Skip to main content

Scaling and Innovation Culture

The Business Law Playbook Series — Playbook 3: Intellectual Property, Privacy & Internet Law

The Business Law Playbook Series —

Playbook 3: Intellectual Property, Privacy & Internet Law

Last Verified: 2026-09-08 | Author: Kateule Sydney | Published by Kat-Syd Resources Hub
Digital network of interconnected nodes representing data protection, IP rights, and internet law
Intellectual property, privacy, and internet law represent the intersection of common law rights and emerging digital challenges

Summary: Playbook 3 examines the intersection of intellectual property, privacy, and internet law under common law and statutory frameworks. It covers patents, copyright, trademarks, trade secrets, passing off, the right to privacy, data protection and the GDPR, digital contracts, social media and employee conduct, and the Communications Decency Act § 230 — a provision that has been interpreted to create sweeping immunity for online platforms.

Chapter 1 — Introduction to Intellectual Property

1.1 Defining Intellectual Property

Intellectual property law protects creations of the mind through patents, copyrights, trademarks, and trade secrets. The common law has long recognized a property right in trademarks, and this right was not created by statute and does not now depend upon it for its enforcement.

The statutory intellectual property regimes include:

  • Patents — Protecting inventions and discoveries
  • Copyright — Protecting original works of authorship
  • Trademarks — Protecting source-identifying marks
  • Designs — Protecting ornamental designs

In practice, multiple IP rights often overlap with respect to the same underlying subject matter. This overlap requires practitioners to consider how these rights work together, facilitating a deeper understanding of how and when they may be encountered in practice.

1.2 Common Law Foundations

The common law protection of intellectual property has deep roots. The tort of passing off protects business goodwill from misrepresentation. The protection of representational rights of trade designations, branding, and character merchandising through the statutory misleading conduct action and the common law passing off action in tort is also covered as is the protection of business goodwill through restraint of trade covenants.

The common law also protects confidential information and trade secrets. This protection arises from a duty of confidence when information is entrusted in circumstances where the recipient is relied upon to keep the confidence.

Chapter 2 — Patents and the America Invents Act

2.1 Types of Patents

Patents protect inventions and discoveries, granting limited monopoly rights that encourage research and development, intangible asset creation, and entrepreneurship.

  • Utility Patents — Protect processes, machines, articles of manufacture, and compositions of matter
  • Design Patents — Protect ornamental designs for manufactured items
  • Plant Patents — Protect asexually reproduced distinct plant varieties

The overlap between patent and design protection, patents and trade secrets, and interfaces in plant intellectual property are areas of particular legal complexity.

2.2 The America Invents Act

The America Invents Act (AIA) of 2011 changed U.S. patent law from a "first to invent" to a "first inventor to file" system. This shift aligned U.S. law with international patent systems and introduced new procedures for challenging patent validity.

The AIA also established the Patent Trial and Appeal Board (PTAB) and created new post-grant review procedures, fundamentally changing the landscape of patent enforcement and litigation.

Chapter 3 — Copyright Law and Fair Use

3.1 Copyright Protection

Copyright protects original works of authorship fixed in any tangible medium of expression. This includes literary, dramatic, musical, and artistic works, as well as software and digital content.

In practice, copyright often overlaps with other IP rights, particularly in the context of character merchandising and design. When copyright and trademark rights overlap, courts must carefully navigate the interface between these distinct regimes.

3.2 The Fair Use Doctrine

The fair use doctrine allows limited use of copyrighted material without permission for purposes such as criticism, comment, news reporting, teaching, scholarship, or research. Courts consider four factors:

  • The purpose and character of the use
  • The nature of the copyrighted work
  • The amount and substantiality of the portion used
  • The effect of the use on the potential market

Fair use is a flexible, case-by-case doctrine that balances the interests of copyright holders with the public interest in access to information.

Chapter 4 — Trademarks and Service Marks

4.1 Common Law Trademark Rights

Trademarks distinguish goods, while service marks distinguish services. At common law, the exclusive right to a mark grows out of its use, and not its mere adoption. Protection is based on priority of appropriation — the first user obtains rights, regardless of novelty, invention, discovery, or any "work of the brain."

This principle was established in the leading case of Spalding v. Gamage, where the House of Lords held that protection is afforded to the goodwill in the business likely to be injured by the misrepresentation. The action protects property not in the mark, name, or get-up improperly used by the defendant, but rather the property in the business or goodwill likely to be injured by the misrepresentation.

