Category: Case law

Cookie-compliance-ntic-advocado

How compliant is your cookie banner? An important German case provides more clarity!

Have you ever heard about dark patterns and deceptive designs in the context of a cookie banner and compliance with the e-Privacy directive? No? Then, this court case might be a good opportunity to learn about it. A court case issued by the Landgericht Rostock (pdf in German) on 15 September 2020, ref. 3 O 762/19 (summary in German and very good analysis in English here), which I will comment in this article.

Cookie compliance is a complex area at the intersection of technology and data privacy. What makes it more complicated in the EU, is that cookie law refers to both the e-Privacy directive (cookie directive) and the GDPR. The fact that the e-Privacy is a directive means that it requires implementation is each EU country. Guidance and interpretation can still differ from each EU country, while all industries are waiting for the e-Privacy Regulation to get finalized. 

_______________________________

THE ADVOCADO CASE EXPLAINS HOW TO DESIGN A COOKIE BANNER

A quite important German Court Case on data privacy and cookie banners (let’s call it “Advocado” case) was recently issued in the field of cookie compliance.  This ruling explains in more details the way cookie banners have to be designed. Maybe we should say: it clarifies how cookie banners should not look like! The German judgement also takes the opportunity to provides some more information about how transparent with users website operators shall treat their joint controllership relationship with third parties. In that context, website operators should take care of informing users about third parties’ plugins appropriately to avoid infringing the law.

In this court case, the German court first confirms where consent is required, which is in particular the case for non-essential cookies. This is not really new since the Planet49 ruling issued by the EU Court of Justice on 1 October 2019. Under Planet49 case law, the ECJ issued a long awaited clarification ruling about essential VS non-essential cookies, although many questions still remained unanswered. Platet49 mainly addressed the following elements (among others):

  • consent is required for all non-essential cookies
  • zero cookie load
  • no pre-ticked boxes are permitted
  • collecting personal data is not relevant for cookie compliance
  • GDPR consent requirements (and fines) apply in the context of cookies (see below summary of recent cases)

With those statements, controllers have to take clear actions for cookie compliance and, where necessary assess their banners, cookie notices, map their practices with third parties and modify them appropriately.

_______________________________

WHAT THE ADVOCADO CASE SAYS

Advocado Gmbh is a company which uses a website to offer an online service that helps people find a lawyer. The cookie banner configured on the website initially provided several pre-ticked boxes. This means that all boxes, including non-essential cookies, were activated by default. During the trial, the company changed its practice to propose an accept all / deny all banner, where the “accept all” banner was highlighted in flashy green and the “deny all” in a light grey. Obviously non-compliant one may say?

What is interesting in this German court case, is that the judgement not only explains that consent is required for non-essential cookies, that zero cookie is necessary or that it should be granular. This should be known by all website operators. It explains in more details how controllers shall design their cookie banners.

The end of dark patterns

The Landgericht Rostock explains how to remain transparent, fair, unambiguous and concise, in the short summary box that controllers / website operators have to display in first cookie banner pop-up. The first text that is displayed in the cookie compliance pop-up is very often used by simply copying and pasting information from other websites. Well, think twice before considering doing this. Especially if you use such cookies to share data, for marketing purposes or to use targeted Ads, this activity is more risky and intrusive. Data Protection Authorities are now very sensitive to every bit of text included in banners, they look at cookies notices, consent management tools and are scanning actively websites for compliance!

The explanations of the court especially bans bad practices that would constitute “dark patterns” to avoid deceptive reactions from users. With dark patterns, a cookie banner is designed is such a way that, although it provides certain degree of choice, it remains misleading by suggesting users to consent to cookies and, thus, influence their choice to a more intrusive activity.

_______________________________

KEY TAKEAWAYS FROM THIS RULING

In this judgment of 15 September 2020, ref. 3 O 762/19, the Federation of German Consumer Organisations (vzbv) filed a complaint against “advocado”, an online service that helps people find a lawyer. The court found that:

1. Using tracking technologies for analysis and marketing purposes requires consent.

Especially, this applies when collecting personal data to share it with third parties.

  • This is interesting to read that Google analytics cookie requires consent. Not explicitly, it suggests, that if Google Analytics does not transmit any personal data to other websites, consent requirement may not apply. The reason is that there may likely not be a risk for the rights and freedoms of data subjects. This is a position that may work in Germany and validated by other data protection authorities, such as in France. This is also the position of the Swiss Commissioner. However, this a concept and a rule that requires further harmonization and clarity. When using analytics cookies, I strongly recommend to read each relevant EU country latest guidance from data protection authorities. For Germany, you may have to read the guidance from each of the 16 German Data Protection Authority. It may provide with stricter rules, including consent for analytics cookies even where no personal data is processed. You should not assume that aggregate analytics is always exempt from cookie compliance and assess on a case-by-case.
2. Cookie banners that have all pre-ticked boxes, even if a user can deselect them and chose “see more”, are unlawful.
3. It is unlawful to use cookie banner using accept all / deny all options, when highlighting the “accept all, and pre-loading cookies.

This requires to apply the following recommendations:

  • Cookie banners and the way controllers have to provide transparency requires to design them in an equal, transparent and fair manner to comply with e-Privacy and the GDPR.
  • Do not copy paste the content of a box from another website without analyzing what your website is actually doing, collecting and placing in terms of cookies. Instead, suggest privacy-default choices (less intrusive choice) and explain clearly what this means for users
  • Do not use colours to highlight what you would like users to click on. Influencing the choice of users would likely constitute a prohibited dark pattern that may be unlawful some EU countries.
  • Clicking on an “Accept All” button should not mean that all cookies have been pre-selected or that non-essential cookies are already loaded.
4. Confirmation that Google Analytics and the Facebook pixel means Joint Controllership (art. 26 GDPR).
5. Failing to provide the essence of the contract with Google and Facebook is against the GDPR.

Joint controllership means that both parties, the website operator have clear obligations together. The controller and the third party are jointly responsible to explain to the user what is the purpose of the processing of personal data, and the “essence of the arrangement” of using such plugin.

According to the Landgericht Rostock, users must receive a copy of the “essence of the arrangement” between the website owner and those third parties. This apply when integrating third-party cookies transmitting personal data. Since third-party providers (also) process personal data for their own purposes the court considered Advocado infringing privacy laws. It failed to comply with its obligation to provide information about the essence of the joint controllership agreement. This obligation applies when integrating the Google Analytics cookie on a website, which is a third partie cookie.

  • This is pretty significant and will be difficult in practice for most small to mid-size website operators to make this effort and do it on their own in compliance with art. 26 of the GDPR.
6. The burden lies with the website operator to demonstrate compliance (burden of the proof)

The website operator has to show that it uses it with a design that complies with data protection laws. This includes third-party plugins, such as Google Analytics or Facebook pixels. Those are important points for the industry to take into account. Also, it is worth noting that,  contrary to what one might think, cookie compliance is not that obvious in Germany in particular from an enforcement perspective. Reading the above commentaries show that Germany may not be the strictest country in this sector. See below more information about recent case law on cookie compliance, the e-Privacy directive and sanctions issued by data protection authorities.

