on the basis of three categories of evidence. First, the FDA standard of identity for “Gruyere cheese” indicates the mark is generic. Second, the district court held that USDA import data (which showed the prevalence of imported gruyere from countries other than Switzerland and France), as well as evidence of domestically produced gruyere-labeled cheese, favors a finding of genericness. Third, the district court found that “common usage” of the term gruyere shows that it is generic. On appeal, the Fourth Circuit agreed with the district court that the FDA standard of identity for “Gruyere cheese,” which does not contain any geographic restrictions on where the cheese can be produced, supports a finding that the term “GRUYERE” is generic. The court noted that, while the FDA standard of identity for “Gruyere cheese” does not preclude registration of the “GRUYERE” certification mark, that standard of identity “presents strong evidence that GRUYERE is a generic term.” Moving on to the second category of evidence (non-Swiss/French imports and domestically produced gruyere), the Fourth Circuit agreed with the Consortiums that the district court made an improper inference from the USDA import data. Specifically, the district court erroneously concluded that that data showed that the majority of gruyere-labeled cheese imported into the U.S. was from countries other than Switzerland and France, when that was unclear at best. Unfortunately for the Consortiums, despite this improper inference, the Fourth Circuit nonetheless held that “a substantial quantity of cheese has been imported to the United States from countries other than Switzerland and France and sold to consumers as gruyere.” Similarly, while conceding that some of the Consortiums’ criticisms of the domestically-produced gruyere cheese evidence had merit, the appellate court still concluded from the evidence that millions of pounds of domestic-produced cheese are sold as gruyere in the U.S. Next, the Fourth Circuit discussed the evidence of common usage of the term gruyere. Yet again, the court found that even though the district court had made mistakes, they didn’t impact the conclusion. The district court had first looked at various dictionary definitions of the term gruyere and concluded that most of those definitions did not limit the meaning of gruyere to cheese produced in Switzerland and France. But, as the Consortiums pointed out, some definitions do define “Gruyere cheese” as being produced or originating in Switzerland or France. Thus, the Fourth Circuit held that the district court erred in concluding from dictionary definitions of gruyere that the term was generic. But the district court had also considered references to gruyere in the media, and the Fourth Circuit agreed that those references – many of which described gruyere as originating in places other than Switzerland and France – supports a finding of genericness. Finally, the Fourth Circuit addressed the Consortiums’ argument that summary judgment was improper because Opposers failed to provide consumer survey evidence. In the court’s words, that “argument slices the cheese too thinly.” While survey evidence is common in genericness cases, it is not mandatory and evidence of consumer understanding of a mark may be obtained from any competent source. In sum, the court held that because the evidence made clear that cheese consumers in the U.S. understand “GRUYERE” to refer to a type of cheese (and not cheese from a particular region), the term is generic and the district court properly granted summary judgment to Opposers.
March 16, 2023
Trademarks
2023 China Trademark Legal and Practice Updates for Foreign Brand Owners
In order to strengthen the protection of the intellectual property rights and improve the quality control of trademark prosecution and enforcement, China issued a number of new regulations and practice guidelines in late 2022. The purpose of the new regulations, which were issued by the China National Intellectual Property Administration (the “CNIPA”) and the State Market Supervision Administration (the “State MSA”), was to further guide and regulate trademark practice as well as trademark agency conduct. In addition, on January 13, 2023, the CNIPA published the Draft Amendment of the PRC Trademark Law for Public Comments. The State MSA also published the Draft Amendment of the PRC Anti-Unfair Competition Law for Public Comments on November 22, 2022. This post will provide a brief update on these recently published regulations and guidelines regarding trademark practice in China, including highlighting the aspects that are relevant to foreign brand owners and foreign trademark practitioners. 1. Detailed Rules on Administration and Supervision of the Conduct of Trademark Agencies In China, most of the trademark applications are filed in the PRC Trademark Office through agencies such as law firms or companies that provide IP services. For foreign brand owners, a frequent concern and challenge in China is the prevalence of trademark squatting activities. As part of the Chinese government’s efforts to tackle this problem, the 2019 PRC Trademark Law seeks to address this problem by regulating these trademark agencies’ practice and conduct. For example, Article 19 of the PRC Trademark Law imposes certain duties on trademark agencies and prohibits certain conduct. A trademark agency violating any of those provisions under Article 19 may be penalized under Article 68 of the PRC Trademark Law. On October 27, 2022, the State MSA issued the Rules on Administration and Supervision of Trademark Agencies (the “Trademark Agencies Rules”), which came into effect on December 1, 2022. These new Rules supplement the general provisions (such as Articles 19 and 68 mentioned above) under current PRC Trademark Law and its implementation measures with respect to the practice and the conduct of trademark agencies in China. Specifically, Section 29 of the Trademark Agencies Rules explains what constitutes “disturbance to the market order of trademark agencies by way of slander or other improper means” under Article 68(2) of the PRC Trademark Law by setting out ten (10) specific practices that are prohibited. One of practices that is prohibited under Section 29(1) is for a trademark agent to accept an instruction to file a trademark application knowing that it is for a mark that is taking advantage of sudden events, quick fame gained by internet celebrities, influencers, hot topics or buzz words. In September 2022, just shortly before the Trademark Agencies Rules was issued, the trademark agency Alibaba Technology (Beijing) Co., Ltd was ordered by the local MSA to pay a fine in the amount of RMB80,000 (~US$12K) for accepting instructions to file trademark applications for a trademark squatter for the mark “谷爱凌GU AI LING” and “Eileen GU”, which are the Chinese and English names, respectively, of a freestyle skier who quickly gained great fame in China during the 2022 Winter Olympic Games held in Beijing. Under Section 23 of the Trademark Agencies Rules, if a trademark agency is intentionally involved in any IP infringing activities, such as submitting a bad faith trademark application, it will not only be penalized under the PRC Trademark Law, but will also be placed on a blacklist of enterprises deemed to have engaged in illegal and/or dishonest conduct. 2. Guidelines On Avoidance of Conflict with Prior Rights in Article 32 of the PRC Trademark Law On December 7, 2022, the CNIPA issued the "Guidelines on How to Avoid Conflict with Prior Rights in Trademark Application and Use" (the “Prior Rights Guidelines”), whereby it provided further clarification on the scope of “prior rights” under Article 32 of the PRC Trademark Law. This guidance included providing case examples and guidelines on how to avoid conflict with existing prior rights when applying for trademark registration in China. The Prior Rights Guidelines expand on the list of prior rights to include rights and interest in the title of a work, the name of a famous role in a work, the name of a database or a virtual figure. Such rights have previously been recognized by various decisions of the Chinese courts. In this regard, the Prior Rights Guidelines provide a case example in which protection of an opponent’s prior rights in the name of the world’s first Chinese Vocaloid and virtual figure “LUOTIANYI” was granted by the Chinese trademark authorities. 3. Clarifications On Class 35 Services in China On December 7, 2022, the CNIPA also published another important guideline providing clarifications on Class 35 services items, namely, the “Guidelines on the Application For and the Use of Service Marks in Class 35” (the “Class 35 Guidelines”). The Class 35 Guidelines provide a detailed interpretation of the service items in Class 35 in the PRC Goods and Service Classifications. In a nutshell, the Class 35 Guidelines explain that the services covered in Class 35 refer to services that are provided to others and to assist others’ business and operation rather than to the registrant itself for its own business operation. For example, advertising and promotion of one’s own trademarked clothing products does not qualify as “advertising” services under Class 35, but instead is use of a trademark for clothing under Class 25. By contrast, the typical use of a trademark for “advertising” services in Class 35 includes advertisement planning, design, and production for a third party’s products and/or services. Although Chinese courts have made similar clarifications in adjudicating trademark cases, the Class 35 Guidelines now provide clear guidance to assist trademark practitioners in understanding Class 35 services. However, foreign brand owners should know that this does not mean that Class 35 is unimportant and a brand owner should include Class 35 in its trademark portfolio in order to obtain proper trademark protection in China. By way of example, if a clothing products brand owner does not protect its trademark rights by securing trademark registration in Class 35, its brand name may be pirated by a third party in Class 35. The third-party pirate could then use the brand name as a shop name for selling clothing products, and the brand owner would likely find it difficult to stop the third party from using the shop name even if consumer confusion was obvious. 4. New Draft Amendments to the PRC Trademark Law and the PRC Anti-Unfair Competition Law for Public Comments On January 13, 2023, the CNIPA published the Draft Amendment of the Trademark Law of PRC on its website for public comment. The draft has introduced 23 new provisions into the trademark law as well as substantive amendments to 45 provisions in current trademark law. Significant amendments in the draft include the prohibition on repeated trademark applications for the same mark in respect of the same goods or service item by the same applicant/registrant, the introduction of “promise to use” requirement, and a related mechanism to remove registered trademarks that are not in use after five years of registration. In addition, on November 22, 2022, the State MSA released the Draft Amendment of the Anti-Unfair Competition Law of PRC for public comment. We will continue to monitor any developments on these important legal changes in China and make sure to keep you updated.
