Tagged:Law

Internet Taxation of Software-as-a-Service

Recently, several states have made attempts at expanding their taxation of out-of-state businesses who provide services or products to customers within the state. (See generally, the Tax Foundation Special Report No. 176, March 2010).

In many of the analyses I’ve read, folks have jumped straight into the state law analysis. But, unless and until federal law changes, there are constitutional limits on states’ rights to tax out of state Businesses

Federal Law

The Supreme Court of the United States has issued a long line of cases which holds that in order for a state to tax a business conducted within that state there must be a “Substantial Nexus” between the business and the state.(*1) Developments in the delivery of electronic communications over the Internet have made it easier than ever before for out-of-state businesses to deliver goods or services to customers within states where they have no substantial nexus under the traditional test.

Specifically, the Supreme Court has issued a bright line distinction between . . . sellers with retail outlets, solicitors, or property within a State . . . on one hand and those who do no more than . . . communicate with customers in the State by mail or common carrier as part of a general interstate business . . . on the other hand.(*2) The Court has consistently held that businesses belonging to the second group (e.g. those who have no agents within the state, but communicate with customers and deliver products to customers via generally available distribution channels within a state as part of a general interstate business) may not be taxed by the state where customers reside because it places an undue burden on interstate commerce.

This initial federal legal analysis is very important to complete before performing the analysis of the applicability of a state’s tax law.

State taxation of goods and services that are provided by out-of-state businesses over the Internet is an evolving area of the law. In 2007, the U.S. Congress extended the Internet Tax Moratorium until the year 2014,(*3) signaling Congress’s commitment to prohibiting multiple and discriminatory taxes on Internet usage. Recently, several states have taken aggressive stances attempting to assert the right to tax goods and services delivered to such states via Internet usage.

Amazon.com, in particular, is actively disputing several of these newly enacted tax laws. Amazon has responded to laws that claim the state has a right to assert taxes on sales to residents in the state as a result of Amazon’s affiliate program by (i) canceling the affiliate program in the applicable state; or (*4) (ii) challenging the state’s right to tax it in court (and thereby subjecting the state’s tax collections to dispute and making them difficult for the state to use).(*5)

The case law that will arise as a result of Internet-based companies disputing these state laws should provide some additional clarity. Additionally, it is important to note that it is the U.S. Supreme Court’s interpretation of the Congress’s exercise of its powers under Commerce Clause of the Constitution that provides mostt of the limits on how far states may extend their power to tax out of state businesses. It is not only future case law that may modify the law in this area — in the event that the U.S. Congress were to pass new legislation with an express position on interstate commerce and state taxation of out of state business over the Internet, the law would necessarily change.

Therefore, Software-as-a-Service providers need to be diligent about staying abreast of new developments in the law in these areas to ensure that they are in compliance with the current laws of the United States as well as the various states where they have customers.

*NOTES:
(1)Quill Corp v. North Dakota, 504 U.S. 298 (1992).
(2)National Bellas Hess, Inc. v. Dept. of Rev. State of IL, 386 U.S. 753 (1967)
(3)Tax Foundation Special Report No. 176, March 2010 http://www.taxfoundation.org/publications/show/25949.html
(4)(e.g. Colorado, North Carolina, and Rhode Island) Id.
(5)The New York trial court found for the State of New York, the case is currently on appeal to New York’s intermediate court, the New York Supreme Court, Appellate Division. Id.

Overlawyered?

I received a form license agreement from the other side (a Fortune 100 company) with this most excellent Y2K provision the other day:

Supplier represents and warrants that neither performance nor functionality of the services, Products or systems is or will be affected by dates prior to, during and after the year 2000.

It’s not like I can strike it and argue that it shouldn’t apply.

But, really?

The Latest Case Against Facebook

On May 5, 2010, The Electronic Privacy Information Center (EPIC) filed a complaint with the FTC regarding Facebook’s privacy practices (or lack thereof).

The biggest two complaints, to my reading are that (1) Facebook unilaterally tried to convert some information previously designated as private to public; and (2) Facebook changed its developer data retention policy to allow developers to retain end user data indefinintely.

Neither of these changes benefits end users, no doubt. But, what I’m fascinated to see is that today, a mere 12 days after the complaint, the user experience is significantly different from the experience described in the complaint (notably, the experience is more protective of user’s data when compared against the experience described in the complaint).

