The Consumer Protection group opened its discussions on how it will be participating in the ABA project to put up safeselling.com. The group will be adding much from the consumer's perspective, including needs for sellers to analyze and address the Magnuson-Moss Act's consumer warranty requirements as well as methods to disclaim certain warranties.
Touch base with Prof. Don Clifford if you wish to participate -- His Working Group's home page can be found here. This is a really great opportunity for the person who wants to get started with CLC, since the project lends itself well to one who wants to write both short or long pieces. See
Saturday, April 08, 2006
Corporate Aspects of Information Technology (CAIT)
The CAIT subcommittee met on Saturday morning, chaired by standing Chair Don Cohn. First order of business, Don introduced the incoming new Co-Chair Bill Denny of Potter Anderson in Wilmington. Don and Bill have worked together for many years, and are looking forward to carrying on their work in the Committee.
Don ran through a number of projects that are in various stages of life, and made sure that potential participants knew that their mission was to get in touch with Bill or Don and get their wishes known.
(photos by Roland Trope)
Don ran through a number of projects that are in various stages of life, and made sure that potential participants knew that their mission was to get in touch with Bill or Don and get their wishes known.
- An M&A checklist for IT concerns (Bruce Doeg & Bill Denny are leading the charge.) Can we assist the business community to understand the issues in IT that will come up in their deals? How can we get experienced lawyers in line when these deals come up?
- How can the IT purchasing community start to get vendors to take contractual responsibility for the security breaches caused by their products?
- Corporate-sponsored blogs -- Can we produce a product to advise counsel on analyzing the risks of issuing corporate-sponsored content via 'blogs' (or any of the other non-traditional mechanisms that we see now or that will surely be invented soon).
- Corporate rules on how to filter incoming e-mail going to employees -- The USA perspective is essentially that the employer is in total control of this, but EU and other jurisdictions feel differently. How can a company that crosses boundaries have a viable policy?
(photos by Roland Trope)
Next Year's WWM
Candace announced at the plenary sessions that we are tentatively a GO for meeting this coming January in member Elizabeth "Soon-to-be-a-Mom" Bowles' home town of Little Rock, Arkansas. (Elizabeth later reminded us that while most of the locals refer to themselves as ar-kan-sans, the state constitution officially denotes them as ar-kan-sawyers.)
This is another great opportunity to enjoy the home city of one of our members (just as we did this year with Bill Denny and Don Cohn welcoming us to Wilmington and the wonderful Hotel DuPont). I am looking forward to seeing a town I've yet to spend time in.
This is another great opportunity to enjoy the home city of one of our members (just as we did this year with Bill Denny and Don Cohn welcoming us to Wilmington and the wonderful Hotel DuPont). I am looking forward to seeing a town I've yet to spend time in.
Model Data Breach Notification Procedure and Payment Card Industry information Security Standards (CLE session)
Panelists: Joan Warrington (off cam); Michael Power; Robert Rothman; Jon Armstrong; Tom Laudise (moderator); Peter McLaughlin and Hank Judy (off cam)
Questions from the audience were lively.
Panelists provided an unconventional discussion to company responsibilities to fulfill statutory obligations when data breaches occur.
Tom Laudise noted that the California statute (the "grand daddy" of data breach reporting statutes) overlooks the fact that with web search capabilities, data thieves do not need several kinds of personal data, they need only one important kind such as social security number and can then locate the rest of the data they need in order to make illicit use of the data.
Tom also noted that with so many states now having enacted disparate data breach statutes, it is time for federal legislation to harmonize these obligations. He discussed the pending HR 4127, Data Accountability and Trust Act, and its underlying theme "If you can't protect it, don't collect it." It gives enforcement action authority to the FTC and state attorney generals, which is strongly opposed by financial service companies. He doubts, however, that unless there is a significant data breach for a triggering event that the House will enact any of the competing bills currently pending.
Jonathan Armstrong, from the UK, discussed data breach -- a view from Europe. He noted that there are increasing numbers of data breaches in Europe, and particularly in the use by EU businesses of offshore call centers. He noted that companies seem reluctant to recognize that if you pay employees less, you increase the chances that they will be susceptible to bribes by data thieves. He drew an analogy to a weather map, and noted that there is a strong storm system of threats to data privacy moving west from Eastern Europe. He also provided the graphic example of a person who once told him "you will never understand data privacy until a neighbor of yours has been taken out and shot." Jonathan noted that despite the EU-wide Data Directive, each Member State has implemented its own national version, and that the prosecuting official for a data breach will, therefore, not come from EU headquarters in Belgium, but from the local Member State. In Europe he added that there is "loads of law, but little enforcement", whereas in the US "you have little privacy law, but vigorous enforcement." Mandatory reporting requirements are proliferating, with Norway being the first, where the mandatory report must be to the Norwegian data commission, which then will decide if the company must report to end-users or affected customers. Data reporting laws also have emerged in Hungary, Malta, Sweden and Germany. In most countries, persons have the right to make a "subject access request" -- if they believe they are in a class affected by a data breach, they can submit such a request, and the company must respond within a brief period. In Europe, it is common that prior to handling personal data, a company must register with the Member State's data protection commission.
