Author: TM Attorneys

  • Know your rights as a consumer this Black Friday

    Know your rights as a consumer this Black Friday

    Black Friday deals are upon us, and the festive shopping season is around the corner, therefore it is important that all businesses which market, distribute, manufacture, or sell goods and services in South Africa, comply with the Consumer Protection Act 68 of 2008 (CPA). Below are a few noteworthy regulations that one should be aware of when buying or selling something in South Africa.

    Consumer’s right to cooling-off period after direct marketing

    According to Section 16 of the CPA; if a business markets any goods and services to consumers through direct marketing mechanisms such as via email, social media messages, approaching them directly, telephonically or SMS, consumers have five days to cancel the contract without any penalties and to be refunded any monies paid within 15 business days.1

    Disclosure of prices of goods and services  

    Under Section 23 of the CPA; businesses are required to display a price if advertising any goods or service to the public, unless:

    • The goods are displayed predominantly as a form of advertisement of a business.
    • The goods are in an area within the premises where the public does not ordinarily have access.
    • The business has provided a price estimate for repair and maintenance services.

    A price will be deemed to be displayed if a second price fully covers and obscures the first. In an instance where there are multiple prices (of varying values) displayed, the supplier can only charge the lowest price on display. However, if the price displayed is an obvious error, the supplier would not be bound by it if they correct the price displayed and reasonable steps are taken to inform the consumer of the pricing error. A supplier would further not be liable for a change in price if an unauthorised person has altered, defaced, covered or removed a price displayed by the supplier.1

    returns and refunds

    Returns and refunds

    It is essential for businesses to have a returns and refunds policy. Customers can legally return goods and receive a full refund under the following circumstances, stipulated in Section 20 of the CPA:

    • Goods purchased as a result of direct marketing and the consumer has cancelled within the five-day cooling-off period.
    • When the goods purchased were not examined by the consumer prior to the delivery and the consumer rejects delivery of the goods for any of the reasons stipulated in section 19(5) of the CPA (as an example, goods are not of the quality as stipulated in the agreement or the goods fail to conform to material specifications stipulated in a special order).
    • When goods are intended to satisfy a specific purpose (that has been communicated to the supplier) and within 10 business days of delivery to the consumer, the goods are found not to be suitable for said purpose.
    • The goods delivered are not as per the order for instance the delivery includes a mix of the goods that the consumer ordered along with goods that were not part of the consumer’s order. In this instance, the consumer can accept the correct items in the order and return the incorrect items or reject the entire order altogether.

    In addition, under Section 56 of the CPA; customers also have the right to receive a refund, replacement, or repair at their own choice if the goods purchased from a business are defective within six months of purchase. This automatic warranty is in addition to the business’ or manufacturer’s warranty. 1

    Here are some tips provided by the Consumer Goods and Service Ombud (CGSO) to minimise problems with online purchasing:

    • Use well-known and reputable websites.
    • Ensure that there are valid contact details where you can lodge a complaint or send queries after a transaction.
    • Make sure that you are aware of the delivery timeframe to ensure that you will receive the goods on or before the date you require the goods.
    • Read the terms and conditions and check for any hidden costs.
    • Check the internet for reviews and any complaints about that supplier.
    • Use secure payment platforms and keep records of the transaction.2

    References:

    1. https://www.gov.za/documents/consumer-protection-act
    2. http://www.cgso.org.za/wp-content/uploads/2019/11/CGSO-Press-Release-Nov2019-Final.pdf
  • Parallel Imports

    Parallel Imports

    Parallel importation can be defined as the act of importing and trading in genuine goods that are sold without the original manufacturer’s knowledge or consent. These goods are also referred to as “grey goods”.

    An example of how parallel importation typically takes place is when an individual travels to a foreign country, and purchases an item in said country at a lower retail value than that which the item is typically sold in South Africa. The individual then re-sells the item in South Africa, typically at a lower price than the average retail value, but still at a profit.1

    Parallel imports are not counterfeit goods and are legally permissible, provided that they comply with the provisions of the Acts below.

