Tag Archive for: IP

GDPR Best Practices: How Companies Adapted to Comply

By: Jon Avidor

The European Union’s privacy regulation General Data Retention Protection Regulation (GDPR) came into effect on May 25, 2018, which prompted companies to quickly review or change the way in which it collects and process users’ personal data. The new regulation gives European Union citizens more control over the private information they share online and applies to all companies worldwide that do business with E.U. citizens. Compliance with GDPR is critical for companies, as non-compliance could cost a company fines of as much as 4% of its annual revenue or 20 million Euros, whichever is more. We looked at how companies including major brands have changed their terms of use and privacy policies in compliance with the newly effective GDPR rules and requirements as a follow-up to an earlier GDPR article.

 User-Friendly Language and Interface

The crux of GDPR is that users now have the right to their own data and must consent to companies collecting their data by opting in, rather than opting out.  For users to understand what data they are divulging, how that data is being used, and what a user can do to remove or update their data, companies had to update its terms of use and privacy policies to be understood by the average user. This required the use of less technical language and the inclusion of definitions for lesser-known or ambiguous terms.  For example, Google now includes explanatory videos of how Google uses the data it collects from its users, and Twitter includes scroll-over definitions for terms such as “location data” and “advertising partner data” so that users can have a better understanding of what these terms mean in regard to personal data. These terms are important to define for users because terms such as “location data”, “online identifiers” or “genetic data” are now deemed to be personal information under GDPR.

Additionally, shifting away from dense, aesthetically unpleasing terms of use and privacy policies, companies have updated their interfaces to create a better user experience. The less technical language coupled with the more user-friendly interface have made the terms of use and privacy policy easier and more inviting to read and understand.

Personal Privacy Controls

Most companies now include a privacy settings tab that allows users to review what specific personal data the website has collected, review or rectify that data, and approve what data the website may continue to retain or share. These controls also allow users to have a transparent understanding of how the companies will use the data provided by its users. Companies have also included step-by-step tutorials and guides on how users can access and review this information.  In some instances, such as LinkedIn, any visitor to the site, regardless of whether the user has a registered account, has the right to access and control their personal data on the site.  Some sites only provide this feature for users accessing their site with registered accounts.

Data Protection Officer

The role of a data protection officer (DPO) is a mandatory implementation under GDPR for public authorities that process person data, companies that systematically monitor personal data on a large scale or companies that collect or process sensitive personal data or data regarding criminal convictions and offenses. The appointed DPO (either a designated employee or a hired outside consultant) must possess expert knowledge of data protection law and practices. The DPO is responsible for educating its company and employees on important compliance requirements, training staff involved in data processing, and conducting routine security audits.

To comply with GDPR, large scale data processing companies, such as Salesforce and Google, have appointed DPOs that will be the point-person for its companies’ users to inquire about the data collection procedures of its companies and policies as it pertains both generally and individually.

GDPR Compliance Good-Faith Effort

There is no magic language or magic sauce that a company can use to ensure complete and total compliance with GDPR.  There are many complexities and unanswered questions regarding GDPR, making it difficult for companies to guarantee complete and total compliance. By demonstrating good-faith efforts to substantially comply with the requirements of GDPR, companies may be able to mitigate the risk of paying the exorbitant fines for noncompliance.

Make America [Insert Adjective Here] Again! Why Trademarking Someone Else’s Popular Phrase and the Mad Dash to the USPTO is Trivial

By: Jon Avidor and Torie Levine

Fake news. Covfefe. Make America Great Again. These are phrases and words that are a big part of our current culture and seem like opportunities to make some big money if monetized. But before you spend your energy, and more importantly your money, trademarking these popular catchphrases, consider whether they can be registered and if you are actually eligible for protection.

Trademark as a Source-Identifier

A trademark is any word, name, symbol, logo, slogan, sound, color, or any combination thereof used to identify and distinguish goods and/or services and indicate their source. The objective of a trademark is to allow the public to recognize certain goods and services as originating exclusively with a particular individual or company. It’s all about brand recognition and brand protection. Thanks to trademark registrations, you know that when you walk into the fast food restaurant with the golden arches and order a Coke® and a Big Mac® that you’re getting a cola soft drink with a distinctive taste, two all beef patties, special sauce, lettuce, cheese, pickles, onions on a sesame seed bun®, and, if you’re lucky, a Happy Meal® toy, and that you can expect a certain level of quality from Coca-Cola®, McDonald’s®, and, let’s say, Hasbro®.

The “Use in Commerce” Requirement

The United States is a first-to-use, rather than a first-to-file, jurisdiction, meaning that, all things being equal, priority ownership and use rights goes to the first party to have used a trademark in commerce. A trademark must be actively used in commerce, i.e. in connection with the commercial offering or sale of goods or services, in order to be protected under trademark law. The Lanham Act defines use in commerce to be “the bona fide use of a mark in the ordinary course of trade, and not made merely to reserve a right in a mark.” A mark will be considered to be in use in commerce when (1) goods are sold or transported in commerce and the mark is displayed on the goods or their containers, in association with the goods or on tags affixed to the goods, or if the nature of the goods makes placement impracticable and (2) services are rendered in commerce and the mark is used or displayed on materials to advertise or sell the services. If you plan to use a trademark in connection with certain goods and services in the future, you can apply for trademark protection on an intent-to-use basis, but you would not be eligible for registration unless and until the trademark is used in offering goods or services to the public.

Let’s say you want to trademark the phrase “fake news.” We know now that the trademark must be used in commerce, and you cannot simply trademark the phrase because you thought of it—trademark law protects brands, sellers, businesses, etc. and their goods and services, not conceptual ideas. “Easy solution,” you say. “Let’s put ‘fake news’ on t-shirts and hats and sell them.” D’oh®! The U.S. Patent and Trademark Office will refuse registration of a mark if the use of the mark is purely used as an ornamental or decorative feature on the goods, but not as a trademark to indicate the source of the goods. For instance, slogans displayed on t-shirts and hats can be considered merely ornamental because those purchasers would not automatically think the slogan identified the source of the goods but would just view the slogan as a decoration on the goods.

This brings us to the next issue: who can register that trademark?

Whose Trademark Is It Anyway?

Whether a trademark can be registered is one consideration in the application process, but equally important is whether you, as the applicant, have the exclusive right to use and exploit that trademark and its goodwill. A trademark must identify a source and be associated with the trademark owner and his, her, or its goodwill and recognition among the public and not with some other third party. Catchphrases that don’t identify the source of a product cannot be trademarked. Thus, political catchphrases like “Lock her up,” “Covfefe,” and “Fake News” are associated with President Donald Trump, not any other person applying for registration.

The slogan “Make America Great Again” is owned by Donald J. Trump for President, Inc. (Serial Nos. 85783371 and 86724115). The trademark is used in connection with everything from bumper stickers, to clothing, and political campaign services. Therefore, President Trump’s distinctive use of the phrase gives him an advantage over competitors because he is the sole identifiable source of the catchphrase. Or is he? Back in 1980, presidential and vice presidential candidates Ronald Reagan and George H. W. Bush used “Let’s Make America Great Again” as their campaign slogan, and undoubtedly sold bumper stickers, clothing, and used the mark in the same manner as Donald Trump and Mike Pence. But the association between Reagan and his campaign slogan precursor to MAGA largely faded from the memories of the American electorate, and in a hypothetical trademark dispute between the two campaigns, Trump and Pence would easily prevail over Reagan and Bush as having stronger claims to the trademark on the grounds of actual and current use in the marketplace and present brand recognition. The bottom line is that it’s all about timing, current use in the marketplace, and customer goodwill and brand recognition.

#Trademark

A hashtag is a word or phrase preceded by the symbol # that classifies or categorizes the accompanying text (such as a tweet). Many brand owners want to protect their hashtags from being used in a way that is misleading, disparaging, or confusing with that of a competitor. The Trademark Manual of Examining Procedure (TMEP) states that “a mark comprising or including the hash symbol (#) or the term hashtag is registrable as a trademark or service mark only if it functions as an identifier of the source of the applicant’s goods or services.” Like “.com” in relation to a website, hashtags often do not, if ever, add any distinctive value to a trademark that would make an otherwise generic or descriptive mark a distinctive trademark. The TMEP offers #SKATER for skateboarding equipment as an example of a mark that would be refused because it is merely descriptive. A hashtag would also not differentiate a trademark from the same or a confusingly similar prior trademark since, as with .com, # is largely functional and meant to facilitate searches within online social media.

