Sunday, August 07, 2005

Committee Face Book

To help new members know who's who, we have created a sister blog that contains good "face shots" of committee members. Please check out the pictures.

If any of you are not pictured, and you'd like your picture added, please track down Fleming or me, and we'll take a photo of you and add it.

If any of you who are pictured don't want to be, let us know, and we'll take down your picture.

And the coffee was excellent


Fleming and I made the pilgramage to Chicago's coffee palace, Intelligentsia. The coffee was so good, we didn't even mind the $20.00 we spent in cab fare to get there and back.

We started with an order that confused the gal behind the counter; we each ordered a single espresso and a single macchiato. We quaffed those very quickly, and immediately followed up with another order. Fleming went for the latte pictured here. I ordered a traditinal cappuccino.

We sat and enjoyed the place for a bit, and then we headed back. I couldn't leave without taking a bit more of the store with me. We'll see how well the pound of whole bean espresso does in my home espresso machine.

Vince Polley's "Retirement/Thank You" Gift


At the Cyberspace Dinner, the Committee presented a retirement/thank you gift to Vince Polley to say thanks for his tremendous service as a member, and then Chair, of the Cyberspace Law Committee. As Hank and Michael Fleming described in lengthy detail (see earlier post), the group finally agreed upon a very low-tech gift--a book!

Food, Friends and Free Flowing Beverages






The Cyberspace Dinner was one of the best ever. The evening started with (SURPRISE!) an open bar, courtesy of the law firm Gordon & Glickson. (Thanks Steve). A big thanks also goes to Jackie Scheib for all the hard work she put into setting up the dinner at Wildfire.

Rotenberg Accepts Cyberspace Excellence Award

Last night, Marc Rotenberg of EPIC, graciously accepted the third annual Cyberspace Law Excellence Award. I had the privilege of sitting with Marc at dinner. We had a very lively conversation about privacy, security, notification of consumers about security breaches, goings-on at the Department of Homeland Security, and my reporter friend Declan McCullagh.

It was a thoroughly enjoyable evening.















Cyberspace Committee Dinner



A great time was had by all, as we awarded the Cyberspace Award for Excellence, honored our departing chief, and welcomed the new boss. Let us remember the night with a few photos.

Marc Rotenberg



Mark, Michael, Candace and Vince



Susan and Jason Epstein brought along their new twins



Jason holds our Committee's newest member



John and Chris



Don, Jackie and Don's spouse Diane


Elizabeth and Rafael



John, Elizabeth Cole (Australian attorney practicing in Shanghai), and Hank



Brad and Jane

[more to come...}

Wi No WiFi in Chi?

Actually, we have plenty of WiFi in our meeting space (thank you Business Section!). What I refer to is the new op-ed (registration required) from the NY Times about the town of Hermiston, Oregon and surrounding environs. The city has contracted with a private provider to set up what appears to be the world's largest WiFi Hotspot -- no cost service over a 600 square mile area.
Driving along the road here, I used my laptop to get e-mail and download video - and you can do that while cruising at 70 miles per hour, mile after mile after mile, at a transmission speed several times as fast as a T-1 line. (Note: it's preferable to do this with someone else driving.)

Author Nicholas Kristof noted the irony of a rural area in Eastern Oregon pulling this off while bigger cities are still stuck in the mud. I suspect we shall see this issue (or similar concerns about next generation wireless broadband such as WiMax) coming up more and more in the next years.

Saturday, August 06, 2005

CLE PROGRAM: Sailing in Dangerous Waters















E. Michael Power, Roland Trope, Francoise Gilbert

The panel members used the metaphor of a submarine to describe data management and its risks to members of boards of directors. The panel provided a good overview of the various sources of law that make data security an increasingly important issue for companies. Moreover, the panel argued for increased attention to these issues by Boards of Directors of large and small companies.

This session demonstrated how data, its management, and security, is a common thread that runs through many of the programs at this year's meeting. The lack of attention to data management is a common source of many coroprate challenges:

  • data privacy issues
  • the difficulty of many companies to cope with the challenges of ediscovery
  • data security breaches and the obligation to notify consumers of the breaches

Michael Power made my favorite comment of the session. To paraphrase: "You can batten every hatch on your boat, and it's still going to get in. That's what bilge pumps are for. Data is just like water. You may think you've got a handle on where your data is stored and how it is secured, but, just like water, it goes everywhere."

Seminar Materials are available here. [ABA ID Required]

Ecommerce Subcommittee Meeting

The Ecommerce Subcommittee meeting ran at breakneck pace as we tried to cover the substance-packed agenda in the one-hour time allotment. Luckily, no other group was scheduled for the conference room so we could continue for an extra half-hour.

The meeting opened with the announcement that Juliet Moringiello is stepping down as Co-Chair, having reached the end of her three-year term. In her new role as Co-Chair of the Programs and Publications Subcommittee, the entire Cyberspace Committee will reap the benefits of her leadership talents and enthusiasm. Chris Kunz will be the new Co-Chair of the Ecommerce Subcommittee. Chris has been the driving force behind the impressive body of work on "click wrap" and "browse wrap" agreements produced by the Working Group on Econtracting Practices during her tenure as its Co-Chair. The timing is especially good for Chris to shift into the Ecommerce Subcommittee because of her interest in the Model Trading Partner Agreement and the Subcommittee's newest project, the Model Electronic Transaction Routing Services Agreement.

