Share


Share

Share it !



share/bookmark
Showing posts with label Legal. Show all posts
Showing posts with label Legal. Show all posts

Cloud Computing - The Legal Issues Are Somewhat Cloudy in the Cloud


"Cloud computing" has become a very hot topic. For the uninitiated, "cloud computing" generally refers to providing access to computer software through an Internet browser, with the software and data stored at a remote location at a "data center" or "server farm," instead of on the computer's hard drive or on a server located on the user's premises. This is also referred to "software as a service."

Proponents of this approach claim many benefits, including lower costs, less need for on-site support and "scalability." "Scalability" means that the number of licenses and available resources can easily be adjusted as the need increases. Access can typically be provided to any computer with a browser and an Internet connection, but can be controlled through password protection and other measures. Proponents also argue that the cloud makes it easier to manage and push down software upgrades. Software as a service is usually provided on a fee for service approach that may result in cost savings compared to the traditional local area network. Think of it as somewhat like renting as opposed to owning.

Cloud computing is not a technology of the future, but is here today. Google, for example, uses this approach to provide its suite of business applications intended to compete with Microsoft Office. Google applications are provided free or at very little cost. Salesforce.com is one of the best known providers, providing customer relationship management ("CRM") software to a growing list of companies. IBM and Microsoft are also entering the playing field.

There appears to be little doubt that cloud computing is here to stay, and that it may indeed represent the future of information technology. There are many advantages and potential advantages to the cloud computing model.

That said, from a legal perspective, cloud computing raises a host of issues. Having spoken recently to several cloud computing vendors, there are some rather obvious questions. Perhaps the most obvious question is, "What happens if you lose my data?" The answers I was provided focused on technical and not legal issues, such as the back-up procedures provided.

Technical issues are important, and there are certainly technical issues that a potential customer may want to consider, such as maintaining a back-up on site, or a back-up through a separate vendor. These approaches might provide some real practical protection in the event of a catastrophic failure or bankruptcy at the primary provider. Other technical issues might focus on what happens when the relationship ends, whether happily or not. Is there another vendor that can provide the software and host the data? Will data have to be converted to a different format? If the customer decides to switch back to a local area network, will the terminals that have been used for cloud computing (which, I am told, can be very basic "low powered" machines) be of any use, or will a completely new network need to be installed?

Although technical solutions are a good thing, over twenty-five years of litigation experience have taught me that disasters do happen, even with fail-safe plans in place, and even with parties acting in complete good faith. And, I suppose, it is natural for a lawyer to focus on legal rights and remedies rather than technical solutions.

From a legal standpoint, cloud computing appears to raise a host of essentially contractual issues to be addressed by the parties' contract or licensing arrangements. There are also potential regulatory issues (ranging from privacy to export control issues), potential e-discovery issues, and certainly other issues that have not yet crossed my mind.

As businesses and their lawyers become more experienced with cloud computing issues, it is likely that a consensus will emerge as to how cloud computing issues will be addressed. Hopefully, purveyors of cloud computing services will be flexible and reasonable in addressing legitimate business concerns. However, given the prevalence of "standard" licensing in the software field (often on a shrinkwrap or clickwrap basis) and efforts to limit liability under any circumstances, there is some cause for pessimism.

All that said, here is a list of issues that one might wish to consider asking a vendor or otherwise considering in entering into a possible cloud computing arrangement:


What contractual obligation will you assume to protect my data? This could include reference to particular steps and procedures, including back-up obligations. The contract or license may specify a standard of care that the provider must meet.
What contractual obligation will you assume regarding uptime, if any? Will you provide any type of uptime warranty? Even if such a warranty is subject to a limited remedy, it probably would provide considerable incentive for the provider to limit downtime.
Most providers seem savvy enough to disclaim any interest in your data and will freely say -- in a sales setting anyway -- that "your data is your data." Well, that's good, but how do I physically get my data back at the end of the contract or if you go bankrupt?
What remedy limitations, if any, are in your terms? Are consequential damages excluded? Are total damages capped (such as to a return of fees paid)? Even if contractual obligations are assumed, if remedies are severely limited, the provider may be shielded from liability.
Where is my data going to be stored? Are you willing to agree that all my data will be kept in this location under specified conditions and at agreed security levels? This could be important for regulatory reasons, but also for reasons associated with meeting general customer confidentiality obligations or complying with privacy policies.
Have you inserted a forum selection clause into the terms? Many providers want to insist on litigating on their home turf (which often, it seems, is California), but that is rarely a happy instance for a customer.
How do I get out of this arrangement if you do not perform and what is my exit strategy? What rights do I have upon termination? What obligations do you have to assist in transitioning to a new vendor or back to a self-managed platform?