    Consumer Protection Act 68 of 2008 (CPA)

    Section 25(2) of the CPA states that a person who markets parallel imports or grey goods is required to apply a “conspicuous notice” on those goods in the following prescribed manner and form:

    • The notice must be written in an easily legible size (e.g. in the product description line), where the supplier, in plain language, expressly draws to the consumer’s attention (e.g. by adding an emboldened paragraph in the specification of the product) that the goods:
      • have been imported without the approval or license of the registered owner of the trade mark embossed on the goods; and
      • that no guarantee or warranty will be fulfilled by any authorised importer of such goods.
    • The notice must be applied on the goods themselves (including the marketing material of the goods) where a consumer is likely to see that notice.2 Below is an example of a “conspicuous notice”:
    parallel import takealot screenshot
    Image source: https://www.takealot.com/paco-rabanne-lady-million-edp-30ml-for-her-parallel-import/PLID15206077

    Trade Marks Act 194 of 1993

    In terms of the Trade Marks Act, as long as the goods have not been altered or interfered with, a distributor may still comply with the provisions of the CPA and the Trade Marks Act.

    However, goods that bear a registered trade mark and which have been altered or interfered with cannot be defined as grey goods or parallel imports as they are no longer genuine goods, in the strict sense. Considering that these altered goods are no longer genuine, the importation and sale of these goods would not be permissible under South African law as they would fall within what is considered to be trade mark infringement, thus violating the Trade Marks Act 194 of 1993.3

    In terms of the Counterfeit Goods Act 37 of 1997 (“the CGA”), any interested person may lay a complaint with an inspector relating to a consignment which is suspected to contain counterfeit goods.4

    The customs authorities and police may also enforce Section 113 of the Customs and Excise Act 91 of 1964, which allows goods to be stopped to ensure that they are not counterfeit.5

    References:

    1. https://www.golegal.co.za/parallel-importation-black-friday/
    2. https://www.gov.za/documents/consumer-protection-act
    3. https://www.gov.za/documents/trade-marks-act
    4. https://www.gov.za/documents/counterfeit-goods-act
    5. https://www.gov.za/documents/customs-and-excise-act-31-jul-1964-0000
  • Clickwrap Agreements

    Clickwrap Agreements

    Have you also done it? Briskly skimming through the terms and conditions or not bothering to read them at all before blindly clicking “I agree”. This is not uncommon, however, we put ourselves at risk by signing away various rights over what happens to our personal data; namely, how platforms collect, use, store and share our personal information. In some cases, one might even be waiving their intellectual property rights.

    These agreements are termed clickwrap (also known as click-accept, click-to-sign, or clickthrough) agreements. A clickwrap agreement is defined as “an online agreement that users agree to by clicking a button or checking a box that says “I agree.” The act of signing via an electronic signature is replaced with the act of clicking.”1 Therefore, it is important to note that when you click “I agree” on these documents, your approval is legally binding.

    Terms and conditions are created to serve the best interests of the company by explaining what the rules are for customers when using their service. Whereas a privacy policy explains to users how their data will be collected, stored and used by the company and any third parties or affiliates. It is important to pay attention, particularly to areas in the document which pertain to matters such as granting a company the right to sell your personal information to third parties, monitor your movements using location tracking and GPS, or track your device identifiers such as your device’s IP address.2

    Another common agreement is an End User License Agreement (EULA), which is also referred to as a software license. A EULA is an agreement which grants the purchaser the right to use the developer or publisher’s software after they have purchased it. The main issues which discourage the careful review of these agreements are the length of the document and the complicated wording, and legal and technical jargon which might deter the layman.

    The Cybersecurity & Infrastructure Security Agency (CISA), has highlighted the following recommendations for protecting oneself from the security and privacy problems associated with EULAs:

    • Read the EULA before you install the software. It can be tedious, but reading the agreement is the only way to know exactly what privacy and security risks you might be taking by agreeing to the EULA.
    • Consider the software publisher. If you are unfamiliar with the publisher, carefully review the EULA covering its software.
    • Beware of firewall prompts when installing software. Take caution when firewall prompts request permission for certain traffic to pass. Review the EULA to find out why this traffic must be allowed and whether you wish to allow it.
    • Beware of free software, especially peer-to-peer (P2P) file-sharing software. “Rarely is anything truly free.” Review the EULA to find out what actions are required of you or permissions to be granted in exchange for using the software, and evaluate what impact this might have on the security of your computer and personal information.3

    It is never wise to sign anything that you have not read and thoroughly understand. It is advisable to always read a document or agreement prior to signing, agreeing to, or acknowledging that you have read the contents within.