4.2 The Ace Brand Principle

The consequences of the common law approach are well illustrated by the Ace Brand case. The plaintiff had an established reputation in "Ace Brand" for toothbrushes sold in Singapore. After a change in import duties, the plaintiff abandoned its business there under the mark. Three years later, it purported to grant an exclusive license of the mark to a part-owned subsidiary. After a further two years, it sought an injunction to restrain another concern from adopting the mark "Age" for toothbrushes. The Judicial Committee of the Privy Council held that, at the very least, the attempted license showed a final abandonment of any residual goodwill in the mark. The plaintiff had no entitlement to sue for passing off thereafter merely because it stood to lose royalties under the license.

Chapter 5 — Trade Secrets and the Defend Trade Secrets Act

5.1 Protection of Confidential Information

Trade secrets include formulas, patterns, compilations, programs, devices, methods, techniques, or processes that derive independent economic value from not being generally known. Protection arises from a duty of confidence when information is entrusted in circumstances where the recipient is relied upon to keep the confidence.

The common law protection of confidential information and trade secrets is a well-established area of law. The duty of confidence is also recognized in the biomedical context, where it interfaces with modern data protection frameworks.

5.2 The Defend Trade Secrets Act

The Defend Trade Secrets Act of 2016 (DTSA) created a federal civil remedy for trade secret misappropriation. The DTSA allows trade secret owners to bring claims in federal court and seek remedies including injunctions and damages. The Act also provides for ex parte seizure orders in extraordinary circumstances.

Chapter 6 — Unfair Competition and Passing Off

6.1 The Tort of Passing Off

The tort of passing off protects business goodwill from misrepresentation. It occurs when a defendant makes, in the course of trade, a false representation calculated to deceive customers in a way likely to damage the claimant's goodwill. There is no need to prove an intention to harm; the focus is on the likely effect of the misrepresentation.

In the classic formulation from Erven Warnink v. Townend, the House of Lords established that passing off requires a misrepresentation made by a trader in the course of trade to prospective customers, calculated to injure the business or goodwill of another trader, and resulting in actual damage or a likelihood of damage.

6.2 The Plaintiff's Reputation

The first thing that a plaintiff in a passing-off case must show is that he has a reputation with the public. There must accordingly be something about his conduct of affairs which causes the public to seek out his goods or services rather than those of competitors. Protection is not confined to badges of recognition of any particular kind, such as trademarks or business names. Distinctive get-up in bottling or packaging can suffice.

British courts have been reluctant to find that an exclusive reputation has been proved in a functional shape, though they have protected distinctive packaging and get-up when it serves as a badge of origin.

Chapter 7 — International Intellectual Property Protections

7.1 International IP Treaties

International treaties protect intellectual property across borders:

  • The Berne Convention — Protects copyright works internationally, establishing automatic protection without formal registration
  • The Paris Convention — Protects patents and trademarks, providing national treatment and priority rights
  • The TRIPS Agreement — Sets minimum standards for IP protection under the WTO, integrating IP into international trade law

While the focus of many IP regimes is on UK, US, and European law, comparison tables of overlapping IP rights in other countries offer a detailed overview as to how these overlaps apply in different legal jurisdictions, as well as how they differ.

7.2 Cross-Border Enforcement

Enforcing intellectual property rights across borders presents significant challenges. The exploitation of IPRs through licensing and technology transfer arrangements, and the protection of IPRs internationally, requires careful consideration of jurisdictional issues and the varying standards of protection in different countries.

International arbitration and dispute resolution mechanisms are increasingly important for cross-border IP disputes.

Chapter 8 — The Right to Privacy and Business Surveillance

8.1 Common Law Privacy Protections

The common law recognizes a right to privacy, with remedies for breach of confidence and misuse of private information. Researchers have argued that policy-makers should rely on the common law to govern questions of data privacy because its case-by-case, evolutionary nature is more likely to provide a sustainable and adaptive framework to approach difficult questions.

In the biomedical context, the common law duty of confidentiality has experienced rapid development in the 21st century, particularly with the push for Big Data research and the digitisation of society. This area of law explores the interplay between UK data protection law, the common law duty of confidentiality, and wider frameworks in Europe and at the international level.

8.2 Privacy in the Digital Age

Privacy rights have not evolved as economic rights, but scholars argue that the common law has resources to deal with modern privacy challenges. Property rights in data, joint ownership, and concurrent estate ownership concepts familiar in the context of tangible resources can be mapped onto joint production of intellectual resources.

The common law also addresses the issue of possession in the digital context. Courts have found that accessing someone's digital data can deprive them of their possessor interest, recognizing it as a property interest.