That is not to say that it is impossible to register a hashtag mark. In fact, there are hundreds of hashtag marks registered including #EVERYDAYMADEWELL (Reg. No. 4895377) for online retail store and retail store services and conducting contests and #THE ESTEE EDIT (Reg. No. 4950926) for a fashion, beauty, and lifestyle blog. Yet, even if a hashtag mark is registered, there are challenges to enforcing the mark because tagging a topic on social media is not considered a trademark use under the Lanham Act. Additionally, using another company’s name in a hashtag can be considered fair use. Therefore, while the U.S. Patent and Trademark Office grants registrations for hashtags where they serve as a source identifier, there is still a lot of uncertainty of trademark protection for hashtags.

Think Twice Before You Try to Trademark a Catchphrase

A phrase or word can gain immense popularity in a manner of minutes and entrepreneurs looking to exploit that as a business opportunity should be careful to avoid wasting their time and money. Despite the appeal of trademarking popular catch phrases, it is ultimately difficult to achieve due to who the applicant may be. Further, even if you are able to successfully register the trademark, you still face the hurdle of protecting the trademark from infringement. After all, if the catchphrase is as popular as you think it is, there will be others flooding the market in the same way you are. If trademark genericide has shown us anything, having a federal trademark registration has little value if you cannot defend it from infringement.

 

***

*We would like to thank Torie Levine for her contribution to this article.

Forms of Communication Subject to Regulation & ICO Marketing Collateral

By: Steve Masur

ICOs have become a dominant topic of discussion both within the blockchain community and among securities attorneys and regulators. The US Securities and Exchange Commission (SEC) views an ICO as an offering of securities if it meets all of the elements of the ”Howie test,” based on an old court case which has become familiar to most entrepreneurs in the blockchain/cryptocurrency space. If it meets the elements of the test, an ICO is subject to relevant SEC regulations most of which relate to communications about the ICO.

Further guidance from the SEC seems to indicate that most tokens sold in ICOs, particularly those whose platforms are as yet undeveloped, are securities. A series of recent enforcement actions against companies whose ICOs the SEC deems to have violated the securities laws have come to be referred to as the “Great Rescission” of 2018 because they have resulted, or likely will result, in investors receiving rescission rights from the ICO (i.e., they can get their money back). This can be costly for a company and can disrupt its plans to develop and launch its platform.

Because the ICO market grew exponentially before the SEC could adequately determine how to apply existing regulations, customs emerged in ICO offerings that may not lend themselves to proper SEC compliance.  ICO issuers eagerly await further guidance from the SEC in their quest for some certainty about the requirements, and the SEC is hard-pressed to keep pace with emerging issues in this area. For now, as both sides struggle to apply the existing regulations to this new technology, it is clear that if an ICO token constitutes a security, SEC regulations relating to communications apply. So companies need to learn these regulations and adjust their approach to fit them in their ICOs to US investors.

Forms of Communication Subject to Regulation and Related ICO Issues

Offering Documentation and Advertising in General

Offering documents are the materials presented to investors in connection with a securities offering. They differ in length and detail depending on whether the offering is public or private, its size and the nature of the targeted investors.

For a public offering, they generally consist of a prospectus containing a description of the company, the terms of the offering, risk factors, how the proceeds of the offering will be used, audited financial statements, an analysis of the financial statements and other information about the issuer’s securities. This information is filed with and reviewed by the SEC in a registration statement, generally on a Form S-1.  Corporate communication, about the offering but also in general, is strictly regulated during the pendency of a public offering. However, because the vast majority of blockchain companies choose to avoid the arduous and expensive process of registering their ICOs as public offerings, this will focus mainly on private offerings which, by complying with certain requirements, are exempt from the registration requirement applicable to public offerings.

For a private offering, three likely scenarios emerge. Under the first two, the company plans to approach a number of “accredited investors” with a proposed offering in mind, generally using a Private Placement or Offering Memorandum (a “PPM” or “POM”). The PPM contains much the same information as a public offering prospectus but without the requirement that the financial statements be audited as long as all investors are accredited.  These PPM disclosure standards, while not statutorily mandated, are often followed to protect the company from investor lawsuits alleging fraud and misrepresentation.

In one of these two scenarios (under “Rule 506(c)” of Regulation D under the Securities Act of 1933, as amended), the company may engage in “general solicitation and advertising” of its offering beyond its principals’ circle of acquaintances, but to do so, it must comply with some fairly stringent requirements with respect to verification of its investors’ qualifications. For this reason, many traditional company’s have steered away from Rule 506(c) offerings. However, ICOs seem to favor them.

In the third scenario, the company negotiates a funding arrangement with a relatively small group of sophisticated investors. Often the investors themselves dictate the terms of the deal, and do not require the same level of disclosure as do “friends and family” or a broader circle of investors. As a result, the offering materials in this type of private offering often consist of a simple term sheet with a statement of risk factors. These documents are delivered with a business plan and other materials requested by the investors in their due diligence. These offerings are not advertised and are essentially private deals made with investors who are both accredited and sophisticated and are therefore deemed able to fend for themselves in evaluating the company and requesting information.

In addition to the PPM or term sheet, the private offering materials in all three scenarios contain a subscription or purchase agreement and generally a separate questionnaire under which each investor certifies that it meets the requirements for an investor in a private offering, including the specific factors that qualify it as “accredited”. The offering materials also often accompany or even incorporate the company’s business plan.

In each of the above scenarios, the company will generally limit its offering to “accredited investors” which is defined under the regulations based on income and asset tests for various types of investors. Note, that for a private offering involving non-accredited investors, the financial statements must be audited as with a public offering, and the company must comply with other specific disclosure requirements, which is part of what prompts companies to steer away from non-accredited investors.

The most commonly used form among ICOs appears to be under Rule 506(c) employing general solicitation and advertising. This, however, is subject to change as various trends emerge in this area. A growing contingency within the blockchain community is calling for a different offering structure under a relatively new SEC regulation, “Regulation CF.” in this context, CF stands for “Crowdfunding.”

Before an offering under Regulation CF is launched, communication about it is limited. An issuer can only engage in communications that do not mention the offering or raise public interest in the offeror. General advertisement of the company and its products or services is permitted, but any heightened advertising may raise suspicion that you are seeking out investors for your company. After the company has launched its offering by filing a Form C with the SEC the company may only engage in the following communications outside of the crowdfunding platform: communications that don’t mention the “terms of the offering”, and communications that just contain “tombstone” information. (Tombstone information is limited to just a limited set of hard factual information: (1) a statement that the issuer is conducting an offering pursuant to section 4(a)(6) of the Securities Act  the name of the intermediary through which the offering is being conducted and a link directing the potential investor to the crowdfunding platform; (2) the terms of the offering (the amount of securities offered, the nature of the securities, the price of the securities and the closing date of the offering period); and (3) factual information about the legal identity and business location of the issuer, limited to the name of the issuer of the security, the address, phone number and Web site of the issuer, the email address of a representative of the issuer and a brief description of the business of the issuer. Despite the general prohibition on advertising the terms of an offering, an issuer may communicate with investors and prospective investors about the terms of the offering through communication channels provided by the crowdfunding platform, as long as the issuer clearly identifies itself in all communications so as not to be misleading and persons acting on behalf of the issuer identify their affiliation with the issuer in all communications on the crowdfunding platform.

Offering materials, regardless of which type of offering is conducted, must be prepared in order to avoid the issuer saying either too much or too little. On the one hand, they should not include statements that amount to “puffery” which potentially overstate the merits of the investment or risk making false promises to investors. On the other hand, they must include all relevant information to the offering and the company, including risks of making an investment and any other statements that might be necessary to make other information “not misleading.” Also, any statements that are forward-looking or predictive of future events or probabilities should be couched in appropriate disclaimers and meaningful cautionary language.

