law

A Complainant who claims an old domain name must demonstrate its use in order to justify prior rights

Source: WIPO, Arbitration and Mediation Center, Jan. 22, 2020, No. D2019-2992, Cyberplay Management Ltd v/ WhoisGuard Protected, WhoisGuard, Inc./DIREX NV and Johann Mayer.

The Maltese company Cyberplay Management holds a gaming license for the purpose of operating an online casino. The latter owns the European trademark “Loki”, deposited on January 10, 2017 and registered on 6 September 2017, as well as the domain name <loki.com>, registered in 1992 and currently operated for online casino services. Said Company filed a UDRP Complaint before the WIPO Arbitration and Mediation Center against the domain names <lokicasino16.com>, <lokicasino17.com>, <lokicasino18.com>, <lokicasino19.com> and <lokicasino.com>, with the prejudice that they infringe its rights. Indeed, they associate the “Loki” trade mark with the term “casino”, which refers to its activity. The domain name <lokicasino.com> had been registered on May 16, 2016 and the other four domain names on January 11, 2017 (one day after the registration of the Complainant’s trademark,).

At the time the Complaint was filed, the Respondents were using these domain names in connection with an online casino. The Complainant considers that the Respondents registered and used the domain names in bad faith. The Respondents, for their part, claim that they never had knowledge of the applicant and its trademark. In addition, the Respondents have provided several screenshots, taken from the WayBack Machine website databases (archive.org) of the history of the Complinant’s website, showing the latter has never used the domain name <loki.com> for casino activities prior to the current period. For example, in 2006, it referred to a site allowing the user to find all types of events near their location.

The expert ruling on the case concludes that the complaint must be rejected, since the applicant did not provide evidence showing it was the holder of trademark rights for the sign “LOKI” at the time of registration of the disputed domain names. The trademark application was filed after the registration of the domain name <lokicasino.com > owned by the Respondents. Furthermore, in regard to the law on unregistered trademarks (right of use), the Complaint does not submit any evidence of use of the sign “LOKI” in connection with the services of an online casino. Thus, it is important to recall that in order to prosper in a UDRP proceeding, it is imperative for a Complainant to submit evidence establishing, in particular, the registration and use of a domain name in bad faith. In this case, the Complainant failed to provide such evidence. This decision also shows the growing importance of the archives proposed by WayBack Machine, which the judges now tend to accept as evidence (subject to justifying a bailiff’s report).

Read More

UDRP procedure. The bad faith complainant: when the chances of success are so low that the applicant should not have taken action

Source: WIPO, Arbitration and Mediation Center, Jan. 30, 2020, No. D2019-2937, Scalpers Fashion, S.L. c/ Dreamissary Hostmaster

 

The Spanish company Scalpers Fashion is active in the fashion industry. It is the owner of numerous trademarks incorporating the “Scalpers” sign, including the European Union trademark “Scalpers” No. 6748578, registered on September 29, 2008. The company has filed a UDRP complaint before the WIPO Arbitration and Mediation Center against the domain name <scalpers.com>, claiming that it infringes its rights. The domain name was registered on September 15, 1997, by the Respondent Dreamissary Hostmaster, who is in fact a natural person, a U.S. citizen and the holder of a substantial number of domain names featuring dictionary words. The domain name at issue was exploited to generate pay-per-click revenues by leading to sponsored links referring to the sale of tickets. At the time the complaint was filed, the domain name in question resolved to a parking page.

The Complainant submits that the Respondent intends to take undue advantage of its reputation in fashion and to disrupt its business. In addition, the Complainant submits that the large sums proposed by the Respondent in various attempts t negotiate are evidence of his bad faith. Indeed, the Respondent allegedly offered initially $150,000 and then $195,000. Finally, the Complainant considers that the Respondent’s bad faith is manifested by the registration of more than 100 domain names, for him to be able to resell them for a profit.

The Respondent contends that he registered and used the domain name <scalpers.com> because of the definition of the word “scalper”: a person who buys tickets at the normal price and then resells them at a high price when demand is high and available seats are scarce. In addition, the latter requires the expert to conclude to reverse domain name hijacking.

