06 June 2015

Metadata and Divides

'Judicial Review of Mass Metadata Surveillance in the Post-Snowden Era' (University of Cambridge Faculty of Law Research Paper No. 32/2015) by Nora Ni Loideain comments
Legal frameworks exist within democracies to prevent the misuse and abuse of personal data that law enforcement authorities obtain from private communication service providers. The fundamental rights to respect for private life and the protection of personal data underpin this framework within the European Union. Accordingly, the protection of the principles and safeguards required by these rights is key to ensuring that the oversight of State surveillance powers is robust and transparent. Furthermore, without the robust scrutiny of independent judicial review, the principles and safeguards guaranteed by these rights may become more illusory than real. 
Following the Edward Snowden revelations, major concerns have been raised worldwide regarding the legality, necessity and proportionality standards governing these laws. 
In 2014, the highest court in the EU struck down the legal framework that imposed a mandatory duty on communication service providers to undertake the mass retention of metadata for secret intelligence and law enforcement authorities across the EU. This article considers the impact of the Snowden revelations on this landmark judgment. Subsequently, the analysis explores the significance of this ruling for the future reform of EU law governing metadata surveillance and its contribution to the worldwide debate on blanket and covert monitoring in the post-Snowden era.
'Overcoming the Public-Private Divide in Privacy Analogies' by Victoria Schwartz in (2015) Hastings Law Journal (forthcoming) comments
When a photographer takes unauthorized aerial photographs of a company’s plant, the legal framework under which courts evaluate the case, as well as its likely outcome, depends on whether the photographer was hired by a private actor or the government. If a competitor hired the photographer, the aerial photography would likely constitute improper trade secret misappropriation. If, however, the government hired the photographer, the aerial photography would not violate the Fourth Amendment. This scenario illustrates a public-private divide in which privacy violations by the government are treated separately from privacy violations by the private sector. Despite this divide, some courts have analogized from the Fourth Amendment into the trade secret context, while the Supreme Court has rejected such an analogy in the opposite direction. 
A similar but reverse phenomenon occurs in the workplace privacy context. Traditionally, whether an employee whose privacy has been invaded by an employer is likely to prevail in court depends in part on whether the employer is in the public or private sector. The longstanding wisdom is that public sector employees receive stronger workplace privacy protections than similarly situated private sector employees as a result of Fourth Amendment protections. Nonetheless, Supreme Court precedent suggests that private sector analogies are appropriate in evaluating public workplace privacy cases. 
Neither courts nor scholars have offered any systematic criteria for evaluating when privacy analogies across the public-private divide are appropriate. Rather courts import or reject privacy analogies between the public and private sectors without any meaningful consideration of when such analogies make sense. This Article offers a coherent and consistent normative framework to analyze when privacy analogies are appropriate across the public-private divide. In deciding whether such privacy analogies make sense, courts ought to apply a multi-factored test in which they consider the presence or absence of factors within the privacy-invading actor that could justify the traditional public-private distinction. These factors include the power of coercion, ability to harm identity formulation or the protection of democracy, access to superior technology, and presence of bureaucratic features.

