Enjoining Damaging Web Posts by Former Employees Comes at a Steep Price

Our last blog entry discussed the First Amendment shield that covers current and former employees who use anonymous or pseudonymous Internet postings to trash their employers. Today’s cautionary tale highlights the practical challenges employers face in court even when a current or former employee posts confidential records on the Web in violation of confidentiality agreements and laws.

Bank Julius Baer & Co., a Cayman Island subsidiary of a Swiss bank, fired a disgruntled vice president. On her way out, she took confidential documents she believed show that her former employer engaged in unlawful conduct. The next day, she posted those documents on a public website devoted to leaking confidential documents.

Instead of pursuing the disgruntled vice president, the Bank filed a lawsuit seeking to enjoin the leaking website, Wikileaks.org, and its domain name registrar, Dynadot. The Wikileaks website enables users to anonymously publish submissions, including alleged confidential corporate and government documents. The site aims to be an “untraceable version of Wikipedia for untraceable mass document leaking and analysis.” The site runs on modified MediaWiki software, similar to the software that runs Wikipedia.

Dynadot, a small company not interested in a protracted legal battle, stipulated to a permanent injunction that required it to shut down the website instead of fighting the Bank. Judge Jeffrey White of the federal district court in San Francisco signed the stipulated permanent injunction. The Bank dismissed its lawsuit against Dynadot with prejudice, and Dynadot shut down the website. The Bank appeared to have silenced its disgruntled vice-president, quickly, quietly and at minimal cost.

But the next day, Wikileaks was up and running through multiple mirror sites. Mirror sites use a similar domain name that is registered through a different domain name registrar. Wikileaks, for example, also used the domain name Wikileaks.cx through a domain registrar in the Christmas Islands. Wikileaks posted the Bank’s confidential documents on these mirror sites. 

Within the week, the New York Times, while neglecting to mention the agreement between the Bank and Dynadot, reported that Judge White’s approval of the stipulated permanent injunction “present[ed] a major test of First Amendment rights.” Also failing to mention the agreement between the parties, blogs buzzed about apparent constitutional violations. 

Not long after publication of the Times article, heavy hitters such as the ACLU, Project on Government Oversight, and the Electronic Frontier Foundation, came out with statements against the Bank. In response to their court papers, Judge White abnegated the agreement the Bank had negotiated with Dynadot, dissolved the permanent injunction, denied the Bank's request for a restraining order, noted the injunction may involve impermissible prior restraints, pondered whether an injunction would serve any purpose and questioned whether the Court had subject matter jurisdiction to hear the dispute. In the meantime, the Wikileaks site, complete with the Bank's stolen documents, is still up and running. On March 5, 2008, the Bank voluntarily dismissed its lawsuit, apparently concluding that litigation was no longer worth the cost.

Employers should view the Bank’s experience as a cautionary tale. What started as a quick agreement and apparent resolution literally, as the saying goes, ended up on the front page of the New York Times. The case also shows how quickly journalists will publicize a story that can be portrayed as “an attack on the First Amendment.” Sometimes filing suit is not the best way for an employer to protect its interest.

Is Confidential Business Information Safe At 30,000 Feet?

It will soon be easier to conduct business on airline flights, and a lot riskier from a privacy perspective.  The New York Times ran a story the other day – “Some Airlines to Offer In-Flight Internet Service” – describing Jet Blue’s plans to begin offering free in-flight e-mail and instant messaging service.  Several other airlines also have announced plans to offer Internet service on their planes.  While the convenience may be welcome news to busy executives who criss-cross the country on non-stop business trips, employers should be concerned about the security of private workplace communications and confidential business information in the cramped confines of an airline cabin.  

Consider the number and proximity of work-related travelers —especially in business class.  Now imagine linking the traveler’s laptop or Blackberry to seat-back entertainment systems (Virgin America has plans to implement a system that allows passengers to send messages during a flight).  And now envision your company’s strategic business plan, or non-public profit figures, on display, like an in-flight movie.  Add to this the passenger’s oblivion to his surroundings and the scrutiny of other bored and seemingly harmless passengers.  Without determined efforts, inadvertent in-flight disclosure of confidential business information could become as commonplace as data breaches caused by stolen laptops.

Internet and email communications are not the only high altitude privacy hazards.  A colleague of mine recalls sitting on the tarmac during a flight delay and listening as a nearby passenger discussed very sensitive business information over a cell phone.  Although the passenger did not identify his high-profile company by name, the content of the call made the identity easy to guess.  This passenger might as well have been broadcasting his company’s non-public, business tactics over the airplane’s intercom. At the end of the flight, my colleague turned to the blabbermouth and said, “If I were your boss, I’d fire you, and if I were a shareholder in your company, I’d sell your stock.”

Before business executives start using on-board Internet access to conduct business, employers should examine the risks that this latest wave of technological conveniences creates.  Bear in mind that the risks will include not just the possible inadvertent disclosure of confidential business information but also, for example, the possible continued storage of that information on the airline’s e-mail servers and the possible increased risk of interception during transmission.  Once the service and the attendant risks are better understood, employers can modify existing electronic resources policies, or prepare new policies, to address the most recent risk to privacy in the wired business world.