20 February 2014

Smells

There's an old gibe that vaudeville isn't dead, it just smells that way.

I was reminded of that claim in reading reports that retail giant Coles has defended its use of the descriptor “baked today, sold today” in a federal court action brought by the Australian Competition and Consumer Commission (ACCC).

The ACCC, represented by Colin Golvan SC, has argued that the bread is partially baked before being sold in store, with Golvan commenting
It essentially involves a process where [a] product is cooked to the part where the interior is complete and there is a commencement of the baking of the crust, which is left to be finished by Coles
Representations by Coles were false, misleading and deceptive on the basis that baking occurred six month before the bread was sold in stores.

Last year it was argued in court that the bakery products were either made in Ireland or had been initially baked in different locations in Australia.

In a nice example of casuistry Coles claims that it was not suggesting that the bread was baked on the day.
What is happening with this ‘baked today, sold today’ in a Coles supermarket is that a consumer is being given the choice between the juxtaposition, the commercially manufactured bread, which has preservatives and keeps for longer, with the bread that is baked in-store and doesn’t have preservatives.
The bread that is baked in-store is crunchier, and smells and has the flavour of freshly baked bread. That’s what we submit it is.
In mid 2013 the ACCC indicated that
The ACCC is alleging false, misleading and deceptive conduct in the supply of bread that was partially baked and frozen off site, transported to Coles stores and ‘finished’ in-store. The products were then promoted as ‘Baked Today, Sold Today’ and/or ‘Freshly Baked In-Store’ at Coles stores with in-house bakeries. 
The legal action covers various ‘Cuisine Royale’ and ‘Coles Bakery’ branded bread products. The ACCC alleges that labels on these par baked products stating ‘Baked Today, Sold Today’ and in some cases ‘Freshly Baked In-Store’, and nearby prominent signs stating ‘Freshly Baked’ or ‘Baked Fresh’, were likely to mislead consumers into thinking that the bread was prepared from scratch in Coles’ in-house bakeries on the day it was offered for sale and that it was entirely baked on the day it was offered for sale. 
Coles also uses these same representations to promote bread that has been made from scratch in Coles’ in-store bakeries. The ACCC is concerned that Coles’ lack of distinction in its promotional representations between bread products that are freshly prepared from scratch and par baked products is misleading to consumers and places competing bakeries that do freshly bake from scratch at a competitive disadvantage. 
ACCC Chairman Rod Sims said, “There are two important issues at stake. First, consumers must be able to make informed purchasing decisions. Bread is an important grocery basket staple and customers need to be confident in claims made about food they buy.” 
“We believe consumers are likely to have been misled by Coles that the entire baking process, including preparation, occurred in-store, when in fact the bakery products were prepared and partially baked off site, frozen, transported and then ‘finished’ in store. Indeed, the Cuisine Royale products were partially baked overseas.” 
“Second and just as important, is the detrimental impact on the businesses of competitors. Misleading credence claims can undermine the level playing field and disadvantage other suppliers. In this case those suppliers are the smaller, often franchised bakeries that compete with Coles,” Mr Sims said. 
In the past few years, Coles has heavily promoted its in-store bakeries and introduced a number of ‘rustic’ bread lines. Many of these ‘artisan-like’ breads have been par baked and frozen before being ‘finished off’ before sale, whereas many independent bakeries make their bread from scratch in the bakery on the day of sale. 
Bringing this action is part of the ACCC’s publicly declared enforcement priority of investigating credence claims, particularly in the food industry, with the potential to significantly impact consumers and competitors.

