Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§...

73
Hot Topics in Privacy, Class Actions and IP: Things Every Lawyer Needs to Know about Risks, Compliance and Best Practices in This Age of Big Data, Big Lawsuits and Big Risk July 16, 2014

Transcript of Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§...

Page 1: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Hot Topics in Privacy, Class Actions and IP:Things Every Lawyer Needs to Know about Risks, Compliance andBest Practices in This Age of Big Data, Big Lawsuits and Big Risk

July 16, 2014

Page 2: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Agenda

I. Privacy (Dominique Shelton) Big Data

o Regulatory and Legislative focus in May 2014o Behavioral Tracking Class Actionso Video Privacy Protection Act (“VPPA”)o TCPA

Mobile Apps Data Security/Reasonable Security

II. Privacy Class Actions (Cari Dawson)

III. Overlap between IP and Privacy (Ryan Koppelman)

Page 3: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Dominique R. SheltonPartner

Alston & Bird LLP333 S. Hope Street, 16th Floor

Los Angeles, CA 90071(213) 576 1170 

[email protected]

Big Data

Page 4: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Emerging Legal Issues Relating to Data

Regulatory and Legislative Focus:

May 2014

Page 5: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Five Big Data Reports in May 2014

• May 1, 2014 ‐ White House release Big Data led by John Podesta. See, Executive Office of the President, Big Data: Seizing Opportunities, Preserving Values (Executive Office of the President, May 1,2014)

• May 1, 2014: White House releases technological feasibility Big Data report. See, President’s Council of Advisors on Science and Technology, Big Data and Privacy: A Technological Perspective (the “PCAST Report)

• May 15, 2014: The Senate released a report on malware. Senate Permanent Subcommittee on Investigations, “Online Advertising and Hidden Hazards to Consumer Security and Data Privacy (May 15, 2014)

• May 21, 2014: CA AG came out with her report on privacy policies See, Att’y Gen. Kamala D. Harris, Making Your Privacy Practices Public: Recommendations on Developing a Meaningful Privacy Policy, (Cal. Dep’t of Justice, May 21, 2014), available at http://tinyurl.com/CAAGMakingYourPrivacyPractices .

• May  27, 2014: Data Broker report. See,  F.T.C., Data Brokers: A Call for Transparency and Accountability (May 27, 2014)

Page 6: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

May 2014 Reports

Page 7: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Takeaways

• The Senate, FTC and CA AG are focused on “Big Data” and behavioral tracking in particular.

• There is a renewed focus on transparency.  Regulators are concerned that consumers don’t understand the advertising/data‐broker ecosystem (i.e., the number of trackers on websites and mobile apps).

• Use of internal data‐tagging can provide a method for companies to access to Big Data within companies.

• New laws will be proposed.• FTC will be using Section 5 of the FTC Act to enforce.

Page 8: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Emerging Legal Issues Relating to Data

Behavioral Tracking Class Actions(Privacy Claims under The Electronic 

Communications Privacy, Stored Communications Act and Wiretap Act)

June 2014

Page 9: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

How Big are “Do Not Track” Class Actions?

– 195 Do Not Track class actions have been filed in the past36 months, and 12 mobile app class actions have beenfiled in the past eight months.

– On June 11, 2013, the largest privacy class action wasaffirmed by the 7th Circuit – 1 billion exposure based onbehavioral tracking.

– The plaintiffs’ bar is focusing on privacy class actions.– The FTC has increased its enforcement activity.– Based upon global and U.S. trends, more focus onprivacy and tracking will occur in 2014.

