Friday, January 25, 2008
Thanks to the Sponsors
Larkin Hoffman Daly & Lindgren, Michael Fleming
Gray Plant Mooty, Jennifer Debrow
William Mitchell College of Law, Chris Kunz
National Arbitration Forum, Kristine Dorrain
Oppenheimer, Wolff & Donnelly Law Firm, Bob Beattie
Putting "Winter" Back into the Winter Working Meeting
Some of the new members include:
Alan Wernick
Chicago, IL
Karen King
Wilmington, DE
Jeff Aresty
Boston, MA
[I'll keep adding as I meet new folks]
Thursday, January 24, 2008
Impromptu Thursday Night DInner at Fogo de Chao
Winter Working Meeting Overview
I am really looking forward to welcoming all of you to Minnesota in just a very few days now -- Per the request of a number of you who decided that if you're going to Minnesota it might as well be REALLY cold, I've tried my best to get the big thermostat turned down. No guaranty, but it might actually be a cold-spell next Thursday, so bring a good coat. (And, remember that you'll have cars and busses for most everything you need to do, so don't be overly worried, OK?)
Here is our current draft of the meeting detail for the upcoming Winter Working Meeting here in Minneapolis. You'll note it's set up in the new format Lisa and I discussed with you a few weeks back -- Friday is "Project Day" and Saturday morning is reserved for more traditional subcommittees.
I need any of you who are shown here as being responsible for any of these meetings to get back to Lisa and I with any changes you want made to your project names or descriptions. (In a few cases there are no descriptions, so please help us to fill them in if you are in charge of such a project.)
For those of you who were looking to schedule a traditional subcommittee meeting on Saturday AM, look to see if we've accommodated you. If you did need to meet as a subcommittee (and we have not scheduled you), please let us know quickly. If we have set you up for a slot for your Saturday subcommittee meeting, look at whatever description we've provided and comment accordingly if changes are desired.
Finally -- Look at all of the things that are happening at the same time. We tried to guess how to avoid significant conflicts of projects happening at the same time which should be at two different times, but no doubt there are going to be concerns you can raise on that point. Let us know, and we'll see if we can figure out a fix.
There are still some open slots -- In particular, we have not scheduled the 'big' room at all for breakouts, so we've got more room here (i.e., 2 more project slots and one more subcommittee slot). Given the projected number of attendees (and our recollections of how the last few WWMs went), we're actually thinking that maxing out at about 4-5 slots at a concurrent time is the right number. Still, if a case can be made for expanding that we're all ears.
Finally, please understand as always that Lisa and I will be working our darndest to accommodate what we can, but there are still laws of physics and the like that must be obeyed. In other words, if we come to a conclusion that we're going to have to do something in some particular way, I'm hoping that we'll all live with it, learn how to do this better next time, and move on.
PLEASE PLEASE PLEASE -- Let us know of your requests for changes by end-of-business on Friday (a/k/a tomorrow!).
Cheers,
Michael
Friday, January 18, 2008
CAIT Agenda for Winter Working Meeting
We will be meeting on Friday (January 25), jointly with the Internet Law Subcommittee, to plan a program for the ABA Business Section Spring Meeting, currently entitled "Blurring the Line Between Work and Play: Updating the Rules for Employee Use of Internet and Web 2.0 Technologies". This program is our stepping stone to preparing a revised version of Vince Polley's book published by the ABA in 2002, entitled "Employee Use of the Internet and E-Mail, a Model Corporate Policy." We will be looking for volunteers to help develop a new model corporate policy and to draft commentary for the publication. That new policy will take into account issues that were barely visible in 2002, such as the rampant use by employees of blogs, instant messaging, social networking and free web applications both inside and outside of corporate firewalls. We are interested in collecting as many sample corporate policies as we can find, so if you have one or can get one that you can share, please send it to me or bring it along to the meeting.