BioTrolls

'Patent Trolling — Why Bio & Pharmaceuticals are at Risk' by Robin Feldman and W. Nicholson Price II comments that
Patent trolls — also known variously as non-practicing entities, patent assertion entities, and patent monetizers — are a top priority on legislative and regulatory reform agendas. In the modern debates, however, the biopharmaceutical industry goes conspicuously unmentioned. Although biopharmaceuticals are paradigmatically centered on patents, conventional wisdom holds that biopharmaceuticals are largely unthreatened by trolls. This article shows that the conventional wisdom is wrong, both theoretically and descriptively. In particular, the article presents a ground-breaking study of the life science holdings of five major universities to determine if these might be attractive to monetizers. 
This was deliberately a light, rather than an exhaustive, search. Nevertheless, we identified dozens of patents that could be deployed against current industries. These include patents on active ingredients of drugs; methods of treatment; screening methods to identify new drugs; manufacturing methods; dosage forms; and ancillary technologies that could be deployed in a “peddler’s bag” approach. The article describes the types of patents we found, including an example of each type. 
In deciding whether to undertake this analysis, we lost sleep over whether the potential for harm outweighed the potential benefit. If reform efforts are not undertaken, our work could do no more than provide a handy road map for those who would follow. However, with scattered anecdotal evidence suggesting that monetization is moving into biopharmaceuticals, life sciences trolling is predictable and in its infancy. If reforms are implemented before the problem proliferates, legislators and regulators could cabin the activity before it becomes deeply entrenched and too much harm occurs.

Vexatious People in Victoria

Given the recent judgments in New South Wales regarding a vexatious litigant (noted here and here) it is useful to note the Vexatious Proceedings Bill 2014 (Vic), introduced and read for the first time in the Victorian Legislative Assembly.

The Attorney-General indicates that the proposed legislation will introduce "a new regime for the management and prevention of vexatious litigation in Victorian courts and tribunals".
The Bill aims to improve the effectiveness of the justice system by ensuring that unmeritorious litigation is disposed of at an early stage and that persons are prevented from wasting court time with further unmeritorious cases. This will allow court and judicial resources to be allocated to the determination of meritorious cases, which will reduce delays in the court system for other pending matters. 
The Bill enables the Supreme Court, the County Court, the Magistrates' Court and VCAT to make various types of "litigation restraint orders", which increase in severity in accordance with a person's litigation history and pattern of vexatious behaviour. The Children's Court is also given the power to make litigation restraint orders, but only in relation to litigation conducted under the intervention order legislation. The tiered approach to litigation restraint orders promotes early intervention and aims to provide flexibility for the Courts and VCAT to adopt a proportionate response to a person's conduct. 
The Bill draws upon recommendations made by the Victorian Parliamentary Law Reform Committee in 2008, and also implements aspects of a Model Bill approved in 2004 by the former Standing Committee of Attorneys-General (Model Bill). 
The Bill repeals the vexatious litigation regimes in the Family Violence Protection Act 2008 (Vic) and the Personal Safety Intervention Orders Act 2010 and re-enacts those regimes in the Bill to align those regimes with the new regime established under the Bill.

Victorian Mental Health Law

In Victoria the Mental Health Bill 2014 (Vic) is past the first reading stage.

In summary the Bill is for an Act to provide a legislative scheme for the treatment of persons with mental illness, to repeal the Mental Health Act 1986 (Vic), to make consequential amendments to the Sentencing Act 1991 (Vic), the Crimes (Mental Impairment and Unfitness to be Tried) Act 1997 (Vic) and other Acts and for other purposes.

Its specific purposes are -
(a) to provide a legislative scheme for the assessment of persons who appear to have mental illness and for the treatment of persons with mental illness; and 
(b) to provide for the appointment of the chief psychiatrist; and 
(c) to establish the Mental Health Tribunal; and 
(d) to establish the Mental Health Complaints Commissioner; and 
(e) to continue the Victorian Institute of Forensic Mental Health; and 
(f) to provide for the appointment and functions of community visitors; and 
(g) to repeal the Mental Health Act 1986; and 
(h) to amend the Sentencing Act 1991 and the Crimes (Mental Impairment and Unfitness to be Tried) Act 1997; and 
(i) to make consequential and statute law amendments to other Acts.
In the Northern Territory the Criminal Code Amendment (Expert Psychiatric or Medical Evidence) Bill 2013 (NT) has been read a third time, passed all stages and is awaiting assent

19 February 2014

Deferred

A recent post noted concerns regarding the UK care.data initiative, i.e. proposals to commercialise anonymised/pseudonymised whole-of-population health data gathered from UK National Health Service hospitals and general practitioners on a poorly-managed opt-out basis.

(Another piece on concerns regarding commercialisation of NHS Big Data is here).

