Showing posts with label Social Media Case Law. Show all posts
Showing posts with label Social Media Case Law. Show all posts

Sunday, August 14, 2011

Social Media Law: Who should be drafting your State's laws, (or your Company's policy)?

As social media begins to enter its adolescence it is not surprising that we are beginning to see legislation specifically directed at interaction on social media, the platforms themselves, and their rapidly expanding use in many varying areas of our life. One of those laws which has engendered a wide range of debate is Missouri Senate Bill No. 54 which was unanimously approved by the Senate on April 7, and recently signed into law by Governor Nixon. The legislation will go into effect August 28.  

I've deliberately held off writing about Missouri's new law until now because I was curious to see what the initial reaction would be. Not unexpectedly (although I expect some in the Missouri legislature did not foresee this amount of uproar over what they thought was a child protection bill) this law has proven to be controversial. While I have not spoken to the bill's author, Sen. Jane Cunningham, I have little doubt that her efforts in passing the "Amy Hestir Studen Protection Act" were well meaning. Sen. Cunningham's website touts that she has "fought for this legislation for our children for five years" and that "this legislation is vital to protect our children from sexual predators in our schools" While one could debate whether the law actually serves to accomplish its stated goal(over 75% of child abuse actually occurs at home, not by educators)(2009 Childwelfare Public Fact Sheet ), or whether it potentially stifles the learning environment, I believe Sen. Cunningham's well meaning attempt to protect children may provide a glimpse of the challenges that the future regulation of social media will face.

Initially, it should be stated that the legislative process (and the court system for that matter) is somewhat ill-equipped to handle the rapidly changing world of social media. As Sen. Cunningham's statement indicates, she had been working on this legislation for over five years. At that time, Facebook had been open to the general public for less than a year and Twitter had only recently launched. When she initially envisioned the legislation, Sen. Cunningham could not have hoped to foresee the cultural impact that these services would have.  Laws that attempt to address social media should keep this reality in mind.
In considering the ramifications of Missouri's law, it is helpful to consider the bill itself.  The applicable text of Senate Bill 54 is relatively short and reads as follows:

1. Every school district shall, by January 1, 2012, promulgate a written policy concerning teacher-student communication and employee-student communication.  Such policy shall contain at least the following elements:

(1) Appropriate oral and nonverbal personal communication, which may be combined with or included in any policy on sexual harassment; and 
(2) Appropriate use of electronic media such as text messaging and internet sites for both instructional and personal purposes, with an element concerning use of social networking sites no less stringent than the provisions of subsections 2, 3, and 4 of this section.
 
2. As used in this section, the following terms shall mean:
(1) "Exclusive access", the information on the website is available only to the owner (teacher) and user (student) by mutual explicit consent and where third parties have no access to the information on the website absent an explicit consent agreement with the owner (teacher);
(2) "Former student", any person who was at one time a student at the school at which the teacher is employed and who is eighteen years of age or less and who has not graduated;
(3) "Nonwork-related internet site", any internet website or web page used by a teacher primarily for personal purposes and not for educational purposes;
(4) "Work-related internet site", any internet website or web pages used by a teacher for educational purposes.

 3. No teacher shall establish, maintain, or use a work-related internet site unless such site is available to school administrators and the child's legal custodian, physical custodian, or legal guardian.
4. No teacher shall establish, maintain, or use a nonwork-related internet site which allows exclusive access with a current or former student. Nothing in this subsection shall be construed as prohibiting a teacher from establishing a nonwork related internet site, provided the site is used in accordance with this section.
5. Every school district shall, by July 1, 2012, include in its teacher and employee training, a component that provides up-to-date and reliable information on identifying signs of sexual abuse in children and danger signals of potentially abusive relationships between children and adults. The training shall emphasize the importance of mandatory reporting of abuse under section 210.115 including the obligation of mandated reporters to report suspected abuse by other mandated reporters, and how to establish an atmosphere of trust so that students feel their school has concerned adults with whom they feel comfortable discussing matters related to abuse.

