Σάββατο 20 Σεπτεμβρίου 2014

Digital Forgetting in the Age of Social Media: Establishing a Comprehensive Right to Cyber-Oblivion

Ioannis Iglezakis
Assistant Professor, Aristotle University of Thessaloniki


Abstract:
In the age of social media where it is almost impossible to escape your past on the Internet, the right to be forgotten enhances the ability of the individual to control the use of his or her personal data. Such a right has been recognized by the CJEU in the Google Spain case as far as search engines are concerned. With the adoption of the Data Protection Regulation by the EU it will form part of the EU legal framework in data protection.

Keywords: Data protection, digital forgetting, right to be forgotten, right to oblivion


1. Introduction

In the age of social media it is almost impossible to escape your past on the Internet, since every status update or photograph, and every tweet may be copied and/or reposted by other users or saved in Internet archives, such as the wayback machine1, and in cached pages2 or even – in case of photographs stored in the cloud – leaked online after an attack by hackers; as a result personal information may be available online, even if it has been deleted in its initial place (Mitrou/Karyda, 2012).

To address the issue of the Web that never forgets, jurists have proposed the introduction of a new digital right, a right to delete personal information from the Net (Mayer-Schönberger, 2009). This right draws its origin from the French and Italian law which recognize the right to oblivion that allows a convicted criminal who has served his time and been rehabilitated to object to the publication of his conviction and confinement.

In the digital world this right acquires a new substance; it is conceived as a right to delete personal information published in the web by data subjects, particularly in social networking sites. Some authors also consider this not as a legal right, but as a value or interest worthy or protection or as a policy goal to be achieved through law or through other regulatory mechanisms (Koops, 2011, Rouvroy, 2008).

The right to be forgotten in enshrined in Article 17 of the Draft Regulation on Data Protection (‘General Data Protection Regulation’, GDPR), which was presented in 2012 by the EU Commission and its adoption is still pending.

The introduction of this right has been the subject of much debate, for it is being criticized as a threat to free speech on the Internet (see, e.g. Rosen, 2012, Fleischer, 2011). Viviane Reding, Vice-President of the EU Commission describes this right as a modest expansion of existing data privacy rights. The Court of Justice of the EU with its decision of 13 May 2014 in the Google Spain case (C-131/12) confirmed this view, interpreting the provisions of Directive 95/46/EEC in such a way as to include a right ‘to be forgotten’ on the Net.4

2. Outline of the right to be forgotten

The provision of Article 17 GDPR basically includes a right to erasure of data that requires the controller to delete personal data and preclude any further dissemination of this data, but also to oblige third parties, e.g. search engines, etc., to delete any links to, or copies or replication of that data.5

In the initial Draft it was mentioned that this right has particular relevance when the individual made data available as a child. Although this provision was deleted after the vote in the Libe Committee, it is still a fact that a right to erasure of information has particular reference in cases where the information posted by young people in social media becomes obsolete when this person grows old. In more general, embarrassing information may be the subject of a right to digital forgetting that may protect against the negative use of information relating to the past (Costa, Poullet, 2012).

 This applies in five instances, which derive from data protection principles: a) where data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; b) where the data subject withdraws consent on which the processing is based or when the storage period consented to has expired and there is no other legal ground for the processing of the data; c) where the data subject objects to the processing of personal data; d) where a court or regulatory authority base in the Union has ruled as final and absolute that the data concerned must be erased; or e) where the data has been unlawfully processed.

The right to be forgotten which is enshrined in the GDPR is not conceived as an absolute right; thus, a number of exceptions restrict its ambit, the most important being the freedom of expression and information. There is consensus that such a right cannot amount to a right of erasure of history and turn our modern society into a society of ‘lotus eaters’ (Iglezakis, 2014), which would be the case if the Internet was programmed to forget, e.g. if Internet content was programmed to auto-expire (Fleischer, 2011). Consequently, the erasure cannot take place where the retention of the personal data is necessary for exercising the right to freedom of expression.

3. The current EU legal framework and the Google Spain of the CJEU

Authors have taken the view that the existing legal framework in the EU, i.e. the Data Protection Directive (DPD)6 does not establish a comprehensive right to effectively control the use of personal data with a view to erase them, but some provisions provide a legal basis for a limited recognition of the right to be forgotten (Ausloos, 2012).

