Equifax terms of service may include binding arbitration clause
twitter.com
twitter.com
1. This contract does appear to apply to the data breach check site run by equifax. To be specific, the contract at http://www.equifax.com/terms/ describes its scope of coverage as "ALL OTHER WEBSITES OWNED AND OPERATED BY EQUIFAX AND ITS AFFILIATES" which would appear to include https://www.equifaxsecurity2017.com (which links those terms).
2. Arbitration clauses are very bad in cases like this, because by far the most effective technique for forcing companies to compensate people and deterring similar problems in the future is the class action, and this arbitration clause, like so many others, includes a waiver of class actions. Class actions are important because litigation is really expensive and class actions are the only generally applicable way to aggregate enough small claims to make them financially viable. (They're the way we keep corporations from stealing five dollars from everyone in America.)
3. As someone down-thread correctly noted, arbitration clauses are also extremely enforceable. The short version is that the federal arbitration act puts a very big thumb on the scale in favor of the enforceability of even really oppressive arbitration clauses, and the Supreme Court has added a couple of thumbs of its own.
4. I can't tell whether Equifax meant to do this. The cynical interpretation is that some evil person decided "ok, there's going to be a panic and everyone is going to go to our website to check if their data is breached, so let's sneak in a way to get all these people out of class actions." The less cynical interpretation is "someone threw up a website, and the standard procedure within the company for throwing up a website is to include a link to these boilerplate terms of service." No way from the outside to tell which of these stories is true, and I'm not sure it really matters.
5. There are arguments that a sharp lawyer could make to try to convince a court that this clause is unenforceable. I'm happy to go into them if people want, but, offhand, I would much rather not have agreed to such a contract than have to try to convince a court to bounce it.
6. Yes, there is an opt-out. The opt-out is only useful for people who have actually read and understood the contract, which even with the press coverage is likely to be a vanishingly tiny percentage of the people who have inadvertently "agreed" to it. So it doesn't make it meaningfully less evil.
7. If you want to learn more about this kind of issue, I recommend Boilerplate by Margaret Radin. http://press.princeton.edu/titles/9837.html She does a great job of explaining why this kind of thing is a complete disaster and also bears no relationship to our traditional conception of what a contract is or should be.
Editing to add:
8. I guess I'll add really briefly that the key argument that this clause doesn't even apply would be that the contract distinguishes between "product terms of use" and "site terms of use," and that arguably the arbitration clause only applies to the purchase of products and registration. If checking breach status doesn't count as purchasing a product, maybe that part (with the arbitration clause) doesn't apply on the terms of the contract itself. HOWEVER, registering for some kind of identity protection service as a result of having checked breach status probably does, so that's cold comfort to a lot of people who might use the site. I'll have to parse the contract more slowly and carefully before having any confidence in much more along these lines.
(Standard warning: nothing here is individual legal advice, contact an attorney in your jurisdiction before deciding whether you'll use this site, I'm just speaking about the overall interpretation of this contract and what we should think of it as citizens.)
As somebody who has been building websites for living and worked with corporate clients, this is about 99% likely to be true IMHO. Unless they run an extremely efficient legal department with lawyer equivalents of Superman working there, it just doesn't happen that new and specifically case-targeted TOS appears that fast, especially in a large corporation environment. "Just toss a standard link there, nobody reads it anyway", OTOH, happens all the time.
1. Is there any legal reason any more for a corporation not to include forced arbitration in its contracts? Like any hidden downside? "Get out of class action free" card seems like a no-brainer.
2. Is there anything special you do in your day-to-day life to deal with forced arbitration issues? Avoid certain businesses, etc.? Have you ever actually tried to send one of those "opt-out" things and how did it go?
1. Honestly, I can't think of any downside, not in consumer contracts (as opposed to b2b) anyway. I guess there are some cases where particularly favorable courts might be preferable from the corporation's point of view (there's a court in Texas that gets tons of patent suits for that reason, also there are some states that are good for corporations --- Virginia has no class actions, for example). That's about it.
2. I personally haven't. (Though, a long long time ago, I did kick enough of a stink about an arbitration clause in a car loan contract that the dealership put some money on the table to make me stop.) The thing is, most of the time, for most consumers, it doesn't really matter--the probability that I'm likely to get harmed by some transaction enough to want to be part of a class action is so small, that it's probably rational for me on a day to day basis to just accept them. It's collectively that they're a problem, because they seriously damage one of the main ways that the legal system has to hold corporate misconduct accountable. So we really need a collective solution, rather than just individual avoidance. (Obviously, the exception being in cases like this Equifax thing were we know that litigation is on the immediate horizon.)