March 10, 2023
Trademarks
Journey’s Trademark Squabble – Who’s Crying Now?
When Journey was inducted into the Rock and Roll Hall of Fame in 2017, Steve Perry was ranked 76th on Rolling Stone’s “100 Greatest Singers of All Time.” Arguably, many Journey fans view the front man and his voice as the core identifier for the band and its most popular and commercially successful music. After considerable success between 1978 and 1987, Perry left the band and the band took a hiatus until 1995. Perry agreed to reunite with the band under a new manager, and the band enjoyed the success of a new album. However, in 1998, Perry left the band permanently and the face of Journey was After All These Years, changed. An Agreement between the parties in 1997, the so-called “Elmo Agreement,” set forth the terms of profit sharing. The Agreement was amended in 1998 when Perry left the band, and Neal Schon and Jonathan Cain, longtime guitarist and keyboardist for Journey (respectively), state that Perry still “receives a significant share of profits from the exploitation of the Journey song marks.” Fast-forward to Fall 2020. Freedom NJ LLC, a company run by Schon and Cain and current members of the band, filed 20 new trademark applications for well-known song titles for merchandise, including such hits as Don’t Stop Believin’, Who’s Crying Now?, Wheel in the Sky, and Any Way You Want It. All of the applications matured to registration in early 2022. Notably, none of the applications were challenged by Perry when published for opposition purposes. In September 2022, Perry filed a Petition to Cancel each of the 20 trademark registrations, alleging that the applications should not have been filed without his authorization. The 1997 Elmo Agreement states that “any use or exploitation, or grant or license of rights in or to any Group Composition(s), in whole or in part, including, without limitation, the titles thereof in connection with any product or otherwise, without the prior, written, unanimous consent of all of the Partners in each instance.” Perry, as a partner to the Agreement, was apparently not consulted about the applications. The Elmo Agreement was amended in 1998, addressing Perry’s departure from Journey, but Perry asserts that the amendment did not change the unanimous consent requirements in the Agreement of 1997. Schon and Cain subsequently assigned their interests and rights in the songs subject to the Elmo Agreement in 2019 and 2020, respectively, but Perry has not transferred any of his rights and interests. Thus, Perry asserted that the registrant, Freedom NJ, is not the owner or the user of the trademarks registrations, because Perry never provided his consent to the use or registration of the titles as trademarks for merchandise. Aside from asserting an ownership issue, Perry also alleged that the applications were fraudulent in making statements that the registrant had exclusive rights to the marks, that the marks were not in use, and that the song titles as trademarks falsely suggest a connection with Perry as the lead singer of the 20 songs. In response to the Petition to Cancel, Freedom NJ filed its Answer in early December 2022 asserting affirmative defenses, including: (1) the marks have been in use since the 1970s and 1980s with no objection from Perry; (2) Perry has received proceeds resulting from the licensing of the registered trademarks; (3) cancellation of the registrations would lead to prejudice to both Perry and Freedom NJ; (4) Perry uses a company called Pear Co. to manage assets, and both Pear Co. and Perry are signatories of the Elmo Agreement, thus Perry should not be shielded from liability through Pear Co.; and (5) Perry’s substantial income from current Journey tours and albums is in jeopardy as a material breach of the Elmo Agreement through the filing of the Petition to Cancel the registrations. Additionally, Freedom NJ asserted the following defenses: laches (Perry was not diligent in pursuing these claims), acquiescence and waiver (Perry accepted the benefits of the Elmo Agreement), bad faith and unclean hands (Perry accepted the benefits of the Elmo Agreement and breached the agreement by filing the cancellation), and breach of contract (breach of Elmo Agreement terms). On January 4, 2023, counsel for Perry withdrew the Petition to Cancel the 20 registrations, and because Freedom NJ had already filed its Answer and the withdrawal was without its consent, the Petition for Cancellation was denied with prejudice. This means that Perry cannot challenge these registrations in the future. Why did the Petition seem to take the midnight train going anywhere but the finish line at the Trademark Trial and Appeal Board? At its crux, this TTAB filing did not ever seem to be about trademarks. Rather, it was about the terms of the Elmo Agreement between the parties. Perry appears to have gained nothing but expenses by filing the Petition to Cancel the 20 registrations, all while continuing to receive financial benefit from the licenses tied to the trademarks in the interim. Did Freedom NJ welcome this outcome with Open Arms? Schon posted on Twitter a screenshot of the filing and said “So much for [Cain] trying to throw me under the bus as he claimed I was blatantly trying to rip off [Perry] while collecting the checks for the very diligent work my wife and I did to protect our merch.” Cain separately filed a lawsuit in November 2022 against Schon in California for “running up enormous personal charges on the band’s credit card account.” Perhaps Schon and Cain are also going Separate Ways. If the band members, both present and past, cannot Faithfully follow the terms of their Agreements, they surely cannot have it Any Way [They] Want it. As the Wheel in the Sky keeps on turning, we will provide updates on further developments.
February 21, 2023
Trademarks
Hashtag or Pound? One Law Firm’s Quest to Trademark #law
How would you pronounce #law? Is it “hashtag law,” as the PTO examiner suggested would be the most common understanding, or “pound law,” as alleged by the unsuccessful registrant of #law as a service mark. And to what does it refer: a hashtag for a social media topic, or a number that can be dialed from a mobile phone to reach an attorney referral service? Law firm Pound Law, LLC filed a lawsuit against the PTO and its director, arguing that its application for #law was improperly denied. According to Plaintiff, “the #LAW mark has become widely recognized by the relevant public as a distinctive brand and as a mnemonic/vanity telephone number mark uniquely associated with the services of Morgan & Morgan,” because Plaintiff spent “hundreds of millions” of dollars advertising it since 2006. Notably, this #law apparently only applies to telephone calls made on a mobile phone; it does not work on landlines, and the firm uses the website “www.forthepeople.com” and not either Pound Law or Morgan & Morgan. The examiner, and TTAB, decided that “consumers would not perceive [Plaintiff’s] use of #LAW as a source indicator but rather only as a means to contact [Plaintiff], based on the manner of use.” The history of this mark illustrates how quickly technology has unfolded over the past 15 years. Morgan & Morgan allegedly began using #law as a mnemonic and vanity phone number in 2006—the same year Twitter was founded. A few years later, Twitter took off: it had 300,000 tweets per day by the end of 2008, which ballooned to over 50 million tweets per day by early 2010. In 2022, there were over 500 million tweets per day, a non-negligible number of them using #law to identify the subject. A Twitter search renders countless tweets from law firms to law schools, legal consultants, protestors, and coaches using #law. Is Morgan & Morgan’s use really as “unique” and “distinctive” in 2023 as it may have been in 2007? The treatment of this mark calls to mind the Booking.com saga, covered extensively in this blog. The TTAB determined that the mark “Booking.com” was not registrable on the basis that it was generic, described here. The TTAB decision was overturned by Judge Brinkema in the Eastern District of Virginia, which held that Booking.com had acquired distinctiveness, described here, but awarded fees to the PTO because the case had been brought in district court instead of appealed directly to the Federal Circuit, as described here. The Fourth Circuit affirmed the District Court’s decision that the mark is registrable, but ordered the plaintiff to pay the PTO’s fees on appeal, described here. The PTO petitioned for certiorari to the U.S. Supreme Court, which was granted as described here, and the Supreme Court ultimately ruled that Booking.com is registrable, rejecting the premise that a generic.com term is ineligible for trademark protection, described here. This also calls to mind a different source of trademark obsolescence: trademarks that have been lost due to genericide. Among these are the yoyo, the flip phone and the escalator – all of which were marks associated with one brand until they became so widely used that they no longer identify a specific brand. Will #law go the way of the yoyo, or will it follow the winding path of the Booking.com decisions? Only time will tell.