Another ongoing CAIT project is the development of a comprehensive checklist, with commentary, of IT issues in mergers and acquisitions. Given the pivotal role that IT plays in the operation of any sizeable company, parties negotiating and structuring a corporate divestiture must consider the treatment to be given to its IT needs. We have an excellent early draft, focusing on categories such as negotiation of the purchase and sale agreement, transitioning from a highly leveraged IT infrastructure, assignment or allocation of third party IT rights, setting up a due diligence review of IT contract rights, and the post-closing relationship between the parties. We will welcome your input and assistance in moving this project to completion, and possibly designing a program to be presented at a future Business Section meeting. We will discuss this at our regular CAIT meeting on Saturday morning.
Other current or potential new projects that we will discuss on Saturday may include:
(1) development of form data transfer agreements for cross-border transactions;
(2) review of IT security issues arising out of the use by corporations of software under mass market licenses and consideration of whether questionable onerous clauses should be enforceable;
(3) preparation of articles or podcasts on discrete but related issues such as blogging guidelines for businesses, the corporate "cybersmear" and online reputation monitoring in the face of the rise of a new breed of search engines such as ZoomInfo, challenges to corporate record management policies in the face of new electronic communication practices, and safe harbors afforded by the Communications Decency Act; and
(4) issues relating to the outsourcing/offshoring of first level document review in an era of eDiscovery.
Looking beyond the Winter Working Meeting, if you have an idea for 15 minute presentation for the CAIT subcommittee meeting at the ABA Business Section Spring Meeting on April 10 in Dallas, please let me know as soon as possible. We have an opportunity to get information into the Spring Meeting program guide if we have the information by this Friday, January 18. Please also put on your thinking caps and send me other ideas for projects that would fit within CAIT's scope.
Best regards, and bundle up for Minneapolis.
Bill
Agenda for IP Subcommittee at the Winter Working Meeting
We wanted to follow up on our last e-mail from November to give you a brief glimpse of what will be happening in Minneapolis next week:
You should have received by now the November 2007 issue of The Business Lawyer, which contains the Annual Survey of Cyberspace Law. Both John and Kristine devoted a lot of time last year to preparing the Overview of 2006 Cyberspace IP-related cases. The Cyberspace Committee would like to make this an annual contribution, and we are looking for Subcommittee members who would like to see their names in print. Start collecting your nominations for 2007 Cyberspace IP cases now and either bring them with you to the meeting or e-mail them to us ahead of time. We will compile them and spend some time discussing them in Minneapolis as we have in past years at the Winter Working Meeting. This will serve both as a useful review of 2007 Cyberspace IP case law developments as well as getting more people involved in this project.
We will also spend some time discussing possible new projects, so bring any thoughts, suggestions or problems that need some work with you (or send them to us via e-mail ahead of time). Some thoughts include:
- The advent of social networking and its implications on web development; including, how open source is being integrated into more development platforms to encourage community development efforts. If others are interested in delving more deeply into open source issues as related to social networking, we will discuss project and program possibilities;
- Digitization of currently available works (for instance, the taking and display of digital photos of historically significant works) and whether or not these newly digitized works are mere copies of the underlying work, or are derivatives, or something else, and the implications on copyright term. We are interested to hear if anyone is currently addressing these sorts of issues in their practice, and how they are dealing with them;
- Possible discussion or program or article on common errors, misconceptions, etc. in cease and desist letters. All you have to do is take a look at http://www.chillingeffects.org to see what we mean;
CIPerati (the IP Subcommittee’s electronic newsletter) is always looking for content. Typical articles are reasonably short (1,000 – 2,000 words) preferably continuing useful, practical content on Internet intellectual property topics. Content can be recycled from law firm or other organization newsletters (with permission), or can be original submissions. If you have written or have seen something that you think fits and want to see it published, you can contact Raphael Guttierrez (rguttierrez
We hope to see many of you in Minneapolis.