The meeting proceeded with a round-up of the Subcommittee's on-going projects. We were fortunate that Co-Chairs of all five Working Groups were in attendance to present status reports.

  • Linda Rusch summarized the progress that the Working Group on Transferable Records has been making on their attempt to give practical direction on how to establish "control" over electronic chattel paper.
  • Kathy Porter explained the Working Group on Electronic Contracting Practices' upcoming article on modification of standard form electronic contracts. Their next project will be a comprehensive review of the recently-published model website in anticipation of version 2.
  • Ben Beard reported on the annotations to Model Trading Partner Agreement, proposing that the Agreement be harmonized with the Model Electronic Transactions Routing Services Agreement, and that the two be published together.
  • Don Clifford discussed the revisions that the Consumer Protection Working Group is making to the ABA-sponsored website for consumers, www.safeshopping.org, which still contains content from its 1999 launch.
  • Jon Rubens brought us up-to-date on www.safe.selling.org, a proposed ABA-sponsored website for new Internet entrepreneurs .

Elaine Ziff made a presentation on two ecommerce decisions which were handed down in the past year. The first was Cairo v. Crossmedia Services, wherein the N.D. California upheld a choice of forum clause contained in terms and conditions posted on a site, despite the fact that the action meant to indicate assent, i.e., using the site, was undertaken by a robot which was not programmed to read the terms and conditions. The second case was Batesville Casket v. Funeral Depot, wherein in the S.D. Indianapolis suggested that the general rule that a website can link to another without liability for copyright infringements on the linked site does not necessarily apply where the linking site controls the content of the linked site.


The remainder of the meeting was dedicated to discussing the Model Electronic Transactions Routing Services Agreement. Phillip Schmandt and Chris Kunz led the group through their list of key conceptual questions, including, what is the difference between data and content, and what intellectual property, if any, will be created in the parties' relationship and who should own it? Between now and the Winter Working Meeting, a series of conference calls will be scheduled to go over the Model Electronic Transaction Routing Services Agreement in greater detail and focus on the actual language of the Agreement. If you would like to participate, please let Phillip or Chris know at pschmandt@mcginnislaw.com and ckunz@wmitchell.com.


Elaine Ziff, Co-Chair, Electronic Commerce Subcommittee

CLE PROGRAM: Information Security and Dealing with Information Security Breaches

Information Security Panel

This panel included speakers with a wealth of information about the current state of information security breach notification laws, the experiences of companies who have suffered a breach, and the legislative response to this situation.

Here are a few highpoints of many of the presentations.

Julie Brill
Assistant Attorney General, Vermont

Ms. Brill briefly reviewed some of the litigation filed by state Attorneys General in response to companies failing to provide notification to citizens of a state when the companies suffer security breaches. The CDRom for the Annual Meeting contains the testimony presented by the State Attorneys Generals at the recent hearings on consumer notification. That testimony includes a comprehensive list of the known security breaches that affected consumer accounts. She estimated that approximately 50 million consumers have been affected by security breaches.

Ms. Brill encouraged everyone to read the new state breach notification laws to ensure they can appreciate the subtle variety in the laws. She also commented that some of press reports about the new states laws have contain inaccuracies. To the extent the state notification laws differ, she felt the differences were largely in respect to how much of the OCC guidance was included in the state law.

Ms. Brill also summarized what she thought were the differences between the OCC Guidance and the majority of the state laws:
  • The definition of the information that triggers an obligation to notify is broader in the OCC Guidance
  • The language that describes whether notice must be given is more ambiguous
  • The OCC Guidance requires notification whether the information acquired was encrypted or not
  • The OCC Guidance also covers paper information as well as computerized information

She commented that the argument that the state laws lack uniformity is a red herring. She believes the state laws are similar enough that we have, effectively, uniform legislation.

She also does not agree there is a risk that consumers may become “numb” from receiving security breach notifications too often. She believes consumers are responding appropriately and that they are right to be very concerned about these breaches. She believes the breach notifications are an incredible educational tool that are beginning to help consumers learn what they must do to protect themselves from the risks of Identity Theft. Until American business changes its practices and improves the security of consumer information, the breach notifications will continue to be a good tool that has value.


She commented that most of the states want a federal security breach notification law. They believe the federal law should address two important points. First, the trigger for providing notice ought to be objective, not subjective, like the OCC Guidance. The states don’t want the entity that suffered a breach to decide if notice must be given. Second, the states don’t believe preemption is necessary.

Finally, she commented that the states want an expansion of the Safeguards Rule. They do not believe the current rule is strong enough, and should be modified to cover all entities that store or process sensitive consumer information, not just financial institutions that are currently covered by GLB.

[More to follow after lunch]