Showing posts with label Facebook. Show all posts
Showing posts with label Facebook. Show all posts

Friday, May 27, 2011





Facebook Users’ Privacy Claims Dismissed

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law.

The federal district court in San Jose has dismissed claims filed by a putative class of Facebook users who alleged that the social networking website unlawfully transmitted their personal information to third-party advertisers without their consent.

The users’ California Legal Remedies Act (CLRA), Unfair Competition Law (UCL), and unjust enrichment claims were dismissed with prejudice, but the users were granted leave to amend claims alleging that Facebook violated its privacy policy, the federal Wiretap Act and Stored Communications Act (SCA), and the California computer crimes and civil fraud statutes.

The users alleged that, during a four or five month period in early 2010, a redesign of Facebook’s website caused it to transmit to a “referral header” to third-party advertisers when a user clicked on a banner advertisement. The referral header allegedly reported the user ID or username of the user who clicked on an advertisement, as well as information identifying the webpage the user was viewing prior to clicking on the ad.

Federal Wiretap and SCA Claims

The Wiretap Act prohibits electronic communication services providers from divulging the contents of a communication to any person or entity “other than an addressee or intended recipient of such communication.” The SCA provides that an electronic communication service provider “shall not knowingly divulge to any person or entity the contents of a communication while in electronic storage by that service.”

Under both statutes, an electronic communication service provider may divulge the contents of a communication to an addressee or intended recipient of such communication.

The court discerned that the users’ allegations were subject to two interpretations. Under the first view, when a Facebook user clicked on a banner advertisement, that click constituted an electronic communication from the user to Facebook. The contents of the communication were a request for Facebook to send the electronic communication to the advertiser. Under the second interpretation, clicking on an advertisement constituted an electronic communication from the user directly to the advertiser.

According to this interpretation, Facebook served merely as a conduit for transmitting the communication to its intended recipient, the advertiser. Neither scenario would support a violation of the SCA or the Wiretap Act, according to the court.

California Computer Crimes Law

The court also held that the Facebook users failed to state a claim under California’s computer crimes statue. To state a violation under most subsections of Cal. Penal Code §502, a plaintiff must show that the defendant’s actions were taken “without permission.” A defendant may only be subjected to liability for acting “without permission” under §502 if the plaintiff can prove that the defendant “circumvented…technical barriers” that had been put in place to block the defendant’s access to the plaintiff’s website.

The users did not allege that Facebook circumvented technical barriers to gain access to a computer, computer network, or website. To the contrary, they alleged that Facebook caused “nonconsensual transmissions” of their personal information as a consequence of Facebook’s “re-design” of its website.

Facebook could not have acted “without permission” as there were no technical barriers blocking access to its own website. To the extent the users’ §502(c) claims alleged that Facebook acted “without permission,” they were dismissed with prejudice.

The court noted that Cal. Penal Code §502(c)(8) created liability for any person who “knowingly introduces any computer contaminant into any computer, computer system, or computer network.” Unlike the other sections of Cal. Penal Code §502(c), subsection (8) does not require that a defendant act “without permission.” Although the users failed to state a claim under §502(c)(8), they were granted leave to amend their claim.

California CLRA, UCL Claims

To assert an unfair competition claim under the California UCL, a private plaintiff must have “suffered injury in fact and . . . lost money or property as a result of the unfair competition.” A violation of the CLRA can only be alleged by an individual consumer who “purchases or leases any goods or services for personal, family, or household purposes.”

The users did not allege that they lost money as a result of Facebook’s conduct. Nor did they allege that they paid fees for Facebook’s services. The users only alleged that Facebook unlawfully shared their “personally identifiable information” with third-party advertisers.

An alleged loss of personal information did not constitute a loss of “property” that could form the basis for a UCL claim, the court held. With regard to their CLRA claim, the users failed to provide any legal support for their assertion that their personal information constituted a form of “payment” to Facebook for its services.

Breach of Contract Claim

To maintain an action for breach of contract under California law, an aggrieved party is required to show “appreciable and actual damage.” Allegations of nominal damages and speculative harm did not amount to legally cognizable damages. The users’ unsupported conclusory statement that they “suffered injury” as a result of Facebook’s breach of its privacy policy was insufficient.

