Hollywood film studios, talent and other deal participants regularly commit to, and undertake production of, high-stakes film projects on the basis of unsigned “deal memos,” informal communications or draft agreements whose legal enforceability is uncertain. These “soft contracts” constitute a hybrid instrument that addresses a challenging transactional environment where neither formal contract nor reputation effects adequately protect parties against the holdup risk and project risk inherent to a film project. Parties negotiate the degree of contractual formality, which correlates with legal enforceability, as a proxy for allocating these risks at a transaction-cost savings relative to a fully formalized and specified instrument. Uncertainly enforceable contracts embed an implicit termination option that provides some protection against project risk while maintaining a threat of legal liability that provides some protection against holdup risk. Historical evidence suggests that soft contracts substitute for the vertically integrated structures that allocated these risks in the “studio system” era.
31 July 2012
Soft Contracts
The insightful 'Hollywood Deals: Soft Contracts for Hard Markets' (USC Legal Studies Research Papers Series No. 12-15) by Jonathan Barnett notes the observation by Ninth Circuit Judge Alex Kozinski comment in Effects Assoc., Inc. v. Cohen 908 F.2d 555 (9th Cir. 1990) that “Moviemakers do lunch, not contracts” before commenting that
Rebalancing Copyright
The concise 'Copyright in the Participatory and Online Video Environment' by Patricia Aufderheide, co-author with Peter Jaszi of Reclaiming Fair Use: How to put balance back in Copyright (University of Chicago Press, 2011), argues that
the nature of copyright exceptions to the limited monopoly rights of copyright holders as well as why a grasp of copyright exceptions is central to the evolution of participatory and online video environments. It also explains the historical underpinnings of unbalanced copyright policy, and how challenging attempts to rebalance it have been. In that light, the success of practice-related rebalancing efforts has been remarkable. These rebalancing efforts are of particular interest to participatory and online video creators and users, who can both make use of their successes and translate their techniques into the copyright regimes of their own national environments. Finally it argues that such participation in rebalancing copyright will be critical to the evolution of participatory and online video culture.Aufderheide concludes
he U.S. experience is valuable to international creators. In practical terms, since the U.S. has the harshest penalties for infringement, clearing the fair use bar is usually good enough for many commercial distributors internationally. The logic of fair use is entirely different from the exceptions of other nations. The core principle of freedom of expression applies to all, however, and many of the same options are available to users, even though for different legal reasons.
The U.S. example has already proved inspirational. As a result of the achievements of U.S. documentary filmmakers, filmmakers under other copyright regimes in other countries have also explored, sometimes with scholarly help, the opportunities to make the most of exceptions under their law. South African filmmakers have probed the possibilities of more aggressively employing right of quotation, especially in the effort to document the history of apartheid (Flynn & Jaszi, nd. [2009]). Norwegian filmmakers have also discovered that right of quotation appears to be a far more ample exception than they have heretofore exploited (Larsen & Nærland, 2010).
These policy victories and successes in expanding creative practice demonstrate that creators who are aware of their rights can take creative action, and also take political and policy action to defend them. They can both innovate in their field and support innovative policy. They also provide a small but sturdy challenge to the overreach of large copyright holding stakeholders, who typically discount the value of copyright exceptions. Nonetheless, such actions remain demonstration cases in a much larger contest between those who hope to expand the monopoly rights of owners and those who want to increase the flexibility for use of existing culture in the creation of new culture Makers of participatory and online video, and educators who teach and support them, currently participate willy-nilly in the contest between those who wish to unbalance copyright and those who are struggling to rebalance it. They are examples of innovators, and they participate in an undefined, emergent culture, which cannot develop and grow without access to copyright exceptions. In order to explore their environment and create new culture, these creators have been forced to confront the imbalance of copyright policy.
Creators in this participatory, online environment need to understand and use the relevant exceptions to limited monopoly rights under copyright. Doing so can not only permit them creative range of action, but can enable them to exercise and defend their free speech rights. Users who are aware of their rights and see the way those rights change what they can do can also be active participants in shaping their copyright policy.
