Showing posts with label data protection. Show all posts
Showing posts with label data protection. Show all posts

Wednesday, October 27, 2021

In parting meditation on pub gossip, Czech judge peels onion on privacy limits, judicial transparency

Does GDPR pertain to pub buzz?, AG Bobek asks.
Earlier this month, Czech judge and legal scholar Michal Bobek rounded out a six-year term as an Advocate General (AG) of the European Court of Justice with a mind-bending meditation on the ultimate futility of enforcing data protection law as written and a confirmation of the essentiality of transparency in the courts.

The case on which Bobek opined hardly required a deep dive.  He said so: "This case is like an onion," he wrote.  "I believe that it would be possible, and in the context of the present case entirely justified, to remain at that outer layer.   No peeling of onions unless expressly asked for."

But the case provided Bobek an optimal diving board, and, on the penultimate day of his term as AG, he plunged and peeled.

Complainants in the case were litigants before the Dutch Council of State (Raad van State).  They asserted that disclosure to a journalist of summary case information, from which they could be identified and details of their personal lives worked out, violated their right of privacy under the General Data Protection Regulation (GDPR) of the European Union, as transposed into Dutch law.

The disclosures are permissible under a GDPR exemption for judicial activities, Bobek concluded.  But en route to that conclusion, he further opined that the potentially unbridled scope of the GDPR must be tamed to accord with social norms and democratic imperatives.

With remarkably plain reasoning, he framed the problem in a comfortable venue:

If I go to a pub one evening, and I share with four of my friends around the table in a public place (thus unlikely to satisfy the private or household activity exception of ... the GDPR) a rather unflattering remark about my neighbour that contains his personal data, which I just received by email (thus by automated means and/or is part of my filing system), do I become the controller of those data, and do all the (rather heavy) obligations of the GDPR suddenly become applicable to me? Since my neighbour never provided consent to that processing (disclosure by transmission), and since gossip is unlikely ever to feature amongst the legitimate grounds listed in ... the GDPR, I am bound to breach a number of provisions of the GDPR by that disclosure, including most rights of the data subject contained in Chapter III.

The pub might not be the only place where the GDPR runs up against a rule of reason.  Consider the more nuanced problem of footballers considering a challenge against the processing of their performance stats.  Goodness; the pub convo will turn inevitably to football.

Let's step back for a second and take stock of the GDPR from the perspective of the American street.

Americans don't get many wins anymore.  We just retreated from a chaotic Afghanistan, despite our fabulously expensive military.  We resist socialized healthcare, but we make cancer patients finance their treatments on Go Fund Me.  We force families into lifelong debt to pay for education, undermining the social mobility it's supposed to provide.  We afford workers zero vacation days and look the other way from the exploitation of gig labor.  Our men's soccer team failed to qualify for the last World Cup and Olympics, while we're not sure why our women are rock stars; it can't be because we pay them fairly.  When it comes to personal privacy, we tend to want it, but our elected representatives seem eager to cede it to our corporate overlords.

Truth be confessed, then, Americans are willing to engage in a smidge of schadenfreude when Europeans—with their peace, their healthcare, their cheap college, their Ryanair Mediterranean vacations, their world-class football, and their g—d— G—D—P—R—get themselves tied up in regulatory knots over something like the sufficient size of a banana.  Ha.  Ha.

Therein lies the appeal, to me, of Judge Bobek's train of thought.  He finds inevitable the conclusion that posting case information is data processing within the purview of the GDPR.  The parties did not even dispute that.  For today, Bobek found an out through the GDPR exemption for the business of the courts in their "judicial capacity."

The out required a stretch to accommodate posting information for journalists, which is not, most strictly speaking, a judicial capacity.  Bobek reasoned by syllogism:  For the courts to do what they do, to act in the judicial capacity, they require judicial independence.  Judicial independence is maintained by ensuring public confidence in the judiciary.  Public confidence in the judiciary is bolstered by transparency in the courts.  Transparency in the courts is facilitated by the provision of case information to journalists.  Therefore, the judicial capacity requires publication of case information to journalists.

The problem, tomorrow, is that there is no answer in the case of pub gossip.  Bobek meditated on the human condition: "Humans are social creatures.  Most of our interactions involve the sharing of some sort of information, often at times with other humans. Should any and virtually every exchange of such information be subject to the GDPR?"