ICO Offering Materials and Whitepapers

Many ICOs are conducted using “whitepapers” which describe the company, its blockchain solution and the tokens or coins being generated and ultimately issued. These whitepapers are often presented on a company’s website alongside of POMs or simple term sheets describing the terms of the token generation and sale, whether it is to be direct or through “Simple Agreements for Future Tokens (SAFTs),” the types of investors, the process for investing, detailed risk factors and standard cautionary language and disclaimers.

As long as the whitepaper has all of the legally recommended information or is accompanied by a standard POM or term sheet containing it, it should suffice to satisfy all of the offering material requirements and standards. However, because whitepapers are modeled more after the tradition of business-to-business marketing documents rather than securities offering materials, they tend to stretch the rules a fair amount, particularly when it comes to “saying too much.” Any language that purports to guaranty a return on investment or assure any appreciation in value should be avoided. Also, whitepapers should have their own disclaimers and cautionary language.

Some issuers and their attorneys seem to have difficulty conforming the language of the traditional POM to fit the token/coin issuance model. Tokens can be analogous to shares of stock in a corporation, but the analogy is not perfect and can break down in certain key areas such as governance and equity ownership. The description of the tokens in an ICO and all rights conferred (or not) upon investors must be clear and accurate. To achieve this, the company should retain counsel who understands blockchain and the nature of tokens and the ICO process to review all offering materials, including the whitepaper.

Also, because many companies seek to conduct ICOs on their own websites, they comply with the requirements of Rule 506(c), mentioned above, in order to employ general solicitation and advertising without having to limit their contacts with potential investors. However, they often issue public POMs that have strict confidentiality language in them, in several cases even requiring that investors return the offering materials to the company if they choose not to invest. This language comes from a private offering model in which the POM is considered a confidential document and the company does not engage in “general solicitation.” It makes no sense to post a document publicly on a website and claim that its contents are “strictly confidential.”  Again, careful review by a qualified attorney is key.

Solicitation/Advertising Materials

Similarly to offering materials and whitepapers, any supplemental materials used to promote or advertise offerings of a cryptocurrency or other token that constitutes a security should avoid any sort of puffery or overstatement of the potential for profit. Although supplemental materials need not contain all of the information in the offering materials, any information must be accurate and cannot omit anything that would render it misleading. Because of the general excitement and media attention surrounding cryptocurrency and ICOs, examples of puffery and unqualified promises of great appreciation in value abound. These are amplified by celebrity endorsements and the use of social media.

In addition, there are specific rules regulating the timing, nature, and content of soliciting and advertising materials in both public and private offerings. With respect to public offerings, specific rules under the Securities Act detail what can and cannot be said about an offering prior to the initial filing of offering materials with the SEC, while the SEC’s review is pending and after the SEC has declared the offering effective and it has commenced. For private offerings, general solicitation and advertising are only permitted in limited circumstances.

Press Releases, Social Media and Celebrity Endorsements

Press releases have a long history of being used by both public and private companies to announce major events and important news. For any entity engaged in offering securities, press releases should be carefully reviewed by an attorney to ensure they do not contain exaggeration or statements that could complicate or delay the offering. The same applies in the ICO context.

The same guidance applies to posts on social media. However, the ease with which posts can be made to social media, versus issuance of a traditional press release, poses certain risks in and of itself. Offhand remarks on social media have become the norm and, in many contexts, have replaced carefully thought out, planned communication strategies. The nature of social media also gives access and voice to a wide number of participants in a company’s ICO, many of whom favor social media over traditional means of communication partly for the very reason that they are disruptors themselves and favor more modern, open processes.

Celebrity endorsements, particularly over social media, pose even greater risks. They present the usual risks of overblown promises and exaggeration but also must be reviewed for accuracy by the person giving the endorsement or a representative and should only be used with written permission under a carefully drafted agreement. They may also be subject to heightened scrutiny because of the weight a celebrity’s voice can carry, rightly or wrongly.

Only one or two individuals in a company should have the ability to post about its tokens and, in particular, a token offering, on social media accounts. A process should be in place to review and approve each such posting, regardless of how insignificant it may seem. Also, any claims of celebrity endorsements or quotes should be vetted and approved in writing before being released by the named celebrity or another expert.

Best Practices

I recently had a conversation with a blockchain/crypto client who told me that after talking to eight different attorneys about the application of American securities laws, he had not received the same advice twice. This cannot continue. We need to get our arms around how these existing regulations apply. But more than that, we need to advocate. In some ways, existing regulations simply don’t fit.  In those cases, we need to figure out what does and demand that lawmakers and regulators act on it. Eventually, a consensus will emerge around how cryptocurrency and ICOs should be regulated in the US, and experienced, thoughtful securities attorneys will be part of forming that consensus. Until then, best practices have less to do with concrete guidance and more with making the best decisions and using the best judgment in an uncertain environment.

First, find an experienced securities lawyer whom you trust. It should be someone who understands blockchain and cryptocurrency but also is willing to learn and consider innovative ways to apply long-standing rules to entirely new issues. Your attorney should be able and willing to keep abreast of developments as they unfold and to inform you of and explain any changes to prior advice.

Second, once you have secured the counsel of a good lawyer, use it. Regardless of how excited you are about your ICO, pause for a moment before issuing any form of public or private communication and discuss it with your lawyer. Consider whether it is forward-looking, whether it is supported by documents or other evidence, whether it is premature or requires disclaimers. Make sure you include your attorney early in the ICO process to avoid going down the wrong path.

Finally, document your honest attempts at compliance. In a regulatory climate where the laws and regulations are lagging the technology, regulators will be less likely to bring harsh enforcement actions against those who have sincerely endeavored to comply with laws and regulations and can demonstrate it.

E.U. General Data Protection Regulation Looms for American Multinational Businesses

By: Jon Avidor and Cassidy Lopez

If you do business in Europe, a new landmark European Union data protection law may have a huge impact on how you may collect and store personal information from their E.U. clients and customers.

The General Data Protection Regulation (GDPR), which is set to go into effect on May 28, 2018, is perhaps the most significant change in personal data privacy rules to date. The new regulation gives European Union citizens more control over the private information they share online and applies to all companies worldwide that do business with E.U. citizens. It is a prime example of the difference in how American law and European law approach consumer privacy—opt-in vs. out-out—while forcing global companies, especially those in the tech, retail, healthcare, and financial industries, to find a compliant yet practical and workable balance.

The new law itself has extensive technical and costly requirements, including providing E.U. customers with copies of their personal data at their request and also deleting any such personal data at the customer’s behest. Companies must also report any data breaches within a 72-hour period. Non-compliant companies can face threatening fines of as much as 4% of its annual revenue or 20 million Euros, whichever is higher.

Implications for Data Collection and Retention


Personal Data:
 The GDPR regulates directly or indirectly identifiable information about a person, or “Data Subject,” which is more expansive than the traditional American concept of “personally identifiable information,” and can include the consumer’s name, photo, email address, financial and banking information, social media posts, medical information, and even IP address.

Information Concerning Minors: Data controllers must obtain parental consent before processing personal data of children under the age of 16, though E.U. member states may lower the minimum age to no less than 13. This sets a higher bar than American privacy law, which under the Children’s Online Privacy and Protection Act requires verifiable parental consent before collecting and storing personally identifiable information relating to children under the age of 13.

Consent to Collect Data: The hidden browse-wrap privacy policy is a no-go under the GDPR. Data collectors must have “unambiguous” consent to collect ordinary identifiable “personal data,” such as a person’s name, location data, or demographics, but “explicit” consent to collect sensitive personal data, including information relating to a person’s racial or ethnic origin, political opinions, religious beliefs, health, and more. An intelligible and easily accessible form stating the purpose of data collection is sufficient for unambiguous consent, but explicit consent requires affirmative acceptance or opt-in.

Data Retention and Consumer Requests: The GDRP’s greatest compliance cost will likely result from the strict data retention policies. Data collectors must routinely account for the data they hold and why and where, how, and for how long its stored. Within one month upon request by a data subject, these companies must provide E.U.-citizen customers with reports detailing all high-risk personally-identifiable information held by the company and disclose how they use that data and under what permissions. Companies will develop mechanisms for users to submit data requests to gain access to personal information.