The court advised the users to allege “specific facts showing appreciable and actual damages in support of their claim.” Because the users alleged the existence of a valid contract with Facebook, they could not maintain a claim for unjust enrichment.

The decision is In re Facebook Privacy Litigation., CCH Guide to Computer Law ¶50,183.

Further information about CCH Guide to Computer Law is available here.

Wednesday, September 22, 2010





Facebook’s Advertising Charges Could Violate California Unfair Competition Law

This posting was written by Jody Coultas, Editor of CCH State Unfair Trade Practices Law.

Social networking website Facebook PPC could be held liable under the California Unfair Competition Law (UCL) for unfair business practices related to a breach of an advertising contract, but not for fraudulent or unlawful business practices, according to the federal district court in San Jose, California.

Sports website Rootzoo entered into an advertising contract with Facebook that allowed Rootzoo to place advertisements on portions of Facebook’s website with embedded links to external sites.

Facebook gives advertisers the choice between two payment structures: “cost per click” or cost per thousand impressions. In selecting the “cost per click” option, Rootzoo specified the maximum amount it was willing to pay for each click and each day.

Each advertising contract contained a disclaimer stating that third parties may generate clicks that could affect the cost of the advertising and that advertisers accept the risk and cannot hold Facebook liable for those fraudulent clicks.

Despite the disclaimer, Rootzoo alleged that Facebook made representations that it would charge for only certain types of clicks and that it had measures in place to ensure advertisers would be charged only for legitimate clicks. Rootzoo filed the UCL claim after Facebook billed for allegedly invalid clicks.

Unlawful, Unfair, Fraudulent Practices

The UCL prohibits unlawful, unfair, and fraudulent business practices and unfair, deceptive, untrue, or misleading advertising. Each prong applies separately in each case and a party need only meet one of the three criteria—unlawful, unfair, or fraudulent—to state a UCL cause of action.

Rootzoo’s UCL claim under the unfair prong could go forward based on the alleged breach of contract, according to the court. Although California courts have found that systematic breaches of contract may state a claim under the unlawful prong of the UCL, the court determined that the issue was better analyzed under the unfairness prong.

Because Rootzoo’s claims based in fraud were too general, they could not be brought under the unfairness prong. However, the claim based on Facebook’s systematic breach of the advertising contract was not subject to Rule 9(b) and was sufficient to withstand the motion to dismiss.

Heightened Pleading Standard

Because Rootzoo could not meet the heightened pleading standard of Federal Rule of Civil Procedure 9(b) that applies to UCL claims under the fraudulent prong, the court dismissed the claim. Rootzoo alleged that Facebook misrepresented how advertisers were billed, misrepresented the methods in place to protect advertisers from paying for invalid clicks, and failed to disclose that it charged for invalid clicks.

Rule 9(b) requires evidence of the time, place, and specific content of the false representations in order to give defendants notice of the particular misconduct at issue. In this case, Rootzoo’s allegations were too general and lacked any evidence of reliance on the alleged misrepresentations. Thus, the claim was dismissed.

The decision, In re Facebook PPC Advertising Litigation, appears at CCH State Unfair Trade Practices Law ¶32,125. It also will appear at CCH Advertising Law Guide ¶63,980 and CCH Guide to Computer Law ¶50,022.

Further details regarding CCH State Unfair Trade Practices Law appear here.

Friday, May 14, 2010





Advertisers Can Pursue Suit Against Facebook for “Invalid Click” Charges

This posting was written by William Zale, Editor of CCH Advertising Law Guide.

Advertisers that entered into “cost per click” arrangements for ads posted on Facebook stated claims that Facebook breached its agreement to charge only for “legitimate clicks” and violated the California Unfair Competition law, the federal district court in San Jose has ruled.

The advertisers’ class action complaint alleged that Facebook charged for “invalid clicks” and “fraudulent clicks” on ads posted on its social networking website.

Disclaimer—Click Fraud

The court agreed with Facebook’s argument that the advertisers failed to state a claim for breach of contract based on fraudulent clicks because the contract expressly waived liability for third-party click fraud.

