10 May 2013

Corby family in the copyright spotlight

Posted by Cara Friedman, Nicole Reid and Paul Kallenbach

Image courtesy of renjith krishnan
The Federal Court of Australia has found in favour of Schapelle Corby's sister, brother and mother in relation to five photographs published in the book, 'Sins of the Father'.  The book – published by Allen & Unwin Pty Ltd (which was the respondent in the action) and written by journalist Eamonn Duff – attempts to portray Schapelle as a knowing participant involved in her father's drug trafficking.  Neither the publisher nor the writer of the book sought permission from the owners of the photographs to use the photographs in the book.

The law

Generally, the owner of copyright in a photograph is the person who took it (although there are exceptions that may apply where the photograph was commissioned for a private or domestic purpose or created under the terms of an employment agreement with the proprietor of a newspaper or magazine).   As a photograph is an artistic work in which copyright subsists, its owner has the exclusive right (amongst others) to reproduce it, or permit its reproduction, unless the owner grants a licence to another to do so or another person can exercise that right under one of the statutory licences or exceptions set out in the Copyright Act 1968 (Cth) (Copyright Act).

The person who took the photograph also has moral rights in the photograph, including the right to have his or her authorship attributed, unless a defence applies.

The issue

The Court held that the publisher did not have express permission from any of the copyright owners to reproduce the photographs in the book.  The relevant question for the Court was whether Allen & Unwin could reproduce the photographs without this express permission, given that express or implied permission had been given to others to reproduce the photographs for an earlier purpose.

Allen & Unwin withdrew its 'innocent infringement' defence (under section 115(3) of the Copyright Act) during closing submissions.  Nor did it try to argue that it had engaged in fair dealing for the purpose of reporting news.

The photographs

The relevant photographs were of Schapelle Corby and/or her mother, sometimes with others.   Two of them were taken by Rosleigh Rose, Schapelle's mother, who also owned a 25% share in the third photograph, as it had been taken by her late partner, of whose estate she was a 25% beneficiary.   The other two photographs were taken by Michael and Mercedes Corby, Schapelle's brother and sister, respectively.

The evidence was that three of the photographs were initially supplied for use in an article that Mr Duff was writing in 2005 for Fairfax media.  Buchanan J held that no licence existed for reproduction of these three photographs in the book.  Any lawful supply of the photographs (if at all) was limited to the context in which they were initially supplied (ie for use in the article).  His Honour held that the current use had no connection with the previously authorised purpose.

Nor did the Court find that any licence existed in relation to the fourth photograph, which was originally given to Schapelle's friend, who in 2005 had provided it to Mr Holland, a Fairfax photographer, in order to assist Schapelle's case.

In relation to the final photograph, the court found that even if it had been provided as a gift to Mr McHugh or Mr McCauley (the two men in the photo with Rosleigh Rose, who were both later convicted of drug dealing), this would be insufficient, without more, to constitute a licence for its reproduction in the book.

Buchanan J observed that 'the defence mounted was weak to say the least.'  Consent was sought neither by the author of the book, nor the publisher, for copyright clearance.  The Court noted that in these circumstances it was the responsibility of the publisher, not the author, to decide which photographs were reproduced in the book.

Moral rights

The court found that the applicant family members' moral right of attribution had been infringed in relation to four of the photographs, as Allen & Unwin had failed to attribute authorship to them.  There was no evidence to establish the defence (to moral rights infringement) that it was 'reasonable in all the circumstances' not to identify the author on the basis of industry practice (this was especially so given that authorship of some photographs in the book was attributed) or any other of the defences available in the Copyright Act.

Orders

The Court granted an injunction prohibiting Allen & Unwin from further reproduction of any of the five photographs, and ordered destruction of any copies of the book in its possession.

The Court did not assess compensatory damages on the basis of what the copyright owners may have accepted as a licence fee, as the evidence was that they would not have given permission to use the photographs in the book.  Instead, damages of $9,250 were awarded, based on the commercial significance of each photograph and its relevance to the central themes of the book.  For example, damages of $5,000 were awarded for infringement of the copyright in one of the photographs, due to its prominence on the back cover of the book and its focus on the relationship between Schapelle and her father, a central theme of the book.

