2018/02/06

Italia: diritto all'oblio e protezione dei cittadini italiani oltre i confini europei

Dopo il provvedimento dello scorso giugno, il Garante torna ad occuparsi di diritto all'oblio.
Se nella pronuncia precedente aveva sottolineato la rilevanza di elementi ulteriori rispetto a quello temporale al fine di valutare l'opportunità di una deindicizzazione, nell'ultimo caso è intervenuto in favore di una estensione della protezione dei cittadini italiani anche al di fuori dei confini europei.
Nel caso di specie, il ricorrente aveva chiesto la deindicizzazione di numerosi url europei ed extraeuropei che rimandavano a messaggi o brevi articoli anonimi pubblicati su forum o siti amatoriali e giudicati gravemente offensivi della propria reputazione. Tra di essi comparivano inoltre informazioni, giudicate false, attinenti allo stato di salute del ricorrente nonché a presunti reati da questo commessi. 
Il Garante si è pronunciato in senso favorevole al ricorrente, invitando Google a deindicizzare gli url riferibili al ricorrente, cittadino italiano, sia nelle versioni europee sia in quelle extraeuropee del motore di ricerca. Infatti la perdurante reperibilità di informazioni inesatte - a maggior ragione in quanto attinenti a dati sensibili - contenute in campagne personali e commenti spiacevoli, nel cagionare un impatto"sproporzionatamente negativo" sulla sfera privata del ricorrente, induce necessariamente ad una valutazione ed un approccio piu' rigoroso da parte dell'Autorità.





2017/02/13

Italia: il Garante della privacy si pronuncia sull'aggiornamento di articoli online

Il Garante italiano per la privacy si e' pronunciato circa le corrette modalita' di aggiornamento degli articoli di quotidiani online.
La pronuncia nasce dalla vicenda di un personaggio pubblico coinvolto in una vicenda giudiziaria e successivamente scagionato. Il quotidiano online, nel riportare l'aggiornamento della notizia, si era limitato ad apporre una semplice postilla agli articoli precedenti, lasciando l'uomo del tutto insoddisfatto.
Quest'ultimo, nel ricorrere al Garante, aveva evidenziato come la presenza in rete delle notizie concernenti la vicenda giudiziaria in cui era stato coinvolto, pregiudicasserro la sua reputazione professionale e personale, non corrispondendo pienamente alla realta' dei fatti.
Il Garante ha ritenuto lecito il trattamento dei dati contenuti negli articoli presenti nell'archivio storico del quotidiano, ma ha osservato che "il diritto della persona di ottenere l'aggiornamento delle informazioni che lo riguardano deve essere comunque garantito  qualora eventi successivi abbiano modificato quanto riportato, incidendo in modo significativo sul suo profilo e sulla sua imagine".
Ed ha sottolineato, in particolare, che perche' sia effettivamente garantita tutela all'interessato, l'aggiornamento dell'articolo deve essere immediatamente visibile al lettore, sia nel titolo sia nel contenuto dell'anteprima, non ritenendosi sufficiente l'apposizione di una mera postilla.
L'editore del quotidiano online, pertanto, ha ricevuto l'ordine di aggiornare la vicenda inserendone gli sviluppi in una nota accanto o sotto il titolo dell'articolo.
 


2016/11/18

German Law: critical infrastructures and cybersecurity

The frequency and the impact of incidents affecting information systems and services are continuously growing, because of the development of increasingly sophisticated methods.One of these methods consists in creating and using ‘botnets’, namely, the act of establishing remote control over a significant number of computers by infecting them with malicious software through targeted cyber-attacks. Once created, the infected network of computers that constitute the botnet can be activated without the computer users’ knowledge in order to launch a large-scale cyber-attack, which usually has the capacity to cause serious damage.
Cyber-attacks can be really critical to sensitive functions in both the private and public sector, with particular reference to the so-called “critical infrastructures”, namely, facilities and installations, the disruption or destruction of which could seriously affect essential economic and societal activities (e.g. transportation and traffic, IT and telecommunication, water and food, finance and insurance, healthcare).
The most relevant German regulation on the matter is contained in the IT Security Act, which came into effect on July 25, 2015.
The IT Security Act applies to websites operators and others considered as service providers according to the German Telemedia Act, telecommunication companies and operators of critical infrastructures, requiring them to implement security measures and to report security incidents to the Federal Office for information Security - “Bundesamt für Sicherheit in der Informationstechnik” (BSI).  This regulation applies to operators based in Germany, as well as, to foreign operators to the extent they provide infrastructures, products and services in Germany.
The IT Security Act is relevant in particular because of the regulation provided for the operators of critical infrastructures.
The IT Security Act provides a general definition of “critical infrastructures” and it empowers the Federal Ministry of the Interior to specify, in each sector, which operators could be deemed as a critical. At this purpose, the Ministry shall use branch-specific threshold values. The first ordinance, recently issued, covers the following sectors: energy, information technology and communications, water and food. The ordinance for the health, banking and insurance sectors is expected by the end of 2016 and the ordinance concerning the transport and traffic sector is expected by the beginning of 2017.
According to the IT Security Act and the ordinances, critical infrastructure operators must fulfill the following requirements.
First of all, companies shall adopt state-of-the-art technical and organizational measures to protect and ensure the availability, integrity, authenticity and confidentiality of their IT systems and services. IT Security Act does not define what is to be considered as state-of-the-art in each branch. The specification will be provided by the BSI, in cooperation with the representatives of the relevant sectors. Companies and industry associations may also propose branch-specific security standards.
Companies shall adopt the measures provided by the BSI within two years after the above mentioned ordinances has taken effect and they will be also required to demonstrate compliance to the BSI at least every two years (e.g. by security audits, examinations and certifications).
During the transition period, companies shall apply state-of-the-art measures, which are appropriate, technically feasible and commercially reasonable. In order to identify the “state-of-the-art measures”, companies can refer to national and international standards as well as to examples successfully proven in practice for the respective sector.
Within six months, after the above mentioned ordinances, companies shall also define an internal procedure in order to accomplish the reporting obligation to the BSI and they shall identify a person as a single point of contact with the authority. In case of incident, companies shall inform the BSI immediately, providing any relevant information on the disruption (e.g. the suspected or actual cause, the information technology and the facilities involved). The IT Security Act does not ask companies to report cybercrime attacks publicly but, in limited circumstances, the BSI could provide third parties with information on reported incidents.
In case of failure in implementing IT security measures, companies should pay fines up to EUR 100,000. Fines could be lesser in case of failure in complying with reporting obligations to the BSI.
The IT Security Act forestalled the European directive 2016/1140 concerning measures for a high common level of security of network and information systems across the Union (NIS Directive).
The NIS Directive clarifies that Member States may adopt or maintain provisions with a view to achieving a higher level of security of network and information systems. Moreover, the analysis of the rules shows significant similarities between European and German regulation.
Hence, the Directive does not affect the validity of the IT Security Act, but the German legislator should be asked to adjust the current legislation where necessary. Responding effectively to the new challenges in the cyber security sector requires, in fact, a global approach at Union level, covering common minimum capacity building and planning requirements, exchange of information, cooperation and common security requirements for operators.
 
