Showing posts with label trade secrets. Show all posts
Showing posts with label trade secrets. Show all posts

Tuesday, July 31, 2012

The Computer Fraud and Abuse Act and Employee Data Theft

When Congress enacted the Computer Fraud and Abuse Act in 1986, a number of us believed that employers had a powerful tool to deal with employees improperly removing key company information from electronic data storage systems for the employee's benefit. The statute, which has both civil and criminal components, makes a person liable for damages if they intentionally access a computer without authorization, or exceed authorized access to a computer, to obtain information from any protected computer; accesses a protected computer without authorization or exceed authorized access to commit fraud; or intentionally access a protected computer without authorization and recklessly cause damage or loss to the computer's owner.


CFAA cases typically arise in one of two circumstances: someone outside the company hacks into the company's servers or databases and either maliciously damages the system, or removes confidential information for use elsewhere, or an employee who has routine access to the system takes information from it to use for the benefit of a competitor, or for the employee's own use, to the detriment of his employer. While the courts have had no trouble finding that the CFAA applies to the first scenario, the courts are split on whether the statute applies to the second.


A recent decision by the Fourth Circuit provides useful guidance on the application of the CFAA to situation where an employee, who is authorized access to employer's computer system, removes proprietary information from it, shortly before he leaves the company to join a competing business. In this case, a project director for a company providing specialized welding and related services to the power generation industry was accused of systematically removing confidential and trade secret information from his employer's network by sending it via his work computer to his personal e-mail address.

Note to potential data thieves everywhere-in my experience, it is virtually impossible for the average employee to remove information from a company server in electronic form without detection. And every one of my clients performs an immediate review of all the activity on a manager's information technology account, following an abrupt and unanticipated departure.

There are two schools of thought with respect to CFAA application to this kind of situation. The first school, which is in session here in the Seventh Circuit, is that an employee who removes information from an employer's computer system, in breach of his fiduciary duty to the employer (as in our example case), cannot say that she is authorized to do so, and is therefore in violation of the statute. I like this approach, because it's logical and makes common sense. After all, no employer would say that an employee who steals its trade secrets is doing so in an authorized manner. The second school of thought takes a more literal reading of the statute, noting that an employee who can access the computer system as part of his job is "authorized", regardless of the purpose for which he does so. This more limited reading of the statute, which was articulated by the Ninth Circuit, is the one that was ultimately adopted by the Fourth Circuit in this case.

A key part of the Fourth Circuit's ruling is that the CFAA is a criminal statute, as well as a civil one. Criminal statutes are usually read very narrowly, in order to provide as much notice to the public as to what conduct is actually prohibited. The court noted that a broad reading of what is "authorized" access would theoretically criminalize conduct by any employee that was not specifically okayed by an employer. Visits to Facebook, shopping sites, personal banking sites, etc., would become criminal violations because they were not specifically authorized by an employer's policy. The court also noted that it was not necessary to find an expansive scope for the CFAA because there were numerous other state law causes of action, e.g., theft of trade secrets, breach of fiduciary duty, etc., that would encompass and protect the employer's data in this type of situation.

In short, the CFAA is not a cure-all for employee data theft. My personal opinion is that the Fourth Circuit's read on this is likely to be more persuasive with the federal district courts that confront the situation. Accordingly, companies should look to more traditional means of protecting their data under trade secret, fiduciary duty, confidentiality, and other doctrines.

Wednesday, May 2, 2012

The Illinois Trade Secrets Act Is for Trade Secrets


A recent decision by an Illinois federal court provides useful guidance on the scope and preemptive effect of the Illinois Trade Secrets Act.  The case involves a claim by a supplier that Caterpillar misappropriated both trade secret and non-trade secret confidential information as a result of the transaction between the supplier and Caterpillar. Specifically, the supplier alleges that Caterpillar used its proprietary information to design its own versions of the supplier’s product in order to avoid dealing with the supplier in the future.