Bobek
Can't be, he concluded.

[I]n my view, I suspect that either the Court, or for that matter the EU legislature, might be obliged to revisit the scope of the GDPR one day. The current approach is gradually transforming the GDPR into one of the most de facto disregarded legislative frameworks under EU law. That state of affairs is not necessarily intentional. It is rather the natural by-product of the GDPR's application overreach, which in turn leads to a number of individuals being simply in blissful ignorance of the fact that their activities are also subject to the GDPR. While it might certainly be possible that such protection of personal data is still able to "serve mankind," I am quite confident that being ignored as a result of being unreasonable does not in fact serve well or even contribute to the authority or legitimacy of any law, including the GDPR.

While we await reassessment of the bounds of data privacy law in modern society, Bobek opined more and mightily on the importance of judicial transparency as a countervailing norm.  He opened the opinion with philosopher-jurist Jeremy Bentham:

"Publicity is the very soul of justice. It is the keenest spur to exertion, and the surest of all guards against impropriety.… It is through publicity alone that justice becomes the mother of security. By publicity, the temple of justice is converted into a school of the first order, where the most important branches of morality are enforced...."

Bobek later picked up the theme:

Judging means individualised detail brought to the public forum....

On the one hand, the basis for judicial legitimacy in an individual case are its facts and details. The judge settles an individual case. His or her job is not to draft abstract, general, and anonymous rules detached from individual facts and situations. That is the job of a legislature. The more a judicial decision departs from or hides the factual background to a public court case, or if it is later reported with significant limitations, the more often it becomes incomprehensible, and the less legitimate it becomes as a judicial decision.

On the other hand, ever since the Roman age, but presumably already earlier, if a claimant asked for the help of the community or later the State to have his claim upheld and enforced by the State, he was obliged to step into the public forum and let his case be heard there. In classical Roman times, the applicant was even entitled to use violence against the respondent who refused to appear in the public (the North Eastern part of the Roman Forum called comitium), before the magistrate (seated on a rolling chair on a tribune higher than the general public—hence indeed tribunal), when called before a court (in ius vocatione).

It is true that, later on, there were other visions of the proper administration of justice and its publicity. They are perhaps best captured by a quote from a judge in the Parlement de Paris writing in 1336 instructions to his junior colleagues, and explaining why they should never disclose either the facts found or the grounds for their decision: "For it is not good that anyone be able to judge concerning the contents of a decree or say 'it is similar or not'; but garrulous strangers should be left in the dark and their mouths closed, so that prejudice should not be caused to others.... For no one should know the secrets of the highest court, which has no superior except God...."

In the modern age, returning to the opening quote of Jeremy Bentham, it is again believed that even garrulous strangers should be allowed to see and understand justice. Certainly, with the arrival of modern technologies, a number of issues must continuously be re-evaluated so that garrulous strangers cannot cause prejudice to others....

Naturally, the publicity of justice is not absolute. There are well-grounded and necessary exceptions. The simple point to keep in mind here is: what is the rule and what is the exception. Publicity and openness must remain the rule, to which naturally exceptions are possible and sometimes necessary. However, unless the GDPR were to be understood as imposing a revival of the best practices of the Parlement de Paris of the 14th century, or other elements of the Ancien Régime or the Star Chamber(s) for that matter, it is rather difficult to explain why, in the name of the protection of personal data, that relationship must now be reversed: secrecy and anonymity were to become the rule, to which openness could perhaps occasionally become the welcome exception.

Bobek seems content with judicial exceptionalism in the GDPR framework.  I'm not so sure.  I rather think the problem of the courts points to the broader problem of GDPR scope.  Will there ultimately be a pub exception, too?  Stubborn American insistence on framing data protection as business regulation, as in California data protection law, suddenly exhibits some appeal.

The case is X v. Autoriteit Persoonsgegevens, No. C-245/20, Opinion of Advocate General Bobek (Oct. 6, 2021).  HT @ Edward Machin, writing in London for Ropes & Gray.

This is not Bobek's first high-profile opinion on the GDPR—even this year.  Read in Fortune about his January opinion in a Facebook case.

Sunday, June 27, 2021

Disputed allegations in malicious prosecution suits against Apple raise data protection issues

Apple Store Osaka (Sébastien Bertrand CC BY 2.0)
A case of identity theft, now the subject of lawsuits against Apple and a security contractor, SIS, in three jurisdictions, seems to have raised an alarm about data protection.  But the case might be more complicated, as the defendants have accused the plaintiff of false pleadings.