The Court of Justice of the European Union (CJEU), on the other hand, found that the provisions of the Directive can serve as a legal basis for the right to be forgotten vis-à-vis search engine providers. In its decision on May 13 2014, in case C-131/12 (Google Spain SL, Google Inc. v. Agencia Espanola de Proteccion de Datos, Mario Costeja Gonzalez), it ruled that the ‘right to be forgotten’ is rooted in the provisions of Directive 95/46/EEC (Alsenoy et al., 2013).

In this case it was held that an Internet search engine operator is responsible for the processing that it carries out of personal data appearing on web pages published by third parties, i.e., content providers. The Court ruled that the data subject may request the removal of links, which are displayed in the list of results after a search on the basis of a person’s name.

In more particular, in response to the question whether the directive enables the data subject to request that links to web pages be removed from such a list of results on the grounds that he wishes the information appearing on those pages relating to him personally to be ‘forgotten’ after a certain time, the Court held that, if it is found, following a request by the data subject, that the inclusion of those links in the list is, at this point in time, incompatible with the directive, the links and information in the list of results must be erased.

The Court stressed out that even initially lawful processing of accurate data may, in the course of time, become incompatible with the directive where the data appear to be inadequate, irrelevant or no longer relevant, or excessive in relation to the purposes for which they were processed and in the light of the time that has elapsed.

It also added that it should in particular be examined whether the data subject has a right that the information in question relating to him personally should, at this point in time, no longer be linked to his name by a list of results that is displayed following a search made on the basis of his name. If that is the case, the links to web pages containing that information must be removed from that list of results, unless there are particular reasons, such as the role played by the data subject in public life, justifying a preponderant interest of the public in having access to the information when such a search is made.

This decision has had significant repercussions; it was criticized by Wikipedia founder Jimmy Wales who called it ‘astonishing’ and free speech advocates at the Index on Censorship said this ruling "should send chills down the spine of everyone in the European Union who believes in the crucial importance of free expression and freedom of information".7 Google received immediately after the decision was issued takedown requests, some of which are indeed ambiguous, such as the request of an ex-politician seeking re-election to have links to an article about his behavior in office removed and a man convicted of possessing child abuse images to have pages about his conviction wiped and a doctor asking negative reviews to be removed from search results.8

In order to cope with the flood of takedown requests Google launched a service to allow Europeans to ask for personal data to be removed; it created a a webform through which people can submit their requests for the erasure of links to information regarding them.9 This solution was criticized by EU regulators, since it restricted the removal of Internet links to European sites only and it notified the owners of websites that have been removed from search results when it proceeds to such removal.10

4. Perspectives
The CJEU ruling find direct application on search engines and concerns the right of the individual to erasure links to names of data subjects by a list of results displayed after a search is made on the made of his name. However, the court recognized that the data subject has to the right to object to the processing of personal data published on the Internet. As a result, data subject may invoke this ruling when filing takedown requests against content providers. It remains to be seen whether the right to be forgotten would acquire a more general scope of application even before the adoption of the Data Protection Regulation.






REFERENCES:
Alsenoy, B., Van/Kuczerawy, A./Ausloos, J., Search engines after Google Spain: internet@liberty or privacy@peril?, ICRI working paper 15/2013, online available at: https://www.law.kuleuven.be/icri/  and http://ssrn.com/link/ICRI-RES.html
Ausloos, J., The 'Right to be Forgotten' Worth remembering?, (2012)  Computer Law & Security Review 28, pp. 143-152.
Costa, L./Poullet, Y., Privacy and the regulation of 2012, (2012) Computer Law & Security Review 28, pp. 254-262.
Fleischer, P., Foggy Thinking About the Right to Oblivion, Privacy...? (Mar. 9, 2011), online available at: http://peterfleischer.blogspot.com/2011/03/foggy-thinking-about-right-to-oblivion.html.
Iglezakis, I., The right to digital oblivion and its restrictions (2014), Sakkoulas ed. (in Greek).
Koops, B.–J., Forgetting Footprints, Shunning Shadows. A Critical Analysis of the “Right to Forgotten” in Big Data Practice, (2011) scripted vol. 8, Issue 3, Dec. 2011.
Mayer-Schönberger, V., Delete: The Virtue of Forgetting in the Digital Age (2009), Princeton University Press.
Mitrou, L./Karyda, M., EU's Data Protection Reform and the Right to be Forgotten: A Legal Response to a Technological Challenge? (February 5, 2012). 5th International Conference of Information Law and Ethics 2012, Corfu-Greece, June 29-30, 2012, online available at SSRN: http://ssrn.com/abstract=2165245
Rosen, J., Free Speech, Privacy, and the Web that Never Forgets, (2011) 9 J. on Telecomm. and High Tech. L. 345.
Rosen, J., The Right to Be Forgotten, 64 Stan. L. Rev. Online 88, February 13, 2012, online available at: http://www.stanfordlawreview.org/sites/default/files/online/topics/64-SLRO-88.pdf
Rouvroy, A., Reinventer l'art d'oublier et de se faire oublier dans la de l'information? version augmentée, (2008) online available at: http://works.bepress.com/antoinette_rouvroy/5/ 


