cybersecurity

Is your organization equipped with the right cybersecurity policies?

Introduction

Cyberattacks no longer target IT systems alone: they also reach intellectual property assets, trade secrets, customer files and trademark databases. Facing this growing threat, French and European lawmakers have built, over recent years, a demanding framework: the GDPR, the NIS2 Directive, and the recommendations issued by the CNIL and ANSSI. Yet many companies still do not know whether these obligations apply to them, and above all what they must concretely put in place. This article reviews the cybersecurity policies to adopt, the measures authorities expect, and the reporting deadlines that apply in the event of an incident.

A legal framework that depends on the company's status

The intensity of cybersecurity obligations depends primarily on the status of the organization concerned. French law broadly distinguishes between two categories of actors.

Entities of essential importance

Certain organizations engaged in critical activities are subject to enhanced cybersecurity requirements.

  • Operators of vital importance are designated from among those entities whose unavailability or destruction could seriously affect the nation’s security, economy, defense, or the lives of its citizens.
  • Essential service operators, on the other hand, are identified when an incident affecting their networks or information systems could seriously disrupt the provision of a service essential to the functioning of society or the economy.

These operators must, in particular, implement measures related to security governance, the protection of systems and access, the detection and handling of incidents, as well as business continuity and crisis management. They may also be subject to specific obligations to report incidents to ANSSI.

Data controllers and processors

For any organisation, public or private, that processes personal data, article 32 of the GDPR requires the pseudonymisation and encryption of personal data, the ability to ensure the ongoing confidentiality, integrity and availability of processing systems, the ability to restore access to data in the event of a technical incident, and a process for regularly testing and evaluating security measures. These same requirements are echoed and detailed by the CNIL.

Summary table of obligations by company status

Company status Reporting authority Deadline Reference text
Operator of vital importance (OIV) ANSSI Without delay / per sector-specific order Defence Code, article L1332-7
Operator of essential services (OES) ANSSI Without delay NIS Directive, French transposition
Data controller / processor CNIL 72 hours maximum, where feasible GDPR, articles 33 and 34
Essential and important entities (upcoming) ANSSI 24 hours (early warning) then 72 hours Directive (EU) 2022/2555 (NIS2)

The security measures authorities expect from companies

The CNIL and the ANSSI have published practical guidance. The reported incidents show that effective protection depends as much on the implementation of appropriate technical measures as it does on internal organization and staff awareness.

The essential baseline

  • keep software and systems up to date in order to promptly address known vulnerabilities;
  • require strong and unique credentials for each user account;
  • strengthen the security of professional email accounts;
  • regularly raise employees’ awareness of the main cybersecurity risks and fraud attempts;
  • implement frequent backups, ensuring that at least one copy is kept isolated from systems accessible online.

Advanced protective measures

  • implement multi-factor authentication for sensitive access, particularly remote access;
  • assign individual accounts to employees, partners, and service providers in order to avoid credential sharing;
  • restrict network access to devices that have been previously authorized or authenticated;
  • deploy monitoring mechanisms to quickly detect unusual behavior or connections.

Documenting every incident: an obligation too often overlooked

The GDPR requires data controllers to keep a record of every data breach, its effects and the remedial measures taken (articles 33(5) and 34). This record allows supervisory authorities to verify compliance in the event of an audit. Processors, for their part, must assist the controller and keep appropriate internal documentation. The law does not set a precise retention period: in practice, the record should be kept for as long as the legal risk exists.

Reporting a breach or incident: to whom, and within what deadlines?

To the CNIL, for personal data

Three types of incidents must be reported: a confidentiality breach (unauthorised disclosure of or access to data), an availability breach (loss or destruction of data), and an integrity breach (unauthorised alteration of data). Notification must occur within 72 hours of the company becoming aware of the breach, where feasible, via the CNIL's online notification service.

To ANSSI, for entities of essential importance

Operators of vital importance must report any incident affecting their vital information systems, following the procedures set out in the relevant sector-specific order (OIV incident reporting form).

Operators of essential services must, in turn, report any incident likely to have a significant impact on the continuity of their services (OES incident reporting form).

Shorter deadlines ahead under the NIS2 Directive

Directive (EU) 2022/2555, known as NIS2, not yet transposed into French law at the time of writing, requires essential and important entities to submit an initial notification, known as an 'early warning', without undue delay and within 24 hours of becoming aware of a significant incident, followed by a full notification within 72 hours. These timelines may be further specified by the national implementing measures.

Checklist: the first 5 actions in the event of an incident

  • Qualify the incident: does it affect confidentiality, availability or integrity of the data?
  • Identify whether the company is a controller, a processor, an OIV or an OES.
  • Start the clock: 24 hours (NIS2 early warning) or 72 hours (GDPR).
  • Document the facts, effects and remedial measures in a dedicated register.
  • Notify the competent authority using the appropriate form, then inform data subjects if the risk is high.

