Showing posts with label European Law. Show all posts
Showing posts with label European Law. Show all posts

Saturday, 25 January 2020

Exporting personal data I: introduction (and a small Brexit niggle)


Well, I'm back.

I hope to carry on blogging about the law from the slightly different perspective that I have adopted in the past. In particular, I want to try talking about some difficult questions that I come across while working with clients and which I can't help thinking about in my spare time. Thank you for helping me scratch that itch.

This post is just an introduction. If you are familiar with how the GDPR works, then you should skip to the bit about Brexit.

The export of personal data

I want to start by talking about the General Data Protection Regulation, or GDPR as it is affectionately known, which will have been in force for two years in May. In particular, I want to talk about the regime create by the GDPR for the international transfer of data. From a technical point of view, transferring data around the world is, thanks to the Internet, not only straightforward but often invisible. However, from a legal perspective it is not so simple.

The reason why the GDPR tries to control international transfers of data is simple to see. The GDPR's aim is to create a region of really strong protection for personal data in the European Union and the European Economic Area. If someone processing personal data could simply transfer it outside that region and do whatever they liked with it, it would be really easy to get around the GDPR. The protection it gives would be much less useful.

How exports are controlled

The GDPR divides the world into two parts: a "safe" part, which at the moment contains the EU and the EEA; and a potentially wild and dangerous part consisting of what are called "third countries". By the way, there is (as far as I have been able to discover) no formal definition of "third country" as you might expect. It seems to be understood to mean anywhere that isn't a member state of the EU or the EEA, but maybe other countries (eg the UK after Brexit) could escape being "third countries" in the same way as the EEA members have done.

By default, moving data from the safe part of the world to a third country is forbidden, unless one of a (long) list of conditions is met. I plan to look through some of these conditions over this blog series, but in a moment, I will give a brief summary of two that are particularly significant.

Adequacy

The European Commission can declare that a country has "adequate" protection. Even though the country is a mere third country, it has done enough to live up to the high standards set by Europeans and data may be exported there.

This is a sort of data imperialism, perhaps with the hope that European data protection law will dominate the world. Given the steadily increasing list of countries declared "adequate", this may be working.

But, a word of caution about adequacy. Adequacy decisions can be made that are limited to certain kinds of transfer. In other words, just because a country is in the list, does not mean that you can just export data there without further thought. A few countries, for example the United States and Japan have adequacy decisions that are limited in various ways.

For example, the United States clearly does not think that it has to play along with the EU's data protection rules but has set up a system known as the "Privacy Shield" which allows companies to opt into a lightweight version of the GDPR. The USA only counts as having "adequate" protection for transfer to companies who are members of the Privacy Shield. I will have quite a bit to say about the Privacy Shield in a later blog.

Standard Contractual Clauses

A very popular option is for the export and importer to sign an agreement which contains a set of standard clauses approved by the European Commission (or in theory by another regulator). These are, in essence, a promise by the importer that they will not take advantage of the fact that the data is now outside the "safe" part of the world to do evil and/or unspeakable things to it and that they will in all ways be good. The standard clauses are meant to be enforceable by individuals whose personal data is being processed and they contain their own rules controlling further export of the data.

At first sight this system seems very flexible. Most transfer of data will either be internal to a company (in which case each part can sign the standard clauses) or be made subject to some terms or conditions, even if they are standard terms on a website. Including some standard material cut and pasted from the European Commission or elsewhere should be easy enough.

In practice there are quite a few difficulties with the standard clauses, which I intend to look at in some detail later in this series.

What about Brexit?

Unless something dramatic happens between now and then (given past history this is not entirely impossible), the effect of the EU-UK withdrawal agreement and the European Union (Withdrawal Agreement) Act 2020 is that the UK will leave the EU next week on the 31 January 2020.

Article 127 of the withdrawal agreement and section 1 of the Act keep EU law going in the UK for the time being during what is known as the "implementation period" until 31 December 2020 at 11.00pm GMT, though of course that data could end up being renegotiated. So at first sight it would appear that nothing will change for a while yet.

