New Online Registration Requirements for Designated Agents Under the Digital Millennium Copyright Act

The U.S. Copyright Office has developed a new electronic system for registering your designated agent under the Digital Millennium Copyright Act (“DMCA”).  As of December 2016, the U.S. Copyright Office has begun transitioning to an online registration system which allows online service providers to register a designated DMCA agent in a centralized public directory.  Any new registrations must be completed through this online system.  Most importantly, even if a service provider has previously registered its designated DMCA agent with the Copyright Office through the previous paper filing system, the service provider must re-register through the Copyright Office’s new online system before December 31, 2017.

Registering and maintaining a designated agent with the Copyright Office for copyright infringement takedown requests is necessary to obtain safe harbor protection under the DMCA.  Safe harbor protection can help shelter online service providers from potential copyright liability for any third party content posted on or transmitted via their websites.  In order to qualify for safe harbor protection under the DMCA, any online service provider that has a website or application which allows users to post, share, transmit, or comment on content must designate a Copyright agent.  To designate an agent, an online service provider must not only provide the contact information for the agent to the Copyright Office as part of its online public directory, but also make the contact information for the agent available to the public on the online service provider’s website so that users can notify the service provider of allegedly infringing material.

On the Copyright Office’s online registration system, online service providers must create an account and provide all necessary information regarding the service provider itself, the designated agent, and the associated websites.  Registration costs $6 per online service provider submission.

While the registration forms seem relatively simple, they raise additional issues that need to be considered carefully.  For example, related companies that are separate legal entities (parents, subsidiaries, etc.) and own related but separate websites must register separately.  An online service provider must also provide all alternate names under which the service provider is doing business, such as any of its associated website names and/or domains, software application names, or any other commonly used name that the public would be likely to use to search for the service provider’s designated agent.  In many cases a website owner can submit multiple websites/alternate names in one submission, but it depends on the specific circumstances.  The DMCA must be strictly complied with in order to receive full safe harbor protection, so it is essential that the registration forms are properly and fully completed.

Once the DMCA agent has been designated through the Copyright Office’s online system, online service providers must ensure that all of the registered information remains up to date.  Any failure to maintain accuracy in this information could result in losing the protection of the DMCA safe harbor provisions.  For example, if an online service provider’s designated agent changes, the service provider must make sure that the agent registration information is updated not only with the Copyright Office, but also in all places on the service provider’s website where the designated agent is identified.

Online service providers can amend their registrations at any time for an additional $6 per submission.  Additionally, the Copyright Offices requires online service providers to renew their agent designation at least every 3 years.  To do this, service providers must resubmit their registration before it expires, either with the same information if still accurate or with any updated information.  Renewals are also $6 per submission.  Any amendment filed will begin a new 3-year period before a renewal is due.

All online service providers should carefully review their current DMCA policies and materials and determine whether they may need assistance with drafting online DMCA policies for consumers, establishing and maintaining a designated agent with the Copyright Office, and/or drafting internal policies and procedures on reviewing and addressing DMCA takedown notices.  Online service providers do not want to miss out on compliance with the DMCA’s safe harbor provisions and potentially face copyright infringement liability for user content.  — Rina Van Orden

Secrets to a Successful Privacy Policy

Privacy policies may seem like a snooze, but they can actually be a key tool in protecting your business and communicating with customers.  A privacy policy explains your entity’s views and procedures regarding privacy and provides information about how you will use a website user’s personal information and/or data.  It also details the steps you take to maintain user information securely.

Privacy policies must:

  • Be specifically tailored to your industry, business, and circumstances
  • Have clear and accessible explanations understandable to the average consumer
  • Provide enough information that users have informed consent
  • Be strictly adhered to once published
  • Be updated to reflect any changes

A recent case underlines the importance of a well-crafted privacy policy.  In Carlsen v. GameStop, Inc., the plaintiff brought a lawsuit against GameStop regarding the video game retailer’s information sharing practices.[1]  The appeals court dismissed the plaintiff’s claims and proposed class action because of GameStop’s privacy policy.

The plaintiff subscribed to GameStop’s monthly publication Game Informer magazine, including both print and online versions.  GameStop provides a feature that allows subscribers to log in to the magazine content through their personal Facebook accounts.  The plaintiff filed suit because once he logged in to the magazine through Facebook, his Personal Facebook ID and Game Informer browsing history were transmitted to Facebook.

