Justia Internet Law Opinion Summaries

by
A man was investigated after Google and Yahoo flagged several of his email accounts for sending and storing what appeared to be child pornography. Both companies identified the user through information like a shared recovery phone number, birthdate, and selfies associated with the accounts. Yahoo manually reviewed and confirmed the images as child pornography before reporting them to the National Center for Missing and Exploited Children (NCMEC). Google used both human review and a hash-value matching protocol, whereby a file’s unique digital fingerprint was compared against a database of previously identified illegal images. One of the files in the defendant’s account matched the hash of a known child pornography image. Law enforcement, after receiving tips from NCMEC, conducted warrantless searches and confirmed the illicit nature of the files, leading to search warrants for the defendant’s residence and devices, which yielded more incriminating evidence.The United States District Court for the Middle District of Florida denied the defendant’s motions to suppress the evidence (arguing a Fourth Amendment violation), to dismiss one of the charges on double jeopardy grounds, and to exclude certain evidence. The court also rejected his arguments concerning the admissibility of defense evidence, the sufficiency of the evidence, and the jury instructions. The defendant was convicted by a jury on both distribution and possession charges and given an enhanced sentence based on a finding of a pattern of activity involving abuse or exploitation. His subsequent motions for psychological evaluation and sentencing continuance were also denied.On appeal, the United States Court of Appeals for the Eleventh Circuit held that Google’s use of hash-value matching constituted a valid private search under the Fourth Amendment, so the government’s warrantless review did not violate the defendant’s rights. The court also held that possession and distribution of child pornography are separate offenses for double jeopardy purposes. The appellate court affirmed all district court decisions except for the application of a pattern-of-activity sentencing enhancement, which it found improper; it vacated the sentence and remanded for resentencing. View "USA v. Brillhart" on Justia Law

by
In response to a mass shooting in Buffalo, New York, that was planned, publicized, and broadcast via social media, the state legislature enacted the Hateful Conduct Law (HCL). This statute requires social media networks conducting business in New York to provide a clear, easily accessible mechanism for users to report "hateful conduct" and to maintain a public policy describing how the network will address such reports. "Hateful conduct" is defined as using a social media network to vilify, humiliate, or incite violence against groups based on protected characteristics. Plaintiffs, including operators of social media platforms, challenged the law before it took effect, arguing that it would compel them to speak against certain content and chill protected expression.The United States District Court for the Southern District of New York granted a preliminary injunction, finding that the HCL likely violated the First Amendment by compelling social media networks to endorse the state’s definition of hateful conduct and to publish policies about it. The court determined that the law could have a chilling effect on free speech, even though it did not require removal of the content itself. The Attorney General appealed to the United States Court of Appeals for the Second Circuit, which determined that resolution of the constitutional issues depended on the proper interpretation of the HCL under New York law. The Second Circuit certified three questions to the New York Court of Appeals concerning the scope of the statute’s requirements.The New York Court of Appeals concluded that social media networks comply with the law if their reporting mechanism and public policy do not explicitly reference or define "hateful conduct," as long as users can report such conduct and learn how reports will be addressed. The court further held that the law does not require networks to respond to reports of hateful conduct. The certified questions were answered accordingly. View "Volokh v James" on Justia Law