 

2016/11/04

Cybersecurity: the relevant European regulation

Network and information systems and services play a vital role in society. Their reliability and security are essential to economic and societal activities as well as to the functioning of the internal market.
However, the frequency and the impact of security incidents are continuously increasing and they represent the major threat to the functioning of information systems and services, as well as to the protection of the personal data.
Furthermore, the different approach of the Member State has led to fragmented regulations across the Union.
Responding effectively to the new challenges in the cyber security sector requires a global approach at Union level, covering common minimum capacity building and planning requirements, exchange of information, cooperation and common security requirements for operators.
In order to accomplish this purpose, the European Union issued, inter alias, the following acts:
- Directive 2013/40/EU of 12 august 2013, on attacks against information system.
- Directive 2016/1148 of 6 July 2016, concerning measures for a high common level of security of network and information systems across the Union.
- Regulation 2016/679 of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
Directive 2013/40/EU of 12 august 2013, on attacks against information system
The objectives of this Directive are to approximate the criminal law of the Member States in the area of attacks against information systems by establishing minimum rules concerning the definition of criminal offences and the relevant sanctions and to improve cooperation between competent authorities, including the police and other specialised law enforcement services of the Member States, as well as the competent specialised Union agencies and bodies, such as Eurojust, Europol and its European Cyber Crime Centre, and the European Network and Information Security Agency (ENISA).
In fact, there is evidence of a tendency towards increasingly dangerous and recurrent large-scale attacks conducted against information systems which can often be critical to particular functions in the public or private sector. There is also a relevant number of “critical infrastructures” (infrastructures which are essential for the maintenance of vital societal functions like health, safety, security and transport), the disruption or destruction of which would have a significant cross-border impact.
Furthermore, it is really relevant the development of increasingly sophisticated methods, such as the creation and use of so-called ‘botnets’, namely, the act of establishing remote control over a significant number of computers by infecting them with malicious software through targeted cyber-attacks. Once created, the infected network of computers that constitute the botnet can be activated without the computer users’ knowledge in order to launch a large-scale cyber-attack, which usually has the capacity to cause serious damage.
Hence, the Directive aims to introduce criminal penalties for:  (i) illegal access to information systems, (ii) illegal system interference, (iii) illegal data interference, (iv) illegal interception.
In all cases, the criminal act must be committed intentionally. Instigating, aiding, abetting and attempting to commit any of the above offences will also be liable to punishment.
The Member States will have to make provision for such offences to be punished by effective, proportionate and dissuasive criminal penalties.
Where an offence is committed in the context of a criminal organisation and causes substantial loss or affects essential interests, this will be considered an aggravating circumstance. The same applies if an offence is committed using another person's identity and causes harm to this person.
The Directive also introduces the liability of 'legal persons' and sets out sanctions that may apply if they are found liable.
Each EU country will assume jurisdiction at minimum for offences committed on its territory or by one of its nationals outside its territory. Where several countries have jurisdiction over an offence, they must cooperate to decide which one will conduct proceedings against the author of said offence.
In order to fight cybercrime effectively, it is also necessary to increase the resilience of information systems by taking appropriate measures to protect them more effectively against cyber-attacks. Member States should take the necessary measures to protect their critical infrastructure from cyber-attacks, as part of which they should consider the protection of their information systems and associated data. Ensuring an adequate level of protection and security of information systems by legal persons, for example in connection with the provision of publicly available electronic communications services in accordance with existing Union legislation on privacy and electronic communication and data protection, forms an essential part of a comprehensive approach to effectively counteracting cybercrime. Appropriate levels of protection should be provided against reasonably identifiable threats and vulnerabilities in accordance with the state of the art for specific sectors and the specific data processing situations. The cost and burden of such protection should be proportionate to the likely damage a cyber-attack would cause to those affected. Member States are encouraged to provide for relevant measures incurring liabilities in the context of their national law in cases where a legal person has clearly not provided an appropriate level of protection against cyber-attacks.
To fight cybercrime better, the Directive also calls for greater international cooperation between judicial and law enforcement authorities.
To this end, EU countries must: (i) have an operational national point of contact, (ii) use the existing network of 24/7 contact points (iii) respond to urgent requests for help within 8 hours to indicate whether and when a response may be provided, (iv) collect statistical data on cybercrime.
This Directive has been implemented by national laws across the Union.
Directive 2016/1148 of 6 July 2016, concerning measures for a high common level of security of network  and information systems across the Union.
The Directive requires minimum IT security requirements and a reporting scheme for security incidents to digital service providers as well as operators of essential services, so called “critical infrastructures”.
Within the meaning of the Directive, digital services are: (i) online marketplace; (ii) online search engine; (iii) cloud computing services. The Directive does not apply to: (i) undertakings providing public communication networks or publicly available electronic communication services, within the meaning of Directive 2002/21/EU, which are subject to the specific security and integrity requirements laid down in that Directive; (ii) trust service providers within the meaning of Regulation 910/2014/EU which are subject to the security requirements laid down in that Regulation.
Digital service providers should identify and take appropriate and proportionate technical and organisational measures to ensure the security of network and information systems which they use in the context of offering their services within the Union, as well as to prevent and minimise the impact of incidents affecting their systems.
Having regard to the state of the art, those measures shall ensure a level of security of network and information systems appropriate to the risk posed, and shall take into account the following elements: (i) the security of systems and facilities; (ii) incident handling; (iii) business continuity management; (iv) monitoring, auditing and testing; (v) compliance with international standards. They also should notify the competent authority without undue delay of any incident having a substantial impact on the provision of a service. In order to determine whether the impact of an incident is substantial, the following parameters in particular shall be taken into account: (i) the number of users affected by the incident, in particular users relying on the service for the provision of their own services; (ii) the duration of the incident; (iii) the geographical spread with regard to the area affected by the incident; (iv) the extent of the disruption of the functioning of the service; (v) the extent of the impact on economic and societal activities.
For the purposes of the Directive, a digital service provider should be deemed to be under the jurisdiction of the Member State in which it has its main establishment, namely, the head office. If the digital service provider is not established in the Union but offers services within the Union, should designate a representative in the Union.
Operators of critical infrastructure are subject to rules slightly different. Each Member State will determine which operators in their jurisdiction could be considered as critical infrastructures. The criteria for the identification should be as follows: (i) an entity provides a service which is essential for the maintenance of critical societal and/or economic activities; (ii) the provision of that service depends on network and information systems; and (iii) an incident would have significant disruptive effects on the provision of that service.In order to establish if an incident could have significant disruptive effects, the Member States should take into account the following factors: (i) the number of users relying on the service provided by the entity concerned; (ii) the dependency of other sectors referred to in Annex II on the service provided by that entity; (iii) the impact that incidents could have, in terms of degree and duration, on economic and societal activities or public safety; (iv) the market share of that entity; (v) the geographic spread with regard to the area that could be affected by an incident; (vi) the importance of the entity for maintaining a sufficient level of the service, taking into account the availability of alternative means for the provision of that service. It is also possible that some entities provide both essential and non-essential services. Therefore, the operators should be subject to the specify security requirements only with respect to those services which are deemed to be essential. Furthermore, for the purpose of the identification process, when an entity provides an essential service in two or more Member state, those Member States should engage in bilateral or multilaterals discussions with each other. The Directive underlines the importance of an international cooperation within the Union, considering that services and incidents could have cross-border impact.In order to facilitate cross-border cooperation and communication, each Member State should designate a national single point of contact responsible for coordinating issues related to the security of network and information systems and cross-border cooperation at Union level. EU countries will have 21 months from the date the directive comes into force to implement the new EU legislation into national laws, and have a further six months to identify the operators of critical infrastructures.
Regulation 2016/679 of 27 April 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
The economic and social integration resulting from the functioning of the internal market has led to a substantial increase in cross-border flows of personal data. Furthermore, technological developments and globalisation have brought new challenges for the protection of personal data. Hence, those developments require a strong and more coherent data protection framework in the Union, backed by strong enforcement. In order to ensure a consistent and high level of protection of natural persons and to remove the obstacles to flows of personal data within the Union, the level of protection of the rights and freedoms of natural persons with regard to the processing of such data should be equivalent in all Member States.
With particular reference to the security of personal data, the Directive provides that, taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing as well as the risk of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement “appropriate technical and organisational measures” to ensure a level of security appropriate to the risk, including as appropriate: (i) the pseudonymisation and encryption of personal data; (ii) the ability to ensure the ongoing confidentiality, integrity, availability and resilience of processing systems and services; (iii) the ability to restore the availability and access to personal data in a timely manner in the event of a physical or technical incident; (iv) a process for regularly testing, assessing and evaluating the effectiveness of technical and organisational measures for ensuring the security of the processing. This Regulation shall apply from 28 May 2018.