In order to access the online content of Game Informer, a subscriber must agree to the site’s terms and conditions, which includes GameStop’s privacy policy.  GameStop’s policy stated that “Game Informer does not share personal information with anyone.”

The court held that the transmission of Game Informer subscribers’ Facebook IDs and browsing history did not constitute “personal information” under GameStop’s privacy policy because these items were not included in the explicit list in the privacy policy detailing “personal information” and because the information at issue was not specifically solicited by Game Informer or voluntarily submitted in response to such a solicitation, as specified in the privacy policy.  Because the Facebook IDs and browsing history were not included in the privacy policy as protected personal information, GameStop did not act wrongly in sharing that information, and thus there was no breach of contract.  GamerStop’s clear and well-written policy was key in extricating GameStop from this lawsuit.

Privacy policies have become a common business practice for many websites.  These days, website users are keenly aware of privacy concerns and protective of their personal information.  The prevailing view is that a credible website will operate with at least minimal privacy standards in place.  Privacy policies are especially necessary when you are engaged in e-commerce or data collection.  If your prospective and current clients are likely to have concerns about privacy, then they will expect you to have a policy that details the various protections and procedures that you have in place.

Every website will have different elements to cover, and some websites will need more comprehensive policies than others. This is likely dependent on what kind of user information is collected and how much/to what extent it will be shared with third parties.

Regulated industries, like banking, medical, and others, are required by law to maintain a privacy policy that applies both on and off the internet.  Entities in these industries should address all issues covered under industry regulations in an online privacy policy as well.

We advise against copying a policy from another business, even if that business is similar to yours.  A poorly written or inapplicable policy taken from another website can expose you to liability.  You want to make sure that your privacy policy specifically covers the individual needs of your business.

Often websites will have full terms and conditions with a separate privacy policy integrated into the terms.  A privacy policy needs to be easy to understand even though it is a legal document.  Your policy should be also clearly and prominently displayed on your site and accessible from key pages like the homepage and shopping cart, if not every page.

You want to make sure that as your business or technology evolves (say you launch a related app or pair with a social media platform), your privacy policy is updated to address the same.  Anytime a change to your policy is made, you should provide clear notice to users and in some cases obtain consent from users for material changes.

Privacy policies typically include sections that address:

  • user information that is collected
  • method of collection
  • how that information is shared and/or stored

A policy should address not only the required personal information that a user enters into the website but also any data logged automatically by your website, application, servers, etc.  A privacy policy should also address any use of cookies.

Once you have a policy in place, it is essential that you abide it and make sure that your practices actually match the statements in your policy. Your policy creates a contract with your users. If your policy and practices do not align, you open yourself up to liability, both from lawsuits by users and actions by regulators like the FTC, who scrutinize unfair or deceptive trade practices.

If your website is directed toward children under the age of 13, additional requirements apply to your website under the Children’s Online Privacy Protection Act and should be detailed in your privacy policy.

As demonstrated by the GameStop case, a clear privacy policy drafted to meet your needs and circumstances can not only provide your users with a transparent explanation of your privacy practices, but also protect your entity from liability. — Rina Van Orden

[1] 833 F.3d 903 (8th Cir. 2016).

The Digital Millennium Copyright Act: The Copyright Office Examines Whether it Needs Revamping

As most internet users of today know, music, videos, poems, photographs, and various other creative works are often posted on social media and other sites without the permission of the work’s creator.  These postings violate the creator’s exclusive right to distribute his or her own work, one of the central rights protected by copyright law and based on the Constitution.[1]  To address concerns of increasing copyright infringement online, Congress enacted the Digital Millennium Copyright Act (the “DMCA”) in 1998.  The DMCA allows copyright owners to submit takedown notices to internet service providers (who provide the platforms for postings, think YouTube, SoundCloud, Twitter, etc., abbreviated in this article to “ISPs”), demanding that access to an infringed work be blocked or the work removed.  In exchange for compliance with the DMCA and the swift removal of infringing materials, ISPs are exempted from liability for copyright infringement.

