Articles Posted in Government

Most, if not all, of our readers are familiar with e-commerce websites and related transactions.  Notably, Amazon.com’s empire, as well as other forms of e-commerce such as iTunes subscription services or purchasing an e-Book are part of these transactions.  In recent news, one of China’s largest e-commerce websites is being sued in the United States for selling counterfeit and knock-off products. Shares of the company, Pinduoduo, plummeted after news of the lawsuit was made public.  Currently, six law firms are in the process of filing class actions on behalf of investors who purchased shares of Pinduoduo.  The company went public in the United States earlier this year, raising over $1.6 billion from investors. Pinduoduo is traded on NASDAQ under PDD, and currently has a $25 billion market cap.

Pinduoduo is known for combining online shopping with entertainment. It was founded in September 2015 by Colin Guang, a former Google employee.  As of now, however, the company has faced an influx of negative media in China, with claims that the platform sells knock-offs of major brand names. This selling of fake goods could give investors standing to sue.  If the investors were misled, and invested because of the false information, they will have a cause of action under the federal securities laws. Executives of companies, and insiders who communicate information to investors about a company, have a duty not to make any misleading or materially false statements about the company.  This includes information about the financial health of the business.

Started only three years ago, Pinduoduo had 295 million active users and 4.3 billion total orders in 2017.  China is the largest online retail market, with other e-commerce names such as Alibaba and JD.com.  Pinduoduo sells groceries, electronics, clothing, and household items, among other things.  While Amazon may be the number one e-commerce website in the United States, Pinduoduo is the second larges e-commerce website in China behind Alibaba.

Do you monitor what personal information companies access and store when you visit a website?  Do you wish you had more ability to know what companies do with such data?  In 2018, user data privacy rights have become a major topic for discussion. Starting with Europe’s enactment of the General Data Privacy Regulation earlier in the year, and California’s passing of the Consumer Privacy Act, we have seen many changes in the online legal world.  The trend continues, with internet giants now lobbying for a federal regulatory scheme, which would ease the number of laws they have to comply with if each state follows California and enacts its own user privacy legislation.  In this blog, we will provide an overview of the recent changes.

After California passed a law this year, which grants consumers greater data privacy rights, there has been much backlash from technology giants.  Facebook, Google, Microsoft, and IBM are currently lobbying officials in Washington for a federal privacy law that would overrule California’s legislation.  These technology giants are hoping for such legislation to be passed through Congress, as the lobbyists would influence how the law is written, giving them discretion over their ability to use personal data and information.  Because federal law on such a matter would supersede state law, California’s user privacy law may become naught.

According to Ernesto Falcon of Electronic Frontier Foundation, a user rights group, the strategy of Facebook, Google, and Microsoft here is “to neuter California[‘s law] for something much weaker on the federal level.  The companies are afraid of California because it sets the bar for other states.”  As user data and information is such a key part of the business model of the social media companies – who use such information to sell advertisements – they want as much freedom as possible to collect and exploit such data.

Is a warrant required for law enforcement to access a suspect’s location information generated by the suspect’s cell phone?  Would obtaining such data violate a person’s Fourth Amendment rights?  In this blog, we will be discussing whether a warrant is required for law enforcement to access a user’s location information from cell phone service providers.  As geolocation information is almost continually updated when users interact with apps and send and receive messages, such location information is almost always available.  But also, as constantly available are Fourth Amendment rights, namely the right to be free from unreasonable searches and seizures.

In Carpenter v. United States, the Supreme Court analyzed this Fourth Amendment issue.  In order to obtain a search warrant, police typically must submit a warrant application to an independent judge or magistrate.  In the application, the police must outline facts leading the judicial officer to believe there is probable cause that the suspect is engaging in criminal behavior.  This showing of likely criminal behavior is known as “probable cause” and is required for police to conduct a search of a place or person.

There is an applicable federal law.  Section 2703(d) of the Stored Communications Act, which protects privacy information and the stored content of electronics, allows an exemption to the typical warrant required for a search.  Orders made under 2703(d) can compel the production of certain stored communications or non-content information if “specific and articulable facts show that there are reasonable grounds to believe that the contents of a wire or electronic communication, or the records or other information sought, are relevant and material to an ongoing criminal investigation.” This is closer to what is known as the “reasonable suspicion” standard than “probable cause.”  Reasonable suspicion comes into play when police pull over a vehicle, for example, or conduct a stop and frisk of a suspicious person who they believe may be concealing a weapon.  Reasonable suspicion is a much lower bar to meet than probable cause.