The legal process is slow and cumbersome and using it to argue with a quick and nimble internet-based adversary is going to be frustrating, to say the least. However, where end users are concerned, perhaps the quick responsiveness of Facebook is a benefit. If enough people complain, they just roll out a fix, long before the Feds, or the courts order them to do so. Certainly, this means that the fix is likely to be on Facebook’s preferred terms, rather than what the court or Feds order, but isn’t a quick fix better than a long period of open sharing without a fix (when it comes to privacy)?

I’m not saying I approve of Facebook’s most recent blunders. But, I do applaud of their quick “opt-in” and “opt-out-of-all” additions after the complaint about the blunders. And, I’m fascinated to see how or where the law fits in this world where the facts upon which any legal claims may be based are so ephemeral.

The Real Risks of Open Source Software

Every software start-up company I’ve ever worked with uses (or did use) some form of open source software. And yet, high level executives and board members at many of these companies, when asked whether their company uses any open source software, would regularly answer, “No” without hesitation.

Where is this disconnect coming from? Open Source Software is often perceived as “risky” or “untested” or “a liability nightmare” or, in the worst case, “an infectious disease” by some business folks, while most technical software people believe the correct use of open source software to carry minimal risk.

Risky?

There are risks associated with using any third party’s software. When that third party is unidentified, not bound by a support agreement, based out of a foreign country, and/or impossible to get a hold of, then yes, it is fair to say that using it would be “risky” when compared with an established company with a business reputation to protect and an SLA to cover errors.

Untested?

In some case — it’s true. There are many untested open source projects out there. These tend to be associated with a handful of developers instead of an active community, and a little due diligence should be able to help a start-up understand whether this particular ill is a problem with the open source software they are considering using.

A Liability Nightmare?

This is, by far, the most complicated issue I face as an attorney who deals with open source issues. At its most basic, the liability equation associated with open source software is the same as that associated with any third party component. The third party would like to disclaim liability for your use of their product.

The benefit of many proprietary software licenses is that the licensor may provide limited coverage for Intellectual Property claims related to their software. But, most software publishers go to great lengths to limit the amount and type of liability they will cover relating to a third party’s use of their software.

The typical open source license expressly disclaims all liability associated with the use of the software — effectively, it comes “AS IS” on a pure “BUYER/USER BEWARE” basis. On the other hand, if you read the license agreements of proprietary software carefully, you will find that most software (unless you pay quite a bit for it), comes with an express limitation on liability that is on the order of magnitude of the purchase price. It is consistent with the approach taken by proprietary software publishers that open source authors are liable for damages related on the order of magnitude of the license fee they receive (e.g. $0).

An Infectious Disease?

One flavor of open source licenses places conditions of “freedom” upon the use of the licensed code. The most famous of these licenses are the GPL, LGPL, and the AGPL. Essentially, these licenses require, as a condition of some uses or distributions, that software code combined with code licensed under these licenses must also be made available under the same license.

These conditions make these types of licenses “viral” because they may extend the license terms to some of the additional code (e.g. the start-up’s code) that the licensed code touches.

The key word in the previous sentence is *MAY.*

Actual Risk

The thoughtful evaluation of the issues outlined above and a comparison of the likely downside against the monetary benefit of using an open source component brings a start-up to understand what I call the “Actual Risk.”

By far, the most complicated part of the Actual Risk evaluation is the technical and legal analysis related to viral licenses. However, a technical read of the license by a knowledgeable tech attorney and code review with an engineer is likely to provide a good engineer or architect with comfort that the start-up’s use of a particular open source component is not subjecting the start-up’s code base (or the portion of the code base that they care about keeping proprietary) to any “viral” risk.

The Resource Risk

Investors and potential acquirors will want their own attorneys or possibly even code auditors to assess the Actual Risk, regardless of how correct the start-up’s own analysis may be. This investigation and analysis is a time and resource drain that can be minimized by good record keeping, but can never be entirely eliminated. Even in the event of zero Actual Risk, a company will incur some Resource Risk in connection with their use of open source software.

The FUD Risk

No matter what the final conclusion may be after the Resource Risk and the Actual Risk have been assessed and assumed by a start-up, there is the risk associated with the fact that a board member or a CEO will have to answer “Yes” to the question “Do your products contain open source?” A board member or CEO may not have the time to understand the outcomes and analysis of the folks who have willingly taken on the Resource Risk and the Actual Risk. If challenged, a board member or CEO need to feel confident that they can answer the question honestly, without incurring undue scrutiny or concern. In my opinion, the biggest risk associated with the use of open source software (assuming there is no Actual Risk that hurts the start-up’s business) is the FUD risk.

