Saturday, March 16, 2013

The Law, the Military, and Big Data


America has a long history of separating military operations from civilian law enforcement and domestic governmental functions.[1] The information technology revolution has created new realities that will challenge this old order of things.  As knowledge grows, it will greatly improve decision making for the military, law enforcement, the domestic sector of the government, as well as the business community.  With these opportunities, come threats to privacy from the compilation of information, as well as the threat from malicious digitized information itself.[2]  This post focuses on the implications of the military holding all of this information.

Organizational silos have separated military, domestic intelligence, law enforcement, and other parts of the government form each other for over two centuries.  The processing of online information and the need to protect our IT systems is slowly starting to merge across these parts of the government.[3]

Historically the military worked overseas.  The military's potential role in domestic cyber protection was discussed in a previous post on this blog, but this post concerns data collection.  Essentially, what do the American people want the military to know?  The Defense Department has vast resources of computing machines and highly educated personnel to collect all kinds of information.  International crime syndicates, money transfers, immigrant population flows, and of course cyber investigations are all subjects about which the military could collect domestic data in the conduct of its duties.

What other parts of the government and the business community do with that information from the military is yet another set of issues.  The military might have data sets about children's academic performance at on-base schools that the federal and local education authorities might like.  Many medical and scientific innovations come from the battlefield.  In addition, the research and data that the military, and all other parts of the government collect are invaluable to the business community.  These are policies that should be allowed, but then that raises the issue discussed below of whether the aggregation of too much information sets up a power imbalance between the government and citizenry.[4]

As the word privacy is not written in the constitution, it is usually associated with the First and Fourth Amendments.  The U.S. Supreme Court has stated that the military can collect information on civilian matters without a presumption of violating First Amendment rights such as the right to associate.[5]  The law needs to be modernized to control how the information is protected and with whom it is shared.

The other big issue is Fourth Amendment issues in law enforcement.  We want criminals arrested, and better yet, deterred from the start. The Posse Comitatus Act generally bans the military from civilian law enforcement.[6]  The normal judicial test is 1) military troops may not pervade law enforcement organizations, 2) the military cannot be used to catch criminals, and 3) civilians cannot be subject to the military's regulations.[7]  While there is no rule to exclude evidence from military investigators in federal civilian court,[8] three states ban it and it is a rare occurrence.[9] The exception is when military investigators discover fraud with defense contractors or espionage on a base, since there is a nexus between the military and the criminal code on those subject matters.

In the world of Big Data, the military might be able to amass volumes of domestic information legitimately and the hand over evidence of crimes with such regularity that civilian law enforcement becomes dependent on it.  That is where the law comes in.  To stop the temptation to use analyzed data, albeit for public good, when it violates the expected privacy of the American people.




[1] Laird v. Tatum 408 U.S. 1, 15 (1972)
[2] http://thehill.com/blogs/hillicon-valley/technology/280243-overnight-tech-hagel-stresses-importance-of-cybersecurity-ahead-of-confirmation-hearing
[3] http://www.nextgov.com/cybersecurity/2013/02/defense-positions-military-cyber-squad-dhs-turf/61057/
[4] http://www.wired.com/politics/security/commentary/securitymatters/2006/05/70886
[5] Laird v. Tatum 408 U.S. 1 (1972)
[6] 18 U.S.C. § 1385
[7] Congressional Research Service, The Posse Comitatus Act and Related Matters: The use of the Military to Execute Civilian law August 16, 2012 http://www.fas.org/sgp/crs/natsec/R42659.pdf

[8] U.S. v Walden 490 F 2d. 372, 376 (1974)
[9] http://www.fas.org/sgp/crs/natsec/R42659.pdf

Friday, March 15, 2013

Defining Inherently Governmental Functions in the Era of Big Data

The sheer amount of data and knowledge available today is beyond the ability to comprehend.  Individuals and organizations who are able to take data sets and infer patterns, predictions and conclusions will add much value to efficiency in commerce, prudence in collective action, and enriching our lives as individuals. The U.S. Government has long relied on contracted vendors to conduct studies and analysis to support its decision-making.  This article will focus on the government, and keeping control of its prerogatives as it inevitably outsources a lot of data analysis to vendors.