For this week’s blog post, we will continue with the topic of recent Supreme Court decisions that are affecting the business, e-commerce, and internet world.  Specifically, we will discuss Ohio v. American Express, a case involving the Sherman Antitrust Act and major credit card companies.

In the United States, credit card use is composed mainly of four cards: Visa (45%), American Express (26.4%), MasterCard (23.3%), and Discover (5.3%).  In 2010, the government and 17 states sued American Express, Visa, and Mastercard, alleging that the credit card companies were unreasonably restraining trade and therefore violating the Sherman Antitrust Act.  The government claimed that the credit card companies’ “anti-steering provisions” suppressed competition from rival credit card networks. These anti-steering provisions were between the credit card companies and merchants, and prohibited merchants from “steering” cardholders at the point-of-sale to use cards with lower merchant transaction fees.  Notably, American Express charged the highest transaction fee for merchants.

In fact, both Visa and MasterCard settled with the government in a consent decree in 2011 to change their anti-steering provisions.  American Express, however, continued to litigate up until the Supreme Court case was decided on June 25, 2018. American Express’s business model is different than most credit card companies, which generate revenue mainly from the credit portion of the transactions.  It instead focuses on offering better rewards to consumers than other credit cards, typically attracting a higher-spending for the wealthier consumer.  It then generates the majority of its revenue from merchant fees, arguing that higher merchant fees are justified by the higher spending clientele that it brings to merchants (AmEx also has a higher minimum spending amount for cardholders than other credit cards).

For this week’s blog post, we will be continuing with a discussion of another recently decided Supreme Court case.  Specifically, we will cover United States v. Microsoft Corporation, and talk about the ramification’s the Court’s decision has on the world of internet technology.

This case involves user data privacy rights and the ability of US based technology companies to refuse to comply with federal warrants when user data is stored overseas.  The case had to do with the extraterritorial (outside of the United States) application of the Stored Communications Act (SCA), and whether warrants issued under SCA could be effective with regard to new internet technology such as cloud storage and data centers.

In 2013, FBI agents obtained a warrant requiring Microsoft to disclose emails and information related to a customer’s account who was believed to be involved in drug trafficking.  Microsoft attempted to quash the warrant, claiming that all of the customer’s emails and information were stored in Microsoft data centers in Dublin, Ireland.  The court held Microsoft in civil contempt for refusing to give agents the emails, but this decision was reversed by the Second Circuit.  The Second Circuit held that requiring Microsoft to give federal agents emails that were stored overseas would be outside the realm of permissible extraterritorial application of the Stored Communications Act (18 U.S.C. 2703).

For this month’s blog posts, we will be discussing some of the most recent Supreme Court cases that have been decided this year.  Specifically, we will address cases that are likely to have an impact on internet, e-commerce, technology, business, and cybersecurity laws.  We will start with a discussion of Murphy v. NCAA. 

Murphy v. NCAA was decided on May 14, 2018, and generally was the Supreme Court ruling in favor of states’ ability to legalize sports betting.  The Supreme Court overturned the Professional and Amateur Sports Protection Act (“PASPA”) which previously prohibited all but a few states from legalizing sports gambling.  In Murphy, the Supreme Court held that PASPA violated states’ rights to make their own decisions regarding the legality of sports gambling.  The Court explained that Congress cannot commandeer states to enact or enforce a federal regulatory program, which was essentially what PASPA as a federal statute was doing towards the states.

Many states, such as New Jersey, are thrilled with this decision.  They view it as an opportunity to generate revenue, prevent black market gambling, and help their economy.  The Court’s decision in Murphy empowers states with the ability to legalize and regulate an estimated $150 billion sports betting industry that was previously illegal.  New York, Connecticut, West Virginia, and New Jersey are among the 20 or so states already introducing legalizing legislation.

Cyberbullying in schools is one of the most troubling activities currently plaguing our educational system.  When children are bullied, they can’t focus, they don’t feel that they fit in, and they often lose interest in school.  This creates absenteeism, depression, and even suicide among school-age children and teenagers in our society.

According to the California Attorney General: “Anyone who sends any online communication to deliberately frighten, embarrass, harass, or otherwise target another is a cyber bully.”  California Penal Code section 652.3 is slightly more specific, and states that every person who, with the intent to place another person in reasonable fear for their safety of the safety of their immediate family, by means of an electronic communication device, for the purpose of harassing, is guilty of a misdemeanor punishable by up to one year in a county jail, by a fine of not more than one thousand dollars ($1,000), or both.  Penal Code § 652.3 also makes it a crime to electronically distribute or make available personal identifying information, including a digital image of another person, or an electronic message of a harassing nature about another person, which would be likely to incite or produce unlawful action.