05 June 2015

Cognitive Capital

'The New Cognitive Property: Human Capital Law and the Reach of Intellectual Property' by Orly Lobel in (2015) 93 Texas Law Review 789 [PDF] comments
Contemporary law has become grounded in the conviction that not only the outputs of innovation—artistic expressions, scientific methods, and technological advances—but also the inputs of innovation—skills, experience, know-how, professional relationships, creativity, and entrepreneurial energies—are subject to control and propertization. In other words, we now face a reality of not only the expansion of intellectual property (IP) but also “cognitive property.” The new cognitive property has emerged under the radar, commodifying intellectual intangibles that have traditionally been kept outside of the scope of intellectual property. This Article introduces the growing field of human capital law at the intersections of IP law, contract and employment law, and antitrust law and cautions against the devastating effects of the growing enclosure of cognitive capacities in contemporary markets. 
Regulatory and contractual controls on human capital—postemployment restrictions, including noncompetition contracts, nonsolicitation, nonpoaching, and antidealing agreements; collusive do-not-hire talent cartels; pre-invention assignment agreements of patents, copyright, as well as nonpatentable and noncopyrightable ideas; and nondisclosure agreements, trade secret laws, and economic-espionage prosecution against former insiders—are among the fastest growing frontiers of market battles. 
Regionally and globally, these disputes heavily shape industrial competition. Through this web of extensively employed mechanisms, knowledge that has traditionally been deemed part of the public domain becomes proprietary. Pre-innovation assignment agreements regularly go beyond the subjects that IP deems commodifiable. They also regularly reach into the future, propertizing innovation that has not yet been conceived. Nondisclosure agreements span beyond traditionally defined secrets under trade secrecy laws and are routinely enforced by courts. Violations of secrecy requirements are also increasingly criminalized, chilling exchanges that are recognized as productive and consistent with professional norms. Noncompete agreements are now required in almost every industry and position, stymieing job mobility and information flows. Beyond the individualized agreements between firms and employees, new antitrust investigations of Silicon Valley giants, including Apple, Google, Intel, eBay, and Pixar, reveal the rise of collusive antipoaching agreements between firms. Postemployment restrictions have become so widespread that they form a cognitive property thicket that curtails efficient recruitment efforts and entrepreneurship. While IP law restricts knowledge and information that cannot be taken out of the public domain, this delicate balance is subverted in the emerging field of human capital law. In patent law, the lines between nonpatentable abstract ideas and patentable inventions are heavily monitored. Most recently, in June 2014, the Supreme Court unanimously ruled that a computer-implemented electronic escrow service for facilitating financial transactions was ineligible for patent protection because the claims were drawn to an abstract idea rather than a patentable invention. Similarly, in copyright law, the boundaries between expressions and ideas are extensively policed to ensure that ideas themselves will not become property. And yet, this Article uncovers how the logic of IP, cautiously maintaining a balance between monopolized information and the public domain, between propertized intangibles and knowledge flow, is undermined by a second, rapidly growing layer of cognitive controls through human capital law. The expansion of controls over human capital has thus become the blind spot of IP debates.
The talent wars are heated. More than ever before, the recruitment, retention, and engagement of employees sit atop businesses’ priority lists,  and yet human capital law remains diffuse and murky. Analyzing the current state of human capital law against new empirical research, this Article challenges orthodox economic assumptions about the need for cognitive property, demonstrates the inadvertent harm from the unrestrained shifts toward such controls, and calls for the recognition of human capital as a shared public resource. The realities of twenty-first-century production and competition, which have changed work patterns and increased the premium on constant innovation, coincide with the accumulation of new empirical insights on innovation and knowledge creation. While these developments are of great significance, legal scholarship on human capital remains surprisingly thin. The traditional and underdeveloped analysis of human capital law views controls over human capital as necessary to generate investment and growth. At the same time, a growing body of empirical evidence indicates that excessive human capital controls have detrimental effects. Law’s role in safeguarding and promoting human capital as a shared resource is little understood. A closer study of human capital law regimes suggests that the most successful regional economies have relied on legal regimes that nurture a cognitive commons, protect mobility, and encourage the densification of knowledge networks. 
The Article proceeds as follows: Part I argues that the contemporary IP debates have obscured the broader ways in which knowledge and the potential to innovate are restricted. The Part presents three interrelated expansions of human capital controls. First, subject-wise, through agreements assigning all innovation “whether patentable or nonpatentable; whether copyrightable or noncopyrightableas well as through developments in trade secret law, the propertization of intangible assets has expanded deep into the intangibility spectrum, enclosing knowledge that falls outside the scope of patent and copyright. The increased criminalization of trade secret protections, far more amorphously defined than other IP pillars, functions to further subvert the boundaries between protectable and nonprotectable knowledge. Second, time-wise, ownership has expanded to future innovation as well as attempts to go back in time and capture prior knowledge that an employee held when joining a firm. The expansion includes a rise in both pre-innovation assignment contracts, including trailer clauses, which reach into the postemployment period to assign IP ownership back to the firm, as well as new legal constructs, including the assignor estoppel doctrine, which prevents assignors from challenging the validity of a patent. The assignor estoppel doctrine dramatically limits the defenses available to former employees who seek to compete in the industry and turns these experienced employees into legal liabilities of the new firms that recruit them. Third, scope-wise, recent years have witnessed a colossal rise in the use of noncompetes along with a shift from individualized controls to metacontrols—cognitive cartels—as evidenced in the ongoing antitrust class action suit against Silicon Valley high-tech giants for their no-poaching agreements. 
Analyzing new empirical research on the nexus between innovation and human capital, Part II uncovers the harms of the new cognitive property by developing a novel taxonomy of different types of knowledge as they relate to human capital flows: tacit, relational, networked, motivational, and disruptive. Each aspect of knowledge helps explain the various harmful effects of the new cognitive property. The Part analyzes these effects of contemporary human capital law through the lens of new economic research about endogenous growth, labor-market search, and innovation networks, demonstrating the extent to which markets benefit from continuous investment in shared cognitive capital. 
Part III argues that the rise in cognitive controls should be understood as the Third Enclosure Movement, turning human capital and intangibles of the mind—knowledge, experience, skill, creativity, and network—into property, with detrimental effects on the public domain. This Part explains these developments in relation to the ongoing shift from viewing IP through the lens of antitrust to the lens of property. The expanding lens of property into the intangibles of the mind has now reached the next frontier, enclosing not merely innovation but the potential for innovation. This Part further shows how regions that promote employee mobility encourage positive spillovers and densification of knowledge networks, which lead to economic growth and innovation, and conversely how regions that restrict employee mobility stifle growth. Finally, this Part demonstrates how the threat of litigation diminishes the quality of human capital and encourages companies to hire employees with no experience rather than seasoned employees. The new cognitive property benefits incumbent firms with superior resources and chills new market entry. The Article concludes with a call to reform human capital law from a nebulous set of harmful doctrines to a body of law committed to the promotion of innovation, knowledge flow, and economic growth.