RSMo 162.069

While I commend Sen. Cunningham for the bill's recognition that social media policies are an integral part of any organization's social media efforts, I believe that the law should serve as a warning to those of us who practice in the social medial sphere (and also to those who seek to write laws related to social media in the future) that many of our current legislators are not be experienced in social media and may not realize the ultimate ramifications of the laws they propose. 

Social media, chat rooms, blogs, and instant messaging are no longer the realm of tech aficionados and teenagers. These channels now provide a means for efficient, and often enhanced, communication to a broad array of individuals and industries.  From the mass communicative capabilities of Twitter to the relatively focused "circles" available at Google+, social media has the potential to provide heretofore unknown educational and commercial opportunities.  Laws that ban and/or strictly limit the use of social media serve to stifle those opportunities. 

While defenders of this law have stated that its intent is not to prohibit the use of Facebook by educators, its seemingly broad, and under defined terms will likely serve to have that effect.  By proclaiming that no teacher shall use an internet site unless such sight is available to school administrators and legal guardians, and that no teacher shall use a nonwork related site which allows exclusive access with a student, by its express terms, the law appears to foreclose many social media applications.  Almost all sites "allow" exclusive communications, whether by direct message, chat, or other means.  Without further clarification, the law as currently written, will likely deter many educators from taking advantage of social media's potentially enormous educational value.

Those who regularly participate in social media understand the benefits that it can provide, some of which we are only now beginning to appreciate. Companies are using social media to interact with their customers through forms of direct marketing and advertising which was previously impossible.  Educators (when not stifled by overly restrictive laws) are forming collaborative groups both with other teachers and also with students which allow all to interact in real time in on-line after-class discussions.  Customers are able to provide direct feedback, and receive personalized responses.  Students have (or had) the opportunity to ask that question (that they were afraid to ask in class) through a medium in which they were more comfortable.  When drafting laws, or social media policies, the vast potential of social media should be considered just as thoroughly as any potential pitfalls.  

Because these areas are rapidly changing, and because legislators, or those drafting policies for your organization, may not be as familiar with social media, it is vitally important to engage those fluent in the medium when drafting rules that will effect social media.  Include members of your marketing, advertising, and public relations staff in your discussions, and be sure to seek out members of your organization that are active, both personally and professionally, on social media.  These are the people who will understand the actual ramifications of the policies that your are proposing and may also be able to provide you with more efficient and effective means to accomplish your goals without stifling social media's benefits.  If the people who are writing your policies, (or your State's legislation) aren't actively engaged in social media, they may not see the potential benefits that overly restrictive policies can preclude.

Let me know what you think.
Craig Moore

Monday, April 18, 2011

Is Social Media information "valuable property"?

An interesting question was raised last week Claridge v. Rockyou, Inc. ((2011 WL 1361588 (N.D.Cal.)):  Is the personally identifiable information ("PII") submitted to social media sights "valuable property"?  Assuming the answer to this question is yes, an interesting corollary to the question, from a privacy perspective is: What are you doing to protect this valuable property?  How your company answers both of these questions could have serious consequences.

THE CASE:
Here's what happened:  RockYou develops and distributes applications and services for use on social media sites.  Among the applications developed by RockYou are Gourmet Ranch and Zoo World. When customers sign up to use RockYou's applications, they are asked to provide an e-mail address, and registration password which RockYou stores.  In certain instances, RockYou also requires customers to provide user names and password information necessary for accessing social media sites. 

The Plaintiff, a registered account holder with RockYou, brought suit alleging that RockYou failed to secure and safeguard Plaintiffs PII, including email, passwords, and social media login credentials.  Plaintiff alleged that while RockYou promised to safeguard user sensitive PII through a policy which stated that "RockYou! uses commercially reasonable physical, managerial, and technical safeguards to preserve the integrity and security of your information..." RockYou instead stored PII in clear or plain text which provided no encryption and easily allowed intruders to read and remove the information.  Plaintiffs PII was therefore easily accessible to anyone with a minimal amount of hacking ability (of  which this author has none).
Plaintiff alleged that instead of leaving the barn door open (to steal a phrase from Gourmet Ranch) RockYou could have followed any one of a number of commonly used methods of protecting PII.  