Page 10: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

DO NOT TRACK CASES

Washington ‐ 3

Montana ‐ 2

California ‐ 108 Arizona ‐ 1

Colorado ‐ 1

Minnesota‐ 1

Wisconsin ‐ 1

Illinois ‐ 8

Missouri ‐ 4

Arkansas ‐ 17

Louisiana ‐ 1

Texas ‐ 6

Alabama ‐ 2

Georgia ‐ 4

Florida ‐ 4

Tennessee ‐ 1

Ohio ‐ 1

N. Carolina ‐ 1

New York ‐ 13

Massachusetts ‐ 2

Virginia ‐ 1

Maryland‐ 1

Delaware ‐ 2

Connecticut ‐ 2

Rhode Island ‐ 1Michigan‐ 1

New Jersey ‐ 2

Pennsylvania ‐ 1

Puerto Rico ‐ 1

District of Columbia ‐ 2

Page 11: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

“Do Not Track” Typical Class Action Claims

Page 12: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Harris v. comScore, Second Amended Complaint, No. 1:11‐cv‐05807 (N.D. Ill Jan. 

31, 2013) ECF: 169

• Plaintiffs alleged tracking based upon downloads of bundled software that did not disclose tracking technologies or comScore’s name.

• Plaintiffs alleged inadequate privacy disclosures• Sought to certify 10 million user class at $10,000 statutory damages under the stored communications act.

Page 13: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Harris v. comScore:  Northern District of Illinois Certifies Largest Privacy Class Action 

in history $1 billion

• Key takeaways:

– Court held common questions of fact and law predominated.– Plaintiffs could self‐identify to become members of the class – Note:  This is highly unusual and rarely permitted.

– Emails contained in comScore’s records were  considered sufficient to ascertain class members.

Harris v. comScore, Inc., 292 F.R.D. 579 (N.D. Ill. 2013).

Page 14: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Harris v. comScore:  June 11, 2013, 7th Cir. Affirms Certification of ‐1 Billion Class

Page 15: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Harris v. comScore $1 billion exposure settled May 30, 2014 for $14 million

Page 16: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

In re Zynga Privacy Litig., 2014 U.S. App. Lexis 8662 (9th Cir. May 8, 2014)

• The Ninth Circuit affirmed the Northern District of California’s dismissal of two putative class actions alleging Facebook Inc. and Zynga Game Network Inc. improperly shared consumers' personal information with advertisers, finding the social network giant and the gaming company didn’t disclose the contents of communications.

• Plaintiffs claimed that Facebook and Zynga  claims violated the Wiretap Act and  Stored Communications Act by sharing referer headings (that included user ids and the web pages viewed by the user with advertisers and other web analytic companies).

• The Stored Communications Act says that a service provider may divulge records and other information pertaining to a customer, but may not divulge the contents of communications, the opinion said. Customer record information including the customer’s name, address and subscriber number, does not qualify as contents under the federal law.

• The Ninth Circuit upheld the dismissal of the two class actions that alleged violations of the Wiretap Act and the Stored Communications Act — sections of the Electronic Communications Privacy Act — ruling that the plaintiffs failed to state a claim because they didn’t allege that either Facebook or Zynga disclosed the “contents” of a communication, a necessary element of their ECPA claims, according to the opinion.

• Takeaway:  No liability under ECPA for sharing referer headers alone with third parties.

Page 17: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Video Privacy Protection Act (“VPPA”)

Page 18: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

VPPA BACKGROUND

• The VPPA prohibits disclosure of personally identifiable information (“PII”), includinginformation identifying a person as requesting or obtaining specific videomaterial. 18 U.S.C. § 2710, et seq.

• The VPPA does not define PII directly, stating that it “includes information whichidentifies a person as having requested or obtained specific video materials orservices from a video tape service provider.” 18 U.S.C. § 2710(a)(3). This includesinformation shared with vendors, including subject matter categories. Some vendorsargue that generic categories (e.g., “likes sports”) are not PII.

Page 19: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

VPPA BACKGROUND

• VPPA defines “video tape service provider” to mean “any person, engaged inthe business, in or affecting interstate or foreign commerce, of rental, sale, ordelivery of prerecorded video cassette tapes or similar audio visualmaterials…” 18 U.S.C. § 2710(a)(4).

• VPPA defines the term “consumer” to mean “any renter, purchaser, orsubscriber of goods or services from a video tape service provider.” 18 U.S.C.§ 2710(a)(1).