February 16, 2023
Trade Secrets
Congress, President Align on Powerful New U.S. Intellectual Property Protection Law
On January 5, 2023, President Biden ushered in the new year by signing into law the Protecting American Intellectual Property Act of 2022 (“PAIPA”), Pub. Law 117-336.1 PAIPA was passed with considerable bipartisan support in both houses of Congress. The new law mandates the collection of certain data on international trade secret theft so the U.S. Government can issue annual unclassified public reports listing foreign individuals and entities who knowingly take or abuse U.S. trade secrets. PAIPA also requires the President to impose harsh legal sanctions against such named offenders, including on any entity owned or controlled by such a listed person. PAIPA reports will name foreign individuals and entities who have knowingly engaged in, benefited from, or materially assisted in the theft of U.S. trade secrets that pose “a significant threat to U.S. national security, foreign policy, or economic health.” The public PAIPA reports must also list the names of the foreign individuals who serve as the chief executive officers or board members of any listed foreign entity and of any entity that is owned or controlled by such a listed entity. Moreover, the Government’s published list must also explain the “nature, objective, and outcome of the theft of trade secrets” for each listed individual or entity. PAIPA also prescribes that any such public listing of an entity or individual as having engaged in such trade secret theft is to be an executive determination by the President and not an administrative finding of fact. However, the new law does not set forth any specific legal process or threshold of evidence to be found by the President before making such a determination. PAIPA requires the President to impose at least five different kinds of sanctions on a listed person but gives the President discretion to select from among those sanctions.2 More specifically, PAIPA allows the President to: block a listed person’s property-related transactions through economic sanctions enforced by the Office of Foreign Assets Control (“OFAC”) in the U.S. Department of the Treasury; place a listed person on the Entity List enforced by the Bureau of Industry and Security (“BIS”) in the U.S. Department of Commerce and thereby block such person’s access to any goods, software or technology that would be subject to the Export Administration Regulations (“EAR”); bar a listed person from access to any Export-Import Bank assistance; urge denial of loans to a listed person by any international financial institution of which the United States is a member; block any U.S. financial institution from lending to a listed person; if a listed person is a foreign financial institution, bar such listed person from being named as a primary dealer in U.S. government debt instruments or acting as a repository for any U.S. government funds; debar a listed person from being a federal contractor or a supplier of goods or services to the U.S. Government; block any listed person’s banking or foreign exchange transaction that is subject to U.S. jurisdiction; bar any U.S. person from investing in any equity or debt securities of a listed person; deny an entry visa to a listed individual or a corporate officer, principal, or shareholder who holds a controlling interest in a listed entity; or apply any of the above sanctions to the executive officers of a listed entity. PAIPA also states that it does not authorize or require the President to impose any sanctions on a listed person with respect to the importation of goods into the United States. Additionally, PAIPA provides the President with the power to waive the imposition of sanctions that would otherwise be required under the law if the President determines that the “national interest” would be served by such a waiver and notifies the relevant committees of Congress. Congress also inserted a “sunset” provision into PAIPA and so, unless reauthorized by Congress, this new law would expire in seven years. PAIPA contains a civil penalty provision applicable to any person who violates, attempts to violate, conspires to violate, or causes a violation of PAIPA or regulations issued under PAIPA. The amount of the PAIPA civil penalty is linked directly to the penalty prescribed under § 206 of the International Emergency Economic Powers Act (“IEEPA”),3 the amount of which was updated for inflation as of January 2023 to $356,579 per violation.4 Plainly, application of OFAC’s broad blocking powers against a PAIPA-listed person would then have immediate and profound implications for the international banking community in regard to international funds transfers by such a listed person, especially those involving U.S. dollar assets or payments made in U.S. dollars. Such banking effects would also potentially impact the payments or bank deposits of any other entities around the world that are owned or controlled by such a listed person. This new legislation thus continues a growing trend to expand the application of U.S. export control beyond the traditional and relatively circumscribed protection of export-controlled technologies for military or “dual-use” applications. As one other recent example, in October 20195 as we described here, BIS invoked its Entity List designation authority on 28 Chinese entities, including Dahua, Hikvision and several other leading electronics manufacturers for their roles in the suppression of human rights and in promoting electronic surveillance among Uyghurs and other minority Muslim populations in the Xinjiang Uyghur Autonomous Region (“XUAR”) of China. PAIPA also appears to continue another trend in which Congress requires Presidential action in certain prescribed circumstances rather than deferring to traditional Executive Branch discretion in the enforcement of laws enacted by Congress. Given the potentially dire consequences for a foreign entity or individual that could result from such a PAIPA listing, the new law may well provide a stronger deterrent to international trade secret theft committed against U.S. companies. However, it might also conceivably spur more legal disputes about whether the property allegedly stolen by a foreign person truly constitutes a “trade secret” of a U.S. company that can be subject to this law as a way to invalidate and reverse such a PAIPA listing. These new and severe consequences, along with the required publication of the details and effects of the underlying trade secret thefts, may also give U.S. companies some pause about exactly when, how and possibly even whether to report any suspected or known international trade secret theft to the U.S. Government. These annual public PAIPA listings will certainly fuel more corporate due diligence in the conduct of significant international business transactions and add to the growing family of such U.S. Government lists to be examined, such as OFAC’s Specially Designated Nationals List (“SDN List”) and Non-SDN Chinese Military-Industrial Companies List (“Non-SDN CMIC List”), the Department of Defense Section 1237 List, and the BIS Entity List. Finally, it seems virtually certain that some PAIPA-listed foreign entity or individual will eventually challenge its designation under this new law and raise due process concerns about the sufficiency of evidence considered by the President, which could lead to adoption of formal processes by which a listed individual or entity could raise a reasonable administrative challenge and seek its removal from the PAIPA listing. More may be known about the future implementation of PAIPA when and if President Biden issues a new Executive Order to delegate the duties and powers under PAIPA to other U.S. Government officials. One possibility in such an Executive Order might be to place the locus of PAIPA’s enforcement under the Secretary of Commerce (with input from other relevant senior officials such as the Attorney General and the Director of the Federal Bureau of Investigation). Historically, the Commerce Department has led in the field of intellectual property protection and has generally advocated on behalf of U.S. industries that rely on trade secrets in their intellectual property portfolios, and it is also the Cabinet department that includes the U.S. Patent and Trademark Office. 1 https://www.congress.gov/bill/117th-congress/senate-bill/1294 2 The PAIPA requirement for the President to impose five or more sanctions from all legally available legal sanctions follows the precedent of a similar mandate from Congress in the Iran Threat Reduction and Syria Human Rights Act of 2012 (“ITRSHRA”), Pub. Law 112-158. 3 Pub. Law 95-223. 4 88 Fed. Reg. 2229, 2230 (Jan. 13, 2023). 5 https://www.federalregister.gov/documents/2019/10/09/2019-22210/addition-of-certain-entities-to-the-entity-list
January 31, 2023
Data Protection and Privacy
Policing the Digital Space – New Rules Require Platforms to Take Responsibility for Users’ Content
Since the emergence of the Internet, under current European Union rules, services that host user-generated or user-contributed content have enjoyed legal immunity from liability, provided they take down unlawful content once notified of it. This existing regime gave online platforms, such as search engines, social media platforms, e-commerce sites and numerous other digital services, the freedom to determine their own rules on how their services can be used and – most importantly – the freedom to decide to what extent they wished to enforce their terms and conditions and user policies. This hands-off approach is now set to change dramatically with the introduction of new regulatory frameworks in the European Union and the United Kingdom for the operation of digital platforms designed to protect users from unlawful and unsafe content, which means significant new compliance obligations for the operators of such services. Each of the UK and the EU have recently produced new regimes for combatting online harm and protecting the safety of online users. In the EU, the Digital Services Act (DSA) has been accepted as law and will come into force in February 2023. While the UK’s parallel Online Safety Bill (OSB) is still the subject of parliamentary debate, it is also expected to become law in April 2023 and intends to make the UK the “safest place in the world to be online”. These new regimes will drastically change the way digital platforms need to regulate their services and reduce online harm to users. They consist of wide-reaching measures designed to minimize unlawful content and to protect children in particular from harm online, and will introduce a serious compliance burden on any online platform, regardless of size, provided it has more than a negligible UK or EU presence. The laws will apply to almost all social media and content