by
Guild Mortgage Company LLC and CrossCountry Mortgage LLC are direct competitors in the residential mortgage industry. Over an 18-month period, several Guild employees in the Kirkland, Washington branch, including the branch manager and other high-level staff, were allegedly recruited by CrossCountry while still employed by Guild. According to the complaints, these employees solicited their colleagues to also move to CrossCountry, diverted customers and loan applications, and accessed Guild’s computer systems to take confidential and proprietary information. The employees had signed agreements with Guild prohibiting such conduct, and Guild subsequently lost nearly its entire Kirkland branch workforce to CrossCountry.After Guild initiated arbitration against the former employees and prevailed, it filed a lawsuit in the Superior Court of San Diego County against CrossCountry. Guild’s claims included interference with economic advantage, interference with contract, violation of California’s Comprehensive Computer Data Access and Fraud Act (CCDAFA), unfair competition, and aiding and abetting tortious conduct. The Superior Court sustained CrossCountry’s demurrers, finding that the claims were preempted by the California Uniform Trade Secrets Act (CUTSA) or otherwise failed to state a cause of action, and dismissed the case without leave to amend.The Court of Appeal, Fourth Appellate District, Division One, reviewed the case. It held that Guild had adequately alleged actionable duties of loyalty and, for the branch manager, fiduciary duty, that were breached by the employees and aided by CrossCountry. The court found that the claims for interference and violation of the CCDAFA were not displaced by CUTSA because they arose from conduct beyond trade secret misappropriation. The court also held that the unfair competition claim could proceed since the other claims were viable. The Court of Appeal reversed the judgment in favor of CrossCountry and remanded for further proceedings. View "Guild Mortgage Company v. CrossCounty Mortgage" on Justia Law

by
The case concerns a man who sued several parties after negative posts about him appeared in a large Chicago-based Facebook group where women share experiences about local men. The posts, made in late 2023, included a woman he briefly dated recounting her unpleasant experiences, attaching a screenshot of a profane text message he sent her after their breakup. Other posts by unidentified users included supportive comments and, in one instance, a link to a news article about a criminal case involving someone with a different name and appearance. The plaintiff alleged these posts caused him reputational, economic, and emotional harm.In the United States District Court for the Northern District of Illinois, the defendants—including the former date, her parents (for allegedly allowing use of their internet connection), the group’s administrators, and Meta Platforms—moved to dismiss the complaint for failure to state a claim. The court granted the motions, finding the claims legally insufficient and dismissing the case with prejudice. The plaintiff appealed and voluntarily dismissed claims against unidentified “Jane Doe” defendants to preserve diversity jurisdiction.The United States Court of Appeals for the Seventh Circuit reviewed the district court’s dismissal. The appellate court affirmed, holding that the plaintiff failed to state plausible claims under the Illinois Right of Publicity Act because none of the defendants used his likeness for a commercial purpose. The court also found the “doxing” claim insufficient, as there were no plausible allegations of intent or recklessness regarding harm or stalking. Defamation and related claims failed because the allegedly defamatory material could be innocently interpreted or lacked special damages. The court also concluded that the appeal as to the woman and her parents was frivolous and ordered the plaintiff and his attorneys to show cause why sanctions should not be imposed for bringing a meritless appeal and for submitting briefs containing fictitious quotations and misstatements of law. The court awarded costs to other appellees and referred attorney conduct to state disciplinary authorities. View "D'Ambrosio v Meta Platforms, Inc." on Justia Law

by
An educational technology company was contracted by a county office of education to provide software and technology services to school districts, which involved collecting and storing various types of student data, including medical information. In 2022, the company experienced a data breach that resulted in unauthorized access to student medical records, including those of a minor plaintiff. The minor, through a guardian, filed a class action lawsuit alleging violations of both the Confidentiality of Medical Information Act (CMIA) and the Customer Records Act (CRA), claiming the company was negligent in protecting confidential medical information and failed to provide timely disclosure of the breach.The Superior Court of Ventura County granted the company’s demurrer and dismissed the case, concluding that the plaintiff failed to state a claim under either statute, as the company was not a covered entity under the CMIA or CRA and the plaintiff was not a “customer” under the CRA. The California Court of Appeal, Second Appellate District, Division Six, reversed, finding that the company fell within the scope of both statutes and that the plaintiff had alleged sufficient facts to support both claims. The appellate court also determined that the trial court erred by denying leave to amend the complaint.The Supreme Court of California reversed the appellate decision. The Court held that the plaintiff did not sufficiently allege the company was a “provider of health care” under the CMIA, nor that he was the company’s “customer” under the CRA, so no claim was stated under either statute. However, the Court clarified that under the CMIA, a breach of confidentiality occurs when medical information is exposed to a significant risk of unauthorized access or use, and actual viewing by an unauthorized party is not required. The judgment was reversed and remanded for further proceedings. View "J.M. v. Illuminate Education, Inc." on Justia Law