The Complainant’s position was not followed by the expert. The expert considers that the domain name was neither registered nor used in bad faith. Indeed, the Respondent had registered the domain name more than 10 years before the Complainant’s alleged date of first use of the “Scalpers” trademark. In such circumstances, there was no basis to conclude that the Respondent targeted the Complainant’s mark, which was not in existence at the time the Respondent registered the disputed domain name. As regards the use of ???, the expert also concluded that there was no bad faith, since the Respondent had used the domain name for the meaning of the word “scalpers”. The expert ruling on the case indicates that the complaint should be dismissed. In addition, he stated that the complaint was filed in bad faith by the Complainant, and was intended to deprive the Respondent of ownership of his domain name. Indeed, several facts contribute to the expert’s position: the domain name was registered by the Respondent long before the Complainant owned a trademark right in the Scalpers sign; the UDRP Complaint was filed after two unsuccessful attempts to purchase the domain name from the Respondent; and the Respondent’s counsel notified the Complainant that the complaint should be withdrawn due to the manifest impossibility of establishing bad faith.

The Complainant clearly should have known that the complaint could not succeed. Thus, it should be borne in mind that the UDRP procedure is not a one-way tool. The aggrieved Respondent may attempt to reverse the proceedings to obtain a decision against the Complainant. Here, the lack of chance of success was particularly blatant, as the domain name predates the trademark rights of Scalpers Fashion.

Read More

The rise of phishing in the midst of the coronavirus crisis

Source: Bank Info Security, Feb. 11, 2020

 

The global health crisis caused by the coronavirus is a favorable context for phishing techniques. Indeed, many organized gangs of cybercriminals are pretending to be health organizations by using fake domain names. As a result, they send an e-mail pretending to be a health-related entity, in which they ask the recipient to click on a link and enter or confirm a login and password. For example, cybercriminals therefore send phishing e-mails containing domain names similar to those used by the Centers for Disease Control and Prevention. For example, cybersquatters have incorporated the domain name “cdc-gov.org” which is similar to the official domain name “cdc.gov”.
Thus, these malicious e-mails encourage users to click on a link that looks like it contains information related to the issues related to the coronavirus. In fact, Internet users are redirected to a fake website where they have to enter a username and password. In other cases, cybercriminals send phishing e-mails looking like they originate from the World Health Organization, inviting users to a link to download a document on security measures against the spread of the virus. Of course, this is not the case and users are redirected to a pop-up screen asking for a username and a password. It should be noted that some cybercriminals adopt a different tactic by posing as entities linked to the world of economics, such as shipping companies or manufacturing industries. The coronavirus crisis can have an impact that extends beyond health concerns. Hence, it is necessary to be doubly careful about the extension of these phishing campaigns, alert may be raised for example by e-mails containing numerous spelling mistakes.

Read More

The <.eu> extension against Brexit

Source: EURid, registry of the <.eu> extension 

The United Kingdom parted from the European Union on January 31, 2020. As a result, the United Kingdom and the European Union entered into a transitio period, a period that has been announced to last till December 31, 2020. During this period, UK residents are still entitled to register and renew names in <.eu>.

However, once this period expires, they will no longer be able to register domain names with the <.eu> extension, nor to keep those they already hold, unless they comply with the requirements. The EURID originally detailed a comprehensive plan that was supposed to be implemented from November 1, 2019, the date when the United Kingdom was due to leave the European Union. It will finally apply at the end of the transition period, although no precise deadlines have yet been set. Once the transition period ends, only the following persons are entitled to register domain names in <.eu>: a citizen of the European Union, regardless of his/her place of residence; a natural person who is not a citizen of the Union European but is a resident of a Member State; a company established in the Union; or an organization established in the Union, without prejudice to the application of national law.

Thus, for already registered domain names, registrants will be able to update their contact details in an attempt to maintain their assets. In particular, they will have to indicate a country code of citizenship corresponding to a Member State of the European Union of 27 regardless of their residence or establish an entity legally established in one of the eligible Member States of the European Union of 27 or the EEA. All registrants who do not comply with these eligibility rules will see their domain names cancelles such the domain names will then be available for registration to all.

