JUN/JUL 2014 VOLUME 1 1 / NUMBER 3 TODAYSGENER A LCOUNSEL.COM
D R A W Y A W
DATA
CYBERSECURITY MANAGEMENT 2014: A TODAY’S GENERAL COUNSEL SURVEY Best Practices Slow to Take Hold How Metadata Can Affect a Case Complexities of Cross-Border E-Discovery The Challenge of Privileged Content Multi-Matter Repositories are the iTunes of E-Discovery
Mediation, Sins and Strategies Employee Social Media “Ambush Elections” on the Fast Track
Tech-Savvy Paralegals
Metrics to Evaluate Law Firms
Database Collection: IT Department Or Third Party?
Corporate Charging Guidelines and Antitrust
INTELLECTUAL PROPERTY 3D Printed Organs Trade Secrets in the Digital Age Managing Risk In Foreign Patent Filings Good News for Cyber-Squatters
$199 Subscription rate per year ISSN: 2326-5000 View our digital edition: digital.todaysgeneralcounsel.com
M&A in Bermuda and the Cayman Islands SEC’s New Enforcement Options
REDEFINING LEGAL SOLUTIONS. REALIZING A BETTER WAY FOR CORPORATE LEGAL DEPARTMENTS TO WORK.
©2013 ©20 13 Tho Thomso mson n Reut Reuters ers T Thom homson son Re Reute uters rs and th thee Kine Kinesis sis lo logo go are tr trade ademar marks ks of Tho Thomso mson n Reut Reuters ers LL-38 -38730 7303/9 3/9-13 -13
Whether you practice law or manage the legal interests of your organization, legal solutions from Thomson Reuters deliver best-of-class products and services like WestlawNext® and Practical Law™, and secure hosted solutions like Thomson Reuters Concourse™ and Serengeti Tracker®. Intelligently connect your work and your world through unrivaled content, expertise, and technologies. See a better way forward at legalsolutions.thomsonreuters.com/corporate
NEW! Today’s General Counsel Career Center Let TGC help you find your next job. New in-house postings added daily.
Plus, for a limited time TGC is offering employers a complimentary listing. Use code TGCintro when submitting your job listing.
T O D AY S G E N E R A L C O U N S E L . C O M / C A R E E R - C E N T E R
jun/jul 2014 toDay’s gEnEr al counsEl
Editor’s Desk
Biotech and 3D printing aren’t new technologies, but a hybrid called “bioprinting” is. According to an article by Craig Martin and Sara Tonnies Horton, scientists are on the verge of a breakthrough that would enable the manufacture of functional human organs by special 3D printers, which are loaded with “bio-ink” (don’t ask). The question the authors address is whether scientists and the companies they work for will be allowed to patent these organs, even though they faithfully reproduce objects that exist in nature. Naturally occurring biological phenomena are not patent-eligible, according to a recent Supreme Court ruling, but that same ruling upheld a patent on synthetically created DNA. The authors believe the courts, when they consider patent eligibility, will make a distinction between the manufactured object, the process for making it and the substance it is made of. A survey about cybersecurity in this issue reveals some potential litigation problems for corporations. A large majority of respondents never heard of or hadn’t reviewed the recently issued NIST Framework for data protection, which the Commerce Department hopes organizations, regulators and customers will use to create and assess cybersecurity programs. Several experts quoted in the article accompanying the survey expect that the Framework will inevitably become a standard to which defendants are held when lawsuits over data breaches are filed, and they advise getting familiar with it. Editorial Advisory Board member Jeffery Cross discusses the exception the DOJ makes for antitrust violations when it decides whether corporate compliance programs should be a factor in charging decisions. Antitirust is the only area where
2
such programs are not a mitigating consideration, and he wonders why. General Counsel, whose minds reel when they confront the problems created by electronic technology, might consider an article in this issue by paralegals Carol Newman, Kerri Neitzel and Kelli Rangel. They discuss how technology has expanded their responsibilities, noting that communications technologies, especially electronic discovery, have created a new niche for paralegals. On the law firm side, paralegals are now expected to have some expertise in predictive coding, for example. For additional timely artcles and information from TGC and other useful sources, check out our website at http://www.todaysgeneralcounsel.com, and watch for our daily and weekly newsletters in your email box.
Bob Nienhouse, Editor-In-Chief bnienhouse@TodaysGC.com
Join us
on Day One of the ILTA 2014 conference for the inaugural Corporate Law Department and Legal Operations Event. ILTA’S 37TH ANNUAL EDUCATIONAL CONFERENCE
Register for the one day for $500
August 17-21, 2014 at the Gaylord Opryland in Nashville
If you have questions, contact ILTA2014@iltanet.org.
or register for the full ILTA conference at conference.iltanet.org/register.
View the full program at conference.iltanet.org.
Corporate peers will come together to share concerns, hear from experts and develop
ILTA aims to deliver a high-value,
strategies and takeaways for use in their corporations. The day’s events include:
affordable, revolutionary education and networking event for our Law
• The ILTA keynote
Department and Legal Operations
• Private roundtable discussions (one on general issues related to Corporate Law
members in this unique opportunity
Departments and one on e-discovery issues) • A discussion on Security Inside the Law Department • A session on Services and Applications: Jump Start the Vetting Process • A reception with vendors/consultants who provide products and services to the corporate legal community • The ILTA 2014 Conference Exhibit Hall Opening Reception – ILTA’s Vendor Comicon
to share with their peers.
JUN/JUL 2014 TODAY’S GENER AL COUNSEL
Features
56
M&A TRANSACTIONS IN BERMUDA AND THE CAYMAN ISLANDS Tonesan Amissah and Simon Raftopoulos A guideway through a jungle of acronyms.
60
SEC’S NEW, POWERFUL ENFORCEMENT OPTIONS Daniel Patrick Wendt Agency can impose its own sanctions
COLUMNS
50 Visualized Metrics Help Evaluate Law Firms
52 Mediation, Sins and Strategies
Rees Morrison A picture of how outside counsel stack up.
Jaffe D. Dickerson Getting to yes is not the same as winning.
4
Page 60
54 Eliminate the Antitrust Exception to Corporate Charging Guidelines By Jeffery M. Cross Compliance program should be a factor.
“THE EXCHANGE”
THE LE ADING INTER AC TI V E CORPOR ATE E-DISCOVERY PROGR AM SERIES
New York A FFINIA MA NHAT TA N
JULY 16-17, 2014 SPECIAL OFFER FOR TGC RE ADERS: REGIS TER TODAY FOR
FREE
USING CODE T GCMAG100
FREE CA LIFORNIA CLE
TO REGIS T ER V ISIT www.todaysgeneralcounsel.com/institute/chicago Please no e-Discovery personnel allowed unless from one of the sponsoring companies
As in-house counsel you know litigation costs can blossom out of control often driven by e-Discovery. This two-day colloquium will give you the chance to share your experiences and develop solutions, all guided by and drawing on the expertise our panel of expert moderators.
2014 Exchange Program Series Sponsors Included:
Hear what a sampling of past attendees had to say: An educational bonanza for all litigators and those desiring a broader and more in-depth understanding of e-Discovery. –DUK E ENERGY
“An outstanding and highly informative program.” –R AY ASHBURG, SENIOR COUNSEL THE DOW CHEMIC AL COMPANY
“I thoroughly enjoyed this roundtable conference on a topic that is so important to today’s operation of business, learned a lot, met great people, and am looking forward to the next one.”
S T R AT E G I C A L L I A N C E
S T R AT E G I C A L L I A N C E
–DANIEL K IM, CORPOR ATE COUNSEL PMC BANCORP
L E A R N M O R E A B O U T T H E UP C O M IN G
HOUSTON EXCHANGE SEPT 9-10, 2014 www.todaysgeneralcounsel.com/institute/chicago USE C ODE T GC M A G10 0 T O R EGIS T ER FOR F R EE
jun/jul 2014 toDay’s gener al counsel
Departments Editor’s Desk
2
Executive Summaries
9
E-DISCovEry
14 Multi-Matter Repositories are the iTunes of E-Discovery
6
Page 42
Adam Barr Cloud-based solutions to intractable e-discovery problems.
16 The Complex Challenges of CrossBorder E-Discovery Management Daniel Kavan and Eric Robinson Translation slip-ups can invalidate a patent.
18 Tech-Savvy Paralegals Filling Out E-Discovery Ranks Carol Newman, Kerri Neitzel and Kelli Rangel E-discovery means new roles for paralegals.
20 How Metadata Can Affect a Case Tom Turner It’s the ultimate proof in some kinds of litigation.
L abor & EmpLoymEnt
IntELLEC tuaL propErt y
22 Using Predictive Coding to Find Privileged Content Manfred Gabriel and David Sharpe Technology will make it possible to use TAR for privileged documents.
26 Who Should Perform a Database Collection, IT Department or Third Party? Joe Sremack No one knows the system like your own IT department, but sometimes that isn’t enough.
28 Securing Trade Secrets in the Digital Age
34 New Web Domains Raise Risk of Cyber-Squatting
40 NlRB Puts “Ambush Elections” on Fast Track
Pamela Passman Understanding the threat is step one.
Jan Corstens Big U.S. food industry and clothing retailers are having brand infringement problems.
Mark Carter Employers will find it harder to make their case.
30 Managing Risk in Foreign Patent Filings Michael V. Sneddon and Stuart W. Hinckley Filing for multiple foreign patents multiplies litigation risks.
36 Patent Eligibility of 3D Printed Organs Will Soon Be an Issue Craig C. Martin and Sara Tonnies Horton It looks like an ear and acts like an ear but it’s made of bio-ink.
42 Permissible limits on Employee Social Media Lisa E. Aguiar and Julian Pardo de Zela Policies need to be narrowly tailored to avoid NLRA infractions. tGC SurvE yS
44 Cybersecurity Management 2014 Survey shows awareness of standards are lagging.
September 7-9 2014 CANADA
September September September7-9 7-9 7-92014 2014 2014 CANADA CANADA CANADA VANCOUVER CONVENTION CENTER
PHOTOS COURTESY TOURISM VANCOUVER/ALBERT NORMANDIN PHOTOS COURTESY TOURISM VANCOUVER/ALBERT NORMANDIN PHOTOS COURTESY TOURISM VANCOUVER/ALBERT NORMANDIN PHOTOS COURTESY TOURISM VANCOUVER/ALBERT NORMANDIN
VANCOUVER VANCOUVER VANCOUVER CONVENTION CONVENTION CONVENTION CENTER CENTER CENTER
— For details visit — ——For —For For details details details visit visit visit ——— www.ipo.org/AM2014 www.ipo.org/AM2014 www.ipo.org/AM2014 www.ipo.org/AM2014
editor-in-Chief Robert Nienhouse Chief operating offiCer Stephen Lincoln managing editor David Rubenstein
exeCutive editor Bruce Rubenstein
senior viCe president & managing direCtor, today’s general Counsel institute Neil Signore art direCtion & photo illustration MPower Ideation, LLC law firm business development manager Scott Ziegler
business development manager Liz Kenny
database manager Matt Tortora Contributing editors and writers
8
Lisa Aguiar Tonesan Amissah Adam Barr Mark Carter Jan Corstens Jeffery M. Cross Jaffe Dickerson Manfred Gabriel Stuart W. Hinckley Sara Tonnies Horton Daniel Kavan Craig C. Martin Rees Morrison
Kerri Neitzel Carol Newman Julian Pardo de Zela Pamela Passman Kelli Rangel Eric Robinson David Sharpe Michael V. Sneddon Joe Sremack Tom Turner Simon Raftopoulos Daniel Patrick Wendt
editorial advisory board Dennis Block GREENBERG TRAuRiG, LLP
Art Rosenbloom
WiLEy REiN
JOEL HENNiNG & ASSOCiATES
CHARLES RiVER ASSOCiATES
Peter Bulmer JACKSON LEWiS
Sheila Hollis
George Ruttinger
Mark A. Carter
DuANE MORRiS
CROWELL & MORiNG
David Katz
Jonathan S. Sack
DiNSMORE & SHOHL
James Christie BLAKE CASSELS & GRAyDON
Adam Cohen
Steven Kittrell MCGuiREWOODS
Jerome Libin
Jeffery Cross
SuTHERLAND, ASBiLL & BRENNAN
FREEBORN & PETERS
WiLMERHALE
For reprint requests, email rhondab@fosterprinting.com Rhonda Brown, Foster Printing
WACHTELL, LiPTON, ROSEN & KATZ
FTi CONSuLTiNG
Jamie Gorelick
reprints
JONES DAy
Joel Henning
WiNSTON & STRAWN
Subscription rate per year: $199 For subscription requests, email subscriptions@todaysgc.com
Robert Profusek
Thomas Brunner
Thomas Frederick
subsCription
Dale Heist BAKER HOSTETLER
Robert Haig KELLEy DRyE & WARREN
Jean Hanson FRiED FRANK
Robert Heim DECHERT
Timothy Malloy Mc ANDREWS, HELD & MALLOy
Jean McCreary NixON PEABODy
Steven Molo MOLOLAMKEN
Thurston Moore HuNTON & WiLLiAMS
MORViLLO, ABRAMOWiTZ, GRAND, iASON, ANELLO & BOHRER, P.C.
Victor Schwartz SHOOK, HARDy & BACON
Jonathan Schiller BOiES, SCHiLLER & FLExNER
Robert Townsend CRAVATH, SWAiNE & MOORE
David Wingfield WEiRFOuLDS
Robert Zahler PiLLSBuRy WiNTHROP SHAW PiTTMAN
Ron Myrick RONALD MyRiCK & CO, LLC
All rights reserved. No part of this publication may be reproduced or transmitted in any form or by any means, electronic or mechanical, including photocopy, recording, or any information or retrieval system, with out the written permission of the publisher. Articles published in Today’s General Counsel are not to be construed as legal or professional advice, nor unless otherwise stated are they necessarily the views of a writer’s firm or its clients. Today’s General Counsel (ISSN 2326-5000) is published six times per year by Nienhouse Media, Inc., 640 Park Avenue, Hinsdale, IL 60521-4644 Image source: iStockphoto | Printed by Quad Graphics | Copyright © 2014 Nienhouse Media, Inc. Email submissions to editor@todaysgc.com or go to our website www.todaysgeneralcounsel.com for more information. Postmaster: Send address changes to: Today’s General Counsel, 640 Park Avenue, Hinsdale, IL 60521-4644 Periodical postage paid at Hinsdale, Illinois and additional mailing offices.
TODAY’S GENER AL COUNSEL JUN/JUL 2014
Executive Summaries E-DISCOVERY PAGE 14
PAGE 16
PAGE 18
Multi-Matter Repositories Are the iTunes of E-Discovery
The Complex Challenges of Cross-Border E-Discovery Management
Tech-Savvy Paralegals Filling Out E-Discovery Ranks
By Adam Barr Catalyst Repository Systems
Corporations are using “iTunes” to manage e-discovery, but they call it a multimatter repository. The volume of data exploded when people started creating and accessing content through computers and networks, and organizing music collections and burning MP3s onto CDs became a bigger job than most people had time to manage. The entertainment industry responded with iTunes and other multi-media repositories. Today, corporations face a similar challenge in managing the exponential growth of data. Just as multi-media repositories provided the solution for digital music, multimatter repositories provide a solution for corporate data. Corporations are using the same big-data, cloud-based technology that we have become familiar with in our personal lives to manage their discovery requirements. Access to a repository can be set up for multiple parties, similar to the way iTunes can be set up so family members can share access, but with the users coming from a company legal department and its outside law firms. Case databases are synchronized and connected to the repository. just as multiple devices and playlists are used for distributing music. Dashboard reports provide visibility across all the available data. They can be customized to accommodate user needs, to provide review and progress metrics across active cases, as well as insight into where each pocket of data exists. A multi-matter repository can also help with early case assessment, using built-in technology-assisted review tools and “more-like-this” functionality. These work like the iTunes “Genius” feature, but they are used to isolate document subsets.
By Daniel Kavan and Eric Robinson Kroll Ontrack
E-discovery project management is a rapidly growing specialty. While best practices continue to evolve, no true standards or standardized protocols have been developed. Further complicating the world of traditional EDPM is the growing volume of cross-border or global e-discovery projects, giving rise to GEDPM, which is developing as a niche within a niche. Just as cross-border or global business is fraught with regulatory, language, temporal and cultural issues, so is GEDPM. There are obvious complicating factors in the process: time zones, regulatory difference/requirements, language barriers. Often forgotten, however, are the cultural differences and the general approaches to e-discovery in other regions of the world. It is incumbent on any e-discovery professional involved in GEDPM to identify and understand these factors. Beyond local regulations/policies, there is the issue of perspective on the entire discovery process across legal cultures. No other country approaches discovery with as expansive a view as the United States. For Americans, if it’s potentially relevant, it’s discoverable and subject to U.S. discovery rules. Contrast this with the United Kingdom, where relevance is strictly defined as documents that either help or hinder one of the parties’ cases. Further down the spectrum, in civil law countries parties need to produce only the documents they wish to rely upon as evidence. Appropriate resources must be brought together to form the GEDPM team. This team should be empowered and able to address the myriad challenges that come with cross-border discovery.
By Carol Newman, Kerri Neitzel and Kelli Rangel Nilan Johnson Lewis
Historically, paralegals have been most involved with document review and processing, interviewing clients, assisting with depositions and written discovery, and providing support for motions practice. But technology and the demand for cost efficiency has expanded their responsibilities considerably. Demand for paralegal services is on the rise. The Bureau of Labor Statistics projects that 50,000 new paralegals will be added to the U.S. workforce from 2010-2020, an 18 percent rise over the prior decade. The key driver of change in the legal profession over the last decade has been the profusion of communications technologies and the necessity for electronic discovery that comes with it. This has created a new niche for paralegals who specialize in searching in multiple electronic formats and being able to capture key information. At the forefront of new e-discovery trends is predictive coding, a tool that assists the legal team in document review by using algorithms, in coordination with human guidance, to identify likely relevant documents. Paralegals are now increasingly responsible for being expert in how this technology works. Paralegals are also responsible for essential tasks that keep things moving in the lead up to a trial, and during the trial itself. Such tasks include preparation and management of exhibits and evidence, electronic presentation of exhibits, assistance with voir dire, background research regarding jurors, assistance with witness preparation and coordination of witness scheduling, interaction with courtroom personnel, note taking during testimony, watching juror reactions and post-trial juror interviews.
