
For many years mired in its cryptocurrency history, blockchain held little interest to those working outside the financial world. It now offers the fashion industry and its diverse publics the enticing prospect of a transparent value chain for ethical and sustainable fashion, catering to public demands for a right to know data on authenticity and provenance. Whether this is a feasible prospect remains to be seen. Nevertheless, in staking out its position, blockchain appears to be moving into an interesting phase of its short tumultuous existence. In short, it is taking on the character of a “convening technology” – becoming “the focus of a conversation that can [potentially] address issues far beyond what it may ultimately be able to address itself”, and marshalling “resources, institutions and other forms of power”. A difficulty is reconciling this beneficial function with the need for the so-called “technology of trust” to be trustworthy in practice, requiring at least a minimal governance model.
Blockchain technology, introduced in the Bitcoin blockchain in 2009, can be used to ensure the integrity of data using a distributed consensus algorithm, executed by a potentially large number of participants. A variety of blockchain applications have been proposed in recent years. The distributed nature of blockchains is advantageous in many respects but can be challenging from a legal and regulatory perspective. The European eIDAS regulation, for example, regulates trust services—but it assumes these services to be provided by individual trusted entities instead of multiple collaborating parties. We show how a particular eIDAS service, (qualified) electronic time stamps, can be seen as competing with blockchain technology. Both concepts can be used to provide proof of the existence of specific data at a certain point in time. On this basis, we explain to which extent a combination of both concepts is possible and useful in practice. This is founded on both technical and legal arguments. If the combination gains practical relevance, it may endanger a business model of trust service providers, possibly necessitating action by the state.
The right of withdrawal allows authors to unilaterally withdraw a copyright contract and retract copyrighted work to disassociate based on moral reasons. Although accepted in some European jurisdictions, the right of withdrawal is mainly theoretical due to the scarcity of case law resulting from its strict requirements. Therefore, it has been perceived as a concept without practical use. However, this right is underpinned by a significant and still valid European idea reflected by the EU’s General Data Protection Regulation, outlined in the data subject’s right to be forgotten. While the right of withdrawal and the right to be forgotten have different characteristics and goals, these two rights share the same reasoning, emphasising that the same European spirit is still alive and very much needed.
In April 2019, the UK Government’s DCMS released its White Paper for ‘Online Harms’, which would establish in law a new duty of care towards users by platforms to be overseen by an independent regulator. Our earlier research outlines how we got to this point, sets out what the White Paper proposes, and criticises its key aspects. Our objections and criticism remain applicable to the UK Government’s Online Safety Bill. The Parliament is now scrutinising the Bill. The House of Lords Report sparked some optimism that the scrutiny could address critical concerns around free speech in particular. The Draft Online Safety Bill Joint Committee Report, however, suggest otherwise. This paper returns to key arguments as to why risk-based regulation and duty of care are not appropriate for policing content and expression online. We focus on the human rights implications of the Bill, in particular, the provider duties to ‘handle’ legal but harmful content. Here, we reemphasise the vague conceptualisation and nature of this harm, as well as the inadequate duties attached to it. We argue that the independence of OFCOM cannot be guaranteed.
In Thaler v The Comptroller-General of Patents, Designs and Trade Marks (DABUS), Smith J held that an AI owner can possibly claim patent ownership over an AI-generated invention based on their ownership and control of the AI system.This AI-owner approach reveals a new option to allocate property rights over AI-generated output.While this judgment was primarily about inventorship and ownership of AI-generated invention in patent law, it has important implications for copyright law.After analysing the weaknesses of applying existing judicial approaches to copyright ownership of AI-generated works, this paper examines whether the AI-owner approach is a better option for determining copyright ownership of AI-generated works.The paper argues that while contracts can be used to work around the AI-owner approach in scenarios where users want to commercially exploit the outputs, this approach still provides more certainty and less transaction costs for relevant parties than other approaches proposed so far.
Data identifiability standards in Canada and the European Union rely on the same concepts to distinguish personal data from non-personal data. However, courts have interpreted the substantive content of such metrics divergently. Interpretive ambiguities can create challenges in determining whether data has been successfully anonymised in one jurisdiction, and whether it would also be considered anonymised in another. These difficulties arise from the law’s assessment of re-identification risk in reliance on qualitative tests of ‘serious risk’ or ‘reasonable likelihood’ as subjectively appreciated by adjudicators. We propose the use of maximum re-identification risk thresholds and quantitative methodologies to assess data identifiability and data anonymisation relative to measurable standards. We propose that separate legislation be adopted to address data-related practices that do not relate to demonstrably identifiable data, such as algorithmic profiling. This would ensure that regulators do not expand the jurisprudential conception of identifiable data purposively to capture such practices.
Algorithms have entered courts, e.g. via scores assessing recidivism. At first sight, recent applications appear to be clear cases of solutionism, i.e. attempts at fixing social problems with technological solutions. Deploying thematic analysis on assessments of two of the most prominent and widespread examples of recidivism scores, COMPAS and the PSA, casts doubt on this notion. Crucial problems – as different as “fairness” (COMPAS) and “proper application” (PSA) – are not tackled in a technological manner but rather by installing conversations. It shows that even technorationalists never see the technological solution in isolation but are actively searching for flanking social methods thereby accounting for problems that cannot be eased technologically. Furthermore, we witness social scientists called upon as active parts of such engineering.