Page 20: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

2012 VPPA AMENDMENT

• The VPPA was amended in December 2012 to allow video service providers toobtain consent electronically over the internet for a 2‐year advance period withcertain requirements. It requires a separate consent (outside of a Terms of Useand Privacy Policy).

• Section 2710(b)(2)(B) was amended to permit electronic consent. Video ServiceProviders can share information with the user’s informed consent as follows:– written consent that

• Is in a form distinct and separate from any form setting forth other legal orfinancial obligations of the consumer;

• At the election of the consumer;• Is given at the time the disclosure is sought; or• Is given in advance for a set period of time, not to exceed 2 years or untilconsent is withdrawn by the consumer, whichever is sooner and

– the video tape service provider has provided an opportunity, in a clear andconspicuous manner, for the consumer to withdraw on a case‐by‐case basisor to withdraw from ongoing disclosures, at the consumer's election.

Page 21: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

In re Hulu Privacy Litigation Background

• Case filed in 2011• August 2012:  Two motions to dismiss based on lack of harm and other statutory defenses failed.

• December 2013:  Hulu’s motion for summary judgment based upon lack of harm failed.

• April 28, 2014:  Hulu’s motion for summary judgment re: no disclosures of PII under the VPPA granted as to comScore claims, denied as to Facebook

Page 22: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

On April 28, 2014 Hulu Court dismisses Hulu Plaintiffs’ comScore claims but denies MSJ 

as to Facebook

• Takeaways:– Unique identifiers plus specific titles to data analytics firm –not a disclosure of PII under the VPPA

– Facebook ID + specific video titles may be PII if Hulu knew that cookies provided this data before user hit the “Like” button.

– Metrics and advertising not “incident to the ordinary course of business”

– Dicta:  Unique identifiers depending on context could be PII under VPPA – just not in this case.

Page 23: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

In re Hulu Privacy Litigation:  Motion for Class Certification Denied (June 17, 2014)

• Plaintiffs sought to certify a Facebook class:– All Hulu and Facebook users that involved disclosures ofFacebook’s c_user cookie (i.e., Facebook cookie that relaysinformation to Facebook for users that have checked the boxto always stay logged into Facebook and use the samebrowser to access Hulu).

• Court denied class, without prejudice. Class notascertainable.

Page 24: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Hulu: 2013 Ends With a Bang  

Page 25: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Hulu: April 28 2014 Hulu’s MSJ Denied as to Facebook class  

Page 26: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

In re Nickelodeon Consumer Privacy Litig., No. 12‐829, 2014 U.S. Dist. LEXIS 91286 (D.N.J. July 2, 2014) 

(granting motion to dismiss)

• The claims were against Google and Viacom for data collected through the Nickelodeon and other Viacom  Apps. Google not a VTSP – all claims dismissed.

• Viacom only disclosed “anonymous information” ( e.g., “anonymous username; IP address; browser setting; ‘unique device identifier’; operating system; screen resolution; browser version).   Not PII under the VPPA.

• Leave to amend granted for VPPA claim and intrusion upon seclusion against Viacom.  Wiretap and SCA claims dismissed with prejudice.

Page 27: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

More VPPA Cases to Come

• Five VPPA Lawsuits filed in February –June 2014– February 17, 2014:   Perry v. Cable News Network, Inc. et al., No. 1:14‐cv‐1194 (N.D. Ill.) 

– February 19, 2014:   Ellis v. The Cartoon Network Inc.,  No. 1:14‐cv‐00484,(N.D. Ga)

– March 13, 2014:  Locklear v. Dow Jones, No. Case 1:14‐mi‐99999‐UNA (N.D. Ga) 

– March 28, 2014:  Eichenberger v. ESPN, No. 2:14‐cv‐00463 (W.D. Washington) 

– June 9, 2014:  Robinson v. Disney,  No. 14‐cv‐4146 (S.D. N.Y.)

Page 28: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Takeaways 

• Plaintiffs’ bar are attracted to privacy claims that carry statutory damages.