The UK Independent now reports that the grand plan has been somewhat delayed
Although leading groups, including the British Medical Association and the Royal College of General Practitioners (RCGP) initially backed the scheme, both have broken ranks within the past week saying that while they back the principle, NHS England needed to do more to guarantee “the support and the consent of the public”. 
Concerns persisted despite a publicity campaign in which information leaflets were delivered to 26 million households in England in January. Polls suggested that fewer than one in three adults recall receiving the leaflets, which were derided as “junk mail” by critics. Despite containing important information, the leaflets were not addressed to individuals and did not contain an opt-out form. … 
Tim Kelsey, NHS England’s national director for patients and information who has spearheaded care.data, said the NHS was “determined to listen”. 
He added: “We have been told very clearly that patients need more time to learn about the benefits of sharing information and their right to object to their information being shared ... [and] that is why we are extending the public awareness campaign by an extra six months.” … 
A Department of Health spokesman said ministers support the decision to delay the launch. “This is a vital programme which will bring real benefits to patients. But concerns over how this has been explained to patients have been raised which must be addressed,” he said. 
Dr Chaand Nagpaul, chair of the BMA’s GP committee, said it was “only right” that the public “fully understand what the proposals mean to them and what their rights are”. 
“With just weeks to go until the uploading of patient data was scheduled to begin, it was clear from GPs on the ground that patients remain inadequately informed,” he said.
The Independent comments
The pause will allow the NHS more time to inform people about “the benefits of using the information, what safeguards are in place, and how people can opt out if they choose to,” officials said. 
The Department of Health has grown increasingly concerned in recent weeks that NHS England has not sufficiently reassured the public – nor the medical profession – about how the care.data programme would benefit patients. Critics have also warned that the private data, which will be held centrally in a “pseudonymised” form, could be vulnerable to hackers who would be able to identify individual patients.
In France, meanwhile, the Commission nationale de l’informatique et des libertés (CNIL) reports -
On 3 January 2014, the CNIL’s Sanctions Committee issued a decision against Google for infringing several provisions of the French Data Protection Act. It consequently ordered the company to pay an administrative fine of 150.000 € and to publish a communiqué referring to its decision on the homepage « www.google.fr ». 
The company had requested the Conseil d’Etat (the French High Administrative Court) to suspend this publication order. In a ruling dated 7 February 2014, the judge rejected this request. 
Google must publish this communiqué for a period of 48 hours in accordance with the modalities set by the Sanctions Committee. 
This decision does not prejudice the final claim against the decision that is still pending in the Conseil d’Etat.

Refugee Data Breach

The Guardian has revealed that there has been a serious data breach involving the Department of Immigration and Border Protection.
The personal details of a third of all asylum seekers held in Australia – almost 10,000 adults and children – have been inadvertently released by the Department of Immigration and Border Protection in one of the most serious privacy breaches in Australia’s history. 
A vast database containing the full names, nationalities, location, arrival date and boat arrival information was revealed on the department’s website, raising serious concerns that thousands of asylum seekers have had confidential details made public.
Every single person held in a mainland detention facility and on Christmas Island has been identified in the database, as well as several thousand who are living in the community under the community detention program. A large number of children have been identified in the release, which also lists whether asylum seekers are part of family groups. 
The breach raises serious questions about whether those identified could be placed at risk of retribution if they are returned to their countries of origin. ... 
Guardian Australia has chosen not to identify the location of the data and made the department aware of the breach before publication. 
The Department of Immigration has released a statement saying the information was never intended to be in the public domain. 
“The department acknowledges that the file was vulnerable to unauthorised access. The department is investigating how this occurred to ensure that it does not happen again,” it said.
So far there has been no statement from the Office of the Australian Information Commissioner, which has been promoting the amendments to the Privacy Act 1988 (Cth) that come into effect next month. The Office has been recurrently criticised in scholarly and civil society organisation literature for its dilatory and permissive response to serious data breaches.

The Commissioner will presumably lament that the Office is under-resourced and under-authorised … and that in dealing with the breach it is inappropriate to take any action until all information is available.

I have argued elsewhere that the Commissioner can and should offset resource problems - or lack of power pending establishment of the amendments - by use of its moral authority.

