Showing posts with label e-commerce. Show all posts
Showing posts with label e-commerce. Show all posts

21 September, 2016

Locked Out - Providers of WiFi Access Not Liable for Copyright Infringement, Says CJEU

As wireless internet connections have become near ubiquitous in our daily lives amongst the cafés, libraries or businesses we visit, so has our appreciation for the facility, especially when traveling when a weary traveler might not have a connection on their smartphone. But underneath these open networks lurks the danger, and question, of possible abuse, and thus liability for those who operate the networks. This matter has been litigated in the European courts for some time now, and after an Advocate General's opinion early this year (discussed more here), many IP specialists have been waiting for the decision in McFadden; something the CJEU finally handed down late last week.

The case of Tobias Mc Fadden v Sony Music Entertainment Germany GmbH dealt with the provision of an unprotected wireless network connection by Mr Mc Fadden at his business selling and leasing lighting and sound systems, which aimed to bring in business and interest for his endeavor.  In late 2010 a song was shared in his network by a third-party (the rights to which Sony Music owned), and Sony subsequently sent Mr Mc Fadden a notice to this effect. Mr Mc Fadden then took the matter to court, seeking a negative declaration of infringement, to which Sony counterclaimed infringement. The matter ultimately ended up in the CJEU, who sought to take on the matter of liability of infringement for the provider of an unprotected wireless network.

The referring court asked eight questions of the CJEU, who took each question in turn to answer the matter.

The first question dealt with whether the provision of an open WiFi connection could fall under Article 12(1) of the E-Commerce Directive, i.e. whether the service would be classed as an 'information society service'. The Court quickly saw that, even in the light of a lack of remuneration (as required by EU legislation in this instance), the service would be classed as an 'information society service' under the Directive if "...the activity is performed by the service provider in question for the purposes of advertising the goods sold or services supplied by that service provider". The provision of the service is clearly therefore equated to one producing a monetary gain, even if not charged for on the outset, possibly therefore being afforded safe harbor protection as a 'mere conduit'.

The CJEU then moved onto questions two and three, which they summarized together as asking whether Article 12(1) of the Directive only requires the provision of the aforementioned service so as to be included, or if further conditions have to be met for it to be deemed as have been provided under the Article. This would include a contractual relationship and the advertisement of the provider's services. The Court concluded that, for the service to have been provided under the provision, the access must not "...go beyond the boundaries of a technical, automatic and passive process for the transmission of the required information, there being no further conditions to be satisfied". This follows recital 43 to the tee, and clearly the mere passive provision of such a service would be deemed to have been 'provided' by virtue of doing only that.

Password required? Not interested!
The Court then answered the remaining questions in a non-sequential fashion, tackling question six first. This asks whether Article 12(1) should be interpreted as including a further condition set out in Article 14(1)(b) (on the removal of infringing content upon notification thereof). The CJEU saw that, as the Articles dealt with very different services (communication services v hosting), the condition does not apply to the provision of more transient services, but to ones that remain more permanent in the provided services (meaning, content hosted on a website stays on said website till removed, unlike in mere transient communication using a wireless connection).

This was followed by questions seven and eight, which the CJEU clumped together, summarizing them as asking whether Article 12(1) includes any further provisions in addition to the one within the Article, which are not expressly mentioned. The Court quickly dismissed this assertion, as further conditions would clearly impede the balance sought by the legislature in the introduction of the provision.

The Court then moved onto question four, which, in essence, asked whether a person (or entity) harmed through the infringement of a right could seek injunctive relief and/or possible costs for the harm caused using the above service to do so. If read in seclusion, the Article does preclude a person harmed from seeking such remedies; however, it does not expressly prevent them from doing so using national authorities to prevent the infringement from continuing. This would seem correct, as Article 12(3) expressly does not preclude national authorities from requiring such actions and/or allowing for the retrieval of costs.

