Author: Tom Hagy

  • 7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation? | By Jennifer M. Oliver | MoginRubin LLP

    7th Circuit: Is Each Transmission of Biometric Data a BIPA Violation?

    By Jennifer M. Oliver

    The outcome of this case will have a dramatic impact on statutory damages.

    The Seventh Circuit U.S. Court of Appeals has certified a question to the Illinois Supreme Court over the accrual of claims under the Illinois Biometric Information Privacy Act (BIPA). The question, posed by the court in Cothron v. White Castle Systems, Inc., reads:

    “Do section 15(b) and 15(d) claims accrue each time a private entity scans a person’s biometric identifier and each time a private entity transmits such a scan to a third party, respectively, or only upon the first scan and first transmission?”

    The case was brought by an employee of the White Castle hamburger chain, which requires fingerprint scans for employees to access computer systems. The plaintiff charged that sharing her fingerprints with a third party vendor violated the law. Cothron v. White Castle Sys., No. 20-3202, 2021 U.S. App. LEXIS 37593 (7th Cir. Dec. 20, 2021).

    An accrual rule based on each collection, opponents to such a finding argue, would pose potentially existential damages — especially in the class action context — since BIPA provides for statutory damages of $1,000 or $5,000 per violation. Parties disagree on whether BIPA damages are mandatory or discretionary, however. Should the court determine that the first scan is the only scan that starts the statute of limitations clock ticking, opponents to that interpretation say,  anyone bringing a claim after five years would be out of luck, even if their private biometric data continued to be transmitted more than five years after the first occurrence.

    Preceding the federal court’s certification of this question by just five days, an Illinois appellate court ruled that, yes, claims under sections 15(a) and (b) accrue with each capture and use of a plaintiff’s biometric  information. Watson v. Legacy Healthcare Financial Services, LLC, et al., 2021 IL App (1st) 210279 No. 1-21-0279, Opinion filed Dec. 15, 2021.

    This is an important case to watch. Illinois was the first to implement such legislation, something several states have since emulated.

    Should the state Supreme Court come down in favor of an “all scans” interpretation, defendants may find themselves on the receiving end of devastating damages multipliers. Of course, the Illinois Supreme Court could determine that damage awards are at the discretion of a court, and are not mandatory under the law. Or it could rule that every scan or transmission restarts the statute of limitations clock, but that a claimant may only collect damages once for a series of transmissions of the same data, similar to how damages for defamation are not based on each publication of the same defaming remarks. Yet another possibility is that the court could determine that the clock starts to run when a claimant first learns of an alleged violation, which has precedent in litigation involving latent diseases caused by products, where individuals cannot know they were harmed until they developed a signature disease, i.e., one connected to a specific product.

    The ruling in this case is especially interesting as the COVID-19 pandemic has led to skyrocketing adoption of remote access tools that can collect biometric data for learning, court appearances, and work-from-home arrangements, and a corresponding uptick in BIPA lawsuits.

    Edited by Tom Hagy for MoginRubin LLP. Reposted with permission from the MoginRubin Blog. © 2022 MoginRubin LLP. 

    The Author

    Jennifer M. Oliver

    Jennifer M. OliverMoginRubin LLP

    Jennifer is a partner in the San Diego offices of MoginRubin LLP, where she focuses on antitrust, complex business, and investment litigation. Her experience includes active roles in several high-profile jury trials, serving as lead counsel in complex mediations, and arguing before courts at both the trial and appellate levels. Jennifer earned her B.S. (Business Administration), M.B.A., and J.D. degrees from the University at Buffalo, each with honors, where she also served as the Vice President of the undergraduate student body and was an editor of the Buffalo Law Review and Buffalo Intellectual Property Law Journal. Jennifer is also a certified information privacy professional.

    We are pleased to add that Jennifer is a member of the Board of Advisors for the Journal on Emerging Issues in Litigation and the Emerging Litigation Podcast.

    More from Jennifer and her colleagues.

  • The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The New Lloyd’s Market Association War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies | By Vincent J. Vitkowsky | Gfeller Laurie LLP

    The Author

    Vincent J. Vitkowsky

    Vincent J. VitkowskyPartner | Gfeller Laurie LLP

    Vince Vitkowsky is a partner in Gfeller Laurie LLP, resident in New York. He focuses on cyber risks, liabilities, insurance, and litigation. Vince assists insurers and reinsurers in product development, and in all aspects of coverage evaluation and dispute resolution in many lines of business, including cyber, CGL, property, and professional liability. He also assists in complex claim evaluations, and if necessary, the defense of insureds in complex matters.