Although the DMCA may have provided a sufficient[2] remedy for copyright holders in 1998, copyright owners in recent years have complained that the increase in infringing posts resulting from the proliferation of user-upload sites such as eBay, SoundCloud, Vimeo, and others makes the takedown process onerous.  For example, since 2012 the music recording industry has sent takedown notices for over 17 million infringements.[3]  Google receives on average over 75 million URL takedown requests per month, and must use computer programs to sift through them all.[4] In response to the uproar from copyright holders, Congress has requested the Copyright Office conduct a study to determine the effectiveness of the DMCA.[5]  The study is currently ongoing, with the Copyright Office receiving more than 92,000 submissions in its first round of comments.[6]

In reviewing comments submitted during the first round, battle lines have clearly been drawn between the creators of works and ISPs.  In support of its position that the DMCA sufficiently protects the various parties’ interests, in its comment Amazon focused on the economic growth driven by the DMCA’s safe harbor provision, noting that, because of the safe harbor, ISPs have not been required to conduct the “difficult” task of policing posted content, a policy that has been “crucial to the growth of the Internet.”[7]  Amazon further asserted that the DMCA strikes “the right balance” between providing rights holders with the ability to remove infringing content while allowing ISPs the ability to “innovate and host ever-increasing amounts and types of content without fear of massive liability based on the activities of their users.”[8]  Other ISPs argue that, in fact, the takedown system is being abused, with a “guilty until proven innocent” approach often leading to misuse and overreach.[9]  One Google-backed study, conducted by the Berkeley School of Law, found that almost 30 percent of takedown requests received in a six month period had validity issues.[10]

Creators of copyrighted works, however, assert that the take down provisions are not an adequate deterrent to infringement, [11] particularly when a majority of takedown notices are for infringing uses previously the target of a notice.[12]  To counteract the cycle of takedown-repost-takedown, many creators are arguing for a “takedown, stay down” provision, which would allow copyright holders to submit a takedown notice for a work once with the expectation that the work never appear again on the same platform.[13]  Indeed, in support of its position that the DMCA needs strengthening, the Artists Rights Society argues that the current takedown provisions, contrary to Congressional intent, favor ISPs, who profit from infringing posts through listing fees, advertising, and/or increased traffic.[14]  To restore balance, the Artists Rights Society recommends that online service providers be required to pay a percentage of the quantifiable revenues received from an infringing third-party user to the copyright owner.[15]  The Artists Rights Society does not elaborate on how these fees would be collected and dispersed.

Taking a slightly different course from both their fellow creators and the ISPs, the American Photographic Artists (“APA”) propose turning the tables on the oft-anonymous infringers who are benefitting from, according to the APA, a “de facto immunity” under the DMCA.  This de facto immunity is the product of the high cost of pursing a copyright infringement claim and the potentially low damages return (particularly for unregistered works),[16] making the pursuit of infringers essentially pointless.  Although it does not appear from its comment that the APA is advocating for one particular measure to shift the risk of infringement, one possibility the APA discusses is requiring an infringer to reimburse the copyright holder’s costs spent on a takedown.[17]

As the Copyright Office weighs these competing interests, it will also need to keep in mind how evolving technology may continue to impact takedown proceedings.  We will keep you updated on developments as the Copyright Office prepares its report. — Stephanie Martinez


[1] 17 U.S.C. § 106; U.S. Const. art. I § 8 cl. 8.

[2] Many would argue the DMCA never worked well and was instead poorly thought out and poorly executed.  See Chris Mills, These Three Dumb Examples Prove that Copyright Is Broken, BGR (May 24, 2016),

[3] Randolph J. May & Seth L. Cooper, Copyright ‘Notice and Takedown’ System Needs Fixing (May 9, 2016)

[4] Google, Transparency Report,  Requests sent to Google are to remove links from Google’s search results due to infringing content on the website, not to remove the allegedly infringing content from the site itself.

[5] See United States Copyright Office, Section 512 Study,

[6] See United States Copryight Office, Requests for Public Comments: Digital Millennium Copyright Act Safe Harbor Provisions,!docketBrowser;rpp=25;so=ASC;sb=title;po=0;dct=PS;D=COLC-2015-0013;refD=COLC-2015-0013-0002.

[7], Inc., Section 512 Study: Notice Docket No. USCO-2015-7 and Request for Public Comment, p. 3.

[8] Id.

[9] Caroline Craig, DMCA ‘Reform’ Harbors Return of SOPA, InfoWorld (May 20, 2016),

[10] Id.; Jennifer M. Urban, Joe Karaganis, & Brianna L. Shofield, Notice and Takedown In Everyday Practice, 11 (2016), available at

[11] See American Photographic Artists, Inc., Initial Response to Notice of Inquiry 78 F.R. 13094 (Docket No 2015-7) Section 512 Study: Notice and Request For Public Comment, p. 2.