    As stated by CISA: “While you might incur a half hour of boring reading, doing so can spare you security and privacy headaches.”3

    References:

    1. https://ironcladapp.com/journal/contract-management/what-is-a-clickwrap-agreement/
    2. https://www.usatoday.com/story/tech/2020/01/28/not-reading-the-small-print-is-privacy-policy-fail/4565274002/
    3. https://www.cisa.gov/sites/default/files/publications/EULA.pdf
  • Cybersecurity: Whose Responsibility Is It?

    Cybersecurity: Whose Responsibility Is It?

    The world has changed drastically in the past three years; with the COVID-19 pandemic speeding up the process. The number of people working from home has increased significantly, in fact, the ability to work remotely is now used by some companies as an incentive to attract talent.1

    With remote work being at an all-time high, people communicate a lot via emails and other applications designed to facilitate remote work. Individuals and companies send invoices for services rendered by email. This practice has opened a window of opportunity for cybercriminals to intercept these communications and dupe people into paying funds into the criminal’s bank account rather than into the service provider’s bank account. This is known as business e-mail compromise (BEC) fraud.2 Other types of cyberattacks include hacking, phishing and spear-phishing, ransomware, and fake law firm websites.2

    With the aim of protecting both natural and juristic persons from such data breaches, South Africa promulgated a few laws. In 2020, South Africa already had policies and frameworks in place to regulate activities occurring in cyberspace. Statutes such as the Consumer Protection Act, 2008 (CPA), Promotion of Access to Information Act 2 of 2000 (PAIA) and Protection of Personal Information Act 4 of 2013 (POPIA) are some of the Acts that were promulgated to reinforce people’s right to privacy and ultimately, reduce the occurrence of data breaches.

    Unfortunately, even with these measures in place, cybercrime is ever evolving and cyberattacks are on the rise. A recent case involving cybercrime is that of Fourie v Van der Spuy and De Jongh Inc and Others 2020 (1) SA 560 (GP). In this case, the Applicant (Fourie) claimed the payment of R1 744 599.45 from the Respondents.3 This amount was paid over to the trust account of the 1st Respondent (a law firm representing the applicant) for the benefit of the Applicant. The 2nd Respondent (a partner at the law first listed as 1st Respondent) rendered services to the Applicant and was instructed to retain the funds until such time that the Applicant gave further instructions of what should be done with the money.3

    Eventually, the Applicant sent instructions for the 2nd Respondent to pay the abovementioned amount back into the account of the Applicant. The 2nd Respondent made the payment but unbeknownst to her, a hacker intercepted the Applicant’s emails and sent the 2nd Respondent their own banking details. Consequently, when the 2nd Respondent paid the amount, it was actually paid into the bank account of the hacker and not the Applicant. The 2nd Respondent argued that they had already made the payment and were not liable to pay the Applicant again. However, the judge stated that “The 2nd Respondent was negligent and failed to exercise the requisite skill, knowledge and diligence expected of an average practising attorney and thus failed to discharge her fiduciary duty to the Applicant by transacting via e-mail whilst full-well knowing that fraud is prevalent in her profession and not employing any measures to ensure that neither she, nor the Applicant will fall victim to fraud.”3

    The judge further stated that the “2nd Respondent has failed to discharge her obligation to the Applicant to pay him. The 2nd Respondent’s defence that a fraud occurred that released her from paying the Applicant is no defence as she is as principal obliged to account to the applicant for the funds, a duty 2nd Respondent thus far has failed to discharge. It is irrelevant that emails similar to that of the Applicant was sent to her, the common law position pertaining to trust funds as set out above is clear. The duty of care, owed to a client and the mandate to pay as principal, point to the attorney as the one who, in this case, is liable.3 The court ordered the 1st and 2nd Respondents to pay R1 744 599.45 to the Applicant. In this case, the court placed the responsibility of vigilance against cybercrime squarely on the shoulders of the partner of the law firm (2nd Respondent). It is thus crucial for companies to employ risk mitigation measures to prevent such incidences from occurring.