Acknowledging the need for deterrence (both general and specific) and marking its disapproval of such 'flagrant disregard' for the applicants' rights, the Court awarded the applicants additional damages of $45,000.   It would appear that the Court's perception of the copyright infringement as a 'conscious, calculated business decision' by the publisher provided the necessary impetus for this additional damages award.

In relation to the four relevant photographs, the Court made only a declaration of moral rights infringement.   Neither damages nor an apology was ordered, as no loss – neither commercial nor personal – was considered to have resulted from the lack of attribution.   Schapelle's family members wanted no association with the book at all, including by being attributed as authors of the photographs.   Accordingly, Buchanan J labelled the moral rights infringement as 'more a question of form than substance'.

This case does not establish any new law.  It does, however, remind publishers that it is their responsibility to seek copyright clearance prior to publishing photographs, and not to rely on unwritten permissions granted to others, the scope of which is unclear and may not cover later uses.   It is also a rare case that considers moral rights issues (although the infringement issues were not considered in great detail), though it seems the conclusion here is that a finding of moral rights infringement may not help applicants obtain a larger award of damages.

02 May 2013

All signs point to mandatory data breach notification in Australia

Posted by Elisabeth Koster, Amy Gibbs and Paul Kallenbach

It's been reported today that a confidential Exposure Draft Bill for an Australian mandatory data breach notification scheme has been released by the Federal Attorney-General's department to a limited number of key stakeholders.

This news comes in the wake of Commonwealth Attorney-General Mark Dreyfus's comments at this week's launch of Privacy Awareness Week 2013 that he believes there is 'a strong case to move to a mandatory scheme.'

Discussion paper

Former Attorney-General Nicola Roxon released a discussion paper in October last year seeking submissions on whether mandatory data breach notification laws should be introduced in Australia.

The discussion paper was published in response to the Australian Law Reform Commission's 2008 report on the state of the effectiveness of Australian privacy laws, which recommended the introduction of a mandatory breach notification scheme. Our earlier article on the discussion paper can be read here.

Recent developments

On Monday 29 April 2013 at the launch of Privacy Awareness Week 2013, the Attorney-General suggested that mandatory data breach notification laws were on the horizon. Mr Dreyfus said organisations involved in a data breach should inform affected parties in a timely fashion, noting that 'if there continues to be under-reporting of data breaches, or we continue to find out about them only through media reports, some would argue there is a strong case to move towards a mandatory scheme'.

Mr Dreyfus also commented that 'mandatory notification requirements may also act as an incentive for holders of information to secure it'.

The Exposure Draft Bill: what we know

It has since come to light that an Exposure Draft Bill entitled the Exposure Draft Privacy Amendment (Privacy Alerts) Bill 2013 was circulated by the Attorney-General's office to a limited number of key stakeholders this week.

Reports indicate that the following provisions have been included in the Exposure Draft:
  • an organisation must notify the Privacy Commissioner in the event of a 'serious breach'. The notification must outline the nature of the breach, what information was compromised and advise of any remedial steps the affected parties should take;
  • a breach will be considered 'serious' if an organisation fails to take reasonable steps to secure consumer information in accordance with the new Australian Privacy Principles, and if it exposes the affected consumer to a 'real risk of serious harm';
  • an organisation must also notify the affected consumers of the breach. Additionally, the Privacy Commissioner may instruct the organisation to post a public statement to its website and inform media outlets of the breach; and
  • the Privacy Commissioner may declare certain organisations as exempt from the new regulations if it is in the public interest to do so.
Although civil pecuniary penalties of up to $1.7 million have been introduced by the Privacy Amendment (Enhancing Privacy Protection) Act 2012 in the event of serious or repeated interferences with privacy by an entity, it is not yet known whether civil pecuniary provisions will be introduced for failure to comply with the new notification requirements.

What next?

Mr Dreyfus commented on Monday that the Government was still engaging in a consultation process in relation to any Australian data breach notification laws.

Although stakeholders will likely be given an opportunity to prepare submissions on the draft legislation once it has been publicly released, it appears clear that mandatory data breach notification may become a reality in the Australian privacy landscape.

We will provide a more detailed analysis of the Exposure Draft Bill once it has been released for public consultation and comment.

19 April 2013

Death and cyberspace

Posted by Tony Kelly and Paul Kallenbach

An estate plan is a plan formulated to deal with a person's assets which are owned or controlled by them during their lifetime.