I've actually thought for a while about some solutions that people in the tech world might be able to work on. One idea that I just finished sketching out for print (will be in the University of Toronto Law Journal sooner or later) would be to build a kind of coordinated contract negotiation platform, where people could commit to saying "hey evilCorp, if a million other people also agree to this, we'll all collectively cancel our accounts unless you get rid of evil terms X, Y, and Z." This would resolve some of the collective action problems with it being individually rational to accept these terms usually but collectively disastrous. If, that is, people would use it...
Don't assume a contract actually means what it says when it comes to enforcement. Seek legal advice.
I've seen in a more than one case where the Judge blamed the plaintiff that the onus is on them to read the TOS BEFORE agreeing to anything. In the end, it just depends on what kind of a judge you get.
https://www.eff.org/wp/clicks-bind-ways-users-agree-online-t...
However, courts generally do not require that you actually have read the terms, but just that you had reasonable notice and an opportunity to read them.
In other words, it’s not merely clicking the “I Agree” button that creates the legal contract. The issue turns on reasonable notice and opportunity to review—whether the placement of the terms and click-button afforded the user a reasonable opportunity to find and read the terms without much effort.
https://twitter.com/AGSchneiderman/status/906195350532304896
http://thehill.com/regulation/court-battles/333417-supreme-c...
What the Supreme Court, unfortunately, has decided the "fact" is that you are correct - If you were covered in the forced arbitration clause, you would forfeit your right to civil action against Equifax in exhange for having your case heard by an "Arbitrator" that Equifax chooses. Have fun with that.
On the other hand, you might be able to make a case that since they leaked your information, they couldn't prove it was you anyway.
I don't know who's signing up for these "free" identity protection services anyway. This company has failed to protect the personal information of roughly half the population of the entirety of US. (I understand they are not limited to US, but those are the numbers.)
They do not need to be "protecting" anybody after that. They should be tarred and feathered for putting up these websites after what they've done, and whatever lawyer advised them to sneak in a provision against class action lawsuit should be immediately disbarred, in my not so humble opinion.
How many digits of my SSN do I need to enter into this five-day-old website that provides me with no clue what they're going to do next, in order to see if I need any further "protection" from this group with which I have no direct relationship, and whom I've never done business with, but that has diligently kept records on me for my entire adult life?
Except for that Equifax has all that data. So what's to stop them from just using their own data to prevent anyone else from suing them? (Or to prevent the people who stole the data from doing this for whatever reason.)
You mean right after the database containing full list of SSNs and last names of virtually every person in the US has been stolen? Of course, there's nobody around that could guess this information. And of course, there's no way to enumerate most common last names and the huge amount of 6 digits... It probably would take literally a million milliseconds!
Here's some help: http://thehill.com/regulation/court-battles/333417-supreme-c...
Nobody is signing anything on your behalf with power-of-attorney. Does this ruling say that I or my agent can relinquish my rights in a contract, that does not actually come out and say that I am relinquishing my rights?
I'm sure that's not what it says, but that's approximately what I'm able to tease out of the words in that link you posted. That sounds like absolute nonsense, so please explain precisely what this is supposed to mean if you will be so kind.
The Supreme Court said "Other laws don't matter - if there is an arbitration clause you have to go through that: No Court For You regardless of how you were injured." ( https://en.wikipedia.org/wiki/Southland_Corp._v._Keating )
And then they were all like "Even if the law explicitly says you can take the party that harmed you to court, you can't": ( https://en.wikipedia.org/wiki/Preston_v._Ferrer )
And then in 2011 they went absolutely bonkers and were like "OK, listen guys. Before this was just between businesses... but now a business can use it against people." ( https://en.wikipedia.org/wiki/AT%26T_Mobility_LLC_v._Concepc... )
and then all hell broke loose and now every company tries to use them for everything.
The link provided was just the most recent example of the SC expanding the power of the FAA.
Thanks! That kind of makes sense. In a very Machiavellian kind of way.
Emphasis on unscrupulous...
https://www.equifaxsecurity2017.com/frequently-asked-questio...
> The arbitration clause and class action wavier included in the TrustedID Premier Terms of Use applies to the free credit file monitoring and identity theft protection products, and not the cybersecurity incident
Seems to me that just filling out that form does not waive your rights to participate in the class action suit. It also even sounds like using their free product has no impact on your ability to participate in any class action suit.
Despite the SCOTUS ruling in AT&T Mobility LLC v. Concepcion if this question is put before a US judge, there's a good chance that the contract won't be worth the paper its printed on.
