“Magic Words” Protect Software Developer’s Copyright

Kendra Rosenberg

SEATTLE — In Vernor v. Autodesk, a three-judge panel on the Ninth Circuit recently held that customers purchasing second-hand computer software are licensees–not owners–and therefore cannot invoke “first sale doctrine” or “essential step” affirmative defenses to copyright infringement lawsuits. This means a purchaser of second-hand software will not be able to resell the software if the “magic words” of a three-part test appear in the software use agreement.

Timothy Vernor purchased copies of Autodesk Inc.’s AutoCAD Release 14 software–with handwritten activation codes–at an office sale by Cardwell/Thomas & Associates, Inc. (“CTA”).  Vernor then tried to sell the software on eBay.  Autodesk filed a Digital Millennium Copyright Act (“DMCA”) take-down notice claiming Vernor’s sale infringed on its copyright.  eBay initially removed Vernor’s auction, but reinstated it after Vernor filed a counter-notice contesting Autodesk’s copyright claim.

Vernor sought a declaratory judgment that the “first sale” doctrine protected his resale of the software and therefore did not infringe on Autodesk’s copyright. The first sale doctrine is an affirmative defense to copyright infringement that permits owners of copyrighted work to resell those copies. The doctrine allows book owners, for example, to sell their used books to others. A first sale affirmative defense requires showing (1) a legal purchase, (2) of copyrighted material, (3) which the seller had the right to resell without restriction by the copyright owner.  17 U.S.C. § 109. The defense is only available to owners–not licensees–of software.

Venor also raised the “essential step” affirmative defense. Under this defense, if copying software is necessary (“essential step”) to using the software (such as temporarily loading software during installation), such copying is not infringement. Again, this affirmative defense is only available to an owner of copyrighted software. 17 U.S.C. § 117(a)(1).

The software at issue in Vernor was provided on a CD-ROM accompanied by a Software License Agreement (“SLA”).  The SLA granted customers a nonexclusive and nontransferable license to use Release 14, imposed transfer and use restrictions, and required destruction of older software copies if the customer received an upgrade. The issue was whether CTA was an owner of the software under this SLA–and therefore able to pass title to Vernor–or merely a licensee.

The district court initially found Vernor’s sales were non-infringing under the first sale doctrine and the essential step defense because Venor purchased the software from an end-user, granting him indefinite possession, regardless of the restricting language in the SLA.  Because Vernor retained indefinite possession, the first sale doctrine permitted him to freely resale the software.

The Ninth Circuit, however, devised a new three-part test and reversed because the SLA: (1) specifically authorized only one license; (2) significantly restricted the user’s ability to transfer the software; and (3) imposed notable use restrictions:

CTA was a licensee rather than an ‘owner of a particular copy’ of Release 14, and it was not entitled to resell its Release 14 copies to Vernor under the first sale doctrine. 17 U.S.C. § 109(a). Therefore, Vernor did not receive title to the copies from CTA and accordingly could not pass ownership on to others. Both CTA’s and Vernor’s sales infringed Autodesk’s exclusive right to distribute copies of its work. . . .

In other words, the court used a three-prong test to determine that Autodesk retained title under the SLA and CTA was therefore a licensee–rather than owner–of the Release 14 copies. As such, CTA did not grant title to Vernor so Vernor could not pass ownership to others. In fact, anyone who purchased Venor’s software on eBay and installed it would be violating Autodesk’s copyright and also unable to invoke the first sale doctrine or essential step defense.

In 2009, Thomas A. Hackett, in a Shidler Journal of Law, Commerce + Technology (now the Washington Journal of Law, Technology & Arts) article analyzing the district court’s decision, approached the issues in a similar manner to that of the Ninth Circuit: “Vernor v. Autodesk may be a last stand of sorts for the first sale doctrine with software sales as digital media is increasingly sold via downloads.” Hackett observed that the district court provided a fresh approach to the transfer of software, but concluded that the practical realities of software downloading would likely give way to the position the Ninth Circuit ultimately adopted.

Following the Ninth Circuit’s decision, it appears software makers can protect their copyrighted material by drafting SLA provisions that comply with Vernor’s three-prong test and specifically authorize users to only one license and prohibit the transfer of licenses. Software makers may grant a nonexclusive and nontransferable license with transfer and use restrictions to protect their copyright.