We all know that making a will is a critical part of this estate planning process. Ideally, a separate document, usually referred to as the asset register, should also be prepared and updated on an ongoing basis by the will maker. This document acts as a road map to assist the executor to identify assets or entitlements that will need to be accessed, so that they can be held in accordance with the estate plan. An obvious example is a life insurance policy. Not only should details of the policy and the risk advisor be specified on the asset register, but the policy document, birth certificate and anything else needed to make a claim on the policy should be readily to hand.

But what does this have to do with cyberspace?

Our ever increasing use of and reliance on the internet requires that details of online banking accounts websites, domain names as well as social media accounts such as Facebook, Twitter and blogs, together with their passwords, access codes and details of relevant service providers, be added to the asset register. Although a deceased's social networking accounts may not be 'assets' in the traditional sense, the information they contain may be extremely valuable to the deceased and his family – particularly as more and more aspects of our lives are uploaded, in digital form, to cyberspace.

Unfortunately, legislative complexities in America, caused by the lack of interaction between US State and Federal legislation, as well as the privacy policies of social networking providers, have demonstrated that being appointed as someone's executor (or their administrator if they die without a will) may not be sufficient to gain access to the deceased's digital assets.

Facebook, for example, recently refused to give a mother access to her deceased 23 year old son's account following his death in a motorcycle accident, citing corporate policy. Even though she subsequently discovered the password, Facebook changed it without obtaining her consent. And after she sued for access and was successful, Facebook took the page down. A costly pyrrhic victory!

Although the terms and conditions governing social media sites usually contain a prohibition on the account holder making their passwords available to third parties, if the mother had had access to the password in the first place, the death of the account holder would likely never have come to Facebook's notice.

Depending on the scale and complexity of a person's cyberspace activities, it may be advisable to prepare a more detailed document, which not only contains the details of their various digital assets and how to access them, but also includes the content of the 'posting' to be made subsequent to their death, so that they can have the cyberspace funeral of their choice.

The document may also appoint someone more internet savvy than the executor (or executors) to access and manage the deceased accounts and social media sites (including by deleting sensitive information or data where appropriate).

The need to provide for how we want our digital assets to be handled after our death simply reflects the ever increasing role of the internet in our day-to-day activities. And the lack of a cyber 'road map' may well make access to digital assets impossible, not only for our legal representatives, but also for our loved ones.

28 March 2013

ASX requires listed companies to monitor social media

Posted by Nicole Reid and Alberto Colla

Directors and senior executives of companies listed on the Australian Stock Exchange (ASX) have another reason to play close attention to what is being said about their company on the internet. The ASX's recently released updates to its guidance note 8, which deals with listed entities' continuous disclosure obligations, make it clear that the ASX expects companies to monitor social media for certain content. The updates are expected to come into effect around 1 May 2013.

ASX Listing Rule 3.1 requires a listed entity to immediately notify ASX once it becomes aware of 'any information concerning it that a reasonable person would expect to have a material effect on the price or value of the entity's securities'. There are a number of exceptions to this rule, including where the information is (and has not ceased to be) confidential. Listed companies sometimes request trading halts where they are not in a position to 'immediately' disclose market sensitive information, so as to prevent uninformed trading in the market prior to the disclosure being made. This is a practice that the ASX continues to support, where appropriate, to ensure compliance with the spirit of Listing Rule 3.1.

The updated guidance note relating to this Rule 'strongly encourages' an entity that has not yet disclosed existing market sensitive information to monitor 'any investor blogs, chat-sites or other social media it is aware of that regularly include postings about the entity… for signs that the information in the announcement may have leaked'. In the ASX's view, such monitoring should take place both while the company is awaiting board approval for an announcement, and where it is relying on the exception for confidential information. If the monitoring identifies that the market sensitive information has been leaked online, in the ASX's view the company should either immediately request a trading halt or provide the required notification to the ASX.

