DISCLAIMER: This communication, along with any documents, files or attachments, is intended only for the use of the addressee and may contain legally privileged and confidential information. If you are not the intended recipient, you are hereby notified that any dissemination, distribution or copying of any information contained in or attached to this communication is strictly prohibited. If you have received this message in error, please notify the sender immediately and destroy the original communication and its attachments without reading, printing or saving in any manner. This communication does not form any contractual obligation on behalf of the sender or Wildman, Harrold, Allen & Dixon LLP. Unless expressly stated otherwise, any tax advice in this message is not intended or written to be used, and cannot be used by a taxpayer, for the purpose of avoiding penalties that may be imposed on the taxpayer. Please consult your tax attorney regarding the form of tax advice that may be relied upon to avoid penalties under the Internal Revenue Code.
Let's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).
She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.
Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.
Do we use the same dialin-number
as the Thursday calls?
Thanks.
/thomas/
Hello,
Line C which is your normal line is open at that time so you can feel free to use it:
Teleconference Info:
- Skype: +9900827042954214
- North American Dial-In: +1-201-793-9022
- Room Code: 2954214
I put the call with dial-in in the UMA calendar. If anything changes the calendar should be updated to reflect.
thx
UMA LEGAL CALL INVITATIONFor all of you interested in legal considerations of UMA you are invited to join a call on this topic. I have added additional call times in the Doodle to help schedule this call.As, Eve has so nicely painted a picture with the scenarios from the UMA 'Regarding Legal Considerations in UMA Authorisation'I suggest we move right on. I have scanned this email thread for legal consideration to start with and am using this list to create a draft agenda. Please suggest items or edits at will.
Draft Agenda1. addressing the liability and penalties - Jeff
2. The ability to uniquely specify new terms and conditions - Jeff3. additional parties beyond the six specified in the OITF document - Jeff4. I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.- TomSuggestion: - we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis. - EVEBest Regards,- Mark
Let's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).
She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.
Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.
To this picture, UMA adds the possibility of a new kind of web-based application: a kind of "traffic cop" for overseeing all these instances of travel itinerary sharing, which will help Alice manage her digital footprint. We'll call this site CopMonkey.com.
Attending: Mark Lizar, Tom Smedinghoff, Jeff Stollman, Eve Maler, Louis Monvoison
On 3 May 2010, at 8:27 AM, Mark Lizar wrote:
UMA LEGAL CALL INVITATIONFor all of you interested in legal considerations of UMA you are invited to join a call on this topic. I have added additional call times in the Doodle to help schedule this call.As, Eve has so nicely painted a picture with the scenarios from the UMA 'Regarding Legal Considerations in UMA Authorisation'I suggest we move right on. I have scanned this email thread for legal consideration to start with and am using this list to create a draft agenda. Please suggest items or edits at will.
Agenda-bashing:
Draft Agenda1. addressing the liability and penalties - Jeff
Let's add enforcement as a related issue to #1.
2. The ability to uniquely specify new terms and conditions - Jeff3. additional parties beyond the six specified in the OITF document - Jeff4. I would also add a fourth -- which is the fact that not all legal concerns can be addressed by contract.- TomSuggestion: - we find that we can point to OITF or a similar meta-framework as a constraint on the terms that can be agreed to, that may flow nicely into the forthcoming additional analysis. - EVEBest Regards,- MarkLet's imagine a web user, Alice Adams, who doesn't mind sharing her personal travel information with the right sources as long as the process of sharing is convenient (e.g., no requirements to alert authorized recipients every time a new trip gets booked); her expectations for the uses of that information are met (e.g., she's not worried about recipients divulging to the whole world that her house is going to be empty); and she feels "in control" of what's allowed and not allowed (e.g., she can get an at-a-glance view of who's seeing what).
She uses a website called TravelIt.com (think TripIt) to store all of her travel itineraries. Since it's the nature of travel information to change frequently, she wants to be sure that her good friend Bob Baker always has the latest version so he can pick her up from the airport on time and make sure her cat is fed while she's away; he likes to use Schedewl.com (think Google Calendar) for subscribing to TravelIt. She would also like her social travel site Airplanr.com (think Dopplr) to pick up her itineraries automatically and make them available to friends who are on that system.
Because Alice is a frequent and seasoned traveler, she's interested in entertaining discount offers from travelogue company FrodoReviews.com (think Frommer's) for making her itineraries available to them for survey purposes.
To this picture, UMA adds the possibility of a new kind of web-based application: a kind of "traffic cop" for overseeing all these instances of travel itinerary sharing, which will help Alice manage her digital footprint. We'll call this site CopMonkey.com.