_______________________________

RECENT COURT CASES ON COOKIE COMPLIANCE E-PRIVACY & GDPR

We already commented that authorities warned AdTech industries about compliance on this matter. Not only are they now actively scanning websites, but also enforcing the law. In France, the CNIL issued three fines late 2020 for breach of the e-Privacy directive and the GDPR for unlawful use of cookies.

Amazon.fr fined €35M by the CNIL:

In this case, Amazon violated both the French Data Protection Act and the GDPR (informatique et libertés), which is the implemention the e-Privacy directive, about:

  • poor information in the cookie banner about the use of Ads
  • no real way to object to the cookies, and
  • many cookies were loaded before consent was provided
Google.fr fines up to €100M by the CNIL: Google violated the French law, for:
  • Google used cookies for advertising purposes and placed them automatically on users’ computer, without requesting any action on his or her part
  • lack of information provided to the users of the search engine google.fr
  • partial failure of providing the « opposition » mechanism,
Carrefour.fr fined €3M by the CNIL

This case is not specific to cookies and there are other infringements to the GDPR.

Here, Carrefour placed Google Analytics and other tracking technologies and cookies on its French site Carrefour.fr. The CNIL found that Carrefour did not use Google Analytics exclusively to enable or facilitate electronic communications. This means that Carrefour did not use it strictly necessary for the provision of the service.

In particular, Carrefour used such analytics cookie together with Google Ads to measure the conversion rate of users. Carrefour then pushed Ads with a better auction in order to monetize this activity done by tracking the user’s navigation. It is worth mentioning that the CNIL considered the violation for the use of such cookies and Google Analytics on art. 82 of the French data protection Act, implementing the e-Privacy Directive, but calculated the fines under the GDPR.

_______________________________

CONCLUSION

Cookie law is a complex matter, that has not reached harmonization yet. This ruling and other recent cases in France demonstrate the importance of cookie law. It has become an important and requires due care to protect user’s use of electronic communications. 2021 will be an important year to observe the privacy landscape. In particular, every awaits the enactment of the e-Privacy Regulation to harmonize what has become a difficult area.

I anticipate 2021 and 2022 years of Data Protection Authorities. Also we may see more innovation in the cookies and consent management tools sector. Data Protection Authorities are showing tech giants and Adtech companies that monetizing EU personal data requires compliance. Without such compliance with cookies privacy rules, the use of tracking technologies may not be the best idea.

We are  seeing initiatives to advertise privacy as a marketing advantage, such as Safari blocking cookies by default apple devices. Will this become the next trend? Is this for the good of consumers or for the benefit of large organizations that do not need competitors? What about abuse of dominant positions encouraging to increase certain GAFAM’s monopoly?

Interesting to see how the cookie banner design will influence the use of tracking technologies!

__

By Gabriel Avigdor, CIPP/E

Attorney at law

Specialised in emerging and New Technologies, AI and Privacy

NTIC.ch

Revision of the Swiss Data Protection Act: Conference for HCPs

This Thursday 24 October 2019, I will have the pleasure to present the current state of the revision of the Swiss Federal Data Protection Act (DPA), as currently discussed at the Federal Parliament. I will be discussing the consequences for doctors in private practice in a conference organised by FMH Services, at the Hotel Aquatis in Lausanne.

Since the GDPR become enforceable on May 25, 2018, data protection has become a hot topic and an area concern for many sectors, particularly in the healthcare sector. The various actors, whether healthcare institutions or organizations (HCOs), hospitals, clinics or doctors (HCPs), are particularly sensitive to the changes of the legal framework given the sensitivity of the data processed on a daily basis.

The objective of this conference is to review the updates that will likely pass and be introduced by the total revision of the Swiss Data Protection Act. We will discuss the challenges that doctors will face and the recommendations they will need to receive for preparing to the changes. This will be the opportunity to discuss how the GDPR applies to physicians and HCPs, as well as best practices for the use of technologies by doctors as data controllers of health-related personal data.

The revision of the Swiss DPA aims at strengthening the rights of the individuals, in this case patients, and at aligning on the European data privacy standards. We will examine to what extent the revision fulfils this objective.

________________________________

CONSEQUENCES ON THE DAILY PRACTICE OF HCPS

Generally, the daily practice of HCPs will not change drastically with the new Swiss Data Protection Act and the guidance will remain similar for a physician’s practice to the ones already issued by the Commissioner in the past.

In my previous article on outsourcing medical billing, I mentioned what guidance the Federal Commissioner issued in the context of healthcare, which contains exhaustive recommandations, examples and cases studies on security measures at the medical office, outsourcing, guidance on the use of cloud computing and how to respond to patients exercising their access right to medical records. The Federal Commissioner also issued a guidance on how to deal with data privacy generally at the office.

This being said, the major changes for processing of medical information is relating to the use of new technologies, where the risk for medical secrecy and data protection is the highest. This is also true because a very low number of HCPs are prepared to face digital transformation and have little measures in place or best practices for the use of ICTs. This requires an increased vigilance and diligence from health professionals and physicians to avoid being held liable from a civil or a criminal perspective.

Therefore, security and the application of data privacy principles of patient data at the medical office remains essential because of the increased risks associated with the use of information systems, social media, cloud computing, telemedicine and other similar technologies. In this context, all previous recommendations of the Federal Commissioner remain valid (see below) and must be followed, as must those issued by the Code of Ethics of the Swiss Federation of Physicians.

It should be noted that risks increase with the use of telemedicine systems and unsecured means of communication, as well as in the case of outsourcing (subcontracting) of services, such as invoicing or secretarial services.

________________________________

FINES IMPOSED ON HOSPITALS AND DOCTORS UNDER THE GDPR

In Europe, we have already seen hospitals sentenced by data protection authorities to administrative penalties of several hundred thousand euros.

Since the implementation of the GDPR, most breaches have consisted of deficiencies in appropriate security measures to protect patient data. Similarly, the violation of the duty to set up controls for the rights of access to the same data in patient files has often been the cause of sanctions and breaches by health institutions.

In this respect, the following European decisions are worth mentioning:

  • Portugal: my previous article and comments on the € 400,000.- fine imposed to a Portuguese hospital. Note that in this article, I also discuss other major fines under the GDPR (equifax, Cambridge Analytica) and the very first fine (ICANN) under the GDPR, as well the situation of Swiss hospitals with regard to privacy and data protection and some elements of the current revision of the Swiss Data Protection Act;
  • Pays-Bas: € 460,000 fine imposed to Haga Hospital (Netherlands) for allowing non-authorized access to employees and third parties to the medical record of a local celebrity. The fine was imposed as a result of inapropriate security measures, especially a weak access control mechanisms (art. 32 GDPR) with no double-factor authentication, which was considered the “ABC” of security;
  • Cyprus: € 14,000 imposed to a doctor for publishing health-related information of a patient on Instagram, mentioning the name of the patient without her consent. After investigations, the Data Protection Commissioner of Cyprus also imposed a €5,000 fine to the hospital for not being able to recover the medical record of the patient following an access request.