ENDNOTES:
1.       https://archive.org/web/
4.       Court of Justice of the European Union, case C-131/12 - Google Spain SL, Google Inc. v. Agencia Espanola de Proteccion de Datos, Mario Costeja Gonzalez.
6.       Directive 1995/46/EC.
7.       D. Lee, Google ruling ‘astonishing’, says Wikipedia founder Wales, http://www.bbc.com/news/technology-27407017
8.       J. Wakefield, Politician and paedophile ask Google to ‘be forgotten’, http://www.bbc.com/news/technology-27423527
9.       ”Google launches 'right to be forgotten' webform for removal requests”, theguardian, Friday 30 May, 2014, www.theguardian.com
10.   See J. Fioretti, Google under fire from regulators on Eu privacy ruling, Reuters, July 24, 2014.


Τετάρτη 17 Σεπτεμβρίου 2014

A German Minister has asked Google to reveal details of its search algorithm

By Liam Tung for The German View |
To address Google's "exceptional" power in Europe, Germany's justice minister Heiko Maas has called on the search company to reveal how it creates search engine rankings.
As Google and the European Commission go back to the drawing board over the company's controversial European antitrust proposal, Maas wants Google to give up a far bigger concession,telling the Financial Times Google had to become more "transparent" about its highly secret algorithm that underpins its search engine rankings.
Chances that Google will ever reveal any details of its secret search sauce to regulators and competitors is close to zero, but Maas said it was necessary to address Google's "exceptional" and "extraordinary" power in Europe over both consumers and market operators.
"When a search engine has such an impact on economic development, this is an issue we have to address," he told the Financial Times.
Google handles around 70 percent of web searches in the US, whereas in Germany and France it's closer to 95 percent, according to StatCounter. Comscore meanwhile estimated in February Google had about 75 percent of the overall European search market.
The most contentious aspect of Google's ongoing run-in with European competition regulators is the way it favours its own vertical search services. While earlier this year it seemed that Google's proposals to address the EC's concerns on that score would be accepted, the Commission has now asked Google to improve its suggested remedies. A further threat on the horizon for Google is a potential European investigation into Android, following complaints about Google's Play app store and the bundling of key Google apps with the free OS.
Maas, who is responsible for consumer protection in Germany, said that Europeans should not be afraid of Google as Mahia Döpfner, CEO of Germany publisher Axel Springer, said earlier this year. However the minister believes that Google's dominance in search allows it to unfairly promote its own business interests.
Maas also said that breaking up Google would be a "last resort", but that it is too early to begin considering such a move.

Κυριακή 14 Σεπτεμβρίου 2014

Intellectual property issues for start-ups

Ioannis Iglezakis, Assistant Professor,

Aristotle University



A. Introduction
At present there is a growing number of start-ups, and some of them in the high technology sector are valued at 1 billion dollars or more.[1]

In a startup, Intellectual Property (IP) or intangible assets are often more than 90% of the value of the company and that is not limited to patents, of course.[2] A company that does not develop any IP will find it hard to attract investors, since IP provides them security and leverage. IP also helps companies to secure financing, using IP as collateral.[3]

As it is evident, the legal protection of IP rights is of paramount importance for a start-up, to protect its assets and maintain a competitive advantage. It needs, therefore, to be ensured that the company has exclusive rights to its IP and is not using technology or other assets (e.g. trademarks) belonging to competitors. It should also be confirmed that the company’s IP rights are legally protected with appropriate licenses.