A quick and public response that condemns bad behaviour - including behaviour, such as egregious invasions of privacy by media organisations, that are permitted by the Act - may be just as effective as any imposition of a financial penalty.

So far there hasn't been a peep from the Office. That's a lost opportunity.

If the Office wants to signal that it is engaged, is vigilant, is positive, and is credible why not issue a media release indicating that the Commissioner notes with concern reports regarding a major unauthorised disclosure of sensitive information about vulnerable people. Indicate that investigation is underway. Don't wait until directed by the Minister. Don't delay for six months.

The Guardian aptly notes that
At a news conference last November, the immigration minister, Scott Morrison, outlined the government’s responsibility to protect the identities of asylum seekers in its care. 
“What the Australian government has an obligation to do, though, is ensure that we take all steps necessary so as not to violate their identity,” he said. 
“Now, it is important that people who are making claims about asylum can do so in a discreet way and a private way. And we need to take all reasonable steps under our duty of care to ensure that we don’t expose people to that situation.” 
Both the current and previous governments have said the secrecy surrounding Australian detention facilities is necessary to protect asylum seekers’ privacy.
If that is the case, let's be seen to be providing protection. More broadly, since all people - refugees or otherwise - have a right to privacy - let's see the Office announce that the matter is being investigated. Such an announcement doesn't involve a condemnation of the Department or an endorsement of claims by media organisations that are now echoing the Guardian. It does however tell us something about the Office's culture and about the importance of privacy.

As a colleague noted, it takes ten minutes to make a call to the Department, a few words for a short media release and only a few keystrokes to let the world know that exploration is underway. All in all, not very hard. All in all, cost effective. All in all, the responsiveness and initiative that we can reasonably expect from some quite well-paid bureaucrats but alas have not been seeing.
  • update 1: the Commissioner
In a welcome development the OAIC has released the following statement -
Personal information of asylum seekers — Statement from Privacy Commissioner 19 February 2014 
The Office of the Australian Information Commissioner (OAIC) is aware of this data breach. I have spoken to the Department of Immigration and Border Protection and have been assured that the information is no longer publically available. This is a serious incident and I will be conducting an investigation into how it occurred. As part of this investigation, the Department has undertaken to provide me with a detailed report into the incident. Further, the OAIC will be working with the Department to make sure they are fully aware of their privacy obligations and to ensure that incidents of this nature will not be repeated.
Past public reports by the OAIC into data breaches have been slow to appear, far less detailed and more permissive than reports by ACMA (notably regarding the latest Telstra data breach). Let us hope that the OAIC acts with vigour.
  • update 2: the Minister
The Minister for Immigration subsequently released the following media statement
Unacceptable breach of privacy 
I am advised that an immigration detention statistics report released on the Department of Immigration and Border Protection's website on 11 February 2014 inadvertently provided access to the underlying data source used to collate the report content which included private information on detainees. 
This is an unacceptable incident. I have asked the department Secretary to keep me informed of the actions that have been initiated, including any disciplinary measures that may be taken, as appropriate. 
Immediate steps were taken to remove the documents from the department's website immediately after the department became aware of the breach from the media. 
The information was never intended to be in the public domain, nor was it in an easily accessible format within the public domain. 
The department Secretary has engaged KPMG to review how this occurred and an interim report is expected to be provided next week. 
As part of that investigation the department has tasked KPMG to review all data publications and to ensure that proper mechanisms will be in place to make sure it doesn't happen again. 
I am advised the department has ensured all possible channels to access this information are closed, including Google and other search engines. It appears the personal information underlying the report cannot be accessed through search engines. 
This is a serious breach of privacy by the Department of Immigration and Border Protection. 
I have received a brief on this matter and have sought assurances that this will not occur again. 
I also welcome the privacy commissioner's investigation into this breach. 
My department will also be requesting that the media organisation that published this data advise if they have disseminated the information to any other parties and to return all copies of the information to the department.
The Guardian responded
[T]here are a few points in the immigration minister’s statement which require a response. 
Morrison says the information was not “in an easily accessible format within the public domain”. Guardian Australia can confirm that the document was freely available for download from a public area of the department’s website, along with many other public files. The document and the data contained within it were straightforward to access. 
In his statement, Morrison reveals details about the document, including the date of its publication and the type of file. In a subsequent television interview, he named the document. Guardian Australia has not released the name or date of the document, to ensure no further breach of privacy. 
Morrison concludes his statement with this paragraph: “My department will also be requesting that the media organisation that published this data advise if they have disseminated the information to any other parties and to return all copies of the information to the department.” 
No such requests have yet been received by Guardian Australia from the department, but we can confirm that we have never published the data, including in our original story; that we have refused all requests for the data from other news organisations, to protect the privacy of those named; and that we have not disseminated the data in any way. 
Guardian Australia notified the department of the breach before publication, and did not publish until the document had been removed from the department’s website. We also notified the privacy commissioner of the breach.
My item in The Conversation, with Benjamin Smith and concentrating on privacy aspects rather than broader duties to vulnerable people under the Migration Act and international law, is here.

