info@josefelgueroso.com
2021-02-16
In a preliminary ruling, a judge in Arizona held that the plaintiffs had sufficiently alleged that a law that required them to write computer code for car dealerships violated their freedom of speech.
The plaintiffs develop and operate computer systems known as dealer management systems ("DMSs") that process information from various sources. The defendants are the Arizona Automobile Dealers Association and the attorney general of Arizona.
In March 2019, Arizona enacted the Dealer Data Security Law, which provides that DMS providers must not restrict the integration of a third party into the dealer's DMS, if the third party complies with certain security standards. In addition, under the Dealer Data Security Law, DMS providers must make available a framework for the exchange and integration of data from a DMS and allow authorized integrators to access application programming interfaces.
The question before the judge was whether the lawsuit should be dismissed for failure to state a claim, as the defendants had requested.
A complaint must contain factual allegations beyond mere speculation; otherwise it can be dismissed for failure to state a claim. While evaluating a motion to dismiss for failure to state a claim, the judge must take the plaintiff's factual allegations as true, and interpret facts in the light most favorable to the party that did not file the motion.
On the other hand, computer code can be protected by freedom of speech, if it communicates with the user of the program in a non-mechanical manner.
The judge concluded that the complaint contained factual allegations, because the program mandated by the Dealer Data Security Law involved substantial interaction with the users. In addition, the plaintiffs had to draft code to handle the requests of authorized integrators, who interacted with that code. Finally, the computer code mandated by the Dealer Data Security Law required creative choices by the developers to be communicated to users of the program and other third parties.
Since the complaint contained allegations that the plaintiffs' freedom of speech had been violated, the judge denied the motion to dismiss.
The fact that computer programs can be protected by freedom of speech has implications for computer security, as the following two cases illustrate.
Bernstein v. US Department of State (1996)
The first case in the United States regarding the protection of computer code as a form of expression was decided in 1996. The question before the judge was whether requiring a license for the export of an encryption program violated freedom of speech.
The Arms Export Control Act ("AECA") granted the president of the United States authority to control the import and export of defense items by including them in the United States Munitions List (the "Munitions List"). Any item in the Munitions List required a license to be exported. A related regulation authorized the United States Secretary of State to implement AECA.
Daniel Bernstein, the plaintiff, was a Ph.D. candidate at the University of California, Berkeley. He was the author of an encryption algorithm, which he articulated in an academic paper and a computer program. Bernstein intended to discuss his encryption program online, in journals, and at academic conferences, including to audiences outside the United States. The State Department, however, included Bernstein's program in the Munitions List, and as a result the program required a license to be exported. Bernstein sought an injunction to prevent the enforcement of the AECA in connection with his program.
The judge found that Bernstein's program was a form of written communication, expressed in computer code rather than in English, as it communicated information to programmers and, ultimately, to the computer. The judge concluded that the license requirement violated freedom of speech, because it suppressed the communication of content expressed in computer code.
Apple v. FBI (2016)
In a more recent case, the FBI wanted to access the contents of the iPhone of one of the suspects in the 2015 San Bernardino terrorist attack. It asked a judge to compel Apple to write code and to cryptographically sign it to allow the FBI access the contents of the iPhone. In a brief filed with the court, Apple argued that compelling it to write code against its will was a violation of its freedom of speech.
Before the judge ruled on the matter, however, the FBI found an alternative way to access the contents of the iPhone and withdrew its request.