Informing data subjects and the public

Where a personal data breach is likely to result in a high risk to the rights and freedoms of individuals, the company must also inform the data subjects directly, unless the CNIL considers that appropriate measures have rendered the data unintelligible to any unauthorised third party. This communication may take several forms: direct messaging (email, SMS), a prominent website banner or notification, postal mail, or an announcement in the print media.

Conclusion

Putting the right cybersecurity policies in place is no longer optional: depending on its status, a company is subject to the GDPR, to reinforced sector-specific obligations, or soon to the NIS2 Directive. The essential measures remain within reach of any organisation, regardless of size. In the event of an incident, how quickly it is qualified and reported largely determines the scale of the legal and reputational consequences.

Dreyfus Law Firm assists its clients in managing complex intellectual property matters by providing tailored advice and comprehensive operational support to ensure the full protection of intellectual property rights.

Dreyfus Law Firm works in partnership with a global network of intellectual property attorneys.

Nathalie Dreyfus, with the assistance of the entire Dreyfus team.

Q&A

What happens if a company fails to report a breach on time?

It may face CNIL fines of up to €20 million or 4% of global annual turnover, in addition to potential compensation claims from affected individuals.

Do these obligations apply to small businesses too?

Yes. The size of a company does not exempt it from its obligations under the GDPR where it processes personal data. However, certain enhanced obligations depend on the nature of its activities, the types of processing carried out, or the status of the organization.

Is appointing a Data Protection Officer mandatory?

The appointment is mandatory for public authorities and bodies, for organizations whose core activities involve regular and systematic monitoring of individuals on a large scale, and for those that process sensitive data or data relating to criminal convictions and offences on a large scale.

Does the 72-hour deadline still apply if the incident occurs at a service provider or processor?

Yes, the processor must alert the controller without undue delay upon becoming aware of the incident, so the controller can still meet the CNIL notification deadline.

Does missing the 72-hour deadline automatically trigger a penalty?

No, the CNIL assesses the circumstances of each case; a justified and documented delay is treated differently from a complete failure to notify.

Should a company maintain an out-of-hours on-call rotation to meet these deadlines?

It is not an explicit legal requirement, but it is strongly advisable in practice, since regulatory deadlines run continuously, including weekends and public holidays.

This publication is intended for general public guidance and to highlight issues. It is not intended to apply to specific circumstances or to constitute legal advice.

Read More

Cybersecurity and intellectual property : protecting your digital assets against growing threats

In 2024, France’s National Cybersecurity Agency (ANSSI) handled 4,386 security events, a 15% increase over 2023, and confirmed 1,361 successful malicious attacks. Meanwhile, CNIL received 5,629 data breach notifications, up 20%. These figures reveal a reality that intellectual property rights holders can no longer ignore : cyber threats are directly targeting companies’ intangible assets.

Dreyfus a firm specializing in intellectual and industrial property, integrates cybersecurity into each of its advisory and support services. Nathalie Dreyfus, a court-appointed expert accredited by the French Supreme Court (Cour de cassation, Trademark specialty) and the Paris Court of Appeal (Trademarks and Designs specialty), brings this expertise to bear through a legal approach adapted to the realities of cyberspace.

This article analyzes the main cyber threats to intellectual property assets, the applicable legal framework, and concrete solutions to protect your trademarks and sensitive data.

  • Protection against phishing, trademark impersonation and trade secret theft
  • Compliance with regulatory obligations : NIS2, GDPR, AI Act
  • Defense against digital counterfeiting on marketplaces and social media
  • Anticipation of emerging threats related to generative AI and deepfakes
  • Comprehensive legal support, from prevention to litigation, by a court-appointed expert

Cyber threats targeting intellectual property

Phishing and  trademark identity theft

Phishing is one of the most widespread and damaging threats for trademark holders. Malicious actors register domain names imitating well-known trademarks to create fraudulent websites designed to collect personal or banking data. In 2025, WIPO recorded a historic high of 6,282 domain name disputes, a growing share of which involve phishing schemes. Domain name monitoring enables early detection and action before damage materializes.

Theft of trade secrets and sensitive data

Cyber intrusions frequently target confidential information related to intellectual property : formulas, manufacturing processes, patent filing strategies, and client databases. ANSSI documented 144 ransomware compromise cases in 2024, involving 39 different strains (LockBit 3.0, RansomHub, and Akira leading). Personal data protection and GDPR compliance are integral parts of any cybersecurity strategy.

Digital counterfeiting and marketplaces

Online commerce platforms facilitate the global distribution of counterfeit products. The 2025 joint EUIPO-OECD report estimates the global counterfeit trade at $467 billion, representing 2.3% of worldwide imports and up to 4.7% of European Union imports. The French cosmetics industry alone suffers €800 million in annual losses. Online trademark protection requires active monitoring and rapid content removal actions on these platforms.