This is not surprising in light of the 2014 ruling by the Court of Justice of the European Union that, under the EU’s 1995 Data Protection Directive, individuals have the “right to be forgotten,” more specifically, the right to request Internet search engine operators remove information from search results that is “inaccurate, inadequate, irrelevant, or excessive.” Listen to John Oliver’s take on Last Week Tonight.

Mandatory Security Breach Notifications: To ensure accountability, in the event of a “high risk” security breach, the data controller must notify its country’s supervisory authority and all affected individuals within 72 hours of discovering the breach.

Appointing Data Protection Officers: Organizations that engage in “large scale” systematic collection and processing of personal data must hire an expect in data protection law and practices as a Data Protection Officer.

Penalties for Non-Compliance: The enforcement mechanism under the GDPR is a fine, tiered up to the greater of 4% of total worldwide turnover (i.e., revenue) in the past financial year or 20 million Euros, based on, among other things, the scope and duration, negligence, and subsequent transparency of the data breach or non-compliance, as well as past infringements

Effect of “rexit: Since the United Kingdom will still be a member of the European Union when the GDPR goes into effect later this year, the GDPR will become part of U.K. law and remain so after leaving the E.U. The U.K. Department of Digital, Culture, Media and Sport introduced into Parliament the Data Protection Bill, which according to Shearman & Sterling, would largely implement and perhaps even enhance the GDPR framework and policies. As of January 18, 2018, the bill had proceeded from the House of Lords and is currently under consideration in the House of Commons. Check the status here.

U.S. Cooperation and the Privacy Shield

The E.U.-U.S. Privacy Shield framework is an agreement between the U.S. Department of Commerce and the European Commission designed to provide a regulatory framework for commercial personal data exchange between the European Union and United States in a way that satisfies both jurisdictions’ privacy and consumer data protection laws, namely the GDPR. It replaces the U.S.-E.U. Safe Harbor program. Once an eligible U.S. organization voluntarily and publicly commits to the Privacy Shield Principles, compliance with its commitment to data processing transparency, security, and accessibility is enforceable under U.S. law, primarily by the Federal Trade Commission or, if relating to an airline or ticket agent, the Department of Transportation. Participating American businesses must also provide a free mechanism for consumers to resolve privacy issues directly with the company and agree to final, “last resort” arbitration with an approved data protection authority. The E.U.-U.S. Privacy Shield will not apply to data transfer between U.S. and U.K. companies post-Brexit, according to a U.K. parliamentary committee report as reported by TechCrunch.

Looking Ahead, Companies Weigh Their Options

Compliance with GDPR is a top priority for many large U.S. based multinational companies, but achieving compliance won’t be cheap. PricewaterhouseCoopers reported that, to insure against the threat of fines and penalties resulting from non-compliance, 92% of U.S. multinational companies cite compliance with GDPR as a top priority and 68% of those companies are committing between $1 million to $10 million to GDPR compliance efforts. For others, the investment isn’t worth the return, and the threat of high fines and injunctions is instead leading some businesses to reconsider doing business in Europe. In another recent survey conducted by PwC, 32% of respondents plan to reduce their European presence, while 26% plan to exit the European market all together. While Google parent company Alphabet certainly won’t exit the European market, which contributes approximately $9.3 billion to Google’s annual revenue (approximately 33%), Deutsche Bank predicts Google’s bottom line could take a 2% hit as an estimated 30% of E.U. users will likely opt-out of data sharing under the GDPR, decreasing Google’s targeted ad efficiency by 20%. One report also claims that only 34% of sites in the EU are ready for GDPR. As European regulators continue to clarify how they will interpret the GDPR, more American companies are likely to re-evaluate the return-on-investment of their European initiatives.

* We would like to thank Cassidy Lopez for her contribution to this article.

DMCA Safe Harbor: Protecting Yourself from Copyright Infringement

By: Jon Avidor

The Digital Millennium Copyright Act, 17 U.S.C. § 512, (“DMCA”) provides Internet communications service providers, including website operators, with immunity from copyright infringement liability for, among other things, infringing material posted on its sites by its users, provided the online service provider implements a procedure that allows copyright holders to report alleged infringement of its protected work on its website or through its service.

The type of “service provider” exempted from copyright infringement liability under the DMCA is defined as “an entity offering the transmission, routing, or providing of connections for digital online communications, between or among points specified by a user, of material of the user’s choosing, without modification to the content of the material as sent or received” or “a provider of online services or network access, or the operator of facilities therefor.” In practice, service providers are the conduits for transmitting digital online communications among users and include telecommunications companies or ISPs like Verizon or Comcast as well as the companies that provide online services and networks, including websites. It’s a broad definition.

To avoid liability for copyright infringement, a service provider must not have prior actual or constructive knowledge of the infringing material, not “receive a financial benefit directly attributable to the infringing activity,” have a notice and takedown procedure in place for reporting infringing material, and, where appropriate, terminate repeat infringers accessing the site or service. Here are general guidelines to remain protected by the DMCA safe harbor:

Before Posting Terms of Use or Terms of Service

  1. Review procedures for dealing with intellectual property infringement as set forth in the service or website’s terms of use or terms of service.
  2. Establish an email address to receive notices of claimed infringement and counter notifications, such as “copyright@yourdomain.com” or “IP@yourdomain.com,” and update the email address in the terms of use or terms of service.
  3. Choose someone within the company to receive notices of claimed infringement and register that person as a “designated agent” with the U.S. Copyright Office’s DMCA Designated Agent Directory. Agent designations expire after three years and service providers will have to re-register to remain current.

An Note on Designated Agents: The Copyright Office introduced an electronic directory of DMCA designated agents on December 1, 2016, and subsequently required any service provider with a designated agent prior to November 30, 2016 to re-register its agent through the new online system by December 31, 2017 to continue its protection under the DMCA safe harbor. For more on this change and its implications, see our Legal Alert for Online Service Providers.

Upon Receiving a Notice of Claimed Infringement

The DMCA’s safe harbor and notice and takedown procedures only apply to alleged copyright infringement, though comprehensive terms of use or terms of service will provide a similar mechanism for trademark or other intellectual property infringement allegations and complaints.

  1. Review the Notice of Claimed Infringement to determine whether it sets forth the formal requirements per the posted terms of use or terms of service.
  2. If the Notice of Claimed Infringement does not meet the formal requirements, the service provider may reject it and notify the reporting party that it must resubmit with the required information before it will consider taking action.
  3. If the Notice of Claimed Infringement does meet the formal requirements, the service provider should expeditiously remove or disable access to the material that is claimed to be infringing and then notify the user/poster that its material was removed and that they may choose to file a Counter Notification to reinstate the content according to the procedures set forth in the terms of use or terms of service.

Upon Receiving Counter Notification

  1. Review the Counter Notification to determine whether it sets forth the formal requirements per the posted terms of use or terms of service.
  2. If the Counter Notification is non-compliant, the service provider may reject it and notify the responding party that it must resubmit with the required information before you will consider reinstating their content.
  3. If the Counter Notification does comply with the formal requirements, the service provider should notify the reporting copyright holder and provide a copy of that Counter Notification.
  4. If a proper Counter Notification is provided and the complaining copyright holder does not file a lawsuit against the alleged infringer within ten to fourteen business days and notify the service provider that it has done so, the service provider may restore the removed material. However, even if an alleged infringer has complied fully with the Counter Notification procedure, a service provider is not necessarily obligated to restore the reported content. Comprehensive terms of use or terms of service will reserve a service provider’s right to terminate any user and prevent it from using or accessing the website and services after receiving even a single Notice of Claimed Infringement.

Unless a service provider has staff trained in evaluating and responding to notice and takedown requests, they should seriously consider involving legal counsel to make those determinations because, as discussed below, non-compliance or otherwise lackadaisical attention to claims of copyright infringement can cause service providers to blow their DMCA safe harbor protection and face costly claims of contributory copyright infringement.