2016/09/01

Italia: Privacy ed invio di spot pubblicitari mirati

Con provvedimento del 13 luglio 2016, il Garante si e' pronunciato sulla richiesta di verifica preliminare presentata da Sky in merito alla possibilita' di veicolare messaggi pubblicitari mirati a spettatori di un medesimo programma.
Destinatari della pubblicità i nuclei familiari in possesso di uno specifico apparecchio per la ricezione da satellite o via internet, raggruppati in appositi cluster in base a caratteristiche relative al servizio fruito (ad es., tipologia del "pacchetto" tv, durata dell'abbonamento, modalità di pagamento) e ad altre informazioni (fascia di età,  luogo di residenza).
Piu' in dettaglio, il progetto presentato da Sky si presenta suddiviso in quattro fasi: a) creazione di una banca dati anonimizzata, partendo dai dati (gia' pseudoanonimizzati)  in possesso di Sky, in conformta' con gli standard contenuti nel parere Parere n. 5/2010 del Gruppo di lavoro Articolo 29. L'anonimizzazione avverrebbe dunque tramite l'eliminazione di ogni riferimento univoco a singolo abbonamento/smart card, inclusa l'anagrafica cliente; b) definizione delle regole di segmentazione volte ad enucleare (da parte di personale appartenente ad una divisione della società cui è inibito l'accesso al database contenente i riferimenti anagrafici) segmenti di interesse, composti da almeno 5.000 clienti (cd. cluster) risultanti dalla combinazione di più attributi, e trasmissione in broadcast di tali "regole" ai STB; c) applicazione delle regole e, conseguentemente, associazione a ciascun cluster di determinati spot mirati, memorizzati sugli hard disk dei STB "My Sky HD" in base agli attributi presenti sulla smart card. Al momento del passaggio dello spot, e' il STB a veicolare, in base a informazioni inserite nel flusso video, la pubblicità in onda ovvero quella mirata precedentemente memorizzata sull'hard disk. Mediante un algoritmo, i sistemi producono per ogni slot pubblicitario identificato come sostituibile una lista di possibili campagne selezionabili dai STB per la sostituzione; la scelta, effettuata dal STB, non è determinabile a priori; d) trasmissione via Internet, da parte dei soli dispositivi abilitati (i soli STB connessi a Internet), in forma aggregata, dei feedback relativi agli spot oggetto di sostituzione e senza cambio di canale per fini statistici e di rendicontazione relativa all'analisi sulle performance delle campagne pubblicitarie. 
Il Garante si e' pronunciato positivamente sul progetto, aggiungendo tuttavia alcune prescrizioni intese ad elevare il livello di protezione degli utenti.
In particolare, gli utenti dovranno essere messi in condizione di opporsi agevolmente all'invio degli spot mirati, digitando "no" sul telecomando, opppure spuntando una apposita casella nella sezione dedicata agli utenti registrati nel sito della società, o ancora inviando una comunicazione, anche via email, alla società ovvero interagendo con il call center. 
Sky dovra', inoltre, informare gli utenti delle finalità che intende perseguire con questo progetto (marketing sulla base della profilazione); spiegare loro le modalità impiegate per assicurare l'uso dei dati in forma aggregata,  tali da non essere riconducibili ai singoli abbonati; avvisarli della possibilità di esercitare i diritti riconosciuti dalla normativa in materia di protezione dei dati (accesso ai dati, rettifica, cancellazione, opposizione al trattamento).
L'informativa potrà essere resa in forma sintetica mediante un cartello che apparirà a video alla prima accensione dopo l'aggiornamento del software e che dovrà rimandare ad una pagina web, reperibile facilmente e in ogni momento. Nell'informativa, oltre a fornire le informazioni sui diritti degli utenti, Sky dovrà descrivere il progetto nel dettaglio. Il messaggio dovrà essere ripetuto più volte e con modalità tali da assicurarne la visibilità a più componenti della stessa famiglia.









2016/08/22

Germany: the legitimacy of the parody under the EU law

On 28th July, 2016, the Federal Supreme Court ruled that the section 24, subsection 1 of the Copyright Act, relating to the free use of a copyright protected work in order to realize a parody, must be interpreted in accordance with the Art. 5 (3) lit. k of the Directive 2001/29/EC.
In this regard, it is relevant the decision issued by the CJEU on 3td, September, 2014 (C-201/13). The CJEU said that concept of ‘parody’, which appears in a provision of a directive, that does not contain any reference to national laws, must be regarded as an autonomous concept of EU law and interpreted uniformly throughout the European Union.
That interpretation is not invalidated by the optional nature of the exception mentioned in Article 5(3)(k) of Directive 2001/29. An interpretation according to which Member States that have introduced that exception are free to determine the limits in an unharmonised manner, which may vary from one Member State to another, would be incompatible with the objective of that directive (see, to that effect, judgments in Padawan, paragraph 36, and ACI Adam and Others, C‑435/12 , paragraph 49). 
In the opinion of the CJEU, the article 5(3)(k) of Directive 2001/29 must be interpreted as meaning that the essential characteristics of parody, are, first, to evoke an existing work, while being noticeably different from it, and secondly, to constitute an expression of humour or mockery. On the contrary, the concept of ‘parody’, within the meaning of that provision, is not subject to the conditions that the parody should display an original character of its own, other than that of displaying noticeable differences with respect to the original parodied work; that it could reasonably be attributed to a person other than the author of the original work itself; that it should relate to the original work itself or mention the source of the parodied work.
Moreover, the application of the exception for parody, within the meaning of Article 5(3)(k) of Directive 2001/29, requires a fair balance between, on the one hand, the freedom of expression of the user of a protected work who is relying on the exception for parody, and on the other,  the interests and rights of persons referred to in Articles 2 and 3 of that directive.



 