    In a similar case, Hawarden (the plaintiff) put in an offer for R6 million to purchase a house, she paid a deposit of R500 000 to the estate agency.4,5 The conveyancer that was hired by the seller was ENS Inc. Hawarden received an email purporting to be from a conveyancing secretary at ENS which also included bank account details into which Hawarden was supposed to deposit the rest of the funds. Unfortunately, the email was from a hacker and not the ENS conveyancing secretary. The hacker had intercepted the secretary’s email and replaced the firm’s banking details with their own.4,5 This is very similar to the earlier case of Fourie v Van der Spuy and De Jongh Inc. Even after this cybercrime was discovered, ENS asked Hawarden to make a payment to secure the sale of the property.4,5

    The judge stated that “ENS was at fault on the basis of negligent conduct. I am not inclined to agree with submissions made by counsel on behalf of ENS that Ms Hawarden must take responsibility for her failure to protect herself against the known risk of relying on banking details received by email. The defendant was an expert conveyancer and was facilitating and managing the transaction. Under these overall circumstances it not overly burdensome or unreasonable to impose liability on ENS. The risk of loss to Ms Hawarden was highly foreseeable by ENS. There is no risk of boundless liability as feared by ENS as the loss in this case is claimed by a single plaintiff and is finite in its extent. It is, accordingly, not unlimited or indeterminate.”4

    The judge further stated that “The interests of the defendant as well as the society demand that a legal duty is recognised in this case. ENS is best placed to understand and prevent BEC. Individuals in society are generally not as well-placed to respond to the ever-evolving threat of cybercrime, which is sophisticated and technical in nature.”4 In these two cases that we have discussed, the court placed the responsibility of cybersecurity on the law firms. This is a cautionary note for all businesses to be hypervigilant and to ensure that they do everything possible to prevent their clients from falling victim to cybercriminals. A heavier burden of proof will be placed on businesses to show that they have attempted everything reasonably possible to prevent the cybercrime from happening before this responsibility will be discharged by the courts.

    Attorneys in particular have been targeted by cybercriminals. In 2017, a Risk Alert was released which warned practitioners about cybercrimes. It read “Cyber related risks are on the increase and attorneys must: ensure they have adequate risk mitigation/avoidance measures in place to deal with cyber related risks”.3 Attorneys pay professional indemnity insurance to insure against liability that may arise from the professional conduct as a practitioner.6 The risk alerts that the insurer issued have seemingly gone unheard as they have received 137 cybercrime claims since 2016.3 The insurer implemented a cybercrime exclusion clause in 2016. The clause reads “This policy does not cover any liability for compensation…arising out of cybercrime…”6

    Here are suggested steps that one can take to mitigate the risks of BEC and other cybercrimes:

    1. Have systems to verify banking details.
    2. Employing the services of a cyber risk specialist and conducting regular vulnerability assessment.
    3. Educating everyone in the organisation on cyber scams.
    4. Educate your clients about cybercrimes.
    5. Try and avoid sending sensitive information such as banking details via email. Out of interest, this is what the judge had to say in the Fourie case “Perhaps a time will come when monies will be transferred in the presence of a client, client will have to waive the nicety of EFT’s being done without client being present, alternatively client being phoned…”2 The judge also remarked that perhaps it is about time that attorneys inform clients that they will not accept change in banking details via email.
    6. Obtaining cyber insurance cover.2,5

    It goes without saying that one must scrutinise emails with sensitive information because in some cases, you may be able to tell when an email is fraudulent. For example, in the Hawarden matter, the cybercriminal had misspelled the ENS email address so instead of @ensafrica.com, they used @ensafirca.com.5 The change is very subtle but by looking very carefully at the details of one’s email, the occurrence of cybercrime could be reduced. Though the courts places responsibility on firms to protect clients from cybercriminals, ultimately, cybersecurity is the responsibility of everyone. All of us must exercise vigilance against cyberattacks, and use recommended measures to protect ourselves.

