As a Silicon Valley corporate attorney, I work with a lot of Internet law and cyberspace law issues and am often asked by businesses to make sure their websites keep them free from trouble. Whether you are a large, multi-national corporation, a mid-size company, or a small business owner, chances are you run and operate a commercial website. One way to minimize the risk that comes from operating a commercial website is to create the conditions, sometimes called Terms of Use, that govern a visitor’s use of the site. A court decision in September, however, found that website terms could be invalid and therefore fail to provide any protection to website operators. Because the court is located in the federal district that includes California, it is a critical decision that affects California website operators.
The case, In re Zappos.com Inc., Customer Data Security Breach Litigation, 2012 WL 4466660 (D. Nev. Sept. 27, 2012) arises out of Zappos’ customer data security breach in January of this year. As is typical in a data breach situation, Zappos notified all persons whose personally identified information may have been compromised. When the inevitable lawsuit was filed, Zappos attempted to enforce an arbitration clause in the Terms of Use found on its website. A federal court in Nevada said “not so fast”.
Some background is helpful. Terms of Use are often created with little thought, and can often be changed at any time by the website operator. They typically are submitted as a “browse-wrap” agreement, which, unlike a “click-wrap” agreement, does not require the user to click on a box to confirm the user’s consent to the agreement. Browse-wrap agreements are usually referenced with an inconspicuous link at the bottom of a home page.