These examples demonstrate the importance of privacy and security compliance and data protection principles. Those basic principles have to be applied in medical offices and hospitals. Also to guarantee a good control over personal data, it is crucial to apply the principle of privacy-by-design, implement a complete data protection and management program for all types of health actors.

This should include training, rules of conduct for employees and managers, access controls, as well as appropriate organizational and technical measures to avoid data breaches, unauthorized access to personal data, data losses, alteration, and other violations protection. It also remains key, even for micro enterprise and medical offices to have an action plan in the event of a data breach in order to notify the authorities or the patient if necessary. Given those challenges, a light version of an data protection officer (external) would be welcome.

Even if the legal regime of the Swiss DPA will differ from the European sanctions under the GDPR (2% – 4% of the global turnover or €10 – €20 million), these basic rules and principles are essential and must be respected in order. This is key to avoid civil or criminal liability for violation of the Data Protection Act. Also, where applicable, such behavior may infringe the Criminal Code (Art. 321) for violation of medical secrecy.

Now, the Swiss sanctions system only offers the possibility for individuals to initiate a civiel or a criminal proceedings for violation of the Federal Data Protection Act. The maximum penalties amount to CHF 10k. However, the plan with the revision is to increase the level of criminal fine up to CHF 250,000 maximum. This still remains a criminal fine, based on a criminal trial initiated by a plaintiff or a data subject, where the individual will be held liable, excepting the data controller that cannot receive any direct administrative sanction from the Swiss authority.

Find my other articles relating to healthcare:

  • Article on the outsourcing of medical data
  • Non-economic physicians and the consequences of overbilling (in French: “polypragmasie”, in German “Überarztung”)
  • Videoconference: software and medical devices regulation
  • Conference on telemedicine

Google fined €50M by the CNIL under the GDPR

This 21 January 2019, the French data protection supervisory authority (Commission Nationale de l’Informatique et des Libertés – the “CNIL“) fined Google LLC 50 million Euros for breach of the General Data Protection Regulation (the “GDPR“).

In today’s communication (in French), the French authority issued the highest fine against Google LLC since 25 May 2018 considering severe infringements of the GDPR by Google for failing to inform properly the users and collecting valid consent for targeted advertising services.

SCOPE OF THIS DECISION. It is worth noting that this decision is solely based on investigations of the CNIL related to configuration of new Android device for the first time by a user. This particular infringement of the GDPR only relates to the privacy notice displayed to users when they create an account and when logging into their new Android phone. However, the full complaint has not yet been examined by the CNIL and goes far beyond that. The complete case is much broader and related to targeted advertising on Youtube, Gmail and Google Search platforms. The CNIL will have to examine how Google may have or not “forced” users to consent to sharing their personal data via Google targeted ads services. So we can expect to hear more from the CNIL in the upcoming months in this case. This is probably only the beginning of a long series for 2019. The two organizations also filed (as explained below) similar complaints against other GAFAM in several jurisdictions.

________________________________

FINDINGS OF THE CNIL

The CNIL considered that Google did not comply with the GDPR for three main reasons: (1) lack of transparency (art. 5 GDPR); (2) insufficient information (art. 12 and 13 GDPR); and (3) invalid consent collection (art. 7 GDPR).  The two complaints were brought by Max Schrems’ non-profit organization called “None Of Your Business” (NOYB) and the association La Quadrature du Net, a French association that regrouped complaints from 9’974 individuals. Those two organizations claimed that Google’ services, including the targeted advertising services on Android OS, did not comply with its obligation to process personal data with the proper legal basis (art. 6 GDPR), forcing users to share massive amount of personal data and therefore compromising their privacy without their consent.

Those complaints have just been confirmed by the CNIL in today’s findings. After that, it is interesting to read on the blog of NOYB, that Google will move its EU headquarters to Ireland with effect to 22 January 2019, with the Irish DPA (Data Protection Authority) as the lead authority.

The French authority adds some interesting considerations to its findings. The CNIL explains that with Google current services, due to the way the data are collected, the volume that can be processed and the type of data collected through those services, it can result in revealing entire parts of someone’s life, which becomes very intrusive. The CNIL also considered the fact that Google’s business model is partially based on those intrusive services.

Finally, the CNIL explains that, essentially, despite Google’s efforts to change its processes, Google is still not compliant. This also means that as long as Google remains non compliant, it may face other complaints and, potentially other fines unless the way Google processes data about individuals changes drastically.

________________________________

HISTORY OF THE CASE

Two massive complaints on 25 and 28 May 2018 for € 7,6 bn

25 May 2018. Max Schrems – the Austrian privacy advocate who provoked the cancellation of the Safe Harbor framework by the European Court of Justice (see judgement here) – founded a not profit organization called “None Of Your Business” (NOYB) to support consumers and data subjects in filing complaints against companies and to authorities to enforce and protect their privacy. Just the day the GDPR became enforceable on 25 May 2018,  Max Schrems sued Instagram (Belgium), WhatsApp (Hamburg, Facebook (Austria) and Android (France) with a massive complaint amounting to € 7,6 bn via its NGO for infringement of the GDPR. Find more details on NOYB’s website here.

28 May 2018. The French Digital Rights Group “La Quadrature du Net” lodged a complaint on 28 May 2018 against Google, Apple, Facebook, Amazon and LinkedIn in front of the CNIL on the behalf of 12,000 individuals for illegal processing of personal data.

The CNIL’s sanction of € 50 millions issued today is only one sanction against one company – Google LLC – and in one juridiction. There is most likely other sanctions to come if other authorities follow the CNIL’s argumentations and considerations.

In terms of procedure, Google can appeal to this sanction and contest the fine (edit 24-janv-2019), which the company announced publicly. Even if the fine remains low compared to the €4bn it can incur in the event of a maximum fine, the amount is high for this case. In its public statement, Google said:

We´ve worked hard to create a GDPR consent process for personalised ads that is as transparent and straightforward as possible, based on regulatory guidance and user experience testing

By appealing against this decision, Google wants initiates the process of a precedent in interpreting the GDPR’s requirements on information, transparency and how to validly obtain consent, particularly in the area of targeted advertising.

Google’s appeal is therefore highly strategic. Not contesting this fine would create room for potential more severe sanctions, especially as the scope of the case is limited. In addition, it could be seen as an indirect acknowledgment of responsibility for using non-compliant practices.

Finally, Google defends itself by arguing that it has worked hard to set up data collection in order to respect transparency, but also said:

We´re also concerned about the impact of this ruling on publishers, original content creators and tech companies in Europe and beyond

We will see if his work has been sufficient or not and how strong this EU Regulation can effectively be in practice.

________________________________

THE CASE IN MORE DETAILS

To get into more details, the CNIL provides the following explanations to justify the sanction against Google:

  • Breach of transparency: the transparency principle refers to how you inform individuals about the processing activities. This usually takes the form of privacy notices. This information is supposed to remain concise, clear, accessible, unambiguous and intelligible by any person.