If you are considering going to the cloud, you should consider involving your business and technology lawyer early in the process. As stated, there are probably many other legal issues that have not even occurred to me. It is clear, however, that lawyers need to begin considering these issues, because cloud computing is clearly not going away.




John L. Watkins is a Shareholder of Chorey, Taylor & Feil, a Professional Corporation, a business litigation and business law firm in Atlanta. John has been a commercial litigator for over 25 years, and has handled a wide variety of cases. Currently, John's litigation practices concentrates on trade secret (including computer data misappropration), insurance coverage, corporate, shareholder, and commercial contract matters. Joh also negotiates and drafts sales contracts, non-disclosure agreements, and other business documents. John represents domestic and international companies or their U.S. subsidiaries. He has spoken frequently at public and private domestic and international seminars on various legal topics.

John graduated first in his class at the University of Georgia law school in 1982. He was named to the list of Georgia Super Lawyers in Business Litigation by Atlanta Magazine and the Journal of Law and Politicis. John is rated AV by the Martindale-Hubbell Law Directory, its highest rating, and 10.0 by the AVVO website, its highest rating. More information can be found at the firm's website, http://ctflegal.com, or its podcast page, http://ctflegal.blip.tv




Computer Forensics and Legal Aspects


The rate of crimes on internet and networks is increased to an alarming state by hackers, contractors, intruders and employees. Laws are enforced and computer forensics is practiced to avoid and prevent these crimes. Using computer forensics investigators use latest techniques of science and technology to find some evidence against crimes. The evidence will be collected for legal purposes when criminal matters are dealt. Investigation by using latest techniques of science and technology along with computer sciences to collect evidence in criminal and civil courts is called computer forensics. Experts use advanced tools to recover deleted, corrupted or damaged files from hard discs, flash drives and other storage media. A complete examination of windows registry, drives, cookies, deleted files, emails and all other relevant locations is done to find any clue to prosecute the case in law courts.

The first step in collecting evidence is to obtain warrant to search the suspected system. This warrant includes not only seizing and investigating the suspected computer but any devices connected with the crime are also included in it. A printer, scanner or any other device may be used with computer in making crime so these devices are also seized for investigation. Person who examines the computer system is not only an IT expert but a detective. He detects clues to find out the story or details of the crime. The main aim of an investigator or expert is to find out evidence not the culprit. Using computer forensics large amounts of money are recovered by following the law suits in civil and criminal courts.

Computer forensics specialist revealed frauds, crimes and corruptions in insurance companies, criminal prosecutors, large corporations and law enforcement office. The standards, methods and laws of computer forensics are different in different countries. Some evidence is acceptable in some countries but not in others while dealing with crimes at international levels. There is no boundary of internet so it is a problem while investigating and collecting evidences because different countries have different laws.

Personnel, Network administrators and security staff should have knowledge about computer forensics and its legal aspects. An expert should have authority to monitor and collect evidence related to intrusions and computer crimes. The use of security tools should be legal and according to the policies of the company and rules of the country. Computer forensics is a new discipline so the use of existing laws is instable while prosecuting computer crimes. Website of United States Department of Justice's Cyber Crime is the reliable source of information and rules to apply it. Standards of computer forensics and list of recent cases which are in proceeding are given on the website. Evidences are collected in a way which is accepted by the court. Laws are being approved in the favor of personal data security in organizations.

Organizations have to prove that they have applied necessary securities. So when data is theft or affected then there will not be any lawsuit on the company if proper security applications and policies are installed and implemented.

Computer security law has three areas which one should know. First is in United States Constitution; it protects against unreasonable search, attacks and self-incrimination. These were written before problems occurred but tell how to practice them.

In the second area anyone practicing computer forensics should know the effect of three U.S. Statutory laws.

Wiretap Act

Pen Registers and Trap and Trace Devices Statute

Stored Wired and Electronic Communication Act

During the practice of computer forensics violations of any one of the above statutes lead to fine or imprisonment. If a company feels any doubt about that it has committed mistake it should consult with its attorney.