9
jun/jul 2014 today’S gEnEr al counSEl
Executive Summaries e-Discovery Page 20
Page 22
Page 26
How Metadata Can Affect a Case
Using Predictive Coding to Find Privileged Content
Who Should Perform a Database Collection, IT Department or Third Party?
By Tom Turner DSi
10
Metadata is data about data. File metadata is stored within the file and includes properties that are visible to the common user. System metadata is stored with the content of the file. It includes time stamps associated with data, such as date modified, accessed, created and entered. If you simply open a computer file, you will not know when it got to that computer or when it was moved to a certain folder. That information can be determined with metadata. Most of the time, metadata in litigation is used to discredit or support other evidence. Metadata can prove that a certain user created or opened a document in a specific time frame. Metadata can be used to help create timelines. A forensics analyst can look at how files were accessed and in what order. Because the data is mostly “black-and- white,” a factual report usually suffices and there is no need for the expert to testify. Metadata also comes into play with filtering during e-discovery. Common filters include de-duplication and file type. De-duplication gets rid of duplicates of documents, which reduces the data attorneys will need to review. This can become problematic if the documents have different metadata, because things like file name and location typically are not included in the de-duplication process. The duplicate is deleted, even though it could have had unique metadata that was relevant to the case. This issue is being addressed by de-duplication software.
By Manfred Gabriel and David Sharpe KPMG
Predictive coding, also known as technology-assisted review (TAR), is gaining wider acceptance in litigation and regulatory investigations, but lawyers generally insist that all documents deemed responsive need to be reviewed individually to guard against inadvertent disclosure of privileged documents. The stakes for correctly identifying privileged documents are higher than for any other category of documents, and because of the potential effect on a matter’s outcome the protection of privileged information tends to be the most expensive and time-consuming e-discovery task. Currently, it involves running multiple iterations of search terms with linear eyes-on review of the results, and rigorous quality-control. Privilege is hard to identify using common predictive coding technology for several reasons. Among them: Text in a document claiming that it is “privileged and confidential” is meaningless, and documents that are in fact privileged often will not contain those words. New developments in machine learning technology promise to more accurately identify privileged documents. Among these developments is finite state machines modeling. Like other approaches, this mathematical method starts with one or more initial seed sets of documents used to train the tool to detect similar text in the broader population, a process which is then refined. But distinctive advances in finite state machine technology enable it to be far more accurate in identifying privileged content. Perfection is elusive and will remain so, but new technologies promise to significantly reduce the time and cost of e-discovery document review.
By Joe Sremack Berkeley Research Group
The writer considers the question: Whom do you contact first when you need to respond to a request involving your database systems, someone in your IT department or a third-party provider, such as outside counsel or an e-discovery service provider? The IT department is likely to the most expert in its own systems, and it may prove to be the fastest and most cost-effective resource for performing a database system collection, particularly for a small collection with clearly defined requirements. But while an IT department may be the expert in the house database systems, it probably is not with regard to the processes required to collect and document data for an investigation. Two additional advantages of using third-party providers are their understanding of documentation and validation, and their independence from the organization. Third-party provider independence is beneficial when a party to the investigation is associated with those performing the data collection, or questions about your organization’s cooperation exist. Third-party providers are familiar with the requirements of an investigation and ensuring that those requirements are met. Their ability to manage complex data collections and navigate issues surrounding cross-border discovery, data retention policies and disparate data sources are additional advantages. IT departments may not be equipped to handle the additional burden of taking on such a project, and they may not have the expertise required to identify the pitfalls and requirements of a large-scale, complex database collection.
today’s gener al counsel jun/jul 2014
Executive Summaries Intellec tual ProPert y Page 28
Page 30
Page 34
Securing Trade Secrets in the Digital Age
Managing Risk in Foreign Patent Filings
New Web Domains Raise Risk of Cyber-Squatting
By Pamela Passman Center for Responsible Enterprise and Trade
By Michael V. Sneddon and Stuart W. Hinckley MultiLing
By Jan Corstens Deloitte
Trade secrets are increasingly critical to success in a competitive global economy, but legal protections for them remain weak in much of the world. This prompted the none-profit Center for Responsible Enterprise and Trade (CREATe.org), in partnership with PwC, to issue a report on the economic impact of trade secret theft. As highlighted by a 2013 report by the Obama Administration, the theft of trade secrets is a growing geopolitical problem that threatens exports and jobs and undermines innovation. Individual cases that have come to light offer a glimpse of how much damage trade secret theft can do. In April of 2011, for example, a former Ford Motor Company employee was sentenced to 70 months in federal prison for stealing trade secrets when he left to work for a competing automaker in China. He had made illicit copies onto external hard-drives of some 4,000 Ford documents. Those documents contained trade secrets that Ford valued at $50 million. The CREATe-PwC report describes the magnitude of the problem, discusses the main perpetrators and analyzes how trade secret theft may affect business and regulation in the future. It also provides a practical framework for assessing a company’s trade secrets, including their vulnerability to theft, and it provides a systematic way of investing in safeguards to help avert catastrophic losses and the cost of legal action. Companies and industries can also use the report as a way of entering the broader public discussion about trade secrets.
For foreign patent filings, employ specialized IP translation teams that include in-country native linguists who have subject matter expertise in the applicable technology as well as experience in patent language and processes, so they can precisely translate the filings. The right translators produce quality documents that lead to clarity, hold up through prosecution and reduce the chances of problems. For example, while European translations of chemical names can look very similar to English, only an experienced chemist fluent in Chinese could employ the proper Chinese equivalent translation. One single letter different in English, such as the difference between “methyl” and “ethyl” in a long chemical name, changes the entire name of the chemical in Chinese. The wrong chemical in translation will likely render at least that portion of the patent unenforceable. No matter how experienced the translator, the translation quality will be limited by the inability to collaborate and communicate across languages. Errors found in one language may not be corrected in others. By implementing a centralized model that streamlines translations and project management, enterprises can improve consistency and transparency. While machine translation can play a role, investing in technology-aided human translation is the most efficient way to manage IP translations. Technologies such as translation memory and terminology management contribute to the speed of translation, and provide consistency and value. Implementing best practices internally and using service providers who apply best practices for translating IP documents will help ensure overall quality.
With new web domains beginning to appear online – including .London, .guru and .sexy to name a few – businesses need to act to defend their brand from infringement. In March, the Trademark Clearinghouse revealed that more than 500,000 Claims Notices had been downloaded. These are sent as a warning to anyone attempting to register a domain name that matches a trademark term recorded in the Clearinghouse. Even though fewer than 70 of the 1,300 Top-Level Domains (TLDs) applied for are live and accepting registrations from the general public, the number of warnings issued indicates a high level of interest in trademarked terms from third parties. According to Interbrand’s “Best Global brands 2013” list, 48 percent of the top 50 brands are currently not in control of several key domain names already available. Brand infringement has generated some high-profile litigation. Donald Trump filed suit against an individual for falsely registering trumpmumbai.com, trumpindia.com, trumpbeijing.com and trumpabudhabi.com. Salvatore Ferragamo and Gucci won court cases against multiple third parties deceptively using their brand names. Burberry and Tommy Hilfiger are now facing brand infringement from unknown third parties who have registered both brands under the new .clothing TLD. Another complaint was filed against the domain names IBM.guru and IBM.ventures. Trademark Clearinghouse currently offers protection to more than 10,000 brands and businesses. It deters cybersquatters from registering protected terms, provides an ongoing notification service which is not time limited, and serves as protection for previously abused terms.
11
JUN/JUL 2014 TODAY’S GENER AL COUNSEL
Executive Summaries INTELLEC TUAL PROPERT Y
12
L ABOR & EMPLOYMENT
PAGE 36
PAGE 40
PAGE 42
Patent Eligibility of 3D Printed Organs Will Soon be an Issue
NLRB Puts “Ambush Elections” On Fast Track
Permissible Limits On Employee Social Media
By Craig C. Martin and Sara Tonnies Horton Jenner & Block
By Mark Carter Dinsmore & Shohl LLP
By Lisa E. Aguiar and Julian Pardo de Zela Ropers Majeski Kohn & Bentley
Biotech companies and scientists are working on a breakthrough that could allow specialized 3D printers to create human organs, a process known as “bioprinting.” Scientists already have printed blood vessels, a variety of organ tissues, and last year Princeton University scientists printed a functional ear. Should scientists and companies who manufacture organs be able to obtain patents on them even though they already exist in nature? The interplay between these new technologies and patent laws are unclear and ripe for examination by the courts. The Supreme Court weighed in on the question of patent eligible subject matter last year, in Association for Molecular Pathology v. Myriad Genetics, deciding whether a naturally occurring DNA segment could be patented. In that case, the Court invalidated previously issued patents on a gene sequence, but upheld a patent on synthetically created DNA. The Court’s reasoning in Myriad hints that the touchstone of such decisions should be whether the subject matter is an unknown but natural phenomenon, or a manufacture or composition of a matter that does not occur naturally. Both the process of creating a bioprinted organ or tissue and the composition of such organs and tissues may form the basis for future patent applications. A patent for a human liver would be denied, but would an application for a lab-created liver which functions like a human liver be denied? Patentability will likely rest on what the applicant seeks to patent: the method, the bioprinted substance or the organ itself.
In March, Chairman Mark Pearce of the National Labor Relations Board refused a 30-day extension of the comment period on the controversial “representation case procedures” rule, sometimes called the “ambush election” regulation, submitted by the Board. Thus the NLRB has placed finalization on a fast track. Chairman Pearce previously voted for the regulation in its earlier form, and it is evident he intends to put it in place as soon as possible. Currently, it takes at least 25 days from the date of a petition to hold an election to certify a union. The new regulation removes the 25-day minimum period and would pave the way for election periods in as little as 14 days. The new regulation also eliminates the right of an employer to make preelection appeals of critical rulings on the composition of the employee unit eligible to vote. It requires a hearing on pre-election issues within seven days of the filing of the petition. If employers want to raise issues concerning the union petition, they must raise them at that hearing, as they cannot raise issues on appeal that they failed to identify at the hearing. In addition, among other new obligations, it requires that before the election the employer provide the petitioning union with employee email addresses and telephone numbers. A dissenting Board member says the proposed regulation creates a “vote now, understand later” election climate. Absent an immediate injunction prohibiting its enforcement, employers in non-union workplaces should be prepared to respond quickly to an election petition.
When do an employee’s criticisms, complaints, or derogatory statements constitute protected activity, and when are there proper grounds for discipline or termination? Several recent NLRB opinions suggest answers. Employee communications critical of the employer or fellow employees are protected, provided the communication is intended to generate conversation about working conditions or group action towards the employer. Thus employees are free to discuss working conditions, benefits, or wages. Communications that are critical of the employer are not protected where they merely constitute griping and do not encourage concerted activity. An employee’s private communications on social media are not protected merely because they are made outside the workplace. Employees may find this counterintuitive, so employers must make an effort to convey this message. Policies that are too broad may violate the National Labor Relations Act. An unlawful policy would be prohibiting employees from posting statements that harm the company’s reputation, or consist of “disrespectful conduct and language” or in any way “depict” the company without permission. The NLRB found Costco’s social media policy was overly broad, where it prohibited postings that “damage the company” or “any person’s reputation.” Similarly, General Motors went too far with generalized prohibitions of conduct that is “offensive, demeaning or inappropriate.” Walmart struck the right balance where it prohibited discriminatory remarks, harassment, threats of violence or unlawful conduct. This formulation still allows employees to engage in concerted activity to improve working conditions.
TODAY’S GENER AL COUNSEL JUN/JUL 2014
Executive Summaries TGC SURVE YS
FEATURES
PAGE 44
PAGE 56
PAGE 60
Cybersecurity Management 2014
M&A Transactions in Bermuda and the Cayman Islands
SEC’s New, Powerful Enforcement Options
By Tonesan Amissah and Simon Raftopoulos Appleby
By Daniel Patrick Wendt Miller & Chevalier
This article is a guide through the many acronyms associated with regulatory and process requirements associated with M&A in Bermuda and the Caymans. KYC stands for “know your client,” a regulatory objective requiring businesses in these jurisdictions to know who their clients are and what they do. While such laws primarily apply to financial institutions and fiduciaries, they can extend to other parties in certain jurisdictions. Anyone contemplating an M&A transaction in Bermuda or the Cayman Islands should expect to encounter the KYC regime at some point. Businesses and service providers in Bermuda and the Cayman Islands are subject to stringent anti-money laundering (AML) and anti-terrorist financing (ATF) legislation, both local and international. In March of 2010, FATCA was signed into U.S. law. It primarily imposes a reporting system on U.S. taxpayers holding financial assets outside the United States, requiring them to report those assets to the IRS. But FATCA also requires foreign financial institutions (FFIs) to report directly to the IRS certain information about financial accounts held by U.S. taxpayers or foreign entities in which U.S. taxpayers hold a substantial ownership interest. The regulatory landscape in Bermuda and the Cayman Islands continues to change in response to global demands for higher levels of anti-money laundering, anti-terrorist financing, tax cooperation, transparency and fund oversight standards. Although these changes have introduced a slew of intimidating-sounding acronyms, with the help of a local advisor there are still opportunities for M&A activity.
A lesser-known provision of the 2010 Dodd-Frank legislation allows the Securities and Exchange Commission to pursue civil penalties for a broad range of actions through administrative actions, and to impose civil penalties on its own as well as through federal court. As a result, companies and executives challenging enforcement actions or negotiating settlements involving the Foreign Corrupt Practices Act are confronted with a new situation, advantageous in some circumstances and a disadvantage in others. It has now been several years since this rule changed. The SEC has pursued civil penalties in administrative proceedings, although not for FCPA violations. Many defendants have argued that these actions violate their constitutional rights. Rajat Gupta of Goldman Sachs was able to secure the withdrawal of an administrative action, although the SEC ultimately initiated a successful federal action against him. Two recent defendants, however, have lost preliminary motions on these issues in the Southern District of New York and the DC District. General counsel should note that when the SEC pursues contested enforcement actions before its own administrative law judges, certain disadvantages are created for defendants. However, the SEC and general counsel may together have more flexibility in negotiating the terms of FCPA-related settlements, given that the federal judiciary does not need to play a role. Corporate defendants may also be able to avail themselves of shorter timelines for resolving issues that are voluntarily disclosed, as is often the case in FCPA investigations.
Cybersecurity and the Law Department
Nearly half of respondents to a Today’s General Counsel survey regarding trends and attitudes toward cybersecurity felt their industry was very susceptible to security breaches. The larger the department or organization, the higher the percentage of respondents that indicated their industry was very susceptible. Almost half of respondents reported their organization had experienced a data breach. Asked whether the breach resulted in litigation, more than 80 percent said no. More than 60 percent said they had consulted about cybersecurity with outside consultants. Asked how familiar they were with the recently published National Institute of Standards and Technology (NIST) framework for a cybersecurity infrastructure, about one-third had never heard of it; one-third had heard of it but had not read or reviewed it; and one-third had read it/reviewed it, or were already using or planning to use it. Experts who commented on this finding note that the NIST framework will soon be the de facto standard for appropriate safeguards when the issue is raised in litigation. Asked what percentage of the IT budget is devoted to cybersecurity, 44 percent indicated that it was ten percent of the budget or less. Only four percent of respondents said that cybersecurity was 30 percent or more. Half the respondents said that the CIO is the person to whom the information security function reports. Ten percent said it was the CTO. Only four percent identified the CLO as the head of the information security function.
13
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
14
Multi-Matter Repositories are the iTunes of E-Discovery By adam Barr
D
id you know that corporations are using iTunes to manage ediscovery? It’s true, sort of. But instead of calling it iTunes, they call it a multi-matter repository. The name is not as catchy, but the objectives are the same.
Think back to the first time that you heard about MP3. It was farewell CD sleeves, hello gigabytes. Before MP3, we had an assortment of devices that stored and played music and videos. That wasn’t a problem for most of us because content stored across cas-
sette tapes, CDs and even vinyl was equivalent to about a gigabyte in today’s world. But things have changed. Volumes exploded when we started creating and accessing content through computers and networks. Organizing music collections and burning MP3s
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
onto CDs became a bigger job than most people had time to manage. The entertainment industry responded to this massive growth in digital music with iTunes and other similar multi-media repositories. These applications make it simpler for music lovers to organize their collections while also providing instant access to all the music and media ever produced across a trillion-dollar industry. We deposit our purchases into our personal multi-media repositories and there they remain for whenever we want them. Today, corporations face the same types of challenges in managing the exponential growth of data across the entire EDRM [Electronic Discovery Reference Model]. Every time an employee clicks “send” or “save,” a new “song” is added to the collection. And just as multi-media repositories provided the solution for digital music, multi-matter repositories provide a solution for corporate data. Corporations are using the same big-data, cloud-based technology that we have become familiar with in our personal lives to more effectively and efficiently manage their discovery requirements. Access to a repository can be set up for multiple parties, similar to the way iTunes is set up so family members can share access, but with the shared users coming from a corporation’s legal department and its outside law firms. Like iTunes, multi-matter repositories provide a centralized home where you can search and organize across large volumes of data. Not finding what you are looking for? Connect to the corporate iStore, or “corporate compliance cloud,” to select more, to be automatically processed and imported into the repository. Case databases are synchronized and connected to the repository just as multiple devices and playlists are used for distributing music, so the repository becomes a centralized one-stop shop of information. Dashboard reports provide visibility across the available data. They can be customized around users’ needs, to provide review and progress metrics across active cases, as well as insight into where each pocket of data exists.