"Inherently governmental functions" is a term of art describing decisions and actions that must be done by sworn government workers.  This is based in public law[1], the Federal Acquisition Regulations[2], and Executive Orders[3]. The government embeds contractor employees at its sites and as well as working offsite to do a lot of its work.  However decisions like awarding contracts, pressing criminal charges, directing combat forces, voting on legislation, or investing the government's money cannot be outsourced while maintaining the integrity and credibility of the government.

The amount of data and statistics will add a great tool to give insights into public health, crime stoppage, education, and virtually any other governmental function imaginable.  However, Big Data will require a labor force of statisticians, analysts, and subject matter experts that the government does not readily have.  As the saying goes, "knowledge is power" and the government contractors working on data analytics will have their own power base given the tremendous knowledge they will gain.  A vendor that secures some long term contracts will gain expertise in analytics as well as the subject matter they were contracted to study.  This will increase the value of their business, the goal of every business.

This is where the law must come in.  A tension can develop between a vendor seeking to gain as much knowledge as possible, and protecting the privacy of the American people. In a healthy, well functioning contract, a vendor is doing well financially by helping the government achieve its public mission. As vendors are motivated by sales, public officials are motivated to achieve their goals.  As data analysis pervades more and more executive agencies, public officials will have to have legal rules to force them to rein in vendors, we well as their own employees from collecting too much information.    Simple rules can include requiring contractors to wipe all data from their computers' memory, as well as non-disclosure agreements for contractor employees.

Big Data worries are not just about substance, they are about process.  Certain information is available through free online search engines.  Even more is available through expensive databases.  The government, supplemented by embedded private contractors, also has tremendous technical investigative tools and power of legal discovery to access data.  Classic Fourth Amendment (Criminal Procedure) prinicples will inform how domestic government agencies collect, analyze and store data.  Using data "in a manner which will conserve public interests as well as the interests and rights of individual citizens[4] will continually be redefined as search and storage capacity grow geometrically.  America requires a legal regime dynamic enough to keep up with the changing frames of “subjective expectations of privacy”[5] and the temptation for government and vendors to use this information for public goals.


[1] FAIR Act Public Law 105-270
[2] Federal Acquisition Regulations Section 7.500
[3] Publication of the Office of Federal Procurement Policy (OFPP) Policy Letter 11-01, Performance of Inherently Governmental and Critical Functions
[4] Carroll v. U.S.  267 US 132, 149 (1925)
[5] Kyllo v U.S.  533 U.S. 27, 33 (2001)

Wednesday, February 20, 2013

Federalism Issues with Cyber Security



Incidents of American government IT networks being illegally accessed are increasing in sophistication and tempo.  These software intrusions come from foreign states, as well as foreign and domestic non-state actors.  They range from pranks to malicious efforts to shut down databases, software, hardware, and equipment.  This article is aimed at discussing some constitutional issues arising from a catastrophic incident against a state government that necessitates federal protection of their IT systems.

The main threat is from online worms that could steal data (e.g. a list of a police department's undercover officers), destroy data (e.g. the property tax transactions), or control infrastructure like the controls for an aqueduct.  In the immediate aftermath of a big cyber event on a state government, it may seem intuitive to have the federal Department of Defense of Homeland Security put up a virtual firewall and set compliance procedures.  But that would bring a whole host of questions about federal power and potentially civil-military relations.

In the fall of 2012, the state of South Carolina had a major hacking occurrence with over 3 million citizens having their (federal) Social Security Numbers stolen, as well as tax information for several businesses.[1]  It was the U.S. Secret Service that informed the state government of this.  It took the state government several days to secure its network and even more days to disclose this to the public.[2]  In this case, a private company was contracted to survey the damage and recommend remedial steps, but an attack from a foreign government on several states at once may require a federal government response.[3]

The courts have always maintained the federal government's plenary authority to coordinate defense of the country.  There are also constitutional designs articulated in cases such as New York v United States (1992)[4] and Printz v United States (1997)[5] that elucidate the notion that states are sovereign and must be allowed to function independently in a federal system.  That is a check against political tyranny by the federal government.[6] So how does cyberspace fit in?