sharing platforms. The overall intention of the regimes is to minimize the presentation of harmful content to users by placing a duty of care on the providers of that content. Once in force, it is hoped these will create a safer environment for internet users, but this will come at a cost of more onerous obligations for platforms that host user-generated content, and harsh penalties if they do not comply. These new regulatory frameworks will supplement, rather than replace, the existing rules that have governed content dissemination in both the UK and the EU since 2000 and which provide hosting services with immunity from liability for user-contributed content (subject to take-down obligations). Platforms will continue to enjoy legal immunity in respect of content posted by users; however, regulatory obligations will now require service providers to take proactive measures to keep their platforms lawful and safe rather than simply respond to takedown obligations initiated by others. For businesses operating online, understanding the applicability of the legislation and the obligations imposed will be very important: large fines, business suspension and even imprisonment can result. Territorial application of the legislation Importantly, the new regimes extend to businesses outside of the UK and EU. The obligations apply regardless of the place of establishment of the company running the service, instead focusing on the location of its users. The UK’s OSB will apply to services that have “links with the UK” – meaning a “significant number” of UK users – or those where the UK is a target market. Similarly, the EU’s DSA applies insofar as a platform offers services with a “substantial connection” to the EU, and notably requires such businesses having no establishment in the EU to appoint a legal representative there (who, where necessary, would be the target of regulatory enforcement action and liable for the service provider’s failures to meet its regulatory obligations). Types of digital services covered The OSB covers search engines and any user-to-user platform, which has a wide definition, encompassing any online service that allows user-generated content to be shared between users. This will extend to any app or website that has this functionality, such as those that allow users to talk with each other through messaging, comments and forums, as well as those that host users’ images, videos and other content. This means, for example, that certain online games and storage platforms may be covered, as well as the obvious messaging and content sharing apps and sites. The only platforms exempted are those that allow solely for emails, SMS, MMS and voice calling functionality, and this exemption does not extend to over-the-top messaging apps like WhatsApp. There are also exemptions for recognized news publisher content, and for sites where the only user-to-user content posted is in the form of comments or reviews. Under the DSA, search engines and intermediary services that are simply hosting, caching or functioning as a mere conduit, have some obligations. But, similar to the UK’s OSB, the most onerous obligations under the EU legislation are placed on those services that are deemed “online platforms”, being those that host and disseminate user content such as marketplaces and social media platforms. Each of the two regulatory regimes in the UK and the EU imposes additional obligations on the largest platforms: services deemed “high risk and high reach” under the OSB will have additional duties, such as having to provide users with empowerment tools and the option to verify their identity. Under the DSA, “very large online platforms” having 45 million users or more in the EU will have additional obligations. For smaller platforms, duties are less onerous; in line with this, the OSB applies a concept of proportionality in which measures required to be taken to comply with obligations will be proportionate to the risk level, size and capacity of the service provider. Key obligations imposed The duties relate mainly to illegal content and content harmful to children, and involve conducting risk assessments, having appropriate systems and processes in place, taking action in relation to illegal or harmful content, keeping records and reporting to the regulator. Importantly, these will need to be undertaken extensively and properly, and there is a duty to publish risk assessments or transparency reports under both regimes. Regulatory oversight will be applied to ensure the services discharge their duties in accordance with guidelines and policies to be developed in due course by the national regulators (in the UK and in EU member states). With respect to illegal content posted on platforms under the OSB, service providers will need to carry out an assessment to understand the risks of such content being presented on their platform. A large focus of the OSB is on child sexual exploitation and terrorism content, but the duties relate to any criminal offence where the victim is an individual (with a few exceptions). Platforms must take proportionate measures to mitigate and manage the risk of such content, and must have systems in place to minimize the exposure of users to illegal content, allow users to report the content and have processes ensuring it is swiftly taken down. There is also a duty to report UK-linked child sexual offences to the National Crime Agency. Under the DSA, all online platforms are obligated to remove content that is illegal in any EU Member State, suspend accounts that disseminate such illegal content, and report criminal offences. Very large online platforms need to produce an annual risk assessment and independent audit, have risk mitigation measures in place, and appoint a compliance officer for illegal content obligations. Platforms that are likely to be accessed by children have additional obligations that extend beyond strictly illegal content, and each service provider must assess whether the platform is likely to be accessed by children. Under the OSB, platforms likely to be accessed by children need to carry out a children’s risk assessment for harmful content. Obvious examples are pornographic and violent content, but this could also extend to things like cyber bullying, self-harm promotion, or content about eating disorders, as well as anything that risks causing a child psychological or physical harm. The platform must implement proportionate measures to mitigate and manage the risk of harm to children to prevent them from encountering the harmful content. These include having proper age assurance mechanisms in place. Related to this, there is a specific provision requiring services that publish pornographic content to prevent children from accessing it, again, likely through age verification measures. In the case of the DSA, platforms “accessible to minors” must have appropriate measures in place to ensure that minors have a high level of privacy, safety and security. Specific obligations are not listed in the same way as they are in the UK Bill, so operators of services will need to assess and limit the risks their platforms pose to children. Best practices for doing this are expected to be developed over time by regulators and quite likely by the industry itself. As originally proposed, the OSB outlined duties in relation to the management and mitigation of legal but harmful content to adults. The UK government recently announced that those duties have been dropped from the bill following political controversy not only over the fact that it is a heavy obligation to monitor legal but harmful content, but also over freedom of expression concerns. By comparison, under the DSA, there is no general duty on platforms to mitigate against harmful content to adults which is not unlawful. However, very large online platforms will have a risk assessment duty requiring them at least once a year to identify, analyze and assess “systemic risks” coming from their service regarding not only the dissemination of illegal content, but also serious harm to physical and mental wellbeing and to society in general. Consequences The OSB will be overseen by the UK’s communications regulator, OFCOM, which will have a range of powers to address non-compliance, including applying to the courts for an order that a business be blocked for use in the UK in cases where urgent action is required. Such an order is temporary but can be made permanent, and can require internet service providers, search engines and app stores to block the platform or take it down. In addition, fines of up to the greater of £18 million or 10% of the business’s annual revenue can be imposed. OFCOM will also have rights of entry and inspection and can request information at any time; a failure to comply with such a request, or the deliberate withholding or destroying of information, can result in the imprisonment of a senior manager. Under the DSA, each EU Member State will designate a competent authority to ensure compliance. The national regulators will be empowered to interview operators, carry out inspections, access data, request documents and information, and carry out searches and seizures. Again, in urgent situations, restriction of access can be ordered. The regulator can order a cessation of DSA infringements, and impose fines of up to 6% of annual turnover. How to prepare Preparation for compliance with the new regulatory regimes is essential for all affected digital platforms. The DSA will come into force on 17 February 2023, with most providers needing to publish an initial statement of usage by that date but otherwise having a one-year general grace period to comply with their remaining obligations. However, those that the regulator designates as “very large online platforms” will only have four months from such designation to comply. The OSB is likely to pass in April 2023; if it is delayed further than this, under Parliament rules, the bill will need to be dropped entirely and the legislation process will have to be restarted, which is something the Government will want to avoid. To help service providers comply with the OSB, OFCOM will publish Codes of Practice within three months of the Bill becoming law that can be taken as authority for compliance purposes. In practice, compliance with the regimes will likely involve developing and/or operating automated tools and algorithms, specialty compliance staff, secondary manual review systems, age assurance processes, user control mechanisms, policies, transparency, audits and record keeping. In the meantime, it is prudent for digital service providers to assess whether the OSB and DSA apply to their business, to prepare to implement such systems and processes, and to assess and adapt their existing systems and policies relating to user-generated content for risk.