Repeat Infringers

The DMCA safe harbor provisions require that service providers “adopt and reasonably implement” a policy for terminating the accounts of any “repeat infringers” where appropriate. What’s sometimes troublesome is that the DMCA does not define who is a “repeat infringer” and what the “appropriate circumstances” are that would require the service provider to terminate an infringer’s access, so service providers have some discretion in setting and implementing their own policies. For example, a service provider’s repeat infringer policy might be to notify and terminate any alleged infringer’s account or access if the service provider has received and acted on more than, let’s say, two DMCA-compliant Notices of Claimed Infringement concerning that user. Once a service provider receives a Notice of Claimed Infringement, the law considers the service provider to then have actual knowledge of multiple instances of infringing content on its site or through its service and, therefore, must act to remove it and prevent repeat offenders, or risk losing its DMCA protection from copyright infringement liability.

The risk of non-compliance with formal DMCA requirements can be costly. In December 2015, Cox Communication lost its DMCA immunity and was found guilty of willful contributory copyright infringement and ordered to pay a $25 million judgment to music publisher BMG for disregarding infringement notices and its repeat infringer policy against users who freely passed copyrighted music through its system. According to The Hollywood Reporter, “Although Rightscorp detected 1.847 million instances of infringement and collected more than 150,000 copies of copyrighted works downloaded directly from Cox subscribers, according to testimony presented at trial, there was 1,397 copyrighted works in contention in the lawsuit. That means that the $25 million verdict amounts to about $18,000 for each song infringed.” An appeal to the U.S. Court of Appeals for the Fourth Circuit is currently pending.

The Pitfall of Trademark Genericide: When Household Names and Brands Collide

By: Jon Avidor and Qualia C. Hendrickson

Escalator. Heroin. Dry Ice. Teleprompter. Laundromat. Each of these words or phrases were originally coined as trademarks, though have since lost their distinctive nature and exclusivity as they slowly became part of the American lexicon in the years since their introduction. They’ve fallen victim to genericide.

“Genericide” occurs when a once-distinctive trademark becomes the commonly used and understood word for a certain type of good or service, in general, and not in reference to any one particular product or manufacturer. Back to our initial list of genericided marks, when people take an escalator, all they know is that they’re hopping on a mechanically ascending or descending staircase and praying it won’t eat their shoelace. As early as 1950, the general public no longer associated the escalator with its 1891 inventor (and Lehigh graduate) Jesse Reno or the Otis Elevator Company, which trademarked “escalator” in 1900. See Haughton Elevator Co. v. Seeberger, 85 U.S.P.Q. (BNA) 80 (Apr. 3, 1950). A trademark can become generic either through the trademark owner’s improper policing of the mark against infringing uses or the public’s use of the mark as the general name for similar good and services. For example, in an October 2013 SEC filing, Twitter Inc. expressed concern that the term “‘Tweet’ could become so commonly used that it [could become] synonymous with any short comment posted publicly on the Internet.” Similar to Xerox, Band-Aid, Kleenex, and TABASCO, Twitter launched a public relations campaign as early as 2010 on how to properly use the word “Tweet,” which drew some vocal opposition, including from the cofounder, CEO, and editor-in-chief of Business Insider.

Trademark owners often lose their exclusive right to use their respective trademarks or service marks due to genericide in two ways: (1) in trademark infringement litigation where a defendant successfully argues genericide as a defense resulting in the mark’s cancellation or (2) where a challenging brand, producer, or manufacturer seeks to cancel the trademark owner’s trademark registration. In deciding whether a trademark has become generic, courts use the primary significance test and ask “whether the primary significance of the term in the minds of the consuming public is now the product and not the producer.” Elliott v. Google, Inc., No. 15-15809 (9th Cir. May 16, 2017). What is relevant is not whether some small portion of the public considers the term an indicator of the source, but rather what the “entire consuming public” considers the term to indicate. Bayer Co. v. United Drug Co., 272 F. 505 (S.D.N.Y. 1921). Courts also consider whether declaring the mark generic will create a likelihood of confusion among the consuming public and induce consumers into buying a competitor’s product when they intended to purchase the one made by the original trademark owner.

The following cases illustrate the risks to trademarks posed by, first, a trademark’s owner improper policing and, second, the public’s appropriation of the mark in relation to the type of goods or services in general.

Improper Policing Against Infringement

Asprin
Bayer Co. v. United Drug Co., 272 F. 505 (S.D.N.Y. 1921).

Bayer once owned exclusive rights to call the drug acetylsalicylic acid “Asprin” but lost its trademark in one of the greatest examples of genericide. The pharmaceutical company tried to prove the strength of their mark by showing that pharmacists and chemists understood the term “Aspirin” as a reference specifically to Bayer’s drug, but ultimately lost on the basis that whether a mark is generic does not depend on whether a select section of the public understands the mark as a source identifier, but rather whether the public as a whole understands the mark to refer to the product and its single source.

Thermos
American Thermos Products Co. v. Aladdin Industries, Inc., 207 F. Supp. 9 (D. Conn. 1962).

Because it failed to stop others from using “thermos” in connection with insulated bottles and the like, the company that originally owned and produced the bottles under the trademark Thermos is now limited in its rights to its trademark. Additionally, the company failed to prevent generic uses of the term by non-trade publications or follow up with trade publications that agreed to discontinue their generic use but persisted. As a result, other insulated container manufacturers may use the term “thermos” as long as they eliminate the risk of confusion among consumers by preceding the term with their own name or brand and display the term “thermos” in all lowercase, same sized letters.

Public Appropriation of the Trademark

Cellophane
DuPont Cellophane Co. v. Waxed Products Co., 85 F.2d 75 (2d. Cir. 1936).

The original creator of “cellophane” lost his grounds for trademark protection because the mark was employed to describe the product with no other descriptive words, e.g., “Cellophane brand transparent wrapping.” Producers developing products that are the “first of their kind” in the marketplace should keep in mind what the term means to the buying public, which will be central to a court’s analysis. An inventor who does not provide the public with an alternate name and uses only the trademark to market the product will likely subject the trademark to genericide.

Beanie Baby
Ty Inc. v. Perryman, 306 F.3d 509 (7th Cir. 2002).

While Ty Inc. still holds its trademark for BEANIE BABY®, it failed to prove that the use of the term “beanies” for second-hand beanbag stuffed animals diluted the value of its trademark and misled the public regarding brand affiliation. Citing the difference between trademark dilution and fair use, the court noted descriptive or suggestive marks are better candidates for becoming generic than more distinctive marks. If a trademark is a more appealing term than its generic name—just as the term “beanies” is a more appealing name for “beanbag-stuffed animals”—the trademark owner may lose its trademark protection due to public appropriation as a convenient short-hand. Meanwhile, I’m still waiting for my Beanie Baby collection to be worth, like, a million bucks some day—the Millennial dream.

What we can learn from these cases is that trademarks are not well suited for “Set It and Forget It”®, but instead require attention. What trademark owners do with their marks—registered or not—can have significant consequences on the value of their brands as they gain greater market penetration and become household names.

Trademark Case Roundup

By: Jon Avidor and Qualia C. Hendrickson

As we recently reported in our blog post Disparaging Trademark or Reclaimed Slur? The Supreme Court Weighs In, the high court ruled 8-0 in Matal v. Tam that the Lanham Act’s ban on disparaging marks was an unconstitutional violation of the First Amendment and allowed Simon Tam to move forward with his trademark application for his Asian-American dance-rock band The Slants. This case will certainly open the door to registering many other marks previously rejected or cancelled by the United States Patent and Trademark Office on the basis of their offensiveness, including the polarizing Washington Redskins’ recently cancelled trademark.

In this post, we will review other recent trademark cases that may have implications on businesses in the media, technology, and consumer products and services spaces.

Elliott v. Google, Inc., No. 15-15809 (9th Cir. May 16, 2017).

Issue: Whether the GOOGLE trademark lost its trademark protection on the basis that the word “Google” had become a generic name for the act of searching the Internet. “Genericide” occurs when a trademark has lost its value as a distinctive brand-identifier when “the public appropriates a trademark” and uses the mark to refer generally to a type or class of goods or services without regard to any particular brand or source, and “the primary significance of the term in the minds of the consuming public is now the product and not the producer.”

Decision: The Ninth Circuit Court of Appeals decided in favor of Google, holding that a claim of genericide must relate to a particular type of good or service and that the use of a trademark as a verb does not automatically constitute generic use. GOOGLE is still a protected trademark even if it is used as a verb, as in “I Googled current trademark cases,” because the primary significance of the term in the minds of the public is a single internet search engine, Google, not of search engines in general.