Emerging threats : generative AI and deepfakes

The rise of generative artificial intelligence adds another layer of complexity. Deepfake technologies can reproduce logos, packaging, and visual identities with unprecedented realism, facilitating the creation of fake websites and advertisements. AI systems can also automatically generate thousands of domain name variations targeting a trademark , rendering manual monitoring entirely insufficient. According to ENISA, 35% of social engineering attacks in Europe now use AI-generated content to enhance their credibility.

The legal framework : bridging cybersecurity and IP law

Cybersecurity in the context of intellectual property relies on a rapidly evolving European regulatory framework. The NIS2 Directive, transposed into French law, strengthens corporate security obligations and broadens the scope of affected entities. GDPR governs personal data processing, while the AI Act introduces new requirements. Dreyfus  commands the full range of these regulations through its expertise in compliance.

In the blockchain and Web 3.0 space, new issues are emerging around the protection of decentralized digital assets. NFTs, smart contracts, and decentralized autonomous organizations (DAOs) raise unprecedented questions regarding ownership and counterfeiting. The firm has developed dedicated expertise in Web 3.0 asset protection, covering NFT law, blockchain, and related compliance.

An integrated approach : Dreyfus’ services

Facing the convergence of intellectual property and cybersecurity, Dreyfus deploys a cross-functional approach covering the entire lifecycle of intangible assets, from prevention to remediation.

Upstream, prior art searches verify sign availability before any filing, limiting the risk of future conflicts. Trademark and design filing and renewal are accompanied by a reflection on digital naming strategy and the protection of sensitive variants.

Active portfolio management involves continuous monitoring of domain names, trademark registries, and digital spaces (social media, app stores, marketplaces). When an infringement is detected, the firm implements the appropriate procedures : cease and desist letters, UDRP proceedings, host notifications, or legal actions.

For contentious situations, expertise in counterfeiting and unfair competition enables effective defense of corporate rights before the competent courts. The firm’s experience in conducting French trademark oppositions and European trademark oppositions complements this framework.

A strategic collaboration with business law attorneys

Cybersecurity and intellectual property issues sit at the crossroads of several legal specialties. Business law attorneys facing cases involving digital IP dimensions find in Dreyfus  a natural partner whose expertise complements their own.

Whether securing an M&A deal involving sensitive digital assets, assisting a client who is the victim of a cyberattack targeting their trademarks, structuring an international protection strategy, or assessing the impact of a data breach on an IP portfolio, Dreyfus ’ network of specialized attorneys offers a cooperation framework adapted to each situation.

The designation as a court-appointed expert recognized by the French Supreme Court and the Paris Court of Appeal gives the firm particular credibility in cases requiring technical expertise before the courts. This dual legitimacy—legal and technical—is a decisive advantage for business lawyers seeking solid support on digital IP matters.


Conclusion

The convergence between cybersecurity and intellectual property is no longer a trend,it is a daily reality. Companies that neglect this intersection expose themselves to financial losses, reputational damage, and increasingly severe regulatory penalties.

Dreyfus  provides an integrated response to these challenges, combining intellectual property legal expertise with mastery of cybersecurity issues. Contact us to secure your digital assets against current and future threats.


Q&A

What is the link between cybersecurity and intellectual property ?

Cybersecurity protects the digital infrastructure that hosts and exploits intellectual property assets. A security breach can lead to the theft of trade secrets, trademarkimpersonation, distribution of counterfeit products, or compromise of client data linked to licenses. The two disciplines are complementary and must be addressed together.

 What actions can be taken to combat domain name abuse and phishing targeting a trademark ?

The first step is domain name monitoring to detect fraudulent registrations. Rapid actions then follow : cease and desist letters, UDRP proceedings, reports to hosts and registrars. Implementing email authentication protocols (SPF, DKIM, DMARC) further strengthens protection by preventing domain spoofing for sending fraudulent emails.

Does the GDPR make it more difficult to identify the registrants of abusive domain names ?Yes. GDPR has significantly reduced access to domain name WHOIS data, making it more difficult to identify holders of abusive domain names. Specific mechanisms, such as RDAP (Registration Data Access Protocol) or disclosure procedures with registrars, nevertheless allow this information to be obtained in the context of defending intellectual property rights.

What does the NIS2 Directive require of French companies ?

The NIS2 Directive broadens the scope of entities subject to enhanced cybersecurity obligations. It notably requires  an early notification within 24 hours, the implementation of risk management measures, and executive liability. For companies holding critical IP assets, these obligations provide a structural framework that aligns with best practices in intellectual property protection.

Why should a business lawyer collaborate with an IP specialist on cyber issues ?

Cases involving cyberattacks on IP assets require dual expertise : business law for managing contractual risks, regulatory compliance, and corporate implications, and IP law for identifying, protecting, and defending rights. This collaboration ensures comprehensive treatment of each situation and avoids legal blind spots that could prove costly.

Read More

The French SREN Law: Safeguarding the Digital Space and Enhancing Cybersecurity

The digital landscape has undergone significant transformations, necessitating robust regulatory frameworks to ensure user safety and fair competition. In response, France enacted the SREN Law on May 21, 2024, aiming to secure and regulate the digital space. This legislation introduces measures to protect citizens, particularly minors, combat online fraud, and enhance digital sovereignty.