But I still have a concern. From the many examples I have seen, many agreements for sharing, selling or otherwise transferring personal data have provisions in them saying something like "... shall not transfer any personal data outside the European Economic Area..." or wording like that. The problem here is that, despite all the magic words about the implementation period, the UK will not as a matter of fact be in the European Economic Area and so any transfer within or to the UK may well end up being in breach of contract.

I have, since Brexit became a clear possibility, tried to press different wording on clients and their contracting partners. Typically I swap in "third country" for "outside the European Economic Area". It seems to me that the effect of the withdrawal agreement will be that the UK is not a "third country" until at least the end of the implementation period. The alternative would be to include a section attempting to explore all the possibilities along the lines of "If the UK is a member of ...." which seems complicated and fragile.

Does any of this matter? English courts are quite good at preventing over-literal readings of a contract. It's quite possible that a court would be generous and decide that the parties didn't intend that transfer to a country subject to EU law would be prohibited. But I can see the counter-argument quite easily. Not least that the UK is now not nearly as "safe" in GDPR terms as the EU was because in less than a year it could leave the whole protection framework behind. 

That is why I have called this a "niggle" and not a problem. Even so, it is much better to avoid having courts sort your contracts out for you. In my experience, ambiguities make it easier for an aggrieved party to get legal proceedings off the ground, even if they ultimately lose, or to refuse to comply with a contract without being taken to court. It is something that is worth correcting if you can.

Thursday, 20 October 2011

Can we force facebook to give us its "like" database?

Jim Killock of the Open Rights Group pointed me at an interesting response made by facebook to an Irish student named Max's subject access request under Irish data protection legislation which forms a part of the Europe versus facebook campaign.

The particular point that interests me is that, concerns facebook's tracking of all pages visited which show a "like" button - a practice that can be really intrusive. Although Max did obtain a considerable quantity of information, facebook did not release to him their list of "like" tracked data.

In their response facebook say:

Section 4(12) of the Acts carves out an exception to subject access requests where the disclosures in response would adversely affect trade secrets or intellectual property. We have not provided any information to you which is a trade secret or intellectual property of Facebook Ireland Limited or its licensors.

Unfortunately for facebook, that isn't quite what the relevant Irish legislation appears to say (health warning: I am not an Irish lawyer). What section 4(12) of the Irish Data Protection Act 1988 says, according to a consolidated version of the statute, is:

(12) Subsection (1)(a)(iv) of this section is not to be regarded as requiring the provision of information as to the logic involved in the taking of a decision if and to the extent only that  such provision would adversely affect trade secrets or intellectual property (in particular any  copyright protecting computer software).

Note the phrase "information as to the logic involved in the taking of a decision". What this is all about is that section 4 gives data subject several different rights. One right (in section 4(1)(iii)(I)) is to be supplied with a copy of "the information constituting any personal data of which that individual is the data subject" - a simple right to information. Another, and different right, can be found in section 4(1)(iv) which applies to automatic decision making by the data controller. Here the data subject has a right to be informed of the "logic involve in the processing". Obviously that's quite a different right since it is essentially a right to know about algorithms rather than data.

Quite clearly section 4(12) is a restriction on the right under 4(1)(iv) to know about the logic of automatic decision making and not a restriction on the right of information simplicter. Nice try facebook, but I can't see that working.

Our own legislation is very slightly different. We also have a right (in section 7(1)(d) of the Data Protection Act 1998 to be informed about the logic involved in automatic decision making, but the restriction on that right is limited to trade secrets. Section 8(5) says:

Section 7(1)(d) is not to be regarded as requiring the provision of information as to the logic involved in any decision-taking if, and to the extent that, the information constitutes a trade secret.
So that any UK national involved in the Europe v facebook campaign has a much stronger argument.