"Traditional and non-traditional" government functions have we're debated for a centuries in determining where federal regulation reached its limits. While in 1985, the Supreme Court declared that "traditional and non-traditional" functions was impossible to delineate[7], the following decades of jurisprudence have narrowed the federal government's authority in general.  The Internet, and its pervasiveness and mobility, has transformed our way of life, our economy, and thus, how we govern ourselves.  We can pay for municipal parking tickets on our cell phone, take classes at a state university online, and we can have a federal court subpoena our documents stored in "the cloud." 

New York v U.S. and Printz v U.S. stand for the notion that the federal government cannot mandate that the states follow a federal policy scheme, nor can the federal government commandeer state workers and resources to follow federal processes.  As more state government functions are processed through information technology, and more interaction between states and the public is virtual, a federal regulation of a state's IT systems would be a major constitutional quagmire.

According to cyber security experts, the weakest link in protecting IT systems from hackers is the human element.  Therefore federal regulations regarding how state workers answer email and plug in thumb drives into their home computers could take effect.  Regulations punishing a state worker for a security lapse could very well be required.  Who would administer that is very unclear.  Needless to say, any government functions blending federal and state networks like law enforcement, Medicaid, or public health administration could be impeded if a state did not secure its network.

Given its vast IT resources, the Department of Defense (DoD) is the lead agency protecting the federal government, as opposed to the Department of Homeland Security (DHS).  This raises popular concerns about involving the military in the management of not only federal civilian agencies, but state and local agencies.  The law in fairly clear, as argued in a U.S. Department of Justice memo[8], that there is no law against DoD civilians enforcing the law, or regulations.  Laws such as the Posse Comitatus Act[9] prohibit members of the armed forces from law enforcement and regulating civilians, but non civil servants in the DoD.

During the midst of a massive, debilitating hacking, there could be no choice but for the president to find that state civil resources have been overwhelmed and invoke the Insurrection Act[10] to allow troops to take temporary control of state IT infrastructure.  This is not the notion of army troops on trucks with fixed bayonets driving down Main Street.  It is more likely a bunch of young soldiers in massive computer labs working with state officials to restore their databases, computer systems and websites.

Legal processes would be easiest if a state asked the federal government for help.  Issues of commandeering a state could be written into a contract.  The main problem concerns the protocol for identifying that a major incident is underway, and whether the president decides he or she must act in the national interest to protect state governments.  The incident in South Carolina for example took place with cumulative software intrusions over months[11].

There are a host of issues not analyzed in the article including contract monitoring of state government vendors' cyber security, private companies controlling critical infrastructure, how states collect digitized data, and the criminal investigatory methods states use to deter and investigate hackers.

I hope to have provoked some ideas for the constructional concerns that would come with the federal government protecting a state online. 

Monday, November 29, 2010

Entrepreneurs, Welcome to the Law, Part 4

This fourth part is on the boring, yet crucial ongoing topics of accounting and employment law.

Accounting
It is the language of capitalism and commerce. A balance sheet is a snap shot of your company’s finances. No investor will take you seriously without good accounting paperwork.
An Income Statement is an annual or monthly recording of revenues and expenditures. A cash flow statement is like an EKG of how the money is circulating. Cash flow is the most important metric you have to monitor.

Accounting allows you to do analyses on which operations are profitable and which are not.

Employment Law
This is a minefield that you and your management need to understand.

With interview questions, do NOT ask:
Race- What are you, Filipino, Hispanic?
National Origin- What kind of name is that?
Family- Do you have kids? Are you pregnant?
Age- When did you graduate from Central High?
Mere brush with the law- Have you been arrested (not convicted)

Sexual Harassment: You can be sued under two theories
Hostile work environment- Jokes, pin-up calendars, whistling
Quid Pro Quo- If you do sexual favors for the boss, your work life improves.
Brief EVERYONE upon joining, and continue. Set up a procedure.

Job descriptions must be exacting as to qualifications and have no hint of any prejudice. For example, don’t say “Computer Literate, say “Proficient with Microsoft Word, Excel, QuickBooks.” For example, avoid saying “no more than 20 years in Grade” that is age discrimination.

Every 3-6 months have a formal, consistent, regularized counseling.

With trouble makers, first give them a verbal warning and document the incident. If it happens again, have a written form where you explain what happened, and what the expectations are. If it happens again, you might want to consult an attorney but there is now a paper trail.

Make sure any termination is strictly job related and not based on any
personal animosity or prejudice.