Users should be active participants in that discussion, which is lively and ongoing. Copyright policy will adapt to a more participatory creation environment, but the least adaptive of the 20th century business forces driven by monopoly rights in copyright will continue to be powerful voices. Therefore, work in legal literacy will be be important. This work, particularly making people aware of their free speech rights, must be done within the legal framework of each nation. While legal clinics, legal scholars, and pro bono lawyers can help, ultimately teachers of content, critical thinking and media literacy need to co-own the agenda of legal literacy. Legal experts can assert what the limits and terms of current law are, but this is merely the skin of practice. As has been proven by the vast changes in fair use practice in the U.S., practice creates practice; use changes the contours of law.
We can expect to see attempts on the part of large copyright holders to influence copyright policy in ways that further unbalance it. Some examples include: extending copyright terms even further; developing legislation that cripples Internet transparency in the name of limiting “piracy” (which usually means P2P downloading); demanding treaty terms that “harmonize” across national boundaries to further unbalance copyright. Members of an emergent, participatory digital culture have every reason to need a balanced copyright policy, and also to argue to policymakers that such rebalancing is in the national interest.'Museum Policies and Art Images: Conflicting Objectives and Copyright Overreaching' by Kenneth Crews in 22 Fordham Intellectual Property, Media & Entertainment Law Journal (2012) 795 looks at the 'Bridgeman Problem', commenting -
Museums face steady demand for images of artworks from their collections, and they typically provide a service of making and delivering high-resolution images of art. The images are often intellectually essential for scholarly study and teaching, and they are sometimes economically valuable for production of the coffee mugs and note cards sold in museum shops and elsewhere. Though the law is unclear regarding copyright protection afforded to such images, many museum policies and licenses encumber the use of art images with contractual terms and license restrictions often aimed at raising revenue or protecting the integrity of the art. This article explores the extent to which museums have strained the limits of copyright claims and indeed have restructured concepts of ownership and control in ways that curtail the availability and use of art images far beyond anything that may be grounded in the law.
This article examines the relevant copyright law applicable to the making and use of reproductions of art images, and it identifies the challenging pressures that museums face as they strive to make policies in the context of law but that also serve the multiple competing interests coming to bear on officials and decision makers inside museums. The article analyzes selected policies from major museums and provides an original construct of forms of “overreaching” that often appear in written standards offered by museums for the use of images. The analysis of policies also demonstrates that museums have choices in the shaping of institutional policies, and that breaking away from familiar policy terms can sometimes better serve institutional and public interests.
Speech
'Confused? Analysing the Scope of Freedom of Speech Protection vis-à-vis European Data Protection' (Oxford Legal Studies Research Paper) by David Erdos "analyses the qualified derogations under the EU Data Protection (DP) framework made available for activities which are solely journalistic, literary or artistic (Directive 95/46/EC, Article 9)".
Erdos indicates that
Erdos indicates that
notwithstanding the apparent breath of the European Court of Justice’s 2008 Satamedia judgment, the scope of this provision remains highly opaque and confused. This has led courts and regulators alike to find this ‘special purposes’ Article inapplicable when large databases of information are disseminated, when data is communicated to essentially privatized individuals, even if indeterminate in number, and when the processing includes a purpose other than journalism, literature and art. Since Member States have almost exclusively relied on this provision to reconcile Data Protection (DP) and free speech, a wide variety of expressive activity, including rating websites, mapping services, search engines, academic research, socio-political speech and social networking, are subject to onerous standards in the general data protection (DP) scheme.
The ‘special purposes’ provision in the proposed European Data Protection Regulation (COM (2012) 11 Final) must be revised so as to clearly and explicitly protect all activities orientated to disseminating information, opinions or ideas for the benefit of the public collectively. In addition, Member States should deploy more limited derogations available in the interests of the ‘rights and freedoms of others’ to protect activities which merely, but importantly, facilitate public expression (for example, search engines) or which promote individual self-expression (for example, social networking).
Nevertheless, to properly balance the competing values in this area, it is essential that such an expansion be coupled with measures specifying in a more unambiguous fashion the requirement that all derogations be truly proportionate in relation to the various rights and interests involved.
