Friday, February 03, 2006

Computer Business Records Without Foundation?

A recent decision out of the 9th Circuit (sitting as the U.S. Bankruptcy Appellate Panel) should be of interest to Cyberspace lawyers.

While all of us are familiar with the usual litany of how to get business records admitted under the relevant exception to the hearsay rule, many of us have long wondered if there was too much of a leap of faith in the process where the records were computerized. Well, the naysayers finally have a case to lean on.

In In re Vinhnee, (2005 WL 3609376) the district court had refused to admit evidence proffered by a credit card company regarding the debtor's credit card transactions. The refusal was on the ground of defective evidentiary foundation. The trial court suggested that determining the authenticity of proffered electronic records "necessitated, in addition to the basic foundation for a business record, an additional authentication foundation regarding the computer and software utilized in order to assure the continuing accuracy of the records." Even after the proponent was given a second bite at the apple (by being allowed to file a post-trial declaration to lay sufficient foundation), the court found the witness statements to be overly conclusory and the witnesses themselves to be of unproven qualifications. On that basis, the evidence was not admitted, the proponent lost its case because of the evidence issue, and the appeal ensued.

The appeal affirmed the decision (notably on an abuse of discretion standard, which the court said might allow for a "trial court that is finicky about settled authentication requirements [to be] sustained..."). The court noted some scholarship on point, equating computer evidence to be a form of scientific evidence, and suggested that the problem is more complex than it seems. "The 'built-in safeguards to ensure accuracy and identify errors' ... subsume details regarding computer policy and system control procedures, including control of access to the database, control of access to the program, recording and logging of changes, backup practices, and audit procedures to assure the continuing integrity of the records." In this instance, the best the proponent of the evidence could come up with (even after being allowed to go home and do its homework!) was to list off the brand of computers and software the business used, and restate a conclusory opinion that the system was reliable. The trial court determined that this did not meet its requirements for foundation, and the evidence was tossed.

Astute readers will begin to notice a common element to the above discussion with topics that our members are already frequently touching -- Data Security after GLBA, HIPPA and their ilk, and Internal Controls after SarbOx. We also see these same issues popping up in our discussion of what constitutes "control" of an electronic record in the context of a negotiable instrument under UCC § 9-015. All of these matters begin to turn on the creation, documentation and compliance with business procedures. This continues to point out the problem with relying on canned programs that operate without intelligent oversight -- Be it for credit card records, electronic chattel paper, corporate books or medical records.

Which leads to the question of lawyering. One can only wonder how a written declaration was issued in the above matter which made no attempt to discuss policies and procedures regarding the safeguarding of the data -- But I can suggest that had a well-versed cyberspace lawyer been on the task, the proponent might have had a better chance at crafting a document that would have won the day. Is this yet another reason that our practices should be getting more in the faces of others and pointing out our value?

(The sideline to the case: The trial court turned away the credit card company even though the defendant (debtor) did not even show up or enter any argument, having the company suffer "the ignominy of losing even though its opponent did not show up." The judge himself, Hon. Samuel L. Bufford, raised the issue during a routine hearing, and pointed the company to scholarly materials that dealt with the issues -- And the lawyers still did not comply with his requests. Has any of our membership met Judge Bufford? We should look into how he came to be interested in these topics and where he might be taking these things!)

Internet Jurisdiction and Global e-Commerce Subcommittee

The Internet Jurisdiction and Global e-Commerce Subcommittee met in Wilmington as part of the Winter Working Meeting, last Friday, January 27, in the morning and afternoon. We discussed international conventions that might affect an Asia-Pacific electronic transaction; practical and policy considerations relating to Voice over Internet Protocol (VoIP) that might do likewise; and drafting non-compete clauses in an era of borderless communications.

A report of our discussions is on the Subcommittee homepage is here.

The Subcommitte homepage itself is here.

Comments on any of this material welcome. In particular:

- Contributions to the VoIP program for the Annual Meeting should be addressed to Konrad Trope or Kristie Prinz.
- Ideas for use of the Subcommittee's time in Tampa in April would be welcome. We have an hour as ourselves, and Hal Burman's International Policy working group has an additional hour.