Liability: Tom observes that, according to some work taking place in the ABA currently, there's a lot of concern about "What happens if something goes wrong or something bad happens?" But under what legal theory does liability get assigned? -- liability "for what"? E.g., the party being sued may have the ability to limit liability or not. Liability in the abstract isn't a very helpful concept. There are contract, tort, negligence, etc. theories.This isn't probably the first thing to settle; rather, we could discuss "What could go wrong?" and go from there. Eve suggests validating a scenario, describing its "success conditions" (as if it were a software user story/use case), and then describing its "error conditions". She walked through the three proposed sharing scenarios in the Legal Cons doc. The three are:- Alice->Bob through TravelIt/CopMonkey/Schedewl- Alice->Airplanr (on her own behalf) through TravelIt/CopMonkey- Alice->FrodoReviews (on its own behalf) through TravelIt/CopMonkeyHere are some possible error conditions:- Alice's calendar being shared to the world (or at least a wider circle), not just Bob- Alice's calendar being misrepresented as being someone else's calendar- Alice's calendar being unavailable on the promised schedule, despite FrodoReviews having already given her some consideration for itIn fact, each of the seven entities involved in this set of scenarios could be exposed to liability by making something go wrong.Most Terms of Service disclaim liability for pretty much anything, though there are a few legal limits on how much they can do this (the amount of harm is one factor that gets considered). If all these services have TOS's that disclaim all liability, how can the Alices and Bobs in the world deal with this? And what liability should they "ideally" have, even if they want to disclaim it?Louis suggests that we should focus on ways in which UMA wants to provide unique value, and see if we can identify key ways we can extend confidence to the user that this value can be provided. Eve identifies the main value-add as allowing the authorizing user to extract promises from the requesting party (this is under NDA, this is under embargo until X date, you have to adhere to DataPortability.org best practices, you have to be over 18 to see this photo...). A consequence of the UMA architecture in its most Internet-scale form, though not truly a unique value-add in the sense that it's why we're building UMA, is that the host must come to trust the user's chosen AM.Eve's hope is that UMA can help users to hold out an incentive (fresh data access) to requesting parties to "ratchet up" their terms of service, so that in addition to prevailing law and their own existing generic TOS's, they might agree to pairwise terms that meet the user's requirements.When you add the international dimension, enforcement could get *really* complicated. Can we work on a simple U.S.-only case for starters, to see what we flesh out? International treaties or conventions would have to recognize agreements and consider enforcement mechanisms.So let's take the very simple case of demanding that a requesting party (let's say this is for the Alice->Airplanr scenario through TravelIt/CopMonkey) support data portability, such that any data they end up storing about you they must offer to export on your request. We assume, to begin with, that the desired policies are boilerplated and well known, and their semantics can be conveyed in an entirely machine-readable manner. Examples of such policies are Creative Commons (webby, lightweight) and IncoTerms (used in international trade).Things that could go wrong:- Alice could forget to configure the policies that constrain Airplanr- CopMonkey could incorrectly issue an access token without correctly requesting/requiring the promise from Airplanr- CopMonkey could fail to secure its audit logs that show the promise and that Airplanr made it for this particular kind of access- TravelIt could incorrectly give access even though Airplanr didn't present a properly formed token- TravelIt could give the wrong kind of access that doesn't match the access granted (e.g., as listed above)- Even if everything else was done correctly, Airplanr could be total losers and not make Alice's data on their site available or wipe her account as required by DP.org practice
[Eve had to drop at this point; hopefully other folks will capture other juicy discussions...]
Regarding Next Monday's Call Time:As I didn't realise next Monday is a holiday I propose that we move the next UMA Legal Subteam Cal from Monday May 31l to June 7. If this is not a good time please message me and I will setup a new doodle poll. With no objections received we can assume that all can make the call on June 7th at 7pm UK time.In addition, I am cc'ing this to other interested lawyers who may want to participate.Best Regards,Mark
I have been on the UMA conference bridge for the last 10 minutes no one has showed.On 7 Jun 2010, at 19:05, Smedinghoff, Tom wrote:Is there a call today? Or do I have the time wrong?
Thomas J. Smedinghoff
Wildman Harrold
225 W. Wacker Drive
Chicago, Illinois 60606
Phone: +1 312-201-2021
Fax: +1 312-416-4773
smedi...@wildman.com
www.wildman.com/smedinghoff
From: wg-uma-...@kantarainitiative.org [mailto:wg-uma-...@kantarainitiative.org] On Behalf Of Eve Maler
Sent: Sunday, May 30, 2010 9:06 AM
To: Mark Lizar
Cc: wg-uma UMA; Aaron Titus; Scott David; Louis Monvoisin; Juan Avellan
Subject: Re: [WG-UMA] Updated: Notes from 10 May 2010 legal subteam call
Looks OK to me right now.
-Aaron Titus
Information Privacy Director
Liberty Coalition
http://www.nationalidwatch.org
http://wiki.privacycommons.org
http://www.libertycoalition.net
Twitter: @aarontitus
Agenda-bashing:
Issues raised for next Agenda- Enforcement- Automation levels and the need for user/ host/AM/requester action- Terms of Service Negotiation- Unique User Imposed Conditions (advanced UMA)- Liability- Policy Recommendations for the use of UMA. (where the law may be lacking and UMA can 'bridge a gap;)