B. Intellectual Property

Intellectual Property protects applications of ideas and information that are of commercial value.[4] There are various types of rights which are included in IP, but the main categories of this branch of law are two: copyright and industrial property. Certainly, the most important types of IP used by start-ups are patents, copyrights, trademarks, and trade secrets. National laws protecting IPR vary among different countries, so we will describe the laws of Greece and the EU in this area.

1. Patents

Patents are granted in respect of inventions which are new, which involve an inventive step and which are susceptible of industrial application (article 5 of Law 1733/87 as amended). In Europe, patents are issued by the state or a national patent office after a substantial examination of their validity, the duration of the validity of the patent is twenty years from application; and the invention should be publicly described in the patent specification.[5]

Patents afford a right to their owner to prevent others from using the invention for the duration of the patent. Thus, it is the strongest means of protection of all IP and may lead competitors in peril, if they use an invention for which a patent was granted. Therefore, a start-up should proceed to a clearance search in the patent office and to see whether a product that it develops is not already patented.

Patent protection is particularly important for a start-up to protect its business and its invention from competitors and simultaneously, and to avoid the risk of facing claims of patent infringement by competitors and third parties.[6]

Software may not benefit from the rigid protection of patent law under Greek law, which provides that computer programs shall not be regarded as inventions (Article 5 (2)(c) of Law 1733/87). This is line with Article 52 of the European Patent Convention which excludes from patentability programs for computers as such. However, this wording gave grounds to grant a patent for software

However, the European Patent Office grants patents for computer programs, if they provide a technical contribution to prior, that is, a further technical effect that goes beyond the normal physical interaction between the program and the computer. Examples include a reduced memory access time, a better control of a robotic arm, etc.

2. Copyright

Copyright grants protection to authors, artists and other creators for their literary and artistic creations, commonly referred to as works. The requirement for granting protecting is that a work is original. In case of computer software the standard for originality is very low. According to Article 1 (3) of Directive 2009/24, a computer program shall be protected if it is original in the sense that it is the author’s own intellectual creation.

In contrast to patents, copyright-protected works are not required to be registered with a state authority. Copyright is afforded when a work is created, but it is hard to prove authorship. Copyright gives the owner or licensee the exclusive right to reproduce, distribute, modify, publicly perform and publicly display a work.

In contrast to patents, copyright protects the expressions of an idea, not the idea or a concept. Thus, the source code of a computer program is eligible of copyright protection, but not the algorithm or the abstract idea or mathematical method on which it is based.

3. Trademark

Trademarks are distinctive signs, i.e. words, names, symbols, slogans, etc., that identify certain goods or services produced or provided by a company.  A trademark when associated with a successful product or service it becomes an asset or prime value to a company.[7] An outstanding example is the word ‘Google’ for Internet searching, the bitten apple logo for computers, etc. Their protection stands as long as they are used and they may continue to be used forever, as there is no limit on the duration of this right.

Under Greek Law, protection is afforded to registered trademarks and also to non-registered trademarks, i.e. to distinctive signs. 

Trademark law prevents third parties from using a trademark which is confusingly similar to the trademark of a start-up.

4. Trade secrets

The law also affords protection to trade secrets, i.e., secret business information, technological know-how, ideas for new products and markets, information about customers, finance, etc.[8] Examples of trade secrets in the high tech area include customer lists, source code, semiconductor manufacturing processes, etc.[9]

Protection of trade secrets is granted by provisions of unfair competition law in Greece, while in common law countries it takes the form of sui generis protection. The said protection is rather limited, since it prohibits the misappropriation of trade secrets, which leaves certain acts, such as reverse engineering, unpunished.

C. Specific Issues

 Something that happens very often is that IPR are developed by the founders before the establishment of a start-up or contractors after its establishment. Generally, in such cases a license should be granted, otherwise rights are not transferred to the start-up, with the exception of software or an invention developed by an employee, which under Greek law are owned by the employer. The failure of a license may lead to legal disputes.

Another problem which may occur is the lack of a strategy for patent protection of products or services. Many start-ups do not file for patent registration due to ignorance of the advantages offered by such protection or simply, because of indifference. Under Greek law (Article 5 of Act 1733/1987) and law in most countries patent protection is not granted for an invention that has been public disclosed, e.g. when a technical paper has been published or the invention was demonstrated at a trade show, with the exception of recognized exhibitions. Disclosing an idea to the public should be carefully planned, because the risk is eminent that rights to file a patent and to protect trade secret may not be enforceable, since patent law requires that an invention is new and not made public, while to claim right on trade secrets requires that the start-up has taken appropriate measures to keep business information secret.