The contract disclaimer provided that “Facebook shall have no responsibility or liability to me in connection with any third party click fraud or other improper action that may occur.” The term “click fraud” directly followed the disclaimer’s reference to “clicks or other actions affecting the cost of the advertising” that are generated by third parties for “fraudulent or improper purposes.”

Invalid Clicks

However, the advertisers stated a claim for breach of contract at least as to “invalid clicks” resulting from Facebook’s own conduct, the court held.

The advertisers alleged that “invalid clicks” can result from deficiencies in Facebook’s system as a result of “(a) technical problems; (b) system implementation errors; (c) various types of unintentional clicks; (d) incomplete clicks that fail to open the advertiser’s web page; and (e) improperly recorded or unreadable clicks originating in some cases from an invalid proxy server or unknown browser types.”

“Invalid clicks” arguably need not be fraudulent, improper, or the result of the actions of third parties. The language of the contract was reasonably susceptible to this interpretation, the court determined.

Unfair Competition Law

The advertisers had standing to assert California Unfair Competition Law claims, according to the court. The allegation of a systematic breach of contract was sufficient for a claim under the statute predicated on unlawful business practices.

Although the advertisers failed to allege the element of reliance required to pursue a claim based on fraud, they succeeded in stating a claim that they reasonably could not have avoided the injury because of the ambiguities in the disclaimer, the court concluded.

The opinion in Facebook PPC Advertising Litigation will be reported at CCH Advertising Law Guide ¶63,836

Wednesday, October 07, 2009





Facebook Settles Privacy Claims over “Beacon” Ad Program

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Social networking website Facebook has agreed to shut down its controversial “Beacon” advertising program, as part of a settlement of a class action lawsuit brought by Facebook members, alleging that the program violated their privacy rights.

Launched in November 2007, Beacon allegedly caused information about books, movies, and other products purchased by Facebook members on participating sites—such as Blockbuster and eBay—to be posted publicly on Facebook’s “news feed,” without permission.

Facebook members were allegedly “opted in” to Beacon automatically and were not notified of their participation in the program.

Class Action

The complaining members filed suit against Facebook and several participating retailers (including Fandango, Hotwire, and Overstock.com) in August 2008, alleging violations of the Electronic Communications Privacy Act, the Computer Fraud and Abuse Act, the Video Privacy Protection Act, the California Consumer Legal Remedies Act, and the California Computer Crime Law.

Proposed Settlement

Facebook admitted no wrongdoing in the settlement agreement, which was filed with the federal district court in San Jose on September 18, 2009. The agreement includes a provision under which Facebook will contribute $9.5 million to a “settlement fund,” devoted to the formation of a non-profit foundation for the purpose of promoting online privacy, safety, and security.

“We learned a great deal from the Beacon experience,” said Barry Schnitt, Director of Policy Communications for Facebook. “For one, it was underscored how critical it is to provide extensive user control over how information is shared. We also learned how to effectively communicate change that we make to the user experience.”

The settlement is awaiting judicial approval.

The proposed settlement agreement is Lane v. Facebook, Inc., Case No. 5:08-cv-03845-RS, dated September 18, 2009. Text of the agreement will appear at CCH Privacy Law in Marketing ¶60,377.

Thursday, September 10, 2009





Facebook Agrees to Privacy Safeguards After Canadian Investigation

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Online social networking site operator Facebook has agreed to add significant new privacy safeguards and make other changes in response to the Privacy Commissioner of Canada’s recent investigation into Facebook’s privacy policies and practices, the Privacy Commissioner announced on August 27.

On July 16, Privacy Commissioner Jennifer Stoddart issued a report on an in-depth investigation triggered by a complaint from the Canadian Internet Policy and Public Interest Clinic (CCH Privacy Law in Marketing ¶60,350).

Stoddart was particularly concerned about the risks posed by the over-sharing of personal information with third-party developers of Facebook applications, such as games and quizzes.

Facebook was given 30 days to respond to the Commissioner’s report and explain how it would address the outstanding concerns. Following a review of Facebook’s formal response and discussions with company officials, Stoddart said she is now satisfied that Facebook is on the right path to addressing the privacy gaps on its site.

Changes to Privacy Practices

Facebook has agreed to make changes to help users better understand how their personal information will be used and, ultimately, make more informed decisions about how widely to share that information. The Commissioner’s office will follow up with Facebook as the changes are implemented.