Belmora LLC. v. Bayer Consumer Care AG, 819 F.3d 697 (4th Cir. 2016)cert. denied, 580 U.S. __ (2017).

Issue: Whether a foreign corporation may sue under the Lanham Act—the American federal trademark act—over the unauthorized use of a foreign trademark that has never been used in the United States of America or been registered with the United States Patent and Trademark Office.

Decision: The Fourth Circuit Court of Appeals reversed the lower district court’s holding in favor of an American trademark holder and ruled that a Mexican trademark holder could sue under the Lanham Act. Section 43(a) of the Lanham Act “does not require that a plaintiff possess or have used a trademark in U.S. commerce as an element of the cause of action” for unfair competition, such as for false association and false advertising. The law only requires that a plaintiff be “likely to be damaged” and show its prospective injury is in the “zone of interest” of the Lanham Act, i.e., the deceptive and misleading use of a trademark. Belmora petitioned the Supreme Court to reconsider the Fourth Circuit’s ruling and the Court denied certiorari on February 27, 2017.

Tiffany & Co. v. Costco Wholesale Corp., 127 F. Supp. 3d 241 (S.D.N.Y. 2015).

Issue: Whether “Tiffany” had become a generic term for a style of diamond ring setting, and whether punitive damages were available for clear evidence of infringement.

Decision: The New York district court denied Costco’s claim that using the term “Tiffany” in a generic manner to describe a style of jewelry was covered under the fair use exception to trademark infringement. In light of the evidence of Costco’s clear intention to imitate Tiffany & Co.’s mark and to confuse consumers, Tiffany & Co. sought punitive damages for the infringement. Although the Lanham Act (specifically, 15 U.S.C. §1117(a)) does not allow courts to grant punitive damages in trademark infringement cases, N.Y. General Business Law § 360-M (for registered marks) and New York case law (for all marks) permit punitive damages where an infringer uses another’s trademark to sell a competing product in bad faith, what the court called “wanton or willful fraud or other morally culpable conduct to an extreme degree.”

Princeton Vanguard, LLC v. Frito-Lay North America, Inc., 786 F.3d 960 (Fed. Cir. 2015).

Issue: Whether a trademark that is a compound term (two or more words strung together) should be evaluated for distinctiveness on the strength of the individual words or the strength of the mark in its entirety.

Decision: The Federal Circuit Court of Appeals held there is only one legal standard for genericness, regardless of whether the mark is a compound term or a phrase: (1) identifying the genus of goods or services at issue and (2) assessing whether the public understands the mark, as a whole, to refer to that genus. In evaluating the mark PRETZEL CRISPS, the Trademark Trial and Appeals Board was incorrect in analyzing genericness by the meaning of the individual words instead of the compound mark as a whole.

Couture v. Playdom, Inc., 778 F.3d 1379 (Fed. Cir. 2015).

Issue: Whether offering a service, but not actually providing the service, is sufficient to constitute “use in commerce” to support the mark’s registration as a protectable trademark.

Decision: A mark is “used in commerce” in connection with services, and therefore protectable, when it is (1) used or displayed in the sale or advertising of services and (2) the services are rendered in commerce, which requires a “bona fide use of the mark in the ordinary course of trade,” and at a bare minimum, in an open and notorious public offering or advertisement. Such advertisements must relate to an existing servicea service mark cannot be deemed “used” in commerce when the service has been advertised to the public, but no service has yet been rendered.

Disparaging Trademark or Reclaimed Slur? The Supreme Court Weighs In Matal v. Tam

By: Jon Avidor and Qualia Hendrickson

In a unanimous decision in Matal v. Tam, 582 U.S. __ (2017), the U.S. Supreme Court ruled that federal law prohibiting the registration of disparaging trademarks or service marks was unconstitutional under the First Amendment and that the United States Patent and Trademark Office (“USPTO”) may no longer reject applications to register trademarks deemed potentially offensive.

The “Disparagement” Clause of the Lanham Act

At issue in this case was Section 2(a) of the Lanham Act, which refused federal registration to trademarks and service marks that consist or comprise of “immoral, deceptive, or scandalous matter; or matter which may disparage or falsely suggest a connection with persons, living or dead, institutions, beliefs, or national symbols, or bring them into contempt, or disrepute . . . .” 15 U.S.C. § 1052(a). According to the Trademark Manual of Examining Procedure, in determining whether a proposed mark was disparaging, trademark examiners would look at “the likely meaning of the matter in question” based on the dictionary definition and other elements of the mark and how the mark is used, and “whether that meaning may be disparaging to a substantial composite”—not necessarily a majority—of the referenced, identifiable persons, groups, institutions, beliefs, or national symbols based on contemporary attitudes.

This prohibition—and case—only applied to registration of trademarks on the Federal Register (either the Principal Register or Supplemental Register). Federal registration provides substantial benefits to the trademark owner, including among other things, a legal presumption of nationwide ownership of a valid trademark, constructive notice to all other persons of the owner’s exclusive right to use the mark in commerce (plus the right to use the ® symbol), and greater monetary remedies in infringement lawsuits. However, prior to this case, potentially disparaging marks that would have otherwise been ineligible for federal registration could nevertheless develop common law trademark rights based on continued use in commerce.

The Slants

Matal v. Tam concerned the Asian-American dance-rock band The Slants, or as their new EP cleverly refers to themselves, “The Band Who Must Not Be Named.” The band applied to register THE SLANTS trademark with the USPTO twice, first in March 2010 and again in November 2011, in Class 41 for use in connection with “Entertainment in the nature of live performances by a musical band.” The USPTO issued an office action denying the application under Section 2(a) of the Lanham Act because the likely meaning of “SLANTS” was a negative term used in reference to the shape of certain Asian people’s eyes “in a disparaging manner because it is an inherently offensive term that has a long history of being used to deride and mock a physical feature of those individuals.” On appeal, the refusal was affirmed by the Trademark Trial and Appeal Board.

Lead singer of the rock band and named appellant Simon Tam argued he named his group The Slants to “reclaim” and erode the Asian stereotype and slur and to empower other Asians to “be proud of their cultural heritage, and not be offended by stereotypical descriptions.” Through their songs and performances, The Slants “weigh in on cultural and political discussions about race and society,” which Tam argued are at the heart of the First Amendment’s protection of free speech and expression. The U.S. Court of Appeals for the Federal Circuit agreed with Tam in a 10-2 ruling, writing, “Whatever our personal feelings about the mark at issue here, or other disparaging marks, the First Amendment forbids government regulators to deny registration because they find the speech likely to offend others. Even when speech ‘inflict[s] great pain,’ our Constitution protects it ‘to ensure that we do not stifle public debate.'” The government appealed the ruling to the Supreme Court.

Appeal to the Supreme Court

The Supreme Court heard arguments on January 18, 2017 (prior to Justice Gorsuch’s appointment) and decided the case on June 19, 2017, holding 8-0 in favor of Tam and The Slants. Justice Alito delivered the opinion of the Court, and Justices Kennedy and Thomas filed concurring opinions. The high court upheld the Federal Circuit’s decision and struck down the disparagement clause of the Lanham Act as a facial violation of the First Amendment to the Constitution, agreeing that the Lanham Act’s provision prohibiting the registration of trademarks that may “disparage . . . or bring . . . into contemp[t] or disrepute” any “persons, living or dead” could not withstand legal scrutiny of laws that discriminate on the viewpoint of the speaker.

While the government may constitutionally regulate or prohibit certain types of speech, these restrictions are narrowed exceptions to the “fundamental principle of the First Amendment that the government may not punish or suppress speech based on disapproval of the ideas or perspectives the speech conveys.” Governmental restrictions on one’s speech based its the content, i.e., either the subject matter or viewpoint of the speech, must meet strict scrutiny, meaning the burden is on the government to prove that the content-based restriction is necessary to protect a compelling governmental interest and is narrowly tailored to serve that interest. The Lanham Act, as well as the Trademark Manual of Examining Procedures, generally establishes viewpoint-neutral guidelines for trademark examiners to determine whether to grant an applied-for mark based on factors such as the mark’s distinctiveness to the consuming public, its similarity to other existing marks in the marketplace, and the mark’s likelihood to confuse consumers, among others. However, the Court ruled that the disparagement clause at issue in this case provides the USPTO with broad discretion to reject trademark applications on the basis that the content could offend particular persons, groups, institutions, beliefs, cultures, or ideologies, and unconstitutionally placed the burden on the applicant to prove the mark was not disparaging—a burden Tam and The Slants could not overcome in their first appeal. While the Government argued that trademarks primarily serve to identify the source of good or services, and are therefore commercial speech entitled to lessor scrutiny than expressive speech, the Court held that allowing the government to approve or disapprove of a trademark’s expressive elements was a violation of applicants’ constitutional free speech rights, and that as a fundamental principle of the First Amendment, “Speech may not be banned on the ground that it expresses ideas that offend.”