03 June 2015

The MelbIT Sale

'Market Disclosure and Governance Challenges When Floating University Research on the Stock Market: The Float of Melbourne IT Limited by the University Of Melbourne' by John Selby in 23(2) Journal of Law, Information and Science seeks
to inform stakeholders within Australian universities of some of the risks and opportunities to make better use of information in their governance processes relating to research commercialisation so as to capture a greater proportion of the profits generated by floating research companies on the Australian Stock Exchange. This article applies agency theory to argue that several internal incentive structures, information asymmetries, and decision-making processes within the governance systems of the University of Melbourne led to the university receiving a significantly smaller proportion of the overall profits from the float of MelbIT than it otherwise could have achieved. It also argues that the failure to disclose adequately to the investing public the existence of sales contracts signed by MelbIT before the closing date for subscriptions to the initial public offering of the company may have amounted to a breach of the Corporations Act 1989 (Cth), which was in force at the time. It offers valuable insights for senior managers in Australian universities who may find themselves in similar circumstances in the future.

Catch of the day jellyfish

What happens when you are a retailer, a data breach involves release of addresses and other personal information, you don't reveal the breach until three years later and the national privacy agency then takes a year to investigate?

In a word, not much!

The Office of the Australian Information Commissioner - recently praising its own diligence and effectiveness (presumably on the basis that if other people won't commend you it's necessary to resort to loud self-congratulation) - has announced that it
has finalised enquiries into Australian retail company Catchoftheday.com.au Pty Ltd (COTD), following a data breach notification received in June 2014. 
The breach featured a range of personal information.

The OAIC states that
COTD informed the Australian Privacy Commissioner of a data breach it experienced in 2011, which resulted in the compromise of personal information of COTD’s Australian customer base.
As a result, the OAIC "conducted enquiries in relation to this incident". Those enquiries took a year and of course the Commissioner has not released details.

The statement regarding finalisation - buried in the OAIC site, not as a media release or on the homepage - indicates that
the Commissioner expressed concern about the size of the breach, the possible compromise of financial information, and the significant delay between COTD becoming aware of the incident and notifying affected individuals.
Presumably COTD quivered when belatedly questioned amid the media furore that included the explanation
We unreservedly apologise to our customers for this incident. We take data security seriously and have taken strong measures to protect their personal information. We have committed significant resources both internally, with a large dedicated team and externally via expert consultants to ensure we meet industry standards.
Quite so.

The OAIC states that
COTD has taken a range of steps in response to the incident including notifying banks, credit card companies, and the police; commissioning a third party expert to investigate the issue; rebuilding the e-commerce platform that was the subject of the attack; and upgrading its infrastructure to ensure compliance with the Payment Card Industry Data Security Standards (PCI-DSS). COTD completed an internal Privacy Compliance Assessment, resulting in 20 recommendations that go to improving COTD’s privacy governance arrangements and related matters.
We can sleep soundly, knowing that the tireless bureaucrats have
recommended that COTD improve its processes for notifying customers of data breach incidents in future.
In light of the steps COTD has taken to prevent a similar incident from recurring, the OAIC does not intend to take any further action in relation to the incident at this time. However, COTD has been asked to provide a report about the implementation of the above recommendations within three months.
A sceptic might conclude that it's quite ok for an organisation to experience a major breach ... several years later the OAIC will take twelve months to conduct an investigation that culminates in being savagely flailed with a limp lettuce leaf.

The OAIC states that it
may conduct further enquiries if complaints are received from people who have been adversely affected by this incident.
Given the very substantial delays experienced by individuals who do complain to the OAIC it would be unsurprising if people don't bother making those complaints.

The OAIC response - slow-moving, insubstantial, easily-missed - resembles a jellyfish. We might reasonably look for more spine, more energy, more substance.