Protection of Minors

A primary focus of the SREN Law is safeguarding minors from harmful online content. It mandates stringent age verification mechanisms for platforms hosting adult content, ensuring that minors are effectively restricted from access. The law also empowers regulatory bodies to enforce compliance, with non-adherent platforms facing potential sanctions.

Combating Online Fraud

To address the surge in digital scams, the SREN Law introduces a cybersecurity “anti-scam” filter designed to protect users from fraudulent communications, such as phishing emails and deceptive SMS messages. This proactive measure aims to bolster user confidence in digital interactions by mitigating the risks associated with online fraud.

Enhancing Digital Sovereignty

The legislation seeks to reduce dependency on major cloud service providers by promoting interoperability and fair competition within the digital market. By prohibiting restrictive practices that hinder software interoperability, the SREN Law encourages a more competitive environment, fostering innovation and providing businesses with greater flexibility in their digital operations.

Implications for businesses and digital platforms

The enactment of the SREN Law imposes new compliance requirements on digital platforms and businesses operating within France. Entities must implement robust age verification systems, enhance cybersecurity measures to detect and prevent fraud, and ensure their services adhere to interoperability standards. Non-compliance may result in significant penalties, including fines and operational restrictions.

Conclusion

The SREN Law represents a pivotal advancement in France’s approach to digital regulation, emphasizing user protection, particularly for vulnerable populations, and promoting a secure and competitive digital ecosystem. Businesses and digital platforms are advised to thoroughly assess the law’s provisions and undertake necessary measures to ensure compliance, thereby contributing to a safer and more equitable digital environment.

Dreyfus Law Firm is partnered with a global network of lawyers specializing in Intellectual Property.

Join us on social media!

LinkedIn  

Instagram

Read More

Tesla and the EUIPO Halt Trade Mark “Trolling”

In a recent decision, the EUIPO Cancellation Division declared the European trade mark “TESLA,” held since 2022 by Capella Eood, invalid on the grounds of bad faith. This ruling marks a significant victory for car manufacturer Tesla in its fight against abusive trade mark practices, often referred to as “trade mark trolling.” Here, we examine the key aspects of this landmark case.

Background and Stakes of the Case

In 2022, Tesla filed for the cancellation of the trade mark “TESLA” registered with the EUIPO by Capella Eood, a company linked to an individual notorious for “trade mark trolling” practices. The cancellation request was based on Article 59(1)(b) of the EU Trade Mark Regulation (EUTMR), which allows invalidation of a trade mark filed in bad faith.

Tesla argued that Capella Eood engaged in speculative strategies to register trade marks with the aim of blocking other businesses’ operations and extorting financial settlements. Evidence presented included examples of shell companies, delays in opposition proceedings, and strategic transfers of trade mark rights.

For its part, the trade mark holder denied the accusations of bad faith, calling Tesla’s claims defamatory and asserting that the mark was inspired by independent and unrelated sources.

Criteria Analyzed by the EUIPO to Establish Bad Faith

Under Article 59(1)(b) EUTMR, bad faith is assessed based on the applicant’s intent at the time of filing, considering honest commercial practices. The EUIPO examined this intent using several key criteria, informed by cases such as Sky and Others (C-371/18) and Koton (C-104/18 P).

  1. Motives and Context of the Filing

The contested trade mark was filed shortly after Tesla achieved international recognition, particularly following the success of the Tesla Roadster. This timing indicated that the trade mark holder was aware of Tesla’s growing reputation. Claims that the mark was inspired by a newspaper article or a CD were deemed implausible, especially since the targeted products—vehicles and accessories—matched Tesla’s offerings.

  1. History of Speculative Practices

Evidence revealed that the trade mark holder had a history of systematic filings through shell companies across different jurisdictions. These trade marks were often abandoned or withdrawn, reflecting a deliberate strategy to exploit the EU trade mark system for financial gain by creating blocking positions.

  1. Dilatory Tactics and Lack of Genuine Use

The EUIPO identified procedural delays, such as inconsistent modifications to descriptions of goods and services, aimed at stalling opposition proceedings for nearly 15 years. The holder failed to provide any evidence of genuine commercial activity linked to the mark, reinforcing the perception of a purely obstructive strategy.

  1. Awareness of Tesla’s Operations

Tesla’s products were already widely covered by the media in Austria and beyond before the filing of the contested mark. This media coverage, combined with other evidence, demonstrated that the trade mark holder was aware of Tesla’s operations and sought to capitalize on its anticipated success in the European market.

  1. Violation of Fair Practices

The EUIPO concluded that the trade mark was filed without any genuine intent to use it and with the purpose of obstructing legitimate filings. This conduct was deemed contrary to principles of good faith and fair commercial practices.

Implications of the Decision

This decision aligns with a growing body of case law aimed at curbing trade mark trolling and safeguarding fair competition. It also reinforces principles established by the Sky and Others and Koton rulings, which define bad faith as intent contrary to honest practices at the time of filing.