Finally, questions five, nine and ten remained, which asked effectively whether the granting of an injunction such as the above is allowed (and complied with by the provider), when the provider is required to secure their connection through either a password or by monitoring the connection used. The Court emphasized the need to strike a balance between the rights afforded by the Directive and the Enforcement Directive 2004/48, especially when multiple rights are engaged in such an issue (as is the case here). The Court considered the different ways in which IP rights could be protected, and decided that "...a measure intended to secure an internet connection by means of a password must be considered to be necessary in order to ensure the effective protection of the fundamental right to protection of intellectual property". This measure would, according to the Court, protect both rights in intellectual property, as well as the freedom to conduct business through the supply on a wireless connection and the right to information in using the above. One has to, though, provide their details in order to be able to use the connection and therefore be identified if needed.

The CJEU's decision sets out a practical approach to protecting both interests, while not overly restricting the provision of wireless connections. The striking of this balance was key, and the CJEU seem to have settled on the right answer. The measures required are by no means excessive, and afford the provider plenty of protection in the event of the connection's abuse.

07 July, 2015

Coffee Shop Conundrum - ECJ Set to Decide on Free WiFi and Third Party Liability

In a time when the internet is nearly always with us, be it in a smartphone, a laptop or other smart devices, you often taken things for granted such as free WiFi. For many travelers it has saved their behinds from being lost, out of money, or in some unfortunate cases, even potential harm, and many of us in bigger cities like London can easily overlook the need for WiFi. But, as Uncle Ben framed it so eloquently: with great power (i.e. Internet connectivity) comes great responsibility. People can be inconsiderate, and at times outright indifferent, to potential liability issues in using other peoples' or organizations' free WiFi, which begs the question: can a third-party be liable for possible infringement on their wireless network?

The answer to the question possible lies in the forthcoming decision of McFadden, faced by the European Court of Justice later this year (this writer hopes). The case, refereed to the ECJ from the Regional Court of Munich (decision in German can be found here), concerned a store owner, Toby McFadden, in Germany who's store specialized in light and acoustic engineering services. To further promote the store and its offerings the owner allowed potential customers to freely access a WiFi connection, with no password protection included. An unknown user used this free network to upload and share an infringing song on an online file-sharing platform, and Mr. McFadden was subsequently sued by Sony Music who argued he is liable for the infringement (among other things) that occurred on his unprotected network.

The case does bring forth several questions concerning Article 12 of Directive 2000/31/EC, more commonly known as the E-Commerce Directive. Although each of the questions merits an assessment in their own right, for the sake of brevity this writer shall endeavor to answer the question above, at least in the light of Article 12.

Wifi can cause some degree of envy
What Article 12 seeks to protect are service providers, or in other words 'mere conduits', who provide a service such as free WiFi, should they remain largely hands-off of the provision of that network (i.e. don't cherry-pick the users accessing the network, don't initiate the transmission of information or alter what is received in some way). This, however, cannot be a service for which the provider is remunerated, per Recital 18 of the Directive, and aims to facilitate the better sharing and access of information within the European Community.

This writer will freely admit his lack of knowledge in German law, but proposes to give a perspective from the UK side of things. Pinsent Masons in their Out-Law blog have set out that, per German law, individuals have to secure their internet connections through reasonable means, such as a password, to avoid liability should a third-party use their connection for nefarious purposes; however, this standard does not extend to commercial entities, which the case aims to settle.

Under the Copyright, Designs and Patents Act 1988 the High Court has the capability to issue an injunction against a service provider, provided that the "...service provider has actual knowledge of another person using their service to infringe copyright". What this has been interpreted in Twentieth Century Fox Film Corp & Ors v British Telecommunications Plc to encompass is true knowledge of one or more infringers using the provided network to do so, and the more detail of knowledge or facts given to the service provider (notices etc.) the less protection the provision offers to them. One could argue that a lack of password protection would not in itself give rise to an actual knowledge of possible infringement, as users, even if filtered through via password protection, could still abuse the network without the knowledge of its provider.

Whether Mr. McFadden was brazenly aware of the infringing acts being committed on his network is unknown to this writer, and he awaits the decision of the ECJ with some interest. Voices have been raised in the protection of open networks and access thereto by entities such as the Electronic Frontier Foundation, and one must agree with them to a certain extent. The 'locking down' of networks does provide a more cumbersome regime through which information and the Internet can be accessed, but one still does have to keep in mind the protection of legitimate rights within that space. What the ECJ decides will undoubtedly have ramifications on our WiFi networks, but one can imagine they'll only remain a login away.

Source: JDSupra