by
A defendant accessed the internet using a publicly available Wi-Fi network operated by a local business, A&W, located near his home. Access to the Wi-Fi required users to acknowledge terms of service that, among other things, stated A&W did not actively monitor the network but could cooperate with legal authorities and disclose users’ activities in response to lawful requests. After A&W’s owner and their consultant noticed suspicious activity flagged by their firewall, they informed law enforcement, which then directed A&W to monitor and log the defendant’s internet activity for approximately one year. This surveillance included tracking over 255,000 webpage visits and collecting packet capture data. Information obtained through this monitoring led to the defendant’s identification, arrest, and conviction on charges of encouraging child sexual abuse.The case was first heard in the Lane County Circuit Court, where the defendant moved to suppress evidence obtained from the year-long monitoring. The trial court found A&W’s owner and consultant acted as state agents but ruled that the defendant had no protected privacy interest in his use of the public Wi-Fi network, and denied the suppression motion. After a stipulated facts trial, the court convicted the defendant. On appeal, the Oregon Court of Appeals affirmed, holding that the defendant did not have a constitutionally protected privacy interest in his internet browsing activities on the public network under the circumstances.The Supreme Court of the State of Oregon reversed the decision of the Court of Appeals in part, and reversed the judgment of the circuit court, remanding the case for further proceedings. The Supreme Court held that under Article I, section 9, of the Oregon Constitution, a person retains a right to privacy in their internet browsing activities even when accessing the internet via a public network, and that acknowledging terms of service like those present did not eliminate that privacy right. The year-long warrantless monitoring constituted a “search,” and the State failed to justify the lack of a warrant. View "State v. Simons" on Justia Law

by
Several major music copyright owners, including a leading entertainment company, sought to hold an Internet service provider responsible for copyright infringement committed by its subscribers. The service provider, which serves millions of customers, was notified by a monitoring company of over 160,000 instances where its subscribers’ IP addresses were linked to alleged copyright violations such as illegal music file sharing. Although the provider had policies prohibiting infringement and took steps such as issuing warnings and suspending service, the copyright holders argued these measures were inadequate and brought suit seeking to impose liability on the provider for continuing to serve known infringers.The case was tried in the United States District Court for the Eastern District of Virginia. There, the jury found in favor of the copyright owners on both contributory and vicarious liability, and determined the provider’s infringement was willful, awarding $1 billion in statutory damages. After the District Court denied the provider’s post-trial motion, the United States Court of Appeals for the Fourth Circuit affirmed the finding of contributory liability, reasoning that supplying a service with knowledge it would be used for infringement was sufficient. The Fourth Circuit, however, reversed as to vicarious liability and remanded for a new determination of damages.The Supreme Court of the United States reviewed the case concerning contributory liability. The Court held that a service provider is contributorily liable for a user’s infringement only if it either induced the infringement or provided a service tailored for infringement. Because the provider neither encouraged infringement nor offered a service primarily designed for infringement—since Internet access has substantial lawful uses—the provider was not contributorily liable. The Supreme Court reversed the Fourth Circuit’s judgment on contributory liability and remanded the case for further proceedings. View "Cox Communications, Inc. v. Sony Music Entertainment" on Justia Law