For businesses, this case highlights the importance of monitoring trade mark filings that could impede their operations and acting swiftly to contest abusive registrations. It also underscores the critical role of evidence—such as filing histories and dilatory tactics—in proving bad faith.

Conclusion

The EUIPO’s decision in the TESLA case is a significant step in combating systemic abuse in the trade mark domain. It underscores that commercial practices must remain fair and honest, and that the trade mark system should not be exploited for speculative purposes. For companies like Tesla, such rulings help protect their investments and reputation in the European market. Trade mark law professionals, such as Dreyfus Law Firm, remain committed to assisting clients in addressing such challenges effectively.

Dreyfus Law firm partners with a global network of intellectual property lawyers.

Join us on social media

Instagram

LinkedIn 

Read More

Legal challenges of product similarity in the fashion industry

The fashion industry, known for its dynamism and innovation, is also a sector where protecting trademarks and designs is essential. One of the major challenges brands face in this field is product similarity. The definition and interpretation of this similarity have a direct impact on the scope of legal protections, particularly for trademarks, patents, and designs. This article examines various aspects of product similarity in the fashion industry, based on recent jurisprudence and developments in the field.

CONTENTS

  • What is product similarity?
  • The INPI vs. the Paris Court of Appeal: A jurisprudential divergence
  • The importance of similarity for fashion industry players
  • The rise of “dupes”: A threat to intellectual property
  • The need for jurisprudential clarification to ensure legal certainty

What is product similarity?

Product similarity refers to the evaluation of the degree of resemblance between two products or services, particularly in the context of trademark registration. This assessment is crucial as it determines whether a product or brand already exists on the market and whether another product could cause confusion among consumers.

In the fashion industry, this involves comparing not only the products themselves (clothing, accessories, perfumes) but also their uses, target audiences, and consumer perceptions. Competent authorities, such as the INPI (French Intellectual Property Office) or the Paris Court of Appeal, are responsible for resolving such disputes when a trademark is contested.

The criteria for similarity include:

  • Physical characteristics of the product: shape, color, material, etc.
  • Visual impression: how a consumer might perceive the products when observing them.
  • Purpose and use: products serving similar purposes may be deemed similar.
  • Target audience: for example, a luxury brand and an average ready-to-wear brand, while visually similar, may target different market segments and not cause confusion.

The INPI vs. the Paris Court of Appeal: A jurisprudential divergence

Differences in the interpretation of product similarity in the fashion industry have led to contradictory decisions. In some cases, the INPI considers perfumery, jewelry, and watchmaking products to be marginally similar to clothing. According to the INPI, similarity lies in the potential association between these products in the consumer’s mind, which could cause confusion regarding their origin.

However, the Paris Court of Appeal adopts a stricter stance, often relying on jurisprudence from the European Union’s General Court. The Court views the similarity between products as different as clothing and fashion accessories, such as jewelry or watches, as more limited due to clear differences in their use, design, and presentation.

These divergences create legal uncertainty for fashion industry players. Brands may face difficulties determining whether their protections cover all related products or if their trademarks might be challenged over similar but non-identical products. This raises broader questions about intellectual property protection, particularly regarding the scope and validity of registered trademarks.

The importance of similarity for fashion industry players

For fashion brands, legal protection depends on creating a strong and distinct identity. Industry players must be vigilant to avoid their products being perceived as copies of existing designs. This requires a differentiation strategy based on:

  • Innovative and unique designs
  • A clear brand image
  • Effective communication campaigns

Legal decisions on product similarity directly influence this strategy, as they determine how far a brand can go in launching new products while respecting the intellectual property rights of others.

The rise of “dupes”: A threat to intellectual property

The proliferation of “dupes,” imitations of high-end products offered at affordable prices, disrupts traditional notions of intellectual property protection. These products, widely popularized on social media, blur the line between legitimate inspiration and counterfeiting. While they do not claim to impersonate a brand, their visual or functional similarity can confuse consumers and diminish the perceived value of original products.

Legal challenges posed by dupes include exploiting grey areas in existing protections. Although designs effectively protect certain distinctive features, they often fail to counter such imitations. Shape trademarks and copyright laws, while helpful, involve complex and often lengthy legal proceedings.

The rise of dupe culture reflects admiration for luxury products and a desire to democratize style. However, it also poses an economic risk to established brands. By flooding the market with low-cost products, dupes undermine the exclusivity and innovation that define luxury brands.

In a context where consumers increasingly gravitate toward these alternatives, brands must double down on differentiation efforts through both designs and communication. Explicit recognition of intellectual property rights, combined with a proactive strategy against dupes, is crucial for maintaining their market position.

The need for jurisprudential clarification to ensure legal certainty

Disputes over product similarity are common in the fashion industry, as many brands seek to protect distinctive elements such as patterns, cuts, or logos. These disputes can result in significant costs, not only for the parties directly involved but also for the entire market due to the length and complexity of legal proceedings.

