Accessing Netflix? Subscriber vs. Dependents?
Accessing Netflix? Subscriber vs. Dependents?
In these past few years, with the pandemic fueling the rage further, the consumption of data, content and shift towards buying-into streaming services, found a fillip. This led to new means of piracy, thereby boosting the need for businesses to evaluate, re-evaluate their strategies and tools, to bolster their digital rights management (DRM) framework. Interestingly, the losses that were incurred by major players like Netflix, have egged the OTT behemoth to come down heavily on its users, with several checks and balances set to be introduced within the managed accounts. Through this piece, we intend to wade through the context set out by Netflix, the manner in which the subscribers interact with it, and how the laws are looking at this.
Netflix: A Documentary
Since all of us got onto the content-watching bandwagon, we also put in a lot of money (depending where you are at) on the type of subscription that we sign-up for, over a particular over-the-top (OTT) platform. Netflix was not far from this, it allowed, and continues to allow for several profiles to be created within a main account and allows for preferences and restrictions placed across such distinct profiles. However, while all of this began smoothly, gradually with a greater number of users willing to share their passwords with friends, colleagues, extended family, the idea of having a “Netflix account” for a “household” jumped over the fence.
A quick review of the Netflix Terms of Use clarify that a license to Netflix ‘services’ (personalized service for discovering and accessing Netflix content, including all features and functionalities, recommendations and reviews, our websites, and user interfaces, as well as all content and software associated with our service) is extended to the subscriber, who may further distribute “password” and thereby access to their account, independent profiles, basis the subscription package availed by the subscriber. The very essence of these terms was that the users were able to share their Netflix service with individuals beyond their household as and where allowed by their subscription plan. Netflix garnered a significant market in the streaming industry, albeit with heavy losses on account of usage of single account credentials across multiple members.
Netflix has rolled out a pilot program in Canada, New Zealand, Portugal, and Spain to introduce new terms to address password sharing concerns, whereby users shall be required to set up a primary location for mandatory login, to signify that such individuals belong to the same household. Members will further be enabled to manage access to their account for account security purposes and will be provided with greater control over how they intend their profiles within an account, and how the devices which use the same log-in can interact. The pilot program intends to limit distribution of passwords by members to a specific household, as against the indiscriminate sharing practices that users indulge in on a daily basis.
The pilot program has stimulated a parallel discussion in the legal fraternity, as to the legality of password sharing, and its nexus with copyright infringement, and the perception of password sharing as a method for circumvention of technical measures to protect copyrighted works in the industry. We will seek to analyze the prominent judicial pronouncements, legislations in this regard, and establish a similar parallel within Indian jurisprudence, to determine whether such actions may amount to an action of copyright infringement in India.
Regulatory Landscape
United States. The Computer Fraud and Abuse Act of 1986 (CFAA) is the predominant federal cybersecurity law in the US, which prohibits access to a computer without authorization, or in excess of authorization. While initially intended towards the protection of “protected computers”, in practice, any ordinary computer, connected device is now scoped under the definition of this law, including mobile phones, due to the cross-border nature of most internet communication.
Pertinently, the US Court of Appeals for the Ninth Circuit dealt with the scope of authorized access and password usage in the matter of United States v Nosal, wherein employees had utilized their login credentials to the company network to misappropriate company confidential information to establish a competing business. The accused, all ex-employees, had relied upon the login credentials of the organization to misappropriate confidential information during their stint with the organization from the company network, and had used such information to establish a competing business. The Court of Appeals rejected Nosal’s argument that the employee’s permission to use the credentials amounted to sufficient authorization and held that the authority [capable of authorizing access] is solely permitted to allow or disallow access to its systems. The Court deemed an employee “exceeds authorized access” when he has approval to access a computer but uses his access to obtain or alter information that falls outside the bounds of his approved access.
The Court of Appeals further refused to provide a broadscale definition to ‘circumvention of technological barriers’ and held that the password system in use by the employer would amount to a legitimate technological access barrier, which has been circumvented by the employees in excess of their employment terms. Moreover, they held that the password system adopted by employer unquestionably represents a technological barrier designed to keep out those “without authorization.” It is important to bear in mind that the context that brought fore this conversation was entirely focused on how an employee and employer relationship prerequisites certain accesses and controls be afforded to the employee, during the course of their employment. However, this also clearly enunciated that the “purpose” which is mapped for creation of credentials and continued availment of the same, should not be tempered with at the whims of the user.