As non-compliant domain names will be withdrawn, it is appropriate to carry out a thorough analysis of registrants’ domain name portfolios to see whether any of their registrations is at risk.

Read More

Registries and artificial intelligence

A number of national top-level domain name registries such as the English registry Nominet have begun to use artificial intelligence to prevent abusive domain name registrations. Each registry uses its own system to suspend registrations if they believe there is suspicious activity on an IP address or if the identity of the applicant cannot be verified.

 

Ongoing assessment of the identity of the registrant thus helps reducing domain name infringements.

Read More

Association between blockchain and domain names

Domain names appear to be a fertile ground for innovators related to blockchain technology.

 

 

Domain names and blockchain meet around the launch of the new extension “.luxe”, which contrary to what one might think was not created for the luxury industry (which already has its extension “.luxury” launched in 2014). The Ethereum foundation, whose aim is to promote blockchain technology, has entered into a partnership with the Minds + Machines (MMX) registry to create a new use for domain names, making “.luxe” the equivalent for cryptocurrency of what a classic extension represents for the IP address.

 

 

This association thus makes the IP addresses for the “.luxe” extension more intelligible.

 

 

Indeed, holders can link their domain name composed of the “.luxe” extension to their Ethereum account to replace their 40 characters identification number and make it easier to remember and use.

Read More

The reform of the tax regime for patentable products: “the French-style IP BOX“

The 2019 Finance Act harmonizes French and European tax rules in order to best promote the investment of patentable creations and inventions. We are talking about the French IP Box.

Thus, the taxation regime for the products of patents and similar industrial property rights is brought into line with OECD provisions.

While Irelandwas the first country to set up this system (1973), other countries followed suit, such as Belgium, China and, more recently, the United Kingdom (2013).

The principle allows companies to benefit from a tax advantage on their intellectual property assets with a tax rate that amount to 10% instead of 33% previously.

 

 

 

 

 

Eligible assets

The assets that are eligible for this plan are:

 

  • Patents and patentable inventions
  • Certificates of utility
  • Plant variety certificates
  • Copyrighted software

 

To be eligible, inventions must have been filed. Taking into account that the regime is open to software protected by copyright. It should also be added that this plan is applicable to annual net income calculated after deducting research and development expenses. The aim is to encourage research and development efforts in relation to the overall effect, i.e. in relation to all the investments that the company can make.

 

To be eligible for the reduction rate, the company will have to provide several elementsto establish its file such as:

  • Eligible assets
  • The rule for determining the protection of the proportion of net income taxable at a reduced rate
  • The method for allocating research and development expenses.

 

This makes it possible to monitor the company’s expenses and, above all, to justify the request for a reduction in the tax rate. It will be necessary to submit this file to the tax authorities under penalty of a 5% penalty. 

 

The tax rate

The regime consists in deducting first the proceeds of sale and concession as well as research and development expenses and then, in a second step, calculating from this deduction the net result in order to obtain the net result of the assets on the basis of the Nexus ratio. 

 

What is the Nexus ratio? 

The idea is to limit “the preferential regime in proportion to the part of the expenditure relating to intellectual property. »  

 

This is how the OECD defines this ratio. This is intended to sanction patents acquired and research and development costs subcontracted to affiliated companies. It should be noted that research and development costs in third party companies will not penalize the Nexus ratio. This ratio will be calculated on a cumulative expenditure basis.

Some consider this ratio a “not irrefutable presumption.” 

 

 

Conclusion

 

The advantage of this regime is that it will encourage companies to their research and development in France and produce quality intellectual property assets that generate income.

Read More

Webinar April 7, 2020: Internet and Compliance (part 1)

Webinar : Internet and Compliance (part 1)

 

The rules of the game have changed,

strategies to protect the company and its leaders.

 

 

 

 

The legal, regulatory and fiscal constraints (resulting in particular from the Sapin 2 Law, the LCEN or the EU
Directive of 23 October 2019 on the protection of whistleblowers) that weigh on companies are increasingly rigorous. Companies must implement a governance policy capable of minimizing their responsibility and exposure to their customers, shareholders and the competent authorities.