This was not really the case. Google spread all that information in many separate places through links and buttons which made it very difficult to access, understand and takes ages. At the end, all that information was only accessible after 5 or 6 actions, in any case after several steps to know what data are collected about the individual. The information was not clear enough, vague and described in a too generic way. That means that if nobody takes the time to read that information (why would Google collect your data for what purpose, for how long, what categories of data are used for the targeted advertising, etc.), the obligation of having a clear and easily accessible notice is not achieved. Also, Google failed to inform about the retention period of certain personal data (for how long will Google keep that data).

  • Invalid consent: Google requested the consent of the users to collect the personal data. However, the CNIL considered that this legal basis was not valid for the options of customized advertising for the two following main reasons:

The consent was not informed. This means that users do not understand the scope of use of the data. For example, in the “customized publicity” section, it is not possible to see how many services, sites and applications are related to the processing and there is no information about the volume of personal data that those services will process and combine.

The consent was not specific, nor unambiguous despite the fact that users may have the ability to select several parameters. According to article 7 of the GDPR:

request for consent shall be presented in a manner which is clearly distinguishable from the other matters, in an intelligible and easily accessible form, using clear and plain language

With Google targeted advertising services and options, the users could only access those parameters by clicking “more options”. Also, the option to use “targeted advertising” was already pre-ticked, which forces the user to turn it off. So the option will remain active, if the user does nothing, unless there is an active action from the user to disable the option. Therefore, using pre-ticked boxes is contrary to the principle of privacy by default (art. 25 GDPR), which requires to turn off any settings or parameters by default to apply a maximum protection of privacy to the user. It is only up to the user to decide whether he or she wishes to increase the level of intrusiveness to his or her privacy and agree to share any personal data. Finally, Google only provided one box for the users to click which appeared like this:

“I accept Google’s terms and conditions” and “I accept that my data are used as described above and as detailed in the privacy policy”

Such bundled consent, which is not specific and do not provide any details for each purpose is not compliant with the requirements as set out in the GDPR.  Where several purposes for processing personal data exist, users must have the ability to only consent to those purposes that they wish. Having all the purposes all-in-one, does not work under the GDPR.

________________________________

ARE THOSE REQUIREMENTS NEW UNDER THE GDPR?

Yes and no.

Yes, the requirements to collect a valid consent has been extensively strengthened. It not as easy as before to collect a valid consent and as this case demonstrates, there are individuals and authorities out there that can have a word and ultimately impose fines to your organization.

No,  the principles of consent, collecting personal data with a valid legal basis and informing the individuals via privacy notice, are not new from an EU data protection legislation. The obligation to process personal data with a lawful ground already existed under Directive 95/46/EC and also applies under the Swiss Federal Data Protection Act (DPA), as probably in most of the jurisdiction that have adopted comprehensive data protection framework. A company responsible for collecting and processing personal data has to justify a valid legal reason. As a reminder, the GDPR offers 6 different legal bases to justify the processing of personal data (article 6 GDPR), which are:

  • consent;
  • performance of a contract;
  • compliance with a legal obligation;
  • protect the vital interests of natural persons;
  • performance of a task carried out in the public interest or in the exercise of official authority; and
  • legitimate interest.

Each of those legal bases have their pros and cons, but where you use the consent, you should remain careful to collect it lawfully, unless the processing becomes illegal. With the GDPR, the consent has become much more difficult to obtain. In particular, you need to inform and explain who shall consent, what you will do with that data, for what reasons and based on what legal basis you process the data, with whom you will share them. And this shall apply for each purpose. If those conditions are not, the consent is not valid illicit and you cannot process the personal data.

And this is what happened to Google LLC in the case of targeted advertising, for this first part of the story.

________________________________

By Gabriel Avigdor | ICT.ch 

Digital Lawyer

Prescription support software are considered as medical device

Prescription support software is considered as medical device

On 7 December 2017, the European Court of Justice (‘ECJ’) made an important ruling in the French case SNITEM and Philips vs Premier Ministre des Affaires sociales et de la Santé (Case C-329/16). The Court followed its general advocate advice, who issued a non-binding recommendation on 28 June 2017, and defined for the first time under what conditions should medical software (standalone software) be qualified as a medical device pursuant to Directive 93/42/EEC on medical device.

In this decision, the ECJ considers that “software, of which at least one of the functions makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses, is, in respect of that function, a medical device within the meaning of those provisions, even if that software does not act directly in or on the human body”. Therefore, software of which specific functions do not have a medical purpose, are not medical device and are out of the scope of the Directive.

__________________

CE marking is sufficient

The Court adds that once the software bears CE marking, a national authority cannot request the software developer to proceed to an additional requirement such as another certification, as CE marking is sufficient.

In this French case, a decree contained an obligation to get a specific certification for prescription support software according to art. L. 161-38 of the French Code of Social Security. The French authority maintained its position that such software cannot be considered as medical device and therefore, would require this specific certification. WRONG, says the ECJ who confirmed that the clear intention of Philips to use this software in the context of healthcare, and for medical use, makes the functions of this software a medical device. Certications issued by the “Haute Autorité de Santé” (‘HAS’) were compulsory and now are now anymore. Even more, the decree will certainly be either cancelled or amended after this ruling.

This is an important decision for the medical software industry and for innovation in that sector to place them on the EU market (and also in Switzerland), as ECJ clarifies that although it remains compulsorily to “bear the CE marking of conformity when it is placed on the market. Once the marking has been obtained, the product, having regard to that function, may be placed on the market and circulate freely in the European Union without having to undergo any additional procedure, such as a new certification”.

This EU ruling is a lightening in the process which will benefit the industry by save time and money when putting medical software on the market. This clarification allows companies to avoid engaging costs as compliance as a measure of prevention. Legally speaking, there may be a possibility for companies that are in the process of getting their medical software certified to stop the process, or even claim for reimbursement if the decree is cancelled or modified and becomes illegal as a result of the ECJ ruling. In addition, it is likely that this decision may have an impact in other Member States of the EU, which would also be transposable, not only for prescription support software, but also for other medical software, or mobile medical Apps.

__________________

Scope of this decision

What is the scope of this decision?

Firstly, this decision applies clearly to prescription support software, but not only. The the ECJ provided criteria that are broad enough for applying to other medical software if the objective pursues a specifically medical objective. This ruling may be applicable by analogy to all medical software with a medical objective, even with no interaction in or on the human body. It is however necessary to proceed to a specific analysis on a case by case basis for each functionality of the medical software or the mobile medical App.

Secondly, this decision also applies to hospitals developing medical software, as these institutions can be software developers even with no commercialisation, as though they are responsible for first placing on the market. It is therefore necessary for hospitals developing medical software or Apps to assess whether it requires complying with the EU medical device Directive.

From a geographic point of view, even if the decision comes from a European authority, it applies to Switzerland, with automatic recognition of CE marking thank to the international convention on mutual recognition in relation to conformity assessment dated 2002 with EU.

Finally, the fact that this ruling is based on the Directive 93/42/EEC will remain valid with its replacement by the EU Regulation 2017/745 on medical device that is going to replace as of 26 May 2020.