Realisms
'Legal Realisms, Old and New' by Brian Leiter argues that
“Legal Realism” now has sufficient cache that scholars from many different fields and countries compete to claim the mantle of the "Realist program": from political scientists who study judicial behavior, to the "law and society" scholars associated with the Wisconsin New Legal Realism project, to philosophers interested in a naturalized jurisprudence. But what does it mean to be a “legal realist”? What unites the two most famous “old” Legal Realisms — the American and the Scandinavian — with the “new legal realism” invoked, variously, by sociologists, anthropologists, and political scientists, among others? There are, of course, other “legal realisms,” old and new, from the “free law” movement in Germany more than a century ago, to the Italian realism of the Genoa School today. My focus, however, shall be on the old and new Realisms that are probably most familiar. Is there anything they all share?
I argue that (1) American and Scandinavian Realism have almost nothing in common — indeed, that H.L.A. Hart misunderstood the latter as he did the former, and that the Scandinavians are closer to Hart and even Kelsen than they are to the Americans; (2) all Realists share skepticism about the causal efficacy of legal doctrine in explaining judicial decisions ("the Skeptical Doctrine") (though the Scandinavian skepticism on this score is not at all specific to the legal domain, encompassing all explanation in terms of norms); (3) American Realism almost entirely eschewed social-scientific methods in its defense of the Skeptical Doctrine, contrary to the impression given by much recent work by "new" legal realists; (4) the myth that the American Realists were seriously interested in social science derives mainly from two unrepresentative examples, Underhill Moore's behaviorism and Llewellyn's work with the Cheyenne Indians. Moore's case is a cautionary note in taking au courant social science too seriously; and Llewellyn's work was necessitated by the fact that the "primitive" peoples he wanted to study did not write their judicial opinions down. For any modern legal culture, such "field work" would be unnecessary on Llewellyn's view.
Cloudy Weather
The Article 29 Working Party - the EU data protection policy body that comprises representatives of the 27 EU data protection authorities, the European Data Protection Supervisor and the European Commission - has formally adopted a 27 page Opinion on cloud computing [PDF].
The Opinion is aimed at cloud providers (processors) and users of cloud services (data controllers), with an emphasis on greater understanding of their responsibilities. It features recommendations including requiring cloud providers to tell their clients where their data may be physically stored, to make sure cloud providers delete all personal data in the cloud if it's no longer necessary, and to inform clients about any sub-contractors they plan to use to process data. It also includes specific recommendations covering transfer of European data to the US, notably that cloud clients demand the implementation of data protection safeguards with model contract clauses or a legal agreement which imposes regular reporting and auditing requirements on cloud providers to prove that data is being handled according to EU law.
The Article 29 Working Party comments that -
The Opinion is aimed at cloud providers (processors) and users of cloud services (data controllers), with an emphasis on greater understanding of their responsibilities. It features recommendations including requiring cloud providers to tell their clients where their data may be physically stored, to make sure cloud providers delete all personal data in the cloud if it's no longer necessary, and to inform clients about any sub-contractors they plan to use to process data. It also includes specific recommendations covering transfer of European data to the US, notably that cloud clients demand the implementation of data protection safeguards with model contract clauses or a legal agreement which imposes regular reporting and auditing requirements on cloud providers to prove that data is being handled according to EU law.
The Article 29 Working Party comments that -
In this Opinion the Article 29 Working Party analyses all relevant issues for cloud computing service providers operating in the European Economic Area (EEA) and their clients specifying all applicable principles from the EU Data Protection Directive (95/46/EC) and the e-privacy Directive 2002/58/EC (as revised by 2009/136/EC) where relevant.
Despite the acknowledged benefits of cloud computing in both economic and societal terms, this Opinion outlines how the wide scale deployment of cloud computing services can trigger a number of data protection risks, mainly a lack of control over personal data as well as insufficient information with regard to how, where and by whom the data is being processed/sub-processed. These risks need to be carefully assessed by public bodies and private enterprises when they are considering engaging the services of a cloud provider. This Opinion examines issues associated with the sharing of resources with other parties, the lack of transparency of an outsourcing chain consisting of multiple processors and subcontractors, the unavailability of a common global data portability framework and uncertainty with regard to the admissibility of the transfer of personal data to cloud providers established outside of the EEA. Similarly, a lack of transparency in terms of the information a controller is able to provide to a data subject on how their personal data is processed is highlighted in the opinion as matter of serious concern. Data subjects must1 be informed who processes their data for what purposes and to be able to exercise the rights afforded to them in this respect.