Trademarks may be valuable for start-ups, so their selection should be carefully planned. A generic trademark, e.g. eshop.gr, may be ‘catchy’, but could also turn out to be descriptive and lose the ability for protection.

The use of an infringing trademark could lead to a costly litigation that may worsen the financial situation of the start-up. The cost of changing a logo may also be very high and inhibiting development. Therefore, a search in the trademark office and in a search engine should be carried out, to ensure that a trademark used by the start-up does not infringe third parties rights.

Errors in licensing may prove devastating. An IP license from a third party with a narrow field of use may require renegotiation as the start-up’s products evolve. In that case, the third party can charge a premium for the expansion of the field of use. So, e.g. in copyright law the rule is that a license is not valid for future methods of exploitation.

Similarly, the license to use a third party’s IP should foresee or not preclude the case of a merger; otherwise the merger may fail, as it will miss important assets.

The licensing of a start-up’s own IP should be carefully reviewed, so that the start-up may tie-up fields of use not exploited by the license in order to exploit its technology; and also to grant non-exclusive licenses so that it would not be prevented from using its own technology.

A big risk for a start-up is the use of trade secrets or other confidential information or IP by the founders of the start-up from a prior employer. A lawsuit against the start-up will hinder the functioning of the company, which may be liable to pay compensation and their founders be subject to criminal liability.

Software development is increasingly based on open software products and many start-ups owe their success to its use. However, open source licenses such as the General Public License require that companies using open source software licensed under the GPL must make available source code of the start-up’s software to its licensees and to permit such licensees to modify and redistribute the start-up’s software without charge to third parties. This viral effect of open software has its price: a start-up may find it hard to find investors or sell assets, since investors and acquiring companies demand that no such software is included in the relevant agreements.


Conclusion

To sum up, I would like to stress the following points:
       

  •          A start-up should exercise due diligence with regard to choosing a trademark or brand name, because this can come to be a valuable asset of the company. Therefore, before adopting a trademark or a brand name one needs to conduct a search in a trademark database, such as the TMview[10], and a search for a brand name in a database, such as the geminet.gr in Greece.[11]

  •              To ensure that the IP rights of the start-up are protected, contractual agreements should be signed with all contributors to the creation of an invention or software, excluding employees. These agreements should provide for the transfer of IP rights to the company. In addition, non-disclosure agreements should be agreed upon with co-founders of the start-up, employees, consultants and others, to establish trade secrets protection.

  •              To avoid losing patentability an invention should not be publicly disclosed. According to patent law, an application for a patent may be dismissed if there has been prior use or public disclosure of the invention.   

  •            To protect trade secrets do not disclose essential details of developed technologies and innovations.







REFERENCES:
Cornish & Llwelyn, Intellectual Property: Patents, Copyright, Trade Marks and Allied rights, 2007
DLA Piper, Intellectual Property: Critical issues, http://www.nvca.org/index.php?option=com_docman&task=doc_download&gid=367&
Johnson, A., Intellectual Property for Startups in the Real World, http://gust.com/blog/2012/01/04/ip-startups-real-world/
Juetten, M., Protect Your Intellectual Property -- Before It's Too Late http://www.forbes.com/sites/groupthink/2014/06/03/protect-your-intellectual-property-before-its-too-late/
Kaviar, E. G. J., Five Intellectual Property “Landmines” Startups Face, http://www.wolfgreenfield.com/files/kaviar__5_intellectual_property_landmines_startups_face_copy1.pdf
Rajabali, A., Three Intellectual Property Issues that Startup Founders Can Avoid, online available at: http://startupcalgary.ca/2014/01/three-intellectual-property-issues-that-startup-founders-can-avoid/



[3] E. G. J. Kaviar, Five Intellectual Property “Landmines” Startups Face, http://www.wolfgreenfield.com/files/kaviar__5_intellectual_property_landmines_startups_face_copy1.pdf
[4] Cornish & Llwelyn, Intellectual Property: Patents, Copyright, Trade Marks and Allied rights, 2007, at 6.
[5] Cornish & Llwelyn, at 7.
[6] Kasdan et al, Intellectual property for startups.
[7] Cornish & Llwelyn, at 9.
[8] Cornish & Llwelyn, at 10.
[9] DLA Piper, Intellectual Property: Critical issues.