A multi-matter repository can also help with early case assessment, using built-in technology-assisted review tools and “more-like-this” functionality. These work like the iTunes “Genius” feature, but they are used to isolate document subsets. Data can then be distributed to specific case databases as easily as Mick Jagger and Jimi Hendrix can be added to a”Long Road Trip” playlist. Along with providing organizational benefits, multi-matter repositories save money, in part by eliminating duplication of effort and enabling more efficient file management. But the largest savings are in hosting costs. For most corporate discovery, it is common for a file to be represented as a record multiple times in a case, or across multiple cases. Traditionally, corporations paid for each recorded instance of the same document. But just as we no longer pay for each time we add Willie Nelson’s Georgia on My Mind to a playlist, a corporate multimatter repository combined with a good pricing agreement can prevent paying for a file multiple times. Some corporations are also attracted to alternative pricing options that are based around a subscription model. Spotify anyone? Multi-matter repositories remove the burdens that traditionally were presented when matters closed, when data would be deleted to prevent continued costs but work product often would be lost as well. With multi-matter, closing cases is essentially like deleting your playlist – no harm done and no additional costs, because the repository retains the data and work-product. This is valuable for future matters, when the same records are needed for new cases. How often does outside counsel request documents from a prior case because they need to reproduce those same documents in their current litigation? Gone are the awkward conversations explaining that the prior case was deleted years ago, along with all of its content. No need to recollect, process and upload again. It’s all right there.
There are also cost benefits in retaining the value of legal and technical work previously applied, and from better quality control and consistency. At home, Mom may apply a parentalcontrol tag through the family’s iTunes to a song or movie, and it is instantly represented across all devices that access those files. Consider an analogous legal scenario. Outside counsel in a pending lawsuit conduct a review and determine that a document is privileged. Later, for a separate case, money will be saved when the same record does not have to be re-reviewed for privilege and risks of inconsistency are removed. Global tags can be beneficial for other purposes, as well, including when reviewers tag records as “junk,” such as spam emails that are not relevant for any litigation. When this occurs, the document is automatically flagged globally and suppressed from current and future reviews. Multi-media repositories such as iTunes changed the way we store, listen to, tag and share music, and other media. In much the same way, multi-matter repositories are changing the way corporations manage data for e-discovery. Discovery is complex and expensive to manage. Multi-matter repositories offer greater simplicity, quality and savings. It’s time for corporations to trash the VCRs and cassette players they’ve been using to manage data, and upgrade to a multi-matter repository. They might find it to be music to their ears, and to their budgets. ■
Adam Barr is vice president of professional services at Catalyst Repository Systems, Denver, Colo. With more than a decade of consulting experience in litigation support and e-discovery, he focuses on helping corporations and law firms use technology to manage complex legal matters. abarr@catalystsecure.com
15
JUN/JUL 20 14 TODAY’S GENER AL COUNSEL
E-Discovery
The Complex Challenges of CrossBorder E-Discovery Management By Daniel Kavan and Eric Robinson
16
E
-discovery project management (EDPM) is a fledgling but rapidly growing specialty in the project management world. While best practices continue to evolve, no true standards or standardized protocols have been developed. Further complicating the world of traditional EDPM is the growing volume of cross-border or global e-discovery projects – call it GEDPM. Given the rise and expansion of the global economy, it should come as no surprise that GEDPM is developing as a niche within a niche. Just as crossborder or global business is fraught with regulatory, language, temporal and cultural issues, so is GEDPM. Consider the following scenario: ACME Corporation has its global
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
headquarters in Wichita, Kansas. However, it operates and has holdings extensively in Europe, Asia and Canada. ACME finds itself the subject of a trans-global investigation by regulators in the United States, European Union, Hong Kong and Canada. This is by no means is an implausible situation. Global organizations are increasingly finding themselves the subjects of either coordinated or “add-on” investigations by international or regional regulatory bodies. If this were simply a U.S.-based investigation, managing the e-discovery project would be relatively straightforward. Add multiple investigations governed by foreign law/regulations, not to mention the non-legal chal-
client resources or colleagues half way around the world can become a daunting task. In addition to the logistical challenges, this issue introduces an element that is often overlooked – the impact on expenses. Additional time and effort is required to effectively collaborate. Setting up a schedule of twiceweekly calls with a client’s resources and project teams in the United States and Tokyo, including service providers and outside counsel, usually involves alternating which team will be awake at 3:00 a.m. – and doing so for four to six weeks. This type of requirement is not uncommon and introduces an additional organizational challenge and stress component into the project.
The amount of cross-border e-discovery continues to increase, at the same time conflicting legal precedent persists in U.S. courts regarding a corporate end-client’s obligation. lenges, and it’s clear that ACME has the makings of an e-discovery project fraught with pitfalls. As mentioned, there are obvious complicating factors in the e-discovery process: time zones, regulatory difference/requirements and language barriers. Often forgotten, however, are the cultural differences and the general approaches to e-discovery in other regions of the world, beyond the defined regulatory requirements. It is incumbent on any e-discovery professional involved in GEDPM to identify and understand these factors. Failure to do so could lead to disastrous results for the client (ACME, in this example). Anyone who has been engaged in a cross-border e-discovery project likely has experience with some if not all of these factors. Even the seemingly small obstacles can have a deep impact. Time zones, for example: Coordinating calls and/or meetings with
Far more complicated than meeting logistics, though, is the growing importance and impact of the local, regional and national regulations of various countries around the world. Most e-discovery professionals are at least aware of the European Union’s personal and data privacy regulations. Less discussed but extremely important to GEDPM, however, are the regulations of EU states such as Switzerland, Germany and France, which go far beyond those of the EU. Germany, for example, provides a particularly tricky landscape. Not only will practitioners find more stringent national regulations, but in many jurisdictions they could encounter regional or local regulations. On the other side of the globe are the emerging policies of Tokyo, China, Hong Kong, Singapore and others within the region. In China the state can claim data is protected by “state-secret” regulations. Mean-
while, nations such as Singapore and South Korea are in the process of developing and promulgating data protection guidelines and codes. Navigating these local (intended to be inclusive of the national, regional and/or local regulations of a particular jurisdiction) regulations can be very difficult and introduces not only logistical challenges, but often significant cost factors. For instance, if ACME has data in the United States, Germany and/or Tokyo, attempting to blindly transfer all of the data directly to the United States could result not only in very costly local sanctions, but also in long term business impacts with the locality. Recently, the German government has expressed serious concerns over German data going to the United States, regardless of the protection of Safe Harbor registered companies. In this scenario, ACME’s best approach is to first engage an outside counsel and a service provider that is experienced in managing crossborder matters. In other words, bring the appropriate resources to the table to meet the need. Additionally, unless the organization or counsel has the appropriate local (in-country) resources, it is highly recommended that local counsel also be engaged to assist in navigating the local regulations and authorities. In particular, local counsel are often instructed to advise on collection strategies that comply with local privacy laws. For example, in some European jurisdictions, it is necessary to have a bailiff present while custodians’ data is being collected. Failure to comply can result in serious sanctions. Once the team is in place, an appropriate strategy can be developed and implemented to meet the needs of the matter, while not violating any local laws and regulations. It is important to note that while the amount of cross-border e-discovery continues to increase, conflicting legal precedent exists in U.S. courts regarding a corporate end-client’s obligation. Some opinions have held continued on page 25
17
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
Tech-Savvy Paralegals Filling Out E-Discovery Ranks By carol newman, Kerri neitzel and Kelli rangel
18
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
H
istorically, paralegals were most involved with document review and processing, interviewing clients, assisting with depositions and written discovery, and providing support for motions practice. But as technology continues to change the way we work, perhaps no role within the legal industry has been more affected than that of the paralegal. Demand for paralegal services is on the rise: The Bureau of Labor Statistics projects that 50,000 new paralegals will be added to the U.S. workforce from 2010-2020, an 18 percent rise over the prior decade. The nature of a paralegal’s work now encompasses the demands of a more digital world. Paralegals are increasingly looked on as an integral part of any outside counsel legal team, as many firms seek ways to provide more cost-effective legal services, despite the growing burden of e-discovery. a new niche
The key driver of the changes in the legal profession over the last decade has been the profusion of communications technologies and the requirement for electronic discovery that comes with it. This has created a new niche for paralegals who specialize in searching in multiple electronic formats and capturing key information. “Technology has caused my entire career to change,” says Trisha Smith, Senior E-Discovery Project Manager with UnitedHealth Group. “Early in my career, my responsibilities were, to a great extent, about paper collections. Email was not as widely used, and I would work on a lawsuit from the beginning of the matter through trial. Now my involvement is a much more targeted area of a lawsuit: e-discovery. Additionally, I work on a small team in which we develop ediscovery policies and procedures for UnitedHealth.” With more work than ever stored on computers and online, legal teams need experts with the technical skills to quickly and effectively sort
through massive amounts of data. According to Frank Nelson, e-discovery manager for the Nilan Johnson Lewis law firm, just a decade ago a large lawsuit typically involved about 500 gigabytes of data. That number has ballooned tenfold, from 5 million digital pages to 50 million. At the forefront of new e-discovery trends is predictive coding, a tool that assists the legal team in document review by using algorithms, combined with human guidance, to identify likely relevant documents. Paralegals are now increasingly responsible for being experts in how this technology works. “My role,” Smith explains, “now includes case management of discovery – collection through production – which involves negotiating search terms, establishing litigation holds, and being a liaison between our IT department, outside counsel, internal business partners, vendors, and our legal business partners.” A keyword search is still the preferred method of many for culling through electronically stored information, but this approach has drawbacks, including the fact that lawyers from both sides must be willing to agree on search terms. “There is a push toward more analytics and predictive coding in e-discovery,” says Smith. “Once this is played out in the courts a little more, I hope to see more requests for these tools, as opposed to just using search terms.” As predictive coding takes hold, Smith sees an even greater role for paralegals. FiRST ReSPOnDeRS
Paralegals are playing a pivotal role in law firms’ response to the pressure to reduce legal costs. Often they are first on the scene to investigate claims and determine the path that investigations will take. For outside counsel, these expanded responsibilities provide a way to reduce staffing and increase efficiency. Paralegals are also taking their expanded skills out of the office and
into the courtroom. They are responsible for essential tasks that keep things moving in the lead-up to a trail and during the trial itself. These tasks include preparation and management of exhibits and evidence, electronic presentation of exhibits, assistance with voir dire, background research regarding jurors, assistance with witness preparation and coordination of witness scheduling, interaction with courtroom personnel, note taking during testimony, watching juror reactions and post-trial juror interviews. Although they are prohibited by ethics rules from performing certain aspects of legal work, the role of paralegals continues to expand. The continued push for efficiency and value, plus the steady increase in digital documentation, means that trend will continue. ■
Carol Newman is a paralegal with Nilan Johnson Lewis with a focus on product liability and commercial litigation. cnewman@nilanjohnson.com
Kerri Neitzel is a paralegal with Nilan Johnson Lewis with a focus on ERISA and healthcare. kneitzel@nilanjohnson.com
Kelli Rangel is a paralegal with Nilan Johnson Lewis with a focus on labor and employment matters. krangel@nilanjohnson.com
19
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
20
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
How Metadata Can Affect a Case By Tom Turner
M
etadata can be valuable information for a court case, but its collection is more complicated than standard electronic discovery data collection. If you are faced with a legal situation that involves metadata, you will need to know what it is, how it is collected and how to use it in litigation. Metadata, by definition, is data about data. For computers and digital data, there are two main types. File metadata is stored within the file and includes properties that are visible to the common user. Typical metadata properties in a file include who created the document, when it was last printed, and more. Most people understand this metadata as well as they understand the “to,” “from” and “subject” lines in an email program. The second type of metadata is system metadata, which is stored with the content of the file. Think of a computer as a library. You can get information about a book by looking at the physical book, but there is additional data in the card catalog. No matter how closely you look in the book, there will always be some information about it that cannot be found until you go to the card catalog. The card catalog is like system metadata, which includes time stamps associated with data, such as date “modified, accessed, created and entered” (MACE). If you simply open a computer file, you will not know when it got to that computer or when it was moved to a certain folder, but that information about user actions can be determined with metadata. Metadata is typically “black-andwhite” and does not require a lot of interpretation. While all systems have similar types of information stored as metadata, Macs, PCs and Linux units have different metadata structures. It is critical to have a digital forensics expert handle metadata collection and analysis. Forensics analysts always validate the time of the system, a procedure that is necessary to prove the metadata is accurate. They also understand the nu-
ances of various systems. For example, in Windows 7 the creation date could mean the original file, this version of the file, or the copy of the original file. It’s important to understand the difference. In litigation, metadata typically is used in making a case for spoliation. Most of the time, metadata is used to discredit or support other evidence. That is, it’s used to corroborate what the other data says. For example, metadata can prove that a certain user created or opened a document in a specific time frame. That said, metadata itself can become the “smoking gun.” In one case, our firm’s forensic evidence specialist collected and analyzed data from key defendants to prove that they had taken proprietary information from the plaintiff. The point of origin for the files and the metadata from deleted files were key pieces of evidence in the case. The forensic analyst testified during the trial to show when, where and by whom documents were created, and when and by whom they were last saved – all by using metadata. The analyst was able to prove, for example, that one document originated from the plaintiff’s server and was emailed as an attachment between defendants, resulting in a rebranded version of the proprietary document. Metadata can be used in litigation to help create timelines. A forensics analyst can look at how files were accessed, and in what order, to prove an action. This information is usually submitted in a report to be used as evidence. The report can be factual, including just the data (time stamps, etc.), or it can be opinionbased, with the expert providing individual analysis. But because the data is mostly black-and-white, a factual report usually suffices and there is no need for the expert to testify. Metadata also comes into play with filtering during e-discovery. Common filters include date, de-duplication and file type. But there are issues with date filtering and de-duplication. De-duplication gets rid of duplicates of documents,
which reduces the amount of data attorneys will need to review. This can be a problem if the documents have different metadata because things like file name and location typically are not included in the de-duplication process. The duplicate is deleted, even though it could have had unique metadata that was relevant to the case. This issue is beginning to be addressed by de-duplication software. The other issue pertains to date filtering, and it has yet to be addressed, although data ingestion platforms do help. Standard date filtering uses metadata to find the date. The software does not filter all the sub-emails, though, which can lead to missed emails. For example, say we are looking for email files sent in 2012. If I forwarded an email from 2012 in 2013, my email would not come up in the results. There is also an issue if date filtering is done after de-duplication. For example, if duplicate documents have different creation dates, one will be chosen by software without considering the date. If the document chosen doesn’t fall into counsel’s requested time period, it will not make it to review, even if the duplicate would have been in the right time period. In general, metadata can be a key factor in litigation, even if it is used only to support circumstantial evidence. For it to stay defensible, a digital forensics expert should collect and analyze metadata when attorneys decide to use it. ■
Tom Turner, president and co-founder of DSi, has worked in the litigation support industry since 1994. He was formerly a founding partner and chief technology officer at Paragon Legal Group. mjgabriel@kpmg.com
21
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
22
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
Using Predictive Coding to Find Privileged Content By Manfred Gabriel and David Sharpe
P
redictive coding, also known as technology-assisted review (TAR), is gaining wider acceptance in litigations and regulatory investigations. Increasingly, it’s being used by law firms to limit the amount of document review required before making an e-discovery production. While lawyers are growing more comfortable using TAR for determining responsiveness, they generally insist that all documents deemed responsive need to be reviewed individually to guard against inadvertent disclosure of privileged documents.
privileged information tends to be the most expensive and time-consuming task during e-discovery. Currently, it involves running multiple iterations of search terms with linear eyes-on review of the results and rigorous qualitycontrol. TAR is rarely used. DIFFICULTY OF PREDICTING FOR PRIVILEGE
Privilege is hard to identify using common predictive coding technology for several reasons. Text in a document claiming that it is “privileged and confidential” is meaningless and documents
The need for exhaustive identification of privileged documents requires much higher levels of recall than those typically considered acceptable for simple responsiveness. The stakes for correctly identifying privileged documents are high – higher than for any other category of documents. It is the most common type of protected information identified during e-discovery, and most costly, and the risks from inadvertent disclosure can be critical. First, the risk of waiver can extend to the subject matter of the communication. While claw-backs provide some defense against these circumstances, it is impossible to “un-ring the bell.” Once the opposing side has seen privileged documents, it may gain a litigation advantage that cannot be addressed by precluding the use of those documents in evidence. Because of the potential effect on a matter’s outcome, the protection of
that are in fact privileged will often not contain these words. The determination of whether legal advice was sought or rendered may be nuanced and subtle. Key factors in establishing or waiving privilege include information regarding the identities of the sender and recipient of the communication – information that resides in metadata fields and is often not utilized in predictive coding tools. Joint-defense agreements may preserve privilege despite disclosure to a party that is not the counsel for the disclosing party. Facts not apparent in the text of the document may affect privilege. For example, privilege can be waived for all copies of a document even if only one copy was disclosed to
a third party. This waiver may extend to the subject matter of the disclosed document, and thus to all documents dealing with the same subject matter. Another challenge is that privileged documents tend to occur less frequently in review populations. Historical case data shows that on average only about 2.7 percent of documents are marked privileged. Such low frequency affects typical predictive coding workflows. For example, sample sizes will need to be increased, potentially significantly, to estimate the distribution of privilege and to attain sufficient numbers of privileged training documents. Finally, the need for exhaustive identification of privileged documents requires much higher levels of recall than those typically considered acceptable for simple responsiveness. Since the inadvertent disclosure of privileged documents may lead to the waiver of privilege for the entire subject matter, more than 90 percent of privileged documents must be identified. Such high recall is well above what is currently used in most responsiveness workflows. GOOD PREDICTIONS LOWER RISK AND COST
Effective technology and workflow are key to identifying potentially privileged content. But a successful methodology offers significant savings at the privilege-review stage of e-discovery, which is the most lawyer-intensive stage and thus the most expensive. In practical terms, using predictive coding for both responsiveness and privilege will allow counsel to deploy a separate workflow for each of the following three categories of documents: • Documents predicted to be non-responsive and therefore not producible
23
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
(unless they are family members of responsive documents). After employing statistical sampling for quality control to ensure that predictions are reliable, these documents will be culled. • Documents predicted to be both responsive and privileged. These documents will require attorney review, and if privilege is confirmed they will need to be entered in the privilege log. • Documents predicted to be responsive, and predicted not to contain privileged information. This will be a new category of documents in most e-discovery workflows, and a careful assessment should be made regarding how to handle them. There should be rigorous statistical sampling to determine the rates at which both nonresponsive documents and privileged material appear in this population.