2016/03/16

Italia: come tutelare un Format Televisivo


Se abbiamo un'idea che sia originale ed innovativa, è nostro diritto e nostro dovere tutelarla.
Spesso sento ripetere che non vale la pena di depositare un Format perchè non è tutelabile.
Questa affermazione contiene solo una piccola parte di verità.
Certamente depositare un format presso la SIAE non ha la stessa efficacia del registrare un marchio, ma rappresenta comunque uno strumento di tutela a mio avviso non rinunciabile.
Depositare un Format significa infatti vedere tutelata la priorita´della propria idea e, ove si consideri che la procedura è estremamente semplice e poco onerosa sul piano economico, puo' rappresentare davvero un'utile risorsa.
Vediamo, di seguito, come procedere concretamente.
1. Caratteristiche del Format
Ai fini della tutela, occorre che il Format presenti alcune caratteristiche. Infatti, e' indispensabile che esso: (i) abbia una struttura originale esplicativa dello spettacolo; (ii) abbia una struttura compiuta nell'articolazione delle sue fasi essenziali e tematiche; (iii)presenti i seguenti elementi qualificanti: titolo, struttura narrativa di base, apparato scenico e personaggi fissi. 
In linea generale, quando il tema centrale non ha di per sé carattere di assoluta originalità, il format si puo' comunque considerare sufficientemente preciso (e quindi tale da costituire una elaborazione originale) anche quando, pur senza giungere ad una esposizione minuziosa ed analitica, fornisce elementi sufficienti a caratterizzare in modo definitivo almeno la natura e lo svolgimento degli eventi.
2. Modalita' di deposito
a. Se tu o un altro dei coautori e' iscritto alla sezione DOR della SIAE:
- la procedura di deposito è gratuita
- dovete depositare il Bollettino di Dichiarazione (il cd. Modello 91 più eventuali allegati) compilato e firmato da tutti voi.
-dovete inoltre depositare un esemplare del copione originale firmato su tutte le pagine, sempre da tutti gli autori.
b. Se né tu né un altro degli autori del format è iscritto alla SIAE:
- la procedura è a pagamento. In questo caso dovete versare a titolo di diritti di segreteria € 25,00 + IVA (per un totale di € 30,50), mediante POS pagamento o presso lo sportello UNICREDIT BANCA presente in Direzione Generale, o tramite versamento su bollettino di c/c postale n. 84294008 intestato alla Società Italiana degli Autori ed Editori – Viale della Letteratura n. 30 – 00144 Roma, con la causale: “diritti di procedura per deposito format”.
- dovete compilare il Bollettino di Dichiarazione (questa volta il Modello 91bis più eventuali allegati) compilato e firmato, sempre, da tutti gli autori,
- dovete depositare un esemplare del copione originale firmato su tutte le pagine, sempre da tutti gli autori.
3. Moduli
Cliccando su questo link puoi accedere ai Moduli e stamparli direttamente dal sito web della SIAE: Moduli da compilare. La compilazione, per i format è piuttosto semplice perchè non occorre inserire tutte le dichiarazioni relative alle opere radiotelevisive, né ovviamente compilare i campi relativi alle opere elaborate. Allo stesso modo non dovrebbero riguardarti gli allegati che si riferiscono all’impiego di brani musicali e testi letterari.
Per la compilazione, comunque, ogni caso è a sé stante e richiede delle considerazioni diverse.
4. Consegna della documentazione
Il deposito lo si puo' fare inviando una raccomandata a: SIAE - sez. DOR - Ufficio Documentazione - Via della Letteratura 30 - 00145 Roma, oppure recandosi allo sportello della SIAE a Milano (o in altre città in cui sia presente).
5. Validità del deposito
Il deposito ha validità tre anni e, prima della scadenza, si puo’ chiedere il rinnovo pagando lo stesso importo.
6. Variazioni del format e del titolo
Se successivamente al deposito, decidi di cambiare alcuni elementi del format, devi procedere con un nuovo deposito inviando i testi come modificati.
Se invece decidi di cambiare il titolo del format già depositato, è sufficiente inviare una comunicazione scritta agli uffici della SIAE.






2016/02/22

Italia: Garante Privacy, ai blogger si applicano le stesse regole del giornalista

Con provvedimento del 27 gennaio 2016, il Garante ha enunciato il principio per il quale i blogger che svolgono un'attivita' di informazione sono soggetti alle medesime regole e alle medesime garanzie cui sono soggetti i giornalisti.
Il provvedimento nasce dal ricorso di un noto personaggio pubblico finalizzato alla rimozione di un articolo, pubblicato su un blog, e avente ad oggetto le proprie vicende sentimentali e giudiziarie. Secondo la ricorrente, infatti, la diffusione dei suoi dati personali avrebbe violato la disciplina del Codice Privacy, essendo avvenuta in assenza di consenso; e cio' stante l'inapplicabilita' delle eccezioni connesse alla liberta' di manifestazione del pensiero.
Il Garante Privacy, tuttavia, ha rigettato il ricorso, ritenendo che fosse infondato.
Infatti, il blog che svolge attivita' di informazione e' del tutto assimilabile all'attivita' giornalistica in senso stretto e, per l'effetto e' soggetto all'applicazione dell'articolo 136 del Codice che estende le garanzie riguardanti l'attività giornalistica ad ogni altra attività di manifestazione del pensiero, anche se non effettuata da giornalisti professionisti o pubblicisti.
Cio' significa che, in ossequio alla liberta' di informazione, il blogger puó divulgare attraverso la propria pagina informazioni e notizie contenenti dati personali di terzi senza la necessita' di acquisire preventivamente il consenso degli interessati. Naturalmente, tale liberta' va ogni volta bilanciata con il rispetto dei diritti e delle libertä' fondamentali di questi ultimi.


 

2016/02/01

Germany: Youtube is not responsible for the IP violations by third parties

On 28th January, 2016, the Oberlandesgericht of Munich established that Youtube is not responsible for the IP violations made by third parties through the platform.
GEMA, the German collecting society, asked Youtube to pay the royalties for the utilization of music in some Videos uploaded by the users.
However, Youtube refused to accept the charges, given its role as a provider of a technical service.
As a consequence, lawyers said, Youtube don't have any influence on the publication of the Contents.
The Oberlandesgericht of Munich accepted these argumentations and ruled that GEMA schould address its
compliants against the users and not against YouTube.
The decision is not definitve and GEMA announced that it will bring an appeal before the Bundesgerichtshof.

2015/11/15

Court of Justice: Schrems v. Data Protection Commissioner

On 6 October 2015, the CJEU delivered its judgment on a preliminary reference from an Irish court in matter of data protection.
An Austrian user of Facebook made a complaint to the Irish Data Protection Commissioner, asking the authority to prohibit Facebook Ireland from transferring his personal data to the United States, because of the non-adequate level of data protection in the country. The Commissioner rejected the complaint, pursuant to the Commission’s Decision 2000/520, the “Safe Harbour Agreement” which consider adequate the U.S. data protection law.
The Irish High Court reviewed the Commissioner’s decision, and asked the CJEU to rule on whether the Commissioner was absolutely bound by the Commission’s decision on US law, and whether the Commissioner should instead carry out its own review of US law.
The CJEU ruled that the Data Protection Directive must be interpreted as meaning that a Commission decision does not prevent a national authority from examining a claim from an individual about the level of data protection.
The Court also examined whether the Commission’s decision complied with the Data Protection Directive and the EU Charter of Fundamental Rights, concluding that it was invalid, because the Commission did not state that the United States in fact ‘ensures’ an adequate level of protection by reason of its domestic law or its international commitments.
A new Safe Harbour Agreement is currently being negotiated between U.S. and EU. In the meanwhile, the transfer of European data to the U.S. could be made under model contract clauses.