Robert Rothman emphasized the need during initial diagnosis of a data breach to create a centralized "Fact Sheet" to ensure that one version, not many, becomes the view of the company internally and in contacts with the media. He pointed out that when a company reports a data breach it should give very careful consideration to omitting from such notice any disclosure of information that would alert the data thieves to the significance or value of the platform or stored data that they took.
Michael Power approached the problem as an evidence collection exercise in which the overseeing counsel need to make sure that they can trust everyone involved. He noted this must start with the engagement of a forensic expert. When a company suspects a known person or target who may have stolen the data, he recommends seeking court orders to compel production of their storage devices in order to "ghost" them and review contents to determine if they contain stolen data. He drew the analogy to coming home at night, finding the door had been forced open, and then you have the difficult task of determining what happened -- did the intruders merely walk around, did they party (unlikely), did they go upstairs and take valuables from drawers, etc. Finding out what the data intruders actually did is an important task that needs to be investigated and should not be assumed away. He noted unique issues that arise under Canadian federal and provincial privacy laws. In one instance, he discussed how the team leader (and there MUST be one after a breach) needs to be prepared to deal with the media. He echoed the theme of earlier panelists "Get the Lawyer in Early" if there is a security breach.
Joan Warrington elaborated on that theme emphasizing the risks of class actions and attorneys general investigations. She devoted considerable attention to the Payment Card standards and how clients will increasingly need to grapple with these standards. They emerged, in part, from Visa, which have been approved and adopted by all of the big payment card sponsors -- Amex, MasterCard, etc. They are applicable to all entities that store, process or transmit card holder data. If you go to the websites of these card issuers there are inches thick materials (when printed in hard copy) on compliance with those standards. Several banks, for example, have sued BJ's claiming that they are third party beneficiaries of those standards and seek to recoup funds lost through thefts that originated in data stolen as a result of BJ's alleged failure to comply with those standards.
Hank Judy encouraged counsel to download from the Better Business Bureau and from MISMO websites the primers available on how to handle data breaches (the former is best suited to small businesses, the latter provides a more sophisticated and technologically advanced guide). He highlighted certain issues that can be easily overlooked. Unlike usual thefts where missing items mean something has been stolen, with data "the absence of evidence is not evidence of absence" because hackers are often skillful at compromising data without leaving a trace of their intrusion and leaving the data seemingly intact. There needs to be a person with "unambiguous decision-making authority." Although perhaps counterintuitive to companies fearful of the consequences of a public disclosure, he encouraged the use of a website to provide notice (gets the word out to a wide community, and keeps control of the version released by the company -- and allows a company to combine a good account of the incident, with links to service providers that can help consumers protect themselves from the consequences of the breach, and that allows a company to continuously update its account and such aids as needed). Hank recommended as an example that counsel view a few websites, including this one put out by Georgetown University after an incident.
Questions from the audience, including Michael Khoury's inquiry about how to respond when you advise your client on the best practice responses to the data breach and brings you up short with one or another version of the question, "But isn't that going to cost us a shitload?"
Subcommittee on Privacy, Security and Data Management
Michael Power and Peter McLaughlin co-chaired this morning's meeting of the cyberspace subcommittee on Privacy, Security and Data Management. More than 35 people attended (and more than half of them were new to the subcommittee). There was discussion about possible new projects -- e.g., collection of examples of negotiated clauses/exceptions to standard software vendors' exclusion of liability for security breaches (and/or a collection of examples of how large buyers have used their buying power to move vendors away from their historical hard line). There also was discussion about CAIT's ongoing project to develop (and keep up to date) a set of checklists/tools to help counsel effectively work through the barrage of decisions that have to be made while in the midst of a security incident (e.g., a network security breach).
Andy Serwin made a presentation (using powerpoint in an unexpected way, with non-volatile storage/display tools -- paper) trying to read the tea-leaves about the FTC's emerging security policies. While recent enforcement actions are reported as "privacy-protection" activities, a closer look suggests: (a) the FTC is more focused on lacking underlying security, at (b) companies that are holding financial-related information. Relying on Gramm-Leach-Bliley, FTC has seized on the lack of a written contingency plan (for managing security incidents). (While many companies have at least decent security processes, many of these aren't formally enough institutionalized in a fashion that facilitates knowledge continuity -- hence, the need for a written plan.) FTC actions also illustrate the need for formalized, risk-assessment and risk-management processes, being systematically applied to the area of information security. (An ecopy of Andy's presentation resides here.)