 

 

Among the aspects to be considered in the context of this compliance are domain names. While they are an undeniable corporate asset, they are also vectors of risk: phishing, fraud against the president, fake sites, identity theft, forged e-mails, and so on.

 

In the event of a breach, they can also damage the reputation of the company and its managers, resulting in a loss of customers. It is therefore imperative to put in place the appropriate strategies to anticipate the dangers, react effectively in the event of an attack and ultimately protect the company.

 

The current situation linked to the coronavirus epidemic is increasing the risks, with the number of frauds increasing considerably while companies are disorganized and vulnerable.

We propose to analyse these issues with you, sharing our experience. In particular, we will be able to answer the following questions:

– What are the obligations of companies with regard to compliance?

– What are the risks to be anticipated?

– What strategies should be implemented to do so?

– What are the control points?

– What levers should be implemented to react effectively in the event of a proven breach?

Read More

UDRP Proceedings: what are the risks if a complaint is insufficiently founded?

Introduction

The UDRP procedure is an effective tool for obtaining the transfer or cancellation of a domain name registered and used in bad faith. However, it should not be used as a pressure tactic to recover a domain name that is legitimately held by a third party. Where a complaint is filed without a serious legal basis, or primarily with the aim of depriving the registrant of a domain name, the panel may find Reverse Domain Name Hijacking, meaning that the complainant has used the UDRP procedure in bad faith.

The case Advice Group S.p.A. v. Privacy Administrator, Anonymize, Inc. / Michele Dinoia, Macrosten LTD (WIPO Case No. D2019-2441) is an illustration of this risk.

The Advice group case: a warning against insufficiently grounded complaints

Advice Group is an Italian company founded in 2006 and specialized in marketing. It is based in Turin and also has offices in Rome and Bari, as well as subsidiaries in Bulgaria, Kosovo, Portugal, Colombia and Peru. After becoming aware of the registration of the domain name <advicegroup.com> by a third party, the company filed a UDRP complaint with the WIPO Arbitration and Mediation Center, seeking transfer of the domain name.

The disputed domain name had originally been registered in 2005 and was later acquired by Michele Dinoia, of Macrosten LTD, in September 2014. The domain name resolved to a parking page displaying commercial links and indicating that Internet users could contact the registrant if they were interested in acquiring the domain name.

The complainant’s burden of proof under the UDRP

The Respondent did not file a response. However, the absence of a response does not relieve the Complainant of its burden of proving the three cumulative elements required under the UDRP:

  • First, that the domain name is identical or confusingly similar to a trademark in which the Complainant has rights
  • Second, that the Respondent has no rights or legitimate interests in respect of the domain name
  • Third, that the domain name was registered and is being used in bad faith.

In this case, the panel accepted that the domain name was confusingly similar to the Complainant’s Italian figurative trademark “ ” No. 2015000025292. However, this was not sufficient to justify a transfer.

The panel chose not to make a definitive finding on the issue of rights or legitimate interests, given its conclusions on bad faith. Nevertheless, it made several observations that were favorable to the Respondent. In particular, the domain name was composed of dictionary terms, namely “advice” and “group”, and the Respondent had not actively used the domain name to target the Complainant. The domain name merely resolved to a standard parking page, with a message allowing interested users to contact the registrant regarding a possible purchase.

The panel also noted that there were many companies throughout the world using the name “Advice Group”. This weakened the Complainant’s argument that the Respondent must necessarily have had the Complainant in mind when acquiring the domain name.

Bad faith as the decisive issue

The issue of bad faith was decisive. The panel emphasized that, at the time the Respondent acquired the domain name in September 2014, the Complainant had not yet registered its trademark. The trademark was filed only in June 2015 and registered in December 2016. As a result, the domain name predated the Complainant’s trademark rights.

Nothing in the evidence suggested that the Respondent had targeted the Complainant when acquiring a domain name made up of common English words. The fact that Internet users could make an offer to acquire the domain name did not, in itself, prove that the Respondent had registered it with the specific intention of selling it to Advice Group at an excessive price.

The complaint was therefore rejected.