2015/07/15

Germany: online archives and the right to be forgotten

On July 7, 2015, the Hamburg Court of Appeal decided that the “right to be forgotten” can also be asserted vis-à-vis by the operator on an online archive.
The claim, against the publisher of a national daily newspaper,  was about the availability of old news in an online archive. In particular, this archive included some articles regarding a criminal suit against the claimant. He complained that these articles could be found among the top three search results on google.de by entering his name.
The Hamburg District Court dismissed the complaint in its judgment, stating that the plaintiff was not entitled to ask the publisher to delete or amend the articles in the archive, because of the absence of damages to his fundamental rights.
Instead, the Court of Appeal stated that, although the claimant didn't have the right to obtain the deletion of the articles from the online archive, the appeal was well-founded insofar as he called for the defendant to modify the articles in question in such a way that they did not appear in lists of search results when his name was entered into internet search engines, in order to protect his public reputation  (pursuant to the 1004(1), first sentence of the Bürgerliches Gesetzbuch (Civil Code - BGB) in conjunction with general personality law).





2015/05/20

Freedom of Expression: new guidelines

On May 12, 2014, the Council of the European Union adopted the EU Guidelines on Freedom of Expression Online and Offline, in order to: (i) explain the international human rights standards on freedom of opinion and expression,  (ii) provide a guidance to officials of the EU Institutions and member states for their work in third countries, (iii) contribute to preventing potential violations of the right to freedom of opinion and expression.
Hence, the guidelines identify some priority areas: a) combating violence, persecution, harassment and intimidation of individuals, including journalists and other media actors, because of their exercise of the right to freedom of expression online and offline, and combating impunity for such crimes; b) promoting laws and practices that protect freedom of opinion and expression; c) promoting media freedom and pluralism and fostering an understanding among public authorities of the dangers of unwarranted interference with impartial/critical reporting; d) promoting and respecting human rights in cyberspace and other information and communication technologies; e) promoting best practices by companies; f) promoting legal amendments and practices aimed at strengthening data protection and privacy online/offline.
The guidelines identify the following tools in order to ensure the protection of the freedom of expression: a) political dialogues and high level visits; b) monitoring, assessing and reporting on freedom of expression; c) public statements and demarches; d) financial instruments; e) public diplomacy in multilateral fora; f) media freedom and pluralism in the EU enlargement policy; g) promoting Council of Europe and OSCE acquis; h) trade measures; i) training and technical exchanges; l) capacity building.

2015/04/30

Germany: the first decision of the ZAK in matter of virtual product placement

On April 15, 2014, the Kommission für Zulassung und Aufsicht issued its first decision in matter of virtual product placement.
The decision was about a 15-second sequence of a poster advertising in the film “Hansel &Gretel: Witch Hunters” (RTL2 programme “Berlin Tag & Nacht”, 2013). In the opinion of the Kommission, the sequence did not breach the Land media authorities’ advertising regulations, because the product placement did not appear artificial and forced, as well as it respected the regulation on the matter, like labelling, independence of the broadcaster, no excessive prominence of the product).

2015/03/16

Germany: surreptious advertising

On March, 9 2015, the Bavarian Administrative Court, ruled that the repeated appearance of a logo during a television programme constitutes illegal surreptitious advertising. 
The case no. 7 B 14/1605 concerned the broadcast of the programme ‘Learn from the Pros’ by TV channel Sport1, in which the logo of an internet provider was showed in every shot and in particular when viewers were paying particularly close attention. Moreover, at the end of the programme, viewers were encouraged to visit the website of the internet provider.
In the opinion of the Court, the intensity and the frequency of the logo in the programme, as well as the lack of an advertising label demonstrated the intention to mislead the viewers.


2014/12/23

Garante della privacy: provvedimenti sul diritto all'oblio

Riporto di seguito un estratto della newsletter del Garante Privacy, consultabile sul sito dell'autorità.
"Il Garante privacy ha adottato i primi provvedimenti in merito alle segnalazioni presentate da cittadini dopo il mancato accoglimento da parte di Google delle loro richieste di deindicizzare pagine presenti sul web che riportavano dati personali ritenuti non più di interesse pubblico. A seguito della recente sentenza della Corte di Giustizia europea sul diritto all'oblio, Google è infatti tenuta a dare un riscontro alle richieste di cancellazione, dai risultati della ricerca, delle pagine web che contengono il nominativo del richiedente reperibili utilizzando come parola chiave il nome dell'interessato.
La società deve valutare di volta in volta vari elementi quali ad esempio: l'interesse pubblico a conoscere la notizia, il tempo trascorso dall'avvenimento, l'accuratezza della notizia e la rilevanza della stessa nell'ambito professionale di appartenenza. Di fronte al diniego di Google, gli utenti italiani possono rivolgersi al Garante per la privacy o all'autorità giudiziaria.
Le segnalazioni e i ricorsi pervenuti al Garante, riguardano la richiesta di deindicizzazione di articoli relativi a vicende processuali ancora recenti e in alcuni casi non concluse.
In sette dei nove casi [doc. web nn. 3623819, 3623851, 3623897, 3623919, 3623954, 3624003 e 3624021] definiti il Garante non ha accolto la richiesta degli interessati, ritenendo che la posizione di Google fosse corretta in quanto è risultato prevalente l'aspetto dell'interesse pubblico ad accedere alle informazioni tramite motori di ricerca, sulla base del fatto che le vicende processuali sono risultate essere troppo recenti e non ancora espletati tutti i gradi di giudizio.
In due casi [doc. web nn. 3623877 e 3623978], invece, l'Autorità ha accolto la richiesta dei segnalanti. Nel primo, perché nei documenti pubblicati su un sito erano presenti numerose informazioni eccedenti, riferite anche a persone estranee alla vicenda giudiziaria narrata. Nel secondo, perché la notizia pubblicata era inserita in un contesto idoneo a ledere la sfera privata della persona. Tutto ciò in violazione delle norme del Codice privacy e del codice deontologico che impone di diffondere dati personali nei limiti dell'"essenzialità dell'informazione riguardo a fatti di interesse pubblico" e di non descrivere abitudini sessuali riferite a una determinata persona identificata o identificabile. L'Autorità ha quindi prescritto a Google di deindicizzare le url segnalate".