__________________

In deeper details – Background of the dispute

The dispute arose in relation to “Intellispace Critical Care and Anesthesia” (ICCA”) software developed by Philips, as this company focuses now into the software and IT projects in relation to the healthcare sector. The functions of the prescription support software makes it possible to use patient-specific data for the purposes, inter alia, of detecting contraindications, drug interactions and excessive doses.

The dispute opposed the national syndicate of medical technological industries (SNITEM in French) and Philips on one hand, against the French Minister of Social and Health Affairs on the other hand. Based on a local decree which imposes prescription support software companies to get a specific certification, the French authority argued that: (a) Philips’ software was not a medical device, (b) requires getting the additional specific certification for prescription support software, and therefore (c) cannot freely put into the market its software on the sole basis of the CE marking.

On the other hand, Philips argued that, its software is a medical device and “the requirement to adapt software to technical standards constitutes a measure having equivalent effect to quantitative restrictions on imports which, overlapping with the certification obligation for medical devices laid down in Directive 93/42, which is applicable to software, does not meet the requirements of necessity and proportionality”.

In other words, Philips claimed that CE marking was sufficient. Philips won the case on this question.

__________________

Challenges of this case and first precedent

The central question of this case is not the certification itself, but the question to know if ICCA software is be considered as a medical device or not in accordance with Directive 93/42/EEC on medical device. This question may appear somehow unoriginal. It is not. If a software is considered as a medical device, regardless of how it is classified, will need to comply with the EU medical device Directive requirements. In the German case Brain Products GmbH vs BioSemi VOF, the ECJ only provided an indirect reference to the criteria for software as a medical device (‘SaaMD’) qualification.  In that case, the ECJ mentioned that fitness Apps would probably not meet the definition of medical device, while software monitoring humain brain activity would.

The Philips case also refers to the MEDDEV 2.1/6 (Commission Guidelines on the qualification and classification of stand-alone software used in healthcare within the regulatory framework of medical devices) as explained by the advocate general in its recommendations dated 28 June 2017.

__________________

CONDITIONS AND EXAMPLES

ECJ reminds that it is not sufficient to use the software in a medical context; it is also necessary that the intended purpose, defined by the manufacturer, is specifically medical. Therefore, two cumulative conditions are necessary to consider a health-related software as a medical device, which are relating respectively to the objective pursued and the action resulting therefrom.

  1. Objective pursued: a medical device must be intended by the manufacturer for use in humans for the purposes, in particular, of the diagnosis, prevention, monitoring, treatment or alleviation of a disease, and the diagnosis, monitoring, treatment, alleviation of or compensation for an injury or handicap;
  2. Action resulting therefrom: ECJ interprets the Directive 93/42/EEC and considers that “although that provision provides that the main action of the medical device ‘in or on the human body’ cannot be obtained exclusively by pharmacological or immunological means, or by metabolism, it does not require such a device to act directly in or on the human body”.

Interesting to notice that, according to the ECJ’s argumentation, the second condition is not decisive. On the contrary, requiring that the action resulting from the device shall produce an effect or works directly in or on the body would mean that software with no effect on the body would not be subject to the Directive, which would be contrary to the intent of the EU legislature.

In the case of prescription support software, the European Court of Justice states (§25) that functions of such software: “that cross-references patient-specific data with the drugs that the doctor is contemplating prescribing, and is thus able to provide the doctor, in an automated manner, with an analysis intended to detect, in particular, possible contraindications, drug interactions and excessive dosages, is used for the purpose of prevention, monitoring, treatment or alleviation of a disease, and therefore pursues a specifically medical objective, making it a medical device within the meaning of Article 1(2)(a) of Directive 93/42”.

SaaMD or not? Examples:

The ECJ provides examples of prescription support software that may or may not be used as a medical device:

  • SaaMD: function that permits the use of data specific to a patient to help his doctor issue his prescription, in particular by detecting contraindications, drug interactions and excessive doses, even though it does not itself act in or on the human body;
  • Not a SaaMD: software for general purposes, when used in a healthcare setting, is not a medical device;
  • Not a SaaMD: software intended to indicate the contraindications mentioned by the manufacturer of that drug in its instructions for use;
  • Not a SaaMD: software that, while intended for use in a medical context, has the sole purpose of archiving, collecting and transmitting data, like patient medical data storage software, the function of which is limited to indicating to the doctor providing treatment the name of the generic drug associated with the one he plans to prescribe.

__________________

OUTCOME OF THIS RULING

After this ruling, there are at least three main take aways:

  • First, medical device regulation applies to functionalities of medical software where two cumulative conditions are met (medical purpose pursued by the manufacturer and the action pursued therefrom), with a focus on the first condition;
  • Second, such regulation only applies to functions of the software which are coded in a way to produce such effect, but do not apply to the source code in its entirety, even if the software has no effect in or on the human body;
  • Third, where the software, for that particular section of the source code, bears CE marking, it benefits from freedom of circulation of goods within the EU [and therefore in Switzerland as well] and can be placed on the market without any further certification or requirement.

__________________

What other consequences for software as a medical device?

When a software is qualified as a medical device, the manufacturer will have to assess its classification based on the degree of risk for the human body (classes from I to III) and will have to comply with its duties to declare Class I software to the regulation authority (national authorities in the EU and Swissmedic in Switzerland). For classes IIa, IIb and class III software, obligations are stricter.

Depending on the conditions that are applicable, there is a materiovigilance requirement (pre-market approval and then post-market surveillance/vigilance) by the manufacturer, as well as product security, quality control and quality assurance management, as well as other standards (such as ISO). For products coming from the EU, once they bear the CE marking, they benefit from the freedom of circulation in Switzerland and vice versa without any pre-market approval.

All standards that apply to medical devices, depending on the degree of risk, but also obligations, restrictions and potential sanctions of the authorities, will mutatis mutandis apply to software as a medical device. This is necessary to guarantee free circulation within the EU of safe and secure products for consumers or patient health.

Want to know more?

Cells

Celine case: Bayer not liable for Yasmin contraceptive pills

WHAT THE CASE IS ABOUT

On Wednesday, 21 January 2015, the Swiss-German press reported the verdict handed down by the Swiss Federal Court in the Celine Case, better known to the media as the Yasmin Pills Case. This is a case that created a scandal in the canton of Zurich, as well as at the national level, concerning the use of the latest generation of contraceptive pills in Switzerland. In this case, the Swiss Supreme Court found that Bayer AG did not breach the Swiss Product Liability Act for lack of information in the medication leaflet.

This article outlines the key legal issues relating to drug liability under the Swiss framework and compares the situation between Switzerland and the US in particular from lawsuits perspective involving 4th generation contraceptive pills.