    Vince is also a member of the Editorial Advisory Board for the Journal on Emerging Issues in Litigation.

    Contact: vvitkowsky@gllawgroup.com

    More from Vince and his colleagues.

    Melicent Thompson

    The New LMA War, Cyber War and Cyber Operation Exclusions for Cyber Insurance Policies

    By Vincent J. Vitkowsky

    On November 25, 2021, the Lloyd’s Market Association released four War, Cyber War and Cyber Operation Exclusions (“Exclusions”). The LMA Cyber Business Panel spent well over two years drafting the Exclusions, which are models for use in standalone cyber insurance policies.  Lloyd’s has agreed that they meet the requirement that all insurance and reinsurance policies written at Lloyd’s must, except in very limited circumstances, contain a clause which excludes all losses caused by war.  The Exclusions address some difficult issues troubling the cyber insurance market for several years, following cyberattacks by nation-states (“states”) and threat actors associated with them.  They attempt to reduce uncertainty for both insurers and policyholders.

    Five interrelated issues.

    • The treatment of collateral damage (borrowing a concept from the traditional Law of Armed Conflict). Some state-sponsored attacks had significant effects on many entities that were not the intended targets.
    • How attribution is to be determined, and whether the insurers have an obligation to make payments while attribution is being determined.
    • The extent to which attacks by non-state actors associated with a state are excluded.
    • The treatment of state and state-sponsored cyberattacks directed at essential services, most notably those disrupting financial institutions and the financial markets infrastructure.
    • As in war exclusions in all lines of business, attempting to limit the aggregation risk.

    The Exclusions.

    The principal innovations in the Exclusions are to introduce the concept of “cyber operation” to insurance, to set processes for determining attribution, to partially clarify the scope of essential service, and to set a structure that de facto mitigates the aggregation risk.

    The key concepts and terms are as follows.

    War.  All four Exclusions contain an identical definition of War, largely based on traditional insurance policy language dating back to the Spanish Civil War.  It is “the use of physical force by a state against another state, or as part of a civil war, rebellion, revolution, insurrection, and/or military or usurped power or confiscation or nationalisation or requisition or destruction or damage to property by or under the order of any government or public or local authority, whether war be declared or not.”  (Emphasis is added, throughout this note.)  In the context of cyber war, this would include a cyberattack with kinetic effects.

    Cyber operation.  All four Exclusions also have an identical and innovative definition of cyber operation.  It is “the use of a computer system by or on behalf of a state to disrupt, deny, degrade, manipulate or destroy information in a computer system of or in another state.”

    Attribution.  All four Exclusions also contain an identical and innovative provision on “Attribution of a cyber operation to a state.”  It provides that the “primary but not exclusive factor” in attribution “shall be whether the government of the state (including its intelligence and security services) in which the computer system affected by the cyber operation is physically located attributes the cyber operation to another state or those acting on its behalf.”  Pending attribution by a state, “the insurer may rely upon an inference which is objectively reasonable as to attribution,” and no loss shall be paid.  If the affected state “takes an unreasonable length of time to, or does not, or declares it is unable to attribute the cyber operation to another state or those acting on its behalf,” the insurer, bearing the burden of proof, must “prove attribution by reference to such other evidence as is available.”

    Specified States.  This term appears in some of the Exclusions.  The specified states are China, France, Germany, Japan, Russia, UK or USA.

    The four exclusions treat cyber operations differently.

    The first Exclusion simply provides a blanket denial of coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation.”

    The other three Exclusions deny coverage for loss “directly or indirectly occasioned by, happening through or in consequence of war or a cyber operation that is carried out in the course of war.”

    The second Exclusion has additional provisions denying coverage for “retaliatory cyber operations between any specified states; and/or a cyber operation that has a major detrimental impact on the functioning of a state due to the direct or indirect effect of the cyber operation on the availability, integrity, or delivery of an essential service in that state; and/or the security or defense of a state.”  Although these are excluded, the policy may grant coverage for “any other cyber operations,” with a separately negotiated limit and aggregate.

    Significantly, essential service is defined as “a service that is essential for the maintenance or vital functions of a state including without limitation: financial institutions and associated financial market infrastructure, health services or utility services.”

    The third Exclusion is identical to the second, except it does not grant coverage for “any other cyber operations,” i.e., those not carried out in the course of war, retaliatory cyber operations between specified states, or those having a major detrimental impact.