2014/10/30

Garante Privacy: email promozionali senza consenso

Il Garante ha dichiarato illecito il trattamento di dati effettuato da una società che inviava email promozionali agli utenti che avevano sottoscritto un form online per la ricezione di newsletter.
Il Garante ha ribadito il principio per il quale i cittadini devono poter essere in grado di decidere liberamente se ricevere o meno comunicazioni promozionali, al di là del consenso prestato per la ricezione di newsletter. 
Da tale declaratoria discende dunque l'inibizione alla prosecuzione del trattamento per finalità promozionali. Qualora l'azienda intenda inviare email di questo tipo dovrà modificare il form di registrazione in modo da consentire agli utenti la possibilità di esprimere, un preventivo e specifico consenso per la ricezione di email promozionali. 
L'Autorità sta valutando, con separato provvedimento, l'applicazione della sanzione amministrava per l'illecito commesso.

2014/10/22

Garante Privacy: Big Data nelle statistiche nazionali

Il Garante ha dato l'ok allo schema di Programma statistico nazionale 2014-2016 predisposto dall'Istat, che prevede la possibilità di utilizzare i Big Data di telefonia mobile, al fine di stimare, a livello aggregato, i flussi di mobilità intercomunali delle persone. 
A tal fine tratta i dati relativi al "call detail record" (cdr), ossia  un numero progressivo assegnato dal gestore telefonico all'utente che effettua la chiamata, al quale vanno aggiunte le informazioni relative al Comune nel quale si trova la cella di effettuazione, la data e l'ora della chiamata. 
Il Garante, tuttavia, ha richiesto precise garanzie a tutela degli interessati, dato il rischio di giungere ad una re-identificazione dell'interessato attraverso informazioni apparentemente anonime.
In particolare l'Istat dovrà fare in modo che sia esclusa qualsiasi possibilità di raccordo tra il cdr e gli identificativi originali. Inoltre, dovranno essere oscurate le frequenze di flusso inferiori a tre unità.
Il Garante si è infine riservato di svolgere controlli mirati anche sui trattamenti svolti dai gestori telefonici.
 

