As the year draws to a close, it’s worth looking back over a range of important legal developments in the world of electronic commerce, a number of which set the stage for fireworks in the months and years ahead. Wishing all of our readers a wonderful holiday season, and the best and brightest New Year, we hope you enjoy our “top five” list.
Coming in at number five ...
Friday, December 20, 2013
Friday, December 13, 2013
Song Beverly Strikes Again: Email Address Collection Added to Potentially Worrisome Activity
As we've previously blogged, retailers who sell products to consumers in California and Massachusetts, as well as a number of other states, run the risk of costly class action lawsuits if they collect customer zip codes in connection with purchase of goods by credit card. The prohibitions in those states, as we've explained, often go beyond zip codes, and can include -- in California, for example -- any information that does not appear on the face of the credit card.
A recent decision by the United States District Court in California involved the collection of e-mail addresses in credit card transactions, and found against a retailer on a motion dismiss -- propelling the case to trial. That decision adopted what some might call an inordinately expansive interpretation of the underlying law by the Supreme Court of California, and made things far worse by adding an apparent misreading of the statute to the mix. Not for the faint of heart, but certainly important for the prudent direct marketer who hopes to avoid costly and sometimes bogus lawsuits, the decision helps underscore the risks faced by even the most diligent companies -- risks high enough that companies are often forced to settle when they know in their heart of hearts that they're right.
Wednesday, December 4, 2013
Supreme Court Denies Petitions for Cert of Amazon and Overstock
As we recently wrote, last spring New York State’s highest court, the Court of Appeals, issued a decision upholding the state’s Internet affiliate nexus law after a challenge made by Overstock.com and Amazon.com. The Court of Appeals found that the law, which creates a rebuttable presumption of nexus for out-of-state vendors who employ in-state affiliates, satisfies substantial nexus requirements and does not violate the Due Process clause.
In September, Overstock.com and Amazon.com sought review of the decision of the Court of Appeals by filing petitions for certiorari with the United States Supreme Court. After extensive briefing by the petitioners, the State of New York, and many amicus curiae, on December 2, the Supreme Court denied the petitions for cert. (See the cases’ status here and here.)
This ends the petitioner’s facial constitutional challenge to the New York affiliate nexus law as Overstock.com and Amazon.com have now exhausted their appellate options. The decision by the Supreme Court not to hear the case, however, does not mean that every state’s affiliate nexus law is valid and enforceable. For instance, the Illinois Supreme Court held in October that Illinois’s Internet affiliate nexus statute was preempted by the Federal Internet Tax Freedom Act. The Supreme Court’s decision Monday has no impact on the now unenforceable Illinois law.
In September, Overstock.com and Amazon.com sought review of the decision of the Court of Appeals by filing petitions for certiorari with the United States Supreme Court. After extensive briefing by the petitioners, the State of New York, and many amicus curiae, on December 2, the Supreme Court denied the petitions for cert. (See the cases’ status here and here.)
This ends the petitioner’s facial constitutional challenge to the New York affiliate nexus law as Overstock.com and Amazon.com have now exhausted their appellate options. The decision by the Supreme Court not to hear the case, however, does not mean that every state’s affiliate nexus law is valid and enforceable. For instance, the Illinois Supreme Court held in October that Illinois’s Internet affiliate nexus statute was preempted by the Federal Internet Tax Freedom Act. The Supreme Court’s decision Monday has no impact on the now unenforceable Illinois law.
Tuesday, November 26, 2013
Mail Order Merchandise Rule: Are Your Business Processes up to Snuff?
This is the first in a series of blog posts highlighting the major legal and regulatory issues that are specific to the multichannel merchant. The Mail Order Merchandise Rule, promulgated by the Federal Trade Commission, is intended to ensure that mail order customers actually receive the items that they order from catalog or online merchants. The Rule requires that when a seller advertises merchandise, it must have a reasonable basis for stating or implying that it can ship the merchandise within a certain time. If the business makes no shipment statement, it must have a reasonable basis for believing that it can ship within 30 days. That is why direct marketers sometimes call this the "30-day Rule." Surprisingly, though, many well-established mail order companies have only a loose grip on the operational steps necessary to comply with this rule.