Plaintiff Ousmane Bah was a 17-year-old Bronx honors student and permanent resident alien applying for citizenship at times relevant to the complaints.  An acquaintance of Bah's acquired Bah's temporary New York driving learner's permit (ID); it is disputed what Bah knew about the acquisition.

The ID did not have a photo, and the biographical data did not match the acquaintance's in all particulars, such as height.  Nevertheless, when the acquaintance was, according to the complaints, apprehended trying to shoplift from Apple stores in New York, New Jersey, and Massachusetts, he was misidentified as Bah.  Bah was criminally charged, subject to arrest warrants, and repeatedly compelled to defend himself.  The case does not directly implicate the known risk of race discrimination in facial recognition algorithms.  But in Bah’s version of events, Apple's use of facial recognition technology to identify the perpetrator in subsequent incidents gave police a false confidence that the suspect was Bah.

Apple and SIS have filed for Rule 11 sanctions in New Jersey and characterize the complaint in that jurisdiction as fiction.  They rely on discovered communication between Bah and the acquaintance to allege that Bah knew well that he was being impersonated, and that misidentification resulted from the acquaintance’s deliberate deception, not from error on the part of Apple or SIS. 

Media have been quick to seize on the allegations in the initial complaint, which does resonate with extant privacy issues in public policy.  If the plaintiff’s allegations are complete and accurate, then the case speaks to Americans’ lack of comprehensive data protection law.  A data protection regulation like Europe’s, generally speaking, would shift the burdens of fair and accurate identification to the defendants, rather than a victim of identity theft, time and again.

Moreover, if the plaintiff’s allegations are complete and accurate, the case has unpleasant overtones in race and socioeconomic equality.  A mismatch of data between the false ID and the acquaintance's appearance prompts concern that “black” was all the retailer needed to see, and one must worry whether persons of limited means can afford to defend themselves against false charges and wrongful arrest, not to mention the collateral effects of publication of misidentification to third parties, such as employers and creditors.

Bah claims defamation and malicious prosecution.  The complaints at least allege evidence in support of actual malice, which Apple and SIS deny.  Malicious prosecution is usually a claim made against public officials in tandem with civil rights violations, but the tort is viable against private parties who initiate criminal proceedings on false pretenses.  Whether the plaintiff’s allegations hold up, I do not know.  The counter-allegations of Apple and SIS in seeking sanctions in the New Jersey case are biting.

The cases are:

  • Bah v. Apple Inc., No. 1:19-cv-03539-PKC (S.D.N.Y. filed Apr. 22, 2019) (Court Listener);
  • Bah v. Apple Inc., No. 2:20-cv-15018-MCA-MAH (D.N.J. filed Oct. 27, 2020) (Court Listener); and
  • Bah v. Apple Inc., No. 1:21-cv-10897-RGS (D. Mass. filed May 28, 2021) (Court Listener).
Bah is represented in the New York case by UMass Law alumnus Subhan Tariq, '13.  My thanks to Steven Zoni, '13, for bringing this case to my attention.

Friday, June 4, 2021

First Amendment advocate counsels caution, but doesn't rebuff, American right to be forgotten

Gene Policinski, Freedom Forum Senior Fellow for the First Amendment, published an op-ed last week for the "First Five" blog in which he counseled caution, but did not gainsay, newsroom "fresh start," or "right to be forgotten" (RTBF), programs.

Motivated in part by European notions of personal data protection, or informational privacy, especially RTBF, fresh start programs give persons covered in past news an opportunity to apply for the erasure of their coverage from online archives.  For NPR in February, David Folkenflik and Claire Miller reported on trending fresh start programs at major U.S. news outlets, such as The Boston Globe, "Revisiting the Past for a Better Future."  The NPR stories observed that these programs have come about in part because of European legal norms, even for newspapers beyond the reach of European legal jurisdiction.

In 2013, I wrote in a law review article that Americans' expectations of privacy, including RTBF, are in fact consonant with evolving European norms, but American law has been slow to keep pace.  The twin notions of finite punishment for past wrongs and of a second chance for persons who have paid their dues are quintessentially American, I wrote in a Washington Post op-ed in 2014.  Those values are reflected, for example, in Eighth Amendment jurisprudence and the Ban the Box campaign.