    References:

    1. https://www.uschamber.com/co/grow/thrive/what-is-a-digital-nomad
    2. https://www.derebus.org.za/ongoing-cybercrime-threats/
    3. https://www.saflii.org/za/cases/ZAGPPHC/2019/449.html
    4. https://www.saflii.org/za/cases/ZAGPJHC/2023/14.html#:~:text=Held%20that%2C%20a%20duty%20of,that%20pdf%20attachments%20to%20emails
    5. https://www.masthead.co.za/recent-cybercrime-judgment-impacts-businesses-that-email-bank-details-learn-how-to-protect-yourself-and-your-clients/
    6. https://lpiif.co.za/wp-content/uploads/2023/07/Professional-Indemnity-Policy-2023-2024.pdf

  • Combating Data Breaches in South Africa

    Combating Data Breaches in South Africa

    Artificial intelligence (AI) systems collect an unimaginable amount of data for the use of training algorithms and improving performance. This data also includes personal information (names, addresses, and financial information), and sensitive information (medical records and identification numbers).1 There are concerns regarding the collection and processing of this data and how it is used as well as who has access to it. This vast amount of data can be easily misused by cybercriminals to steal a person’s identity.

    With the aim of protecting people against such data breaches, South Africa promulgated a few laws to protect both natural and juristic persons. In 2020, South Africa already had policies and frameworks in place to regulate activities occurring in cyberspace. This was a necessary course of action due to the increase in broadband access which led to a corresponding increase in internet users.2 This in turn has led to a surge in the usage of digital technologies and processing of personal data, and subsequently, increases in cyberattacks and cybercrimes such as data breaches, identity theft and cyber fraud.

    The South African government enacted laws to supplement the existing legal framework. In June 2021, President Cyril Ramaphosa, signed the Cybercrimes Act into law. This Act criminalises certain illegal activities occurring in cyberspace. Before this, common law was used to criminalise some online activities such as loading malware on a computer, which was considered as the common law crime of malicious damage to property.2 The application of common law to criminalise certain online activities is, however limited, which is why promulgation of the Cybercrimes Act was paramount. Prior to that, the Electronic Communications and Transactions (ECT) Act was put into effect in 2002; with Chapter 13 of the Act dealing specifically with matters relating to cybercrimes.2

    Improving cybersecurity in an effort to mitigate and prevent data breaches is crucial, as the Constitution of the Republic of South Africa, 1996, states that “everyone has the right to privacy”3.  The state must secure the privacy of its citizens (both natural and juristic persons) including in cyberspace. In addition to the Cybercrimes Act and the ECT Act, there are a number of other legislative measures in place in aid of reinforcing this right through data privacy, namely:

    • The Consumer Protection Act 68 of 2008 (CPA) which applies to telephonic direct marketing of goods and services to consumers.
    • The Promotion of Access to Information Act 2 of 2000 (PAIA) which regulates access to information held by both public and private bodies.
    • The Protection of Personal Information Act 4 of 2013 (POPIA) which impacts all individuals processing personal information within the country.
    • The Information Regulator, which was specifically established for the purpose of data protection; and is responsible for the oversight and enforcement of POPIA.4

    According to the IBM Cost of a Data Breach Report, based on March 2022 to March 2023 data breaches experienced by 553 organisations globally (including 21 in South Africa); “the global average cost of a data breach reached $4.45 million in 2023…a 15% increase over the last 3 years. The average data breach cost for South African organisations reached R49.45 million in 2023…an 8% increase over the last 3 years”.5

    In South Africa, the financial sector is targeted the most, and has the highest average cost of data breaches. The Development Bank of Southern Africa, FNB, TransUnion, and Experian are among some of the organisations which have reported data breaches in South Africa. 6

    If there are reasonable grounds to believe that a data breach has occurred, and an unauthorized party has gained access to personal information; the responsible party processing said personal information is obligated to notify the Information Regulator, through the completion and submission of a Security Compromise Notification Form provided in terms of section 22 of POPIA. The responsible party must also notify the data subject thereof, in writing, as soon as reasonably possible.7

    References:

    1. https://economictimes.indiatimes.com/news/how-to/ai-and-privacy-the-privacy-concerns-surrounding-ai-its-potential-impact-on-personal-data/articleshow/99738234.cms?from=mdr
    2. https://link.springer.com/article/10.1365/s43439-023-00089-8#:~:text=These%20are%20the%20Criminal%20Procedure,Financial%20Intelligence%20Centre%20Act%2038
    3. https://www.justice.gov.za/legislation/constitution/SAConstitution-web-eng-02.pdf
    4. https://www.dataguidance.com/notes/south-africa-data-protection-overview
    5. https://www.ibm.com/reports/data-breach?_gl=1*1ydur9s*_ga*MTEzNTI2MTk1LjE2OTY5MzY0NjQ.*_ga_FYECCCS21D*MTY5NjkzNjQ2NC4xLjAuMTY5NjkzNjQ2NC4wLjAuMA
    6. https://www.itweb.co.za/content/Olx4zMkazYQv56km
    7. https://www.gov.za/sites/default/files/gcis_document/201409/3706726-11act4of2013popi.pdf
  • The AI Conundrum: AI and Cybersecurity

    The AI Conundrum: AI and Cybersecurity

    A lot of experts are talking about the Artificial Intelligence (AI) conundrum. Is it a blessing or a curse? AI is a blessing in that it makes certain jobs easier and more efficient. As an example, AI can increase productivity. An AI algorithm can predict and prevent catastrophic events like disease outbreaks and market crashes. On the other side of the coin, these AI algorithms can invade our privacy in ways we have never imagined. For instance, AI can analyse a surprisingly great amount of personal data and can draw accurate conclusions about our habits, preferences, and future actions.1 Data breaches by AI have already been demonstrated by invasion of privacy through collection and analysis of personal data every time one browses the internet.1

    Further, every time one shops online, browses a website, or even ‘likes’ a post on social media, you are leaving digital footprints. AI algorithms collect and analyse these footprints, creating a virtual profile that mirrors your real-life persona. Your personal information is the key to your virtual identity. When AI systems collect and analyse this information, they create a risk of identity theft. Cybercriminals can then misuse AI to commit fraud by stealing your identity or selling your personal data on the dark web.1

    There are of course steps that we can take to mitigate these risks. We can for instance use privacy tools and settings as stipulated in our phishing post. Where possible, one can even limit their digital footprint. Government also has a role to play in the protection of internet users. In South Africa, we have the Protection of Personal Information Act (POPIA) No. 4 of 2013 which is our data protection law. In Europe, there is the General Data Protection Regulation (GDPR) 2016/679, the European Union’s data protection regulation.

    References:

    1. https://www.linkedin.com/pulse/unmasking-beast-incredible-risk-personal-privacy-ai-how-jayaraman/
  • Gone Phishing

    Gone Phishing

    We would be remise if we highlighted cybersecurity awareness without delving deeper into phishing. We have all received notifications from our banks or even employers warning us against phishing attacks. What is phishing exactly?

    Phishing is a cybercrime in which a target or targets are contacted by email, telephone or text message by someone posing as a legitimate institution to lure individuals into providing sensitive data such as personally identifiable information, banking and credit card details, and passwords.1

    The data obtained from such an attack is then used to access essential accounts and often leads to identity theft and loss of finances. This cybersecurity awareness month, we’d like to draw your attention to common features of phishing emails or SMSes to avoid falling into the traps of cybercriminals:

    1. Too Good to Be True – Lucrative offers and eye-catching or attention-grabbing statements are designed to attract people’s attention immediately. For instance, many claim that you have won an iPhone, a lottery, or some other lavish prize. Do not click on these suspicious emails.
    2. Sense of Urgency – A favourite tactic amongst cybercriminals is to ask you to act fast because the super deals are only for a limited time. Some of them will even tell you that you only have a few minutes to respond. Should you encounter such an email or message, it is best to ignore it. Even if the message says that your account will be suspended if you do not respond, do not click on any links. Your bank or any other service provider will never ask you to provide sensitive information via email or SMS.
    3. Hyperlinks – A link may not be all it appears to be. Hovering over a link shows you the actual URL where you will be directed upon clicking on it. It could be completely different or it could be a popular website with a misspelling, for instance www.standabank.co.za – the ‘rd’ is missing, so look carefully.
    4. Attachments – If you see an attachment in an email you were not expecting or that does not make sense, do not open it! They often contain payloads like ransomware or other viruses. The only file type that is always safe to click on is a .txt file.
    5. Unusual Sender – Whether it looks like it is from someone you do not know or someone you do know, if anything seems out of the ordinary, unexpected, out of character or just suspicious in general – do not click on it!1