In the course of the ASX's consultations after the draft updated guidance note 8 was released in October 2012, ASX received a number of comments about this new monitoring requirement. Some respondents were particularly concerned about the breadth of the requirement, and advocated limiting it to 'credible' sites or by taking into account the resources of the listed entity. However, the ASX did not take up these suggestions. In its consultation response, the ASX stated that:
  • the requirement to monitor social media is limited to where market sensitive announcements are pending or are being delayed for reasons of confidentiality;
  • listed entities would be aware of any 'shareholder action' blogs that exist for that entity which may post content including leaked market sensitive information, and many larger listed entities also monitor certain sites as part of their investor relations activities; and
  • accordingly, 'where a market sensitive announcement is pending and where a listed entity is most likely already monitoring the site in question, ASX does not believe it is unreasonable or imposes an undue burden on the entity to expand that monitoring to look for signs that information in the pending announcement may have leaked.'
Although the ASX guidance does not expressly require ongoing monitoring of social media sites, it will be necessary for listed companies to look at their policies and processes before any market sensitive information arises that could be affected by the monitoring requirement. These policies and processes need to be adequate to ensure that appropriate persons are aware of the social media sites on which content about the company may be posted and how those sites may be effectively monitored for relevant information. Even if a company is already carrying out some monitoring of social media for its own purposes, as the ASX suggested, this does not mean that the individuals carrying out that work are best placed to quickly identify information that may indicate early disclosure of market sensitive information. Members of team monitoring social media for reputational and other issues may not even be aware of market sensitive information that has not yet been publicly disclosed, in which case they would not be in a position to identify content that could give rise to a disclosure obligation and accordingly may need to be internally escalated.

Listed entities may also need to ensure that their social media monitoring is sufficient to detect any rumours that may be circulating about the entity and affecting the price of its securities. In such a situation, according to the updated guidance note, the ASX expects that the entity will confirm an accurate rumour or correct a false one, so that the market can trade on an informed basis. As the reach of social media sites expands ever further, rumours circulating on those sites are more likely to be widely disseminated and thereby affect a company's share price if they are perceived to be credible. It will therefore become increasingly important for companies to ensure that social media monitoring is not simply left to marketing personnel but treated with due weight. Failure to comply with continuous disclosure obligations can give rise to penalties, infringement notices and the potential for class actions, so companies need to ensure that their compliance processes are rigorous.

22 March 2013

NZ infringer ordered to pay up

Posted by Genevieve Watt and Paul Kallenbach

Image courtesy of renjith krishnan
In late January, in Association of New Zealand Inc v Enforcement Number: Telecom NZ 2592 [2013] NZCOP 1, the New Zealand Copyright Tribunal issued orders against a copyright infringer under New Zealand's "three strikes" anti-piracy legislation for the first time. The respondent had uploaded musical works via peer-to-peer file sharing protocol BitTorrent, in breach of the copyright holder's exclusive right to communicate the works to the public.

Facts

The respondent in this case was an individual owner of an IP address from which the uploading of music had been detected on three occasions. The applicant was the Recording Industry Association of New Zealand (RIANZ), who filed the application to the Tribunal as representative of the two copyright owners, Island Def Jam Music Group (Universal Music Group New Zealand Limited) and RCA Records (Sony Music Entertainment New Zealand Limited).

The respondent first received a Detection Notice in November 2011, alleging that she had infringed copyright in the Rihanna song Man Down by uploading it via BitTorrent, thereby communicating it to the public in breach of section 16(1)(f) of the Copyright Act 1994 (NZ) (Copyright Act), which grants the copyright owner the exclusive right to communicate copyrighted work to the public. A Warning Notice was subsequently issued to the respondent in June 2012 in respect of a further alleged upload of the same song and finally an Enforcement Notice was sent on 30 July 2012 alleging that the respondent had uploaded the song Tonight Tonight.

The legislation

Section 122 of the Copyright Act creates a graduated response regime for taking enforcement action against people who infringe copyright through file sharing. Under the system, infringers receive a series of three infringement notices of increasing seriousness (Detection, Warning and Enforcement notices) if copyright infringement by file sharing is detected, before a Copyright Tribunal hearing can be held. The first two notices are designed as warnings, and the next notice in the series will be issued if a later, separate infringement occurs after the previous notice has been issued.

Notices are issued by an internet protocol address provider (IPAP) at the request of, and at a cost of $25 per notice to, the copyright owner.

If an infringement is found to have occurred, the Tribunal can require the respondent to pay various sums to the applicant under heads of relief including compensatory damages for infringement, a contribution towards the fees paid by the rights owner to the relevant IPAP, reimbursement of the Tribunal application fee paid by the applicant, and a deterrent sum. The total amount the respondent is ordered to pay cannot exceed NZ$15,000.