24
With a careful assessment of the risk appetite and e-discovery budget, further steps can be taken to eliminate non-responsive and/or privileged documents from the produced set. NEW TECHNOLOGY SHOWS PROMISE
New developments in machine learning technology, among them “finite state machines modeling,” promise to more accurately identify privileged documents. Like other approaches, this mathematical method builds one or more text classification models. The process starts with one or more initial document seed sets, which are used to train the tool to detect similar text in the broader population. Refinements to the training sets lead to improvements in the classifier’s results. However, finite state machine modeling differs from existing methods in important ways. Finite state machine modeling is true to the text. It does not ”cleanse” the input text to eliminate noise, but can work with all words, including “stop words,” and even punctuation. It can also respect the upper and lower case used by the author. These features more fully encompass important nuances in intent and meaning. Finite state machine classifiers oper-
ate at the level of individual characters, rather than simply measuring the occurrence, co-occurrence and proximity of words. Finite state machine classification also works at the sub-document level, assessing “text units” and assigning scores to these individual text units – meaning it can handle a fragment of text or portion of a document, rather than assigning a binary score to the entire document.
identify privileged content. Perfection is elusive and will remain so, but, properly employed, the new technology promises to significantly reduce the time and cost of e-discovery document review. Current technology may not be mature enough to permit extensive reliance on software to consistently identify privileged information in e-discovery document review. But for-
Developments in machine learning technology show promise for more accurately identifying privileged documents. This last characteristic is critical. In a 30-page document, perhaps one paragraph is highly privileged. In a typical document-level tool, the entire document has to be given a single score. The signal from that one paragraph will be diluted by the others, resulting in a score for the entire document that likely falls far below the threshold for being considered privileged. But finite state machine classification can isolate that paragraph and bring it forward for attorney review, to validate or correct its scoring and accurately identify future privileged text strings when it finds them. In a test study, KPMG investigators using a proprietary text classification tool with finite-state machine technology (provided by Canadian-based technology company, Porfiau) were able to identify 90 percent of the text units that the lawyer-reviewer had deemed privileged, with precision of approximately 0.50, much higher than that of typical text classification tools. (Precision is the proportion of all documents identified by the tool as privileged that actually are privileged.) These preliminary results suggest that next-generation technology, when implemented as part of a well-designed workflow that takes into account the special challenges of privilege review, can consistently
ward-thinking attorneys are already looking to cutting-edge technology to bring greater consistency, speed, and accuracy to privilege review. Given the promise of predictive-coding technology, review for privilege will improve in the future, and the stakes are too high to ignore its benefits. ■
Manfred Gabriel is Principal in KPMG’s U.S. Forensic Technology Services practice, New York. A former lawyer, he provides clients with a wide range of services from enterprise-level e-discovery management to delivery on large, complex e-discovery projects. mjgabriel@kpmg.com
David Sharpe is a former lawyer with 12 years experience as an attorney and e-discovery specialist, in New York. He is now Manager of E-Discovery Services for KPMG Canada. davidsharpe@kpmg.ca
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
Cross-Border Management continued from page 17
that a party’s discovery obligations are not diminished simply because data is located in a jurisdiction that prevents its transfer. Others have held that the data must be provided once the pertinent personal and data privacy regulations have been satisfied. As cross-border matters increase in frequency, it is likely that both federal and state courts in the United States will develop more standardized policies for addressing disputes over “protected” data.
Finally, beyond just the local regulations/policies, there is the issue of perspective on the entire discovery process across legal cultures. No other country in the world approaches discovery with as expansive a view as the United States. For Americans, if it’s potentially relevant, it’s discoverable and subject to our discovery rules. Contrast this with the United Kingdom, where relevance is strictly defined as documents that either help or hinder one of the parties’ cases. Further down the spectrum, in civil law countries parties only need to produce the documents they wish to rely upon as evidence.
Global organizations are increasingly finding themselves the subjects of either coordinated or “add-on” investigations by international or regional regulatory bodies. That brings attention to the intangible challenges of language and culture. In many languages other than English, the intonation of a word or stressing one syllable over another can dramatically change the meaning of a word or the context of a sentence – sometimes leading to embarrassing results if the cue is missed. Likewise, simple Western gestures/ actions could be extremely offensive to others, based on the differences in cultural norms. As with the local rules, it is imperative that the GEDPM team be aware of and sensitive to these challenges, not only to ensure the smooth integration and collaboration of the team, but also with respect to dealing with opposing parties, government officials and/or other third parties. There are definitely cost-benefit analyses to be conducted regarding the need to have translators and/or interpreters for both language and cultural purposes. The language and cultural factors could add time, complexity and cost to any GEDPM matter.
Without delving into the pros and cons of the various approaches, suffice it to say that disparities between the legal culture in the United States and other jurisdictions (most of which don’t even call the process “discovery”) are widespread and significant. When, for example, a German company finds itself in a U.S. discovery action and hears that it has to produce all potentially relevant documents – even those which might damage its own case – it finds the whole approach foreign and quite surprising. The key is to identify the differences and through collaboration of the GEDPM team, develop a matter-specific strategy and/or clientspecific protocols to address them, and to educate management and key custodians as to their obligations. It is also important to consider the technical challenges encountered when working with data from various countries. Will an e-discovery provider’s platform handle documents in various scripts and encod-
ing? Can languages be automatically identified to ensure the right documents go to the review teams with the right language skills? And, for consistency, in which time zone should the data be processed? These are some of the major challenges involved with global e-discovery project management. The underlying theme is that it is critical that the appropriate resources be brought together to form the GEDPM team. This team should be empowered and able to address the myriad of challenges that come with cross-border trans-global discovery. ■
Daniel Kavan is Manager, E-Discovery Consultancy, EMEA (Europe, Middle East and Africa) at Kroll Ontrack. His group advises lawyers and their clients on how to manage electronically stored documents in litigation, arbitration, and internal or regulatory investigations. He works on international commercial litigation matters, competition law inquiries and internal investigations, particularly in the areas of fraud and bribery. He formerly practiced as a commercial litigator in Australia. dkavan@krollontrack.com
Eric Robinson, Solution Architect and Portfolio Manager at Kroll Ontrack, consults with Fortune 500 and AmLaw 100 firms on discovery strategies. Before joining Kroll Ontrack, he served as lead project manager for Wright Robinson Osthimer & Tatum, managing the firm’s e-discovery providers as well as e-discovery projects for the firm’s discovery management practice group. erobinson@krollontrack.com
25
jun/jul 20 14 toDay’s gEnEr al counsEl
E-Discovery
26
Who Should Perform a Database Collection, IT Department or Third Party? By Joe Joe Sremack Sremack By
W
ho is the first person you contact when you need to respond to a data request involving your database systems? Is it someone in your IT department? Or do you contact a third-party provider, such as outside counsel or an e-discovery service provider? With the growing importance and volume of data stored in database systems, more discovery and regulatory inquiry requests involve transactional data that are stored in these systems.
Responding in a timely and effective manner is dependent on having the right people performing the collection. Collecting information from a database system is very different from a traditional e-discovery collection. The latter involves carefully acquiring data by means of specialized software that preserves metadata and captures unique fingerprints to prove that the collected data was captured completely and not subsequently altered. The laptops, servers,
and network file shares involved may need to be powered down to perform the traditional e-discovery collection appropriately. Database systems, however, can contain significantly more data, and keeping a database system online can be more critical to business operations than keeping an employee’s laptop or a department’s file share online. In addition, the data stored in database systems does not have the
toDay’s gEnEr al counsEl jun/jul 2014
E-Discovery
same type of metadata as emails and electronic files. ADVANTAGES OF IN-HOUSE INFOrmATION TEcH DEPArTmENT
In-house IT departments might be the foremost experts about your systems. They are typically the ones who have created the architecture, implemented and managed the database systems, and they are familiar with the business processes that are involved. Their understanding of the technical capabilities of the systems allows them to: • Design and execute the database backups or custom queries to extract the data. • Estimate the time required to perform a collection. • Understand and specify the format of the outputted data. Your IT department may also be the fastest and most cost-effective resource for performing a database system collection. If the size and scope of an investigation is small and straightforward, a standard data collection may be the most suitable option. Some IT departments charge a fee back to the general counsel’s office. However, it may be negligible if the collection is small. A small data collection request can be met by your IT department if the requirements are clearly defined and made actionable for the IT department. This is the situation where the IT department can collect the data quickly and effectively. ADVANTAGES OF THIrD-PArTY PrOVIDEr
While an IT department may be expert in the database systems, it may not be with regard to the processes required to collect and document the data for an investigation. Collecting from database systems involves a careful process of properly identifying the appropriate data – including offline and backup data – documenting the entire process, and being able to address questions about objectivity and chain of custody. What data should be identified as relevant depends on the nature of the case,
but the general rule is to map the requirements of the investigation to the various data sources and ensure that the collection captures the required data. Counsel, either in-house or external, and third-party providers are familiar with the requirements of an investigation and ensuring that those requirements are met. There are two additional advantages of using a third-party provider: Their understanding of documenting and validating the collection, and their independence from the organization. Since metadata typically is not involved in a database collection, other means for documenting and validating the collection are required. The documentation and validation materials vary depending on the nature of the investigation and the database system or systems involved, but some examples are: log files, collection queries/ scripts, and calculated control totals to compare to the collected data. While these items can be captured by an IT department, third-party providers have experience with documenting and validating data collections specific to investigations. Third-party provider independence is beneficial when a party to the investigation is associated with those performing the data collection or questions about your organization’s cooperation exist. Their ability to manage complex data collections may be another advantage of third-party providers. Navigating issues surrounding cross-border discovery, data retention policies, and disparate data sources requires detailed and meticulous project management and a thorough understanding of the applicable laws and regulations. Some IT departments are not equipped to handle the additional burden of taking on such a project, and they may not have the expertise required to identify the pitfalls and requirements of a large-scale, complex database collection. WHIcH – Or BOTH?
To make the determination, the first step is to review the requirements of the data collection with your IT department and, if involved, outside counsel. Collectively, you should seek to identify the scope of the collection and the effort and cost required. If you can fully assess the scope and
determine the steps required for performing the collection, and the cost and effort for using your IT department are reasonable, then using your IT department may be appropriate. If you cannot fully assess the scope or have questions about whether the process will be defensible and correct, consider contacting a third-party provider for assistance. The use of your IT department is not an all-or-nothing proposition. You can also consider engaging your IT department to assist with facets of the data collection, such as the development of the collection scripts or the monitoring of the data extraction process, while engaging third-party providers to assist with other facets of the collection. This hybrid approach is useful for budget management and/or in cases where your IT department is well-equipped to perform the technical aspects of the collection, but there is some requirement that a collection be certified or there is a potential need for a declaration or testimony about the data collection. Because data collection from database systems is different from traditional ediscovery, various options exist for selecting who performs the collection. Although traditional e-discovery requires specialized training and software that most in-house IT departments do not have, database system collections can be performed by IT departments if they understand the complexities and requirements of investigations. You need to thoroughly understand your IT department’s capabilities before you can make an informed decision about who should perform the collection. ■
Joe Sremack is a Principal in Berkeley Research Group’s Technology Solutions practice. He has worked with corporate entities and law firms for the past 12 years, assisting and advising on issues involving e-discovery, structured data collections and productions, data analytics and source code analysis. jsremack@brg-expert.com
27
jun/jul 2014 today’s gener al counsel
Intellectual Property
28
today’s gener al counsel jun/jul 2014
Intellectual Property
Securing Trade Secrets in the Digital Age By Pamela Passman
T
o address a threat, you first need to understand it. In the case of trade secret theft, this is a serious challenge. The threat comes from an array of perpetrators, with differing means and motivations, and the digital age has made theft easier. A thumb drive or an email may be all it takes to spirit off sensitive information.
pwc.com/en_US/us/forensic-services/ publications/assets/economic-impact.pdf or by searching “Economic Impact of Trade Secret Theft.”] The report provides a big picture view, including the magnitude of the problem, analysis of its main perpetrators and how trade secret theft may shape the business and regulatory landscapes in the future.
Legal protections for these assets, which are not covered by copyright, trademark and patent laws, remain weak in much of the world. Trade secrets – intellectual assets such as customer information, strategic plans, proprietary research data, unique manufacturing processes and novel IP applications – are the product of experience, investment and hard work. Increasingly, they are critical to success in a competitive global economy. But legal protections for these assets, which are not covered by copyright, trademark and patent laws, remain weak in much of the world. So it is incumbent upon companies to get a clear picture of their valuable competitive assets and address the risk of theft to the greatest extent possible. The challenge this represents prompted the Center for Responsible Enterprise and Trade (CREATe.org), in partnership with PwC, to take a comprehensive look at the issue in a report, “Economic Impact of Trade Secret Theft: a Framework for Companies to Safeguard Trade Secrets and Mitigate Potential Threats.” [The full report can be accessed at https://www.
At the level of the individual company, the report also lays out a practical framework for assessing trade secrets, their vulnerability to theft and a systematic way of investing in safeguards to help avert catastrophic losses and the cost of legal action. THE PRICE TAG
Individual cases that have come to light offer a glimpse of how much damage trade secret theft can do. In April 2011, former Ford Motor Company employee Yu Xiang Dong was sentenced to 70 months in federal prison for stealing trade secrets as he left to work for a competing automaker in China. Yu had made illicit copies onto external harddrives of some 4,000 Ford documents, containing trade secrets that Ford valued at $50 million. As highlighted in a 2013 report by the Obama Administration, the theft of trade secrets is also a growing geopolitical problem that threatens exports and jobs and undermines innovation.
Getting a picture of the overall cost of trade secret theft is important as a guide for policy creation, industry awareness and advocacy, but challenging for a number of reasons. In many cases, companies do not publicize their losses due to trade secret theft because they believe it might compound their problems by causing alarm among shareholders or harm to their reputation. In some cases, the company may not realize its loss, or not realize it until long after it has occurred. Also, in some jurisdictions, companies that have suffered losses are reluctant to use the legal system to address the problem because the legal process requires disclosure of the very secrets they wished to keep confidential. To create an estimate despite the obstacles to collecting data, the analysis behind the CREATe-PwC report leverages multiple studies on illicit economic activity across the United States and other advanced industrial nations as a proxy for the theft of trade secrets. The resulting estimate of losses – some one to three percent of GDP across advanced industrialized nations – puts the problem on par with corruption and black market activities, such as counterfeiting of products from aircraft parts and weapons to food and cosmetics. UNDERSTANDING THE BAD ACTORS
Companies face different threats depending on their unique industry and the nature of their competitive information. The report looks at five main actors, how they tend to operate and the type of information they target. For example, trade secrets are more frequently stolen by profit-driven company employees who can easily access confidential information acting continued on page 33
29
jun/jul 2014 today’s gener al counsel
Intellectual Property
30
today’s gener al counsel jun/jul 2014
Intellectual Property
Managing Risk in Foreign Patent Filings By Michael V. sneddon and stuart W. Hinckley
t
he world’s largest multinational enterprises file thousands of foreign patents every year to protect their intellectual property. However, as many general counsel know well, even the successful filing and issuance of a patent doesn’t ensure the safety of a company’s intellectual property. A poorly drafted patent may not protect critical aspects of the IP and could be captured in a more precise patent by a competitor, or serve as the basis for challenge. When you don’t properly manage IP, the potential for litigation increases while the prospect of success in the courts decreases. Litigation costs can soar, with the added burden on the legal team distracting it from more productive work.
In contrast, skillful patenting and management of IP can add significant value, protect competitive advantage, and provide a powerful tool to negotiate licensing agreements. Just ask IBM. To resolve its allegations that Twitter had infringed on three IBM patents, Twitter purchased 900 of Big Blue’s patents and entered into a cross-licensing agreement. License revenue from IBM’s patent portfolio is reported to exceed $1 billion annually. To help minimize the possibility of litigation and patent invalidation, focus on three things from the start: the quality of the patent, the quality of the legal counsel, and the quality of the translations that facilitate foreign patent filings aimed at global protection.
Patents must be drafted so their specifications and claims are neither too broad nor too narrow, but capture the proper scope of the claimed invention. Those drafting patent applications must know the market and the prior art, including relevant inventions that have been patented, as well as those in the public domain. Regularly searching through patent filings from both competitors and others in the industry will reveal trends. Reading trade journals, other magazines, and blogs can also provide helpful information about recent developments and expectations, as can talking to competitors at trade shows. When an enterprise actively enforces its IP it is less likely to face litigation from a competitor. It sends a message to competitors that it is serious about protection.