The evolution of judicial decisions demonstrates that product similarity in the fashion industry is a constantly evolving concept. The divergences in interpretation between the INPI and the Paris Court of Appeal highlight the need for legal clarification. More consistent jurisprudence would better frame trademark protections and mitigate current legal uncertainty.

Clarifying the criteria for product similarity would enhance legal certainty for fashion industry players. In the meantime, brands must remain particularly vigilant and adopt robust differentiation strategies to protect against litigation and consumer confusion.

The fashion industry, with its specificities, requires in-depth analysis of products, their uses, and consumer perceptions to ensure effective intellectual property protection. The challenge lies in brands’ ability to navigate this complexity while remaining innovative and distinctive.

Our experts are at your disposal to advise you on intellectual property strategy and online brand protection. Dreyfus Law Firm works in partnership with a global network of intellectual property lawyers.

Join us on social media!

LinkedIn 

 

Read More

What Are The Latest Trends In IT Law And How Can You Leverage Them?

The legal landscape of the tech industry is constantly changing, making it difficult to keep up with the latest developments in IT law. Companies must stay up to date with the latest laws and regulations to ensure that their businesses remain compliant. Understanding the latest trends in IT law can help companies ensure that they are taking advantage of the latest legal opportunities and protecting their intellectual property.

 

One of the most important trends in IT law is the increasing focus on data privacy. As technology has advanced, companies have begun collecting and storing more information about their customers than ever before. In response, governments around the world have implemented new regulations to protect consumer data and ensure that companies are held accountable for how they store and use customer information. Companies must understand these laws and make sure that their practices are compliant. Another important trend in IT law is the emergence of cloud computing.

 

Cloud computing allows companies to store and access data remotely, eliminating the need for physical storage devices. However, this also creates a new set of legal issues, as companies must consider the legal implications of storing and accessing data in a cloud environment. Companies must be aware of the applicable laws and regulations in order to ensure that their use of cloud computing is compliant. Finally, IT law is also increasingly focusing on cyber security. Companies must be aware of the legal requirements for protecting their networks and data against cyber attacks. Companies must also be aware of the legal implications of any cyber security breaches that may occur. Understanding the latest trends in cyber security law can help companies ensure that they are taking the necessary steps to protect their networks and data.

 

So, how can companies leverage these trends in IT law? Firstly, they should ensure that they are up to date with the latest laws and regulations. Companies should also consider the legal implications of any new technologies they are using, such as cloud computing or cyber security solutions. Companies must also make sure that they are taking the necessary steps to protect their networks and data against cyber attacks. Finally, companies should consult with an experienced IT lawyer to ensure that they are taking advantage of the latest legal opportunities and protecting their intellectual property.

 

 

 

 

We offer our clients a dedicated and unique experience of expertise that is necessary for the exploitation of intangible assets.  We will also endeavor to keep you informed and up-to-date about intellectual property and digital economic issues through our articles and newsletters written by the Dreyfus Legal Team.

Read More

Legal Watch : THE UDRP PROCEDURE

CYBERSQUATTINGThe UDRP PROCEDURE is designed to deal with cases of abusive cybersquatting.

Since the implementation of the General Data Protection Regulation and, more generally, when domain names are registered anonymously, it is often difficult to identify the enemy that we intend to strike.

The issue can be solved through filing a UDRP complaint. This is what happened to the US company Capital Distribution Consulting Inc. As the owner of the semi-figurative trademark Royal dragon superior vodka 5X distilled, the company filed a complaint against the anonymously registered domain name <royaldragonvodka.com>.

Once the procedure was initiated, the identity of the registrant was revealed. The latter was a certain Mr. X, who was an officer of Horizons Group (London) in the United Kingdom and the owner of the UK trademark Royal dragon vodka.

 

 

In fact, it turned out that both parties obtained their trademarks through a transfer carried out by Dragon Spirits Limited in Hong Kong, of which Mr. Bharwani was one of the shareholders.
This information gave rise to further exchanges between the parties, each accusing the other of having obtained the trademark unlawfully. In particular, the complainant argued that the transfer to the defendant had taken place after the liquidation of the transferee.

The facts reported in this decision are particularly complex and all-encompassing, which indicates that the UDRP is not the appropriate forum for this kind of litigation.
The expert reported that the complainant filed an additional response, which is not provided for in the Regulation, after the defendant’s response and then a second response 9 days later. This response contained 15 annexes, including a sales agreement, court orders, share transfers, a declaration relating to the liquidation procedure, etc.

The expert decided not to accept this response and consequently not to consider the defendant’s request to reply in case these submissions were accepted.
The expert pointed out that this case does not concern a simple case of cybersquatting but rather a competition matter, involving trademarks being registered around the world.