The decision

While the respondent claimed she had only downloaded, and not uploaded, the music, she had downloaded the file sharing software to her computer and the Copyright Tribunal accepted that uploading and downloading can occur simultaneously. In this case, the Copyright Tribunal accepted that uploading did occur regardless of the respondent's intentions.

In any case, under the legislation it is also possible to issue infringement notices in respect of downloading, although this has yet to occur.

The respondent was ordered to pay a total of NZ$616.57, based on:
  • the cost of purchasing the songs (a total of $6.57);
  • a contribution of $50 towards the $75 cost of issuing the three notices (calculated as the whole cost of the Enforcement notice, two-thirds of the cost of the Warning Notice, and one-third of the cost of the Detection Notice);
  • $200 for the cost of applying to the Copyright Tribunal; and
  • $120 for each of the three infringements as a deterrent sum.
The deterrent sum was in this case relatively low as the Copyright Tribunal accepted that the respondent had not intended to break the law and found that the infringing acts were not in this instance flagrant.

Is it logical to pursue individuals who download a small amount of music?

While it may seem somewhat inequitable that this particular individual (who the Tribunal noted had not 'flagrantly' broken the law) was pursued when countless others get away with engaging in copyright infringement by file sharing on a daily basis, the 2012 Australian High Court iiNet decision shows that the idea of pursuing the infringers themselves may be the logical (though perhaps not the most practicable) option.

The iiNet decision, in which the applicant copyright holders unsuccessfully argued that internet service provider (ISP) iiNet was liable for the actions of its customers in unlawfully downloading copyrighted content (on the basis that the ISP had authorised their downloads) highlights the difficulty in seeking to address the issue of piracy by pursuing intermediary entities other than individual infringers (see our summary of this decision here). 

Would this approach work in Australia?

Similar 'three strikes' or graduated response systems are in place in other jurisdictions including France and the USA. While there is currently no graduated response system in Australia, there was some discussion about introducing one following the iiNet decision. At this stage, however, the terms of reference for this year's Australian Law Reform Commission (ALRC) copyright inquiry do not address the issue of piracy and enforcement, although the ALRC states that it is watching for any developments in these areas.

Graduated response systems are of course not without their drawbacks.  Critics point to the high cost involved in pursuing individual infringers, a criticism which may be given some weight by the low deterrent amount levied in the RIANZ case.  In the area of unlawful downloading of copyrighted content, it seems that no enforcement option has yet adequately addressed the problem.

An alternative solution may, of course, lie in giving consumers more options to access and download copyrighted content legally.  In an interesting development (given the continued prevalence of unlawful downloading), the International Federation of the Phonographic Industry (IFPI) announced last month that the music industry experienced growth in 2012 for the first time since 1999, thanks in no small part to digital sales. While the overall industry growth was a modest 0.3%, digital sales recorded stronger growth of 9%.  Some industry commentators have suggested that subscription-based services such as Spotify and Pandora (which allow users to legally stream and listen to music) have contributed to this result.

If the 2012 industry growth can be taken as an indication that the tide is to some degree turning against infringing downloads, it may be that creating new ways for users to quickly and legally access copyrighted content will do more to combat piracy than a program of enforcement action.  Watch this space.

08 March 2013

US Supreme Court rejects challenge to warrantless surveillance laws

Posted by Tarryn Ryan and Paul Kallenbach

Last month the United States Supreme Court put a definitive end to a challenge of the constitutionality of laws which allow the US Government to conduct warrantless surveillance of non-US citizens, by finding that the plaintiffs lacked standing to bring the action.[i]  The challenge was brought by human rights groups including Amnesty International, lawyers and journalists, all of whom claimed that their communications were likely to be caught up in surveillance activities carried out under the laws introduced by the FISA Amendment Act.[ii]

What is the FISA Amendment Act?

The FISA Amendment Act was introduced by the Bush administration in 2008.   It expanded the surveillance powers that already existed under the Foreign Intelligence Surveillance Act of 1978 which was designed to facilitate electronic surveillance of foreign powers for foreign intelligence purposes.

The original Act established the Foreign Intelligence Surveillance Court (FISC) which could authorise surveillance where it found there was probable cause to believe that the target was a foreign power or an agent of a foreign power, and that the facilities targeted were being used by that foreign power or an agent of the foreign power.   The Foreign Intelligence Surveillance Court of Review was also established and given jurisdiction to hear appeals of decisions where authorisation had been refused.  Of course all of this went on behind closed doors.