Sharing information about vulnerabilities and attacks is essential to defend information systems against threats such as malware, phishing and unauthorised access.By identifying this information sharing as a legitimate interest of data controllers, and highlighting the public interests that it serves, the draft Network and Information Security Directive provides a framework to encourage European participation in global information sharing, benefitting all users of the Internet.
The law classically provides strong protection to whatever is inside a home. That protection is lost now that our photo albums, notes and other documents have become digital and are increasingly stored in the cloud. Even if their owner never intended these documents to be shared, their copies in the cloud may be accessed by law enforcement, under possibly lower conditions than apply to home searches. In this paper, we study this problem from a theoretical perspective, asking whether it is possible to establish home-equivalent legal protection of those private digital storage spaces (smartphones, private cloud storage accounts) that most closely resemble the home as a storage environment for private things. In particular, we study whether it is possible, using technological design, to clearly separate digital storage spaces that are used privately versus storage spaces used to share data with others. We sketch a theoretical architecture for such a ‘digital home’ that most closely resembles the physical home in terms of the space that is the most personal storage environment for private files. The architecture guarantees the data are indeed only stored for private use, and can never be shared with others unless the device used for storage itself is shared. We subsequently argue that the law should offer ‘home’ protection to data stored using this system, as an intermediate stepping-stone towards more comprehensive legal protection of cloud-stored data. Such protection is needed, since nowadays, not the home or the smartphone, but the smartphone/cloud ecosystem holds ‘the privacies of life’.
Information is a central concept in data protection law. Yet, there is no clear definition of the concept in law – in legal text or jurisprudence. Nor has there been extensive scholarly consideration of the concept. This lack of attention belies a concept which is complex, multifaceted and functionally problematic in the GDPR. This paper takes an in-depth look at the concept of information in the GDPR and offers up three theses: (i) the concept of information plays two different roles in the GPDR – as an applicability criterion and as an object of regulation; (ii) the substantive boundaries of the concepts populating these two roles differ; and (iii) these differences are significant for the efficacy of the GDPR as an instrument of law.
In this article, I review the legal and regulatory obstacles to the introduction of autonomous vehicles.I provide an overview of the key legislation which is relevant to the introduction of autonomous vehicles in England and Wales.I discuss the motor liability and insurance implications of the introduction of autonomous cars and the legal framework for the testing of autonomous vehicles on public roads.I conclude that there is likely to be significant volume of emerging legislation that car manufacturers and suppliers will be required to navigate as they launch increasingly autonomous driving systems.It is also likely that we will see an increase in the volume and complexity of litigation involving parties such as vehicle manufacturers, software companies, suppliers and mapping agencies.
Google’s Duplex illustrates the great strides made in AI to provide synthetic agents the capabilities to intuitive and seemingly natural human-machine interaction, fostering a growing acceptance of AI systems as social actors. Following BJ Fogg’s captology framework, we analyse the persuasive and potentially manipulative power of emotionally intelligent conversational agents (EICAs). By definition, human-sounding conversational agents are ‘designed to deceive’. They do so on the basis of vast amounts of information about the individual they are interacting with. We argue that although the current data protection and privacy framework in the EU offers some protection against manipulative conversational agents, the real upcoming issues are not acknowledged in regulation yet.
The General Court of the EU confirmed the decision of the EUIPO Second Board of Appeal in relation to the EU figurative trade mark registered by adidas AG, according to which this mark, consisting of "three parallel equidistant stripes", is devoid of distinctive character.The General Court confirmed that adidas AG had failed to demonstrate use of this mark throughout the EU or that the mark, which is inherently devoid of distinctive character, had, by virtue of that use, come to identify the goods for which it was registered and thus had acquired distinctiveness.The General Court, in reaching this conclusion, relied on its assessment that most of the evidence provided by adidas AG was irrelevant for the purposes of establishing that the mark had acquired distinctive character through use as it was not directly linked to the use of the mark in its registered form.In addition, the General Court recognized that there was nothing in the application of adidas AG to suggest that the registered trade mark could be interpreted as a "pattern mark".Finally, in relation to the "law of permissible variations", the General Court stated that because the figurative mark at issue is so simple, even a slight change can alter its distinctiveness.
By Jade Kouletakis. The Marrakesh Treaty to Facilitate Access to Published Works for Persons Who Are Blind, Visually Impaired, or Otherwise Print Disabled was signed on behalf of the European Union on 30 April 2014. On 13 September 2017, the European Union created a Directive (2017/1564) implementing its obligations under the Marrakesh Treaty. This Directive and corresponding Regulations came into force on 12 October 2018, which was the deadline provided to member states in implementing the Directive. On the 11th of September 2018, the United Kingdom made the Copyright and Related Rights (Marrakesh Treaty etc.) (Amendment) Regulations 2018. The UK’s Marrakesh Regulations came into force the day before the EU deadline, and the lack of in-depth critical debate around this piece of legislation as well as the EU having initiated legal proceedings against the UK underscores the necessity of this paper. This paper seeks to assess the UK’s Marrakesh Regulations in light of both the EU legislation as well as non-EU international obligations to which the UK will remain bound beyond Brexit. This paper will ask: Can it be said that the UK in implementing the Marrakesh Treaty is fulfilling its obligations owed both to the EU as well as its own citizens?