Kristine Dorrain and John Ottaviani, Co-Chairs
jottaviani
kdorrain
Tuesday, December 11, 2007
Source Code May Set Us Free
Of course, Minnesota is not the only state where this has been brought up in a defense motion to suppress. I understand that to date the manufacturer of this particular device has refused to grant access to the code, although I would welcome corrections to that understanding since I've only learned it through indirect sources.
Regardless of the facts or outcome of the particular battle between the DUI bar and the manufacturer (which in the end is not a battle we're well equipped to analyze other than as it deals with source code), the Cyberspace practitioner should already be well equipped to understand the fundamental pieces of this dispute. The manufacturer is undoubtedly claiming a right to maintain its source as a trade secret, and has so far only allowed its software to be distributed in object code (or lower) format that is not reviewable by human beings. That may well be its right under trade secret law (although we must leave open the possibility of arguments to be made on public policy grounds, or that somehow the manufacturer in this case waived its rights). Some, on the other hand, might argue that a business model based on proprietary code is not a wise one to follow where courts are more and more willing to demand openness. Could this manufacturer find its business model is ultimately a reason for a competitive manufacturer with a non-proprietary business model to step in and take business away? It all remains to be seen of course, and it's an interesting intersection between our world and another one.
Saturday, December 08, 2007
DC Bar Pipes Up on Inadvertent Disclosure of Metadata
The usual admonition to the lawyer doing the sending was there. Pay attention, learn what metadata is, and remove it if it might disclose privileged or otherwise confidential client data -- failure to so remove might itself be an ethical violation on the part of the sending lawyer. No controversy there.
The interesting part is that DC has joined the small chorus of states that have come out contrary (more or less) to the ABA's opinion on what the lawyer on the receiving end should do. Recall that the ABA's point is that the rules are essentially silent on taking advantage of metadata that an adversary should have removed from a document, although they do not go so far as to formally bless the practice. The abstract for Formal Opinion 06-442 (August 5, 2006) Review and Use of Metadata states, "The Model Rules of Professional Conduct do not contain any specific prohibition against a lawyer’s reviewing and using embedded information in electronic documents, whether received from opposing counsel, an adverse party, or an agent of an adverse party." But, at least two other states have formally come out against this view, Alabama and New York. We summarized those positions here. Alabama, for example, strictly prohibits mining of an opponents metadata: "Absent express authorization from a court, it is ethically impermissible for an attorney to mine metadata from an electronic document he or she inadvertently or improperly receives from another party."
The DC bar has struck a somewhat less harsh standard. "A receiving lawyer is prohibited from reviewing metadata sent by an adversary only where he has actual knowledge that the metadata was inadvertently sent." So, if the receiving lawyer is equally ignorant of how this inadvertent disclosure of metadata occurred, the receiving lawyer is free to use the data!
But, I am not sure how that plays out in practice, and even the opinion seems to acknowledge this. If you see data in the received document that is clearly unintentionally disclosed because it's obviously of a nature that the other side wouldn't want you to know, you're essentially deemed to have the actual knowledge cited in the rule.
Such actual knowledge may also exist where a receiving lawyer immediately notices upon review of the metadata that it is clear that protected information was unintentionally included. These situations will be fact-dependent, but can arise, for example, where the metadata includes a candid exchange between an adverse party and his lawyer such that it is “readily apparent on its face” that it was not intended to be disclosed.
One might think that pretty much anything you might find in an adversary's inadvertent disclosure that you might find useful in your then-current dispute or negotiation or whatever is going on would fall in the category of stuff that the other side would have not wanted disclosed. Thus, the actual knowledge standard is probably only helpful to the extent meaningless or valueless information is inadvertently disclosed, which might avoid an ethics battle over trivial issues.
So, for the most part, DC lawyers are on notice that if they find meta-goodies in the other side's documents, they must immediately stop using it or examining it, and must "notify the sending party and abide by the instructions of the sending party regarding the return or destruction of the writing."