[12] In fact, the Federation of the Phonographic Industry has reported that 94% of its takedown notices are for “recordings uploaded repeatedly” to sites already notified of the infringing posting.  Randolph J. May & Seth L. Cooper, Copyright ‘Notice and Takedown’ System Needs Fixing, The Hill (May 9, 2016),

[13] TorrentFreak, Ten Websites Hit With 70M DMCA Complaints In A Year, TorrentFreak (May 29, 2016),

[14] See Artists Rights Society, Comments of Artists Rights Society, p. 2.

[15] Id.

[16] See American Photographic Artists, Inc., Initial Response to Notice of Inquiry 78 F.R. 13094 (Docket No 2015-7) Section 512 Study: Notice and Request For Public Comment, p. 3.

[17] Id.

Using New Domain Extensions to Your Brand’s Advantage

Registrations for new generic Top Level Domains (“gTLDs”) have topped 13 million.  As the use of new domain extensions becomes more prevalent, questions commonly arise about how search engines treat them and how large brands and marketing companies are using them.  Some misconceptions about the power of a new domain extension to improve SEO and ranking in search engine results have developed, but new domain extensions can be put to valuable use.

In a frequently re-posted blog post, Google has detailed how it handles new domain extensions. The search engine treats “new gTLDs like other gTLDs (like .com & .org)” and has no current plans to change its algorithm in order to favor new domain extensions.  The good news is that Google will return search results with new domain extensions just as readily as .com, .net, etc.  Google looks at new domain extensions more like additional options, and thus, an entity should register whatever domains fit its own specific long-term needs.  Over time, the algorithm will begin to recognize shifts in gTLDs, as it has previously.  For example, .co was once the country code for Colombia. Now .co is commonly used around the world to signify company or commerce and thus Google’s algorithm has evolved to no longer treat .co as specific to Colombia.  Even though Google’s algorithm does not explicitly favor anything to the right of the dot, use of a new domain extension can help increase reliability for your site and those searching for it, send a specific message to consumers, and develop your brand’s web presence.

More Names to Go Around

For the most part, the release of the new domain extensions has not resulted in a “land grab” targeting companies with well-known domains, perhaps simply because there are too many possible domain names.  It’s impractical for cybersquatters to buy and lock up all possible similar domains with the intent of selling them later.  This means that an entity looking for its name has a much higher probability of finding an available option using a new domain extension.

New domain extensions may be most appealing where the .com of the brand’s company name or acronym is already taken or the brand’s name is a common word with multiple meanings. One article cites ‘Lily,’ the world’s first self-flying camera drone, as a prime example.[1]  When the drone was created, had already been registered by Lily Transportation Corp. Plus, the term ‘Lily’ has numerous meanings, including as a first name, the flower, or even a town. That’s why the robotics team responsible for Lily opted to secure — both to differentiate its domain name from others and to provide a clear message of what the site is all about.

If you plan on communicating with your customers primarily through an app interface and your desired .com is already taken, selecting a relevant domain using a new domain extension can be just as effective.  For example, social networking app Whisper could not get its corresponding .com, so instead uses Even without the .com, a simple Google search for Whisper ranks it at the top of the results.

ccTLDs & Local Geo-Targeting

Notably, one type of domain extension that may have some effect on search results is country-code top level domains (ccTLDs) because they are used in geo-targeting. Google uses most ccTLDs to geo-target the website because the website is probably more relevant in the appropriate country.  For small businesses concerned with generating a more local reach, taking advantage of local domain extensions may be very valuable.  A ccTLDs shows search engines and users where the website originates, and this will likely have an effect on search rankings.  Thus, if all else is equal, the website will most likely rank higher in the search engine results for a user in New Zealand than or Notably, new domain extensions have been created for cities like Las Vegas, New York, Boston, and Miami (as well as cities abroad like London, Paris, Istanbul, Tokyo, and Sydney). Though the city extensions are currently treated as gTLDs, these kinds of domain extensions may become the best way to target local consumers in the future if they also become geo-targeted, especially in the U.S., where the .us extension has not caught on.

If you are looking into country code or city domain extensions, you need to research the meaning of the domain extension that you think applies. For example, .ca is commonly mistaken as meaning California, but it is actually the country code for Canada. Thus, if a California company purchases a .ca domain with the mistaken belief that it represents California, it may be a wasted investment because Google will not geo-target the website correctly.  Another example is .de which signifies Germany, not Delaware.