    The fourth Exclusion is identical to the third, except it introduces the concept of “impacted state,” defined as “any state where a cyber operation has had a major detrimental impact on the functioning of that state [as defined in the third Exclusion], and/or security or defense of that state.”  Moreover, it limits the Exclusion for retaliatory cyber operations to those “leading to two or more specified states becoming impacted states.”  It also provides an exception to the Exclusion for loss from a cyber operation that has a major detrimental impact, so the Exclusion “shall not apply to the direct or indirect effect of a cyber operation on a bystanding cyber asset.”  That term is defined as “a computer system used by an insured or its third party service providers that is not physically located in an impacted state but is affected by a cyber operation.”

    The complete Exclusions can be found here.

    A serious attempt to reduce uncertainty.

    These Exclusions are not perfect.  Nothing is.  There is scope for dispute about the terms “an inference which is objectively reasonable,” “reference to such other evidence as is available,” “major detrimental impact,” and “essential service,” among others, as applied to specific facts.  But the Exclusions reflect a well-reasoned, serious attempt to reduce some of the uncertainties over the scope of coverage for state and state-sponsored attacks.

    Written Dec. 9, 2021 and posted with permission with minor formatting changes. Copyright 2021 by Vincent J. Vitkowsky.  All rights reserved.

  • The Rise of Robojudges with Josh Davis

    The Rise of Robojudges with Josh Davis

    The Rise of Robojudges with Joshua Davis

    The good news for all of us, not the least of which are the robe and wig industries,  is that we still have time. Artificial intelligence is advancing rapidly, but it’s still not able to think like a learned jurist. We can say it will have flaws, but so do our human deciders. So it will be a tradeoff, right? What are the risks? What are the upsides? Will robojudges be able to absorb infinitely more information quickly? Will they hand down decisions free from the influence of bias? Wouldn’t it be great to eliminate conflicts of interest? 

    Joining me to discuss this not-so-out-there concept is Joshua P. Davis, a nationally recognized expert on legal ethics, class actions, and artificial intelligence in the law. He is Research Professor of Law at the University of California Hastings College of Law, and Shareholder and Manager of Berger & Montague, P.C.’s new San Francisco Bay Area Office. For more than 20 years Josh was a tenured Professor of Law at the University of San Francisco Law School, where he also served as the Director of the Center for Law and Ethics. Josh is authoring two books, one titled Unnatural Law, dealing with AI and the law, and a second on the important issue of class action ethics. 

    Finally, remind me never to assume anything when I ask Josh a question. I said something like, “Surely we’re not talking about sci-fi robots here,” to which he basically said, “Not so fast.” This happened more than once. When will I learn? 

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the Fastcase legal research family, which includes Full Court Press, Law Street Media, Docket Alarm and, most recently, Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful and forward-thinking Josh is, please drop me a note at Editor@LitigationConferences.com.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    According to an article written by our guest, “Some of the most exciting, vexing, and terrifying issues at the intersection of AI and law involve robojudges.” 

    Can we build a robojudiciary that replaces human judiciaries? Should we? Doing so would massively disrupt how our legal systems operate. It also might transform democratic self-government.” I have to ask: Would any of that be so bad? It’s not like humans are doing such a bang-up job. The risk, of course, is what if we get it all wrong? 

    via GIPHY

  • Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege and IoT with Kathryn Rattigan

    Broken Privilege IOT Kathryn Rattigan

    Joining me to discuss this emerging area of law is Kathryn M. Rattigan, a member of the Business Litigation Group, the Data Privacy + Cybersecurity Team, and the Drone Compliance Team in the Rhode Island office of Robinson Cole.

    Kathryn provides clients guidance regarding privacy and data protection in connection with mobile devices, data storage technologies, mobile apps, and location-based services. She  assists with the development of website and mobile app privacy policies and  terms and conditions. Kathryn is a frequent contributor to the excellent Robinson Cole Data Privacy + Cybersecurity Insider blog.  She holds a J.D. from the Roger Williams University School of Law and a B.A. (magna cum laude) from Stonehill College.

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the Fastcase legal research family, which includes Full Court Press, Law Street Media, Docket Alarm and, most recently, Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful and informative Kathryn is, please drop me a note at Editor@LitigationConferences.com.

    Finally, yes, “skeevy” is a word. And the law is not settled as to whether Shiloh has privacy rights.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    There are now billions and billions of interconnected devices in the world with more coming online every day. Smart cars. Smart cities. Smart agriculture and so much more. Even our pets are connected.

    And you have to look no further than the Colonial Pipeline ransomware attack to see the real-world consequences of what criminals can pull off by connecting with things large and small.

    Worried about your privacy? Well. There is plenty to worry about.