In third area U.S. Federal rules about computer crimes must be understood. There are two areas which affect cyber crimes

1. Authority to collect and monitor data

2. Admissibility of collection methods

If network or system administrators know about the legal and technical complexities of computer forensics or they are able to preserve critical data of the organization then it would be an asset of the organization.




Radha Kishan is currently advertising for a computer forensics provider company whose website is www.cyberevidence.com




Instant Messaging Legal Issues - Five Legal Concerns With Instant Messaging


1. Internet messaging legal issue: Defamation - If you publish defamatory statements via internet messages you may face legal issues for civil defamation, and in some countries criminal liability. Defamation is a tort, or legal wrong. It is a general term which is used globally, but in some countries can be divided into two categories, libel and slander. Australia has abolished the distinction between libel and slander. A defamatory statement is one which lowers a person's reputation in the minds of right thinking members of society generally, or causes them to be shunned or avoided.

Libel refers to defamation by writing, images, broadcast or published works, and tends to be in a permanent form, although in England defamatory statements made in theatre are treated as a form of libel. Slander refers to defamation which occurs through speech, sounds, sign language, or gestures; generally communications of a more transient or ephemeral nature. It isn't always a simple task to assess whether a communication falls into the category of libel or slander. However there is an important legal distinction between libel and slander where the distinction remains. Libel is legally actionable without the need to prove damages, whereas slander requires that the person who is slandered prove special damage to succeed in an action.

There are four exceptions to the above rule in relation to slander where a person can sue if they have been slandered without proving they have suffered damage. The first is where statements have been published accusing a person of committing a crime which can result in imprisonment. The second situation is where statements have been made that a person has a serious contagious disease. The other two categories include suggesting a person is unable to carry out their trade or business or making statements that they are sexually unchaste.

The victim in the above cases of slander only needs to prove a statement has been published. In Commonwealth countries publication of a defamatory statement takes place where the statement is first perceived by a third party. This means that over the internet you can expose yourself potentially to any jurisdiction's laws of defamation and the person who has been defamed can try to sue you in their country's courts. Whether they can actually do so depends on several factors.

When engaging in instant messaging it is easy to forget that you could face legal issues if you commit defamation. The victim only needs to show your internet message was published to a third party for you to encounter legal issues if the statement was defamatory or falls into one of the categories above. If the victim were by themselves at the time the statement was received, this would not give rise to legal issues, however if a third party was present when the instant message was transmitted, you could face potential liability for defamation.

Instant messages are similar to other electronic communications like email, posts to forums, bulletin boards, usenet groups and websites, although the latter are all sent via a host computer and stored in a tangible permanent medium until altered or deleted. If they are defamatory in nature, they would constitute libel. By contrast, a communication made by instant messaging (IM), internet relay chat (IRC) or video messaging would probably constitute slander as the user who has engaged in internet messaging is involved in instantaneous real time synchronous communication, analogous to a phone call. The only difference is that internet messaging technology can now entail the transmission of text, graphics, files, video and/or audio. Such communications being instantaneous and interactive resemble the legal character of telephone communications, although when fixed in a tangible medium as an attachment and exposed to a wider audience, they could also constitute libel.

The user who publishes a slanderous statement through internet messages (IM) may believe there are no legal issues which are different from ordinary email or other use of the internet. However it is likely that the user who publishes a communication via an IM will be creating potential legal issues for slander. It is possible to save a text conversation arising through internet messaging (IM) as messages are logged in a local message history and can be retrieved.

2. Internet Messaging legal issues: Invasion of Privacy - public disclosure of private facts

Even if you send an internet message (IM) that isn't defamatory, you may still face legal issues in some jurisdictions for invasion of privacy or breach of confidence. The legal issues will depend on the laws of the jurisdiction, however if the person you are involved in internet messaging with has a reasonable expectation of privacy and a belief that they are only engaged in instant messaging IM with one person you may face potential legal issues. There is no defence of truth for invasion of privacy. There may be potential legal issues if a victim can establish that they you have engaged in unreasonable disclosure of private facts through your internet messaging (IM).