The Ninth Circuit has two similar cases pending, UMG v. Augusto and MDY v. Blizzard, which both involve transfer of copyrighted materials. These cases will decide whether transactions involving copyrighted works including books, music, and movies, are also subject to Vernor’s three-prong test for whether someone is an owner or licensee.

Washington Journal of Law, Technology & Arts Publishes Autumn Edition

Logo

SEATTLE—Today the University of Washington School of Law published the Autumn 2010 issue of the new Washington Journal of Law, Technology & Arts, the nation’s first student-run electronic law journal focusing on technology, commerce, and artistic innovation.

The Washington Journal of Law, Technology & Arts publishes concise legal analysis aimed at practicing attorneys. The Journal publishes on a quarterly basis. This quarter’s edition includes five articles on topics such as:

  • How to avoiding declaratory judgments in patent disputes
  • New Securities and Exchange Act liability for “hacking and trading”
  • Avoiding liability for content published by third-parties on websites
  • Workplace GPS surveillance
  • New restrictions on anti-spam lawsuits

The Journal is the nation’s first technology and law journal that also publishes articles involving the arts. The new Journal plays a key role in furthering the University of Washington School of Law’s reputation as a center of innovation and path-breaking legal research.
The Journal replaced the Shidler Journal of Law, Commerce + Technology in 2009 as part of a merger with the Law, Technology & Arts Group (LTA), a research group at the law school.  LTA was formed to take a comprehensive approach to legal issues involved in artistic and technological innovation.  LTA consolidated the J.D. and LL.M. programs, the former Shidler Center for Law, Commerce + Technology, and the Center for Advanced Research in Intellectual Property (CASRIP) into a single research unit covering the full scope of these areas.

The Journal accepts outside submissions from students, law professors, and practicing attorneys. For more information about the Washington Journal of Law, Technology & Arts please visit their new website.

A link to download the entire Autumn 2010 issue of the Washington Journal of Law, Technology & Arts is available here.

Washington Supreme Court Cites LTA Journal in Landmark Metadata Opinion

Gareth S. Lacy

OLYMPIA — In an opinion holding that metadata is an electronic version of a record subject to disclosure under the state Public Records Act (PRA), the Washington Supreme Court today cited Jembaa N. Cole’s article, When Invisible Electronic Ink Leaves Red Faces: Tactical, Legal and Ethical Consequences of the Failure to Remove Metadata, published in the Shidler Journal of Law, Commerce + Technology in 2005. The court’s landmark decision, O’Neill v. City Of Shoreline, is now the second state supreme court opinion holding metadata subject to state public disclosure law. In 2009, the Arizona Supreme Court ruled similarly in Lake v. City of Phoenix.

Credit: Zina Deretsky, National Science Foundation

The controversy arose after a private citizen sent a “blind carbon copy” e-mail to various local government officials including the deputy mayor and a city council member. Later, Beth O’Neill, a member of the public, requested a copy of that email. So the deputy mayor removed the “To” and “From” information from the email and forwarded the message. O’Neill then filed a written PRA request for “all information relating to the e-mail, including how it was received . . .  from whom it was received, and the forwarding chain of the e-mail.” The city attorney released a print-out of the e-mail. O’Neill then requested all metadata pertaining to the e-mail chain. O’Neill sued the city under the PRA after the city failed to provide the metadata.

At issue in the case was whether e-mail metadata is a public record that must be disclosed under the PRA. The Washington Supreme Court held metadata is a “public record” subject to the PRA. Quoting from the PRA, the court noted that “public record is defined very broadly, encompassing virtually any record related to the conduct of government”:

‘Public record’ includes any writing containing information relating to the conduct of government or the performance of any governmental or proprietary function prepared, owned, used, or retained by any  state or local agency regardless of physical form or characteristics. Former RCW 42.56.010 (2005) (codified as former RCW 47.12.020(41) (2005))

The Court favorably cited the Arizona Supreme Court’s holding that “when a public entity maintains a public record in an electronic format, the electronic version of the record, including any embedded metadata, is subject to disclosure under [Arizona’s] public records law.” The Court found this holding particularly persuasive given that Arizona, unlike Washington, has no statute defining “public record.”

On remand, the trial court must give the city an opportunity to inspect the computer’s hard drive to consider whether all public records were properly disclosed. If the City  refuses to inspect the hard drive, they will have indisputably violated the PRA. Furthermore, if the city inspects the hard drive, but cannot find the metadata, the trial court must determine whether deletion of the metadata violated the PRA: “If it is possible for the City to retrieve this information, the PRA requires that it be found and released to the O’Neills.”