Familiarity & Reliability

Trustworthiness is a key factor in search engine optimization (SEO). So in the future, once the majority of the websites using the extensions .architect or .accountant are in fact members of those professions, those domain names will become a signal to consumers that those domain extensions can be trusted, similar to the familiarity with and trust of .org and .edu. The same goes for custom brand name domains. If .HBO becomes the primary domain extension for the premium cable channel, then consumers will know that any .HBO site is put forth by .HBO, thus increasing its trustworthiness. To demonstrate this point, a number of highly-regulated domain extensions already exist.  If you want a domain that uses .bank, .dentist, or .law, for example, you must provide authorizations, licenses, and/or other necessary credentials required to be part of that industry or sector when registering that domain. Thus, a website using .law must have been registered by a licensed attorney.

Some commentators still believe that the .com is the “Holy Grail” for a company’s domain in the U.S., primarily because non-savvy Internet users know and trust .com as a website extension.  For many, .com adds legitimacy to sites, while an unknown or not readily recognized domain may raise concerns about spam, malware, viruses, privacy, identity theft, etc.  Consumers don’t inherently trust sites with unusual TLDs more than ones with more recognizable endings.  As an example, one study asked users if, based solely on the domain name, they were more likely to trust an insurance quote from a website ending in .insurance. 62 percent of Americans, 53 percent of Australians, and 67 percent of marketers said they were unlikely to trust the quote based on the domain alone.[2]  But as use of the new domain names spreads, users will become more comfortable with them.

New domain extensions may also cause concern where they indicate the website itself is new. While for some sites appearing less established can be a disadvantage, perception likely depends on the extension itself.  For example, extensions like .name, .rocks, and .cc have received bad press as being commonly used for spam.  But other new extensions have earned credibility with particular industries and types of entities and consumers.  For example, .io has gained a lot of traction for websites about computing and technology startups.[3]  In general, steer away from very generic new extensions such as .website, .company, and .country, and instead select something specific that directly relates to your brand.

Brand Management

Signals to ConsumersIn many cases, the new domain extensions can tell consumers what your site is about before they even click on it.  For example, a website that uses .pizza is probably all about pizza, and the .pizza will signal to consumers who are looking for where to order their next delicious pie that your site focuses on pizza before they even click on your link in the search results. Even celebrities are taking advantage of the new domain extensions for their causes and brands. Lady Gaga has registered and Oprah has

The new domain extensions also allow companies with lengthy .com domain names to obtain a shortened version using a different gTLD.  Short domains can be useful for clients, marketing, and for platforms like Twitter.

Securing .[BRAND]Large companies that secure their names as a domain extension (e.g., .mcdonalds, .nike, .cocacola) can use them to create extremely targeted and specific websites for different consumer experiences, based on what the consumer is seeking.  For example, the National Football League can establish domains for specific teams, cities, or events using .NFL.  Macy’s could tailor specific pages to certain interests, such as Home.Macys, Shoes.Macys, or WeddingRegistry.Macys.  Securing a brand domain extension will also allow companies to determine if users are searching for a domain that does not yet exist and signal them to create one.  For example, if Disney has Shop.Disney and Movies.Disney but discovers that users are searching for Frozen.Disney and that page has not yet been developed, Disney can determine whether to create such a page in order to capture those users’ interest.

Brand domain extensions will also likely have the ability to offer greater security that is controlled by the company itself.  As one commentator stated, “[f]or financial institutions, insurance companies and pharmaceuticals, this will have great value if it’s executed properly. For everyone else, it offers something more to consumers in a security-conscious society.”[4]

URL Shorteners — URL shorteners are commonly used for branding purposes in social media. However, these shorteners are typically owned by another brand.  One of the most well-known and well-trusted is  But consider instead creating a consistent brand message by instead using a custom URL shortener through the new domain extensions.  A commonly used extension as a shortenter is .link. So, instead of employing an unbranded link, HBO could use for posts about Game of Thrones. For brand builders, these custom URL shorteners offer an inexpensive solution for maintaining brand consistency. Both generic extensions like .help and .link and targeted extensions like .food and .style can help brands specifically target the audience they are looking for.

Careful consideration and planning when deciding on new domain extensions to invest in can set you up for online marketing success. As the frontier of Internet marketing continues to develop, new domain extensions are likely to become an ever-more-present force tapped to spread a brand’s message. So make sure you settle on the right one(s) for your brand and keep an eye out for new possibilities in the future. — Rina Van Orden