• They have been able to overcome motions to dismiss based on lack of Article III standing by alleging statutory violations.

• More litigation is likely to follow.

Page 29: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Emerging Legal Issues Relating to Data

Text Messaging Campaigns (Telephone Consumer Protection Act Risks)

June 2014

Page 30: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

FCC New Regulations Effective October 16, 2013

• Prior express written consent is needed before commercial telemarketing texts may be sent.– User must agree to receive autodialed text messages and evidence understanding that agreement is not a condition of using the service.  47 C.F.R. 64.1200

– TCPA Class actions were up 70% last year.  According to InsideARM 785 TCPA cases filed in 2012; 1385 filed in 2013.

Page 31: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Emerging Legal Issues Relating to Data

Mobile (Privacy Disclosures and Security)

May 2014

Page 32: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Regulatory InitiativesRegarding Mobile Apps

Page 33: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Regulatory InitiativesRegarding Mobile Apps

CA AG, FTC and EU Article 29 Working Group Guidance

Page 34: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Regulatory InitiativesRegarding Mobile Apps

• CA AG Guidance – issued 1/10/2013• FTC Guidance – issued 2/1/2013• Article 29 Working Group – issued 3/2013• NTIA Guidance – issued 7/ 2013• DAA Guidance – issued 7/2013

• Just in Time/Short Form Notice: Notice for collection ofsensitive data must be “Just in Time,” in short form, aboveand beyond the privacy policy.

• PII: includes unique identifiers.

Five Mobile Guidances Were Released in 2013:All Call for Just in Time/Short Form Notice

Page 35: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Practice Pointer: Use Alston & Bird’s App Developer Check List for Just in Time Notice

Page 36: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Fandango and Credit Karma Announce FTC Settlement on March 28, 2014

Page 37: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

In re Fandango (FTC Announced Settlement March 28, 2014)

• Failure to secure mobile app credit card information.• Alleged unreasonable security for failure to

– Validate Secured Socket Layer (SSL) to prevent intervention by hackers when users used open networks.

– Provide sufficient protection for data while at rest.

Page 38: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Practice Pointer: Focus on “Readability”

• Use icons – California AG and FTC recommend it. – See e.g., CA AG Making Your Privacy 

Practices Public at p. 10– See also, 

• CA AG Privacy on the Go at p. 11  (“Graphics or icons can help users to easily recognize privacy practices and settings”); 

• FTC, Mobile Privacy Disclosures at p. 17  (“Consider developing icons to depict the transmission of user data”) ; and 

• FTC Protecting Consumer Privacy in an Era of Rapid Change at p. 62 (“… icons … show promise as tools to give consumers the ability to compare privacy practices among different companies) 

Page 39: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Alston & Bird Has Icons!

http://www.alston.com/services/intellectual‐property/technology‐transactions/

Page 40: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Data breach litigation

Page 41: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

FTC v. Wyndham Worldwide Corp., No. CV 12‐1365‐PHX‐PGR (D. Ariz.) 

• The issue:  Does the Federal Trade Commission (FTC) have jurisdiction under § 5 of the FTC Act to regulate data security?  – Wyndham’s position: “Nothing in Section 5 gives the FTC the power to set

standards for the extremely complex computer software and hardwaresystems that businesses employ to ensure data security. And no court has everheld that the ‘unfairness’ prong of Section 5 gives the Commission theauthority to regulate a private company’s data‐security practices.”

– The FTC’s position: Congress has confirmed its authority to regulate unfairand deceptive practices involving data security both implicitly and explicitly byallowing broad enforcement authority. FTC has also argued that other statutesrelevant to data security (like FCRA, GLB, and COPPA) do not limit the FTC’sjurisdiction. As to whether the FTC should address data security issuesthrough guidelines and rulemaking as opposed to litigation, the FTC’s positionis that given the ever‐evolving landscape with respect to data security andprivacy violations, litigation is an appropriate avenue of enforcement.