31
jun/jul 2014 today’s gener al counsel
Intellectual Property
32
To ensure maximum protection of IP, enterprises should use knowledgeable legal practitioners that are keeping up with the current laws in the jurisdictions they plan to penetrate. While this is less problematic for the experienced enterprise IP team, the fact remains that many inventors may rely on poor legal advice. They may not, for example, understand the implications of the first-to-file rule that has been the law in the U.S. since March 2013 as part of the Leahy-Smith America Invents Act. Although other countries may also have first-to-file rules, their other legal requirements for patenting, including the issue of what constitutes “disclosure,” may be significantly different. Enterprises that understand the significance of inadvertent disclosure also ensure that their legal team works closely with their R&D and marketing teams before making any information public. Failure to do so can be costly. For example, a large IP law firm received an urgent call from a client just 24 hours before a presentation in Japan. Due to a lack of communication among product, legal, and marketing teams, the enterprise needed a patent application translated and filed before disclosure to avoid losing its patent rights in various countries. Under duress and at significant additional expense, the IP law firm completed the request, but this fire drill was a costly misstep. Another component of managing IP litigation risk is the selection of a service that can provide quality translations of highly specialized documents during the prosecution of patents in a foreign jurisdiction. Initial applications and each subsequent translation must be more than just technically accurate. What is a quality translation? Dr. Alan K. Melby of Brigham Young University Translation Research Group, who works with the International Organization for Standardization (ISO), defines it this way: “A quality translation (1) demonstrates required accuracy and fluency (2) for the audience and purpose and (3) complies with all other negotiated specifications, taking into account end-user needs.” Patent translations that use consistent and precise terminology are key to protecting IP globally. Even one misused word can result in costly delays and office
actions during patent prosecution, and leave enterprises vulnerable to litigation. All patent terminology developed when creating the initial patent application must be translated precisely and used consistently with foreign patent filings, as well as downstream in additional processes required to bring an invention to market. Technologies such as terminology management and translation memory also allow for consistent language and terminology to be used throughout the entire regulatory and compliance process. According to research by Dr. Alexander Wurzer, director of the Steinbeis Institute for IP Management, the consequences of an incorrect translation potentially include these four negative outcomes: office actions that can be fixed, but are time consuming and expensive; a reduced scope of protection that is not fixable post-grant; unclear situations that leave enterprises dependent on a judge’s decision; and invalidation. Here are some things to keep in mind when looking for an IP translation service provider. They relate to three basics: people, process and technology. • People: Employ specialized teams that include in-country native linguists with subject matter expertise in the applicable technology, as well as experience in patent language and processes that carefully and precisely translate foreign patent filings. The right translators produce quality documents that lead to clarity and hold up through prosecution. For example, while European translations of chemical names can look very similar to English, only an experienced chemist fluent in Chinese could employ the proper Chinese equivalent translation. One single letter different in English, such as the difference between “methyl” and “ethyl” in a long chemical name, changes the entire name of the chemical in Chinese. Having the wrong chemical in the translation will likely render at least that portion of the patent unenforceable. • Process: The traditional translation model, which relies on trust and old networks, is broken. No matter how experienced the translator is, the translation quality is limited by the inability to collaborate and communicate about the quality
of the patent application across languages. For example, errors found in one language may not be corrected in other languages. By implementing a centralized (or huband-spoke) model that streamlines translations and project management, enterprises can improve consistency and transparency. • Technology: Machine translation can play a role, and investing in technology-aided human translation is the most efficient way to manage IP translation. Technologies such as translation memory and terminology management contribute to the speed of translation, as well as consistency and value. Translation service providers that specialize in patent translations will have terminology management systems that will help facilitate the technical intricacies of patent translations, keeping track of terms that may be less common or which need to remain consistent across multiple languages. Ultimately, implementing best practices internally and using service providers who apply best practices for translating IP documents will help ensure overall quality. ■
Michael Sneddon is president and CEO of MultiLing, which provides IP translations and related services for foreign patent filings by Global 500 legal teams. He started the company in 1988. He is an attorney and member of the American Intellectual Property and Law Association (AIPLA). Mvsneddon@multiling.com
Stuart Hinckley is general counsel for MultiLing. A graduate of Brigham Young University’s J. Reuben Clark Law School, he has more than 30 years of experience in corporate and business law. info.law@multiling.com
today’s gener al counsel jun/jul 2014
Intellectual Property Digital Trade Secrets continued from page 29
on their own or on behalf of competing companies. Companies need to be aware, as well, of “hacktivists” who steal information for political or social reasons, and others who may not be profit-driven, but nonetheless damage the company by obtaining confidential information. What can a company do to limit exposure to trade secret theft? Governments around the world are grappling with the issue by drafting new laws and negotiating new treaties, but these mechanisms move slowly. In the meantime, there is much that companies can and should do to comprehensively assess their trade secrets, identify their vulnerabilities and put in place effective measure to stave off threats. The CREATe-PwC report lays out a five-part framework to help businesses do just that. To best protect those trade secrets whose theft would cause the most harm, companies should first document, locate and inventory their trade secrets. The first level of the framework walks the organization through the basic, critical step of identifying and categorizing its trade secrets. The result is an inventory from across the organization, as well as procedures to update the inventory as the company designs new technologies or takes on new ventures. The second step is an evaluation of the threat to the specific company and sector, across countries where the company operates. Does the threat come from nation states, competitors, malicious insiders, transnational organized crime, hacktivists – or some combination of these actors? To illustrate how the framework is applied, the report tracks ABC Widgets, Inc., a fictional U.S.-based alternative energy company with global operations: “…ABC analyzes the various threat actors that may impact its operating environment and the risk they pose, paying particular attention to the probability
and potential severity of a breach. With ABC’s leading market position in the industry, it suspects certain threat actors (i.e., malicious insiders, nation states) warrant closer attention and monitoring due to recent data breaches resulting in the theft of intellectual property at ABC’s competitors in locations where ABC also has production facilities.” The company then looks at its financial, technological and operational systems and assesses the vulnerabilities in each. These vulnerabilities can range from a lack of training on information security to employees using software without routinely checking for updates, to the existence of a highly valuable trade secret stored on an unsecured server with broad access within the company, to a lack of employee awareness regarding where trade secrets are kept. SET PRIORITIES, MAKE INVESTMENTS
It is generally impossible, and certainly impractical, to build impermeable security for all company information. The framework provides a systematic way for the company to allocate resources to make the greatest impact. Steps three and four of the framework provides a means of ranking trade secrets for their value and assessing the potential loss in the event of their theft. These losses include immediate economic impact and loss of market share, as well as indirect effects such as a loss of customer confidence due to the security breach. Together, these steps help provide a basis for the final step – improving the company’s trade secret management system – from the perspective of return on investment. In the case of ABC Widget, the analyses culminated with a plan for action in three areas: • The IT department would increase security by establishing new servers and firewalls and ensuring all software is routinely updated. • Product development teams would develop plans to segregate and limit
access to source code to mitigate the loss from any one theft. • Public relations and customer service teams would design emergency protocols for responding quickly and communicating a trade secret theft incident, with the aim of mitigating adverse impact on confidence among customers and key stakeholders. The framework laid out in the CREATe-PwC report empowers companies to act individually to strengthen safeguards in a competitive economy where each new advance in technology brings new potential vulnerabilities. The report also makes the case that companies and industries can and should also use their findings to contribute to a broader discussion about trade secrets. As individual companies invest time and resources to measure and protect their own trade secrets they can help build a comprehensive picture of collective value and threats. As the report says, “The challenge of trade secret theft is too large for any one government, company or organization to deal with alone – only a collective focus on this issue will help improve innovators’ ability to secure their most critical information and intellectual property.” ■
Pamela Passman is founding president and CEO of the Center for Responsible Enterprise and Trade (CREATe.org), a nonprofit working with companies and supply chain partners to protect intellectual property and prevent corruption. Previously, she was Corporate Vice President and Deputy General Counsel, Global Corporate and Regulatory Affairs, at Microsoft Corporation. Prior to her 15 years at Microsoft, she practiced law with Covington & Burling in Washington, D.C. PPassman@create.org
33
jun/jul 2014 today’s gener al counsel
Intellectual Property
New Web Domains Raise Risk of Cyber-Squatting By Jan corstens
34
W
ith new web domains steadily beginning to appear online – including .London, .guru and .sexy to name just a few – businesses need to act quickly to defend their brands from infringement. During the most recent meeting of the Internet Corporation for Assigned Names and Numbers (ICANN) in Singapore, in March, the Trademark Clearinghouse revealed that more than 500,000 Claims Notices had been downloaded. Claims Notices are sent as a warning to
anyone attempting to register a domain name that matches a trademark term already recorded in the Clearinghouse. Even though fewer than 70 of the 1,300 Top-Level Domains (TLDs) applied for are live and accepting registrations from the general public, the number of warnings issued indicates a high level of interest in trademarked terms from third parties. Some of the largest and most wellknown U.S. brands are unprepared for the roll out of new web domains. According to Interbrand’s “Best Global
brands 2013” list, 48 percent of the top 50 brands are currently not in control of several key domain names already available. More specifically, brands in the food and beverage space were most at risk of being cyber-squatted, with pepsi. us, and kellogs.net found to be under the control of an unofficial third party. What makes this data even more troubling is the fact that 84 percent of those top 50 brands have already filed suits against third parties infringing on their intellectual property online.
today’s gener al counsel jun/jul 2014
Intellectual Property For a more dramatic look at how cybersquatting is affecting businesses today, consider court cases that are being filed against third parties looking to generate a profit in the existing online landscape. One example involved real estate mogul Donald Trump filing a suit against an individual from Brooklyn for falsely registering trumpmumbai.com, trumpindia.com, trumpbeijing.com and trumpabudhabi.com. Trump was award $32,000 in damages. In the luxury retail space, both Salvatore Ferragamo and Gucci ended up winning court cases against multiple third parties deceptively using their brand names, and Burberry and Tommy Hilfiger are now facing potential brand infringement from unknown third parties who have registered both brands under the new .clothing TLD. Another very recent complaint was filed against the domain names IBM. guru and IBM.ventures. Those domains have now been suspended from use due to fraudulent activity.
In the end, court cases only end up costing businesses time and money. The best way to avoid litigation at all is to actively take advantage of the protections offered by the Trademark Clearinghouse as soon as possible. The challenge of cyber-squatting in the context of hundreds of new web domains entering the online space can certainly be daunting, which is why the Trademark Clearinghouse was created. Launched in March of 2013, it currently offers protection to more than 10,000 brands and businesses. More than 28,000 trademarks have been recorded within its database. Today, it effectively deters cybersquatters from registering protected terms, provides an ongoing notification service which is not time-limited, and serves as protection for previously abused terms. Together with the Uniform Rapid Suspension System (URS) and UDRP – both designed to resolve conflicts around the registra-
tion of new web domain names – the Trademark Clearinghouse completes ICANN’s rights-protection toolbox, and is the first line of defense and most cost-efficient way to assert trademarked rights. Through proper education and a clear understanding of the protections now in place, trademark owners and agents can position themselves well to avoid potential infringement, in the face of the Internet’s biggest transformation yet. ■
Jan corstens, a partner in the Deloitte Belgian office, leads a team of experts in Contract Risk and Compliance services. He has performed and managed multiple royalty and IP audits in software, hardware and technology.
35
Discovering the right information can seem like an endless task. Viewpoint makes it simple. Viewpoint™ by Lateral Data, a Xerox company, streamlines e-discovery from beginning to end. By managing the entire flow, you get fast, defensible results with one seamlessly integrated software solution. As the leader in business process and document management, we simplify e-discovery so you can focus on your core business. 877-273-3887 xerox-xls.com/viewpoint
©2014 Xerox Corporation. All rights reserved. Xerox®, Xerox and Design® and Ready For Real Business® are trademarks of Xerox Corporation in the United States and/or other countries. Viewpoint is a trademark of Lateral Data, A Xerox Company.
xerox_AprMay14.indd 1
3/24/14 9:39 PM
JUN/JUL 2014 TODAY’S GENER AL COUNSEL
Intellectual Property
36
TODAY’S GENER AL COUNSEL JUN/JUL 2014
Intellectual Property
Patent Eligibility of 3D Printed Organs Will Soon be an Issue By Craig C. Martin and Sara Tonnies Horton
B
iotech companies, technology companies and scientists are working on a breakthrough that could allow specialized 3D printers to create human organs, a process known as “bioprinting.”
combinations thereof, vary depending on the type of organ or tissue to be printed. Next, the printer deposits the bio-ink in thin layers through printing nozzles onto a platform to create the final product.
Scientists already have printed blood vessels, a variety of organ tissues and a functional ear. 37 Scientists already have printed blood vessels, a variety of organ tissues, and last year Princeton University scientists printed a functional ear. Should the scientists and companies who manufacture ears and blood vessels be able to obtain patents on these objects even though they already exist in nature? The interplay between these new technologies and patent laws are unclear and ripe for examination by the courts. Bioprinting is the process of creating human tissue and organs using a 3D printer. Bioprinted tissue and organs could be used for research, drug development and testing, and even at some point, organ transplants. The process works as follows (much simplified): First, a computer model or scanned image of the tissue or organ is loaded into the 3D printer to create a blueprint of the object. Second, living cells are mixed with a gel to create bio-ink for the printer. The types of cells used for bio-ink, or
Following the printing of the tissue or organ, additional steps may be needed to solidify and incubate the printed tissue or organ. PATENT ELIGIBILITY
The United States Code allows for patents on “any new and useful process, machine, manufacture, or composition of matter.” Human organisms and products of nature are not patent-eligible, but variations of naturally occurring organisms to create new organisms may be. (See the Supreme Court’s 2013 decision in Association for Molecular Pathology v. Myriad Genetics, Inc., and a 1980 case, Diamond v. Chakrabarty.) Indeed, the U.S. Patent and Trademark Office has granted numerous patents for inventions related to human genes and naturally occurring phenomena. However, over the last several years, the validity of these patents has come into question. In Myriad, the Supreme Court decided whether a naturally occurring DNA segment could be patented. A research
jun/jul 2014 today’s gener al counsel
Intellectual Property laboratory had obtained patents covering the precise location and sequence of certain genes. Mutations of those genes can increase the risk for breast and ovarian cancer. The genes are naturally occurring. However, their precise location was unknown before the invention Myriad patented.
not a product of nature but rather a product of human manufacture and innovation. While bioprinted organs may seek to replicate the design, shape and function of human organs, the composition and manufacture require highly scientific methods and precise machinery.
composition of such organs and tissues may form the basis for future patent applications. While it is clear that an application for a patent for a human liver should be denied, it’s not clear whether an application for a lab-created liver that resembles and functions like a human
Would an application for a lab-created liver, which resembles and functions like a human liver, be denied?
38
Several years after the USPTO awarded patents covering these genes, petitioners brought suit seeking a declaration that the patents were invalid because they did not cover patent-eligible subject matter. The Supreme Court held that the isolated naturally occurring DNA segment was not patent eligible, reasoning that the research laboratory “did not create or alter any of the genetic information encoded in genes” and that “[t]he location and order of the nucleotides existed in nature” before the research laboratory found them. The research laboratory also obtained a patent on complimentary DNA (“cDNA”), which is synthetically created DNA. The Supreme Court held that cDNA was not a “product of nature” and thus was patent eligible. The Court’s reasoning in Myriad hints that whether the subject matter is an unknown but natural phenomenon, or a manufacture or composition of a matter that does not occur naturally, should be the touchstone of such decisions. BIO-PRINTED ORGANS
With the advance of science in this area, and several companies competing to perfect bioprinting of organs and tissue, the patentability of such objects is up for discussion. Echoing the Court’s finding in Myriad regarding cDNA, proponents argue that bioprinted organs are
Furthermore, proponents of patents in general argue that patents spur innovation by rewarding inventors of new and useful products. Scientists and companies currently researching and creating the process to bioprint organs and tissue have spent considerable time, energy and resources to create technology that may one day transform the process of drug development and organ transplant. Proponents argue that they should be rewarded with patents for this work. Opponents of the patents in Myriad argued that even synthetically created DNA should not be patentable, because it is not invented and not “markedly different” from what occurs in nature. Because bioprinted organs seek to replicate human organs, and even use human cells as building blocks, opponents may likewise argue that bioprinted organs are not markedly different from what occurs in nature, and in fact are designed to mimic human organs and therefore cannot be patentable. Opponents also would likely argue that patents covering this technology would stifle innovation and access to better medical treatments, because patent monopolies would foreclose future innovation and development of the bioprinting technology. Both the process of creating a bioprinted organ or tissue and the
liver should be denied. It remains to be seen how the USPTO and courts will approach these issues. Patentability will likely rest on what the applicant seeks to patent – the method to create the bioprinted organ or tissue, the bioprinted substance, or the organ itself. ■
Craig C. Martin is a partner in Jenner & Block’s Chicago office and co-chair of the firm’s Litigation Department. He practices in complex civil and commercial litigation involving intellectual property, civil and criminal antitrust, shareholder class action and derivative actions, and other substantive areas of the law. cmartin@jenner.com
Sara Tonnies Horton is a partner at Jenner & Block. She has significant experience with intellectual property issues, with an emphasis on patent litigation and related counseling. shorton@jenner.com
The Magazine The six-time yearly publication, with strategies, best practices and analysis written by expert practitioners within the legal profession, offers an excellent branding opportunity to 58,000 qualified subscribers.
T ODAYS G ENER A L C OUNSEL .C OM / SUB S C R IBE
jun/jul 2014 today’s gEnEr aL counsEL
Labor & Employment
NLRB Puts “Ambush Elections” on the Fast Track By Mark Carter
40
O
n March 31, 2014, National Labor Relations Board Chairman Mark Pearce refused the request of the chairman of the Committee on Education and The Workforce and the chairman of the Subcommittee on Health, Employ-
ment, Labor and Pensions for a modest 30-day extension of the comment period on the controversial “representation case procedures” rule submitted by the Board. The rule is better known in management circles as the “ambush election” regulation.