January 27, 2023
Copyrights
ChatGPT: New Tool, Familiar Issues
What is ChatGPT? When asked this innocuous question, ChatGPT introduces itself, more or less, as an AI assistant trained to provide information and answer questions on a wide range of topics. It stresses that it does not have the ability to conduct internet searches or access any information outside of its training data (which stops at 2021). OpenAI launched ChatGPT in November of 2022 as a general-purpose AI chatbot built upon OpenAI’s GPT3 platform. The program quickly took the world by storm with its ability to produce a wide variety of at times cogent and accurate writings. Though not without flaws, ChatGPT is a sophisticated language model. This chatbot is yet another example of what AI holds for the future. One wonders: what ChatGPT can replace in the present? And, more ominously, what landmines lurk in its use? ChatGPT raises a number of copyright issues common to AI generally. For example: how to assess copyright infringement risks when interacting with chatbots trained on copyrighted works, such as books. Can one own copyright in what ChatGPT generates? Who, ultimately, owns works the works created? The legal landscape is still murky when it comes to copyright issues surrounding AI. Comprehensive case law has not yet developed on the subject, nor has statutory or regulatory guidance. As a starting point, the Copyright Office requires human creativity for copyright protection. What level of human creativity is sufficient, however, is unsettled. For our purposes of testing out ChatGPT, we each provided the same prompt to the bot on two separate days: write a blog post on chatgpt and copyright issues. The output took mere seconds to generate, which can be seen here. Unfortunately, the posts were not particularly insightful, even as starting drafts. Having said that, each output was unique and covered slightly varying copyright issues. The second output was the better of the two, indicating the program improves as it generates responses. As the human involvement here was limited to that simple prompt, it is unlikely to be sufficient for us to claim any ownership in the resulting work. Which raises the question: who does own it? OpenAI’s terms of use assign to its users all of OpenAI’s right, title, and interest in and to any output produced by ChatGPT in response to a user’s input. The terms, however, are careful to limit the assignment to what OpenAI owns, and specifically provide that ownership is settled only as “between the parties.” Of course, this leaves open the possibility that no rights are actually assigned. In addition, it is unclear if OpenAI’s wrap-around terms are sufficient to constitute the signed writing required under 17 U.S.C. § 204. While it is likely the terms would be enforceable against OpenAI, that question has not been firmly decided. Ownership of the output, thus, remains murky. OpenAI’s terms further caution that any user’s output may be similar to output of another user. Accordingly, more than one user could claim ownership in the exact same content the bot generates. Do any of those users own anything? Are these similar or exact works like the proverbial copies of Romeo and Juliet that coincidentally spring from the minds of authors without any exposure to the other’s works, each of which is protected and none of which infringe the others? Relatedly, can one lack exposure to the underlying copyrighted work if the tool used to create the new or derivative work was exposed? Or are these works more akin to copies that roll off a more sophisticated copy machine, each of which is an infringement? Instead, AI outputs may be public domain works from the outset. This brings us to the question of whether the outputs are infringing. ChatGPT relies, by its own explanation, on multiple texts and documents from various sources, many (most?) of which are copyrighted works. It is uncertain if some or much of any output is a copy of, or quite similar to, the foundational sources. Outputs may also be derivative works of one or more of the foundational sources. Both of the bot’s blog posts highlighted this issue. Its recommendation was to ask permission from the sources. Yet, the bot acknowledged the difficulty in seeking permission, as the sources are not identified. Unfortunately, the bot is not quite sophisticated enough to recognize the catch-22 it created. Understanding what the underlying works are, as well as the extent to which they are used, is necessary to determine issues of infringement, licensing and fair use. In some clever cross-marketing, the second blog output directed readers to a sister program that it says will curate and identify underlying sources, OpenAI API, which is currently available in private beta. For now, you can count on ChatGPT to give you a coherent, and oftentimes correct, response to your questions—save for queries reliant on information past the timestamp of 2021. In that way, the bot appears to be most useful as a search engine alternative. Too many issues remain unresolved to rely on the tool as a draft generator or an effective substitute for human effort. But keep your eyes and ears open for the fast moving developments with AI and legal resolutions. As AI increases in sophistication and its legal issues are gradually resolved, we can expect that more advanced uses will become viable.
January 24, 2023
Advertising
The FTC's New Year's Resolution for 2023: Healthier Health Claims
Just in time for your health-focused new year’s resolutions, the FTC released an updated guide for marketers: The Health Products Compliance Guidance. This guide last issued in 1998 under a more narrow title, focusing on dietary supplements. The world of health has changed a lot since 1998. While the larger concepts in this updated guide may seems like nothing new, the FTC has helpfully walked us through more than fifty examples applying the concepts to modern products and forms of advertising. If your company advertises health-related products or services, we suggest reading this business guide cover-to-cover with a nice glass of green juice. The FTC makes every effort to draft their guides with non-lawyers in mind. If you only have a few minutes between your next walking meeting and your morning matcha, we’ll take you through the highlights: The foundational rules remain the same – (1) Advertising must be truthful and not misleading and (2) Before disseminating an ad, advertisers must have adequate substantiation for all objective product claims conveyed, expressly or by implication, to consumers acting reasonably. The FTC and FDA share jurisdiction on health-related products – Just because your products fall under FDA law does not mean you can ignore the FTC. The agencies coordinate their enforcement and regulatory efforts and the FTC’s jurisdiction extends to all advertising claims, even those made on labeling, for which the FDA has primary responsibly. However, the FTC gives deference to the FDA and health claims that meet the FDA “significant scientific agreement” standard will be presumed to be substantiated under FTC law. Health claims require competent and reliable scientific evidence – Randomized, controlled, human clinical trials (“RCTs”) are the most reliable form of evidence and are generally the type of substantiation that experts would require for health benefit claims. It is important to note that anecdotal evidence about the individual experiences of consumers, including surveys of consumer experiences, are never sufficient to substantiate claims about the effects of a health product. Similarly, public health recommendations from advisories from medical organizations cannot serve as a substitute for RCTs. Let the basic principles of scientific research guide your studies – The FTC’s guide recommends that advertisers ensure that the research upon which they rely for any health-related claims complies with the basic principles relied on by the scientific community for research. These key concepts include the use of control groups, randomization, double blinding, reliance on statistically significant results, and reliance on meaningful results. Match your claim to your study – The Guides note that this is common problem for advertisers: valid studies, but those studies don’t support the claim being made. Another warning to take to heart is that claims should be carefully worded to avoid overstating the certainty of science in areas where the science is still emerging. If there are significant limitations or inconsistences within the scientific literature, your consumers should be made aware. Advertising in the form of consumer or expert testimonials still require substantiation – As FTC guidance has repeated over and over again: advertisers should not make claims through consumer testimonials or expert endorsements that would be deceptive or deemed unsubstantiated if the advertiser made them directly. The Guide closes with two overarching recommendations: To ensure compliance with FTC law, marketers of any health-related product should follow two important steps: 1) Consider what express and implied messages consumers are likely to take from your ads. Where appropriate, carefully qualify your claims – in other words, clearly explain the limited circumstances in which the advertised benefits or results apply; 2) Carefully review the support for each claim to make sure it is scientifically sound, adequate in the context of the surrounding body of evidence, and relevant to the specific product and advertising claim. Cheers to a healthy 2023.
