Google Claims It Can't Be Sued In UK Courts
searchengineland.com
searchengineland.com
This is what happens when you try to impose narrative on arguments in court filings. They aren't like regular arguments.
You could just as easily write the next story on if Google is so confident that they can't be sued in the UK, why are they making all these other arguments about why the complainants are wrong? It really undermines their argument if they have to take multiple approaches to it!
Edit: if anyone can find the actual filing, please link it. I'm happy to eat crow if I'm wrong :) I found coverage of this in the telegraph as well, but they also don't link to the actual submission to the court.
I'd also expect that Google's terms include language with the general meaning of "all disputes to be resolved under California law in California courts". Contracts regularly include such terms and other courts will usually support such terms.
> It really undermines their argument if they have to take multiple approaches to it!
It often confuses people when legal filings involve many arguments, some of them mutually incompatible. But the point is that if A is knocked out by the judge, B might work. So you argue A and B, because you don't know in advance what will work.
With respect to Google's filing perhaps the documents have not yet been made public by the court.
It's not my intent to compare UK to Zimbabwe, but to illustrate that holding local companies to foreign standards is kind of insane. Let's turn that around: you can bet that some UK companies are violating the US's insane IP laws. Should American companies be able to sue them for doing things that are legal in their own home country?
I'm not remotely a Google fanboy, but fair is fair. They're subject to US laws, but I don't think Google US should be liable for every regulation everywhere.
Practically, if Google were to try to dodge UK law, there's now a set of tools in place to block websites. This is essentially what happened to the Pirate Bay. It's not likely it would ever come to that of course.
If that's true, then UK citizens should be able to use US company (Google). I'm afraid the rulings may be somehow problematic to enforce, though.
But I suspect all things change because there's Google UK Ltd.
Yes. That's how it works if the UK company operates in the US. Like the other comments said, if there was no Google.co.uk & no Google UK offices then maybe they'd have some ground. But both of those exist, so... Just like China can't open this[1] store on American soil, Google can't have UK offices & Google.co.uk and somehow be immune to UK law, right? If companies can just enter other countries and do whatever is legal back home, I'm sure we can all think of a few examples where that would cause some significant issues.
1. http://www.tealeafnation.com/2013/06/chinas-copycat-phenomen...
Google will have a British subsidiary for administrative purposes. That's a nexus. They might have some money in British banks, which is another nexus. And so on.
More to the point, brother courts in different jurisdictions in the Common Law world will often respect and uphold each other's judgements where possible and where their laws are aligned. An order to pay a certain amount, made in Britain, might be upheld by an American court saying "yes, you broke their laws / performed a civil wrong / broke your contract; now pay the guy". Or instead there might be an inconsistency: "I'd love to help you out, but we just don't have that rule, sorry".
The law is a sophisticated institution unto itself. Every time you think of a first-order or even second-order problem with a story (written by a non-lawyer), guess what? The lawyers thought of that. Probably decades ago. For example, the cases which cover the way ISPs are treated in defamation go back to a pair of cases about AOL and CompuServe.
CompuServe, people. Lawyers think as hard and as far ahead about the law as we do about the web and software development.
If Google did exactly the same thing to the exact same people from those countries, but without having offices in the UK, it would have been fine?
It's interesting that doing business in a country makes you liable to that country's laws, even for things that happen half way across the world on a web server. Though they very likely do have servers in the UK so that doesn't apply here.
The internet is a weird place for the concept of "where" something happened.
Though it would be nice if they could provide servers around the world and operate their street cars without making the entire company liable to every single government's laws.
I'd be even more surprised to learn that any judge ever went along with it as presented. You do business in the UK, you better obey UK laws. Google is not (yet) a State entity granted diplomatic immunity or enjoying some other special arrangement, so the judge will likely laugh in their face.
This said, I can see why Google would try to pull a fast one: there is now a real risk that they'll be sued in every single country with a half-decent privacy law, and some of them won't have a £500K penalty limit. As much as they can, they have to try and claim that the US settlement covers all users, including non-US ones. It's the only alternative to a long list of expensive settlements across Europe.
Those laws include contract laws, which allow parties to agree on where to settle any disputes. Such clauses are very common.
Open any T&C, any EULA, any developer agreement, any copyright assignment. Scroll to near the bottom. You will probably find such a clause.
E.g. if you and me sign a contract stating you'll kill somebody for me with a sledgehammer, and you kill him with a chainsaw, an argument regarding the weapon mismatch will be resolved in whichever jurisdiction we specified in the actual contract, but arguments about the, ahem, nature of the activity will follow different rules (ok this is criminal rather than civil law, but i believe the reasoning is the same.)
That is, the Common Law does not recognise as a contract agreements with illegal objectives.
I'd be amazed, truly amazed, if this weren't true of every common law jurisdiction.
Civil wrongs are less clear-cut, because what constitutes a civil wrong is heavily dependent on local statues. That's part of why most Giganticorp Inc. contracts include clauses about settlement venues.
So what do the people pushing this suit want to happen? The loophole got closed (IIRC, the webkit fix by Google happened prior to the WSJ story exposing the loophole, it's just that Apple doesn't update its browser that frequently), the cookies were removed, the behavior has stopped.
There is still the need for federated, secure, login, whether it is cookies or some other mechanism, it is a problem that has to be solved, I worry government interference can actually inhibit progress here.
And why isn't Apple included in the case? Shouldn't they be suing for a faulty implementation as well? If someone sells a door lock that doesn't really work, and your house gets robbed, the robber gets charged, but you can bring a civil case against the lock manufacturer too. After all, even if Google's behavior is changed, there are lots of other blackhats who can leverage bugs, so going after a single exploit isn't actually solving the problem, the single point of failure was the Safari implementation. <conspiracy theory time> I'm somewhat skeptical that this is an organic case. I mean, I do think people have a right to have their day in court if they think they were actually harmed by this, but could it be that Microsoft's byzantine array of "attack Google" organizations is behind this case? I have a nagging suspicion.
Further, it would be pretty hard to get damages when no money has changed hands and actual economic loss is basically impossible to calculate.
Meanwhile, the presence of the door lock, even if faulty, clearly signals your intention that nobody enter without permission. Even a rope across a driveway can signal an unwillingness to receive visitors; anyone who gets past it is a trespasser, committing a civil wrong and probably a crime.
That's roughly analogous to Google's position: sure the mechanism had a bug. But the intention of the mechanism is pretty obvious and arguing that unless a lock is perfect you can do as you please with other people's property isn't going to be a very scalable law.
TINLA, IANAL.
The Web has an authentication problem. Existing solutions have tried to work around it by leveraging browser features not originally designed for the purpose. The result is privacy snafus like this.
Google, Facebook, et al, would argue that they have platforms, and networks of sites, with a real need for this functionality, whose basic goal is not to invade privacy, but to improve enduser UX when using their services.
I agree with the problem of authentication; I actually have a patent application in covering a solution to a tangential authentication problem.
I tried for several years to do it all with cookies and javascript; my eventual conclusion was that it can't really be done securely. So the generalised design I submitted depends on piggybacking on extensible command channels -- HTTP headers, in this particular case.
Perhaps Google expects to invoke UK law when it is convenient for them but not otherwise. If so, they should be slapped down hard.