Instant Messaging (IM) chat transcripts fall within the legal definition of electronically stored information (ESI), and are therefore treated the same way as emails and other electronic records for discovery purposes. Instant messages (IM) are treated the same as e-mails under the discovery laws of most jurisdictions. A user may face legal issues if the records are subpoenaed by the person who alleges an invasion of privacy or other legal wrong, and requests that the third party present give testimony to the effect that they were present when the instant message (IM) was sent. Many people using text or instant messaging wrongly presume if their messages are sent via instant messaging or sent on a mobile phone they are deleted once they have been transmitted. However, most service providers retain a record of text messages and instant messages from one to three months after they are exchanged.

3. Internet Messaging Legal Issues - Cyberharrassment and Stalking

An online Instant Messaging IM user can become a victim of cyber harrassment, stalking, or misuse of telecommunication networks which can constitute a criminal offence. Employers and individuals need to protect themselves from legal issues from instant messaging which is used inappropriately. The same is true of other electronic communications although instant messaging (IM) is possibly more susceptible to misuse involving cyber harrassment, discrimination, online hate speech, bullying and stalking due to it's immediate, informal and intrusive nature. A user needs to know how to protect themselves by reporting a user misusing instant messaging IM technology and knowing how to block them from sending further offensive messages. Just like email those using instant messaging can still try to reach the user by changing screen names. This medium of internet communication allows direct real time communications between employees and corporations without giving much thought to the legal issues which could arise when drafting acceptable use policies for email. These systems are regarded as even more casual in nature than emails which makes them a tool more susceptible to misuse for the purpose of sexual harassment, cyber-bullying and other offensive communications.

The legal issues surrounding use of IM were widely publicised when a former congressman Mark Foley was found to have sent explicitly sexual instant messages (IM) to house pages and persons under 18 from his congressional office personal computer. The scandal led to concern about legal issues and warnings about the legal consequences of inappropriate internet messages. Businesses have a legal responsibility under occupational health and safety workplace laws to provide a safe work environment free of harassment, discrimination and other illegal conduct. An organisation needs instant messaging (IM) management tools to deal with the legal issues posed by use of internet messaging IM in the corporate environment. A survey conducted in 2007 revealed that 30% of participants had been the recipients of inappropriate instant messaging communications.

4. Internet Messaging Legal Issues - Security Risks & Compliance Risks: Instant Messaging (IM) has been described by security consultants as a preferred method for hackers to conduct phishing attacks and circulate attachments with computer viruses. More than 1100 security attacks were registered by the Instant Message Security Centre over a three year period. Viruses, trojans and spyware can quickly propagate through an infected users' internet messaging buddy list. Instant messaging (IM) can lead to wastage of corporate assets, time and resources when abused by employees engaged in social interactions on work time and also through a lack of awareness of the particular security vulnerabilities posed by internet messaging systems. As IM usually occurs using text, it is more vulnerable to eavesdropping, and as user passwords are stored in text, they are accessible to anyone with physical access to the user's computer. It isn't feasible to encrypt the password on many instant messaging software applications. Additionally, instant message software demands that the user open UDP ports to the world, which enhances security threats. The use of Instant messaging (IM) solutions in the workplace gives rise to legal issues in terms of compliance with data security, storage and retention laws. Business communications in most jurisdictions must be archived and able to be retrieved under regulations. Many organisations may not appreciate the legal issues and the requirement to preserve instant messages.

5. Internet Messaging Legal Issues: Leakage of embarrassing information, company intelligence or intellectual property - Security breaches can mean that trade secrets/confidential information and a company's intellectual property is vulnerable to being sent over an insecure network and falling into the hands of a competitor. All kinds of embarrassing and sensitive information can be discovered through IM disclosures. Just like email communications and other electronic records, internet messaging can lead to the discovery of embarrassing corporate secrets and valuable business intelligence, however Employers have been slower to recognise the legal issues associated with instant messaging.

The advent of web 2.0 and social networking sites has created similar legal issues to those associated with IM facilities. It is important that individuals and businesses turn their minds to the unique legal issues and risks posed by this medium of communication in addition to the broader issues associated with the use of electronic data.




Adele Pace - http://www.pacelegal.com.au for more resources on internet law and e-commerce.




Internet Law Compliance an Internet Legal Guide

Internet Law Compliance is the One-Stop-Shop Handbook website operators need to understand and comply with the regulations and requirements for lawfully doing business on the internet. Complete with forms and disclaimers ready to cut and paste.


Check it out!