A key conclusion of this Opinion is that businesses and administrations wishing to use cloud computing should conduct, as a first step, a comprehensive and thorough risk analysis. All cloud providers offering services in the EEA should provide the cloud client with all the information necessary to rightly assess the pros and cons of adopting such a service. Security, transparency and legal certainty for the clients should be key drivers behind the offer of cloud computing services. In terms of the recommendations contained in this Opinion, a cloud client’s responsibilities as a controller is highlighted and it is thus recommended that the client should select a cloud provider that guarantees compliance with EU data protection legislation. Appropriate contractual safeguards are addressed in the opinion with the requirement that any contract between the cloud client and cloud provider should afford sufficient guarantees in terms of technical and organizational measures. Also of significance is the recommendation that the cloud client should verify whether the cloud provider can guarantee the lawfulness of any cross-border international data transfers.
Like any evolutionary process, the rise of cloud computing as a global technological paradigm represents a challenge. This Opinion, as it stands, can be deemed to be an important step in defining the tasks to be assumed in this regard by the data protection community in the upcoming years..
29 July 2012
Benchmarks
California and Ontario remain the most interesting provincial jurisdictions in North America from a data protection and personal privacy perspective. They offer a perspective - and a benchmark - for policy development and practice in Australia, where several state privacy and law reform agencies continue to move ahead of the national Office of the Australian Information Commissioner despite the recent (and alas very belated) profile-building campaign by the Privacy Commissioner Pilgrim.
California's Attorney General Kamala Harris recently announced the establishment of the Privacy Enforcement & Protection Unit in the state's Department of Justice, with a focus on protecting consumer and individual privacy through civil prosecution of state and federal privacy laws.
The Justice Department comments that
California's Attorney General Kamala Harris recently announced the establishment of the Privacy Enforcement & Protection Unit in the state's Department of Justice, with a focus on protecting consumer and individual privacy through civil prosecution of state and federal privacy laws.
In the 21st Century, we share and store our most sensitive personal information on phones, computers and even the cloud. It is imperative that consumers are empowered to understand how these innovations use personal information so that we can all make informed choices about what information we want to share.
The Privacy Unit will police the privacy practices of individuals and organizations to hold accountable those who misuse technology to invade the privacy of others.Harris indicated that the California Constitution "guarantees all people the inalienable right to privacy". In giving effect to that guarantee - presumably stronger than the "more or less" guarantee by Islington Council noted in the preceding post - the new unit will
protect this constitutionally-guaranteed right by prosecuting violations of California and federal privacy laws. The Privacy Unit centralizes existing Justice Department efforts to protect privacy, including enforcing privacy laws, educating consumers and forging partnerships with industry and innovators. The Privacy Unit’s mission to enforce and protect privacy is broad. It will enforce laws regulating the collection, retention, disclosure, and destruction of private or sensitive information by individuals, organizations, and the government. This includes laws relating to cyber privacy, health privacy, financial privacy, identity theft, government records and data breaches. By combining the various privacy functions of the Department of Justice into a single enforcement and education unit with privacy expertise, California will be better equipped to enforce state privacy laws and protect citizens’ privacy rights.The Privacy Unit will reside in the eCrime Unit and will be staffed by Department of Justice employees, including six prosecutors who will concentrate on privacy enforcement.
The Justice Department comments that
creation of the Privacy Enforcement & Protection Unit follows the forging of an industry agreement among the nation’s leading mobile and social application platforms to improve privacy protections for consumers around the globe who use apps on their smartphones, tablets, and other electronic devices.That agreement, recently joined by Facebook, includes Amazon, Apple, Facebook, Google, Hewlett-Packard, Microsoft and Research in Motion. It is based on privacy principles "designed to bring the industry in line with California law requiring apps that collect personal information to post a privacy policy and to promote transparency in the privacy practices of apps".
