Showing posts with label Technology/internet. Show all posts
Showing posts with label Technology/internet. Show all posts

09 July 2015

New Companies House search facility


First impression of the new free access to UK company data


The new Companies House search facility, giving free access to information on UK companies and copies of filed documents, has been launched in beta here.

My first impression is that it's excellent - immediate one-click access to documents, a huge improvement on the previous elaborate process of selecting, paying for and downloading documents through the public Webcheck facility and the subscription services used by business customers.

The only downside I can see is that information is now so easily accessible that I'm sure there will be an increase in abuse. There appears to be no attempt to prevent automated services harvesting information, which is now all free of charge, which could be used to assist in identity fraud, to identify targets for spam, or to put together more sophisticated abuses. the information was all there before, but was only available if you knew you wanted it and  were prepared to pay your quid per document.


15 June 2012

Click to accept


Are website conditions of use binding?




Many websites have conditions of use, supposedly binding the visitor to various conditions. Usually they are of minor importance, but if they are contractually binding, there is no theoretical limit on the obligations that could be imposed. But is there a contract with the visitor?

Probably not, and a recent case[1] strengthens that view, holding there was no consideration even for an online acceptance click. To form a contract there would have to be offer and acceptance, consideration and contractual intention. None of these is likely to be present just in visiting a website.

The case went further. It held that there was no contract even when the consumer set up an account, registered user details and clicked to accept the terms and conditions. The court said there was still no consideration for the obligations of the consumer: the website owner was not obliged to provide him with any service, and could take down the website at any time. A contract only came into being when an actual order was placed.

That is a surprising conclusion, given the minimal requirements to give adequate consideration, so the case may not be reliable as a precedent in other cases. Including some trivial obligation on the part of the website operator could get round the point.

Less surprisingly, the case also says that attempting to make a consumer responsible for all unauthorised use of his account is unfair and unenforceable under the Unfair Terms in Consumer Contracts Regulations 1999 – see my previous post on that subject, On Level Terms.

07 March 2012

Putting the Djinn back in the bottle


Is an NDA worthwhile?


Non-disclosure agreements (NDAs, also confidentiality agreements or secrecy agreements) are used in a number of commercial contexts, from deal negotiations to technology sharing. But are they worth the paper they are written on? It is sometimes said that the cost of enforcement makes them useless, at least to small businesses.

There are benefits in having an NDA even if you are not likely to sue on it. Foremost is deterrence, and making the other party more aware of the need to respect confidentiality. The biggest downside, in my view, is not cost but evidence, as it's very difficult to prove a breach and even harder to show loss justifying substantial damages. Injunctions aren't much good if the information has already been disclosed (though they can restrain other abuses). I often advise clients not to disclose their "crown jewels" information even if they have an NDA in place.
I drafted one for a client only yesterday, though.

 

17 February 2012

Say Cheese©!


Reproducing the composition of a photograph


I’m an amateur photographer, so I found a recent copyright case interesting: Temple Island Collections v New English Teas – about images of London on tasteful souvenirs in tourist shops. A photograph taken of the same general (but not exact) location and subjected to similar digital manipulation as the original was held to infringe copyright, even though no part of the original was physically copied. The two pictures are reproduced in the judgment or here.

The case stretches copyright towards protecting the creative thought rather than the result. Traditionally it is said that copyright protects the expression of the idea rather than the idea. The problem with protecting the idea, as the judge himself recognised, is where the principle stops. It doesn't stop someone taking a picture from the same vantage point, or converting an image to black and white, or using spot colour on a black and white (which the claimant admitted he has copied from Spielberg’s Schindler's List), or blanking the sky; but at some point doing all these things together, inspired by an earlier work, became copyright infringement.

Would any two, or any three of those factors have been sufficient? If I photograph
four of my mates crossing Abbey Road, is that copyright infringement? What if I have one of them take off his shoes? The case contrasts with Creation Records and Noel Gallagher v News Group Newspapers in which The Sun’s photographer did not infringe copyright by snapping an elaborate photo-shoot set from the same position as the official photographer.