January 19, 2023
First Amendment
So, Nine Justices Walk into a Bar… SCOTUS to Consider Role of Humor in Infringement and Dilution Claims
Justices of the Supreme Court will soon put on their whiskey glasses to decide the proper tests for infringement and dilution claims involving humorous use of another’s trademark. The Court granted certiorari in November to consider a dispute between VIP Products, LLC (“VIP”) and Jack Daniel’s Properties, Inc. (“Jack Daniel’s”) over VIP’s “Bad Spaniels” dog toy, which Jack Daniels contends infringes and dilutes its famous trademarks and which VIP asserts is permissible under the First Amendment. As discussed in a prior TMCA post, the dispute arose in 2014, after Jack Daniel’s sent a letter demanding that VIP cease all sales of its “Bad Spaniels” dog toy, which VIP had been selling since July 2013. A week later, VIP sought declaratory judgment in the U.S. District Court for the District of Arizona, arguing that it had designed the “Bad Spaniels” label to incorporate a few elements of the Jack Daniel’s label design, but had added a number of additional elements to make it clear that the product was a parody and entitled to First Amendment protection (for example, changing the Jack Daniel’s “Old No. 7 Brand Tennessee Sour Mash Whiskey” to “The Old No. 2, on Your Tennessee Carpet”). Jack Daniel’s counterclaimed, alleging trademark infringement, dilution, and unfair competition. The District Court ultimately granted Jack Daniel’s motion for partial summary judgement, finding VIP was not entitled to the defenses of nominative and First Amendment fair use, because it did not use Jack Daniel’s’ identical marks or trade dress. After a four-day bench trial, the District Court ruled in favor of Jack Daniel’s and permanently enjoined VIP from selling the “Bad Spaniels” dog toy. VIP appealed to the Ninth Circuit, which reversed the District Court on the grounds that: (1) the “Bad Spaniels” dog toy is an expressive work entitled to First Amendment protection, and (2) the District Court failed to require that Jack Daniel’s satisfy at least one of the two prongs of the Rogers test. VIP Prods. LLC. V. Jack Daniel’s Props., 953 F.3d 1170 (9th Cir. 2020); see also Rogers v. Grimaldi, 875 F.2d 994 (2d Cir. 1989) (holding that the Lanham Act only applies to expressive works if the plaintiff establishes that the defendant’s use of the mark either: (1) is not artistically relevant to the underlying work, or (2) explicitly misleads consumers as to the source or content of the work). On the dilution claim, the Ninth Circuit also reversed the District Court, because, although VIP used the Jack Daniel’s trade dress and bottle design to sell the dog toy, these elements were also used to convey a humorous message which was protected by the First Amendment, and thus “noncommercial.” Although Jack Daniel’s petitioned for a writ of certiorari in 2020 seeking review of the Ninth Circuit’s decision, the Court denied the petition. On remand, the District Court found that, based on the Ninth Circuit’s decision, the “Bad Spaniels” toy was entitled to First Amendment protection because Jack Daniel’s could not satisfy either prong of the Rogers test. The Ninth Circuit summarily affirmed. In August 2022, Jack Daniel’s again petitioned for a writ of certiorari asking the Court to consider the following questions: Whether humorous use of another’s trademark as one’s own on a commercial product is subject to the Lanham Act’s traditional likelihood-of-confusion analysis, or instead receives heightened First Amendment protection from trademark infringement claims. Whether humorous use of another’s mark as one’s own on a commercial product is “noncommercial” under 15 U.S.C. § 1125(c)(3)(C), thus barring as a matter of law a claim of dilution by tarnishment under the Trademark Dilution Revision Act. Apparently persuaded the second time around, the Court granted Jack Daniel’s’ petition and agreed to hear the case. In its writ, Jack Daniel’s contends that that the Ninth Circuit’s ruling “departs from the decisions of every other circuit to decide this question” and claims it “paves the way for companies like respondent to unleash mass confusion in the marketplace.” It appears that the International Trademark Association agrees and filed an amicus brief arguing: Since the Second Circuit’s decision in Rogers, all other circuits but the Ninth have faithfully limited Rogers to traditionally expressive or artistic works like movies, art, books, and the like. The Ninth Circuit’s decision below continues that circuit’s inappropriate (and concerning) steady expansion of Rogers to any product or service that merely contains discernible expression. This unwarranted expansion beyond the roots of Rogers creates a sharp circuit split on how to balance competing claims of trademark protection and free speech in the context of ordinary commercial products. The Ninth Circuit’s decision threatens a trademark infringement framework that has been intact and applied for nearly a century. Ultimately, if the Court sides with VIP, it would seem to represent a fairly significant expansion of how the Rogers test has typically been applied since it was first articulated in 1989. Notably, an expansion of the types of works covered under the Rogers test would likely leave brands with a narrower scope of protection when dealing with potential infringers claiming “parody” and “artistic expression.” Further, given that the Court is currently considering the Andy Warhol Foundation for the Visual Arts, Inc. v. Goldsmith case (which involves fair use in the copyright context and which the TMCA has covered here), the Court appears eager to define the role of the First Amendment in intellectual property cases. And the opinion in the Warhol case will almost certainly provide insight into the Court’s likely treatment of the issues in this case. We will be following this case closely, so keep an eye out for our eventual breakdown of the Court’s opinion.