The best way to combat the FUD risk is to educate board members and CEOs so that they can comfortably speak about the company’s intelligent use of open source software as a cost reduction tool in areas where the Actual Risk is minimal or non-existent and the Resource Risks are less than the costs of the proprietary alternatives.

How To Find Your Start Up Lawyer

There are any number of ways to go about finding the lawyer that is the right fit for your new company. Matt Bartus recently posted his thoughts on some of the questions you should ask.

Overall, I agree with Matt, you should ask all of the questions he poses and evaluate the answers. However, I have a few additional points that you may wish to consider:

1. If you are bootstrapping your company entirely, and do not expect or intend to take any venture financing because you intend to build a successful cash business that you want to privately control, you may need to question much of the traditional “start-up” legal (and business) advice.

Specifically, if you are covering your own costs out of pocket, you will probably best served by finding two or three good specialized solo attorneys or attorneys at smaller law firms who specialize in the types of services you will need for small emerging businesses. These attorneys are likely to offer fast responses to your needs in the areas where you have issues, but they will have significantly less overhead (and thus significantly lower fees) than a traditional large law firm.

While many large law firms defer billing if they believe you will be getting venture capital funding or if you will be experiencing a liquidity event in the near future, if that is not your goal, it is likely that you will be asked to pay your fees to keep your account current.

2. The large law firm industry’s focus on “Senior Attorneys” “Junior Attorneys” and “Partners” is very different from the meritocracy within the start-up culture.

Rather than focus on how advanced an attorney’s skill set is, most large law firms categorize attorneys solely based on the number of years that each attorney has been in legal practice. This means, that in most firms, the titles are not related to how talented or how effective the attorneys are (with the exception of equity partnership, which often is an indicator of excellence as it is peer-selected).

It is possible that a Junior Attorney is actually a professional with 15 years of relevant business experience coupled with 2 years of legal training. In fact, at one law firm where I worked, an individual with a PhD and 18 years of relevant biotech experience started on day one as a “first year associate” in patent prosecution alongside his 24-year-old colleagues who hadn’t worked a day in the professional world. So, while I would agree with Matt that Junior Attorneys are often not more cost effective than attorneys with more experience, that is not always the case.

On the other end, it is possible in some law firms to earn a business card with the title of “Partner” after a set number of years (often 7 or more) so long as the attorney has billed the requisite number of hours each year. In these law firms, the partnership is often stratified between equity partners, income partners, partial equity partners, etc. An income partner may or may not be very talented, but the “Partner” title alone is not sufficient to guarantee that they will provide the skills you need. So, again I agree with Matt: ask for references and follow up.

3. A good solo or small firm attorney can act like in-house counsel — a cost-effective go-to first responder who evaluates the risks and, if necessary, can act as a gatekeeper to help manage the additional service providers who may be necessary to get the job done.

I work in many capacities with my clients, but the most common role I play is this — my clients have identified that the majority of their day-to-day legal needs fall into the category of “commercial contracts” that focus on intellectual property in all of its forms, services, and money. Because this is my specialty, I provide them drafting, editing, advice and legal analysis in this category, and when they ask for something outside of my expertise, I explain my relative inexperience, and let them know that I have a choice:

a) If I think it’s close to my practice area I can do the research and determine whether I think I can learn what I need to know to do a good job and then offer to do it while writing off my professional education time; or

b) I can refer them to someone I believe is a good fit for their needs.

In this way, my role as a solo practitioner is much more like the role a dedicated in-house counsel plays within larger companies (in-fact, I work on-site to support an in-house legal department of a public company one day per week, and in that capacity, I’ve been impressed by how important management of outside law firms is to running a successful legal department).

So, yes, a solo practitioner or small firm attorney who specializes in transactional work can’t walk down the hall and ask a litigation partner how to manage a dispute. But, if they are good, they should have a great network of qualified attorneys to whom they can refer. They can call litigators with whom they are currently working (I’m working with two litigation partners on a dispute for one of my clients right now), or with whom they’d like to work in the future (I’ve had several litigators take me out to lunch to pitch their expertise and desire to work with my clients) and ask for some professional courtesy advice.