* * *

In 2008, a 16-year-old girl was hospitalized in an emergency and found herself paralyzed following a pulmonary embolism. The consequence was a lack of oxygen leading to severe head injury. Yet it had only been two months since this young woman started taking the contraceptive “Yasmin”, a prescription-based “4th generation” contraceptive pill that many women around the world use. As a result of this serious disability, the young woman represented by her mother, as well as her health insurer, CSS Assurances, brought the case before the courts claiming CHF 5.3 million for tort and CHF 400,000 for moral damage. In the end, the Swiss Supreme Court upheld the previous decisions and dismissed the appeal of the girl and her health insurance, declaring that the drug manufacturer, Bayer AG, could not be held liable. However, Bayer waived its right to claim reimbursement of the appellant’s costs and expenses to Celine, which amounted to CHF 120,000 as a result of the duration of the proceedings, including attorney and courts fees. CSS Insurance did not get this chance.

_____________________

LIMITED INFORMATION DUTY OF THE PHARMACEUTICAL COMPANY

In this case, Bayer was accused of not mentioning in the patient package insert that the risk of undergoing pulmonary embolism was twice as high with the “Yasmin” pill as with other similar contraceptives. In essence, the Federal Court considered, in its judgment of 5 January 2015 (4A_365/2014 and 4A_371/2014 (in German)), that the German pharmaceutical company was not liable for this lack of information for patients, the mere fact that doctors had access to this information being sufficient. The Federal Court pointed out that the placing of a medicinal product on the market and the standards for obtaining the necessary authorisations from Swissmedic for their marketing do not oblige a pharmaceutical company to inform patients of a higher risk than other equivalent products. With regard to prescription drugs, the patient is not in a position to judge the risks involved, so it is up to doctors to evaluate the benefits and risks of the various products on the market to redirect the patient to the appropriate medical treatment.

Thus, the Federal Court acknowledged that the drug was not defective and that the company could not be held liable under the Swiss Federal Product Liability Act (PLA). The “causal liability” mechanism of this law allows the victim of a defective product to claim damages from the manufacturer, without any fault (art. 1 § 1 PLA). However, the product must be considered defective for the manufacturer to be liable for the damage caused.

In particular, the distinctions between manufacturing defects, design defects and presentation defects can be found in the famous “coffee maker case“, where the Supreme court clarifies the causes of a defect for products that have been validly placed on the market.

_____________________

INEQUALITIES IN LOCAL LEGISLATION: COMPARISON BETWEEN SWISS AND US LITIGATION

Market access authorisation framework and liability for defective drugs:

The case of Switzerland

The authority shall grant a market access authorisation for a drug for a renewable period of 5 years and must comply with the legal requirements of the Swiss Federal Therapeutic Products Act (TPA), in particular requiring the approval of Swissmedic.

Market access shall only be granted where a pharmaceutical company:

How the pharmaceutical company decides to label its product and the way in which the information is highlighted in the leaflet are also essential conditions for obtaining such authorisation (Art. 11 § 1 let. f TPA). However, to the extent those conditions are met, the manufacturer cannot be held liable for a defective product, unless its market access
authorisation was not granted properly. The responsibility for defective drug usually extends to suppliers, i.e. distributors and importers, but this excludes the medical liability of doctors or pharmacists.

1) provides evidence that the drug or a manufacturing process is of high quality, safe and effective;

2) holds an authorisation as a manufacturer, importer or wholesaler issued by the competent authority; and

3) has its domicile or its registered office in Switzerland, or has established a subsidiary in Switzerland (Art. 10 TPA).

In summary, the manufacturer’s liability for defective product it is a rather difficult to obtain, especially when a consumer has to pay very large amounts of legal fees and expenses in advance. Therefore, as a result of this case Bayer was not convicted in Switzerland by the Federal Court, which sets a precedent for pharmaceutical companies active in selling 4th generation contraceptive pills.

Situation in the USA

Mass compensation

Since 2013, the German pharmaceutical company has already paid out around USD 1.4 billion in the United States to compensate victims of similar cases by way of settlement in legal proceedings involving a total of more than 6,760 plaintiffs (the figures are not uniform, see the following reports here). These US trials are more broadly related to 3 contraceptive pills “Yaz”, “Yasmin” and “Ocella”. In the USA, the U.S. Food and Drug Administration (FDA), the authority responsible for approving and marketing consumer products, including medicines (which is the equivalent to Swissmedic in Switzerland), must ensure that a drug meets two requirements:

  • Manufacture of safe drugs with precise statements of any potential risks; and
  • Precisely warns under what circumstances the drug may or may not be used.

Le Monde.fr recently mentioned the impressive figure of 15,000 legal actions filed against the pharmaceutical group. The American judicial system allows, thanks to class actions and specific ethical rules on the legal profession (pactum de quota litis), to have a different means of pressure on large companies than in Switzerland where each individual must find their way alone to a long and costly trial.

Position of patient advocates

Pharmaceutical trials in the United States are particularly fascinating for civil law lawyers. For example, the drugwatch website provides information on lawsuits related to pills sold by Bayer and arguments that the attorneys may raise in court against the German manufacturer. The challenges and costs of those trials as well as the risks for manufacturers are so hihg, that some law firms become specialists defending clients in trials for those pills. They do not hesitate to document their willingness to defend the victims with explanatory videos motivating patients to consult and hire them free of charge as long as the pharmaceutical company do not pay anything to compensate any damage caused to them. You can also find links to a free medical assessment form intended for assessing the medical situation of a relative or read sentences such as: “If your loved one has died as a result of using these contraceptives, you may be able to file a wrongful death lawsuit“. There is also an American website specific to the Yaz & Yasmin trials.

On another level related to conspiracy, press articles try to establish a link between FDA members and the German manufacturer. Also from the the FDA we can find reporting risks associated with Beyaz, Safyral, Yasmin and Yaz in highly technical reports.

It’s hard to find your way around in this American romantic universe…!

_____________________

CONCLUSIONS AND LESSONS LEARNED FROM THE SWISS DECISION

The Federal Court’s decision highlights several elements:

  1. A pharmaceutical company is not required to inform patients that its drug presents a higher risk compared to other competing therapeutic products.
  2. The Swiss Supreme Court implicitly confirms the principle that a physician has an obligation to inform the patient of the nature of the risks and the degree of danger associated with taking such a drug. Indeed, the consumer does not have access to the same information as his doctor and is not in a position to make a decision without consulting him and having a free and informed opinion.
  3. Prescription drugs are not treated in the same way as those that do not require them to obtain them. Indeed, when a prescription is mandatory, the doctor must intervene to prescribe the drug in question to his patient, who has the knowledge to refer the patient, supported by a medical record. It is therefore up to the doctor to assess the risk and appropriateness of the patient taking a medicinal product on the basis of information intended for health professionals. The assessment of a pharmaceutical company’s liability for a non-prescription drug would probably be different if the risks are not sufficiently indicated.
  4. Obtaining compensation from the manufacturer of a drug for lack of information is not easy. Where appropriate, and under certain conditions, the civil and/or criminal medical liability of a doctor, or even a pharmacist or other health professionals may be incurred where, as a result of insufficient information, a damage to health occurs which could have been avoided if adequate information had been provided.

The information in the Yasmin pill package insert and contraindications are available on the website of the Swiss Compendium of Medicines.