(I especially liked one aspect of this issuance, which was to clearly distinguish documents created by the other side for purposes of the inter-lawyer discussions versus documents being delivered under a discovery or other court order. In short, if it's evidence, you can't delete the metadata before you send it to the other side, since the metadata is itself part of the evidence. One would hope that this would evident without explanation, but with the ubiquitous use of metadata scrubbers coming into play now we should be careful to avoid unintentionally using them where inappropriate!)
It's also pretty late notice, but ALI-ABA, one of the educational arms of the American Bar Association, is giving a webinar entitled "Confidentiality and Ethics in a Wired World." Check it out soon, since it fires up on Tuesday December 11.
Saturday, October 27, 2007
"To" vs. "BCC": An Oldie but Goodie Strikes Again
I can't vouch for this story other than what we read here, but for what it's worth it's a good reminder to us all. There are reports out that an email was sent out by the US House Judiciary Committee to a group of people who had sent in anonymous notes to a whistle blower tip-box. The email was reminding all of how their identities were going to be kept secret.
Of course -- You guessed it -- The email was sent simultaneously to 150 anonymous tipsters by putting each of their email addresses into the "TO" field. Thus, everybody on the mailing list now knows the email addresses of the other 149. (Plus, all of the recipients were probably annoyed at having to scroll down through 7 inches of addresses before they got to the message!) The problem would have been mostly avoided by simply putting the recipients' addresses into the BCC field rather than the TO field. (Even then, the ISP that originally processes the email from the sender certainly has all of the BCC list on its logs, at least for some period of time, so it's not a totally safe maneuver.)
Without getting into the almost certain political fun that will follow, we can take this as a lesson. While we all work to stay up to date on the most cutting edge of exploits and security tactics, don't let the old ones fall out of sight and out of mind. The oldies but goodies are just as likely to bite you today as they were when they were new.
Monday, October 08, 2007
Electronic Contracting versus Laziness
In each of these matters, one party set up a system to implement something electronically, either through incorporation in one 'contract' of another set of terms posted on the Web, or through the use of a purported click-through system. But, the party who found himself on the enforcement side of those purported terms or contracts challenged their incorporation or enforcement. Let us take a quick look at two of these examples.
In Federal Trade Comm. v. Cleverlink Trading Ltd., 2007 WL 2875626 (USDC N.D.Ill. No. 05 C 2889), the FTC was doing battle over the remaining assets of the losing defendant in a CAN-SPAM enforcement action. At issue was whether a contract that Cleverlink's former credit-card service, Oceanic, claimed was in place would give the erstwhile Cleverlink's money to that provider or leave it for the FTC. Oceanic and its leader, a Mr. Sholes, admitted they had no signed copy of the contract. But, they did claim they sent an email to Cleverlink that contained a link to an application for the service. "Sholes contends that Cleverlink would have had to click an "Accept" box and then digitally sign the document. [Later], Sholes sent an email to his attorney containing lines of computer code. Sholes stated in the email that the lines of code show that an email was sent to Cleverlink on March 11, 2005 with information on the processing agreement.
One might then hope that Mr. Sholes would have put his computer folks on the stand, maybe to do so little as to authenticate the business records purportedly portrayed in that email, or even better to explain what the email might mean and why. But, I can only gather that he rested his case on nothing more than his email. As we might guess, that did not cut it.