I think the new decision is right - after all the reproduction of other forms of work, such as a musical score, does not require mechanical copying, and copying in a different medium can be an infringement. If I made a painting from the photograph (which would be a very poor reproduction!) I would be infringing, so why not if I deliberately re-create a photograph? But it does make it hard to draw the boundary.

26 May 2011

Tea and cookies

Should the law demand the impossible?  

Today the law on cookies changes [1].
Cookies are small files downloaded to a user’s computer or phone when they visit a website or use an online service. Most are completely harmless, and many are essential to the operation of the site, or improve the user experience by, for example, recognising you when you return.
The new law, based on a change to the underlying European directive, requires the user’s explicit consent before a cookie can be transferred to his or her computer. But how is that to work? Government advice confirms that relying on the site terms and conditions is not enough; nor can you rely on the user having set the browser to accept cookies, as that is not specific enough. You must actually ask and get informed, explicit consent.
Easy enough, perhaps, if you have a site that requires people to register or log in; you can get their consent as part of that process. But what about a straightforward information website? The ICO guidance offers a few possibilities, but none of them is satisfactory. Use of pop-ups, for instance, is defeated by users with pop-up blockers. Banners are technically difficult to implement and take up precious space on the site. Demanding consents will put people off using your site, and may drive them to competitors who do not comply. A small business with a website hosted on its ISP’s servers often does not have any facility for the necessary technical measures, or for storing users’ consents. It will simply have to stop using cookies (including inspecting cookies provided by other sites). Many small businesses use ready-made website packages or authoring software and will have no idea whether their sites use cookies; they may have to spend money finding out.
Technically, the exchange of cookie information happens as soon as a website has been accessed – before any information has been displayed. How do you get consent without displaying any text? How do you check if a user has consented to inspection of the cookie on his computer without inspecting the cookie?
The ICO has said that it will not rigorously enforce the new law in the first year, allowing businesses time to comply. That in itself is unsatisfactory – either the law is in force or it isn’t. The regulations were only published three weeks ago.
But the main concern is that it is impossible to comply fully with the regulations. It is this sort of legislative mess that brings business regulation into disrepute, and encourages the impression of thoughtless legislation from Brussels.
The other change made by the regulations is to introduce a new power for the ICO to fine businesses up to £500,000 for breach of the rules. No surprise there.

22 March 2011

Serving documents via Facebook and email

A County Court has given permission for one of its orders to be served through Facebook [1]. Even the law is trying to keep up with the social media revolution! The courts have a wide discretion to allow service by alternative means likely to come the attention of a defendant. There has been a previous instance of service of a High Court injunction on an anonymous defendant via Twitter.
Many contracts specifically exclude the use of email for service of notices, and I am not convinced it is the right approach. Everyone in business uses email, including for important communications, and the risk of someone being caught out by failing to serve a notice by post exceeds the risk of an email notice not being received.

12 February 2011

A decent website?

Advertising code extended to all websites

The Code of Advertising Practice is being applied to all websites from 1 March. I blogged this week about the legal requirements for your website, but now it also has to follow the Code if it directly promotes products or services to consumers (including businesses) in the UK. That includes a Facebook page or LinkedIn company page.
You may think that all your promotional material is already legal, decent, honest and truthful, but do you hold documentary evidence to prove all claims that are likely to be regarded as objective? Is it clear that opinions are not intended to be objective claims?
For a start, very few law firm websites don’t claim to be a “leading” practice!
Some parts of the Code go beyond the content of advertisements: for instance products ordered must generally be delivered in 30 days, and the CAP duplicates and extends some parts of the Distance Selling Regulations, and brings in general obligations to treat customers fairly – and appears to apply them to business-to-business sales. Of course it does not have the force of law – its terms are enforced by the Committee of Advertising Practice through advertising industry sanctions, so it does not give customers direct contractual rights. But an adverse finding could be highly embarrassing. Remember, many complaints come from competitors!