Internet Law Subcommittee WWM activities

During the WWM in Wilmington on January 27 and 28th, the Internet Law Subcommittee primarily worked on the “data breach” notification program scheduled for the Section of Business Law Meeting in Tampa and a new project to address electronic waste disposal concerns.

Data Breach Notification Program

The Tampa program will be presented in conjunction with the Cyber-security and Privacy Subcommittee. The first part of the program, entitled “Model Data Breach Notification Procedure and the Payment Card Industry Security Standards,” will provide practical advice for counsel when the client calls up, reports a data breach and asks what to do next. The second part will focus on the enforcement of new information security requirements against credit card merchants by associations of credit card issuers.

At the WWM, discussions focused on certain issues:

• How does one know if there really has been a data breach (some protected data has actually been “acquired”)
• How does one know the extent of the breach (what protected data has been “acquired”)
• How does one deal with the “race against time” in which there is a competition among the efforts of the forensic experts to learn exactly what happened, the desire to make a complete and accurate public announcement, and the desire to shorten the period during which customers are exposed to theft.
• How to handle the case of a client that is reluctant to report a data breach or want to delay the report, perhaps for an unreasonable period.

In the course of those discussions, we realized that clients with multi-national operations may find themselves weighing strict compliance with US data notification laws with potential criminal and/or civil liability consequences in other countries—probably a good reason for a client’s apparent “reluctance” to comply.

The program will also provide an overview of existing data breach notification laws and pending legislation and will provide information on recent major enforcement cases.

We are very interested in including any data breach notification “war stories” and to address any practical data breach issues which members of the Cyberspace Law Committee have. Please feel free to contact Hank Judy, Tom Laudise and Michael Power or Peter McLaughlin, co-chairs of the Cyber-security and Privacy Subcommittee. (Those offering the best and most well-documented war stories will be treated to the appropriate libations and opportunity to tell the full version of the story in a suitable environment, a/k/a bar, at the next ABA gathering courtesy of Hank Judy and Tom Laudise)

Electronic Waste Disposal

Electronic equipment is laden with harmful material which, if not disposed of correctly, can severely harm the environment. Currently, much of the disposed of electronic waste finds its way to dumps in impoverished areas of the world. Often, the original owner of equipment has no idea that this is the case and believes that it has been “properly disposed of” by the company it hired for that purpose.

Several states have laws requiring the proper and environmentally sound disposal of electronic equipment. Legislation has been proposed in many other states and in Congress. The EU has several directives in place addressing the environmentally sound disposal of electronic equipment, as well as related issues of disposal of packaging, and environmentally sound initial design. During the WWM Tom Laudise and Hank Judy presented Power Points on different aspects of the problem and circulated research materials

Internet Law had originally planned a survey of the law. However, discussion at the WWM revealed that it would be more useful to instead prepare an article which will, first, alert counsel to the issue and potential serious liabilities for improper disposal of electronic waste, and, second, provide a sample agreement/clauses with a third party provider of electronic waste disposal services (as well as assured erasure of hard drives and related memory.) We hope to circulate an initial draft contract in the next several weeks.

We would like to publish such an article this year. Depending upon the response to the article, we will consider an ABA program in 2007. We would very much like assistance and ask that anyone interested please contact Hank Judy or Tom Laudise.

Model Website Development Agreement and Commentary

We will work to finalize a model website development agreement with commentary this spring. This project enjoyed/suffered a brief hiatus but is now back—hopefully in time to be included with the Working Group on Electronic Contracting Practices second release of its the Model Web Site – Cyberspace Law's very successful publication meant for practitioners assisting clients who are setting up eCommerce operations within a corporate environment.

We will circulate the next draft for comments soon. Anyone interested in reviewing that draft and providing insightful feedback, please contact either Hank Judy or Tom Laudise. Tom already has a list of “usual suspects” and, in lieu of volunteering, you may contact him to confirm you are the list.

* * * * *
Finally, if anyone has any additional projects they are interested in seeing the Internet Law Subcommittee take on, please contact either Hank Judy or Tom Laudise.