January 9, 2023
Trademarks
Taco Tuesday: It's a Tasty Cultural Phenomenon Not a Trademark
More and more, we see trademark applications being filed for cultural phenomena, viral sensations and catchy hashtags. We’ve covered this topic before. Do you remember #covfefe? A recent non-precedential decision issued just after Thanksgiving once again confirmed that common laudatory phrases are often incapable of functioning as trademarks. The TTAB’s decision in In re Monday Night Ventures LLC was simple: TACO TUESDAY is indeed tasty, but it is not a trademark for beer. The Board found that TACO TUESDAY failed to function as a trademark for beer because it is a widely used message. In reviewing the Examiner’s refusal, the Board’s set out to answer the following question: We must assess whether Applicant’s proposed mark, TACO TUESDAY, functions as a mark based on whether the relevant public would perceive TACO TUESDAY as identifying the source or origin of the beer. To perform the failure-to-function analysis, the Board reviewed the evidence of record, which consisted of the specimens of use (including a beer menu), the mark as shown on a mockup of a beer can and lots of third-party use of Taco Tuesday submitted by the Examiner. The third-party use fell into two categories: (1) general uses of Taco Tuesday to refer to events on Tuesdays featuring tacos and drinks, including beer and (2) uses of Taco Tuesday on or in connection with beer. Notwithstanding the voluminous evidence of third-party use, the Applicant contended that the failure-to-function refusal was “illogical and incongruous” because TACO TUESDAY is not informational when applied to beer. The Board disagreed. After reviewing the evidence, the Board concluded that Taco Tuesdays often involve beer consumed with tacos. “Thus consumers are accustomed to encountering ‘Taco Tuesday’ in the context of beer.” While the beer menu specimen was adequate and did not show use of the mark in an informational manner, the Board found that Taco Tuesday cannot function as a trademark because of the environment in which it is perceived by consumers. While we surely did not need the Board to tell us that Taco Tuesdays and beer are a great pairing, the decision does provide helpful guidance for would-be trademark applicants of cultural phenomena. Common phrases are often incapable of functioning as trademarks, especially when applied to goods or services that are complementary to the phrase. It is a pretty safe bet that the USPTO would also likely reject TACO TUESDAY for margaritas, but would such a refusal extend to wine? I think wine and tacos are great together, but we’d be wise to see how many restaurants and wineries do a taco-wine pairing before fling an application. In fact, checking the internet before making a trademark filing for one of these types of marks is a great suggestion. While you might be first to file, that doesn’t mean the USPTO will let you have exclusive rights. A better strategy for one of these catch phrase trademarks might be to apply it to goods and services which are actually illogical and incongruous with the phrase. So go and enjoy some tacos and beer – it is Tuesday after all.
January 3, 2023
First Amendment
Eleventh Circuit: First Amendment Means MTV Floribama Shore Does Not Infringe FLORA-BAMA Trademark
In MGFB Properties, Inc. v. Viacom Inc., the U.S. Court of Appeals for the Eleventh Circuit recently sided with Viacom and its subsidiary MTV in a trademark action brought by the owners of the Flora-Bama Lounge, who alleged infringement by the television series MTV Floribama Shore. The court held that the title of MTV’s show was protected by the First Amendment, applying the familiar Rogers v. Grimaldi test, which assists courts in balancing Lanham Act protection against free speech. The Flora-Bama Lounge bills itself as “the most famous beach bar in the country.” The lounge faces Orange Beach on the Florida-Alabama state line. Established in 1964, the Flora-Bama Lounge’s owners operate a restaurant and liquor store that also use the Flora-Bama name and host entertainment and athletic events. In 2013, the owners obtained a federal trademark registration for FLORA-BAMA for bar and restaurant services, among other things. The lounge and the trademarks have made a splash in popular culture (or in the more legalistic telling of the Eleventh Circuit: “have been featured in artistic works by third parties”). Jimmy Buffett’s 1984 song Ragtop Day mentions a plan to “Get ourselves a cool one at the Florabama,” Kenny Chesney named a tune after the establishment, crooning: Sitting here at the Flora-Bama ’Bout to open up a big old can of Good times, unwind Fall in and out of love in the same night Can’t say I got a whole lot of cares I’m in the red neck Riviera It’s getting crazy, getting hammered Sitting right here at the Flora-Bama At the Flora-Bama Chesney packed 25,000 attendees on condo balconies, the beach, and boats near Flora-Bama Lounge for a 2014 concert he called “Flora-Bama Jama,” which was broadcast on Country Music Television, another Viacom channel. Fellow country music performer Neil Dover similarly penned a tribute to FloraBamaTime, where “you leave the world behind.” The lounge has also been described in books, films, and major news outlets. The conflict between the parties had its roots in Jersey Shore, MTV’s television series featuring 20-somethings who live in a beach house in New Jersey. Wanting to ensure that readers who have not watched Jersey Shore understand the show, the Eleventh Circuit explained how the Jersey Shore cast was perceived as belonging to a “sub-culture centered on a love of clubbing, taking care of one’s physical appearance, and a dedication to family and Italian culture.” That’s one way of putting it. Regardless of description, Jersey Shore was a hit that lasted six seasons and spawned several spinoffs. In 2016, MTV sought to revive the Jersey Shore franchise by developing a new series focused on Southern beach culture. That effort would become MTV Floribama Shore. The show’s name began with MTV’s goal of a Shore series that would highlight Southern beach culture. MTV also considered “Florida Shore,” but didn’t feel like that would capture the Gulf Coast setting and might be associated with Miami, which MTV thought had its own culture. MTV also considered “Gulf Shore,” but passed on that name because it sounded too much like another MTV show, Siesta Key. MTV settled on “Floribama” because that name would offer a sense of the subculture and part of the country MTV desired to feature. MTV was aware of the Flora-Bama Lounge during its development, mentioning it in an internal slide deck profiling the region. MTV also commissioned third-party marketing research, which found that 34% of 300 young people familiar with the region had heard the term “Flora-bama” and about half of them identified it as the lounge. Other research suggested that the term “Flora-bama” was either unknown or thought to refer strictly to the lounge. Just before MTV Floribama Shore was set to premiere in 2017, the lounge owners sent a cease-and-desist letter insisting that MTV change the name. MTV declined, the show premiered as scheduled, and it aired for four seasons. In 2019, after the second season aired, the lounge owners sued in Florida federal court, claiming trademark infringement and related torts. They alleged actual confusion, such as lounge patrons asking musicians if they had ever met cast members of the show or inquiring of staff as to when the cast would be in the lounge. According to the lounge owners, an elderly patron even criticized the lounge “for allowing MTV to air such a terrible depiction of the Flora-Bama.” The lounge owners also pointed to expert testimony claiming the show blurred internet search results for the lounge and the show, and that 22% of respondents to a survey were confused as to the sponsorship, approval, or affiliation between the lounge and the show. In response, MTV moved for summary judgment—and won. The Eleventh Circuit upheld the district court’s conclusion that the title MTV Floribama Shore was protected by the First Amendment and thus was a permitted use of the “Flora-bama” name. The court relied on the test for balancing trademark and free speech rights established by the Second Circuit Court of Appeals in Rogers v. Grimaldi—a test we’ve described before. Rogers holds that the title of an artistic work is not trademark infringement “unless the title has no artistic relevance to the underlying work whatsoever, or, if it has some artistic relevance, unless the title explicitly misleads as to the source or the content of the work.” Applying the first part of the test, the Eleventh Circuit concluded that the name MTV Floribama Shore was “well above the artistic reference threshold.” “Floribama” describes the subculture profiled in the series, as well as the geographic area where that subculture exists—“Flori” for Florida and “bama” for Alabama. Also relevant was the addition of MTV’s house mark, and “Shore” to tie the series to the Jersey Shore franchise. The court rejected the lounge owners’ contention that a trademark must be necessary to the name of an artistic work for the work to receive First Amendment protection. The court held that “a title will be artistically relevant when it is necessary to use the title” but that does not mean that “a title must be strictly necessary to be artistically relevant.” (And in the Eleventh Circuit’s view, it would be improper for courts to decide what forms of expression are “necessary” to an artistic work.) Next, the court analyzed the second part of the Rogers test—whether the MTV Floribama Shore title explicitly misleads as to the source of the work. In a previous decision, the Eleventh Circuit had refined this question as “whether (1) the secondary user overtly marketed the protected work as endorsed or sponsored by the primary user or (2) otherwise explicitly stated that the protected work was affiliated with the primary user.” The court concluded neither had occurred here. The court rejected the lounge owners’ survey evidence because there was no suggestion that any misunderstanding was engendered by an overt claim of affiliation by MTV. The court observed that the “MTV” house mark and “Shore” were added to the “Floribama” name, which undercut the lounge owners’ argument that the show’s name was intended to mislead. And although the owners charged that MTV’s use of the name was intentional, the court pointed out that even intentional copying of a mark does not supplant the Rogers test, a case in which a title received First Amendment protection even though it intentionally copied a mark. Finally, the court addressed a much-discussed footnote in Rogers, which provides that the test in Rogers would not apply when an artistic title is confusingly similar to other titles—the so-called “title-versus-title” exception. In the thirty-plus years since Rogers, no other circuit court has explicitly adopted the footnote’s rule. The Eleventh Circuit decided it need not resolve that legal question because the footnote exception didn’t apply. Here, the lounge owners’ Flora-Bama mark is not the title of an artistic work—it is a trademark used to identify the lounge and other businesses. The lounge owners sought to portray third-party use of the mark, such as by Kenny Chesney, as meaning that their mark was used as a title. The court rejected this theory, relying on basic trademark law. The third parties who used “Flora-Bama” in the titles of their artistic works did not do so to suggest that the works originated from the lounge. The titles identify what the artistic works are about, not who produced them. After all, Chesney might have been “sitting right here at the Flora-Bama,” but there was no evidence that the lounge was the source of his song.