He noted that trademark rectification proceedings based on competition grounds have been granted or are still pending in different jurisdictions. Therefore, the domain name in question is fully in line with this broader dispute. The expert recalled that the Guiding Principles of the UDRP are not designed to settle all kinds of disputes that would have any link with domain names. On the contrary, the Guidelines establish an inexpensive and streamlined administrative procedure being limited to ‘abusive cybersquatting’ cases.
This decision serves as a reminder that it is essential to obtain as much information as possible about the disputed domain name that forms the subject of a procedure. For relatively old names such as <royaldragonvodka.com> being registered in 2011, valuable information can be found through consulting the Whois history of the domain name.

 

 

WIPO, Arbitration and Mediation Center, Case No. D2021-2871, Nov. 24, 2021, Capital Distribution Holding Inc. v. Hiro Bharwani, Horizons Group (London) Ltd.

Read More

Are we still really anonymous on social networks in 2021?

Social mediasAnonymity on the Internet, or the eternal debate about social networks, raises more and more moral and legal questions with an exponential number of disputes brought before the courts.

The popularization of social networks is usually associated with anonymity, and therefore with the eternal debate about the lifting of anonymity in the face of the excesses of certain users. The murder in October 2020 of Professor Samuel Paty, targeted on social networks, or a wave of insults towards a candidate of Miss France at the end of 2020, have re-launched this discussion on the political scene. And especially the desire to add a section to the French legislative proposal “strengthening the respect of the principles of the Republic” to fight against online hate.

 

 

 

 

As a preliminary, it is interesting to really ask ourselves about anonymity on the Internet: are we really anonymous on the Internet?

 

The answer is no in most cases. Indeed, when we browse the Internet, an IP address anchors each of our researches. This address makes it possible to identify each device that connects to the Internet, even indicating the geographical location of the person.

This is one of the reasons why it is very difficult to leave no trace of your passage on the Internet, unless you are a very experienced technician.

The difficulty in reality is related to the obstacles linked to the recovery of these data allowing to identify a user, more than to the existence of anonymity stricto sensu. The Internet actors play a preponderant role in the possibility that some users have to hide their identity. This concealment has increased especially with social media.

 

The position of social networks

Social networks and other platforms argue that they are simply “host” or “technical intermediary” to reject a request to lift anonymity or to delete an account that is the author of contentious content.

Only a court decision can force these platforms to lift anonymity on an account. However, judicial decisions are still discreet. This can be explained on the one hand by the fact that positive law only allows the anonymity of an account to be lifted if the content is clearly illicit. On the other hand, the freedom of expression constitutes an obstacle to the lifting of anonymity.

However, some recent decisions seem to reverse this trend.

 

French jurisprudence on the move

On February 25, 2021, the Paris Judicial Court (Tribunal judiciaire, Paris, (ord. réf.), February 25, 2021, G. B. c/ Sté Twitter International Company) ordered Twitter to communicate the identification data of a user, in a case against a female Youtuber. Under Article 145 of the French Civil Procedural Code, “if there is a legitimate reason to preserve or establish before any trial the evidence of facts on which the solution of a dispute may depend, legally admissible measures of investigation may be ordered at the request of any interested party, on application or in summary proceedings. The influencer filed a request with the Court for the communication of identification data in parallel with the filing of a criminal complaint for defamation.

This communication of data by hosts is provided for by Article 6-II of the law of June 21, 2004. Indeed, this article provides for an obligation for hosts to hold and retain data allowing the identification of persons who have: “contributed to the creation of the content or of one of the contents of the services for which [they] are a provider”.

The Court granted the applicant’s request, as the existence of a legitimate reason was well established, namely the short duration of the storage of these identification data. The court thus ordered Twitter to disclose the necessary information:

♦ The types of protocols and the IP address used to connect to the platform

♦ The identifier used to create the account

♦ The date the account was created

♦ The first and last names or the company name of the account holder

♦ the pseudonyms used

♦ the associated e-mail addresses

 

The European court, also seized of the matter

 

The High Court of Ireland has referred to the Court of Justice of the European Union the issue of lifting anonymity in a case between Facebook Ireland and a school, whose staff was subjected to derogatory comments via an Instagram account (a platform recently acquired by Facebook).

The question posed to the CJEU, concerns the threshold of seriousness that allows an exception to the GDPR, which protects our personal data, and thus be able to condemn the platform concerned to lift the anonymity on the authors of the contentious content.

The answer of the CJEU, will not come before several months, however it will surely allow to have clearer criteria concerning the balance between the respect of freedom of expression, protection of personal data, and infringement of people.

 

These decisions could open the way to a more supervised and therefore better regulated anonymity on social networks. A growing body of case law in this area, could encourage the courts to more condemn more easily these platforms, to communicate these identification data in order to punish the illicit content that users publish too easily, taking refuge behind anonymity and freedom of expression.

 

Dreyfus is at your disposal to assist you in securing these projects.

 

ABOUT THIS TOPIC…

♦ How will the Digital Services Act change the legal framework for the Internet service?