The supplier brought suit, alleging a breach of the Illinois Trade Secrets Act, unjust enrichment, and fraudulent inducement, resulting from Caterpillar’s supposed promises to provide significant business to the supplier in the future, in exchange for proprietary information today.

Caterpillar attempted to refine the issues in dispute by alleging that fraudulent inducement and unjust enrichment as causes of action were preempted by the Illinois Trade Secrets Act, which prohibits the wrongful appropriation of certain types of information. A quick refresher:  “trade secrets” are pieces of information that have economic value as result of their not being generally known to the public, and that are subject to reasonable efforts to maintain their secrecy / confidentiality.  Caterpillar was arguing that these other legal theories, which in some cases are more difficult to defend than a Trade Secrets Act claim, were improperly before the court because the Trade Secrets Act covers all that conduct.

There are other types of confidential corporate information that can be protected from disclosure, even though they do not technically comprise a trade secret. Certain business practices, processes, forms, etc., can be considered proprietary, even though their economic value, by themselves, is virtually nil.  The supplier in this case attempted to hedge its bet slightly with respect to whether certain information was a formal “trade secret” by alleging unjust enrichment and fraudulent inducement, which the supplier argued was not covered by the Trade Secrets Act at all.

After some gratuitous beating of the participants about the head and shoulders for not properly characterizing their filings before the Court (I consider the judge in this particular case to be a true expert on the federal Rules of Civil Procedure; his opinions ought to be mandatory reading in every law school in the country), the judge determined that the preemptive scope of the Trade Secrets Act was limited to trade secrets. While the Illinois Supreme Court had not opined on this state law issue, the federal judge looked directly to the language of the statute and determined that there was no preemption for claims based on information that did not qualify as a trade secret.

The decision here is quite useful (it’s also highly entertaining reading, for an intellectual property decision). Companies seeking to protect their intellectual property are not foreclosed from using the full range of business torts available to them, even if the information involved does not fit the formal definition of a trade secret.

Friday, January 13, 2012

The Latest Social Media Issue for Employers: Who Owns a Twitter Account?


There's a particularly interesting case percolating in federal court in the Northern District of California, where an employer is suing a former employee over the content and value of a Twitter account.

The company, going by the unlikely moniker of "Phonedog", is in the business of reviewing wireless and mobile electronic products and services and provides users with resources needed to shop for mobile carriers. The former employee worked as a product reviewer and video blogger and used a Twitter account with the Phonedog moniker, via which he transmitted his reviews and other content. The account was accessed through a password, and disseminated information to promote Phonedog services. This particular former employee was apparently adept at his job and his Twitter account had approximately 17,000 followers at the time he resigned. Following his resignation, the former employee switched the account handle to his own name, and begin using the account to promote another company, TechnoBuffalo.

I can only hope that Phonedog impleads TechnoBuffalo into the case, just for the name.

Phonedog sued the former employee for theft of trade secrets and interference with business relationships. In a recent decision, the court allowed the case to go forward, but what's particularly noteworthy are the issues that the court will be resolving through the course of the litigation. Issues such as: who owns a Twitter account? The short answer is that Twitter does, but is there a property interest when a company licenses an account from Twitter that is then used exclusively by an employee in the pursuit of his duties? And who actually owns the Twitter followers? Or, more appropriately, who has an economic right to continued access to those Twitter followers? The company, of course, argues that the list of followers is akin to a business customer list, but since these people aren't buying anything from the company (Phonedog derives its income from the advertising that it sells based on the number of people that use its site for mobile carrier reviews), does the customer analogy apply? And finally, what's the appropriate measure of damages for loss of such a Twitter account? Is it the loss of advertising, or is it possible to fix a definitive monetary number based on each follower of the account over a set period of time? How far into the future do you have to project that these followers would stay with the account, and can you project increases with enough particularly and reliability?

I'll provide updates on the litigation as I get them.  As the definition of economic activity expands through social media, this case may be a bellwether.  At the very least, it raises some compelling legal questions.

And here's another SM decision involving LinkedIn--similar issues.