It is usually the case in the highly competitive, technologically advanced environment of mail order and internet sales, that merchants are easily able to comply with the Rule by providing a stated shipment representation. If a website says the product will be shipped in two days, it almost always is, and often it is shipped even sooner. But when products are not timely shipped, things sometimes go a little sideways. The most common reason for failure to ship within the stated time frame is the lack of a product–the back order issue.
The rule provides that, if after taking the customer’s order, a seller learn that it cannot ship within the time stated, it must seek the customer’s consent to the delayed shipment. If it is the first such delay, and if the seller can provide a revised shipment date, it must notify the customer of his or her right to cancel the order; sellers are permitted to treat the client’s silence in response as an expression of assent. But, if there is a second delay, or if the seller cannot provide a revised shipment date, then the seller MUST get the client to consent affirmatively to the continued delay. If a seller cannot obtain the customer’s consent to the delay – or if the customer refuses to consent -- the seller must, without being asked, promptly refund all the money the customer paid for the unshipped merchandise.
It is usually the case in the highly competitive, technologically advanced environment of mail order and internet sales, that merchants are easily able to comply with the Rule by providing a stated shipment representation. If a website says the product will be shipped in two days, it almost always is, and often it is shipped even sooner. But when products are not timely shipped, things sometimes go a little sideways. The most common reason for failure to ship within the stated time frame is the lack of a product–the back order issue.
The rule provides that, if after taking the customer’s order, a seller learn that it cannot ship within the time stated, it must seek the customer’s consent to the delayed shipment. If it is the first such delay, and if the seller can provide a revised shipment date, it must notify the customer of his or her right to cancel the order; sellers are permitted to treat the client’s silence in response as an expression of assent. But, if there is a second delay, or if the seller cannot provide a revised shipment date, then the seller MUST get the client to consent affirmatively to the continued delay. If a seller cannot obtain the customer’s consent to the delay – or if the customer refuses to consent -- the seller must, without being asked, promptly refund all the money the customer paid for the unshipped merchandise.
Labels:
30-Day Rule,
FTC,
Internet retailer,
Mail Order Rule
Friday, November 22, 2013
Direct Marketing Association Re-files Challenge to Colorado Notice and Reporting Law in State Court
We have been updating readers on developments regarding the court challenge brought by the Direct Marketing
Association (“DMA”) to a 2010 Colorado law that purported to require Internet retailers and other remote sellers that do not collect Colorado sales tax to: (1) give certain notices to their Colorado customers regarding the purchaser’s obligation to self-report Colorado use tax; and (2) file reports with the Colorado Department of Revenue detailing the private purchasing information of their Colorado customers. The DMA won a preliminary injunction in January 2011 in federal District Court suspending the law on the grounds that it violated the Commerce Clause. The Court later made the injunction permanent when it awarded the DMA summary judgment in March 2012. The State appealed.
In August 2013, the Court of Appeals for the Tenth Circuit ruled on its own initiative that the Tax Injunction Act (“TIA”) barred federal court jurisdiction over the DMA’s claims. The Court of Appeals did not reach the merits of the DMA’s Commerce Clause claims, but rather ordered that the claims be dismissed on procedural grounds. The Court held that the DMA was required under the TIA to bring its claims in Colorado state court. The DMA requested rehearing on the jurisdictional issue, but the Tenth Circuit declined in early October to rehear the matter. The Court of Appeals then issued a mandate to the District Court on October 9, directing the lower court to dissolve the injunction and dismiss the claims. (The District Court has not yet implemented the mandate, so for now the federal injunction remains in place.)
On November 5, 2013, the DMA re-filed its challenge to the Colorado notice and reporting law in state District Court in Denver. At the same time, the DMA moved for a preliminary injunction, in order to continue the suspension of the law after the federal court injunction is lifted. Briefing on the motion for a preliminary injunction is expected to conclude in December, with a hearing on the motion likely to be scheduled for early January 2014. The DMA will request that the state court rule on the injunction request prior to January 31, the deadline under the law for retailers to send certain annual notices to customers who purchased at least $500 in goods from the retailers in the prior year.
Brann & Isaacson partners George Isaacson and Matthew Schaefer are co-counsel to the DMA in connection with the appeal.
We will keep you apprised of further developments in the state court proceeding.