– Judge agrees with FTC’s position

FTC Enforcement Authority

Page 42: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

FTC v. LabMD Inc., No. 1:12‐CV‐3005 (N.D. Ga. Nov. 26, 2012)

• LabMD argues that the FTC has no authority to investigate data security issues.– “Nothing in Section 5 gives the FTC the power to set standards for businesses

to employ in the area of data security.”– There is also no legislative history, administrative law, or case law to support

the position that the FTC has the authority to regulate data security.

• Additionally, LabMD argues that the FTC has publicly acknowledged that it lacksthe authority to regulate data security. LabMD cites a 2000 FTC report in whichthe FTC advocated for legislation regarding data security and asked Congress togrant it authority to regulate data security because “the Commission lacks theauthority to require firms to adopt information practice policies.”

FTC Enforcement Authority (cont’d)

Page 43: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• The Court disagreed and found that the FTC does have authority. 

• Courts interpret Section 5 as a statute broadly conferring authority on the FTC to investigate and regulate unfair practices that are likely to cause injury to consumers that they cannot reasonably avoid, and where such practices may be outweighed by countervailing benefits.  

• The Court found that the FTC had presented sufficient information in its pleadings to support its claim that there is a significant and widespread impact and threat to consumers, including identity theft, that results from data security breaches that affect consumer privacy. – However, this was only in response to the Petition for an order to comply with 

investigative requests (CIDs)– Low threshold: FTC only needs to make “plausible argument in support of its 

assertion of jurisdiction”– Court also finds “there is significant merit to Respondents’ argument that 

Section 5 does not justify an investigation into data security practices and consumer privacy issues”

FTC Enforcement Authority (cont’d)

Page 44: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Companies need to read FTC Guidance, Complaints and Enforcement Orders to Understand expectations for Reasonable Security.

• Alston & Bird has done this – Cyber Risk Legal Pkg.

Takeaways

Page 45: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Training• Physical Security• General Network Security• Password Management• Laptop security• Privacy Audit – Part of this overall effort

– Test vulnerabilities– Identify issues– Remediate

Reasonable Security

Page 46: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Recommendations

Page 47: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Practical Guidance

• Local Terms• Global Terms• Managing Consent

AuditGovernance Security Train regarding

your policiesInvolve All Related Players

Repeat

Managing Compliance

♦ How is Big Data being used?

♦ Risk Avoidance and Mitigation ♦ Protocols♦ Policies ♦ Procedures

♦ Compliance with laws and companies best practices

♦ Technological♦ Policy

1 2 3 4 5

Page 48: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

The 3 Things You Need To Know About Defending Privacy Class Actions

Cari K. DawsonPartner

Alston & Bird LLP1201 West Peachtree Street

Atlanta, GA 30309(404) 881‐7766

[email protected]

Page 49: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

The 3 Things You Need To Know About Defending Privacy Class Actions

1

2

3

How to be proactive and avoid class action litigation

How to defeat class action litigation if you can’t avoid it

How to defend your company’s reputation and not win the battle, but lose the war

Page 50: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Prepare to Stop Privacy Class Actions Before They Start

Page 51: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

The Legal Precedent from the United States Supreme Court on Mandatory Arbitration 

with Class Action Waiver

• AT&T Mobility LLC v. Concepcion, 131 S. Ct. 1740 (2011)

• Held: State law may not invalidate an arbitration agreement solely because the agreement prohibits use of class procedures in arbitration

• American Exp. Co. v. Italian Colors Restaurant, 570 U.S. ____ (June 20, 2013)

• Held: a class waiver is enforceable even if the costs of litigating a claim individually outstrip the plaintiff’s potential recovery

Page 52: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Mandatory Arbitration With A Class Action Waiver: The Silver Bullet To Protect Assets

• Make sure that your class waiver and arbitration language is airtight

– Enforceable language will minimize class action litigation exposure

• Arguing that litigation is too expensive won’t get consumers out of a class waiver

• But, look for the regulators (the Consumer Financial Protection Bureau) to push back

Page 53: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Other Proactive Strategies to Defeat Class Action Litigation