    Fortunately we also have a lot of people fighting back on the technical, security, law enforcement, and legal fronts.

  • The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    The Commercial Drone Industry: Privacy, Security, Threats, and Mitigation of Risk

    HB presents a CLE-eligible webinar
    Now on-demand at the West LegalEdcenter
    THE COMMERCIAL DRONE INDUSTRY
    Privacy, Security, Threats, and Mitigation of Risk

    Drones have become an increasingly valuable tool for businesses of all types and sizes.

    Drones are already being used in many applications, but more will certainly arise as the technology advances. This means that certain risks, like cyber threats, will also continue to present themselves. Protecting the transmission and storage of data collected through drones is critical.

    Unfortunately, security usually comes as an afterthought. The drone industry is part of the aviation industry, which, based on its knowledge, keeps safety as a number one concern. Part of that safety is having proper protection for your systems, including security as a fundamental design principle.

    Take this webinar to gain insights on the topics listed below, and shared by an attorney who practices on the cutting-edge of this evolving technology.

    Topics:

    • Defining drones.
    • Current and future applications.
    • FAA Modernization and Reform Act of 2012.
    • FAA Part 107 Regulations and waivers.
    • Resources, e.g. the FAA Drone Zone and LAANC Portal.
    • Penalties for violations.
    • Privacy implications.
    • Drones as weapons.
    • Vulnerability to cyber attacks.

    Take it now!

    What you get:

    1+ CLE credits (subject to bar rules).

    Insights from an experienced professional who specializes in this area of the law.

    The complete PowerPoint presentation.

    Continued access to the complete recording for later use.

    Answers to your questions.

    Fee:

    No additional charge to subscribers to the West LegalEdcenter.

    Non-subscribers may take the course for $170.

    Meet the Speaker

    Kathryn Rattigan
    Robinson & Cole LLP

    Kathryn Rattigan is a member of the firm’s Business Litigation Group and Data Privacy + Cybersecurity Team. She advises clients on data privacy and security, cybersecurity, and compliance with related state and federal laws. She assists clients in assessing risks related to technology and software contracts, as well as with compliance-related issues with outsourcing and vendor management. She represents clients across all industries, such as manufacturing, insurance, health care, education, energy, and construction.

    Kathryn helps clients comply with all state and federal regulations related to data privacy and cybersecurity. She is also a member of the firm’s Drone Compliance Team. As such, she advises clients on all legal issues surrounding the use of commercial drones, including navigation of Federal Aviation Administration regulations, commercial registration requirements, and Part 107 waivers.

    She is committed to doing pro bono work and being involved in the community. Her recent efforts include assisting Inner Explorer, a non-profit which works to help students focus and succeed through mindfulness practice in the classroom, and College Visions, which helps low-income students pursue a college education.

    She writes for two of the firm’s blogs, Data Privacy + Security Insider and Health Law Diagnosis.

    More about Kathryn

    Also, listen to my interview with Kathryn for the the Emerging Litigation Podcast!

    –Tom Hagy

  • The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The Cyber Insurance Market Has Problems: A Conversation With Tom Johansmeyer

    The author of the piece is my guest on our latest episode. He is Tom Johansmeyer, ARM, is head of PCS, a Verisk business. PCS investigates and provide, independent loss estimates on catastrophes and large individual losses to the benefit of the global risk and capital supply chain. Tom has focused on the broad and rapid expansion of PCS, leading the team into Japan, New Zealand, and other APAC regions in 2019 – as well as Mexico. Tom is the architect of the PCS entry into global specialty lines, most recently adding large risk loss reporting to the group’s portfolio. Previously, Tom held insurance industry roles at Guy Carpenter (where he launched the first corporate blog in the reinsurance sector) and Deloitte. Personally, I like his LinkedIn description: “Aspiring cyclist and distance swimmer, former soldier. Leading the global charge at PCS. Haven’t driven anything with a motor since 2007.” Excellent.

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation, a collaborative project between HB Litigation Conferences and the legal news folks at Law Street Media, and the Fastcase legal research family, which includes Docket Alarm and Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful our guests are, please drop me a note at Editor@LitigationConferences.com.

    You might notice that I misused a commonly used term, one specifically common in the world of insurance, or maybe you weren’t paying that much attention. That would make two of us. Also, Tom J. was just a fun interview and I hope to get him back! I like the way he explained his candor at the end. He suffers from an infliction that I wish were a pandemic. I hope you enjoy it.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    “Facing the prospect of major financial fallout from an attack, C-suites around the world have turned to cyber insurance. Insurers are issuing more policies, and the amounts of protection available are increasing.