In August 2013, the Court of Appeals for the Tenth Circuit ruled on its own initiative that the Tax Injunction Act (“TIA”) barred federal court jurisdiction over the DMA’s claims. The Court of Appeals did not reach the merits of the DMA’s Commerce Clause claims, but rather ordered that the claims be dismissed on procedural grounds. The Court held that the DMA was required under the TIA to bring its claims in Colorado state court. The DMA requested rehearing on the jurisdictional issue, but the Tenth Circuit declined in early October to rehear the matter. The Court of Appeals then issued a mandate to the District Court on October 9, directing the lower court to dissolve the injunction and dismiss the claims. (The District Court has not yet implemented the mandate, so for now the federal injunction remains in place.)
On November 5, 2013, the DMA re-filed its challenge to the Colorado notice and reporting law in state District Court in Denver. At the same time, the DMA moved for a preliminary injunction, in order to continue the suspension of the law after the federal court injunction is lifted. Briefing on the motion for a preliminary injunction is expected to conclude in December, with a hearing on the motion likely to be scheduled for early January 2014. The DMA will request that the state court rule on the injunction request prior to January 31, the deadline under the law for retailers to send certain annual notices to customers who purchased at least $500 in goods from the retailers in the prior year.
Brann & Isaacson partners George Isaacson and Matthew Schaefer are co-counsel to the DMA in connection with the appeal.
We will keep you apprised of further developments in the state court proceeding.
Friday, November 15, 2013
MFA Update: Rep. Goodlatte’s Seven Principles and an Interview with George Isaacson
Although the Marketplace Fairness Act (S. 743) ("MFA") has not yet progressed out of a House committee since its Senate passage last spring, it continues to make headlines. In late September, the House Judiciary Committee, chaired by Rep. Bob Goodlatte (R-Va.), released seven “Principles on Internet Sales Tax.” Brann & Isaacson senior partner George Isaacson was recently profiled by State Tax Notes discussing both the MFA and Goodlatte’s Seven Principles.
The Seven Principles outlined by Representative Goodlatte provide for:
The Seven Principles outlined by Representative Goodlatte provide for:
- Tax Relief – “no new or discriminatory taxes not faced in the offline world”
- Tech Neutrality – brick and mortar and online businesses “should all be on equal footing. The sales tax compliance burden on online Internet sellers should not be less…than that on similarly situated offline businesses”
- No Regulation Without Representation – taxpayers “should have direct recourse to protest unfair, unwise or discriminatory rates and enforcement”
- Simplicity – no “onerous compliance requirements,” “laws should be so simple and compliance so inexpensive and reliable as to render a small business exemption unnecessary”
- Tax Competition – “Governments should be encouraged to compete with one another to keep tax rates low and American businesses should not be disadvantaged vis-à-vis their foreign competitors”
- States’ Rights – “States should be sovereign” and “the federal government should not mandate that States impose any sales tax compliance burdens” and
- Privacy Rights – “Sensitive customer data must be protected.”
Friday, October 25, 2013
California Ups the Ante On Privacy Policy Disclosures
For the past decade, California law has set the template for commercial website privacy policies. With the passage of a new law, set to take effect January 1, 2014, the state has updated the disclosures required of any commercial website operator who collects personally identifiable information from California residents.
California’s Online Privacy Protection Act. In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy. Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement. Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act). Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names. The privacy policy also must be “conspicuously” posted, as defined by the statute.
Now, however, the law has been significantly expanded.
California’s Online Privacy Protection Act. In 2003, California became the only state to require all websites that collect personal information (“PII”) from visitors – in this case, California residents – to post a privacy policy. Until then, there was no generally applicable privacy policy requirement under either state or federal law, and, to this day, neither the other states nor the federal government have imposed such a requirement. Federal privacy policy requirements have been limited to specific kinds of information (such as under Children’s Privacy Protection Act) or industries (under the Health Insurance Portability and Accountability Act). Under the 2003 law, Internet sites need to identify the “categories” of personally identifiable information collected about “individual consumers”; describe the “categories” of third parties with whom the information may be shared; disclose (if there is one) any process for individuals to review or request changes to their personal information; explain how notice is given to consumers of changes in the privacy policy; and post the policy’s effective date. The definition of PII is more expansive than encountered in data breach statutes, and includes email addresses, partial addresses (including street names and towns), and first and last names. The privacy policy also must be “conspicuously” posted, as defined by the statute.
Now, however, the law has been significantly expanded.
Subscribe to:
Posts (Atom)