by
An 18-year-old high school senior from Texas was indicted by a federal grand jury for transmitting threats in interstate commerce, based on statements he made while using the online gaming platform Roblox. The statements, made in a virtual “Church” experience, referenced possessing firearms, preparing munitions, and intentions to commit violence at a Christian event. Other Roblox users, located in Pennsylvania and Nevada, reported these statements to the FBI, believing them to be serious threats rather than mere role-play or trolling. The government alleged the defendant's remarks corresponded to a real concert scheduled in Austin and supported its case with evidence from the defendant’s internet history and statements captured by a keylogger.The United States District Court for the Western District of Texas dismissed the indictment before trial, concluding no reasonable juror could find that the defendant’s statements constituted “true threats” outside the protection of the First Amendment. The court found the context—a role-playing video game environment filled with extreme and offensive avatars—undermined the seriousness of the statements, and excluded evidence of the defendant’s conduct outside Roblox as irrelevant. The district court released the defendant without conditions, later imposing some conditions after a government request.On appeal, the United States Court of Appeals for the Fifth Circuit held that the question of whether the statements were “true threats” is a factual issue that should ordinarily be decided by a jury at trial, not by the judge on a pretrial motion. The court found that disputed facts and contextual uncertainties required a trial on the merits, and that the district court erred by resolving these issues prematurely. The Fifth Circuit reversed the district court’s dismissal of the indictment and remanded for further proceedings. The appeal regarding the defendant’s release was dismissed as moot. View "United States v. Burger" on Justia Law

by
A national trade association representing large online businesses challenged a recently enacted California statute designed to protect minors’ privacy and well-being online. The law imposes specific requirements on businesses whose online services are likely to be accessed by children under eighteen, including obligations regarding data use, age estimation, and restrictions on certain user interface designs known as “dark patterns.” Before the law took effect, the association brought suit in the United States District Court for the Northern District of California, arguing that several provisions were unconstitutional on First Amendment and vagueness grounds, and sought a preliminary injunction to prevent enforcement.The district court initially enjoined the entire statute, finding the association was likely to succeed on its facial First Amendment challenge. On the State’s appeal, the United States Court of Appeals for the Ninth Circuit vacated most of the injunction, affirming only as to a specific requirement regarding Data Protection Impact Assessments and related inseverable provisions, and remanded for the district court to analyze the association’s other facial challenges and the issue of severability under the Supreme Court’s clarified standards in Moody v. NetChoice, LLC. On remand, the district court again enjoined the entire statute and, in the alternative, seven specific provisions.On further appeal, the United States Court of Appeals for the Ninth Circuit held that the association did not meet its burden for a facial challenge to the law’s coverage definition or its age estimation requirement, vacating the injunction as to those. However, the court affirmed the preliminary injunction as to the law’s data use and dark patterns restrictions on vagueness grounds, finding the provisions failed to clearly delineate prohibited conduct. The court vacated the injunction as to the statute’s remainder and remanded for further proceedings on severability. View "NETCHOICE, LLC V. BONTA" on Justia Law

by
ARcare, Inc., a nonprofit community health center receiving federal funding, suffered a data breach in early 2022 when an unauthorized third party accessed confidential patient information, including names, social security numbers, and medical treatment details. After ARcare notified affected individuals, several patients filed lawsuits alleging that ARcare failed to adequately safeguard their information as required under federal law. Plaintiffs reported fraudulent invoices and that their information was found for sale on the dark web.The actions were removed to the United States District Court for the Eastern District of Arkansas, where six class actions were consolidated. ARcare sought to invoke absolute immunity under 42 U.S.C. § 233(a) of the Federally Supported Health Centers Assistance Act (FSHCAA), which provides immunity for damages resulting from the performance of “medical, surgical, dental, or related functions.” ARcare moved to substitute the United States as defendant under the Federal Tort Claims Act, arguing the data breach arose from a “related function.” The district court denied the motion, finding that protecting patient information from cyberattacks was not sufficiently linked to the provision of health care to qualify as a “related function” under the statute.On appeal, the United States Court of Appeals for the Eighth Circuit reviewed the statutory immunity issue de novo. The court affirmed the district court’s denial of immunity, holding that the FSHCAA’s language does not extend statutory immunity to claims arising from a health center’s data security practices. The court reasoned that “related functions” must be activities closely connected to the provision of health care, and data security is not such a function. Therefore, ARcare is not entitled to substitute the United States as defendant, and the denial of statutory immunity was affirmed. View "Hale v. ARcare, Inc" on Justia Law