Chapter 9 — Data Protection and Cybersecurity Regulations

9.1 Data Protection Frameworks

Data protection laws impose obligations on businesses handling personal information. Regulatory frameworks address:

  • Collection, use, and disclosure of personal data
  • Consent requirements
  • Data security and breach notification
  • Individual rights of access and correction

In the UK, the Data Protection Act 2018 and the UK GDPR set the primary legal standards. In the United States, a patchwork of sectoral laws and state regulations create a more fragmented landscape.

9.2 Cybersecurity Obligations

Businesses must implement appropriate technical and organizational measures to protect personal data. Failure to do so can result in regulatory investigations, fines, and reputational damage.

Common law principles also impose duties on businesses to safeguard customer information, and breach of these duties can give rise to tort liability.

Chapter 10 — The General Data Protection Regulation (GDPR)

10.1 Scope and Application

The GDPR applies to organizations processing the personal data of EU residents, regardless of where the organization is located. It establishes:

  • Strict consent requirements
  • Mandatory data breach notification
  • Significant fines for non-compliance
  • Enhanced rights for data subjects

The asserted jurisdiction of the GDPR is broad. It applies to any controller of data or processor of data who has an establishment in the EU and processes personal data in the course of its activities. It also applies where a controller or processor has no EU presence if it is monitoring the behavior of individuals in the EU or offering goods or services within the EU.

10.2 Lawful Grounds for Processing

Under the GDPR, data controllers must establish a lawful ground for processing personal data. The most common lawful ground for legal professionals and investigators is the legitimate interests ground.

To rely on legitimate interests, controllers must satisfy three tests:

  • The purpose test — A legitimate interest must be identified
  • The necessity test — The processing is necessary to achieve that interest
  • The balancing test — The interests of the data subject must be balanced against the legitimate interests pursued
10.3 Critiques of the GDPR

Some researchers have argued that the GDPR helps demonstrate why regulatory approaches toward property rights over data are unlikely to be effective. Proposed in 2012 and finalized in 2016, the GDPR reflects the prevailing technologies and concerns of the time in which it was developed.

Since the adoption of the GDPR, there have been dramatic changes in technology, data use, and the social and political consequences of information disclosure. Rigid regulatory frameworks risk either locking in anachronistic approaches to privacy protections or failing to tackle new and unanticipated problems.

Chapter 11 — Digital Contracts and Clickwrap Agreements

11.1 Enforceability of Digital Contracts

Digital contracts, including clickwrap agreements, are generally enforceable under common law contract principles. Users demonstrate acceptance by clicking "I Agree" or using the service after notice of terms.

Courts have consistently enforced clickwrap agreements when the user is presented with clear notice of the terms and an opportunity to review them before accepting. The key requirements are mutual assent, consideration, and a meeting of the minds.

11.2 Browsewrap vs. Clickwrap

Courts distinguish between clickwrap agreements, where the user explicitly clicks "I Agree," and browsewrap agreements, where terms are posted on the website without active acceptance. Clickwrap agreements are more likely to be enforced because they provide clearer evidence of assent.

Businesses should ensure that their digital contracts provide clear notice of terms and obtain active, affirmative consent from users.

Chapter 12 — Social Media and Employee Conduct

12.1 Employer Rights and Responsibilities

Employers may discipline employees for social media misconduct, but must balance rights under labor laws and protection of legitimate business interests. The duty of fidelity owed by an employee not to disclose trade secrets derives from the contract of employment.

Employers should have clear social media policies that define acceptable behavior, protect confidential information, and address the potential for reputational harm.

12.2 Balancing Interests

Courts have recognized that employers have a legitimate interest in protecting their reputation and confidential information, but employees also have privacy rights and freedom of expression. The law requires a careful balancing of these competing interests.

In the digital age, the boundaries between personal and professional conduct have blurred, making it essential for both employers and employees to understand their rights and obligations.

Chapter 13 — The Communications Decency Act (CDA) § 230

13.1 The Origins and Purpose of Section 230

Section 230 of the Communications Decency Act was originally designed to encourage web-related defendants to self-regulate by shielding "Good Samaritan" websites from liability. Courts have interpreted the section broadly, creating almost complete civil immunity for interactive computer services for the statements of their users, regardless of whether they would have been publishers or distributors at common law.

Despite the good intentions behind Section 230, the broad immunity that it has provided has prevented holding internet companies accountable for their wrongful behavior, including not only defamation, but also conduct such as malicious catfishing.