The NLRB Chairman suggested that interested parties simply rely on previously submitted comments. The Board “will consider all comments and oral testimony submitted in response to the June 22, 2011 (Notice of Proposed
today’s gEnEr aL counsEL jun/jul 2014
Labor & Employment Rulemaking),” he said. “So it is unnecessary for any person or organization to resubmit any report or argument ...” Thus the NLRB has clearly placed the finalization of the regulation on a fast track and, as NLRB Chairman Pearce previously voted for the regulation in its earlier form, it is evident he intends to complete the job as soon as possible. What would the ambush election regulation do? At its core, it is designed to dramatically shorten the period between the filing of a representation petition to unionize a workforce and the election and certification of the petitioning union. Currently, it takes at least 25 days from the date of a petition to hold an election to certify a union. In practice, the NLRB has reported that the majority of election periods are held within the goal period of 42 days. The regulation removes the 25 day minimum period and would pave the way for election periods in as little as 14 days. Beyond that, the regulation eliminates the right of an employer to make pre-election appeals of critical rulings on the composition of the unit of employees eligible to vote. It requires a hearing on pre-election issues within seven days of the filing of the petition, and it prohibits employers from raising issues on appeal, concerning the petition of the union, that it failed to identify in that hearing. It requires the employer to file a comprehensive “statement of position” at the pre-election hearing. And, among other new obligations, it requires that before the election the employer provide the petitioning union with employees’ email addresses and telephone numbers, along with mailing addresses, as required now. This regulation is not new. It was originally proposed in June 2011. However, in May of 2012 the D.C. District Court invalidated the rule because only two members of the NLRB voted to finalize it. That decision was appealed by the NLRB to the D.C. Circuit Court, but in January of
2014 the NLRB, seeking to make the appeal moot, withdrew the proposed regulation. On February 6 the NLRB filed a notice of proposed rulemaking seeking to finalize the regulation again. The NLRB did not unanimously endorse the rule. The U.S. business community is justifiably very concerned about the regulation, and so too is leadership in the House of Representatives. Chairman John Kline of the House Education and The Workforce Committee wrote that the proposal “gives employers only seven days to find legal counsel and appear before an NLRB regional officer at a representation hearing. During that brief period of time, employers will have to identify every possible legal concern or basically forfeit the ability to raise additional concerns during the course of the hearing. The rule also delays answers to important questions such as determining the appropriate bargaining unit and voter eligibility, until after workers have voted. “Additionally,” Kline said, “the proposed rule jeopardizes worker privacy by delivering to union organizers employees’ names, home and email addresses, work schedules, and other personal information. It’s been almost three years since this proposal was first introduced and it is just as bad now as it was back then …” In a Feb 6 dissent from the NLRB’s notice of proposed rulemaking, Board members Phil Miscimarra and Harry Johnson wrote that the proposed regulation would create a “vote now, understand later” election climate, and that it “advocates a ‘cure’ that is not rationally related to the disease.” As a member of the bar, Miscimarra filed comments objecting to the proposed regulation, citing the agency’s own statistical data: “In fiscal year 2010,,” he wrote, “the average time from petition to election was 31 days … unions have prevailed in a majority of elections (where there was no incumbent union) every year from fiscal year 1997 to the present. And the margin by which unions prevailed in
these elections has increased from 50.4 percent to 64.8 percent …” One of the practical impacts of the regulation is that employers will not have a meaningful opportunity to exercise their rights under the law. The National Labor Relations Act itself protects an employer’s right to engage in a dialogue with its employees about the prospect of unionization. Section 8(c) of the law expressly permits employers to share facts, concerns and personal experiences associated with union workplaces. Employers who are forced to retain counsel, prepare for hearings, divulge information to a union and prepare for an election in the span of a two-week period will be severely challenged to address the campaign rhetoric of a union. Indeed, that appears to be a basic motivation for the regulation, which will create a state of affairs that enhances the likelihood that the employees will vote for union representation. The NLRB majority, composed of Pearce, his former clerk and a former AFL-CIO staff counsel, likely will agree and rush to finalize the regulation. Then it almost certainly will be challenged in the courts, as it was in its previous iteration, based on a variety of arguments. However, absent an immediate injunction prohibiting its enforcement, employers in non-union workplaces should be prepared to respond with unprecedented speed to a petition for a union election. ■
Mark Carter is chair of the Labor Practice Group at Dinsmore & Shohl LLP and a member of the Editorial Advisory Board of Today’s General Counsel. He was previously appointed by President George W. Bush to the Federal Service Impasses Panel. His practice focuses on traditional labor law. mark.carter@dinsmore.com
41
jun/jul 2014 today’s gEnEr aL counsEL
Labor & Employment
42
Permissible Limits On Employee Social Media By Lisa E. aguiar and Julian Pardo de Zela
W
ith the advent of social media, such as Facebook and Twitter, there has been an explosion of online commentary by employees regarding their employers and the nature of their employment. Sometimes this commentary is critical of the employer, damaging its reputation or image. For employers, this raises an important question: When do an employee’s criticisms, complaints, or derogatory statements constitute protected activity, and when are there proper grounds for discipline or termination? The answer hinges on several recent opinions by the National Labor Relations Board, which under the National Labor Relations Act (NLRA) issues and enforces rules applicable to virtually all private sector employers, both union and non-union. Employers like Costco, Tar-
get, and General Motors have responded by rewriting their social media policies. All employers should take note. The general rule is that employee communications critical of the employer or fellow employees are protected, provided the communication is intended to generate conversation about working conditions or group action towards the employer: Under Section 7 of the NLRA, employees have the right to engage in “concerted activities” for “the purpose of collective bargaining or other mutual aid or protection.” Employees are free to discuss working conditions, benefits or wages, without discipline or termination by their employer. This includes traditional communications, like those made around the office water cooler, as well as Facebook posts, blogs, or tweets. Communications
are protected, regardless of the medium, if they are intended to generate conversation about the conditions of employment or the potential for group action towards the employer or employment. For example, five employees posted on Facebook, criticizing a coworker who intended to meet with a supervisor to complain about the work performance of the five employees. These posts constituted explicit or implicit criticism of the manner in which the reporting coworker was performing her job, and therefore were protected. And because of their social media posts, the termination of the five employees was unlawful. Employee communications that are critical of the employer are not protected where they merely constitute griping or venting and / or do not encourage concerted activity. The purpose of the NLRA is to
today’s gEnEr aL counsEL jun/jul 2014
Labor & Employment protect employees who want to push for improvements in the workplace or how employees are treated. Communications are therefore protected when directed at coworkers or supervisors, who are in a position to respond to calls for improvements in working conditions, benefits, or wages. “Concerted activity” implies efforts to coordinate the actions of two or more people involving the workplace. Employees are not protected if they complain on social media to people who are not coworkers or supervisors. An example would be an employee on Yelp complaining to prospective customers that his employer’s restaurant does not serve good quality food. This “individual gripe” cannot constitute concerted activity. The commentary is not directed to co-workers or management, and it is not intended to encourage changes in the employer’s policies. Likewise, an employee’s post to all his Facebook friends, “My company stinks” would not be protected. This is not concerted activity. It’s just complaining. There is a fine line between “venting” and engaging in “concerted activity.” The reason the employee posted the negative comments is critical. “Rants” or general complaints, which do not encourage improvement in working conditions, will not constitute protected communications. Where an employee posted a comment on Facebook that her employer did not appreciate its employees, several of the employee’s relatives and friends commented on the post. None of the employee’s coworkers did so. The employer’s termination of the employee was lawful because the Facebook post didn’t appear intended to encourage co-workers to engage in group action. Employee communications are not protected when they reveal trade secrets, proprietary information, or defame other employees or supervisors. The following examples would not constitute protected communications: • An employee, upset about low wages, posts the employer’s secret formula for making its most popular dish. • An employee posts something untruthful about her employer or supervisor – for example makes a false claim that the employer is cheating customers.
• An employee criticizes a coworker or supervisor about a topic unrelated to work. For example, an employee claims the car accident a supervisor had while vacationing was likely the supervisor’s fault because he is a bad driver. The bottom line is that employees have the right to talk about working conditions, whether while in the break room or at home from their personal computer. But employees do not have a right to post confidential company information, nor can they libel or slander someone or discuss individuals not related to the work environment. An employee’s communications are not protected where they are not directed to coworkers and not intended to encourage the coworkers to engage in group action regarding working conditions, benefits, or wages. An employee’s private communications on social media also are not protected merely because they are made outside the workplace. Employees may find this counterintuitive. Employers must make an effort to convey this message to employees. A wellarticulated social media policy needs to make clear that employees may be held accountable for disparaging or critical commentary made even while sitting in front of their own computer at home. There are steps employers can take to strike the proper balance. Employers should make sure their social media policies are narrowly tailored. Policies that are too broad may violate the NLRA, when employees feel they are prohibited from exercising their rights to engage in “concerted activity.” Policies should prohibit only non-protected communications, rather than setting forth across-the-board restrictions. An unlawful policy would be to prohibit employees from posting statements that harm the company’s reputation, consist of “disrespectful conduct and language” or in any way “depict” the company over the internet without permission. The National Labor Relations Board found Costco’s social media policy was overly broad, where it prohibited postings that “damage the company” or “any person’s reputation.” Similarly, General Motors went too far with gen-
eralized prohibitions of conduct that is “offensive, demeaning or inappropriate.” Both companies’ social media policies would unlawfully prohibit protected criticisms of the employer’s labor policies or treatment of employees. On the other hand, Walmart struck the right balance where it prohibited discriminatory remarks, harassment, threats of violence or unlawful conduct. This formulation still allows employees to engage in concerted activity to improve working conditions. Don’t say employees are prohibited from “damaging the company.” Instead, say their communications cannot consist of threats of violence, harassment, or disclosure of trade secrets, customer lists, product roll-out dates, etc. The law of social media is constantly evolving, and it’s important to stay informed about recent developments. And by all means, if you are considering termination for behavior that includes postings involving working conditions, supervisor’s conduct, or terms and conditions of employment such as wages, hours, and overtime, first consult with legal counsel. ■
Lisa E. Aguiar is of counsel in the San Jose office of Ropers Majeski Kohn & Bentley and a member of the firm’s Labor and Employment practice area. She counsels and represents employers and governmental agencies on all aspects of their employee relationships, including hiring, compensation, management problems and technology policies. laguiar@rmkb.com
Julian Pardo de Zela is a senior associate in the Labor and Employment practice area of of Ropers Majeski Kohn & Bentley, based in San Jose. jpardodezela@rmkb.com
43
jun/jul 2014 Today’S Gener al CounSel
TGC Surveys
Cybersecurity Management 2014 A Today’s General Counsel Survey The survey, conducted in April, sought data regarding trends and attitudes toward cybersecurity among Today’s General Counsel readers. Thirty six percent of respondents were from organizations with 5000 or more employees. About 2/3 of respondents came from legal departments with fewer than 10 lawyers. How susceptible to security breaches is your organization’s industry? A Key finding: Forty-five percent felt their
very susceptible
45%
Not very susceptible
31%
at very little risk
18%
industry was very susceptible to security breaches. The larger the department or organization, the higher the percentage of respondents who indicated their industry was very susceptible.
44
other
6%
Perceived breach susceptibility by department size and organization size. overall 1 to 9 lawyers 100 to 499 emPloyees 10 to 99 lawyers 500 to 4999 emPloyees 1 to 99 emPloyees 5000+ emPloyees
70% 60% 50% 40% 30% 20% 10% 0% Very susceptible
Not very susceptible
At very little risk for
Other
continued on page 47
Today’S Gener al CounSel jun/jul 2014
TGC Surveys
Survey Shows Awareness of Standards Lagging
E
dward Snowden, runner-up to Pope Francis for Time Magazine’s Person of the Year, is still the poster boy for data breaches, but when corporate executives ponder that topic the name that probably comes to mind is Gregg Steinhafel. The former Target CEO resigned on May 15, a casualty of the data breach that hit Target last December. Up to 40 million shopper credit card details and 70 million customers’ personal data were compromised by hackers, who reportedly sold the information to criminal organizations in Europe. The day before Steinhafel resigned, 90-plus lawyers who had collectively filed more than 140 lawsuits against Target wedged themselves into U.S. District Judge Paul Magnuson’s office in St. Paul for a case management confer-
In response to the Snowden data breach, and pursuant to an Executive Order by President Obama, the National Institute of Standards and Technology released a set of recommendations in February, called the Framework for Improving Critical Infrastructure Cybersecurity. The accompanying press release said that organizations, regulators and customers should use it to create and assess cybersecurity programs. About one-third of respondents to the recently completed Today’s General Counsel Survey on cybersecurity had never heard of the NIST Framework. Another third had heard of it but hadn’t read or reviewed it. Could failure to acquaint themselves with the Framework’s recommendations increase their organizations vulnerability to lawsuits in the event of a data breach?
Certified Information Privacy Professional. “Plaintiffs attorneys can certainly use that to their advantage.” On the other hand, companies that comply with the NIST standards might be able to turn that to their own advantage, according to Thompson. He notes that lax data security practices are often cited as the basis for fines imposed by government regulators. “So one would hope that certifying to a standard such as NIST would reduce exposure to sanctions,” he says. Lack of awareness about the Framework on the part of in-house attorneys isn’t surprising, according to Brian Brown, Vice President Technology and Security, RenewData. “Standards like the NIST take time to gain visibility and traction,” he says. “We were a part of the working
Case law and public opinion may quickly raise the NIST Framework to the level of a standard of care in claims. ence. “I’m beginning to learn this data breach business is quite a cottage industry,” Magnuson quipped. He also put Target’s defense team on notice that the “big, long, indefinite stays” they hoped for were not in the cards. Failure to take appropriate safeguards is the underlying allegation in most of the lawsuits Target faces. That will certainly be the premise of lawsuits over data breaches to come, most of them in the health and credit card industries if the past is any guide (“some major breaches are about to be announced,” says Ron Plesco, a Principal at KPMG), but the notion of what safeguards are appropriate is evolving almost as rapidly as the hacker’s craft.
“In short, yes,” says Ron Plesco of KPMG, a board member of the National Cyber Forensic Training Alliance. “Organizations and their legal departments need to pay attention to the Framework, because it could quickly become a de facto standard of care that plaintiff’s counsel will attempt to use as a basis for tortious claims.” The framework is not a regulation or standard itself, Plesco explains, but case law and public opinion may quickly raise it to the level of a standard of care in claims. “I do expect the adequacy of data security practices to be a growing concern in civil litigation like the class action suits against Target,” says Merton Thompson, a litigator at Burns & Levinson and a
groups put together to develop the NIST framework. It can be successful, but it will take awareness, training, and adoption before it will spread widely.” More than two-thirds of respondents to the survey indicated that their organization devoted less than 20 percent of its IT budget to cybersecurity, with the largest number of respondents saying they spent between six and 10 percent of IT on cybersecurity. Is the percentage of IT budget spent to make data secure a reasonable measure of how seriously the threat is taken? Is it a measure of how effective whatever steps are being taken might be? continued on page 46
45
jun/jul 2014 Today’S Gener al CounSel
TGC Surveys
Awareness of Standards Lagging continued from page 45
It is not the best barometer, according to Mary Galligan, director, Cyber Risk Services, Deloitte & Touche. “Any amount of money spent on cybersecurity could be inefficient if it is being spent in the wrong areas,” says Galligan, who is former special-agent-in-charge of cyber investigations in the New York region for the FBI.
plan,” says Plesco. “Start with information asset classification, and a risk decision as to what information will be made available on what devices. Once identified, the companies can then decide what investment in security they need to make to protect that data on the device.”
The decisions companies must make about what type of information is allowed on mobile devices are especially tough.
46
Asked for an example of inefficient spending, Galligan mentioned allocating funds to security that might be better spent on obtaining actionable threat intelligence and putting the right monitoring systems in place. She also advocates investing in being resilient and able to quickly respond and recover from an event. “That is as important as the other aspects of cybersecurity,” she says. Plesco of KPMG expects the pressure on spending to increase because of recent high profile breach events. “Nevertheless, the correlation of spend to risk is misleading,” he says. He suggests more attention to threat analysis and protection. Invited to comment, several survey respondents mentioned that the threat posed by mobile devices was the gravest one their organization faced. “Those devices are a node on their network, and depending on how they are configured, need to be classified as part of an overall enterprise security
The decisions companies must make about what type of information is allowed on mobile devices are especially tough, according to Galligan of Deloitte & Touche. Mobile
permitted at all in certain parts of the world,” says Galligan. Proper data safeguards, threat assessments and intelligence are necessities for all organizations, but given the technological sophistication of hackers, and the potential payoff if they can steal data, breaches will occur regularly. Insurance is the only reliable strategy for avoiding a financial disaster. The 2011 data breach that hit Sony’s PlayStation network may be the most costly such event so far, and the damage was compounded by a common error the company made about its insurance. “The breach affected tens of millions of PlayStation accounts,” says Thompson, “and the costs for the forensic investigation and then notifying the consumers and providing credit monitoring for them was likely near $100 per account. Sony looked to its insurer for coverage for damage from a criminal act under their standard policy, but the claim was denied because the company did
Asked for an example of inefficient spending, one consultant pointed to the allocation of funds to security that might better spent be on obtaining actionable threat intelligence. device technology, and the appetite and demand for devices, continues to grow faster than organizations’ ability to vet potential risks. “Proper governance and policy decisions must include whether to institute a ‘bring your own device’ protocol, what types of applications can be downloaded to a mobile device, and if devices should be
not have cyber-risk coverage. The issue is being litigated now, but the lesson is obvious. Don’t look to your standard coverage. Cyber-risk insurance is maturing as a product and it is widely available. If you have exposure through, for example, a large number of consumer files, you should insure accordingly.” ■
Today’S Gener al CounSel jun/jul 2014
TGC Surveys
Cybersecurity Management continued from page 44
Percent of respondents who report they have experinced a cyber breach. Almost half the respondents reported their organization had experienced a breach. Percentages were higher in larger organizations. Asked whether the breach resulted in litigation, more than 80 percent said it had not. 70% 60%
61%
57%
50% 40%
44%
41%
40%
30% 19%
20% 10% 0% 1 to 9 lawyers
10 to 99 lawyers
Asked how familiar they were with the recently published
1 to 99 employees
100 to 499 employees
500 to 4999 employees
5000+ employees
How familiar are you with NIST’s recently published Framework for Improving Critical Infrastructure Cybersecurity?