Without explanation, this Court cannot understand the lines of computer code in Sholes' email. Although Sholes stated in his email that the code lines came from Oceanic's servers, he had no first-hand knowledge regarding how and from where the code was retrieved. Sholes also could not interpret the code lines and explain how they can be read to prove that an email was sent to Cleverlink with a link to the [agreement]. Relief Defendants have provided no affidavit or testimony from anyone with actual knowledge of how and from where the code lines were retrieved. Likewise, there is no affidavit deciphering the lines of computer code. Even if the lines of codes proved that an email was sent to Cleverlink, [the card provider] still would be several steps from establishing that Cleverlink accepted the [agreement] submitted to the Court. First, there is no evidence that Cleverlink responded to the email or otherwise visited Oceanic's Web site. Sholes testified that any such evidence was deleted from Oceanic's servers before the FTC served Oceanic. Second, there is no evidence that whatever document was linked in Sholes' email contained the increased chargeback fees [at issue in this matter]. In this regard, Sholes did not retain a copy of the [agreement] and has indicated uncertainty regarding its exact terms. In the end, [Oceanic has] no competent evidence that Cleverlink electronically accepted the terms of the MPPSA.
So class, can you go through that last paragraph and put together a check-list for your next client who plans to proffer an electronically-solemnized agreement in court?
(Thanks to committee member Eric Goldman for pointing this one out to me.)
The other case in mind is Manasher v. NECC Telecom, USDC E.D. Mich., No. 06-10749, 9/18/07). Here, telephone company NECC attempted to incorporate terms in the parties' contract that NECC had posted on the web -- A technique our Cyberspace folks have viewed favorably, but only if the incorporation is clear and understandable, and is done in a manner where the other party is clearly shown to have taken an action to agree. Here, the telephone company did just about everything it could to do it incorrectly. It signed up the customers over the phone without mention of a contract, it started to provide the services without any need for the customer to indicate agreement with terms, and it tried to incorporate its web terms by burying a line deep inside of the mailed invoice:
After the phone service began, Plaintiffs received an invoice. The second page of the invoice has five boxes containing five statements. The titles of the five statements are: (1) Recurring Fee; (2) Referral Discount 5%; (3) Preferred Customer Plan 'PCP,' Standard Customer Plan 'SCP;' (4) Rates; and (5) Agreement (Disclosure and Liabilities). [Motion, Exhibit D and E]. The fifth box, containing the statement regarding the 'Disclosure and Liabilities' is at issue. The statement provides "NECC's Agreement 'Disclosure and Liabilities' can be found online at www.necc.us or you could request a copy by calling us at (800) 766 2642."
NECC argued that this was adequate to incorporate the text of 'Disclosures and Liabilities', which was in fact a set of purported contract terms including an arbitration clause that was at stake in this suit. The court did not agree.
The language does not betray a clear intent that the Disclosure and Liabilities Agreement be considered part of the contract between the parties. NILAC, supra. Nothing in the statement clearly indicates that the Disclosure and Liabilities Agreement applies to the service contract between the parties, that it forms any part of the agreement between the parties, or that it is intended to be incorporated into the agreement between the parties. The statement merely informs the reader of where to find "NECC's Agreement 'Disclosure and Liabilities.'" Further, the statement is the last of five statements, written in plain text, on the second page of the invoice. There are no allegations of any other references to the Disclosure and Liabilities Agreement either in writing, or in the verbal dealings with Defendant. Thus, the Disclosure and Liabilities Agreement is not incorporated by reference....
I believe that had each of the parties setting up the systems in the above cases simply followed, both in their legal analysis as well as in their implementation, the simple principles our group's authors have long espoused, none of this would have come to pass (for them at least...). If you haven't reviewed them recently, take a new look at the two seminal articles published by members of our Committee -- The original Click-Through article, and the later Browse-Wrap article. Professor Christina Kunz and her team of authors in each article have provided clear pathways towards successful implementation.
Of course, it's up to each of you lawyers advising your clients to ensure that these principles actually get followed on the ground in a meaningful manner. Our jobs do not end when we've written text of the agreements. We must be aware of the process used to get those contracts in front of others, and challenge those processes if they do not lead to clean and admissible evidence. Alternatively, if we allow our clients to take lazy ways through these processes, we are likely to be getting called out later when the contracts fail to be enforced because they were never entered into in the first place!