A prohibitive challenge to RTBF norms in the United States has been the First Amendment, which generally prohibits regulation of the republication of lawfully obtained and truthful information.  Sometimes for better and sometimes for worse, the free-speech absolutist bent of the First Amendment contrasts with a more flexible European approach to rights balancing.  Nothing about the First Amendment, however, precludes a private journalistic enterprise, such as the Globe, from erasing content voluntarily.

Like RTBF itself, fresh start programs have been criticized by free speech and mass communication scholars.  They remind us that journalism is the "first rough draft of history."  Tinkering with archives therefore vests private actors with a weighty, not to mention expensive, responsibility on behalf of the public.  Fresh start advocates point out that this work is not dissimilar to the exercise of news judgment in the first instance.  But the perspective problem is not eliminated by time.  There is no way to be sure that our present-day second-guessing of the historical record is more fair and objective than the original judgment, nor sufficiently preservationist for the future.

Old Slave Mart Museum, Charleston, S.C.
(RJ Peltz-Steele CC BY-NC-SA 4.0)
Just last week, I visited the Old Slave Mart Museum and other historical sites in Charleston, S.C.  To my eyes, the casual treatment of persons as property in the content of news media in times of slavery, as well as racism evident in later media during Jim Crow, is evidence of horrific injustice and a powerful reminder not to take for granted that one's present vision is free of bias.  What if that record had been erased, rather than preserved?  Could Henry Louis Gates Jr.'s "Finding Your Roots" have identified Ben Affleck's slave-owning ancestor (NPR) if history were redacted?

At the same time, I am an advocate for RTBF in some form, just as I support Ban the Box.  I am devoted to the First Amendment.  But digital media, that is, an internet that "never forgets," confronts our society with a new and qualitatively different challenge from any we have faced before.  Viktor Mayer-Schönberger well described in his 2011 book, Delete: The Virtue of Forgetting in the Digital Age, how forgetting, in addition to remembering, is an essential and well evolved part of human social culture.  A failure to forget is an existential threat.

Journalist and academic Deborah L. Dwyer has developed a useful and thought-provoking set of fresh start resources for journalists at her website, Unpublishing the News, cited by Policisnki.  I don't pretend to know whether fresh start, or European RTBF, or some other approach is the best solution, nor whether any of these models will stand the test of time.  I do believe that feeling our way forward is fascinating and necessary.

The op-ed is Gene Policinski, Perspective: News Outlets Need Caution in Offering a "Fresh Start," Freedom Forum (May 26, 2021).

Wednesday, March 24, 2021

Facebook shields records from Mass. AG inquiry

The Massachusetts Supreme Judicial Court today ruled on efforts by Facebook to resist disclosures arising from an internal investigation into application development.  The disclosures are sought by the commonwealth attorney general, which is investigating allegations of consumer data misuse.

AG Healey
(Zgreenblatt CC BY-SA 3.0)
The court's ruling is mixed, but, overall, Facebook gained ground.  The court allowed Facebook more latitude than it won in the lower court to resist disclosure on grounds of attorney work product.  On remand, the lower court will have to scrutinize the records to separate attorney opinion, which is protected, from mere facts, which are not.  The SJC agreed with the lower court that one set of records was within attorney-client privilege, and Facebook will have to produce a privilege log.

Facebook seems to be taking seriously the investigation by the office of Attorney General Maura Healey, and it should.  The company hired fixer-firm Gibson Dunn to handle its internal investigation and is represented by Wilmer Hale in the Massachusetts investigation.  Massachusetts data protection regulation is antiquated relative to the latest generation of regulations in Europe and California, but the law has been on the books for more than a decade.  The AG was represented in the SJC by attorney Sara Cable, whose appointment last year as the office's first chief of data privacy and security signaled an intent to ramp up data protection.  Massachusetts consumer protection law, "93A," the basis of the AG investigation here, is famously expansive, often displacing common law tort in private enforcement and affording generous damages.

Justice Scott Kafker wrote the lengthy opinion for the court in Attorney General v. Facebook, No. SJC-12946 (Mass. Mar. 24, 2021).  Justice Kafker is on a tear of late, having written the court's opinion in a sea change in tort law in late February and the court's unanimous ruling against Gordon College in a First Amendment religious freedom case on March 5.