    “In 2020, according to data proprietary to the team I lead, the global insurance community saw the first cyber insurance program to exceed $1 billion — and the second. However, the momentum that has propelled the sector this far may be running out. The cyber insurance sector may still be in its infancy, but there are signs that it’s hit a (hopefully temporary) plateau.”

    From a Jan. 11, 2021, article in the Harvard Business Review titled “Cybersecurity Insurance Has a Big Problem.”

  • Public Justice Shares Inside Look at Roundup Trial and Appeal in First Episode of “Justice Pod”

    Public Justice Shares Inside Look at Roundup Trial and Appeal in First Episode of “Justice Pod”

    Public Justice Discusses Hardeman v. Monsanto in First Episode of Justice Pod

    Justice Pod

    That is according to a post written by Leslie Brueckner, Senior Attorney with Public Justice following the May 2021 Ninth Circuit U.S. Court of Appeals ruling against Monsanto, and for Edwin Hardeman, a California resident who developed non-Hodgkin’s lymphoma after decades of exposure to Roundup. The jury awarded Hardeman $5,267.634.10 in compensatory damages, and $75 million in punitive damages. The district court reduced the punitive damages award to $20 million. 

    In this inaugural episode of Justice Pod: Conversations with Public Justice Change Makers, Leslie, is joined by David J. Wool, an attorney with the Wagstaff Law Firm.  Wool and Jennifer A. Moore of the Moore Law Group, were on the trial team led by highly-regarded mass tort plaintiff attorney Aimee Wagstaff.  Public Justice’s Brueckner served as co-lead appellate counsel along with Wool before the Ninth Circuit.

    Listen to what they felt inspired the jury to return such a substantial award, how Monsanto attempted to defend its actions, what the evidence revealed, and what it was like in the courtroom with the Hardeman family when the foreman read the verdict.

    I hope you find the episode inspiring and informative!

    Susan Gombert
    Host of Justice Pod:
    Conversations with Public Justice Change Makers

    Listen Now!

    Monsanto Co. has “stopped at nothing to deny the overwhelming scientific evidence” that its widely used and extremely profitable weed killer,  Roundup, is a “deadly product that causes cancer and ruins lives and families.”

  • Putting an AI App to Work to Protect IP with Jan-Diederik Lindemans and Judith Bussé

    Putting an AI App to Work to Protect IP with Jan-Diederik Lindemans and Judith Bussé

    Putting an AI App to Work to Protect IP with Jan-Diederik Lindemans and Judith Bussé

    They are Crowell & Moring partner Jan-Diederik Lindemans and Judith Bussé, both part of the firm’s Technology & Intellectual Property Department in Brussels. And, working with Neotalogic, they developed an interactive app that takes you through a set of attorney-crafted questions that, depending on your answers, take you to other questions. The app applies a layer of artificial intelligence to enhance the information gathering process. Listen to what these innovators had to say about the Crowell & Moring IP Check-Up application, and take it for a test drive yourself.  Or, here is a quick video of someone using the app.

    This podcast is the audio companion to the Journal on Emerging Issues in Litigation*, a collaborative project between HB Litigation Conferences and the legal news folks at Law Street Media, and the Fastcase legal research family, which includes Docket Alarm and Judicata. If you have comments or wish to participate in one our projects, or want to tell me how insightful our guests are, please drop me a note at Editor@LitigationConferences.com.

    Tom Hagy
    Host of the Emerging Litigation Podcast

    * Highly regarded insurance and reinsurance industry attorney Laura Foggan of Crowell & Moring’s Washington, DC, office is on the Editorial Advisory Board. Thanks to Laura for connecting me with J.D. and Judith. 

    An organization’s intellectual property is often its most valuable asset.

    Whether it’s a patent or a trademark, a graphic design or proprietary market information, or just the unique way they do what they do, organizations must protect their innovations or risk significant damage to their future prospects.

    Assessing the vulnerabilities of such valuable inventory is as important as it is time-consuming. But a portfolio protection and process review involves answering the same long set of questions posed to any organization, no matter what type.

    There is the problem. You have a critical invention. You don’t know if it’s at risk. What do you do? You contact a lawyer, of course. You go through the process, one they have managed many times before. What if you could do this yourself first, before contacting a firm? What if it took just 20 minutes and could be done from the comfort of your desk? If you’re the attorney, what if you already had many of your questions answered before your first meeting with a new client? 

    An innovative pair of attorneys in Brussels asked these questions and came up with a solution. And I had the pleasure of interviewing them.