NIST framework for a cybersecurity infrastructure,
32%
31%
about one-third of respondents
21%
said they had never heard of it,
16%
one-third had heard of it but had not read or reviewed it, and one-third had read it/reviewed it, or were already
Heard of it, but have never reviewed
Never heard of it
Have read/ reviewed it
We are using, or plan to use it
using or planning to use it. Respondents planning to use NIST’s framework for cybersecurity infrastructure by department or organization size. 34% 26%
24% 16%
13%
9% Overall
1 to 9 lawyers
10 to 99 lawyers
1 to 99 employees
8% 100 to 499 employees
500 to 4999 employees
5000+ employees
47
jun/jul 2014 Today’S Gener al CounSel
TGC Surveys
Tips From Experts On Cybersecurity
To whom does the security function report? Fifty percent of respondents said it was the CIO. An additional 10 percent said the CTO. Only 4 percent identified the CLO as the head of information security. CIO
50% CEO
16%
CTO
48
10%
CFO
6%
COO
5%
Other C-Level
4%
CLO
4%
Director Level
3%
CRO
3%
“Position a server with a known security vulnerability, a so-called ‘honey pot,’ on the outskirts of your network. Cyber-criminals are constantly probing for vulnerable servers to use as access points to corporate networks. The honey pot will attract their attention without exposing the network. The data security team can analyze attacks on the honey pot, gain information about the probe, and possibly identify the point of origin.” Merton Thompson, Partner, Burns & Levinson, Certified Information Privacy Professional
“Invest the time and effort into properly training your employees, contractors, and customers about security. Build a culture that highlights security as everyone’s job.” Brian Brown, Vice President Technology and Security, RenewData
“Educate your employees. They all need to realize cybersecurity starts at their keyboards. Education about the importance of not clicking on suspicious emails and the actions they need to take if they do so is essential. Make sure that employees only have access to the information they need. Cybersecurity is not a check-the-box task or project. It is a continuous process that changes as technology and threats change. Law firms have to be especially vigilant. They have access to some of the most sensitive information in the corporate world, and properly securing that information is essential.” Mary Galligan, Director, Cyber Risk Services, Deloitte & Touche
“Prioritize your information assets. Map that to actual external threat intelligence on threat actors, and internal breach threats, and invest accordingly. Know your network, where all the nodes are, and where the perimeter actually is. In my experience in breach investigations, it’s not where you think. Link that to where your data is. Audit to make sure your network and data are where you believe them to be.” Ron Plesco, Principal, KPMG
Have you retained an outside consultant? Almost two-thirds said they had. Of these, 21 percent said that the consultant was a law firm.
Don’t know 6% No 31% Yes 62%
Percent of IT budget devoted to cybersecurity. Asked what percentage of the IT budget is devoted to cybersecurity, 44 percent indicated that it was 10 percent or less. Only four percent of respondents said that cybersecurity was 30 percent or more of the IT budget. 1% to 10%
44%
11% to 30%
18%
Don’t know
18%
It is not part of our budget
15%
30% or more
4%
Today’S Gener al CounSel jun/jul 2014
TGC Surveys
Comments from Respondents Respondents who said their organization has experienced a cyber-breach were asked to briefly describe it. Here are some of their answers:
Laptops have been stolen but they were encrypted. Stolen laptops without encryption. Lost laptop with employee data. Complete loss of data, but had backup. Lost and stolen laptops. Phishing scams.
Improper access rights for consultants and terminated employees.
We had a minor incident that disabled individual computers if the user had clicked on a link.
Access by unauthorized user to confidential information.
Ex-filtration of data.
The organization has experienced unauthorized disclosures of data due to human error (misdirected transmission, inappropriate web access) but has not experienced successful hacking or other attacks.
Customers email hacked allowing hacker to impersonate customer; other attempts to log into firm accounts, none successful. Email hacks, mass email message attacks.
We have a continuing focus on improved training and awareness, access controls and improvement of minimum necessary standards. Mobile security is our top priority. It is the gateway to our systems and we have no available way of making sure our mobile security is adequate. Software solutions can and will lie to you. We need hardware/operating systems firewall security for all our mobile devices (smartphones/tablets). If you are not a specialist, use a reputable third party consultant. Check references. This is an area of significant focus for our company in 2014. We try to lock everything down as tight as possible and be one step ahead, but we know that we will always be at risk. Everyone is at risk of a breach.
Vendor inadvertently released employee data.
It is so problematic.
DDOS caused network shutdown for hours. Software uploaded on unsecure server–resulted in 148 unauthorized downloads.
I would say we are more organized than most because, as a utility with multiple sources of generation and also transmission, we must meet NRC and NERC Cyber Security Standards.
Advanced persistent threats on mobile devices. Denial of service. Credit card fraud. Phishing. We have issues every day. The question is which ones are of concern? None, so far, of major concern. Theft by an employee of credit card data from an internal database.
At the conclusion of the survey respondents were asked whether they had any additional comments about the state of cybersecurity at their organization or in their industry. Here are some of their replies: Increasingly good awareness but still a gap in understanding around materiality and how to actually implement an effective security program, and how to interpret requirements. Industry standard remains unclear, and the importance of third parties in the security impact chain needs better understanding,
Password theft.
I am pleased that more focus is being placed on cybersecurity. It is long past due.
Accidentally released confidential information.
“When” not “if” should be the state of mind.
This is an area where I feel it’s almost impossible to be completely prepared. Makes me very nervous. ■
49
jun/jul 2014 today’s gener al counsel
Visualized Metrics Help eValuate l aw FirMs Colum n
by rees morrison
g
50
eneral counsel know a considerable amount about the law firms retained by them, the services they provide, and the fees they charge. However, those same general counsel may not know how to assemble the various kinds of data into a coherent, unified picture. For example, they may know average billing rates of their primary law firms and the number of matters worked on by those firms in the most recent fiscal year. But general counsel who believe that they can learn from the thoughtful collection and analysis of metrics may not know how to integrate those two very different kinds of facts. One method to integrate and visualize multiple metrics about law firms is known as a spider graph or a radar graph. This column describes how to prepare the data for such a graph and how to interpret the results. Assume you have collected data on the ten law firms to which you paid the most in the last fiscal year. For each of them, you know how much you paid in fees and disbursements. You know how many timekeepers billed you. You know how many matters and types of matters, such as litigation, employment, or environmental, that each firm worked on. And you know how many in-house lawyers oversaw the work of each firm. Each of those law firm attributes is
rees Morrison is an attorney and the founder of General Counsel Metrics, LLC. Based in Princeton, NJ, he has for the past 25 years consulted solely to law departments on a wide range of management challenges. He coordinates the largest law-department benchmarking database and analysis ever conducted, with more than 1000 participants. rees@reesmorrison.com
on a different scale with different units – dollars or numbers, hundreds of thousands compared to dozens, and so forth. One method to convert each of those metrics to a similar standard metric is to rank the law firms on each. For instance, on types of matters handled, the law firm that handled the most types would be ranked number ten, the firm handling the second most types of matters would be number nine, and so on. For each of the metrics you can rank your primary firms from one to ten (equal rankings for ties). A spider graph creates, for each firm, a slice that represents the total rankings of that firm on each of the attributes. If there are five attributes, each firm’s slice will have five segments. The longer the slice the higher the law firm ranked overall. In the accompanying visualization, you can see that the “wonk” firm dominates the
“gedp” firm. The scale along the upper left axis, which extends from zero to 20, indicates the total rank score for each law firm. The numbered lines correspond to the concentric circles on the graph. The color coding matches the legend at the bottom of the graph and explains which attribute is represented by which color. For a modest amount of data collection and straightforward graphical technique, a general counsel can analyze a visual index of performance for the department’s primary law firms. Obviously, which attributes are chosen to be measured, and indeed how much weight to assign to each attribute, can vary tremendously. Thus a multifaceted aspect of evaluating your law firms can be pulled together into a striking visual depiction of how embedded the firm is, how broad its services, and how it stacks up against your other important law firms. ■
coMPar Ison on tHe BasIs oF se V er a l cHar ac terIs tIc s oF ten FIrMs tHat Were Pa Id tHe Mos t, WItH a ll cHar ac terIs tIc s sHoWn as r anK .
wonk
bedp
20 bukk
wisg
15 10 5 0
nivp
cawn
jim
domu
hame Va r Ia Bl e
t o ta l
sIz e
In VoIc es
gebd Mat t er s
t y Pes
InHouse
TodaysGC Daily Newsletter The daily newsletter is a terrific advertising vehicle to reach 46,000 corporate subscribers. With a high open rate, the newsletter is unmatched as a marketing vehicle within the corporate counsel community.
T ODAYS G ENER A L C OUNSEL .C OM / SUB S C R IBE
jun/jul 2014 today’s general counsel
Mediation, SinS and StrategieS
Colum n
by Jaffe D. DiCkerson
e
mployment mediations are often stressful, tiring and unsatisfying. A marathon mediation ending in the wee hours without resolution can leave all parties with the profound feeling that it was all a waste of time, energy and money. So, what goes wrong? Having had my share of bad mediations, I can name some common problems that kill the deal, and also provide some strategies for success. First, the Five Commandments:
52
1) Thou Shalt Not Fail to Do Thy Homework. “Winging it” will never be a chapter in anyone’s playbook for success. Preparation is essential. It may be correct that “showing up is half the battle” in life, but just showing up at a mediation unfamiliar with the key facts or the law is extremely frustrating for the mediator and the opposition, both of whom you are trying to convince to see things your way. It can force the mediator to educate you and your client, which is not the mediator’s job. Prepare like you are going to trial, which is where you may end up if you do not reach a mutual agreement in mediation.
Jaffe d. dickerson is a shareholder with Littler Mendelson P.C., in Los Angeles. He has practiced in the field of labor and employment law for more than 30 years. He represents public and private sector employers in a broad range of labor and employment law issues. JDickerson@littler.com
2) Thou Shalt Not Have Unrealistic Expectations. The goal is not to win, it is to get everyone to “Yes.” Every lawsuit has a winner and a loser, but the goal in mediation is to achieve a fair settlement. It is okay to give concessions on issues that are not that important to your client but are important to the other side. It demonstrates your good faith and encourages the opposition to return the favor. 3) Thou Shall Not Bring Pessimism, Personality Conflicts and Past Grievances to the Bargaining Table. You are there to resolve a specific dispute,
not to revisit past wrongs or avenge previous offenses. Clients may want to use the mediation to air old grievances, and you may have a less than positive past track record with opposing counsel. Nevertheless, let bygones be bygones. 4) Thou Shalt Not Omit Key Players from the Process. The decision makers with settlement authority must be fully involved and engaged. Think of settlement as a window of opportunity. That window can close if those with the real power are not available to say yes at critical points in the deliberations.
TODAY’S GENER AL COUNSEL JUN/JUL 2014
5) Thou Shalt Not Bargain in Bad Faith. Trying in earnest to reach a fair resolution is essential to any mediation. Lying to the mediator, intransigence and using the mediation for pre-trial discovery are guaranteed deal breakers.
I mentioned it to the client, he simply shrugged (I don’t know what other response I should have expected). This incident taught me a valuable lesson. No client is worth a speeding ticket. By the same token, no client is worth a blemish on your professional reputation about
SUBSCR IBE TO
Intransigence and using the mediation for pre-trial discovery are guaranteed deal breakers. So what are some indispensable strategies for success? First, pick the right mediator. Select someone who will effectively communicate with the parties, work well with their attorneys, and, most importantly, have the right tools to reach a resolution. I look for a mediator who has “the three S’s.” • Smarts. Athletic coaches say you cannot coach quickness. A player either has it or not. Likewise, great mediators are quick on the uptake, have almost eidetic memories, and delight in nailing down the details. • Sensitivity. Timing is everything. Almost as important are reading and listening to the parties, managing their personalities and expectations, and recognizing what they need from a settlement, not just what they want. • Sensibility. Maintaining control throughout the mediation requires knowing what will work and what will not, and how to create an agreement that comes together and stays together. Know and be able to demonstrate the value of the case. Tough talk and pounding the table may impress your client, but it will not get you a settlement. Presenting your case effectively and persuasively, focusing on the key facts and controlling case law is what sways the opposition and gives the mediator the ammunition to move forward toward resolution. Demonstrate integrity, professionalism, and willingness to compromise. Early in my career, I got a speeding ticket racing to a client meeting. When
ethics or integrity. As an officer of the court, you have a duty to try to resolve disputes, not exacerbate them. Understand what the other side needs, as opposed to what they want. It is not just about the money, even if that is what parties focus on like a laser. For the business or employer it is also about reputation, confidentiality, establishing a precedent, and sometimes that elusive “principle.” For the employee, it is also about reputation, career damage, feeling vindicated, getting a new job or position and having someone hear his or her side. Mediation is often the employee’s first opportunity to confront the employer and say what he or she has wanted to say since the employment relationship was terminated. Until the plaintiff gets to express these often raw emotions, have them heard and validated by the mediator, and then move on, achieving a resolution is very difficult. Be creative and solution-oriented. Mediation affords a unique opportunity for the parties to work together to negotiate a resolution that is fair and acceptable to both sides, unfettered by court rules of pleading, procedures and rigid timelines. The parties can put together whatever mutually agreeable deal makes sense and works. Done right, both sides walk away feeling they gave away more than they wanted, but got what they really needed, including and especially, closure. Maybe there is even a closing handshake, a “good luck,” a “same to you,” and a satisfied 2 a.m. drive home. ■
“Informative and worth reading.” “I refer to the magazine often and the information is useful in my daily work.” “Very useful publication.”
todaysgeneralcounsel.com/ subscribe
53
jun/jul 2014 today’s general counsel
EliminatE thE antitrust ExcEption to corporatE charging guidElinEs Colum n
by Jeffery m. Cross
g
54
ood corporate governance requires a robust and effective legal compliance program. This was the key lesson of the decision by the Delaware Chancery Court in the seminal 1996 Caremark case. It held that a corporation’s board of directors could not turn a blind eye to possible violations of the law by purposefully failing to institute a program to ferret out such violations and bring them to the board’s attention. Establishment of a robust corporate compliance program was also a motivation of Congress in enacting the Sarbanes-Oxley Act. That law directed the U.S. Sentencing Commission to beef up the requirements under which a corporation convicted of a crime could receive a downward adjustment of its fine if it had a meaningful compliance program in place. Antitrust must certainly be a key component of any corporate compliance program. This is especially true today, when the Department of Justice and the European Commission’s Directorate General for Competition are leveling record fines on corporations, and – in the United States and Britain – sending top executives to prison for violations of antitrust and competition laws. Since at least 2006, the Department of Justice has had established guidelines for determining when to charge a corporation with a crime. These guidelines indicate that a factor to be considered is “the
Jeffery cross, a member of the Editorial Advisory Board of Today’s General Counsel, is a partner in the Litigation Practice Group at Freeborn & Peters LLP and a member of the firm’s Antitrust and Trade Regulation Group. jcross@freeborn.com
existence and adequacy of the corporation’s pre-existing compliance program.” In 2008, the guidelines were amended and made part of the U.S. Attorney’s Manual, but the amendments did not change the basic approach. Throughout this time, there has been one glaring exception to the consideration of a corporate compliance program in determining whether to charge a corporation with a crime. If the crime was an antitrust violation, the Department of Justice would prosecute, notwithstanding the existence
of a compliance program. I confronted Scott Hammond regarding this exception several years ago at a public forum held in Washington, D.C. by the American Bar Association Antitrust Section. Hammond was then the Deputy Assistant Attorney General for Criminal Enforcement in the Antitrust Division of the Department of Justice. His response to my question was that allowing antitrust prosecutors to consider the existence and effectiveness of a compliance program would weaken the Antitrust Division’s leniency program. Since 1993, the Antitrust Division has had a corporate leniency policy. This policy has been the centerpiece of criminal antitrust cartel enforcement in the United States. Indeed, the program has been so successful in exposing cartels that many other countries have adopted similar programs. Under this policy, the first corporation to report the existence of illegal antitrust activity will receive immunity from prosecution for the corporation, its officers and executives. There are several qualifiers under this policy, including whether the Antitirust Division has received information about the illegal activity from another source, and whether the corporation was the ringleader or originator of the
TODAY’S GENER AL COUNSEL JUN/JUL 2014
cartel. However, the policy clearly encourages a race to report a cartel. The prize is immunity. This leniency policy was strengthened in June 2004, with the passage of the Antitrust Criminal Penalty Enhancement and Reform Act. Under this law, a plaintiff in the follow-on
by the corporation in the goods and services affected by the conspiracy. In other words, the corporation receiving immunity is not jointly and severally liable for the entire cartel’s damages as would otherwise be the case. I disagree with Hammond’s rationale for the antitrust exception to the
The corporate leniency policy clearly encourages a race to report a cartel. The prize is immunity. civil treble-damage class action cases can receive only single damages from a corporation receiving government immunity. In addition, if the corporation meets certain requirements regarding cooperation, the plaintiff would receive only the actual damages sustained that are attributable to the amount of commerce done
corporate charging guidelines. I do not believe the possibility that a corporation will escape criminal prosecution for an antitrust violation because of a robust antitrust compliance program will diminish this race to report. Despite record corporate fines and enhanced jail sentences for executives, the most significant benefit of immunity
in many instances is the single damages provision of the 2004 Act. Furthermore, a corporation that uncovers an antitrust violation cannot be sure that the prosecutors will find that the compliance program meets the criteria needed to avoid prosecution. However, the first to report cartel activity and meet all of the criteria for the leniency program is almost guaranteed the benefits of immunity. Hammond recently retired after a very distinguished career as head of criminal antitrust enforcement. I hope that his successor, as well as the other leadership in the Antitrust Division, takes a long hard look at this exception to the corporate charging guidelines. The government should encourage a robust corporate compliance program, including for antitrust. Eliminating the antitrust exception to the corporate charging guidelines will help foster such programs without damaging the leniency program. ■
55
View our digital edition
D I G I TA L .T O D AY S G E N E R A L C O U N S E L . C O M
56
M&A Transactions in Bermuda and the Cayman Islands By Tonesan Amissah and Simon Raftopoulos
mental Financial Action Task Force on Money Laundering (FATF), the UN Security Council, the Basel Committee on Banking Supervision, the International Association of Insurance Supervisors (IAIS) and the International Organization of Securities Commissions (IOSCO). Broadly speaking, the regulatory objective is for businesses in these jurisdictions to know who their clients are and what they do. The precise legislation and regulation applicable to a business will depend upon the type of business and the industry in which it operates within the jurisdiction. While such laws primarily apply to financial institutions and fiduciaries, they can extend to parties such as attorneys and estate agents in certain jurisdictions. Anyone contemplating an M&A transaction in Bermuda or the Cayman Islands should expect to encounter the KYC regime at some point.