The number of people in the room, the kinds of questions raised, and the level of passion exhibited during this meeting all suggest that the "perfect storm" of security/privacy is closer than a distant speck on the horizon. The lawyers who prepare earliest may actually benefit from the coming storm, by being able to out-sail their less-well-prepared colleagues. As with Health-Safety-Environment, companies also may find an emerging competitive advantage flowing from their earlier planning. (Argue this, when justifying your participation in our work.)
Andy Serwin made a presentation (using powerpoint in an unexpected way, with non-volatile storage/display tools -- paper) trying to read the tea-leaves about the FTC's emerging security policies. While recent enforcement actions are reported as "privacy-protection" activities, a closer look suggests: (a) the FTC is more focused on lacking underlying security, at (b) companies that are holding financial-related information. Relying on Gramm-Leach-Bliley, FTC has seized on the lack of a written contingency plan (for managing security incidents). (While many companies have at least decent security processes, many of these aren't formally enough institutionalized in a fashion that facilitates knowledge continuity -- hence, the need for a written plan.) FTC actions also illustrate the need for formalized, risk-assessment and risk-management processes, being systematically applied to the area of information security. (An ecopy of Andy's presentation resides here.)
The number of people in the room, the kinds of questions raised, and the level of passion exhibited during this meeting all suggest that the "perfect storm" of security/privacy is closer than a distant speck on the horizon. The lawyers who prepare earliest may actually benefit from the coming storm, by being able to out-sail their less-well-prepared colleagues. As with Health-Safety-Environment, companies also may find an emerging competitive advantage flowing from their earlier planning. (Argue this, when justifying your participation in our work.)
Internet Jurisdiction and Global E-Commerce Subcommittee
The Internet Jurisdiction and Global E-Commerce Subcommittee assembled a lucky 13 participants to discuss three topics.
On the first topic: considerable scepticism on all three points. The subject was considered inchoate at the international level, with "high barriers to entry" because of the complexity, density and high political content of the material (not to mention the travel budgets required to participate in meetings). If anything were to be done, it should be on narrow focused and ideally relatively technical topics, rather than big policy issues like "should policy be set bottom-up, as with ICANN and its user constituencies, or top-down by governments?"
The meeting discussed whether to try to formulate a solution to the WHOIS issues presented by Kristine Dorrain at the Hot Topics session on Friday morning. For reasons to be outlined in more detail in the report of the meeting on the Subcommittee's home page (in due course), there was some reluctance to undertake this. The topic was left with an invitation from the chair to propose topics, ideally narrow and manageable.
The second topic, on choice of law, was inspired by a recent California case and by revised Article 1 of the UCC, which has been adopted in California - but nearly nowhere else, so far, at least on this subject. There was some discussion about how closely linked the questions were to the UCC. At the end, the project was thought to be worth pursuing, so the chair would pursue volunteers, offline and on. It was thought that someone with students with term papers might be a good candidate. It might be useful to reach out to other subcommittees.
The third topic, the UNCITRAL Convention, led to discussions about the nature of the decision to sign conventions under the current US administration, the differences between signature and ratification, the role of NCCUSL and implementing legislation generally, and the process for joining the SciTech submission if we wanted to. Detailed discussion was left for the meeting of the Working Group on International Policy, but the meeting favoured, nemo dissentiente, moving towards support of SciTech and US signature of the Convention.
- The first was Internet governance: has the Cyberspace Committee something to say on that topic, would the ABA agree, and would anyone else in the world care?
- The second was a project on state (and probably federal) courts' response to choice of law provisions in internet transactions.
- The third was whether Cyberspace, and/or the Section, should support the submission by the Section of Science and Technology to the Department of State that the US should sign the UNCITRAL Convention on the use of Electronic Communications in International Contracts.
On the first topic: considerable scepticism on all three points. The subject was considered inchoate at the international level, with "high barriers to entry" because of the complexity, density and high political content of the material (not to mention the travel budgets required to participate in meetings). If anything were to be done, it should be on narrow focused and ideally relatively technical topics, rather than big policy issues like "should policy be set bottom-up, as with ICANN and its user constituencies, or top-down by governments?"
The meeting discussed whether to try to formulate a solution to the WHOIS issues presented by Kristine Dorrain at the Hot Topics session on Friday morning. For reasons to be outlined in more detail in the report of the meeting on the Subcommittee's home page (in due course), there was some reluctance to undertake this. The topic was left with an invitation from the chair to propose topics, ideally narrow and manageable.
