IP Law Daily, COPYRIGHT—C.D. Cal.: No DMCA violation for logging into a database with credentials that have passed to someone else, (May 25, 2023)
Law Firms Mentioned:Fox Rothschild LLP | Valle Makoff LLP
Organizations Mentioned:Fox Rothschild, LLP | Valle Makoff, LLP | iSpot.TV, Inc.
By Matthew Hersh, J.D.
Because the login credentials were used in the “technological manner” by which they were original authorized, it did not matter who owned the credentials now.
The employee of a media agency with authorized access to a third party’s advertising database did not violate the DMCA by continuing to use her login credentials after she left her place of employment, the federal court for Los Angeles has held. The court, in an order that acknowledged the lack of controlling circuit court authority—and indeed openly disagreed with other district courts in the circuit—found that merely continuing to use login credentials that were at one point authorized, even if those credentials now belonged to someone else, did not, without more, constitute “circumvention” of a technical measure in violation of the law (iSpot.TV, Inc. v. Teyfukova, May 22, 2023, Frimpong, M.).
The ruling is the latest in an ongoing dispute between two companies engaged in the business of measuring the television advertising. iSpot,which according to its complaint is “best known for its work in real-time television advertising data and analytics,” maintains a proprietary database which provides extensive advertising data organized by industry. Electronic Data Oracle,another company that provides companies with insights into the efficacy of TV ads, specializes particularly in data relating to consumer engagement and purchase activity.
The companies were partners before becoming adversaries. Between 2014 and 2018, the database owner gave its competitor access, under a series of agreements, to a portion of its database tracking analytics and data in the movie industry. But after the contract ended, the competitor launched a program—the “Ad Engage Convergent Database”—that the database owner believed to be similar to its own. The database owner also came to believe that one of its competitor’s employees, Nadezhda Teyfukova, had used her credentials as a former authorized user of the database to access the database on behalf of the competitor for years after the end of the contract.
The database owner sued its competitor as well as its employee on multiple grounds, including theft of trade secrets under federal and California law, breach of contract, and violations of the Digital Millennium Copyright Act, or DMCA. The competitor and its employee moved to dismiss, leading to this series of opinions.
Trade secrets claims. The court, in an initial opinion, found that the database owner had adequately pleaded a claim under the Defendant Trade Secrets Act as well as its California counterpart. The competitor alleged the database owner failed to take reasonable steps to maintain secrecy because it did not insist that every person who accessed the database sign their own individual confidentiality agreement. But that did not preclude the complaint, the court found. The database owner alleged that a company named Horizon was given access to the database and that Teyfukova, at that time a Horizon employee, is the one who accessed the database on Horizon’s behalf. To be sure, the court noted, Teyfukova herself did not sign an NDA—only her employer. But as the court noted, the complaint alleged that Teyfukova, as a former employee of Horizon, “was—in some capacity—likely aware of the limitations attached to her use of the credentials.” That was enough to state a claim.
Breach of contract claims. The court’s initial opinion also found that the database owner adequately stated a claim for breach of contract. The claim was adequately pleaded, the court found, because it alleged that the competitor breached the contract by accessing unauthorized portions of the database and using that to develop its own product. Moreover, the court noted, the claim was not preempted by trade secrets law. Under Washington State law, which applied to the contract here, a breach of contract claim is preempted where it arises out of the same facts as a trade secrets claim. But it was clear from the complaint, the court noted, that “iSpot’s supporting allegations arise from two different periods and involve two separate claims, making preemption inappropriate.”
DMCA claim. But while the trade secrets and breach of contract claims would remain in the case, the court found, the DMCA claim could not. Here the court’s opinion unfolded over two different opinions at two different times.
The court’s first opinion found that the competitor’s employee could not have violated the DMCA because she was not accused of having circumvented a technical measure. The DMCA makes it unlawful “to descramble a scrambled work, to decrypt an encrypted work, or otherwise to avoid, bypass, remove, deactivate, or impair a technological measure” without the authority of the copyright owner. Here, the competitor’s employee was accused only of having used login credentials from her former employee, Horizon—credentials that she was allowed to have when with Horizon—to continue to access the database without authorization. To be sure, the court noted, the Ninth Circuit had not yet ruled on whether conduct of this nature could constitute “circumvention” as defined under the law. And indeed, the court noted, many district courts within and without the circuit had held that it could. But the court disagreed. The statute used words like descramble, decrypt, bypass, remove, deactivate, and the like, the court noted. Under the plain meaning of the statute, the court noted, the conduct alleged did not meet the threshold.
The court’s second opinion stood by its first, although it had to grapple with several additional arguments that the database owner made in an amended complaint. For one thing, the database owner argued, when the competitor’s employee made use of the credentials from her former job, she was effectively “stealing” those credentials from her former employer. But whether she violated any duty of loyalty to her former employer or whether that former employer still had legal ownership of the credentials was of no matter under the words of the DMCA, the court found. Nor did it matter, as the new complaint alleged, that the competitor actually directed its new employee to use her credentials from her former job. “Even if EDO directed Teyfukova to utilize the Horizon credentials to access the Database,” the court reasoned, “it does not change the fact that Teyfukova did not take any steps that qualify as circumvention within the plain meaning of the statute. The SAC still only alleges that Teyfukova individually used the credentials in the technological manner by which she was authorized to do so—albeit without authorization.”
The Case is No. 2:21-cv-06815-MEMF-MAR.
Attorneys: David Aronoff (Fox Rothschild LLP) for iSpot.TV, Inc. Jeffrey B. Valle (Valle Makoff LLP) for Nadezhda Teyfukova a/k/a Nadya Teyfukova.
Companies: iSpot.TV, Inc.
Cases: Copyright TechnologyInternet TradeSecrets CaliforniaNews