18 February 2014

Coverage and consumer confusion

In Telstra Corporation Ltd v Singtel Optus Pty Ltd [2014] VSC 35 Elliott J of the Victorian Supreme Court has referred to Australian Competition and Consumer Commission v TPG Internet Pty Ltd (2013) 304 ALR 186 in considering television and web advertising by Optus, the second largest telecommunication company in Australia.

Telstra had sought an interlocutory injunction to stop the advertising, which first appeared in late January this year. It argued that the ads were misleading: consumers would construe claims in the ads as indicating that Optus' geographical coverage was only a percentage behind that of Telstra. Optus on the other hand argued that consumers would construe the ads as referring to coverage of the population.

In encountering ads from both enterprises last weekend my thought was that boasts about geographic coverage were, for many people, going to be less important than the quality of service along the main road spines (e.g. the Adelaide - Melbourne - Sydney - Brisbane corridor) and in the main population centres. Most Australians aren't going to spend a lot of time in the remotest and most inhospitable parts of central Australia.

The Court notes that consumers "may include the astute and the gullible, the intelligent and the not so intelligent, the well educated and the poorly educated". It also notes the High Court's analysis in ACCC v TPG -
Though the attention of a viewer might be “arrested” by the contents of a television advertisement, such a viewer cannot be expected to pay close attention to the contents of the advertisement; and “certainly not the attention focussed on viewing and listening to the advertisements by the judges obliged to scrutinise them” in legal proceedings. 
An advertisement may convey a misleading representation where “the target audience might be disposed ... to attend closely to some words of the advertisement and ignore the balance”. 
This observation concerning words in an advertisement is equally applicable to images broadcast in a television advertisement. An example where this may occur is where an advertisement selects some words or images “for emphasis and relegate[s] the balance to relative obscurity”
“[C]onsumers might absorb only the general thrust or dominant message” of an advertisement not because “of selective attention or an unexpected want of sceptical vigilance”, but as “an unremarkable consequence” of the contents of the advertisement.
Elliott J comments that
The principal circumstances surrounding the broadcast of the Advertisement are not in issue. Broadly speaking, the Population Coverage of the respective mobile networks of Telstra and Optus is similar. Telstra reaches approximately 99.3 per cent of Australia’s population, whereas Optus reaches approximately 98.5 per cent. 
In contrast to Population Coverage, the Geographic Coverage of the respective mobile networks is markedly different. As at 6 February 2014, Telstra covered 2.356 million square kilometres of the Australian land mass. In contrast, the mobile network of Optus as at 6 February 2014 covered approximately 970,000 square kilometres (ie only approximately 41 per cent of Telstra’s). I was informed by the parties that 2.356 million square kilometres represented approximately 28 per cent of the Australian land mass. 
The sizable difference between the percentages pertaining to Population Coverage and the percentages related to Geographical Coverage is attributable to the well known fact that Australian society is highly urbanised. 
Telstra alleges that the difference in Geographic Coverage is material and substantial. Although this was not expressly addressed in Optus’ defence, there could be no issue that the Geographic Coverage of the 2 networks is materially and substantially different. . . . 
The issues in this case do not raise any questions about the strength of any signal from the respective mobile networks.
Ellliott J was persuaded by Telstra's arguments.