A solo or small firm attorney can refer you to the best fit, no matter who they are, without fear of offending “the attorney down the hall.” And, if you do (and I hope you don’t) find yourself in need of a litigator, a good solo (like a good in-house counsel) can help you manage a competitive bidding process to ensure you get the best fit at the most cost effective price for your needs.

Paul Ohm: Anonymization Has Failed

I recently had the privilege of attending a talk where Paul Ohm presented the main ideas behind his latest research paper.

I found his reporting on re-identifying users from supposedly non-personally identifiable information fascinating:

-87.1% of Americans can be uniquely identified by their 5-digit zip code combined with the date, month, and year of their birth.

-80% of anonymized Netflix users could be uniquely identified by 3 movie reviews (movie, date, review value).

His take-home message?

Data can either be useful, or perfectly anonymous, but never both.

The majority of laws and contracts dealing with personal information draw a line between “personally identifiable information” and “non-personally identifiable information” (aka aggregate, anonymous data).

But, if you can use non-personally identifiable information to derive personally identifiable information, then the two categories collapse into one.

It will be interesting to see how advertisers, social networks, governments, and end users respond to reality that the separate categories we’ve built into the laws and contracts may not actually exist.

Open Source Legal Docs?

Ted Wang, with the support of Andreessen Horowitz, recently posted some open source legal document forms for companies seeking seed funding.

It’s an interesting concept, and in the abstract, one that I’ve been thinking about for quite some time.

I think, in general, the open source software movement has changed the game.  Not by devaluing the skills of the individual developers, but by decentralizing the control of the software they write from the few corporations to the many of the masses.

This change has resulted in amazing progress in some areas, and, of course, ridiculous amounts of navel gazing in others.  But, at a high level, what it’s really done is to move the value associated with the software from the centralized control of powerful corporations to the decentralized control of the skilled individuals who contribute the copyrighted works.

And, in doing so, it’s shown that In many contexts, the value of open source software is not in the copyright to the code of a particular project, but rather in the goodwill of the community that is supporting, maintaining, and potentially following the direction of the steward of the code of that project.

By analogy, it’s not like posting documents that are freely available in the legal start-up space is a new move.  The National Venture Capital Association has made its standard forms available for many years.

But, the difference with Series Seed is the stated goal.  The open legal document movement, if it is to succeed where it applies to start up companies, is in desperate need of a dedicated community, and most likely, a community-trusted steward who will take this project on and protect it, preside over disputes, and act as a neutral third party when folks with an interest in the project have different goals.

It should be interesting to see if the Series Seed project moves in this direction and is able to play this role in the seed funding community.

Schools? Google? Who isn’t invading privacy?

Today was an interesting day in privacy lawsuit news.

First, there are the parents of a Pennsylvania high school student who filed a complaint against the school alleging that the school remotely activated a school-issued laptop and took a picture of the child. At home. Without his or their knowledge. And without his or their consent.

Then, there’s the class action lawsuit against Google regarding auto-activation of Buzz and the information that was necessarily shared in connection with that activation. Specifically,


Google turned Gmail “into a social networking service and that’s not what they signed up for, Google imposed that on them without getting their consent,” said Kimberly Nguyen, consumer privacy counsel with EPIC of Washington, D.C. “The bottom line is, users should have meaningful control over their information.”

I’d say these lawsuits show that not everyone agrees with Mark Zuckerberg’s statement that Privacy is no longer a social norm.

All the Administrative IT things…

So, getting ready to run my own law firm is full of all sorts of responsibilities I haven’t had to think about in years:

– MSFT Exchange server on your domain?  Gotta hire someone to manage that.

– Email (and Exchange calendar) synch’ed to the phone?  Gotta figure out how to manage that.

– Bookkeeping?  Yeah.  Turns out, March is really sub-optimal in terms of timing for searching for a qualified CPA…

– Taxes?  See above.  Same issues with the CPA, but more serious concerns about penalties associated with getting it wrong.

– Time Keeping (where not on a project or subscription plan) and Billing?  Ugghhh.  That’s going to be fun…

– And hardware?  My laptop is 7 years old.  But it works fine, and much like my car, I’ll probably just drive it into the ground.  My phone, on the other hand, is an entirely different issue… ‘Droid? HTC? What’s a verizon customer to do?

And yet, despite all of these issues pulling me away from the core business I’m trying to start — I’m excited.  It’s fun and interesting to figure out which offerings in the marketplace make the most sense.  I feel like the research to figure out how to run my own practice makes me more able to relate to my clients that need to run their own technology businesses.