This Washington Supreme Court’s decision raises issues concerning what will constitute a sufficient search of the hard drive. The court did not address, for example, whether the city must conduct  data recovery if the files have, in fact, been deleted from the computer. The Arizona Supreme Court’s opinion did not require that computer systems maintain any metadata; it only required disclosure of whatever metadata was present.

Only one other state court has considered the issue of metadata and public records. In Irwin v. Onondaga County Resource Recovery Agency, the Appellate Division of the Supreme Court of New York ruled the trial court erred in denying an order to compel disclosure of metadata associated the disclosure of the metadata associated with unpublished photographs relating to ongoing law enforcement investigations. On appeal, the court amended the judgment to order the production of the metadata. Irwin is useful for describing the three types of metadata: substantive, system, and embedded.

The metadata at issue in Irwin included file names and extensions, sizes, creation dates, and latest modification dates of digitally-stored photographs and was therefore of the “system’s” variety (metadata reflecting automatically generated information about the creation or revision of a document). The court found that such metadata “is at its core the electronic equivalent of notes on a file folder indicating when the documents stored therein were created or filed, [and therefore] constitutes a “record” subject to disclosure under FOIL.”

Other state courts have not addressed the issue of whether metadata constitutes a public record. (Kara Millonzi at Coates’ Canons blog has an excellent analysis of how the law might evolve in North Carolina.) Several useful secondary sources include: Access to Metadata in Public Records, a cover story by Peter S. Kozinets published in the July 2010 issue of  Communications Lawyer; David W. Degnan, Accessing Arizona’s Government: Open Records Requests for Metadata and Other Electronically Stored Information After Lake v. City of Phoenix, 3 Phoenix L. Rev. 69 (2010); Andrea G. Nadel, What are “records” of agency which must be made available under state freedom of information act, 27 A.L.R. 4th 680 (2010); and Scott W. Cockerham, Lake v. City of Phoenix: Is Metadata a Public Record?, 51 Arizona L. Rev. 517 (2009).

In the civil litigation context, Kentucky Speedway, LLC v. NASCAR, Inc. (E.D. Ky.2006) found a presumption that metadata is not subject to disclosure because of the likelihood of its irrelevance. For example metadata will often only identify the typist and not the document’s author or computer from which it was generated. Nevertheless, metadata can be a serious trap for the unwary. Useful advice for businesses seeking to avoid generating metadata is available in Jembaa N. Cole’s 2005 article in the Shidler Journal of Law, Commerce + Technology, When Invisible Electronic Ink Leaves Red Faces: Tactical, Legal and Ethical Consequences of the Failure to Remove Metadata. Cole recommends educating employees, minimizing and reducing metadata, using paper copies, and developing clean document templates.

Jembaa N. Cole is an associate in the Seattle office of K&L Gates LLP. Her practice focuses on corporate and  intellectual property transactions, including mergers and acquisitions and trademark clearance, prosecution, counseling and enforcement. The Washington Journal of Law, Technology & Arts publishes concise legal analysis for practicing attorneys. The Journal began in 2004 as the Shidler Journal of Law, Commerce +Technology. The Shidler Journal was named after Bellingham native Roger Shidler, a founding member of the law firm Shidler McBroom & Gates. In 1990 the Shidler firm merged with Preston, Thorgrimson, Ellis & Holman, which became Preston Gates & Ellis LLP, and then K&L Gates LLP. Today K&L Gates LLP, has approximately 1,800 lawyers across three continents.

“Data Scraping” Does Not Violate the Computer Fraud and Abuse Act if the Data is Publicly Available

ALEXANDRIA — A federal district court in the Eastern District of Virginia recently held that an event planner who “scraped” data about hotels, restaurants, bars, and meeting rooms from a publicly available Web site did not violate the Computer Fraud and Abuse Act (CFAA).

The plaintiff in Cvent, Inc. v. Eventbrite, Inc., 2010 U.S. Dist. LEXIS 96354 (E.D. Va. Sept. 14, 2010) operated a Web site that assisted customers in locating venues for organizing large-scale events. The Web site contained a massive database that listed detailed information about venues all over the world, including the availability, capacity, and amenities of meeting rooms in various cities. Defendant Eventbrite offered event planning services through its Web site and set out to create a similar “Venue Directory” that would contain information about hotels, restaurants, bars, and meeting rooms.