    Here are some tips on how to prevent phishing attacks:

    • To protect against spam mails, spam filters can be used. Generally, the filters assess the origin of the message, the software used to send the message, and the appearance of the message to determine if it is spam. Occasionally, spam filters may even block emails from legitimate sources, so it is not always 100% accurate, so check your spam folder regularly.
    • The browser settings should be changed to prevent fraudulent websites from opening. Browsers keep a list of illegitimate websites and when you try to access the website, the address is blocked or an alert message is shown. The settings of the browser should only allow legitimate websites to open up.
    • Many websites require users to enter login information while the user image is displayed. This type of system may be open to security attacks. One way to ensure security is to change passwords on a regular basis, and never use the same password for multiple accounts. It is also a good idea for websites to use a CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart): A category of technologies used to ensure that a human is making an online transaction rather than a computer)2 system for added security.
    • Banks and financial organisations use monitoring systems to prevent phishing. Individuals can report phishing to industry groups where legal actions can be taken against these fraudulent websites.
    • Changes in browsing habits are required to prevent phishing. If verification is required, always contact the company personally before entering any details online.
    • If there is a link in an email, hover over the URL first. Secure websites with a valid Secure Socket Layer (SSL) certificate begin with “https”.1

    South Africa has the Cybercrimes Act 19 of 2020 that aims to prevent cybercrimes and malicious communications, including provisions that address Unlawful access to, interception of, and interference with data or computer programs and systems.3 Contravention of the provisions of the Act can result in a hefty fine or even imprisonment.

    References:

    1. https://www.phishing.org/what-is-phishing
    2. https://www.pcmag.com/encyclopedia/term/captcha
    3. https://cybercrime.org.za/law#:~:text=The%20Cybercrimes%20Act%2019%20of,or%20computer%20programs%20and%20systems 
  • X Marks the Spot… A Tale of Two Trade Marks

    X Marks the Spot… A Tale of Two Trade Marks

    X Corp, formerly known as Twitter is being sued by a Florida based advertisement agency, X Social Media LLC for the violation of Florida common law due to “unfair competition and trademark service mark infringement”.1 X Social Media, filed a trade mark “X Social Media” on 17 January 2018 and it was officially registered on 04 September 2018.2 The company has claimed to have invested over $2 million in building the brand and reaching consumers.1 They claim to have already suffered revenue losses correlating to when Twitter rebranded to X Corp and started using the X mark.

    X Corp could have faced even more lawsuits against it as Meta (Facebook) had applied for the registration of their own “X” logo (depicted below).2 Meta filed the application on 25 May 2017 with the US Patent and Trademark Office (USPTO).3 However, in April 2019, the mark was officially abandoned.3

    As a reminder, according to the South Africa’s Trade Marks Act No. 194 of 1993, a trade mark is considered to be registrable if it is “capable of distinguishing the goods or services of a person in respect of which it is registered or proposed to be registered from the goods or services of another person either generally or, where the trade mark is registered or proposed to be registered subject to limitations, in relation to use within those limitations.”4 A mark that is, as a result of the manner in which it has been used, would be likely to cause deception or confusion is not considered as a registrable mark.4

    It will be interesting to see how this matter unfolds and whether or not X will remain X Corp or will be forced to rebrand.

    References:

    1. https://www.independent.co.uk/tech/musk-x-twitter-sued-social-network-b2422811.html
    2. https://www.foxbusiness.com/technology/meta-trademark-x-logo-may-pose-legal-issues-twitter-musk-company-rebranding
    3. https://tmsearch.uspto.gov/bin/showfield?f=doc&state=4804:28457j.2.1
    4. https://www.gov.za/sites/default/files/gcis_document/201409/act194of1993.pdf
  • The Metaverse and Intellectual Property Rights

    The Metaverse and Intellectual Property Rights

    The metaverse is considered to be the next evolution of the Internet, with the potential to unlock a completely new digital economy. But what is the metaverse?