What are the "industry standards"? Are they adequate? Are they a matter of lowest common practice?

Should we expect more than a recommendation that COTD - and by extension its peers - "improve its processes for notifying customers of data breach incidents in future"?

Just as saliently, the response is a reminder of the need for timely, clear and comprehensive reporting by public and private sector entities that experience a data breach. We shouldn't have to wait several years. We will presumably continue to wait until there is mandatory data breach reporting, with reporting to data subjects rather than merely to a regulator that is either unwilling or incapable of using its soft power to encourage best practice on the part of database operators. Overseas jurisdictions offer proof that such mandatory reporting is feasible.

Failure on the part of the OAIC is deeply regrettable but, alas, unsurprising, given the agency's history of underperformance and resistance to external scrutiny. It fosters perceptions of regulatory incapacity (potentially regulatory capture) that encourage ongoing financial stringencies on the part of the Government. It also fosters questions about the need to establish a more vigorous, independent and properly resourced agency … particularly an agency that actively engages with civil society rather than on private consultations with unidentified entities that are not necessarily representative of business or consumers.

In the era of big data - and potential big data breaches - we need a watchdog, not an indolent bureaucratic jellyfish.

AI and torts

'Regulating Artificial Intelligence Systems: Risks, Challenges, Competencies, and Strategies' by Matthew U. Scherer comments 
Artificial intelligence technology (or AI) has developed rapidly during the past decade, and the effects of the AI revolution are already being keenly felt in many sectors of the economy. A growing chorus of commentators, scientists, and entrepreneurs has expressed alarm regarding the increasing role that autonomous machines are playing in society, with some suggesting that government regulation may be necessary to reduce the public risks that AI will pose. Unfortunately, the unique features of AI and the manner in which AI can be developed present both practical and conceptual challenges for the legal system. These challenges must be confronted if the legal system is to positively impact the development of AI and ensure that aggrieved parties receive compensation when AI systems cause harm. This article will explore the public risks associated with AI and the competencies of government institutions in managing those risks. It concludes with a proposal for an indirect form of AI regulation based on differential tort liability.

Myriad

'The Supreme Court's Myriad Effects on Scientific Research: Definitional Fluidity and the Legal Construction of Nature' by Peter Lee in (2015) 5 U.C. Irvine Law Review examines -
the implications for biomedical research of the Supreme Court’s ruling in Association for Molecular Pathology v. Myriad Genetics that isolated DNA does not comprise patentable subject matter but that complementary DNA (cDNA) does. Although most of the commentary surrounding this case has focused on the availability of genetic diagnostic tests, this Article considers the related and important implications of this opinion for scientific research. At the outset, it argues that this issue is beset with definitional complexity, as it is often difficult to disentangle “commercial” from “research” uses of patented genes. This Article further argues that context matters significantly in assessing the impact of the Court’s ruling on research. Accordingly, this Article examines the implications of Myriad Genetics from three perspectives. First, considering the conduct of Myriad Genetics itself, it argues that the Supreme Court’s decision creates greater real and perceived freedom to operate for uses of BRCA genes that may yield important scientific insights. Second, reviewing the literature on gene patents and anticommons, this Article argues that the Court’s ruling will help enhance access to diagnostic testing more generally, thus advancing biomedical research. Third, at a doctrinal level, this Article suggests that Myriad Genetics may have significant long-term implications. The Court’s opinion reflects a strong policy interest in excluding “nature” from patentable subject matter as well as a high degree of discretion in determining the contours of nature for that purpose. Such a policy-oriented, pragmatic approach to patent eligibility may create significant flexibility to challenge patents in research contexts going forward.

Assemblage

'Copyright and the New Materialism' by Dan L. Burk in Jessica Lai & Antoinette Maget (eds.) Intellectual Property and Access To Im/Material Goods (Forthcoming)  comments
Copyright has long rested upon a series of dualistic doctrinal structures, including the fundamental dichotomy between the immaterial “work” and its fixation in a physical “copy.” This distinction, which was never entirely coherent even in traditional media, has broken down in the face of digital instantiations of creativity. The disconnection between legal doctrine and new media has now resulted in decades of incomprehensible decisions regarding the fixation of works in computer circuitry or the transmission of works across telecommunications media, particularly the Internet. However, during the past several years, an increasing number of scholars in a variety of fields have begun to re-emphasize the centrality of matter in their exploration of the world. New materialism might offer copyright a path out of such unsustainable distinctions, by providing a viewpoint that traverses the artificial opposition of work and copy, recognizing the primacy of matter in the development of creative expression.