Rather than aggregate this data on its own, however, Eventbrite hired a computer engineer to “scrape” the data from Cvent’s online database. “Data scraping” is a technique in which an automated program scans and copies information that was intended for human viewing. The legal issue was whether data scraping violates laws prohibiting the unauthorized access of data from protected computers.

Credit: NIST

Cvent argued that Eventbrite’s scraping violated section 1030(a)(2) of the CFAA, which prohibits accessing a protected computer without authorization—or exceeding authorized access—in order to obtain information. In dismissing this claim, the court noted the distinction between unauthorized use of data and unauthorized access to data. Only unauthorized access constitutes a violation of the CFAA. Cvent’s database, however, was publicly available on its Web site and could be accessed without any password or login information. In the court’s words, “the entire world was given unimpeded access” to Cvent’s database and Eventbrite had therefore not violated the CFAA when it scraped that information.

Cvent argued unsuccessfully that it had, in fact, limited Eventbrite’s access by virtue of a “browsewrap” agreement containing its Terms of Use, which stated that “No competitors or future competitors are permitted to access our site or information, and any such access… is unauthorized.” The court noted, however, that despite this language, Cvent took no “affirmative steps” to prevent competitors from accessing its database. Because the browsewrap agreement was not prominently displayed, and could only be discovered by following a series of links, no reasonable user could be expected to notice it.

Cvent, Inc. v. Eventbrite, Inc. stands in contrast to Snap-On Business Solutions Inc. v. O’Neil & Associates, Inc., 2010 U.S. Dist. LEXIS 37688 (N.D. Ohio Apr. 16, 2010), another data scraping case decided last spring in which the court refused to grant the defendant summary judgment on the plaintiff’s CFAA claims. There, the information on the targeted Web site had been password-protected and the log-in screen alerted visitors that their use of the site was governed by an End User License Agreement, which users could link to directly. Because of these features, the court concluded that a genuine issue of fact existed as to the scope of authorization and the existence of a contract.

These cases offer important lessons for Web site operators concerned about data scraping. As Cvent demonstrates, the operators of targeted Web sites may be without recourse under the CFAA if the information was made publicly available. However, the Snap-On case provides examples of measures that Web site operators can take to protect themselves.

Federal Circuit Extends the Scope of the Secret Prior Art

When patent examiners examine patent applications, they will look at whether there exists certain prior art in related field to decide whether the patent application is novel.  Novelty is one of the requirements a patent application must meet in order to become a valid patent.  It is important for practitioners to understand the standard for determining a legitimate prior art, in order to evaluate the chances of winning a patent infringement dispute.

A recent Federal Circuit case, In re Giacomini, 2010 U.S. App. LEXIS 13804 (Fed. Cir. July 7, 2010), extended the scope of the secret prior art defined in 35 U.S.C. 102 (e).  A secret prior art means a prior art filed before but published after the subject patent application is filed.  Under the decision, a US patent or published application will be considered prior art as of the filing date of its qualifying provisional application.  In this case, the Federal Circuit held that, agreeing with USPTO’s position, when a provisional application is used as a prior art, the filing date is the 102(e) priority date, rather than the actual filing date of the later formal application.

35 U.S.C. 102(e)(2), bars the patentability if the invention was described in a patent granted on an application for patent by another filed in the United States before the invention by the applicant for patent.  Giacomini’s patent application was first filed on Nov. 29, 2000 and the USPTO examiner found a prior art, U.S. patent 7,039,683 (the “Tran Patent”), against Giacomini’s patent application.   The Tran Patent was filed in December 2000 (after Giacomini) and issued in 2006. However, the USPTO asserted that the patent should be considered as a 102(e) prior art because it claims priority to a U.S. provisional application that was filed in September 2000.

In a prior case, In re Klesper, 397 F.2d 882 (C.C.P.A. 1968), the United States Court of Customs and Patent Appeals (CCPA, the  Federal Circuit’s predecessor court) held that the 102(e) follows the prior precedent of treating a prior art disclosure found in an issued patent as being disclosed as of the “filing date of the earliest U.S. application to which the patent is entitled, provided the disclosure was contained in substance in the said earliest application.”  The Federal Circuit agreed that this provision applies equally to provisional patent applications.  Thus, the Tran Patent shall have the same patent-defeating effect as to the claimed invention as though it was filed on the date of the Tran Patent’s provisional application.

Patent practitioners should be aware of this current development while conducting their prior art search.  Provisional applications could be another source of legitimate prior arts, and should not be overlooked.