Since 9/11, the US Government has made a series of amendments to the original Act, enabling it to cast a wider net in its surveillance activities.   The FISA Amendment Act is the most recent of those amendments.   It enables the US Government to carry out surveillance of any non-US citizen located outside of the United States for the purpose of acquiring 'foreign intelligence information' - a term that is given an expansive definition, and goes so far as to include information that is 'relevant' to US foreign relations.

Under these amendments, the FISC's powers of oversight have also been whittled down so that the US Government is no longer required to show probable cause or even give the FISC any specific details on who is being targeted or how.   All the US Government need show is that 'a significant purpose of the acquisition is to obtain foreign intelligence information' and that it has targeting and privacy intrusion minimisation procedures in place.   In some circumstances the US Government can proceed with the surveillance without even going before the FISC.

Originally the FISA Amendment Act had a sunset clause of five years.   However, just before Christmas last year, the US Congress, with the support of the Obama administration, extended its operation until 2017.

What happened in the Amnesty International case?

On the day the FISA Amendment Act was passed in 2008, a group of human rights activists, lawyers and journalists launched a challenge to the new laws on the basis that they were unconstitutional. However before the plaintiffs even got to mount their case, the District Court for the Southern District of New York (an original jurisdiction federal court) found that they did not have standing to bring the action.   The United States Court of Appeals for the Second Circuit reversed this decision, which was then appealed to the United States Supreme Court.

In a 5-4 decision, the majority held that the plaintiffs did not have standing to bring their claim because they could not show that their communications had been subject to surveillance.   The plaintiffs' argument was that their lines of work required them to be in communication with individuals that were likely to be targeted under the new laws.   As a result, they said there was 'an objectively reasonable likelihood' that their communications would be intercepted.   In the alternative they argued that the risk of being subject to surveillance required them to take onerous and costly measures to avoid interception.   A number of the plaintiffs were lawyers who represented individuals suspected of terrorism offences.   They submitted that in order to prevent surveillance of their privileged communications with their clients, they had to either not engage in these communications or travel outside of the United States to have them.

Nevertheless the majority held that that the plaintiffs' case was based on a series of assumptions and that they could not show the required likelihood of injury to give them standing.   This decision was staunchly criticised by the minority which said that the Court had often found plaintiffs to have standing where the risk of injury was far less likely than in the present case.

What does this mean?

As the ultimate US appellate court, the US Supreme Court's decision brings an end to the plaintiffs' challenge.  Following the passing of the FISA Amendment Act there were a number of parties who sought to challenge the laws on various grounds.  This was one of the few cases that was still on foot.  Commentators are now pessimistic about whether the laws (which many consider to be unconstitutional) will ever be able to be effectively challenged.   The majority of the Court essentially found that only individuals who could actually show that their communications had been intercepted would be able to make the challenge - which will be difficult seeing as these surveillance activities are, by their very nature, carried out in secrect.

While the existence of these powers is concerning for those in the United States, it is of greater concern to non-US citizens who could potentially be a target of, or even just caught up in, FISA's far reaching surveillance net.

[i] Clapper v Amnesty International USA, No 11-1025, slip op (Sup Ct, Feb 26, 2013)
[ii] The Foreign Intelligence Surveillance Act of 1978, which the FISA Amendment Act amends, is codified at 50 USC ch 36

21 February 2013

The Pirate Bay claims copyright infringed by anti-piracy group

Posted by Tarryn Ryan and Paul Kallenbach

Yes, you read it right.   In a move that has raised more than a few eyebrows, the operators of The Pirate Bay, a website that facilitates the downloading of copyright material, have lodged a complaint with Finnish police and are threatening legal proceedings against a Helsinki-based anti-piracy group for allegedly infringing their copyright in The Pirate Bay's website.

Recently the Copyright Information and Anti-Piracy Centre (CIAPC) launched a lookalike website which, instead of connecting users to links that would enable them to download illegally, directs them to information on how to legitimately download entertainment content.   CIAPC's 'Piraattilahti' website, meaning 'Pirate Bay' in Finnish, looks almost identical to The Pirate Bay website except that CIAPC has replaced the logo with the image of a sinking ship (just to make sure they really get their point across).

The Pirate Bay's website
 
The website launched by CIAPC
 

What is The Pirate Bay?