In a concurring opinion, Justice Kennedy focused only on the disparagement clause’s viewpoint-based discrimination and how the government could not carve out a subset of language it did not approve of and disguise their viewpoint discrimination as censorship, writing, “By mandating positivity, the law here might silence dissent and distort the marketplace of ideas.” For that reason, the challenged provision of Section 2(a) of the Lanham Act could not pass rigorous scrutiny. He and Justices Ginsburg, Sotomayor, and Kagan found further discussion of the other arguments presented unnecessary.

In a separate concurring opinion, Justice Alito addressed the government’s other arguments, including the “government-speech” doctrine that the USPTO used to defend its right to express its own viewpoint, warning that the argument is susceptible to dangerous misuse. He distinguished this case from a 2015 case, Walker v. Sons of Confederate Veterans, 576 US __ (2015), in which the Court allowed Texas to refuse to print the confederate flag on specialty license plates because license plates are government speech. Justice Alito wrote, “Trademark is private, not government, speech,” and that to allow trademarks, which are created by private individuals or businesses, to be passed off as government speech by virtue of a government seal and registration to it would be to permit the government to limit and silence speech the government found offensive and infringe on individuals’ rights.

Implications on Future Trademarks

The Court’s decision in Matal v. Tam eliminating the disparagement clause of the Lanham Act will certainly open the door to registering trademarks that have been rejected or cancelled under the disparagement clause. Interestingly, Reuters found that, since 2014, the Supreme Court often disagrees with specialized intellectual property courts and has upheld only 2 of 16 cases decided by the Federal Circuit court of appeals, which hears appeals from the administrative Trademark Trial and Appeals Board and Patent Trial and Appeal Board.

Perhaps the most widely known and hotly debated case of a refusal of trademark protection occurred in 2015 when a judge in the U.S. District Court for the Eastern District of Virginia affirmed a 2014 ruling by the Trademark Trial and Appeal Board declaring that the Washington Redskins’ name was offensive to Native Americans, cancelling six of the football team’s trademark registrations. An appeal was on hold in the Court of Appeals for the Fourth Circuit pending the outcome of Matal v. Tam, though in light of the Supreme Court’s decision, the team, which has used the Redskins name since 1932 amid both wide support from fans and vocal criticism from Native American advocacy groups and in the media, believes their dispute with the government will resolve in their favor. The court of public opinion is an entirely different beast, however, so the future of Redskins brand remains to be seen, though in the meantime, owner Dan Snyder says he is “thrilled” with the ruling.

 

*We would like to thank our intern Qualia C. Hendrickson for her contribution to this article.

A Virtual Reality Check – Oculus v. ZeniMax: Applying Copyright Law to VR

By: Steve Masur and Sarah Siegel

On February 1, 2017, a Texas jury found Facebook subsidiary Oculus VR, Inc. liable for $500 million in damages in its dispute with ZeniMax over Oculus Rift, a virtual reality technology acquired by Facebook in 2014. The jury found Oculus infringed upon ZeniMax’s copyrighted computer code and misrepresented the origin of its VR technology, and that its co-founder violated a non-disclosure agreement he had signed with ZeniMax. However, the jury found Oculus had not misappropriated ZeniMax’s trade secrets when creating Oculus Rift.

Many eyes were fixed on this case, especially from companies such as Google, Samsung, and Sony, which have all recently launched their own virtual reality headsets. With new emerging technology comes a legal landscape that is still developing and taking shape. This case, which dealt with the fundamentals of intellectual property law, provides an example of how copyright law is uniquely applied to virtual reality technology.

Background 

Like many start-up stories, this too starts in a 17-year-old’s parent’s garage with a video game enthusiast who wanted to improve and create a better technology experience. This particular 17-year-old was Palmer Luckey, and the technology in this story is the Oculus Rift virtual reality headset.

Oculus Rift was an idea that came from Luckey’s frustration with the existing virtual reality headsets on the market—the displays were poor quality, bulky, had a low field of view, and carried expensive price tags. He began working on his own design to improve upon these inadequacies, and created what would later be known as the Oculus Rift. In its early days, the Oculus Rift was created using duct tape, ski goggles, and wires. As Luckey made improvements and developments to the headset, he posted updates to a virtual reality online forum. John Carmack, a fellow VR enthusiast, kept up-to-date on Luckey’s forum posts and eventually requested a prototype from Luckey. At the time, Carmack worked at id Software, a software development company owned by ZeniMax, and was a notable video game developer for such series as Doom. At that time, ZeniMax had also been investing millions of dollars into researching and developing virtual reality technology. Luckey sent Carmack one of his two prototypes, and Carmack began making his own improvements, including writing code for the headset. With Luckey’s permission, Carmack demonstrated the Oculus Rift at a 2012 video game trade show by using the Oculus Rift headset with his new game, Doom 3. One year later, Carmack resigned from id Software for a new position as chief technology officer at Oculus Rift.

In March 2014, Facebook announced its acquisition of Oculus VR for $2 billion, and two months later, ZeniMax announced its intent to sue Oculus and Facebook over the Oculus Rift and its code.

Misappropriation of a Trade Secret

A trade secret is proprietary information that carries with it economic value solely by virtue of it not generally known or readily discernible by people who can benefit from it, and is the subject of reasonable efforts to maintain its secrecy. A misappropriation of a trade secret is the improper disclosure or acquisition of that secret.

In this lawsuit, ZeniMax argued that Carmack took company secrets with him when he left id Software for Oculus. Carmack never denied that he worked on the code for the Oculus Rift prior to his employment at Oculus, but he contended that this work was done in his free time, and not while he was on the clock at ZeniMax. ZeniMax, however, claimed that Carmack’s integral work and research for Oculus Rift was not done during his free time, but rather done during his employment at ZeniMax, using ZeniMax’s resources, computer, offices, and employees. The jury did not agree with ZeniMax and did not deem the work Carmack brought to Oculus as a misappropriation of a ZeniMax trade secret, meaning that ZeniMax trade secrets were not contributed to Oculus and its headset.

Copyright Infringement of Virtual Reality

Virtual reality source code is protected by copyright law, not patent law, as an original expression once fixed in a tangible medium, and therefore, any infringement on VR software is governed by the rules of copyright. Under copyright law, an affirmative defense to a claim of infringement is fair use, which allows parts of a copyrightable work to be used in a new work, so long as the new work is transformative, that the nature and objective of the underlying copyrighted work is different than the new work, the new work does not substantially and qualitatively use the original work, and that the intended market for the work is different than the old work.

In this case, Oculus’ fair use defense did not hold up because the jury found that the computer code Carmack took was “non-literally” copied when it was integrated in the Oculus technology, meaning that Carmack changed aspects of the code he developed at ZeniMax to create a different code and used that to create Oculus, which is a similar program with similar functions. Additionally, the market for the new code used in Oculus was the same as the code ZeniMax would use for its virtual reality headset which was in development. Ultimately, the jury found Oculus infringed upon ZeniMax’s copyright in its VR code.

The Implications for Virtual Reality

The gray area of this decision is how to apply and interpret it. How different must copyrighted computer code be in order not to constitute a copyright infringement of prior existing code? Since the code used in Oculus was different than ZeniMax’s code, but used for a similar product, does ZeniMax possess the copyright on all code for virtual reality headsets? Evidently, these are just two of many unanswered questions that have been left in this decision’s path, and which have ramifications on legal and business affairs decisions, including how to structure and present documents governing technology development relationships, and even outcomes of disputes.