While after reading the opinion, one wonders whether this initial security failure would have been enough to let the matter move forward, if Plaintiff's allegations are true, RockYou likely did not help itself when it delayed in responding to the warnings of a noted online security firm that there was a problem with its database.  Specifically, the firm informed RockYou of a SQL injeciton flaw which would allow a hacker to introduce malicious code into a company's network.  At some point it was alleged that at least one known hacker accessed the database and copied the email and social networking login credentials of approximately 32 million users. 

Plaintiff alleged nine separate causes of action: 1) Violation of the Stored Communications Act 18 U.S.C. Section 2702; 2) Violation of California's Unfair Competition Law, Cal. Bus. & Prof. Code Section 17200; 3) Violation of California's computer Crime Law, Cal. Penal Code Section 502; 4) Violation of the California Consumer Legal Remedies Act, Cal. Civ. code Section 1750; 5) Breach of Contract; 6) Breach of implied covenant of good faith and fair dealing; 7) Breach of implied contracts; 8) negligence; and 9) negligence per se.  The Court dismissed the majority of these claims, but allowed Plaintiff's breach of contract, implied contract, and negligence based counts to survive.

In allowing these counts to survive, the Court recognized the issue as whether the plaintiff had sufficiently alleged any actionable harm or concrete loss. Plaintiff's general allegations were that defendant's customers paid for its products and services by providing their PII, and that the PII constitutes valuable property that is exchanged not only for defendant's products and services, but also in exchange for defendant's promise to employ commercially reasonable methods to safeguard the PII that is exchanged. As a result, defendant's role in allegedly contributing to the breach of plaintiff's PII caused plaintiff to lose the ‘value’ of their PII, in the form of their breached personal data. See Claridge *4-5.

While the Court recognized that this theory was novel, it declined to hold as a matter of law that Plaintiff failed to allege an injury. Moreover, the Court specifically noted that the unauthorized disclosure of personal information via the Internet is itself relatively new, and likely to raise issues of law not yet settled by the courts. Finding that the Plaintiff's allegations of harm were sufficient to allege a generalized injury in fact, the case was allowed to move forward. 

WHY IS THIS IMPORTANT?:The reason that I find this case particularly interesting is the potential messages that it sends to those companies who possess customer PII.  While it is unquestionable that it is a good business practice to protect all client data, did RockYou open itself up to additional exposure by expressly promising to do so? Would the Court have found the same potential liability without the express provisions cited by the Plaintiff?(The breach of contract claim surely would have been more difficult to prove.) Would the claim have been different if RockYou had heeded the warnings of the security firm? What if it had basic protections that were nonetheless breached? An even more interesting question is whether the negligence claims would have been allowed to move forward even without the express promises of safety. 

Another emerging issue which this case, and those that will surely follow behind it, could have an impact on is how the log on and user information for social media accounts is considered in the employee/employer environment.  If this sort of PII is found to be valuable property does that have an effect upon who retains it when an employer/employee relationship ends? What about "personal" blogs which are directly business focused? Is the lined blurred?

Once again, its important to note that as this is still a rapidly developing area, many of these questions have not been definitively answered by the Courts.  While they may not solve every problem, having policies and procedures can provide you with a leg up if and when the issue heads before a Court. (Imagine if RockYou had also had a line in their disclosures which said something along the lines of "PII Submitted to this site is NOT valuable property for the purposes of calculating legal damages...would that have helped?)  The intersection of Privacy law and Social Media is sure to be a hot area for litigation for years to come.

Let me know what you think.
 



Monday, April 11, 2011

Be careful what you ask for...you just might get it.

It continues to be readily apparent that companies are struggling to find exactly where the line should be drawn between appropriate social media policy enforcement and the rights of workers under the NLRA.

On April 6, social media legal circles were all a 'twitter' upon the announcement that the NLRB will issue a complaint against Thompson Reuters due to its "discussion" with an employee after what Reuters believed was a questionable Twitter post. While it is believed that this is the first NLRB action related to Twitter, it comes right on the heals of the settlement of the claim related to the firing of Dawnmarie Souza by American Medial Response of Connecticut, for statements made about her supervisor on Facebook. As the Souza case was settled prior to the entry of a formal decision, this case presents one of the first opportunities for a formal line in the sand to be drawn with respect to the proper enforcement of Social Media policies and an employee's rights to criticize an employer through social media.  