Reverse Domain Name Hijacking: when the complaint itself becomes abusive

More importantly, the panel found that the complaint constituted a case of Reverse Domain Name Hijacking. The Complainant had accused the Respondent of cybersquatting even though it had not provided evidence of targeting, and despite the fact that the domain name, composed of generic terms, predated the Complainant’s trademark registration. The panel considered that the Complainant should have known that it could not establish bad faith registration.

This decision remains highly relevant today. The updated WIPO practice, including the WIPO Overview 3.1, confirms the importance of a rigorous evidentiary analysis, particularly in relation to bad faith and abusive UDRP complaints. Panels continue to be attentive to cases where a trademark owner attempts to use the UDRP procedure to obtain a domain name that it could not acquire through ordinary commercial negotiation.

Practical lessons for trademark owners

The practical lesson is clear: where a domain name consists of generic, descriptive or common terms, proving bad faith is particularly difficult. It is not enough to show that the domain name is identical or similar to a trademark. The complainant must establish that the respondent specifically targeted its trademark, business, reputation or customers.

Conversely, certain elements may strengthen a UDRP complaint, such as trademark rights predating the domain name, reproduction of the complainant’s official website, use of the domain name for the same goods or services, fraudulent email activity, a direct offer to sell the domain name to the trademark owner, or a documented pattern of cybersquatting.

Before filing a UDRP complaint, trademark owners should therefore carefully verify the date of registration or acquisition of the domain name, the date on which their own trademark rights arose, the distinctive or generic nature of the sign, and the available evidence showing that the respondent actually targeted them.

Failing this, the complaint may not only be rejected, but may also result in a finding of Reverse Domain Name Hijacking, turning the procedure against the complainant itself.

Conclusion

The Advice Group decision serves as a useful reminder that the UDRP procedure is not intended to resolve all disputes involving a domain name. Its purpose is to address clear-cut cases of abusive registration and use, not to provide a shortcut to obtaining a domain name legitimately held by a third party.

For trademark owners, the key issue is therefore not merely whether the disputed domain name is identical or similar to their trademark, but whether there is sufficient evidence to show that the respondent specifically targeted their rights. This case thus demonstrates that filing a weak or opportunistic complaint can have consequences that go beyond the mere dismissal of the complaint.

Dreyfus law firm assists its clients in managing complex intellectual property cases, offering personalized advice and comprehensive operational support for the complete protection of intellectual property.

Dreyfus law firm works in partnership with a global network of attorneys specializing in Intellectual Property.

Nathalie Dreyfus with the support of the entire Dreyfus team.

Q&A

1.Can a trademark owner file a UDRP complaint if the domain name was registered before its trademark?

Yes, but the complaint will usually be more difficult to prove. Under the UDRP, the complainant must show that the domain name was registered and used in bad faith. If the domain name predates the trademark rights, it may be difficult to establish that the registrant targeted a trademark that did not yet exist. However, exceptions may arise where the complainant already had unregistered rights, strong reputation, or where the respondent clearly anticipated the complainant’s rights.

2.Is the UDRP the right procedure for every domain name dispute?

No. The UDRP is designed for clear cases of abusive domain name registration and use. It is not intended to resolve complex contractual disputes, business disagreements, former partnership issues, or conflicts involving competing legitimate rights. In such cases, court proceedings or negotiated solutions may be more appropriate.

3.Does a respondent have to actively use the domain name for bad faith to be found?

No. Passive ownership of a domain name may, under certain circumstances, constitute bad faith. However, passive ownership is evaluated with caution and does not automatically suffice to establish bad faith.

4.What type of evidence should be collected before filing a UDRP complaint?

A complainant should collect evidence of its trademark rights, reputation, chronology, screenshots of the website, WHOIS records, DNS records, MX records, redirections, phishing attempts, commercial links, offers for sale, prior correspondence, and any pattern of similar domain name registrations by the respondent. The stronger the factual record, the lower the risk of filing an insufficiently grounded complaint.

5.Can a domain name made of common words still infringe trademark rights?

Yes. A domain name made of common words may still infringe trademark rights if it is used to target a specific trademark owner. For example, bad faith may be found where the domain name reproduces the complainant’s branding, redirects to competing services, is used for phishing, or creates a misleading association with the complainant. The key issue is not only the wording of the domain name, but the respondent’s intent and use.

Read More