Wednesday, February 01, 2006

New Efforts on Law of Software Licensing

The American Law Institute (creators of such great works as the Restatement of the Law, and the joint author with the NCCUSL of the Uniform Commercial Code) is now in the process of creating a proposed uniform set of principles that deal specifically with software transactions. Recall that the ALI split from the NCCUSL when the predecessor to UCITA, which was to be issued at one point as Article 2B of the UCC, was rejected by ALI, and NCCUSL went off on its own to issue its proposed UCITA -- with results we need not rehash here.
As noted in today's BNA Electronic Commerce & Law Report, the effort here will be much narrower than that of UCITA -- the scope is explicitly excluding potentially controversial issues like digital databases (let alone entertainment products and the like).

Some of the major issues addressed in an early draft include: contract formation, delayed terms, choice of law, embedded software, the treatment of mixed software and service transactions, and unconscionability.

The Reporter is Robert Hillman, a law professor at Cornell Law School, and the Associate Reporter is Maureen O'Rourke, interim dean of Boston University School of Law. The hope is to present a full draft for discussion at the ALI's annual meeting in May 2007 in San Francisco.
Members of the group that are working on the project are noted here -- Astute readers will note many Cyberspace Committee members sprinkled throughout the list.

Sunday, January 29, 2006

Pictures from Friday Night's Dinner

The WWM's official dinner, held at the Hotel du Pont, was well attended and well received. The staff of the hotel made us feel very welcome, and the food was quite good. Here are some snapshots from the festivities.









Freddie Mac eMortgage Handbook

CLC member Mike Gordon has alerted us that his employer Freddie Mac has recently issued its eMortgage Handbook. As noted on their Web site:

The use of electronic documents to originate mortgages is increasing. The shift from paper documents with wet ink signatures to electronic documents brings the promise of improved efficiency and higher data quality to the home buying process. Freddie Mac continues to be a notable contributor to this evolution through our participation in industry standards groups.

Since the publication of our Preliminary Specifications for Electronic Mortgage Loan Documentation in 2001, the industry and our planned electronic mortgage (eMortgage) process have transformed. Our current specifications, which we have captured in our eMortgage Handbook, provide greater detail about our requirements for electronic documents in the mortgage loan file, and the care and storage of these documents throughout the life of a loan. The eMortgage Handbook is intended to provide directional guidance to industry participants as they make decisions regarding the use and implementation of electronic documents.

This is an important new area of practice that many of our members can contribute to both in ABA as well as in their 'day jobs.' Note the parallel efforts by our Joint Working Group on Transferability of Electronic Financial Assets, which is on the verge of publishing its white paper (created jointly with the Open Group) on the questions of 'control' in electronic chattel paper (see UCC 9-105). It's an example of the promise of eCommerce that we spoke of so glowingly a few years ago and then began to wonder if it was really going to happen. Well, it is.

Mike notes: "In accessing the Handbook, we only request that members remember that it is copyrighted and that copying or re-printing it in whole or part for distribution outside the Cyberspace Committee will require Freddie Mac's written consent. Certainly, quoting or excerpting with citation or downloading a personal copy is permitted."

Revenue Opportunity -- Product Placement

In reviewing the blog entries, I think I've detected a future revenue opportunity for the Committee--Product Placement.

In nearly every photo, members of the Committee are prominently displaying Coke products. I think we should contact Coca-Cola and ask for some of their ad buy. What do you guys think?

[I'm trying to generate some comments, eh!]

Saturday, January 28, 2006

Meeting of High Forehead Working Group


Don, Michael and Hank Showing off their Collective Intellect


UPDATE: I neglected to credit Roland Trope for the photography.

Universal Business Language


Prof. Jane Winn presented Jon Bosak of Sun Microsystems, who informed many of us who are interested in the development of the Universal Business Language -- An implementation of XML designed to form a common set of business contracting documents.

For a quick bit of fun, check out the international form of their data dictionary, with over 600 standard business terms translated over 6 different languages. (Jon left it to the lawyers and others to try and figure out what happens if people disagree on the translations!)

Friday, January 27, 2006

Sunny and 45 Degrees in Minneapolis


I just wanted to point out to everyone that for the second year (not in a row), it's warmer in Minneapolis than it is in the city chosen for the Winter Working Meeting.

The snow has nearly completed melted, the sun was shining, and it was very much not like Minnesota.

Granted, it's forecasted to be warmer in Wilmington tomorrow than it is in Minnesota, but at least for one day it was nicer here.