• Mootness

• Rule 68 Offers of Judgment

• Motions to Strike Class Claims

Page 54: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Best Practices for Defending Privacy Class Actions

• Experienced class counsel are as important as subject matter experts

• Ask the number of class actions defended• Ask the number of class certification hearings argued

• Ask about MDL experience and whether counsel has been lead counsel in an MDL

• Ask if counsel has ever tried a class action case to verdict

Page 55: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Winning Class Action Strategy

• Filing strategic Rule 12 Motions• Executing a coordinated attack on the merits and class issues

• Preparing tactical case management and scheduling orders (scheduling timely technical tutorials)

• Aggressively attacking the class representatives• Developing a robust and persuasive factual record tailored to class and merits arguments

• Retaining (early) the best class and merits experts

Page 56: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Motion for Summary Judgment (Class Rep’s Claims)

Opposition to Class 

Certification

Targeted Rule 702 Motions

Winning A Class Action Strategy (continued)

Deploying a 3‐prong attack at the class certification stage

Page 57: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Recent Privacy Class Action Cases

• Harris v. ComScore– Stored Communications Act, Electronic Communications Privacy Act, 

Consumer Fraud and Abuse Act

• In re Zynga Privacy Litig.– Electronic Communications Privacy Act

• In re Hulu Privacy Litigation– Video Privacy Protection Act

• In re Target Corporation Customer Data Security Breach Litig.– Data breach litigation

Page 58: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Key Class Action Defenses

• Article III Injury‐In‐Fact– Clapper v. Amnesty International, 568 U.S. ___ (2013)

• Ascertainability– Carrera v. Bayer, 727 F.3d 300 (3rd Cir. 2013)

• Commonality and Typicality– Wal‐Mart Stores, Inc. v. Dukes, 131 S.Ct. 2541 (2011)

• Predominance of Individualized Issues– Comcast Corp. v. Behrend, 133 S.Ct. 1426 (2013)

• Due Process and Constitutional Defenses– Lindsey v. Normet, 405 U.S. 56 (1972)

Page 59: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Reputational Defense andProtecting the Brand

• Don’t win the battle, but lose the war• What is the endgame?  Are the business objectives being served by the litigation strategy?

• 4 Cs Plus 1– Communication– Coordination– Collaboration– Compromise– Be proactive, not reactive – if you don’t tell your affirmative story, your adversaries define the issues to their advantage

Page 60: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Trade Secret Protection

Ryan W. KoppelmanPartner

Alston & Bird LLP1950 University Avenue, 5th Floor

East Palo Alto, CA 94303(650) 838‐2009 

[email protected]

Page 61: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Trade Secret Protection

Overlapping Trade Secret Protection Considerations

July 2014

Page 62: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Security is important to both privacy and trade secret law

• Similar and overlapping compliance issues• Standards less defined for trade secret protection but case law suggests numerous factors

Privacy and Trade Secret Overlap

Page 63: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Trade secret rights require “reasonable steps to maintain confidentiality”

• At least one case – failed to take “reasonable steps” when higher security for personal information than for trade secrets

Privacy and Trade Secret Overlap

Page 64: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Training• Physical Security• General Network Security• Password Management• Laptop security• Privacy Audit – Part of this overall effort

– Test vulnerabilities– Identify issues– Remediate

Dominique’s Reasonable Security

Page 65: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Controlled access on actual need to know basis

• Passwords, document shredding and destruction

• Physical security, accompanying guests

• Visitor agreements, restricted and supervised tours

TS Reasonable Steps

Page 66: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Regular review and designation of potential trade secrets 

• Systematic marking of trade secrets with proprietary legends

• Regular warnings, notice and reminders to keep secret

• Exit interviews reminding of confidentiality and secrecy

TS Reasonable Steps (con’t)

Page 67: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

• Dividing a trade secret process into different parts to limit access

• NDAs with employees, vendors, customers, partners

• Policies and procedures, demonstrated enforcement

• Proprietary Information Audit

TS Reasonable Steps (con’t)