The status of workers is very important. W-2 Employees work for you under your control. A whole host of laws and taxes need to be adhered to. 10-99 Independent Contractors have a horizontal business relationship with you. Basically If the company controls the time & manner of the work as well as provides the resources, the law says that is a W-2 worker even if a contract says “1099.”

Entrepreneurs, Welcome to the Law, Part 3

Part 3 is about contracts and how parties litigate over points. Basically, the better the contract you negotiate ahead of time, the stronger your litigation position will be.

Contracts
Any contract can be written from scratch, and any contract handed to you is written to benefit the writer. These are the basics of any contract.
*Keep negotiating until you get each of these.

- Define the duties and standards of performance. In other words, explicitly write down every thing each side has to do. Not only what to do, but how well it needs to be done.
- Define ambiguities, terms, and foreseeable issues. Every business has jargon, special terms, and technical terms. Everything should be clear to both sides. If there is an issue that could come up, define it and the contingency plans. This is what makes contracts so wordy.
- Define the context, inherent risk, and the assumptions of the contract. Risky businesses need a lot of assumptions and calculations. Make sure that both sides understand the nature of the business and how risky it is.
- Clearly set out the pricing structure. Spell out how much money is due, and when it is due.
- Define control and property rights. This is the proverbial baby in the bathwater. This is the cash cow. My be it is a house, the right to live in a house, the right to make money off of a book, or any other set of rights. In addition to the right to money, define the right to have final authority over the property.
- Write duration and termination clauses. When and how either of you can get out of this arrangement must be understood.
- Set forth the process to resolve controversies. A contract or lease is a legal document, meaning it can be enforced in court. You must have a plan for arbitration and litigation. An important part is whether it will be decided in your state, or elsewhere.
-Make sure each party acknowledges in writing that they understand the seven points above.



Primer on Litigation
Documented evidence is the key to all legal disputes. About 95% of all civil lawsuits are settled, and about 95% of all criminal charges are plea bargained. Hardly anything goes to trial. In the settlement negotiations, the side with the most documented evidence has the most leverage.

The practice of law however is geared toward trials. Trials are about proving the elements of various laws. A good example of lawyerly thinking is watching the instant replay of a close call in football. You must show the ball in possession with both feet in bounds. Those are two elements that must be proven, with a receiver being pushed out of bounds an exception. Documented evidence and witness statements are all about proving an element at trial. In a press release, do not admit to an element of a cause of action (law being sued about).

Common lawsuits for a businessperson are “Slip ‘n Falls” torts, wrongful termination, breach of contract, and false imprisonment.

The Media
Reporters are storytellers. They are using you for a controversial story and you are using them for free publicity. There is no such thing as off the record, so make sure everything you say is designed to promote your company’s message.

Entrepreneurs, Welcome to the Law, Part 2

Part 2 deals with the burgeoning areas of intellectual property law and social media law.

Intellectual Property
This is a biggie, it is about your legal right to make a profit. “Property” does not mean owning a house. It means the right to use and make money off of something. If your business involves creation or invention, it is intellectual property is fundamental to your business model.
Patents are for technical and scientific designs. Also included are new business processes. You are basically saying to the rest of the business community, that they cannot use this design without your permission, and your permission will cost them money.
Copyrights are for literary and artistic creations, in addition to software code. They last for the life of the author plus 70 years. Once I type something, like a blog post, I own a copyright in how these ideas are expressed. I can best protect my legal and business interests by filing for a copyright. I do not own the ideas or the facts, just how I articulate them.
Trademarks and trade names are about brands. The more unique sounding them name, the stronger legal protection you have, that is why medicines have such weird sounding names. Ironically, having a business name that is good for search engine optimization is bad for having a unique trade name.

*The least an entrepreneur needs to know: intellectual property belongs to the entity that paid for the work to be created or invented.
So if you are in the technology business, you need to merge product development and accounting. Technical documents, lab reports, designs and the like should be coded with the source of the money that paid for that labor. That way you can document what you have done on your own without investors, government, or other business partners. That will give you a stronger hand in controlling your company and the revenues from your products.


Social Media
Social media is by its nature, immediate and informal. But it is in writing and very public. Browsing and posting can very easily violate: employment law, securities law, defamation law, intellectual property law, criminal law, consumer protection law, and tort law. Whoever in the company is authorized to post about the company must be trained.