Read More

Podcast – You, Me & IP : Intellectual property, Cybersecurity and malicious Domain Names: how to combine them?

podcastWe are pleased to present the “You, Me & IP” Podcast – Episode 4 in which Nathalie Dreyfus, founder of Dreyfus & Associates is the guest of Carlos Northon, founder and CEO of Northen’s Media PR & Marketing Ltd.

“Intellectual property, Cybersecurity and malicious Domain Names: how to combine them?”

 

If you want to know more about intellectual property issues and discover a rich and experienced vision on the subject, you can also read the article Nathalie Dreyfus wrote for “The Global IP Matrix”.

 

ABOUT THIS TOPIC…

 

How to protect your brands in the digital age?

 

 

 

Read More

Why does the willingness to sell a domain name is not conditioned on an active approach? 

Télévision netflix (OMPI, Centre d’arbitrage et de médiation, 23 février 2021, affaire n° D2020-3322, Netflix Inc. c. WhoisGuard, Inc. / Siddharth Sethi)

 

Avons-nous encore besoin d’introduire Netflix ? Cette plateforme proposant des services de streaming vidéo compte 195 millions de membres dans plus de 190 pays et semble être connue dans le monde entier. Pourtant, certaines personnes tentent de se soustraire à cette notoriété pour tenter de se construire une légitimité artificielle et justifier l’enregistrement d’un nom de domaine .

 

En effet, alors que la société Netflix détient de nombreux enregistrements dans le monde pour le signe « NETFLIX » en tant que marque , la société a détecté l’enregistrement du nom de domaine <netflix.store> . En conséquence, elle a déposé une plainte auprès du Centre d’arbitrage et de médiation de l’OMPI pour obtenir son transfert.

Le nom de domaine, enregistré le 3 septembre 2017, pointe vers une page qui présente une animation composée d’un effet d’éclatement de couleur et se termine par un écran de couleur vierge.
Le titulaire soutient que le nom de domaine ne reproduit pas la marque NETFLIX mais est plutôt composé de deux termes , “net” et “flix”. Or, comme prévu, l’expert considère que la marque NETFLIX est reproduite à l’identique dans le nom de domaine.
L’expert considère que si l’utilisation du nom de domaine n’est pas commerciale, son enregistrement ne serait pas non plus considéré comme légitime. En effet, le site mis en place vise à légitimer l’enregistrement afin de dissimuler l’intention de vendre le nom de domaine au Plaignant. Ni la reproduction de la marque NETFLIX dans le nom de domaine litigieux, ni l’extension <.store> n’ont de sens si le projet devait effectivement être non commercial.

 

En conséquence, il estime que l’intimé n’a aucun droit ou intérêt légitime sur le nom de domaine .
Par ailleurs, l’expert constate que le Défendeur connaissait le Plaignant et son activité et prévoyait qu’en achetant le nom de domaine, il serait en mesure de le revendre au Plaignant avec un bénéfice significatif. Cette stratégie a été partiellement couronnée de succès, car Netflix a fait une offre que l’intimée a refusée, essayant d’obtenir une somme considérablement plus élevée.

Or, l’enregistrement d’un nom de domaine qui correspond à la marque d’un Plaignant avec l’intention de le vendre au Plaignant lui-même , établit la mauvaise foi. L’expert précise que le titulaire « [n’aurait pu] raisonnablement penser qu’un tiers serait en mesure d’utiliser commercialement le Nom de domaine litigieux ». Il convient également de noter que l’intimé a tenté de faire croire à la personne qui l’a contacté qu’il avait reçu d’autres offres plus élevées. En effet, le représentant de Netflix, qui n’avait pas indiqué qu’il agissait pour Netflix, ce qui était un secret de polichinelle, avait proposé la somme de 2 000 USD, que le déclarant jugeait trop faible.

L’expert commente ce comportement récurrent de certains cybersquatteurs : « Peu importe que le Défendeur n’ait pas proposé activement à la vente le Nom de domaine litigieux. Il n’est pas rare que des déclarants opportunistes de noms de domaine incluant une marque tierce attendent d’être approchés, réalisant qu’une offre active de vente du nom de domaine peut faciliter un procès UDRP à leur encontre ».

En conséquence, l’expert conclut que le nom de domaine litigieux a été enregistré et est utilisé de mauvaise foi et ordonne ainsi son transfert au Plaignant.

Sauf dans les cas où un nom de domaine reproduisant une marque notoire telle que NETFLIX est utilisé à des fins de critique sans usage commercial, ou pour un usage commercial minimal, il est quasiment inconcevable d’imaginer qu’un tel nom de domaine ait pu être enregistré de bonne foi . Netflix savait évidemment qu’elle gagnerait le procès, mais a visiblement choisi d’essayer de négocier un rachat à l’amiable pour un budget légèrement inférieur à celui d’une procédure UDRP, si l’on compte les 1 500 USD d’honoraires et les honoraires d’avocat. Cette approche, si elle réussissait, aurait permis d’économiser du temps et de l’argent, mais la simple offre de rachat a pour effet d’encourager le cybersquattage.

Read More