13.2 Section 230 in Practice

Section 230(c)(1) states that no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider. Courts have uniformly treated internet platforms as publishers under Section 230(c)(1), and thus immune, whenever a plaintiff's claim stems from the platform's publication of information created by third parties.

This expansive understanding requires dismissal of claims against internet companies for failing to warn consumers of product defects or failing to take reasonable steps to protect their users from the malicious or objectionable activity of other users. As Justice Thomas noted in a statement respecting denial of certiorari, it is hard to see why the protection Section 230(c)(1) grants publishers against being held strictly liable for third parties' content should protect platforms from liability for their own acts and omissions.

13.3 Reform Proposals

For at least fifteen years, commentators have proposed amending Section 230, but Congress has yet to take action beyond one limited exception. Recent political attention to Section 230 provides an opportunity for reform.

One proposed reform is to apply the actual malice standard to torts committed by online platforms in a distributor capacity. This would hold platforms accountable for egregious harm involving knowledge or reckless disregard for the truth, while protecting them from overly burdensome liability. The actual malice standard would be applied to torts beyond defamation, including conduct such as malicious catfishing.

Chapter 14 — Online Defamation and Liability of Platforms

14.1 Platform Liability Under Common Law

Platform liability for online defamation is limited by CDA § 230, but exceptions exist for federal criminal offenses, state laws consistent with § 230, and federal intellectual property laws. A platform may be liable for defamation if it creates the content or removes immunity through the "knowing" test.

In the U.S., Section 230 has been interpreted to provide sweeping immunity to some of the largest companies in the world. The Texas Supreme Court in Doe v. Facebook held that §230 bars common-law claims against platforms, even when a plaintiff alleges the platform "knows its system facilitates human traffickers" but has failed to take any reasonable steps to mitigate the use of the platform for trafficking.

14.2 International Approaches

Unlike in the U.S., where Section 230 shields tech platforms from liability for user posts, there is no direct equivalent in many common law jurisdictions, meaning platforms could be treated as publishers by courts in those countries. In Nigeria, for example, platforms may be fully liable for defamatory content posted by users under common law defamation principles.

Platforms may try to rely on the defense of "innocent dissemination," but this legal principle is not well-established in some jurisdictions. To succeed with this defense, a tech platform must show that it was not the author, editor, or publisher of the defamatory content, that it took reasonable care regarding the publication, and that it did not know, nor had reason to believe, the content was defamatory.

14.3 Emerging Challenges: AI-Generated Defamation

An emerging challenge is the role of Artificial Intelligence (AI) in producing or intensifying defamatory content. AI-driven tools, such as chatbots, automated content generators, and deepfake technology, can create and distribute false information on a large scale. However, current legal frameworks are often silent on how liability should be attributed when AI systems produce defamatory material.

In jurisdictions like the UK, through a combination of statutory provisions and judicial precedent, courts are beginning to contend with intermediary liability and the responsibilities of online operators. The case of Starbuck v. Meta Platforms highlighted the potential for AI-generated content to cause reputational harm. The case was settled, with the plaintiff joining Meta's advisory team to improve AI accuracy and reduce bias.

FAQ

What is the difference between a trademark and a service mark?

A trademark distinguishes goods (products), while a service mark distinguishes services. Both are protected under the same legal principles, and the terms are often used interchangeably. At common law, the exclusive right to a mark grows out of its use, not its mere adoption.

What is the tort of passing off?

Passing off is a common law tort that protects business goodwill from misrepresentation. It occurs when a defendant makes a false representation in the course of trade that is calculated to deceive customers in a way likely to damage the claimant's goodwill. The plaintiff must show that they have a reputation with the public and that the defendant's misrepresentation is likely to cause damage.

References:
Passing Off - WIPO
What does Section 230 of the Communications Decency Act do?

Section 230(c)(1) states that no provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider. Courts have interpreted this broadly to create almost complete civil immunity for internet platforms for the statements of their users, protecting them from liability for defamation and other torts based on third-party content. The scope of this immunity has been the subject of significant debate and reform proposals.

Does the GDPR apply to American lawyers?

The GDPR applies to any controller or processor of data who has an establishment in the EU and processes personal data. It also applies where a controller or processor has no EU presence if it is monitoring the behavior of individuals in the EU or offering goods or services within the EU. An American lawyer with no EU office may still be subject to the GDPR if they are monitoring behavior or offering services in the EU. However, the law is far from settled, and many EU authorities hold an aggressive view of the scope of their jurisdiction.

References

Adapted from the Original work by Kateule Sydney

Public domain 2026 · This adaptation follows the playbook series format

Kat-Syd Resources Hub — Your trusted source for legal education

Comments