2014/09/30

La responsabilità del provider: Delta Tv vs Google/Youtube

Il Tribunale di Torino, con ordinanza del 23 giugno 2014, nell’ambito di un procedimento attivato da Delta TV nei confronti di Google Ireland Holdings, Google Inc, e Youtube LLC, in relazione alla diffusione di materiale audiovisivo protetto, è intervenuto sul delicato tema del bilancia-mento tra la tutela della proprietà intellettuale e la salvaguardia della libertà di espressione nella società dell’informazione; tema che involge un’ulteriore spinosa questione: la responsabilità degli internet service provider.
Delta TV, asserendo di essere esclusiva titolare dei diritti di sfruttamento economico di alcune telenovelas sudamericane, inclusa la versione italiana delle stesse, ed avendo rilevato la presenza di alcuni episodi delle medesime sui siti Youtube.it e .com, a seguito di formale diffida alle controparti, chiedeva, in sede cautelare, (i) la cancellazione o rimozione dei files relativi alle telenovelas; (ii) l’inibizione dell’ulteriore trasmissione o diffusione delle stesse e, infine (iii) l’imposizione di una penale, ex art. 156 l.d.a., per ogni inosservanza agli ordini di rimozione e di inibitoria.
Tali doglianze, inizialmente disattese dal Tribunale, trovavano tuttavia accoglimento nel successivo procedimento di reclamo, in occasione del quale i giudici torinesi hanno confermato l’orientamento nazionale e comunitario prevalente.
Nel ricercare il giusto equilibrio tra tutela della proprietà intellettuale e della libertà d’espressione, i giudici torinesi richiamano innanzitutto alcuni fondamentali principi dell’ordinamento comunitario  volti a delineare l’assetto delle responsabilità dei soggetti coinvolti nella prestazione dei servizi della  società dell’informazione:
- l’hosting provider è esente da responsabilità nella misura in cui svolga un’attività di tipo tecnico, automatico e passivo consistente, unicamente, nel fornire accesso ad una rete di comunicazione elettronica;
- l’hosting provider, appena ricevuta notizia dell’illecito, è tenuto ad attivarsi per la rimozione delle informazioni o per l’impedimento dell’accesso alle stesse;
- il ricorrere di ipotesi di limitazione di responsabilità non esclude la possibilità di azioni inibitorie;
- fermo il divieto di imporre all’hosting provider un obbligo di sorveglianza preventivo e generale, non è esclusa la possibilità di imporre obblighi di sorveglianza in casi specifici.  In proposito la giurisprudenza comunitaria ha precisato che pur potendosi pretendere dal provider che questi prevenga ulteriori future violazioni, non sono ammissibili provvedimenti che impongano, attraverso misure eccessivamente gravose, obblighi di controllo diretti a prevenire qualsiasi futura violazione dei diritti di proprietà intellettuale .
Il Tribunale, muovendo dai principi dianzi esposti, recepiti peraltro dall’ordinamento interno così come dalla prevalente giurisprudenza nazionale, ha compiuto un’analisi della figura dell’hosting provider che tenesse conto delle evoluzioni delle tecno-logie e delle strategie commerciali del settore.
L’hosting provider, infatti, è ben lungi oggi dall’essere una figura passiva e neutra rispetto all’organizzazione e alla gestione dei contenuti.  Il prestatore, e segnatamente Youtube, svolge un’attività finalizzata alla gestione complessiva dei contenuti caricati dagli utenti, i quali vengono riorganizzati, indirizzati e “suggeriti” ai singoli utenti di cui son tracciati i profili di consumo.  Tale attività – che costituisce il valore aggiunto del servizio di Youtube determinando un accrescimento degli introiti pubblicitari della piattaforma implica che il prestatore diventi portatore di una significativa potenzialità lesiva di diritti di terzi, con l’effetto che diventa necessaria una maggiore responsabilità a suo carico.  In tale ottica, dunque devono essere interpretate le norme sia comunitarie e nazionali.
Conseguentemente, secondo i giudici torinesi, avuto riguardo al caso di specie, deve ritenersi che sia del tutto legittimo un provvedimento che, in via cautelare, imponga al prestatore non solo di porre fine a violazioni già perpetrate, ma di prevenire anche nuove violazioni.  Segnatamente ben può esse-re imposto al prestatore l’obbligo di impedire nuovi caricamenti dei medesimi contenuti sulla propria piattaforma.  Ciò non si traduce infatti in un obbligo di sorveglianza preventivo e generale ma consiste in un intervento specifico, mirato su contenuti ben determinati e successivo ad una denuncia.  Inoltre tale intervento non risulterebbe neanche eccessivamente gravoso, stante la possibilità per il prestatore di utilizzare a tal fine il Content ID, tecnologia che consente agevolmente di individuare, attraverso un apposito software, i file lesivi dei diritti terzi.