hen considering the use of offshore vehicles in structuring an M&A transaction, it is important to know what regulatory and compliance requirements apply. This article will provide an overview of two offshore jurisdictions, Bermuda and the Cayman Islands, where the requirements at times depart from the traditional models in ways that bring significant challenges as well as opportunities. We will highlight the similarities and differences between these two venues and chart a course through the confusing landscape of regulatory acronyms. KNOW YOUR CLIENT (KYC) Businesses and service providers in Bermuda and the Cayman Islands are subject to stringent anti-money laundering (AML) and anti-terrorist financing (ATF) legislation, both local and international. These include recommendations and regulatory pronouncements from the intergovern-
FOREIGN ACCOUNT TAX COMPLIANCE ACT, (FATCA) In March of 2010 FATCA was signed into U.S. law, and it’s intended to have global reach. It primarily imposes a reporting system on U.S. taxpayers holding financial assets outside the United States, requiring them to report those assets to the Internal Revenue Service. But FATCA also requires foreign
The core objective of FATCA is to ensure that U.S. tax authorities can identify all assets held by U.S. persons in foreign financial institutions and collect the appropriate tax. financial institutions (FFIs) to report certain information directly to the IRS, about financial accounts held by U.S. taxpayers or by foreign entities in which U.S. taxpayers hold a substantial ownership interest.
57
jun/jul 2014 today’s gener al counsel
The definitions of “foreign financial institution” and “financial accounts” are complex and not as obvious as one might expect. The critical point is for each business in Bermuda and the Cayman Islands to determine in which FATCA category each entity in their group structure falls, and then what aspects of their business amount to a “financial account.”
to ensure local businesses are not subject to any legal restriction preventing them from complying with the FATCA obligations to report directly to U.S. authorities. The third option is for a jurisdiction not to enter into either an IGA 1 or IGA 2, but simply leave it up to local businesses to determine whether and how to comply with FATCA.
An information request under a tax information exchange agreement (TIEAS) must relate to a specific matter and not just be part of a fishing expedition.
58
Tonesan Amissah is a partner and member of the Corporate Finance team within the Corporate and Commercial department at Appleby. She has experience in the formation and administration of corporate vehicles including local, exempted and permit companies and exempted general and limited partnerships, and also with the review and drafting of agreements and documentation for financing transactions. tamissah@ applebyglobal.com
The core objective of FATCA is to ensure that the U.S. tax authorities are able to identify all assets held by U.S. persons in foreign financial institutions and collect the appropriate amount of tax. Although FATCA is a U.S. law, other countries have begun to follow suit. The UK made FATCA a priority topic at the G8 summit in June, 2013, and championed it as a global standard. In preparation, businesses should ensure that the systems they put in place to comply with FATCA are capable of handling the same obligations in relation to persons of each country enacting similar legislation. Due to jurisdictional limits, FATCA is enforced in a number of ways much dependent on each cooperating country entering into an agreement with U.S. authorities to assist in its implementation. The incentive for compliance is high: A 30 percent withholding tax is levied on all U.S.-sourced payments to foreign businesses that do not comply with the FATCA obligations. Three methods of cooperation are available for jurisdictions seeking to become FATCAcompliant, with the chosen method determining how the businesses of that jurisdiction will report requisite FATCA information. Under the Model 1 Intergovernmental Agreement (IGA 1), local FFIs are not required to report information directly to the IRS, but instead to a local authority established in their home jurisdiction by their own government. This authority is then responsible for disclosure of the information to the U.S. authorities. The Model 2 Intergovernmental Agreement (IGA 2) provides for direct registration and reporting by businesses in a country to the U.S. authorities. It requires local laws to be adapted
The Cayman Islands have entered into an IGA 1 with the United States, and Bermuda has entered into an IGA 2. The IGA 1 eliminates the need for individual FFIs within the Cayman Islands to enter into a separate agreement with the IRS, and the IGA 2 eliminates the need for individual FFIs in Bermuda to provide information to the local government authorities for onward transmission to the IRS. But the obligations for FFIs in both jurisdictions will be the same in terms of what information they will be required to obtain, maintain and report. Senior executives of FFIs in both Bermuda and the Cayman Islands will need to be aware of the obligations imposed upon their business by FATCA and ensure that (1) adequate processes are put in place to obtain, maintain and report requisite information in relation to all clients and customers going forward, and (2) an historical due diligence exercise is implemented to ensure that existing client records are updated and upgraded to meet the new requirements. TAX INFORMATION EXCHANGE AGREEMENTS (TIEAS) The global financial crisis of 2008 resulted in increased scrutiny of the offshore financial world and renewed focus on the development and implementation of international standards in tax cooperation. The main organizations that have been responsible for forging global acceptance and cooperation in such matters are the Organization for Economic Co-operation and Development (OECD) and the G20. The OECD has assessed and reported on the legal and administrative framework for transparency and exchange of information on a global scale, in particular the commitment
today’s gener al counsel jun/jul 2014
to transparency and exchange of tax information under the umbrella of eliminating so-called “Harmful Tax Practices” and identifying socalled “Uncooperative Countries or Territories.” The OECD has established standards on transparency and exchange of information for tax purposes, and it has strongly encouraged countries to adopt these standards, which are based on internationally agreed principles of transparency and cooperation for the exchange of tax-related information (“the Principles”). The key aspects of the Principles are: • Exchange of information on request where it is foreseeably relevant to the administration and enforcement of the domestic laws of a treaty partner. • No restrictions on exchange because of bank secrecy or domestic tax interests requirements. • Availability of reliable information, particular accounting, bank and ownership information, and powers to obtain it. • Respect for taxpayers’ rights. • Strict confidentiality of information exchanged. In compliance with the Principles, Bermuda and the Cayman Islands have together entered into 69 TIEAs (Bermuda currently has 38, the Cayman Islands 31). Tax information exchange under a TIEA is by request only, and there are strict criteria with which each request must comply. These safeguards require that each request relate to a real and specific matter and is not just part of a “fishing expedition.” More recently the OECD and G20 introduced and promoted the Convention on Mutual Administrative Assistance in Tax Matters (CMAATM), which has now been accepted as the new internationally recognized standard for mutual administrative assistance in tax matters. While the CMAATM includes provisions for information exchange on request (as was provided for under TIEA), it has also included provisions to cover spontaneous and automatic exchange of information. The CMAATM is already in force in both Bermuda and the Cayman Islands. ALTERNATIVE INVESTMENT FUND MANAGERS DIRECTIVE (AIFMD) The AIFMD is a European Union directive originally introduced in response to the global financial crisis of 2008 to establish a comprehensive regulatory and supervisory framework for managers of alternative investment funds at a European level.
Prior to the introduction of the AIFMD, only those funds that fell within the scope of, and were required to comply with the rules set out in, the UCITS (Undertakings for Collective Investment in Transferable Securities) Directive 85/611/EEC were subject to harmonized cross-European regulation of the sector. All other funds are, for the purposes of the AIFMD, identified by the European Commission as Alternative Investment Funds (AIFs). Historically, alternative investment funds were subject to the financial and company laws of each jurisdiction in which they operated or were involved, and in some cases they were also subject to additional industry standards. It was determined that this regulatory environment did not adequately address the level and types of risks involved in the cross border activities of AIFs and, due to the vulnerability of member states to cross-border contamination of AIF risks, that a Europe-wide approach, similar to that provided under the UCITS Directive, be introduced. Implications for businesses in Bermuda and the Cayman Islands extend only to managers of AIFs that either perform risk management or portfolio management functions in the European Union or market units, shares or interests in AIFs to European investors. The regulatory landscape in Bermuda and the Cayman Islands continues to change in
Simon Raftopoulos is a partner and a member of the Corporate Finance and Insurance teams at Appleby. He represents clients in a wide variety of corporate finance and insurance transactions. He participates regularly at conferences and provides commentary to international and local media regarding the Cayman insurance industry. sraftopoulos@ applebyglobal.com
Historically, alternative investment funds were subject to the financial and company laws of each jurisdiction in which they operated or were involved. response to global demands for higher levels of anti-money laundering, anti-terrorist financing, tax cooperation, transparency and fund oversight standards. Bermuda and the Cayman Islands now lead the world with the highest regulatory standards in these areas. Although these changes have introduced a slew of intimidating-sounding acronyms, the reality is that with the help and guidance of a trusted local advisor in these jurisdictions, regulatory reforms have provided new and exciting opportunities for offshore M&A activity to thrive. n
59
60
SEC’s New, Powerful Enforcement Options By Daniel Patrick Wendt
A
change is underway in the SEC enforcement climate. It has several causes, but the key is a lesser-known provision of the 2010 DoddFrank legislation that allows the Securities and Exchange Commission to pursue civil penalties for a broad range of actions through administrative actions. As a result, companies and executives challenging enforcement actions or negotiating settlements involving the Foreign Corrupt Practices Act are in new terrain, with advantages in some circumstances and disadvantages in others. Historically, Congress has allowed the SEC to choose between pursuing enforcement actions either in federal court or administratively before administrative law judges (ALJs) employed by the SEC. Until recently, the two options were easily distinguished: If the SEC wanted to impose civil penalties, then it was required to go to federal court, except for a small subset of cases typically unrelated to FCPA enforcement.
61 In Dodd-Frank, however, Congress authorized the SEC to impose civil penalties in its own administrative actions as well as in federal court. In short, the SEC can now do its enforcement work in FCPA cases without ever having to leave home.
In Dodd-Frank, Congress authorized the SEC to impose civil penalties by way of its own administrative actions. It has now been several years since this rule changed, and relevant precedent is developing. The SEC has pursued civil penalties against individuals and related entities in administrative proceedings, albeit not for FCPA violations. Many of the defendants have argued that these administrative enforcement actions violate their constitutional rights. Specifically, defendants have argued that they lose the right to a jury trial, the ability to seek discovery as allowed in
jun/jul 2014 today’s gener al counsel
federal courts, and the right to challenge the SEC’s theories before trial. Challenges One of the earliest and most well-known defendants, Rajat Gupta of Goldman Sachs, was able to secure the withdrawal of an administrative action, although the SEC ultimately initiated a successful federal action against Mr. Gupta.
ther admit nor deny” any wrongdoing in civil settlements. Generally, corporate defendants prefer to include this clause in a settlement, to protect themselves from collateral consequences, including shareholder suits. However, Judge Rakoff of New York threatened to undo a non-FCPA settlement over the issue of whether the SEC should have allowed the defendant to neither admit nor deny the allegations.
One result: The SEC and general counsel may have more flexibility in negotiating the terms of FCPA-related settlements.
62
Daniel Patrick Wendt is a Member at Miller & Chevalier Chartered in Washington, D.C. He specializes in FCPA investigations and compliance. dwendt@milchev.com
Two recent defendants, however, have lost preliminary motions on these issues, when federal judges in the Southern District of New York and the DC District were unwilling to suspend ongoing administrative actions, given the clear intent of Congress. The underlying lawsuits remain active, so it is possible that the federal judiciary may take a different tack, but currently it appears that the Dodd-Frank amendments are established. Recently, in the FCPA context, the SEC resolved an enforcement action with Alcoa, Inc. through its administrative process rather than though federal court. As a result of the settlement, Alcoa agreed to pay $175 million as disgorgement of ill-gotten gains, in addition to other amounts owed to the Department of Justice. Technically, because the resolution did not include a civil penalty, the SEC could have brought the action as an administrative proceeding either before or after Dodd-Frank. Nonetheless, agency officials have cited the action as a harbinger of its rising preference for administrative actions rather than civil suits in federal court. While individual defendants may lament the loss of rights with a move from federal court to administrative actions, corporate defendants may welcome the option, especially in FCPA matters. In short, federal judges have been delaying or potentially undoing settlements negotiated between the SEC and corporate defendants in recent years. For example, there has been much debate inside and outside federal courtrooms about whether the SEC should continue its general policy of allowing corporate defendants to “nei-
Similarly, in FCPA matters, some federal judges have substantially delayed the confirmation of settlement agreements, as the court collected and reviewed evidence, essentially to test the appropriateness of the SEC’s settlement terms. By pursuing administrative actions, the SEC will be able to exclude the federal judiciary from settlement agreements. Corporate defendants therefore may welcome the additional certainty that the SEC can now provide, both as to the scope and timing of any agreement. mixed results This change could mean several things for corporate counsel. First, Congress has removed speed bumps for the SEC, allowing the SEC to pursue more enforcement actions with the same resources. Second, and similarly, corporate defendants may be able to avail themselves of shorter timelines for resolving issues that are voluntarily disclosed, as is often the case in FCPA investigations. Third, the SEC and general counsel may together have more flexibility in negotiating the terms of FCPA-related settlements for corporate defendants, given that the federal judiciary does not need to play a prominent role. Fourth, general counsel should note that when the SEC does pursue contested enforcement actions against individuals or corporate defendants, the SEC may opt for administrative proceedings before its own administrative law judges, which may create certain disadvantages for the defendants. n
Sponsored Partners
Presents
LEADERSHIP PROFILES
I n t E L L E c t uA L P R O P E R t y L Aw
wADE wELcH T. Wade Welch & Associates is a Houston, Texas-based law firm representing entrepreneurial interests and Fortune 500® companies in litigation throughout the United States, resulting in the firm being named as a Go-To Law Firm® for several years in a row. BTI Consulting Group has identified T. Wade Welch & Associates as a Client Services MVP based on multiple reviews by a Fortune 50 worldwide agriculture conglomerate, and the firm was also spotlighted in Newsweek magazine’s 2011 Top Attorneys in the Country showcase. The firm is lead by Wade Welch, who is a Lifetime VIP member of Strathmore’s Who’s Who and was named its 2011 Professional of the Year in the area of Complex Commercial Litigation. These accolades are the result of T. Wade Welch & Associates’ centralized litigation practice, which offers nationwide representation to its clients no matter where a particular dispute takes place.
63
At T. Wade Welch & Associates, we realize that superior knowledge of black letter law only provides the fundamentals of effective representation-the art is drawn from its use in furthering your business objectives. We make it our business to know your business, because we appreciate the value in having an intimate familiarity with our clients’ industries, because when it counts, you don’t just need an advocate, you need a partner – someone who can provide creative solutions in dynamic situations; a firm that is totally committed to its clients and who is accessible at a moment’s notice; a proven leader. What our clients want are swift, comprehensible resolutions to their problems in a cost-effective manner. This has been T. Wade Welch & Associates formula for success since the firm began in 1994.
2401 Fountain View Drive Suite 700 Houston, TX 77057 Phone: 713.952.4334 www.twwlaw.com
Sponsored Partners
Presents
LEADERSHIP PROFILES
L A B O R & E M P L O Y M E N T L AW
DANIEL F. MuRPHY, JR . Daniel F. Murphy, Jr. represents management exclusively in all aspects of labor relations, employment law, and related litigation. He counsels employers on a daily basis on topical employment issues. He litigates cases in federal and state courts through out the country. He represents management before arbitration tribunals and administrative agencies on the state and federal level. He also serves as chief spokesperson for management during labor negotiations. He represents employers in health care, higher education, manufacturing, financial services, retail and service industries including not For profit entities. Mr. Murphy received his law degree from Boston college law School, a Masters degree in labor and employment law from new York university law School, and his undergraduate degree, cum laude from le Moyne College. He is a graduate of Regis High School. He is admitted to practice in New York, New Jersey, the United States Supreme court and various federal courts. He is a member of the College of Labor and Employment Lawyers. 64
Putney, Twombly, Hall & Hirson, LLP Counselors at Law
521 Fifth Avenue, New York, NY 10175 Phone: 212-682-0020 •dmurphy@putneylaw.com
TO D AY S G E N E R A L C O U N S E L . C O M
Database Marketing for Lead Generation With over 300,000 names, the TGC database enables marketers an unmatched array of choices to send out co-branded emails with content of their own choosing to several desirable segments within the database.
T ODAYS G ENER A L C OUNSEL .C OM /A D V ER T ISE
GET YOUR ROADMAP TO EXCELLENCE!
Access the Law Department Maturity Model® to transform your department from “order takers” to business aligned. www2.bridge-way.com/roadmap