With regard to third-party application developers, Facebook has agreed to retrofit its application platform to prevent any application from accessing information until express consent is obtained for each category of a user’s personal information the developer wishes to access.

According to Facebook, implementing the necessary significant technological changes to its application platform will take one year.

Facebook also agreed to make it clear to users that they have the option of deleting their accounts, rather than merely deactivating them. In addition, Facebook agreed to change the wording of in its privacy policy to explain what will happen in the event of a user’s death.

Further information on the agreement is available here on the Privacy Commissioner’s website.

Friday, August 14, 2009





Facebook Not Complying with Canadian Privacy Law: Report

This posting was written by Thomas A. Long, Editor of CCH Privacy Law in Marketing.

In order to comply with Canadian privacy law, popular social networking website operator Facebook must take greater responsibility for the personal information in its care, according to Canadian Privacy Commissioner Jennifer Stoddart.

On July 16, Stoddard released a report detailing the results of an investigation into Facebook’s privacy policies and practices.

The investigation was prompted by a complaint from the Canadian Internet Policy and Public Interest Clinic, a public-interest legal clinic based at the University of Ottawa. Stoddart said that the investigation identified several areas where Facebook needs to better address privacy issues and bring its practices in line with Canadian privacy law.

Privacy Information Confusing or Incomplete

An overarching concern was that information provided by Facebook about its privacy practices was often confusion or incomplete. For example, the “account settings” page described how to deactivate accounts, but not how to delete them, which actually removes personal data from Facebook’s servers.

The Privacy Commissioner’s report recommends more transparency to ensure that the social networking site’s nearly 12 million Canadian users have the information they need to make meaningful decisions about how widely they share personal information.

Access by Third Parties

The investigation also found that Facebook lacks adequate safeguards to effectively restrict third-party application developers from accessing users’ profile information, the investigation found.

The report recommended technological measures to ensure that developers can access only the user information actually required to run a specific application and to prevent the disclosure of personal information of any of the user’s friends who are not themselves sighing up for an application.

Deactivated Accounts

The Privacy Commission also recommended that Facebook change its policy of indefinitely keeping the personal information of people who have deactivated their accounts. According to the report, the practice violates Canada’s federal Personal Information Protection and Electronic Documents Act (PIPEDA). To comply with PIPEDA, Facebook should delete personal information in deactivated accounts after a reasonable length of time.

The Office of the Privacy Commissioner will review after 30 days the actions Facebook takes to comply with the recommendations. The Commissioner is empowered to go to Canadian federal court to seek to have her recommendations enforced.

Text of the Privacy Commissioner’s report appears at CCH Privacy Law in Marketing ¶60,350.

Monday, April 13, 2009





Facebook Obtains Order Barring Phishing, Spamming Scheme

This posting was written by Cheryl Beise, Editor of CCH Guide to Computer Law, and Thomas A. Long, Editor of CCH Privacy Law in Marketing.

Social networking website operator Facebook, Inc. was entitled to an ex parte temporary restraining order against Internet marketers that allegedly used Facebook's website to engage in a phishing and spamming scheme, in violation of the CAN-SPAM Act, the Computer Fraud and Abuse Act, and California law, the federal district court in San Jose has determined. Facebook asserted that the scheme compromised the accounts of a substantial number of Facebook users.

The marketers allegedly sent out seemingly legitimate e-mails to multiple Facebook users, asking them to click on a link, which led to a phishing site designed to trick users into divulging their Facebook login information. The marketers then allegedly used the information to send spam to the users' "friends." As the cycle was repeated, the number of compromised Facebook accounts increased exponentially.

A TRO was warranted because of the strong possibility of irreparable injury to Facebook's reputation and to the personal privacy of Facebook users, the court said.

The balance of hardships clearly favored Facebook because it was required to expend significant time and resources to combat the marketer's activities. The marketers would suffer little or no hardship if enjoined from conducting their allegedly illegal scheme.

The order granting a temporary restraining order is Facebook, Inc. v. Wallace, CCH Guide to Computer Law ¶49,699 and CCH Privacy Law in Marketing ¶60,308.