Feeds

US appeals court cans CAN-SPAM suit

A farewell to litigation factories

Secure remote control for conventional and virtual desktops

In a decision that could make it harder for internet users to take spammers to court, a federal appeals court has upheld the dismissal of a lawsuit against a company that sent a man more than 13,000 unsolicited emails.

A three-judge panel from the Ninth US Circuit Court of Appeals agreed with a lower-court judge that under a federal law that went into effect in 2004, plaintiff James S. Gordon Jr. lacked standing to sue online marketing business Virtumundo. The panel ruled that under the Controlling the Assault of Non-Solicited Pornography and Marketing, or CAN-SPAM, act, lawsuits can only be brought by select law-enforcement agencies and providers of an IAS, or "internet access service."

The judges went on to dismiss claims Gordon brought under a separate Washington-state law forbidding deceptive commercial emails, holding that that CAN-SPAM preempted the law. The state statute allowed private individuals to sue people who send them deceptive marketing emails that were unsolicited. The net effect, legal experts said, is that internet users will have fewer options for taking legal action against spammers.

"It is going to be harder for individuals to sue companies that send them spam because trying to shoehorn a claim under statutes prohibiting deception will be looked on by courts with skepticism," said Dave Kramer, an attorney at Wilson Sonsini Goodrich & Rosati who helped draft the Washington law.

Critics have long complained that CAN-SPAM was full of so many loopholes that it had little effect on the torrent of spam that lands in inboxes everyday. The Ninth Circuit's decision is only likely to strengthen those claims. It will set a higher bar for individuals who want to invoke it in lawsuits. Specifically, they will have to show they are an IAS and will then have to show they faced significant harm as a result of receiving spam.

When Gordon brought the suit in 2006, he was already a fixture in state in federal courts, which he peppered with lawsuits against spammers. He made it a habit to send spammers responses demanding they cease their junkmail campaign and demanding $500 for any repeat offenses. He also set up multiple email accounts on behalf of friends and family members and monitored them for unsolicited messages.

Gordon told the court he had collected more than 13,800 junk messages.

This has led to criticism that Gordon is a "professional plaintiff" who opportunistically milks anti-spam laws for his own personal gain. Those points weren't lost on US Appeals Court Judge Ronald M. Gould.

"For a person seeking to operate a litigation factory, the purported harm is illusory and more in the nature of manufactured circumstances in an attempt to enable a claim," he wrote in a concurring opinion. "In my view, manufactured claims should not be tolerated absent a clear endorsement from Congress."

A PDF of the decision is available here. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Regin: The super-spyware the security industry has been silent about
NSA fingered as likely source of complex malware family
Why did it take antivirus giants YEARS to drill into super-scary Regin? Symantec responds...
FYI this isn't just going to target Windows, Linux and OS X fans
Privacy bods offer GOV SPY VICTIMS a FREE SPYWARE SNIFFER
Looks for gov malware that evades most antivirus
Patch NOW! Microsoft slings emergency bug fix at Windows admins
Vulnerability promotes lusers to domain overlords ... oops
HACKERS can DELETE SURVEILLANCE DVRS remotely – report
Hikvision devices wide open to hacking, claim securobods
'Regin': The 'New Stuxnet' spook-grade SOFTWARE WEAPON described
'A degree of technical competence rarely seen'
Astro-boffins start opening universe simulation data
Got a supercomputer? Want to simulate a universe? Here you go
prev story

Whitepapers

Driving business with continuous operational intelligence
Introducing an innovative approach offered by ExtraHop for producing continuous operational intelligence.
Why CIOs should rethink endpoint data protection in the age of mobility
Assessing trends in data protection, specifically with respect to mobile devices, BYOD, and remote employees.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Reducing the cost and complexity of web vulnerability management
How using vulnerability assessments to identify exploitable weaknesses and take corrective action can reduce the risk of hackers finding your site and attacking it.