The Pirate Bay is a website that allows users to search for magnet links which, when opened in a BitTorrent program, start downloading the relevant content (such as a movie or TV show) via peer-to-peer networks.  Since being set up in Sweden in 2003, The Pirate Bay has been engaged in an ongoing game of cat-and-mouse with law enforcement agencies and copyright owners.[1]   In 2009 four men connected with the website faced trial for 'promoting other people's infringement of copyright laws'.  Each was convicted and sentenced to one year in prison in addition to being ordered to pay fines and damages.  Since then, The Pirate Bay has continued to operate but those who now run it have managed to remain anonymous.

Who is CIAPC?

CIAPC is a Finnish anti-piracy organisation that represents members including the Finnish Film Distributors Association and the Finnish division of the International Federation of the Phonographic Industry.

In recent years CIAPC has been active in fighting unauthorised downloads in Finland.  Since May 2011 the organisation has succeeded in obtaining court orders requiring the three largest ISPs in Finland to block The Pirate Bay.  All three ISPs have sought to fight these orders, arguing that making legal downloads more widely available is a preferable way to combat copyright infringement than to resort to censorship.  However the ISPs have been unsuccessful, and following the refusal of Finland's highest court to grant leave to the first ISP to appeal the order, it looks as though CIAPC has come out the winner.

Interestingly CIAPC is no stranger to employing controversial tactics.  In November last year it was widely reported that it had initiated a police raid on a nine year old Finnish girl who it said had illegally downloaded music via The Pirate Bay, resulting in the seizure of the girl's Winnie-the-Pooh laptop.   The father of the girl, who had received a notice from CIAPC informing him that it had traced illegal downloading activity to his account, had previously refused to pay a €600 fine and sign a non-disclosure agreement to settle the matter.

The Pirate Bay's allegations

In a statement issued by The Pirate Bay on its blog, those behind the website seemed to at least acknowledge the irony of their complaint, stating 'while The Pirate Bay may have a positive view on copying, it will not stand by and watch copyright enforcing organisations disrespect copyright'.

The Pirate Bay claims that CIAPC has copied the CSS file that underpins its website in order to set up the copycat site, without first obtaining permission as required by the website's terms of use.  A CSS file contains the coding information that determines the layout and formatting of a website and (at least under Australian copyright law) may be protected by copyright as an original literary work.

In some other countries, CIAPC's use of the copyright material may arguably fall within an exception to copyright infringement (such as the 'fair use' exception in the US, or perhaps the narrower parody and satire exception in Australia).  The Finnish Copyright Act, however, does not contain a parody or satire exception, despite an EU Directive that permits Member States to limit the rights of copyright owners in this manner if they so choose.[2]   This has been the subject of much debate in Finland, which has relatively strict copyright laws.

However, The Pirate Bay may still have a problem with its terms of use, which it claims prevents organisations from using material from its website without permission.  The terms state:
Organisations (for instance, but not limited to, non-profit or companies) may use the system if they clear this with the system operators first. Permission for organisations/ companies is not needed for obvious "well meaning" usage, i.e. distributing works of cultural benefit for the end user. [emphasis added]
No doubt if CIAPC did find itself in court it would simply say that it was entitled to use the CSS file without first seeking permission because its use was 'well meaning'.   It may well be challenging for The Pirate Bay to argue that linking users to information on legal downloading was not a 'well meaning' use.

CIAPC has in fact welcomed The Pirate Bay's threat of legal action, as it would require the website's operators to step out from behind their current veil of anonymity.  This would, in turn, enable CIAPC (and possibly law enforcement agencies as well as other copyright enforcement bodies) to commence legal proceedings against these individuals.

What will the outcome be?

It remains to be seen whether The Pirate Bay's threats of legal action will amount to anything. Presumably the operators will not want to relinquish their anonymity, considering the potential consequences for them should their identities become public.  There have been suggestions that they may enlist a third party to bring the action against CIAPC on their behalf, but it seems unlikely that a court would have much patience for such tactics given the circumstances.

For now, all attention is focused on the Finnish police's next move.

[1] Over the years The Pirate Bay has been blocked by ISPs in a number of countries. Just last year the High Court of England and Wales ordered ISPs operating in its jurisdiction to block access to the site as it was held to facilitate copyright infringement.

[2] Directive 2001/29/EC, Article 4(2)(k).