By Gabriel Avigdor | NTIC.ch

Google Glass

Google Glass : pros or cons ?

Google Glass is very popular but do not receive general agreement. However this gadget has an incredible industrial value and some revolutionary concepts of use (e.g : e-Health, human interaction in other languages, etc.). However, it is, and will remain a cause of concern for consumer protection and privacy.

This article is intended for taking stock of the actual knowledge through  Internet media and the legal situation in several countries that already initiated preventive prohibitions (like USA, UK, France). Finally, a brief outline of the legal issues in Swiss law will be approached.

________________________________

HIGHLY ANTICIPATED AND CONTROVERSIAL TECHNOLOGY

 

Fans of tech inventions really look forward buying Google Glass (hereinafter : “GG”) to see its real potential of use. In reference to the terms of a letter sent to Larry Page (CEO of Google) questioning him about the risks of GG on privacy, the features of these glasses could be shortly resumed as follows :

Google Glass includes an embedded camera, microphone and GPS, with access to the Internet

Speculations about their use, features, but also about the risks and the legal drifts of the GG are the daily bread of journalists, bloggers and Internet users. The question so far would be : “how far could go Google with this new gadget“. 8’000 Internet users have already worn them for the special amount of $ 1’500.- in several American towns. Wearing these glasses not only was a privilege. It was also a way of asking these lucky users to imagine and offer Google use suggestions. Instead of paying the users for their ideas, the Mountain view firm is reversing the situation into an original concept by making “paid crowdsourcing”, as well as the Ads systems of the GG called « Admented reality ».

While all fans are awaiting Google Glass, the technical possibilities should frighten other people for obvious privacy matters. This sober and futuristic computer, which only stands on the tip of the nose, working with augmented reality deserves to be paid attention to!

Technical specifications

« Google Goggles » was not a success. However Google Glass intends to be its evolution with a lot more advanced features. The introduction page of GG seems to show glasses with a camera, a microphone, an analyzing environment tool with voice or gesture control (e.g. : for the zoom) and would definitely be based on augmented reality technology.

Fields of application

GG potential could be really wide in several area of application as well as for private use or  professional use. The question is : will this tool be efficient enough to stand a full day in order to overcome human weaknesses or vagueness? Here are some of the possibilities we could imagine.

Private or professional use

  • Private use won’t be so different as a Smartphone use. It’s just lighter, it works thanks to the voice control application and it can be used without taking your hands out of the pocket.
  • Professional use should really be challenging and exciting. Any kind of job that would require human work with an extreme precision (clock/watch making, micro technology, medicine, surgery, etc.) or real-time complementary informations could be improved with GG, such as zoom functions, real-time data analyzing functions, more camera angle views displayed on the glass, etc.

Medical applications / e-Health

  • During a Surgery, a doctor could have a real-time access to medical analysis, or could see different angles of view taken from several cameras. The zoom function could also be interesting in this case…
  • E-Health will be one the most lucrative but also promising field of activity in terms of innovation, thus for the industry, IP, IT, medical and legal drifts, especially in Switzerland. You might have read news about the Insight function which is built to identify people by their clothes. A medical application used on GG could be a great advantage during an attempt of rescue (e.g. : road accident, etc.). Imagine a rescue worker or an ambulance man identifying the victim of the accident with the GG and accessing immediately to his medical files (checking the blood type, important disease, allergies, reactions, drug or antibiotic resistance, etc.) and respect self-determination of the patients (according to an advance directive).

That kind of technology should be developed with lots of precautions and this means people must be identifiable at a very great probability to avoid serious medical errors. The technique and the power of these glasses will have to be increased a lot to reach that level of feature in order to have a daily professional use. Furthermore lots of tests and legal agreements would be necessary to integrate them in public health programs, which is not going to happen tomorrow.

Other person like visually impaired could be helped by GG to move in the streets  (GPS navigation system, facial, objects or obstacles automatic recognition, etc.).

Other applications

There will be lots of challenge and opportunities for GG Video games, which could boost industry and friendly use of these glasses. A part from that, international federations of sport already thought about referee wearing those glasses during some match. Porno industry is obviously interested in developing features and Apps for the GG, such as the recent fake porn trailer available on the Internet. Some creative people also thought about wearing the GG during a job interview to analyze the candidate’s behavior and to seek candidate’s profile, past, network, and more… Lots of others ideas such as a nature walk, or getting his car back could also be imagined…

________________________________

PROHIBITION ALREADY STARTED

Fears about GG’s entry on the market

Despite lots of fun features and useful professional uses, people, but also organizations, worry about the entry of GG on the market. Fears are twofold.

  • One one side, there are legitimate worries about consumer and data protection for the active users of the GG. Risks for active users may be focused on targeted ads system (based on environment interaction) and direct or indirect surveillance “under Google glass” from the authorities or giant Internet firms.
  • On the other side, all the passive users of the GG (such as people in public places) will  be concerned about their privacy. Passive users protection would be necessary to prevent “undesirable screenshots” from a pedestrian, as well as undue audio or video recordings. Not only the main thing is that people won’t know they would be recorded or pictured, but also that they won’t be able to agree or not to a recording.

When law comes before technology

GG won’t be tolerated in places where Smartphones, cameras or computer are already prohibited (cinema, banks, casinos, shows, hospitals, etc.). Nothing new under the sun.

Just the once will not hurt, and while GG are still in beta test, several public Organizations, private or little companies try to anticipate the take out of the store to prevent conflict situations. Ten privacy Organizations, including Hanspeter Thür, the Swiss Federal Data Protection and Information Commissioner (FDPIC), and the French IT and Freedom National Commission (CNIL), sent a letter to Larry Page about concern for privacy, and the collect and use of user’s data by Google.

Precautionary prohibitions in a few countries

  • In the United States of America, the Google Glass will be prohibited in Las Vegas, and in every Casino of the city. The Google glass will neither be allowed in Seatle at « 5 Point bar » which is the first bar to consider wearing GG as illegal before they are put on the market.
  • In United Kingdom, the spokesperson of the Britain Transport Minister said that GG will be banned for drivers because it would affect too much traffic behaviors even if their purpose is to help drivers with GPS functions.
  • West Virginia State and Delaware State (USA) are also working on a similar draft legislation to ban GG for drivers. Indeed, after the publication of an article on the website CNET entitled “The truth about driving under the influence of Google Glass“, public and political opinions have strongly reacted. As a result, these two government will probably establish rules to ban this gadget for drivers, but maybe for other use. A women already got ticketed for “distracted driving” because she was wearing the GG during driving.
  • In France, such glasses will automatically be banned for drivers according to article R412-6-2 of the French Road Code. This legislation provides that « Placing an operating device with a screen in the field of vision of the driver of a moving vehicle that do not constitute a driving or navigation aid is prohibited ».
  • A website entitled “Stop the Cyborgoffers to download a “Google Glass Ban” sign (pdf) for private places where the owner wants to ban it (bar, restaurant, etc). You can also check the list of ten places where Google Glass will be banned : on this website.

________________________________

WHAT IS THE SWISS LEGAL FRAMEWORK ?