Monday, February 8, 2021

UK court: Long arm of GDPR can't reach California*

Image my composite of Atlantic Ocean by Tentotwo CC BY-SA 3.0
and "hand reach" from Pixabay by ArtsyBee, licensed

*[UPDATE, Jan. 30, 2022:] On December 21, 2021, the Court of Appeal allowed service on U.S. defendants without ultimately resolving the GDPR territorial scope question.  Read more from Paul Kavanaugh, Dylan Balbirnie, and Madeleine White at Dechert LLP.]

A High Court ruling in England limited the long-arm reach of European (now British) privacy law in a suite of tort claims against Forensic News, a California-based web enterprise doing "modern investigative journalism."

The complainant is a security consultant investigated by Forensic News and a witness in the U.S. Senate Intelligence Committee probe into Russian interference in the 2016 U.S. elections.  A British national, he accused Forensic News of "malicious falsehood, libel, harassment and misuse of private information," the latter based on violation of the British enactment of the European General Data Protection Regulation (GDPR).

The extraterritorial reach of the GDPR has been a hot topic lately in privacy law circles, as U.S. companies struggle to comply simultaneously with foreign and burgeoning state privacy laws, such as the California Consumer Privacy Act (CCPA).  

Forensic News has no people or assets in the UK, but the complainant tried to ground GDPR application in the news organization's website, which accepts donations in, and sells merch for, pounds and euros.  No dice, said the court; it's journalism that links Forensic to the plaintiff and to the UK, not the mail-order side show.

The case is Soriano v. Forensic News LLC, [2021] EWHC 56 (QB) (Jan. 15, 2021).  Haim Ravia, Dotan Hammer, and Adi Shoval at Pearl Cohen have commentary.

Wednesday, February 3, 2021

Court: Employer has no free speech right to republish worker healthcare data that state provides conditionally

Confidential (Nick Youngson Alpha Stock Images CC BY-SA 3.0)
An employer has no First Amendment right to republish the identity of workers who relied on publicly subsidized healthcare when the state provides the names conditionally, for restricted use, the Massachusetts Appeals Court held yesterday.

A state program imposed assessments on employers whose employees relied on publicly subsidized healthcare.  The state offered to tell the employer which employees triggered assessment, so that the employer could review, and if appropriate challenge, the assessment. But the names came with strings attached: employers were required to promise that they will use the names in the administrative process only and not republish them.

Emerald Home Care, Inc., challenged the assessment program and conditional disclosures as violative of procedural due process and the First Amendment.

Affirming the Superior Court, the Appeals Court rejected both arguments.  As to due process, the state provided employers ample notice and opportunity to be heard in resisting the assessments.  As to the First Amendment, the state may attach conditions to access to confidential information.

In the First Amendment analysis, the court cited two U.S. Supreme Court oldies but goodies: LAPD v. United Reporting (1999) and Seattle Times v. Rhinehart (1984).  In LAPD, the Court allowed a statute to condition access to criminal histories on non-commercial use.  In Seattle Times, the Court allowed a protective order on discovery disclosures in a defamation-and-privacy case in which a newspaper was the defendant.

Justice Desmond
The Appeals Court applied intermediate scrutiny, drawn from Seattle Times.  The court reasoned that confidentiality in healthcare insurance information is an important state interest, and the restrictions on disclosure were closely tailored to the purpose of maintaining confidentiality while allowing the employer limited access for the purpose of administrative review.

The case is not remarkable for its holding, but it marks an ongoing tension between U.S. and foreign law over free speech, privacy, and data protection.  In the United States, the First Amendment often is a wrench in the works of government efforts to regulate information downstream from its disclosure to a third party.  Legal systems elsewhere in the world are more comfortable with the notion that a person's privacy rights may tag along with information in its downstream transfer from hand to hand, outweighing the free speech right to republish.

I noted some years ago that in some areas of U.S. law, including freedom of information (FOI), or access to information, we can see examples of American privacy expectations that accord with, not diverge from, European norms.  Downstream control by contract has been a key advancement in making some jurisdictions willing to furnish court records to information brokers.  Binding a broker to adjust records later as a condition of receipt helps to solve problems such as expungement, the American judiciary's equivalent to the right to be forgotten.