TooMuchInfo
The UK Pink News site reports Islington Council (north London) has "published details of the sexual orientation of over two thousand tenants after an error with a Freedom of Information request last month".
That disclosure resulted from an FOI request through the WhatDoTheyKnow.com site ... leading one contact to propose setting up TheyDontNeedToKnow.com and TooMuchSharingByLazyBureaucrats.com sites.
The report indicates that -
I particularly like the closing para of the report -
MySociety reports that -
That disclosure resulted from an FOI request through the WhatDoTheyKnow.com site ... leading one contact to propose setting up TheyDontNeedToKnow.com and TooMuchSharingByLazyBureaucrats.com sites.
The report indicates that -
For nearly three weeks, the names, addresses, relationship status, gender, ethnicity, and religion details of 2,376 residents was available online through the Freedom of Information request website WhatDoTheyKnow.com.
On 26 June, the housing department responded to a request that had been filed through the website, where responses to queries are automatically published, about ethnicity and gender of people who had applied for council housing.
But the spreadsheets it sent back included names, marital statuses and addresses of nearly 2,400 residents, along with their stated sexual orientation. Some personal information was visible, some was in ‘hidden sheets’ in the emailed attachments.
MySociety.org, which created the FOI request website, reports on the accidental leak that while some of the personal data was not immediately visible, anyone with basic knowledge of spreadsheet software could uncover it.MySociety is promoted as -
We build websites that give the public simple, tangible ways to connect with and improve their society. As well as offering tools directly to the public we provide integration and development services for local authorities, corporates and government.The UK Information Commissioner’s Office was informed by MySociety but as yet hasn't publicly commented.
I particularly like the closing para of the report -
At the time of that leak, Labour councillor Richard Greening had said: “We will more or less guarantee this won’t ever be repeated.”More or less?
MySociety reports that -
On the 26th June the council responded to the FOI request by sending three Excel workbooks. Unfortunately, these contained a considerable amount of accidentally released, private data about Islington residents. In one file the personal data was contained within a normal spreadsheet, in the two other workbooks the personal data was contained on four hidden sheets.
All requests and responses sent via WhatDoTheyKnow are automatically published online without any human intervention – this is the key feature that makes this site both valuable and popular. So these Excel workbooks went instantly onto the public web, where they seem to have attracted little attention – our logs suggest 7 downloads in total.
Shortly after sending out these files, someone within the the council tried to delete the first email using Microsoft Outlook’s ‘recall’ feature. As most readers are probably aware – normal emails sent across the internet cannot be remotely removed using the recall function, so this first mail, containing sensitive information in both plain sight and in (trivially) hidden forms remained online.
Unfortunately, this wasn’t the only mistake on the 26th June. A short while later, the council sent a ‘replacement’ FOI response that still contained a large amount of personal information, this time in the form of hidden Excel tabs. As you can see from this page on the Microsoft site , uncovering such tabs takes seconds, and only basic computer skills.
At no point on or after the 26th June did we receive any notification from Islington (or anyone else) that problematic information had been released not once, but twice, even though all mails sent via WhatDoTheyKnow make it clear that replies are published automatically online. Had we been told we would have been able to remove the information quickly.Drumroll for a group hug at MySociety -
It was only by sheer good fortune that our volunteer Helen happened to stumble across these documents some weeks later, and she handled the situation wonderfully, immediately hiding the data, asking Google to clear their cache, and alerting the rest of mySociety to the situation. This happened on the 14th July, a Saturday, and over the weekend mySociety staff, volunteers and trustees swung into action to formulate a plan.There are rationales [PDF] for collection of information about sexual affinity, relationship status or other attributes and for the publication of aggregate/anonymised data. A mechanistic dissemination - just press 'send' - of personal information that may or may not have been provided on a confidential basis and that should be treated with care is unacceptable for a range of reasons, including that evident disregard for potential sensitivities erodes the trust needed for legitimate information collection/handling in the public sector.
Subscribe to:
Posts (Atom)