07 February 2011

Name, rank and number

Company details you need on your stationery, websites and emails

Routine stuff, but I see many companies are still getting these wrong. Letterheads and invoices are usually right, but people fall down when it comes to email footers, websites and minor stationery items. Have you got them all right? As a reminder, download my easy guide as PDF.

06 January 2011

Defamation and archives

Unacceptable publications: falsifying the record?

One problem we are having to grapple with increasingly in the internet age is that of archives. In the past, if a book contained illegal or defamatory material, you would supress its further publication, but it took too much effort to engage in book-burning, and libraries would probably retain their copies. No-one would attempt to get back all copies of last week's newspaper, or to fillet the publisher's archive. In the internet age we have semi-permanent, searchable, global access to almost anything, so the damage done continues long after publication of even the most ephemeral comment. How far is it acceptable to require filleting of archives to remove illegal or defamatory material? When does falsifying the record become worse than dissemination of the unacceptable material?

Where’s my Blackberry?

Data protection comes of age – is your law firm taking it seriously?

It’s hilarious, isn’t it? MI6 officer leaves his laptop in a cab. HMRC loses unencrypted data disk in the post. Building society employee’s computer is nicked from his home. Medical records found in car park. Council loses children database on memory stick. Only this week, sensitive Scottish court records discovered at recycling bank. There are so many of these stories, and we all enjoy a laugh at the incompetence of these large organisations in protecting our personal information. After all, this only applies to big, faceless institutions managing huge databases – doesn’t it?
Data protection law has been around for a long time, but it hasn’t been taken terribly seriously by anyone outside of large data centres – except as an excuse to not tell anyone anything: “can’t answer that – data protection”. We used to tell our clients not to worry unduly – make sure you register, but if you get anything wrong all you will get is a telling-off and guidance on how to do better next time.
But now data protection has come of age. Sit up and take notice. In November the Information Commissioner’s Office (ICO) levied its first fines, under stronger powers given it last year. Hertfordshire County Council was fined £100,000 for inadvertently sending child protection case papers by fax to the wrong number. Who hasn’t sent a fax or email to the wrong address? Yet the council should, apparently, have had procedures to stop this happening. What procedures, exactly?
The second fine was even more concerning for businesses. A private company, A4e, was fined £60,000 for the loss of a laptop, stolen from an employee’s house, containing unencrypted data on 24,000 people.
Data protection doesn’t only apply to big databases – the Hertfordshire case concerned only a handful of people, though the information was of the most sensitive kind. It doesn’t only apply to professional data processors; it can apply to any business. And good intentions aren’t enough: failure to have adequate security and procedures can lead to large fines, even with the intervention of errors or criminals. Keeping data on a PC inside a locked private house wasn’t good enough protection.
That led me to think about the attitude of the legal world. Solicitors take client confidentiality very seriously, in terms of their own conduct, but many have not translated that into action on data security or, for that matter, physical security. They think of it as a duty to the client, but not about the other data subjects who may be referred to in their files. Legal practices hold vast amounts of personal data, much of it of a highly sensitive nature. Deeds and will may be kept in a safe, but there is little or no security on paper files, which are stored openly, carried around on public transport and taken home. Many lawyers’ computer systems have no security on internal access to data beyond an access-level password. They have firewalls and virus protection. But usually no protection at all against unauthorised access or copying by legitimate users of the system, or anyone in possession of their passwords. Data is not segmented or internally password-protected.
Access to the servers from the internet is usually tightly controlled, but once in, there are no restrictions on access to client data. Unencrypted email is universally used for almost all communication, and unencrypted attachments are sent that could include large amounts of personal data. Worst of all is the approach to home and mobile working. Data may be freely transferred to work or personal laptops and mobile devices. Mobile devices with weak passwords or PIN numbers allow access to the entire system, or at least to email records.