Il Tribunale, dunque, accoglie l’istanza di reclamo avanzata da Delta Tv e ordina a Google Inc. e a Youtube LLC di rimuovere dalla piattaforma Youtube gli audiovisivi di cui agli URL comunicati da Delta TV; ordina loro di impedire l’ulteriore caricamento sulla piattaforma dei medesimi materiali impiegando a tal fine, a propria cura e spese, il software Content ID e utilizzando come references file i contenuti caricati ai predetti URL.  Rigetta invece la domanda cautelare nei confronti di Google Ireland Holdings .
L’ordinanza esaminata si colloca nel filone giurisprudenziale attualmente prevalente sia a livello comunitario che nazionale.
Rammentando la possibilità di enucleare tre diverse linee di pensiero che interpretano in maniera più o meno stringente la normativa vigente , la pronuncia considerata rientra nella corrente che ha tentato di risolvere  le problematiche afferenti la responsabilità del provider, creando la figura dell’hoster attivo.
La giurisprudenza, infatti, preso atto delle evoluzioni tecnologiche e delle strategie commerciali nella società dell’informazione, avuto particolare riguardo a provider come Youtube, è giunta a distinguere tra la figura dell’hosting provider “passivo” che effettivamente si limita ad una mera e neutra attività di intermediazione, e la figura  dell’hosting provider “attivo”, che di fatto svolge una significativa attività di organizzazione e gestione del materiale caricato dagli utenti, guadagnando dall’accrescimento degli introiti pubblicitari che tale attività di riorganizzazione e targettizzazione sulle abitudini dell’utente comporta .  Tale distinzione concettuale si traduce anche in una differente valutazione delle responsabilità attribuibili agli hosting provider.  E’ chiaro infatti che attività così significative come quelle descritte non potrebbero giustificare un’assenza o una significativa limitazione di responsabilità in capo al prestatore.
L’ordinanza in commento è conforme, inoltre, all’orientamento attualmente prevalente circa l’applicazione del principio per cui l’obbligo di rimozione sorge unicamente a fronte di una diffida specifica contenente cioè gli indirizzi compendiati in singoli URL.
Allo stesso modo, la suddetta pronuncia si pone in linea con la corrente predominante anche in relazione alla possibilità di imporre misure intese a prevenire la commissione di ulteriori illeciti.
Conformemente ai principi statuiti dalla Corte di Giustizia, in base ai quali non sono ammessi né obblighi di sorveglianza preventivi e generalizzati  né misure sproporzionate ed eccessivamente inique o costose, i giudici torinesi hanno ritenuto  che la finalità di prevenzione degli illeciti possa essere utilmente conseguita mediante l’impiego, da parte del provider, del software Content ID, utilizzando come references file i contenuti caricati agli URL indicati dal titolare dei diritti.
L’imposizione di tale misura non sembra che possa contrastare con i principi generali in materia, per essere la predetta circoscritta a specifici contenuti previamente determinati, e per essere altresì successiva rispetto ad una denuncia già effettuata.  Inoltre l’adempimento da parte del prestatore non sembra eccessivamente oneroso sul piano pratico: il prestatore, infatti, come si diceva innanzi, non è tenuto neanche a caricare i references file, già presenti sulla piattaforma in corrispondenza degli URL segnalati; né si ritiene che sia iniqua o sproporzionata la circostanza che siano posti a carico del prestatore i costi per l’espletamento della procedura qui indicata.

2014/09/28

ICT: new guidelines on child online protection

On September 2014, the International Telecommunication Union, the UNICEF and two United Nations agencies published the new guidelines on child online protection, for mobile operators, internet service providers, content providers, online retailers, app developers, social media providers, public service broadcasters, and operating system developers.
The purpose of the guidelines is to ensure the safety of children when using ICT technologies. 
Hence, companies have to focus on: (i) integrating child rights considerations into the corporate policies and management processes, (ii) developing standard processes to handle child sexual abuse material, (iii) creating a safer and age-appropriate online environment, (iv) appointing a qualified team as a responsible for the online child safety; (v) developing of notice and takedown procedures; (iv) educating children, parents, and teachers about children’s safety.

2014/06/16

Opere d'arte e diritti museali

Non tutti lo sanno ma anche se le opere d'arte sono cadute in pubblico dominio deve essere riconosciuta la tutela dei diritti del museo in cui l'opera è custodita.
Secondo l'interpretazione maggioritaria, tale diritto rientrerebbe in quello generale del diritto di proprietà che riserva al proprietario la facoltà esclusiva di sfruttare economicamente i propri beni.
Pertanto anche scaduti i diritti sul corpus mysticum resterebbero i diritti sul corpus mechanicum dell'opera custodita in un luogo chiuso con conseguente necessità del consenso del proprietario, pubblico o privato, per qualsiasi sfruttamento della stessa.