December 29, 2022
Data Protection and Privacy
Universal Opt-Out/Global Privacy Control: Preparing for the New Online World
2022 has been a whirlwind year for cybersecurity, data, and privacy counsel who are navigating an expanding regulatory landscape and unique sets of legal requirements from numerous jurisdictions. This trend is likely to continue and grow more complex in the new year as additional states adopt and implement privacy laws. A growing trend across privacy legislation is requiring company websites to respond to universal opt-out mechanisms, also known as “Global Privacy Control.” If ignored, a business exposes itself to liabilities that can result in legal and financial consequences. As businesses look toward 2023, we encourage them to examine their compliance obligations in connection with universal opt-out mechanisms and if applicable, develop an implementation plan. Universal Opt-Out – The Basics For those who are unfamiliar with the term, universal opt-out is a mechanism by which consumers can exercise their right to “opt out” of a platform or technology processing their personal data for targeted advertising or of the sale of their personal data. In practice, a consumer sets their preferences in their browser or with a plug-in to “opt out” of data sharing. Once the preference is set, a signal indicating the consumer’s preference is automatically sent each time they visit a website. If required, the website operator must respond to that signal by opting the person out of targeted advertising, the sharing of their personal data, or other sharing limited by statutes and regulations. The website operator also must inform its vendors and other third parties with which the consumer’s information has been shared of the opt-out request and they must honor it as well. Current Legal Requirements The most time-sensitive legal requirements come from California. On January 1, 2023, California’s Privacy Rights Act (CPRA) will be in effect. Under the current draft implementing regulations, businesses that interact with consumers online are required to respond to opt-out preference signals as well as to offer another opt-out option. While the CCPA previously included a 30-day cure period for violations, this is no longer available come January 1. Colorado’s Privacy Act (“CoPA”) goes into effect on July 1, 2023, and contains a similar requirement to respond to universal opt-out signals by July 1, 2024. Colorado’s draft regulations anticipate that a universal opt-out could be achieved in other ways than through a browser or plug-in signal, such as through a do not sell list that website operators would be required to query. The Colorado Department of Law plans to release a list of approved universal opt-out mechanisms no later than April 1, 2024. Connecticut’s Data Privacy Act (“CTDPA”) includes a universal opt-out requirement that goes into partial effect July 1, 2023, and into full effect July 1, 2025. Other states are considering similar provisions in their data privacy legislation. While only time will tell how these regulations will play out and how companies will manage to comply with the requirements, the Sephora case highlights the ease by which a regulator can allege legal violations and the monetary and reputational consequences this can have. This past August, the California Attorney General’s office announced a settlement with Sephora, Inc. alleging, among many things, that Sephora failed to process users’ requests to opt out of the sale of their data through the Global Privacy Control. The AG’s office lauded its settlement with Sephora and AG Rob Bonta emphasized that, “I hope today’s settlement sends a strong message to businesses that are still failing to comply with California’s consumer privacy law. My office is watching, and we will hold you accountable.” Technical and Legal Challenges Currently, only certain internet browsers (DuckDuckGo, Brave, Mozilla Firefox) or a separately installed plug-in enable universal opt-out signals. Notably, Google Chrome and Apple’s Safari do not enable such signals. Without support from major browsers, the technical implementation of responding to universal opt-out signals is naturally haphazard. Without more consumers opting to opt out in this way, the business pressure on companies to conform with opt-out requirements may not be omnipresent. The regulatory pressure to conform with the rules, however, remains and cannot be ignored (see, e.g., Sephora). Consent management platforms such as OneTrust are working on helping their customers integrate universal opt-out into their existing consent management program. Effects of Consumers Opting Out and How to Plan for the World of Universal Opt-Out In the short term, consumers opting out of sharing their personal data can have immediate strategic and financial consequences for business. The growth of importance of first party data may also present new business opportunities. It is critical, therefore, to bring together key company stakeholders to best address these changes and properly prepare. No one wants to be caught off guard, and the sooner companies can bring together their legal, business, and data privacy teams to discuss these changes, the more time they will have to pivot, adapt accordingly, and strongly position themselves. As the industry navigates this “new normal,” companies can no longer rely on previous advertising and consumer data business models. This is a time to think creatively and utilize the collective knowledge of company decision makers to implement new solutions. Dorsey’s Cybersecurity, Privacy and Social Media Practice Group would be happy to assist in these discussions.
December 21, 2022
Domain Names
Forestall Phishing Forays with Sophisticated Domain Name Watching
With the holiday season upon us and online goods and services flying off the virtual shelves, companies should not lose sight of the increased risk of phishing and cyberattacks. Society’s reliance on online commerce means businesses are under immense pressure to ensure their website domain names provide a safe destination for customers. To do so, they must prevent attacks on themselves and their customers. Sophisticated domain name watching can provide an early warning of phishing attacks about to happen. According to a 2021 study from IRONSCALES, 81% of organizations around the world have experienced an increase in email phishing attacks since March 2020.1 Further, domain name registry Identity Digital recently reported that 92.9% of all of its abuse claims for Q2 2022 were related to phishing attacks.2 Due to advancing technology and the expansion of allowable characters which can be used in domain names, cyber attackers are now running sophisticated phishing schemes which are not only focused on the technologically-illiterate. See The Top 5 Phishing Scams of all Time - Check Point Software. Domain name fraud is being used to trick employees, customers, and business owners alike. Cybersquatting Cybersquatting occurs when an attacker purchases a domain name featuring a brand’s name and/or trademark and uses it for illegitimate purposes. Typosquatting Typosquatting is a form of cybersquatting in which an attacker purchases a domain name which contains typos or slight discrepancies from a legitimate brand. Ex: D0rsey.com; Dorseylawfirm.com Homoglyph Attacks Homoglyph (sometimes referred to as Homograph) attacks occur when an attacker takes advantage of the similarity between certain characters in Latin and non-Latin alphabets (such as Cyrillic and Greek) to register domain names which appear identical or very similar to the domain name of the legitimate brand. Ex: example.com vs. exαmple.com Once these fraudulent domain names are registered, attackers can set up fake websites and/or email addresses to impersonate brands and fool customers into trusting them. Often these fraudulent emails are used to entice unsuspecting users to transfer funds or interact with links which can result in data breaches or malware attacks. To proactively halt these attacks before they happen, companies can implement domain name watch services (including typosquatting and homoglyph watches) to alert them when a domain name is registered which may be of concern. For further information regarding how brand owners can implement good domain name practices to protect their brands, please see Jamie Nafziger’s article, Deepfakes, Fake News & Viral Hoaxes: How Good Domain Name Practices Can Help Prevent Truth Decay.
December 9, 2022