In any case, at best facebook can claim a database right over the contents of the list of pages visited by Max that they have collected using the "like" button. The database right is a creature of European law (directive 96/9/EC). Recital 48 of the directive states that "the provisions of this Directive are without prejudice to data protection legislation", which seems to me to argue that data protection law ought to trump database right. If you think about it, the contrary would be an impossible situation. Personal data will often be protected by database rights. If you could use database rights to avoid subject access requests they would be of far less use.

Tuesday, 15 March 2011

Colonel Mustard is not in the Library with a copyright claim form

My friend Sym came up with a neat joke:

Playing Big Society Cluedo. It's easier than normal Cluedo because there isn't a library.

and promptly tweeted it. Much retweeted it ended up being used by the BBC's Now Show, without attribution of any kind. Sym is a generous soul and I doubt that worried him too much but he mentioned it on his (private) facebook wall.

As regular readers will know I'm not exactly a copyright maximalist, but I do find it unattractive that large and powerful organisations that would certainly pursue you if you used their intellectual property appear to be quite happy to use other people's so long as those other people are too small to matter very much. I jokingly suggested I'd help draft his claim form and that lead him to wondering whether there could be any copyright in so slight a thing as a tweeted joke.

Unsurprisingly there are lots of answers on the internet, as a cursory google search will show. One site says categorically "no"; an article in the WIPO magazine thinks "it depends" and there's even a site called canyoucopyrightatweet.com written by a US attorney which again comes down on the side of "it depends". Unfortunately all the really detailed discussion relates to US law, not European or English law. While there's some internationally harmonisation of copyright, there are still significant differences.

So, what of English law. Well, English copyright protects, amongst other things any "original literary work". Most tweets are not going to be original - in fact in many cases that is the whole point - but some, like Sym's joke, seem quite capable of being so. Certainly, I am quite sure that he came up with the joke first.

A "literary work" does not have to be high art. Indeed section 3 of the Copyright, Designs and Patents Act 1988 says that a

“literary work” means any work, other than a dramatic or musical work, which is written, spoken or sung

so its really quite a broad term. In a relatively recent case which rejected a claim for copyright in the names of commands for an airline booking system, Mr Justice Pumfrey was quite clear that single words, at least on their own, could not be copyrighted. In the 2009 Infopaq case, the European Court of Justice were prepared to accept that an 11 word textual extract could be the subject of copyright and last year in the case of Meltwater Mrs Justice Proudman agreed that, whatever might have been the position under English law, the decision in Infopaq made it plain that as a matter of European law copyright could exist in newspaper headlines provided they were original enough.

So it seems to me that a tweet, provided it is sufficiently original, can be the subject of copyright.

But as I said in an earlier post the existence of copyright is only half the question. What would or would not infringe a short humorous tweet? I haven't heard the particular episode of the Now Show in question but if they read it out they have certainly infringed (and twitter's terms of service don't appear to let them off the hook). If, on the other hand, they only paraphrased the joke, the question is more difficult. Sym might be able to claim ownership of the particular expression of his joke, but he cannot copyright the idea that lies behind it. That idea is free and open to all.

The difficulty with this neat distinction (called the "idea/expression dichotomy") is that courts recognise that you can infringe by copying something more abstract than the exact words used. This should be obvious when you consider that a translation of a work (which will usually use quite different words, unless its into "pirate") is a potential infringement of the original work. Too close a copy of the plot or characterisation in a play (say) would be an infringement even if there had been a good deal of rewriting and reworking.

How on earth this would apply to something as small and neat as a tweet is anybody's guess. I suspect that it is only a matter of time before someone tries to test the question.

UPDATE

In the comments, Sym has helpfully provided the quote from the Now Show:

Someone amused me no end on twitter the other day, ok, when they answered twitter's question 'what are you doing?' by writing: "I'm playing big society cluedo, it's easier than normal cluedo because there isn't a library"

Clearly, if there is copyright in the tweet, this looks like a potential infringement because the whole tweet has been copied pretty much verbatim. But, could there be a defence. There is, of course, no such thing as "fair use" in English law. But quoting a tweet could be "fair dealing for purposes of criticism or review" which is a defence under section 30 of the Copyright, Designs and Patents Act 1988. This requires that:

  • the use is fair dealing
  • the purpose of the use is criticism or review of a work (not necessarily the work quoted) or works
  • the use is accompanied by sufficient acknowledgement

Normally it would not be "fair dealing" to use the whole of a work, but where the work is as short as a tweet it is likely to be impossible to use it critically in any meaningful way without quoting the whole of it. "Someone amused me" probably counts as "criticism".