Goggle Glass in the private or public context

If Google Glass product access the Swiss market, everyone should wear them without any problem in a private context. Private context is when you are with your family or friends. But, as soon as someone will wear the GG, everyone may be screenshot without knowing it and without prior consent. From a privacy perspective, this may become an issue should there be processing of (sensitive) personal data without prior notice or consent.

In a public place (bar, public transport, parc, demonstration, etc.), many sensitive issues will occur related to the use of GG, particularly regarding privacy, data protection and private sphere.

Data protection and privacy

Data gathering location and data processing

First of all, one of the most sensitive issue would be : What use will be made of all the data gathered by Google ? Even if connecting to Internet is a national issue (Internet provider with 3G and 4G and telecommunication providers), most of the information should automatically transit to Google servers to be stocked (at least temporary) which means in the USA. As can be seen with PRISM case, it is not clear whether the local data (in non-US countries) are not scanned by the NSA. But all our data may be if they are sent to USA to Google servers. Maintain control on all your data might possible only if they are kept in your country, encrypted and if they do not transit through the Internet Giants (Google, Yahoo, Facebook, etc.). Hard to tell before having tested these glasses !

Personal data and private sphere

As soon as a image or sound is recorded, this may cause legal problems. One the fundamental principle is the right to self-determination. Consent is the cornerstone of data protection and is a ground of justification which makes lawful a privacy intrusion (such as data gathering and processing). Thus, data gathering without prior consent is illegal. Every GG user sitting in a bus or a metro taking pictures or filming someone would automatically infringe the Swiss Federal Law on Data Protection (article 12 LPD) or to the Swiss Civil Code (article 28 CC).

Swiss Criminal Law (Penal Code) also punishes unauthorized audio recordings (see article 179bis to 179septies  CP). It can lead to a fine or prison.

The Insight Function of the GG may also be very intrusive in everyone’s life, even if the data are gathered from pictures found on the Internet and uploaded by the users themselves.

Intellectual property

Second sensitive theme : Intellectual Property, such as trademarks, copyright (pictures, music, movies, books, etc.). Since prohibition in cinemas will be obvious,  the issue won’t be so easy with concerts, theaters or museums where controls are not systematic. Remember that according to Swiss Copyright Law provides legal private copying if the use is restricted to friends or family. Such right disappears when the source is illegal or if it is shared out of the private circle.

We can be sure that Google will set up copyright detection system, as it already exists with YouTube. We can trust it.

Google Glass in the context of driving

Since it seems to be debated in several countries, it may be interesting to examine this issue in Switzerland. As you would see further, Swiss legislation seems more precise than french legislation about this prohibition.

Phone Call during driving

In Switzerland, cell phones during driving are prohibited. More specifically, the Swiss Federal Road Traffic Act (RTA) provides that « the driver has to remain constantly in control of the vehicle in order to respect all the prudence obligations (article 31 par. 1 RTA). The  driver would have to pay a CHF 100.- fine to have used his mobile without hands-free unit during the course » (article 3 al. 1 OAM).

In addition, the Federal Ordinance of the Trafic Road Act provides that : « the driver must pay attention to the road and to the traffic. He will avoid any activity which could make driving more difficult. He will also ensure that his attention would not be distracted, in particular not by a sound device nor by any communication or information device. It is established by the Federal Swiss Case Law (jurisprudence of the Swiss Supreme Court) that sending an SMS during driving is a severe infringement to Road Traffic Act (6B_666/2009) (article 90 par. 2 RTA) that may lead to a fine or a maximum three years jail sentence. 

What about Google Glass ?

Driving any vehicle require a perfect attention and visual acuity. Google Glass meet several scope of vision with notifications on one of the glasses. In reference to above-mentioned Swiss legislation and jurisprudence, wearing GG will be illegal if it is harder to drive with, which it seems to be most likely possible. The Google Glass drivers could be receive a administrative penalty (withdrawal of the driving licence) and a penal sentence (fine or jail).

It would more secure to let the passenger wear them.

Criminal proceedings

Criminal proceedings and Surveillance legislation deserve also an attention. The Swiss Federal about Surveillance of the Correspondence through Postal services and Telecommunication (LSCPT in french) allow Authorities to follow and monitor both individuals and companies suspected of charged for criminal offenses. Would it be allowed for Authorities to connect to the GG or ask Google data to proceed to a retrospective surveillance?

If the Investigation Authorities can monitor and record communications through Skype, which is the case in Switzerland, it will be technically possible with the GG. The problem is not how to do it, it is about collaboration. Will Google collaborate with the Swiss Criminal Authorities if they ask for it to resolve criminal cases? International mutual legal assistance in criminal matters is often a fatal obstacle when criminal offenses are committed through IT and New Technologies because the process is too slow. Furthermore, data retaining duration is not long enough to let Authorities have access to data before its erased (even if the duration will be lengthen to 12 months,  judgment 1B_128/2013 of the 8th of May 2013).

Other legislation, such as liability of Internet intermediaries, could enter into consideration.

________________________________

FINAL THOUGHTS

After these conceptual and legal considerations, my impressions, but also risks and abuses of those glasses are mixed. If we were living on Thomas Moore’s Island, Google Glass marketing wouldn’t have any bad consequence in a society composed of exemplary and model citizens or benevolent companies.

Are Google Glass and the future competitors of these glasses going to make a technological revolution? Will our daily habits and human interaction drastically change? Will 2014 be a progress year or we are going to go back 30 years later (1984)?

Swiss legislation seems to be well prepared for the arrival of Google Glass and do not really need to be modified for the moment since lots of situations may be solved with actual legal framework. Nevertheless, we don’t really know what to say before they enter into the Swiss market , which should not be before 2015 …

Stay tuned to see what will the USA authorities to when it will be on the market …

Electronic appeal in Switzerland – attorneys remain liable

In a recent decision (6B_691/2012 of February 21th, 2013), the Swiss Supreme Court confirmed that Swiss attorneys remain liable for the submission of electronic appeals. In this case, the attorney who has not verified that the appeal was properly received by the authority or the Court is liable. On the contrary, as technical service providers cannot guarantee a 100% available service, the submission of an electronic appeal is considered as a risk that shall be borne by the attorney if the provider gets down and cannot deliver the data to the court. The Swiss Supreme Court, reminds that the use of technologies contains risks. Therefore, the attorney remain liable :

  • even when there is no fault on the attorney;
  • even if the server gets down the last day of the deadline for submitting the documents to the Court
  • even if the software installed on the attorney’s computer contains bugs, an older or even an incompatible version that prevent the attorney to connect properly to the provided services.

To avoid any liability in case of any doubt, the attorney shall submit a separate documentation to the authority or the Court … by mail ! If the attorney does not comply with this obligation, he could face the consequence of this negligence which means that the appeal would be considered as a belated action with no possibility to require from the Court a new deadline.

With such opinion, the Swiss Supreme Court does not encourage Swiss lawyers to resort to new technologies. In consequence, this will delay the birth of 100% digital lawyers…

For further details, you can read the full analysis of this decision in French  here.