California law defines harassment as: A knowing and willful course of conduct that a reasonable person would consider as seriously alarming, seriously annoying, seriously tormenting, or seriously terrorizing and that serves no legitimate purpose (Penal Code § 652.3).  Electronic act as related to cyberbullying means: The transmission of a communication, including a message, text, sound, or image, or a post on a social network, by means of an electronic device.  This means that any post through Facebook, Twitter, Instagram, Snapchat, or email qualifies as an electronic act, and thus subjects the sender to potential liability for cyberbullying.

In our first June blog post, we discussed a bill passed by the State Senate which would provide net neutrality rules for ISPs in the State of California.  We continue this week with the theme of internet regulating laws being proposed in our state.

The California Consumer Privacy Act of 2018 (CCPA) is a ballot measure, which would provide unprecedented protection for user data in California.  Users would have the ability to prevent companies from selling their data to third parties, as well as demand full disclosure of all data being collected.  Consumers would also have the ability to sue companies in violation of the law.

The CCPA was started by Alastair Mactaggart, a real estate developer in the San Francisco area, along with Rick Arney, a finance executive, and Mary Stone Ross, an attorney who has worked on national security matters with the House of Representatives and was a former CIA analyst.  The group says they are just three people living in California who want what is best for their kids and the future of Californians.  They believe the “bargaining” that occurs between big companies and users regarding consumer privacy, which is basically take-it-or-leave-it is not bargaining at all.  With the practical necessity of laptops and cell phones today, they want users to have more choice and power in terms of what information is collected, and how that information is used.

On May 30, 2018, the California State Senate voted to pass a bill that will ensure net neutrality on the internet in the State of California.  With the FCC’s repealing of Obama-era net neutrality rules going into effect on June 11, 2018, California’s bill will provide for continued net neutrality protection.  Officially known as Senate Bill 822, the senate passed SB 822 by a vote of 23-12.  The bill will next go to the State Assembly to be voted on by the end of August.  If the bill passes the Assembly, it must finally be signed by Governor Jerry Brown in order to become law.

If made into law, the bill will prohibit Internet Service Providers (ISPs) from manipulating internet traffic.  Net neutrality rules ensure that ISPs cannot slow down or block access to certain websites, or give some websites and content quicker access speeds than others.  Preventing willful alteration by ISPs of internet connections between devices and sources of content is the key focus of net neutrality rules.  SB 822 will also allow the state to supervise commercial interconnection deals between corporate customers and ISPs to ensure that corporate customers are not taken advantage of by ISPs’ dominant market power.  Interconnection arrangements typically occur between content providers such as YouTube and Netflix, and ISPs such as Spectrum or AT&T.

The net neutrality rules would also ban third-party paid prioritization, as well as application-specific differential pricing.  Paid prioritization occurs when content providers pay ISPs a fee in order to ensure that users have higher access speeds to their websites than competitors’ websites.  ISPs claim that preventing this business model may cause an increase in the price that consumers pay for internet service.  Differential pricing is when goods or services are offered at different price points to different consumers.  For example, a company such as Microsoft may charge a higher fee to corporate customers for Microsoft Office software than to a personal user who purchases the software for use at home.  Differential pricing comes into play in the net neutrality laws with regards to user access to applications, content, and platforms (ACP).

Last week we discussed smart toys, and we mentioned “COPPA” in that article.  As such, some of you may be asking what is COPPA?” In short, COPPA is a federal law specifically tailored towards children, and stands for “Children’s Online Privacy Protection Act.” This law is meant to protect children from over exposure and prohibit businesses from gathering invasive amounts of analytics on children using their products or services. This remains a legitimate concern, attempting to curtail some of the worst aspects of online life.  What exactly does COPPA prohibit? Is there any limitation? Does it provide guidelines for a business to follow and ensure compliance?

COPPA Prohibitions

The spirit of COPPA can be summarized as follows: It is unlawful for an operator or a website or online service directed to children or with knowledge that it is collecting or maintaining a child’s information, to violate this federal statute by failing to give notice on the website of what information it collects, how it’s used, and how it’s disclosed, failing to obtain parental consent, providing reasonable means for parents to review or cancel the use of the service or website, to not condition participation in a game, offering of a prize or other activity by disclosing more personal information than is necessary, and failing to establish and maintain procedures to protect the confidentiality, security and integrity of the children’s information.