What about attribution? Section 178 of the act defines "sufficient acknowledgement" as "an acknowledgement identifying the work in question by its title or other description, and identifying the author". "Someone" doesn't seem like enough to me. Although its just possible to argue that "Someone" means "Someone on twitter" and that it is thereby possible identify the author by searching on twitter for the origin of the tweet. Seems like a long shot to me.

Update: I realise with some embarrassment that I didn't link to Lillian Edward's blogpost on this very question.

Monday, 3 January 2011

A new kind of copyright? Graphical user interfaces in the ECJ.

A decision of the European Court of Justice published before Christmas concerning whether a graphical user interface is protected by copyright causes me concern. I have not seen any detailed analysis of the decision which may be due to Christmas and New Year stupor. I plead the same excuse for what follows.

The case Bezpečnostní‌ softwarová‌ asociace‌ –‌ Svaz‌·softwarové‌ ochrany v Ministerstvo kultury C-393/09 has a rather involved background an excellent account of which is provided by Martin Husovec on his blog. Very roughly speaking, a Czech organisation called the Security Software Association (BSA) wished to set up a collective licensing scheme for computer software which included the right to transmit works by cable television. The point in issue was whether the broadcast of the graphical user interface of a computer program could infringe copyright (and would therefore require licensing).

Copyright in computer programs was harmonised across the EU under the Software Directive (91/250/EEC). Article 1(2) applies the directive to "the expression in any form of a computer program". The first question referred to the ECJ was whether a graphical user interface could be described as a computer program "in any form". The ECJ said "no". One fact influencing the court was that Article 10(1) of the TRIPS Agreement requires the protection of computer programs "whether in source or object code". Clearly source and object code are examples of forms of expression of a computer program.

Similarly the 7th recital to the directive states that the term "computer program" also includes "preparatory design work leading to the development of a computer program provided that the nature of the preparatory work is such that a computer program can result from it at a later stage". The common element of these examples, thought the court, was that they lead to the reproduction or creation of a computer program. A graphical user interface does not enable the reproduction or recreation of a compute program, therefore it is not the expression of a computer program "in any form".

This all seems reasonable so far. Although a graphical user interface might contain one or more images or graphical works that would attract copyright as an "artistic work" in the normal way; attempts to claim copyright in an abstraction of the user interface — such as its mode of operation — have tended to founder in the English Courts in cases such as Nova Productions v Mazooma Games [2007] EWCA Civ 219 (concerning features of the play of two computer Pool games) and in Navitaire v Easyjet (concerning a clone of a air travel booking system).

However, the court went on to consider — although it had not been asked to do so — whether the graphical user interface of a computer program might be protected by the "ordinary" law of copyright. Here the court appears to have committed the logical fallacy of affirming the consequent. To explain why I need to say a something about earlier developments in European Copyright Law.

The Information Society Directive (Directive 2001/29/EC) ("INFOSOC") has partially harmonised other forms of copyright in the European Union. Article 2 INFOSOC requires that Member States create in their domestic law a "reproduction right" for "authors, of their works". Although described as a "right" it amounts to a prohibition on anyone else reproducing (in whole or part) a work without the author's permission. In other words it is a copyright. Although INFOSOC does not define "works" (or indeed "reproduction" or "reproduction in part"), the European Court of Justice in the earlier case of Infopag v Danske Dagblades Forening C-5/08 held that the directive only applies to a work that is "original in the sense that it is the author's own intellectual creation".