The case is Emerald Home Care, Inc. v. Department of Unemployment Assistance, No. AC 20-P-188 (Mass. App. Ct. Feb. 2, 2021).  Justice Kenneth V. Desmond Jr. authored the opinion for a unanimous panel that also comprised Chief Justice Green and Justice Lemire.

Sunday, October 25, 2020

'Right to repair' of Mass. Question 1 would close loophole, aid consumers; industry opposition misleads

Teen mechanic in Philippines, 2014
(Rojessa Tiamson-Saceda, USAID, via Pixnio CC0)
Massachusetts has a right-to-repair initiative (Question 1) on the ballot this Election Day.

Voter information explains: "Under the proposed law, manufacturers would not be allowed to require authorization before owners or repair facilities could access mechanical data stored in a motor vehicle’s on-board diagnostic system, except through an authorization process standardized across all makes and models and administered by an entity unaffiliated with the manufacturer."

Passing this initiative should be a no-brainer.  The provision is in fact only an update to an existing law that voters approved in 2012.  Extending the right to repair to "telematic" data, the new law would close a right-to-repair loophole, through which carmakers can shield vehicle data against access by transmitting data out from the vehicle to a proprietary server.  The only source of controversy here should be how we let corporations continuously try to exploit law and technology to evade accountability to consumers and line their pockets with monopolistic product strategies.

The initiative is opposed by the "Coalition for Safe and Secure Data."  The organization's tack is that if you vote yes on Question 1, you'll facilitate domestic violence, because vehicle information can be misused by violent ne'er-do-wells.  The threat is a repulsive red herring, especially considering that telematic data about consumers already are being relocated without subject sign-off.  The Coalition for Safe and Secure Data is not the sheep of consumer privacy advocacy it pretends to be, but a wolf of a trade group, funded to the tune of $25m by the motor vehicle industry to shut down Question 1, according to Commonwealth Magazine.

Friday, October 23, 2020

Canadian privacy advocate deploys anti-SLAPP law in suit by electronic exam proctoring company

John Oliver's Big Coal SLAPP nemesis, Bob Murray, retires

Pixabay by Aksa2011
An IT specialist at a Canadian university is defending a lawsuit against a U.S. tech company over its allegations of copyright infringement and his allegations of infringement of student privacy.

Proctorio is an Arizona-based company offering online testing to academic institutions.  It's similar to ExamSoft, which is used by my law school, the Massachusetts Bar, and other academic and licensing organizations.

Needless to say, businesses in the mold of Proctorio and ExamSoft have taken off since the pandemic.  But these businesses are not without their problems, and their widespread use has brought unwanted scrutiny to their terms of service.

For example, the Electronic Frontier Foundation raised a red flag over ExamSoft in anticipation of its adoption to administer the California bar exam.  Examsoft's terms of service afford the company overbroad reach into the computers of users and, worse, collection of biometric data from studying their faces on screen.  My students have raised legitimate concerns about ExamSoft, and I will not be administering a "closed-book" final exam because I share those concerns.

UBC (GoToVan CC BY 2.0)

Related privacy worries motivated University of British Columbia learning technology specialist Ian Linkletter, MLIS, to tweet out the URLs of unlisted Proctorio instructional videos located at YouTube, meaning to make his case that the company is excessively intrusive of student privacy.  In response, the company sued Linkletter in British Columbia for copyright infringement and breach of confidence.

Now Linkletter has filed for dismissal under British Columbia's anti-SLAPP law.  Linkletter told the Vancouver Sun that fighting the lawsuit for just "more than a month has cost him and his wife tens out thousands of dollars."  Read more in Linkletter's public statement of October 16.

B.C.'s anti-SLAPP law was enacted unanimously by lawmakers in March 2019.  Oddly enough, B.C. lawmakers passed one of Canada's first anti-SLAPP laws in 2001, but quickly repealed it over doubts about its efficacy.  I wrote recently about the dark side of anti-SLAPP laws.  Never have I denied that they are sometimes deployed consistently with their laudable aims; rather, my concerns derive from their ready abuse when deployed against meritorious defamation and privacy causes.   

The case is Proctorio, Inc. v. Linkletter, Vancouver Reg. No. S-208730 (filed B.C. Sup. Ct. Sept. 20, 2020) (civil claim).

Bye, bye, Bob

[UPDATE, Oct. 27, 2020. To be clear, I wrote that sub-headline before this happened: "Coal giant Robert Murray passes away just days after announcing retirement" (Stephanie Grindley, WBOY, Oct. 25, 2020).]