    The metaverse is a virtual universe or virtual environment where people can interact, connect and engage in economic activities through self-assumed characters known as avatars. This virtual universe is commonly experienced through virtual reality (VR) headsets and accessories1. Individuals can also experience events such as Metaverse Fashion Week from the comfort of their homes.

    The adoption of the metaverse opens up a new world of various cybersecurity risks and privacy issues. One of the core pillars of building trust in the digital sphere, is cybersecurity. The metaverse raises concerns over issues such as identity spoofing or impersonation attacks, hacking and the misuse of user data.

    Identity spoofing constitutes a cybersecurity concern for the metaverse and occurs when a scammer assumes the identity of another person or business and uses said identity to commit fraud. These spoofers steal identities through password attacks and credential capture processes2. The most common forms of identity spoofing include IP spoofing wherein the source or destination of a virtual message traces back to an IP address associated with a physical location2. Many systems do not implement authentication protocols. For that reason, the masked IP address takes the place of the legitimate source without the legitimate sender or recipient’s knowledge2. Another form of spoofing is Caller ID spoofing wherein spoofers forge caller ID information, presenting false names or numbers and assuming the identity of a particular person or organisation. And of course, there is e-mail spoofing, where the sender information in the “From” section of an email can be spoofed to hide the origin of fraudulent emails. One of the consequences of spoofing is phishing, which is when the spoofer attempts to capture sensitive information from a person2.

    It is prudent for companies contemplating entering into this space to have a well-thought-out legal strategy. Companies such as Nike, have filed several trade mark applications in the United States Patent and Trademark Office pertaining to the metaverse, in particular, selling virtual branded sneakers and apparel3.

    Intellectual property rights (IPR) play a key role in safeguarding the ownership and use of virtual goods such as avatars, designs and music. The metaverse also allows for the extension of brand recognition for trade mark holding companies.

    References:

    1. https://www.techtarget.com/searchsecurity/tip/Top-metaverse-cybersecurity-challenges-to-consider  
    2. https://fraud.net/d/identity-spoofing/
    3. https://www.cnbc.com/2021/11/02/nike-is-quietly-preparing-for-the-metaverse-.html#:~:text=Nike%20has%20filed%20seven%20trademark,virtual%20branded%20sneakers%20and%20apparel
  • Online Piracy

    Online Piracy

    For years, online piracy has continued to plague intellectual property rights. The main sources of online piracy are the consumption of pirated TV content, the unlawful streaming and downloading of movies, music, publications and software1.

    A study conducted by the European Union Intellectual Property Office (EUIPO), in 2022, found that in Europe, publications piracy was the second most significant form of piracy, preceded by TV piracy. The study found that, publication piracy “accounted for 28% of illegal consumption – a remarkable 60% of which was of Manga comics.”1

    Movies and TV content are usually pirated through illegal streaming. But what about peer-to-peer sharing?

    Peer-to-peer sharing platforms are commonly known as torrents or file sharing platforms. In South Africa, file sharing of copyrighted material is illegal as this violates the copyright holder’s intellectual property rights, and could lead to criminal penalties. The Film and Publications Board (FPB), established by the Films and Publications Act 65 of 1996, has published industry codes and guidelines related to digital and peer-to-peer platforms in South Africa, which highlight some of the following considerations:

    • “Copyright and intellectual property (ensure you have the proper permissions to share the content)
    • Privacy of individuals (including personal information, consent, and ensuring third parties cannot access shared information)
    • Ensure the content is lawful (avoiding harmful content particularly to children)”.2

    These guidelines aim to affirm the democratic values of human dignity, equality and freedom as set out in the Constitution of South Africa. Pirating online content is illegal and can lead to a hefty fine or imprisonment in accordance with Copyright Act 98 of 1978. Additionally, pirated content is also potentially dangerous, as it is often riddled with viruses and malware.

    References:

    1. https://euipo.europa.eu/tunnel-web/secure/webdav/guest/document_library/observatory/documents/reports/2023_online_copyright_infringement_in_eu/2023_online_copyright_infringement_in_eu_FullR_en_en.pdf
    2. https://mybroadband.co.za/news/wp-content/uploads/2023/08/FPB-draft-regulations-and-guidelines-18-August-2023.pdf