The second topic, on choice of law, was inspired by a recent California case and by revised Article 1 of the UCC, which has been adopted in California - but nearly nowhere else, so far, at least on this subject. There was some discussion about how closely linked the questions were to the UCC. At the end, the project was thought to be worth pursuing, so the chair would pursue volunteers, offline and on. It was thought that someone with students with term papers might be a good candidate. It might be useful to reach out to other subcommittees.
The third topic, the UNCITRAL Convention, led to discussions about the nature of the decision to sign conventions under the current US administration, the differences between signature and ratification, the role of NCCUSL and implementing legislation generally, and the process for joining the SciTech submission if we wanted to. Detailed discussion was left for the meeting of the Working Group on International Policy, but the meeting favoured, nemo dissentiente, moving towards support of SciTech and US signature of the Convention.
Cyberspace Committee leadership changes
Candace this morning reported some subcommittee leadership changes:
1. Ben Beard succeeds Elaine Ziff as co-chair (with Chris Kunz) of the Electronic Contracting wubcommittee. Ben will have a challenge filling Elaine's shoes (in so many ways).
2. In Electronic Financial Services, Bob Ledig is rotating off as chair (but rotating into a new role as chair of the Joint Privacy Task Force, whose other parent committees are Banking and Consumer Financial Services). Bob will be succeeded by co-chairs Judy Rinearson (of Bryan Cave) and John Morgan (of Amazon, and who's return the the Cyberspace committee comes after a brief, six-year hiatus).
3. In the Electronic Payments Working Group, Steve Middlebrook (of the Treasury) will be joining as co-chair to help Sarah Janes Hughes (of Indiana Law School).
4. In CAIT (which the poster initially created out of whole cloth in 1997), Bill Denny (of Potter Anderson) will be joining as co-chair to help Don Cohn (of Dupont).
5. Lisa Lifschitz (of the Gowlings incursion, officed in Toronto) will succeed (but never replace) Jackie Scheib as chair of the Membership subcommittee.
6. UPDATE: Kristine Dorrain, from the National Arbitration Foundation in Minneapolis, will be Co-Chair of the Intellectual Property Subcommittee, taking over Eric Goldman's seat at the end of his term.
(I may have missed a couple -- I'm simply acting as a reporter here -- changes and corrections surely will appear as time goes by.)
1. Ben Beard succeeds Elaine Ziff as co-chair (with Chris Kunz) of the Electronic Contracting wubcommittee. Ben will have a challenge filling Elaine's shoes (in so many ways).
2. In Electronic Financial Services, Bob Ledig is rotating off as chair (but rotating into a new role as chair of the Joint Privacy Task Force, whose other parent committees are Banking and Consumer Financial Services). Bob will be succeeded by co-chairs Judy Rinearson (of Bryan Cave) and John Morgan (of Amazon, and who's return the the Cyberspace committee comes after a brief, six-year hiatus).
3. In the Electronic Payments Working Group, Steve Middlebrook (of the Treasury) will be joining as co-chair to help Sarah Janes Hughes (of Indiana Law School).
4. In CAIT (which the poster initially created out of whole cloth in 1997), Bill Denny (of Potter Anderson) will be joining as co-chair to help Don Cohn (of Dupont).
5. Lisa Lifschitz (of the Gowlings incursion, officed in Toronto) will succeed (but never replace) Jackie Scheib as chair of the Membership subcommittee.
6. UPDATE: Kristine Dorrain, from the National Arbitration Foundation in Minneapolis, will be Co-Chair of the Intellectual Property Subcommittee, taking over Eric Goldman's seat at the end of his term.
(I may have missed a couple -- I'm simply acting as a reporter here -- changes and corrections surely will appear as time goes by.)
Friday, April 07, 2006
Model Trading Partner Agreement

One highlight of the MTPA meeting was the return of long-time member Jamie Clark, who has been away from our last few meetings. All of us in CLC are happy to have Jamie back.
The meeting began at 8 AM, with the core people as well as the ABA publications group represented. Discussion focused on the continuing need to move the project forward and some of the difficulties that have kept this from coming to full fruition. We confirmed that the publications group would still like to see this move forward, particularly given that there continues to be demand for the original product from the early 1990s that focused solely on EDI.
Debates focused on concerns of whether the project should focus on the seller/buyer relationship (as in the original product), should focus instead on the 'network' relationship between the seller, the buyer and the provider of the communications mechanisms (somewhat akin to the relationship between licensor, licensee and a software escrow company), or some variation thereof.Prof. Ben Beard left with a clear sense that the project will move forward. Please get in touch with Ben if you are interested in participating.
Smile! You're on Candid Camera!
Roland Trope has been taking some random candid shots of the people who have joined us -- A selection of a few...
Subscribe to:
Posts (Atom)