1. Thou shall not plant false testimonials about your products and services. Any promoting of a product on a blog must include some indication that the blogger was paid by the company.
2. Thou shall not mislead consumers as to the qualities and prices of the products and services you sell; evidence shall set you free. Just like in regular advertising.
3. Thou shall not release information designed to harm a market. Whether you post a false rumor about your company that hurts financial speculation, or causes confusion about consumers, you could get into big trouble by lying online.
4. Licensed professionals shall not give advice that is individual in nature. For example, as a lawyer, I am giving very general advice, not specific to any person.
5. Thou shall not engage in illegal promotion schemes, and take care to adhere in interstate and international laws. Watch out for sweepstakes and raffles and the like.
6. Thou shall not mislead investors and shareholders as to internal and external risks to your company. I cannot stress this enough. If a tweet from your company is inconsistent with anything in the prospectus given to investors, you are asking for a lawsuit.
7.Thou shall not publicize any sale of equity or control of the company. Again, writing publicly about equity, shares, or revenue sharing is technically violating securities laws.
8. Thou shall not release trade secrets. Self explanatory.
9. Thou shall not post the copyrighted, trademarked, or patented material of another.
10. Thou shall not defame. Note, that if you as a business person participate in a discussion or controversy online, you may be losing your “private person” status making it harder for you to sue someone for libel.

*Basically educate your management and employees about law and online social media. Remember the speed with which online posting can be spread...and taken out of context.

Entrepreneurs, Welcome to the Law, Part 1

As a business attorney, I advise entrepreneurs on how to start businesses. It occurred to me that all business owners need to know the scope of how the law applies to business. This blog post will not teach you the law, it will only clue you in to the types of issues that require an attorney’s advice.

Part 1
Part 1 is about the legal duties and legal relationships you have with others.
If you take out a dollar bill, you will notice on the left side the words “This note is legal tender.” What that means is that when one of those pieces of paper changes hands, the arm of the law applies.
Going into business, you now have a whole bundle of new obligations. Here is a quick overview:

Big Picture
First, figure out your business’ main line activity. It should be aligned with your personal values and your talents. You are offering a good or service that a market (a pool of money) is willing to pay money for.
Next design an organization and contractual alliance that you need to sell your good or service.
Lastly, pick the right legal structure for your organization. Make sure that your personal will, marital agreements, and insurance is aligned with your business relationships.

Financing your business
There are two types of financing. Both have implications for taxes, corporate governance, and intellectual property.
With debt financing, you are getting loans or selling bonds. You still own the company and your payments are regular and predictable. The lender wants a track record to know that they will be paid back.
With equity financing, you are selling a slice of the company for needed capital.

Legal duties of the Other Players
Your Board and Officers- Assuming you are incorporated, these people have a legal duty to be loyal to the company and treat it as if they owned it. This goes for nonprofits.

Investors- They may insist on becoming board members. Nevertheless, know that soliciting investment must be from someone accredited, basically wealthy. So do not ever ask friends of ordinary means to invest in your company. It is technically illegal to even talk about raising money unless it is a serious, private conversation with an accredited investor. Talk to a securities lawyer about starting a business with someone who is unqualified as an accredited investor, as opposed to asking for money later. The law is murky.
All conversations and prospectuses with investors should be done very carefully with guidance from a lawyer.

Employees-Adhere to employments laws discussed below.

Regulators- Make sure you have a good document retention policy. Management needs to make sure your business is operated in a legal way.

Opposing Counsel- Everyone in the company should know not to speak to a lawyer suing the company.

Media/blogosphere- Everyone in the company should know not to talk to reporters and to report any internet rumors to the PR person. Social media has its own discussion below.

Marketing, Your Duties to Consumers
Do not mislead consumers and be able to back up all claims. Do not lie or stretch the truth in writing. It is easy to slip up on a social media site.

Duty to Customers and the public
Have you ever noticed in a grocery store whenever someone spills juice on the floor, the workers immediately clean it up? They know that by opening their doors to commerce, they have a duty to keep their place of business safe. This they are liable for a slip and fall.
The same duty extends to the goods you sell. If you are a deli, and the bread you sold to a customer came from the wholesaler with poison, you are liable being in the stream of commerce.
Lastly, if your business involves a dangerous activity, you owe a duty to follow regulations and to be safe.