In other, if distantly related, anti-SLAPP news, Bob Murray is resigning and retiring as board chairman of American Consolidated Natural Resource Holdings Inc., successor of Big Coal's Murray Energy.  It was a tangle with Murray that turned HBO comedian John Oliver into an anti-SLAPP champion.  And, I admit again, HBO's use of anti-SLAPP law was textbook and laudable after Murray brought a groundless suit against the network.

While I disagree with Oliver over anti-SLAPP, he's one of my favorite comedians and social activists, and definitely was the mic-drop-best live act I've ever seen.  Here are his key Murray Energy treatments from Last Week Tonight.

The first, June 18, 2017, drew Murray's lawsuit.

The second, November 10, 2019, followed up with a paean to anti-SLAPP, wrapping up with a musical tribute to Murray.

Tuesday, October 20, 2020

Jarosiński to talk cloud law, from Europe to Zoom, in free transnational legal webinar series

Jarosiński
Wojciech Jarosiński, a friend and colleague, will speak in November on "The Cloud: A New Legal Frontier."  The talk is part of a free webinar series of the American Law Program (ALP) of the Columbus School of Law at The Catholic University of America (CUA) in Washington, D.C., and the law school, foreign program office, and American law student society at Jagiellonian University (UJ) in Kraków, Poland.

In just under a decade, armed with master's-in-law-degrees from UJ and CUA, attorney Jarosiński has risen to prominence as an accomplished attorney in transnational business.  Now a partner at the Maruta Wachta law firm in Warsaw, he heads the dispute resolution practice group, leading or supervising a portfolio of more than 200 technology cases valued at more than US$2bn.  At the same time, I know Wojtek to be a gifted and globally minded person.  In his spare time, he is a co-founder, expedition planner, and skipper for Vertical Shot Expeditions, a wilderness adventure company offering photography expeditions in remote locations from pole to pole.

Here is the description of the talk, which will be in English.

Until recently, the cloud was mainly storage for surplus holiday photos. Today, the cloud plays a vital role in commerce: allowing businesses to thrive in geographically distant markets, limiting operational costs, and enabling workplace flexibility for employees. These applications, though, bring sleepless nights for judges who try to apply existing law to a new reality.

This webinar will begin with a brief introduction to the cloud’s basics: where the cloud is located, what is stored there, and whether it is even possible to avoid the cloud in today’s business world. Then, the session will move to opportunities for lawyers to guide their clients through cloud regulations—highlighting the importance of legal education in cross-border legal concepts. Finally, the webinar will consider dispute resolution regarding cloud-based services. The webinar will consider Zoom, Apple Mail, Amazon Web Services, Oracle, and many other popular services, as well as the Court of Justice of the European Union Schrems II decision and the U.S. Cloud Act. 

The talk is scheduled for Tuesday, November 24, at 1 p.m. U.S. EST (6 p.m. GMT, 7 p.m. CET).  All of the talks in the series are free, but advance registration is required.  

Here is the full schedule.  [UPDATED, Oct. 22: All fall dates are now open for registration.]

  • OCTOBER 21 – Marc Liebscher, "Wirecard, Europe’s Enron? – Auditor Liability to Investors in Corporate Fraud"
  • OCTOBER 28 – Sarah H. Duggin, "Why Compliance Matters – The Increasing Significance of the Compliance and Ethics Function in Global Corporations"
  • NOVEMBER 19 – Roger Colinvaux, "Nonprofits in Crisis: Changes to Giving Rules and Politicization"
  • NOVEMBER 24 – Wojciech Jarosiński, "The Cloud – A New Legal Frontier"
  • DECEMBER 2 – Justyna Regan, "Data Privacy in the US: Where We Stand Today and Predictions for the Future"
  • DECEMBER 9 – Megan M. La Belle, "Artificial Intelligence and Intellectual Property"

I'm proud to claim Wojtek as an alum of one of my classes in 15 years' teaching in the CUA-UJ ALP, though I doubtless have naught to do with his success.  Regrettably, the ALP is not running live this year, because of the pandemic.  Lemonade from lemons, though, is the fascinating work being produced by the Law Against Pandemic project (CFP, CFP en español).  I was privileged meanwhile, in May, to offer an item on American tort law to the pilot iteration of the ALP webinar series.