Page 68: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Alston & Bird’sCommitment to Diversity

Page 69: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Best Practices

Women’s Initiative –Steering Committee and Regional Committees

Firm‐wide diversity management education for all attorneys and staff 

(mandatory)

Practice Group Diversity Development Initiative

Domestic partner insurance

Childcare center & back up care program

Participation in diversity pipeline 

efforts and diversity job fairs

Diverse Bar Leadership Initiative

Diversity programs on generational diversity 

and other topics

Best Practices Guidelines for Maternity Leave for Practice Group Leaders 

and Attorneys

Practice Group Leader Guidelines for Commitment to 

Diversity

Full‐time Diversity Coordinator

Diversity Committee Liaison Program

Diversity Task Force Education & Awareness 

Programs

Alternative Career Path Policy (ACP)

Diverse Forums

Page 70: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Alston & Bird supports diversity outside of the firm through financial funding, participation as presenters at events focused on promoting diversity and membership in national and diverse bar associations and organizations, including: 

Sponsorships & Support

• American Bar Association Minority Counsel Program  

• California Minority Counsel Program 

• Charting Your Own Course 

• Corporate Counsel Women of Color 

• Hispanic National Bar Association 

• Human Rights Campaign 

• Lavender Law 

• Leadership Council on Legal Diversity 

• Leadership Institute for Women of Color 

• Mexican American Bar Foundation 

• Minority Corporate Counsel Association 

• National Asian Pacific American Bar Association 

• National Association of Law Students with Disabilities 

• National Bar Association 

• National Association of Women Lawyers 

• South Asian Bar Association of North America

Page 71: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Selected Recognition & Awards

2015 Guide to VAULT Top 100 Law Firms Ranking:  #9 Overall Best Law Firms for Diversity; Quality of Life Rankings: #6 Minorities Diversity; #10 Women Diversity; #11 LGBT Diversity and #7 Firm Culture 

15 Consecutive Years on Fortune® magazine’s “The 100 Best Companies to Work For”™

Scored 100% on The Human Rights Campaign Corporate Equality Index for 10 consecutive years

Ranked #32 on the 2014 A‐List by the American Lawyer (AmLaw). The A‐List formula provides a collective measurement (from four ALM surveys) on the most successful and committed firms in the United States. 

Selected among Multicultural Lawmagazine’s 2012 Top 100 Law Firms for Diversity (38th overall); Top 25 Law Firms for African‐Americans; Top 100 Law Firms for Women; Top 50 Law Firms for Associates

Winner of The Coca‐Cola Company’s 2012 Living the Values Award

DuPont “Meeting the Challenge" award in recognition of Alston & Bird’s outstanding legal work on DuPont matters and its sustained commitment to diversity in the legal profession

2011 recipient of the “Eaton Law Department Supplier Diversity Excellence Award” in recognition of Alston & Bird’s dedication to furthering diversity in the legal profession

Selected among the 2009 Top 50 Best Law Firms for Women by Working Mothermagazine and Flex‐time Lawyers

Page 72: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Thank You & Questions

Page 73: Topics Privacy, Class Actions and IP - Alston & Bird LLP · 11/06/2013  · material. 18 U.S.C.§ 2710,et seq. • The VPPA does not define PII directly, stating that it “includes

Program Speakers

Kate Hertel, PartnerAlston & Bird LLP333 S. Hope Street, 16th FloorLos AngelesCA 90071+ 1 213 576 2600 (Direct)[email protected] R. Shelton, Partner

Alston & Bird LLP333 S. Hope Street, 16th Floor

Los Angeles, CA 90071+ 1 213 576 1170 (Direct)

[email protected]

Cari K. Dawson, PartnerAlston & Bird LLP

1201 West Peachtree StreetAtlanta, GA 30309

+ 1 404 881 7766 (Direct)[email protected]

Ryan W. Koppelman, PartnerAlston & Bird LLP

1950 University Avenue, 5th FloorEast Palo Alto, CA 94303+ 1 650 838 2009 (Direct)

[email protected]