Solicitors have always relied on their integrity and professional conduct to enforce confidentiality. Systems are devised to prevent casual disclosure of information, but they are not designed to withstand deliberate, criminal attack. Most solicitors would feel that there is not much chance that they will be victims of deliberate espionage or malicious attacks.
Then there was the ACS Law case, in September 2010. ACS, a small law firm, acted for copyright holders trying to sue P2P file sharers for copyright infringement. It got court orders against ISP’s forcing them to disclose lists of users with details of internet usage, allegedly including their access to pornography. BT, and possibly others, sent the data to ACS as unencrypted email attachments – Excel spreadsheets. You wouldn’t have done that – would you? Then the libertarians of the file-sharing community mounted an illegal denial-of-service attack on ACS’s website. In attempting to restore the site, ACS’s IT people accidentally allowed access to internal data, including their email archive – which was promptly stolen and distributed across the net. ACS could yet be fined up to £500,000 for this breach. Clearly that should not have happened. But it was a mistake, made by a technical person. How is a law firm supposed to supervise an IT specialist to make sure he never allows external access to data?
More worrying still, the unencrypted attachments were the main source of the data stolen. What could ACS have done to protect that information? It naturally archives its emails, even if deleted by its users. It also backs up the archive and everyone’s inboxes. So multiple copies of any attachment will be created, even if the user did not save the attachment – or correctly saved it with a password.
This is the heart of the problem for law firms. We deal in evidence. We are instinctively more worried about losing access to data than we are about others gaining access. People leave, and passwords get forgotten. We lawyers hate to throw anything away. We get sued if we can’t prove exactly what advice we gave to Mrs Jones on the phone in 2005, or we can’t explain why clause 24 was deleted in draft 3, or we forgot the family history told to us five years earlier. Professional standards such as Lexcel require us to ensure that other people in the firm have access to client information if the lawyer is absent for any reason. The drive to be efficient and keep costs down requires us to share information quickly.
Part of data protection is the deletion of data that is no longer required, but I have yet to meet a lawyer who thought that any document or record could be discarded. Try persuading them that they should be deleting all records of incoming emails from the other side in litigation because they contain personal data! It’s evidence in the case.
So what should we be doing? The ICO’s guidance is quite clear, and it does not match with what many lawyers have been doing. Review your security with an eye on protecting the privacy of all data subjects, not just your client. Make sure your data is secure even if someone steals your PCs or servers. Identify particularly sensitive items, either because of the nature of the information or the number of data subjects, and take particular precautions, including password-protecting individual documents and preventing their removal from the office, in hard copy or unencrypted electronic form. Ban anyone from working on computers outside the office unless all client data is stored on an encrypted drive with a strong password. Prevent anyone from transferring data to CD or memory stick without getting authorisation, to include checking the security of the data. Promote a culture of data security, including password security.
For now, this will still be an imperfect solution. We need to communicate with outside parties and to transfer data to them. Email encryption is still not widely accepted in the world at large, due to the need for both parties to operate the same system, so email traffic is likely to remain vulnerable in transmission. Make sure your records of incoming and outgoing emails are stored on encrypted drives and that your access passwords are strong, and not remembered by the user’s PC – which Outlook rather encourages. Check that your backups of data are as secure as the originals. If necessary, implement a password management system to securely record the passwords needed to access protected data.
I have done all this myself, now I am working at home, to give clients and data subjects the best protection possible against unauthorised access to my home PC, laptop or smartphone, my wireless network or my email communications. I tell my clients to anonymise bulk information they may send me about their employees or customers wherever possible, and to password protect the information. But no-one has yet shown me how to prevent the mis-keying of a fax number, the loss of a document in the post or accidentally attaching the wrong file to an email. At least by being seen to try, we should be protecting ourselves from the savage criticism that will flow from doing nothing.
I should say that nothing in this article relates in any way to any of the firms I work with – I have no cause for concern about any of them.