After the case was decided, ZeniMax filed an injunction against Facebook to stop the sale of the Oculus Rift and its development kits. Facebook intends to appeal the court’s decision. The continuing shake-out of this case and its implications for virtual reality will be closely followed as it unfolds.

*We would like to thank our intern Sarah Siegel for her contribution to this article.

(Trade)Marking Your Territory

By: Jon Avidor and Sarah Siegel

A strong trademark or service mark can become a valuable asset for your business, so when you come up with a great name or memorable tagline for your product or service, it makes sense to register the trademark. Common law trademark rights originate from use in commerce so all you have to do is use the particular name, word, phrase, logo, symbol, design, color, or sound in association with your good or service to establish priority ownership. However, obtaining a federal statutory registration from the United States Patent and Trademark Office (USPTO) heightens a trademark user’s ownership claim. It prevents later registrations of the same or similar marks and presumes the trademark’s legal validity, the owner’s exclusive right to use its mark nationwide, that the public is on notice, and that the marketplace associates the mark with its goods or services. Registration is a powerful deterrent to infringement and increases the value of a trademark.

Creating a Strong, Distinctive Mark

The first step in obtaining a trademark is to, well, create the trademark. Distinctiveness is the foundation of a protectable mark. Trademarks are evaluated along a spectrum of distinctiveness as shown below that correlates to whether an average consumer would likely associate the mark with the goods and/or services, as well as the producer and brand. In choosing a mark, the word or phrase should set your brand apart from competitors or anyone else in the marketplace so your trademark will be easier to protect and enforce.

masur

A generic mark, like COMPUTERS for your line of personal computers, would not be protectable because it could refer to any old product and would prevent anyone else in the industry from using that general term for its PCs. Unless consumers have come to associate a descriptive mark with a certain brand, a mark that simply describes a product or service’s qualities, like ALL-BRAN CEREAL for bran cereal, would not warrant protection either. A stronger mark would be one that is either suggestive of the good or service’s qualities, arbitrary in its association with the good or service, or invented for the purposes of the trademark. For example, JAGUAR for automobiles would be suggestive of a car’s speed and agility; APPLE for computers, rather than fruit, would be arbitrary; and KODAK, whether used for photography equipment or not, is a fanciful, made-up word. Each of these are considered strong marks.

Be One-of-a-Kind and Be Sure of It

In addition to being a distinctive source identifier, to receive protection, a trademark must not be “confusingly similar” to any preexisting or preregistered mark for goods or services in the same or similar markets. The USPTO will deny or, if litigated, a judge will invalidate a trademark if an average consumer is likely to believe that the source of the goods or services is the same as that of another, senior trademark. It’s not enough to change a few letters or intentionally misspell an existing mark; your mark must look, sound, and feel different and distinct.

Before building your brand around a particular trademark, you should ensure the mark does not infringe upon another similar or exact trademark registered or already in use. You can search the USPTO database for applications and registrations for potential conflicts with your trademark, or possible variants, and use a search engine for common law trademarks. For a more extensive search, especially for the trickier-to-search “confusingly similar” marks, you should hire an attorney who is experienced in trademark law and can make use of more sophisticated searches and skilled analyses.

Use the Mark and Renew the Mark

Once granted, a trademark registration puts the public on notice that the mark is yours and should not be infringed upon. However, you must use your mark in commerce to secure or perfect your trademark rights—it’s use it or lose it. Trademark abandonment occurs if the mark’s owner either intentionally stops using the mark or otherwise discontinues its use for a continual three-year period. Whether abandonment is intentional or presumed, the lapse in use may strip the mark owner of its previous trademark protection.

To retain its federal trademark registration, the owner must file a Declaration of Use or Excusable Nonuse for the trademark between the fifth and sixth years following registration and a Combined Declaration of Use or Excusable Nonuse and Application for Renewal within one year before the end of each ten-year period after registration. Failure to adhere to the post-registration maintenance requirements and renew the trademark in a timely manner will result in cancellation and/or expiration of the registration. Note, however, that common law trademark rights will continue so long as the mark is used in commerce, even if the registration is cancelled or expired.

…and Use It Wisely

Using the mark is important, but using it correctly is critical. A pitfall of highly effective brand PR and marketing is your trademark becoming too popular and acquiring mind share. When the public begins to use a trademark to refer to the general product or service, rather than brand of product or service originating from the trademark owner, the trademark loses its meaning as a source-identifier and, with that, its legal protection. Examples of terms that have famously lost their trademark protection as a result of genericism include “aspirin,” “dry ice,” “escalator,” and “linoleum.” Some marks that are at risk for losing their protection include COKE for cola, GOOGLE for search engines, KLEENEX for tissues, PHOTOSHOP for photo editing generally, Q-TIPS for cotton swabs, TASER for stun guns, and XEROX for photocopy machines. The more famous the mark, the greater risk that mark faces of losing its distinctiveness and protection. Many of these brands even actively campaign to the public to remind them not to use the marks too generically.

Beware of Infringers

If your mark is strong and your product is reputable in the marketplace, others in the industry will inevitably attempt to piggy-back on your brand and customer goodwill. Cue the infringers. Trademark infringement occurs when another producer uses your mark, or a mark “confusingly similar” to yours, to sell goods and services that are not your own, thereby confusing consumers regarding the source of the goods or services. This can happen willfully or innocently.

Not only is trademark infringement illegal, it can threaten your claim to the trademark if too many people begin to capitalize on your mark and consumer goodwill. As the trademark owner, it is your responsibility to police your trademark and bring enforcement actions against any potential infringers lest you surrender your trademark rights. In two famous cases, Pepto-Bismol lost its claim to its distinctive pink coloring to other antacid producers but Christian Louboutin preserved its rights to its trademark red lacquered bottom shoes, with a key difference being whether the owners actively policed their trademark rights.

An easy way to keep track of your trademark is to set up Google Alerts™ notifications for your mark so that you will be notified any time your trademark is used online. You can also keep a close eye on the USPTO’s weekly publication, the Trademark Official Gazette, for trademark applications under consideration and oppose any published mark within 30 days if you believe the applied-for mark’s registration would infringe on your trademark.

If Trademark Official Gazette is not on your “must-read” list or this process seems too meticulous for one person, consider using a service that patrols your mark that will catch and resolve any potential infringement before substantial damage occurs. Third-party trademark watch services monitor potential infringement across multiple platforms, including the USPTO database, foreign trademark databases, and the Internet and social media sites. A monitoring service takes the pressure off the mark owner and allows an experienced trademark team to patrol your mark on your behalf.

With Great Power Comes Great Responsibility

The mere fact that a mark is protected by law does not magically prevent infringement. Trademark protection only works if it is properly enforced. As the proud owner of a trademark, you must decide how much money you are willing to spend on enforcing the mark and protecting your brand.

One way to deter infringers is to send a cease-and-desist letter asserting ownership rights and demanding the infringing use stops immediately or else risk a lawsuit. A cease-and-desist does not initiate a lawsuit, though it may scare the infringer into believing the owner is prepared to sue, which can be a cost-effective route to stop the infringing use.

Of course, you can also bring a lawsuit for trademark infringement and unfair competition, which if you win, may result a legal order instructing the infringement to stop (an injunction) and/or monetary damages for brand damage and lost sales or the infringer’s profits. However, litigation can be costly and time consuming and creates a financial burden for the plaintiff that might last months or years before settlement or adjudication. See Lex Machina’s Trademark Litigation Report 2016 for an insightful analysis of litigation trends from 2009 to 2016, including leading parties, causes of action, remedies, judgments, and damages.

However, you might not want to take any action against the potential infringer if, for example, you don’t believe the infringement threatens your market share or your goods or services. Recall though that failing to police your trademark against infringements may result in loss of your trademark rights by dilution.

Conclusion

Effective trademark protection starts at the very beginning and continues through the mark’s commercial use. A strong and distinctive trademark that leads consumers to associate a brand with its mark is easier to protect than one that is too generic or descriptive. When infringers take advantage of the goodwill built up around your brand, consider your legal options to enforce your trademark rights, and protect your mark. However, the best offense is a great defense, so consider using a trademark monitoring service to catch potentially damaging infringement before it tarnishes your mark.