I didn't enroll specifically because I assumed it might waive my rights. I didn't notice any such disclaimer on the am-i-impacted lookup.
If it really does apply to the lookup itself (or was intended to apply), then it's worth some outrage. If not, it's worth significantly less outrage.
EDIT: The authoritative-sounding @pabloishappy says, "I spoke with equifax rep named Marvin. He said enterining your last name and 6 ss#'s DOES NOT constitute enrollment. Yiu neednto complete1/"
EDIT2: per https://www.equifaxsecurity2017.com/frequently-asked-questio... "The arbitration clause and class action wavier included in the TrustedID Premier Terms of Use applies to the free credit file monitoring and identity theft protection products, and not the cybersecurity incident."
It says nothing about waiving your rights, etc. at all. There is the option to sign up for some of their services ("we will provide you the option to enroll in TrustedID Premier."), which I have read elsewhere include clauses waiving your rights to be part of a class action suit. But just checking this link has no waiving associated with it.
Fascinating legal history behind it, actually: It was all based on a law from the early 1900s that was meant to apply only to two businesses in contracts with each other, but the Supreme Court allowed the creative interpretation that it could apply between companies and individuals... go figure.
Last 6 Digits of Social Security Number: 123456
> Based on the information provided, we believe that your personal information may have been impacted by this incident.
Making you wave your due process rights, in order to "learn" what "they are saying about you". Or, "writing", as it were -- thus the potential for "libel".
IANAL, but it seems perhaps an unreasonable barrier to "setting the record straight". One that they are attempting to force you to enter, simply to learn what they are saying about you.
The credit agencies have gone to a lot of effort, including a lot of lobbying and influencing lawmakers and regulators, to minimize the risk of libel suits. I can only hope that, with continuing over-reach like that in the OP, they are ultimately shooting themselves in the foot, in this regard.
[0] https://twitter.com/AGSchneiderman/status/906195350532304896
Some keep quoting this line from the terms of service:
> YOU MUST ACCEPT THE TERMS OF THIS AGREEMENT, INCLUDING THE ARBITRATION AGREEMENT CONTAINED IN SECTION 4 BELOW, BEFORE YOU WILL BE PERMITTED TO REGISTER FOR AND PURCHASE ANY PRODUCT FROM THIS SITE. BY REGISTERING ON THIS SITE AND SUBMITTING YOUR ORDER, YOU ARE ACKNOWLEDGING ELECTRONIC RECEIPT OF, AND YOUR AGREEMENT TO BE BOUND BY, THIS AGREEMENT. YOU ALSO AGREE TO BE BOUND BY THIS AGREEMENT BY USING OR PAYING FOR OUR PRODUCTS OR TAKING OTHER ACTIONS THAT INDICATE ACCEPTANCE OF THIS AGREEMENT.
Whereas others have pointed to the Opt-Out:
> Right to Opt-Out of this Arbitration Provision. IF YOU DO NOT WISH TO BE BOUND BY THE ARBITRATION PROVISION, YOU HAVE THE RIGHT TO EXCLUDE YOURSELF. Opting out of the arbitration provision will have no adverse effect on your relationship with Equifax or the delivery of Products to You by Equifax. In order to exclude Yourself from the arbitration provision, You must notify Equifax in writing within 30 days of the date that You first accept this Agreement on the Site (for Products purchased from Equifax on the Site). If You purchased Your Product other than on the Site, and thus this Agreement was mailed, emailed or otherwise delivered to You, then You must notify Equifax in writing within 30 days of the date that You receive this Agreement. To be effective, timely written notice of opt out must be delivered to Equifax Consumer Services LLC, Attn.: Arbitration Opt-Out, P.O. Box 105496, Atlanta, GA 30348, and must include Your name, address, and Equifax User ID, as well as a clear statement that You do not wish to resolve disputes with Equifax through arbitration. If You have previously notified Equifax that You wish to opt-out of arbitration, You are not required to do so again. Any opt-out request postmarked after the opt-out deadline or that fails to satisfy the other requirements above will not be valid, and You must pursue your Claim in arbitration or small claims court.
Therefore, I'd take everything with a grain of salt and/or read the full terms for yourself:
Ultimately, I had to resort to sending them letters via certified mail.
Honestly for this (the Equifax thing), you just keep record of when you sent it—it's only an issue if you litigate, and then I'd expect your record of when you sent it + your testimony would be sufficient. But IANAL, and you should of course talk to one if it matters.