Here, Reuters, in what appears to have been an attempt to start a positive conversation on how Reuters could make itself "the best place to work," asked employees for comments via Twitter on what it could do to improve.  Taking the opportunity presented, Reuters environmental reporter Deborah Zabrenko (@dzabarenko) tweeted that "One way to make this the best place to work is to deal honestly with Guild members."

Soon after posting the tweet, Ms. Zabarenko received a call, at home, informing her that her post had violated a Reuters policy that employees were not to say anything publicly that could damage the reputation of Reuters.  Ms. Zabarenko raised the issue of intimidation and the NLRB is now suing Reuters for violation of a workers right to discuss working conditions (which, ironically is exactly what Reuters asked its workers to do when it asked for suggestions on how to make Reuters the best place to work). 

While I'm not an NLRA, or employment law expert, this does strike me as an interesting case.  The issues presented in the Facebook/Souza claim (calling supervisor the equivalent of a mental patient) seemed much farther removed from legitimate criticism of the working environment than those present here.  Although I won't pretend to predict the ultimate outcome of the claim, it provides another example of how social media continues to vex even those companies that are trying to take advantage of the medium. 

In some respects, I have to commend Reuters for using social media to ask the question: "How can we make this the best place to work," as that is exactly the kind of conversation that can be constructive via social media, but in using social media, you have to be prepared for answers that you sometimes don't like.  This is not to say that employees have a free reign with their social media comments, they don't, and sometimes what you say can and should have repercussions, but knowing what sort of statements are actionable is essential.  What is important is that your company have a well thought out social media policy which considers these issues before they become legal problems, and that those enforcing your social media policy know and understand the ramifications of their actions in enforcing the policy.

Monday, April 4, 2011

Impersonating an employee: New and exciting ways businesses are getting into trouble via social media

A recent case out of Chicago, Illinois (Maremont v. Susan Fredman Design Group, 2011 WL 902444, 3-15-2011) exemplifies how businesses are struggling to adapt to the legal issues presented through their use of social media.  While on its face, the issue at the heart of this case may seem obvious, in practice there can be many very difficult issues...is your company ready?

In Maremont, Jill Maremont, an employee of SFDG was an active participant in social media, blogging and posting in her own name, on topics directly related to her employment at SFDG.  Through her efforts, Maremont developed a sizable following and those posts inured to the benefit of SFDG.  She accessed social media sites through SFDG computers, which stored her passwords.

In September of 2009, Maremont was in an accident which left her incapacitated for an extended period of time, in her absence, employees of SFDG made numerous social media postings promoting SFDG on her behalf, without her permission.  Upon discovering this activity, Maremont requested that SFDG refrain from using her accounts.  SFDG continued these posts despite Maremont's requests.   Maremont brought claims alleging violation of the Lanham Act (false endoresment); Illinois' Right to Publicity Act, and Common Law Right to Privacy claims. Her claims under the Lanham Act and Illinois' Right to Privacy Act, have survived Summary Judgment, and the opinion gives at least some indication that a more specifically pled privacy claim may also have had some traction.

The ultimate resolution of these claims is still to be determined, however, their advancement should give pause to companies whose employees use their own followings on social media to promote company business activities.  Could you be exposed to similar claims? Would you loose important aspects of your businesses' promotional strategy if certain employees left? How do you protect your company?

While each situation is different, a strong, and business specific, social media policy can help provide you protection.  In those instances where substantial company followings and promotion are developed through social media, it is especially important that your policy make clear who owns the accounts being used, who has a right to post on the accounts, and that your company has the right control the accounts, regardless of the content input of employees.  These protections can help avoid expensive legal battles if a dispute arises.  There are also ways in which policies can make explicitly clear that intellectual property created related to the business of your company during the course of employment is owned by the company.  Again, avoiding problems, before they arise, is one of the most important functions of a properly drafted social media policy. 

Up next: consideration of the CAN-SPAM Act's application to social media. Can Facebook, Twitter, and Linked-In postings be "spam" under the definition of the Act?