So to the apparent fallacy: in Bezpečnostní‌, the ECJ reasons thus:

The Court has held that copyright within the meaning of Directive 2001/29 is liable to apply only in relation to a subject-matter which is original in the sense that it is its author’s own intellectual creation (see, to that effect, with regard to Article 2(a) of Directive 2001/29, Infopaq International, paragraphs 33 to 37).
Consequently, the graphic user interface can, as a work, be protected by copyright if it is its author’s own intellectual creation.
In other words the court deduces from a statement of the form "P implies Q" a conclusion that "Q implies P". Infopaq establishes that being the author's "own intellectual creation" is a necessary condition. That does not mean it is a sufficient one.

Now the judges of the ECJ are, for the most part, bright and well educated. They will be well aware of the dangers of affirming the consequent. I think it is safe to assume they don't mean quite what they appear to be saying. In particular, the idea that any form of intellectual creation is protected by the general law of copyright would be quite revolutionary.

For example, INFOSOC does not exclude from copyright protection inventions that could form the subject of a patent, or designs that might be protectable under one of the European design rights. Although both might well be some author's "own intellectual creation", I doubt very much that copyright is intended by anyone to extend so far.

In English law merely being creatively original is not enough for a work to obtain copyright protection. For example in Creation Records v News Group Newspapers [1997] EMLR 444, the judge held that it was not even arguable that the scene for the Oasis album cover of Be Here Now could be protected by copyright. It simply did not fit into any existing protected category — and the record company attempted to argue that it was a dramatic work, a work of artistic craftsmanship or even a collage.

So I assume (in hope) that all the ECJ are guilty of is a failure to show working and that they have in mind some other criteria that must be satisfied before a work is protected by copyright. What those criteria might be the ECJ do not say which leaves me with the following questions: if a graphical user interface is protected by copyright, what kind of a work is it and what about it is protected?

It may be possible to gain some inkling as to what is in the ECJ's mind from their answer to the second question posed to them. They were asked if graphical user interfaces were protected by copyright in computer programs (the first question), would television broadcasting of the graphical user interface be an infringement of that copyright (by communication of that work to the public)? Although the ECJ had answered "no" to the first question, ever helpful they considered whether, on the assumption that graphical user interfaces were protected by "ordinary" copyright, TV broadcasting of them could constitute infringement. Again the ECJ thought "no" because the viewers "cannot use the feature of that interface which consists in enabling interaction between the computer program and the user".

It seems from this that the ECJ have in mind not the graphical elements of the user interface, but something about its operational behaviour. A sort of copyright in interactivity, which cannot of course be infringed by TV broadcasting because you cannot interact with the subject of the broadcast. If that is what the ECJ have in mind, then I am troubled.

First, what kind of a copyright is this? Is it an artistic work, a literary work or something else (a work of artistic craftsmanship perhaps)? For the purposes of English law this matters. Different species of work are protected in different ways, even if the differences are sometimes rather subtle. The ECJ do not tell us the answer to this question.

Second, where is the graphical user interface "fixed". In English law a work is only protected if and when it is fixed in some permanent form. If I make a really excellent speech, I will have copyright in the speech when, but only when, it is recorded. Similarly if a group of musicians create an exciting musical work while jamming together in the studio, the work will not be protected until fixed in some form. Is the graphical user interface fixed in the computer program's source code? If so, copying the code may be an infringement of the copyright in the graphical user interface. If it is not fixed in the code, where is it?

Lastly, there are numerous special rules that apply to copyright in computer programs. For example there are rights to make back-up copies, to test and to decompile for certain purposes. If the ECJ is right, these would not apply to a user interface which represented an author's own intellectual creation. In English law, moral rights do not apply to computer programs, but would (presumably) apply to a suitable user interface. Both of these conclusions could be awkward.

Not all is bleak. The ECJ emphasize that when assessing whether a graphical user interface is protected by copyright as its author's "own intellectual creation", a national court should ignore components of an interface that are "differentiated only by their technical character". It will not be every, or every aspect, of a user interface that will be protected. Despite this limitation I suspect that this decision, if taken to its logical conclusion and followed by later cases, will require some careful rethinking about copyright in the computer industry. Just what we need.