For your HOA, hopefully you have some record of when you sent the request (e.g., you kept a copy of the ARC application with a note that you mailed it on $DATE). (Of course, the HOA should be maintaining records of when applications are received.) Depending on what it is, this is something that may be worth paying for legal advice on.
I've had to use it in the past for creditors who don't have a clue.
Equifax has the clause for opting out of arbitration, but Trusted ID Premier's Terms of Use doesn't have it. The enrollment site I've seen is owned by Trusted ID Premier, and it's arguably deceptive that Equifax structured the site as a bat-and-switch to see if their shitstorm exposed you.
Heck, they may have even planned a PR push around telling news outlets to refer readers to that site, omitting that using trustedidpremier.com means that you agree to a ToU that mentions only waiving the right to participate in class-action suits, but not how to opt-out.
It's so phishing-sounding that I want to believe it was chosen after a quick focus group with the "people who are most likely to become fraud victims" demographic.
EV certs on the other hand at least claim to verify who owns the website but even then I would be cautious.
Rudy Giuliani, Andrew Cuomo, Elliott Spitzer, etc, etc.
That isn't a prerequisite for opposing someone due to their views or opinions, regardless if their actions regarding this incident are agreeable.
I'm sure if Trump takes up this cause against Equifax as well you're going to support him in that effort too. Correct?
Last time I checked, I posted useful information in this thread and only noted my opinion of Schneiderman after "josefresco" specifically named him in an attempt to divert the conversation. If I wanted to attack him specifically I would have picked a better forum than Hacker News where politically charged discourse is generally frowned upon. And moreover, I owe no one any further explanation of my opinion of Schneiderman; much less you in particular.
Do you understand correctly, now?
But I will not refrain from using such language in the future when I feel it's appropriate.
Although, if you want to declare I started what can hardly be described as a flame war just by stating an opinion, you should just delete my account now.
Seriously.
The AG is also pissed about the language, but that doesn't mean he's confirmed it's enforceable.
But there's no way that anything like 100% of the affected people will, which is what it would take to even theoretically get them out of the class action lawsuit(s).
Arguing about the legal details seems pointless, this isn't going to get them out of this scrape even if it was 100% iron-clad and court tested, and I seriously doubt anyone at Equifax ever thought for a second this clause would be used that way.
Probably, but people and companies should stop doing that. Equifax has the resources to pay lawyers to do things fairly if they want, they're just choosing not to.
To believe that this clause is related to this matter is to require not merely mendacity (believable), not merely stupidity (believable), but an unbelievably precise combination of mendacity and stupidity that can only be read as constructing a rationalization for a pre-supposed conclusion.
"On April 27, 2011, the Court ruled, by a 5–4 margin, that the Federal Arbitration Act of 1925 preempts state laws that prohibit contracts from disallowing class-wide arbitration, such as the law previously upheld by the California Supreme Court in the case of Discover Bank v. Superior Court. As a result, businesses that include arbitration agreements with class action waivers can require consumers to bring claims only in individual arbitrations, rather than in court as part of a class action."
After this decision, tons of click-wrap ("contracts of adhesion") agreements added "oh BTW you can't join a class-action suit against us." They seem to be on very solid legal ground. :-(
For example, the last name SMITH matches almost any 6-digit numbers on Equifax's website.
Personally I think that lawyers ought not to draft agreements and contracts that are likely to be found unconscionable or wildly asymmetric as a matter of professional ethics. Adversarial legalism between private parties tends to yield crappy results for the public. I mean, if you've just created a problem for 140 million people, trying to trick them into waiving their rights of redress basically confirms that you're a Bad Person - a bad corporate person, a bad executive making the decision on behalf of shareholders, and a bad lawyer for agreeing to promulgate such trickery.
> "AND ALL OTHER WEBSITES OWNED AND OPERATED BY EQUIFAX AND ITS AFFILIATES".
So this would mean that the general TOS would apply to the Trusted ID site also.
And while some parts of this TOS make it seem like it would only apply if you purchase and use a product (which is inapplicable to the Trusted ID program, which is free), other parts make it seem like it applies beyond purchases, to any use:
> YOU ALSO AGREE TO BE BOUND BY THIS AGREEMENT BY USING OR PAYING FOR OUR PRODUCTS OR TAKING OTHER ACTIONS THAT INDICATE ACCEPTANCE OF THIS AGREEMENT.
So it's a big mess, and probably unintentionally so, from the looks of the legal docs.
Approximately nobody is going to do this. Fuck that.
My case involved an employee that committed fraud by offering me bogus shares of a non-existent entity. They terminated me after I brought this up and asked me to sign a waiver in exchange for severance. 100% not enforceable.