United Kingdom. Much recently, The United Kingdom Intellectual Property Office (UK IPO) published guidance documents in December 2022, on avoiding piracy and counterfeit goods online and indicated that pasting internet images into social media accounts, password sharing on streaming services and accessing the latest films, TV series or live sports events through kodi boxes, fire sticks or apps without paying a subscription are all violative of copyright law. UK has typically prosecuted violators for video piracy under the provisions of the Fraud Act, 2006, which considers obtaining services of a member’s club without payment, as an offence. According to the guidance document, violators may further be prosecuted for breach of contractual terms, secondary copyright infringement in addition to fraud charges, per the original [non-redacted] version of the UK IPO Guidance, thereby ensuring civil and criminal liability for piracy actions in the UK.
Indian Perspective
In the Indian context, this has not been tested yet, neither in the context of any potential threats under the IT laws, nor under the defined copyright laws. We find that the provisions relevant to this exercise may be found within the Copyright Act, 1957 (Copyright Act) and the Information Technology Act, 2000 (IT Act). The IT Act provides guidance on the manner of usage of digital certificates, computer networks, computer systems, and lists out an array of offences actionable under Indian criminal law, for violation of the provisions of the IT Act.
The Copyright Act has over time, undergone several amendments, to align it with the best practices in international intellectual property law. Consequently, in order to address the considerations for copyrighted content in the digital space, the Copyright Act was amended in 2012, to align the provisions of the legislation with India’s commitments under the World Intellectual Property Organization (WIPO) Copyright Treaty as well as the WIPO Performances and Phonogram Treaty. Section 65A, introduced vide this amendment, provides criminal liability for any person, who intentionally circumvents an effective technological measure. Furthermore, Section 51 of the Copyright Act penalizes any action of a person who performs any action in excess of the license terms for the limited usage of any copyrighted content.
Furthermore, the IT Act penalizes any person who accessed or secures access to such computer, computer system or computer network without permission of the owner or any other person who is in charge of a computer, computer system or computer network. The IT Act defines ‘computer network’ means the inter-connection of one or more computers or computer systems or communication device through–
the use of satellite, microwave, terrestrial line, wire, wireless or other communication media; and
terminals or a complex consisting of two or more interconnected computers or communication device whether or not the inter-connection is continuously maintained.
In view of the extensive infrastructure and financial investments made by Netflix to offer their services across jurisdictions, Netflix may be deemed as the owner of this computer network. Accordingly, Netflix may rely upon such provisions to build an argument against, any user access to its computer network, without appropriate authorization.
Accordingly, in order to move against a user who seeks to share their passwords with members outside the household, an organization may seek refuge under S. 65A of the Copyright Act r/w S. 43(a), (g)of the IT Act. As the user has no authorization from Netflix to share password details beyond their household, they may be treated to having acted in excess of terms prescribed provided by the owner of the computer network, to circumvent technological barriers, intended to safeguard copyrighted content. It is also important to note here that the subscriber, while registering with Netflix specifically agrees to the terms of use and chooses to abide by them.
It is important to bear in mind that while Netflix focuses on making content available to the end users, when it comes to gaining access to user profiles, the subscriber is subject to the terms which explain how password sharing, may work for a set household, and that is Netflix enabling access to their own computer network. The platform has been releasing a lot of information for people to understand how they can interact with the platform, their profiles, and what all additional measures they will need to undertake to ensure that they are not logged out of their devices inadvertently or are not able to realize full functionalities with equal convenience.
Conclusion
Revolution in technology has often led to evolution in copyright law. We have witnessed these changes in the US and the UK, which factored in prevalent sharing/ infringement activities, made possible vide the internet today. Such advances have in part challenged the constitutional balance between the interests of copyright owners in the exploitation of their works and society’s interest in the free flow of information.
Review of anti-circumvention protocols, designated by regulatory agencies and actioned by stakeholders, will form a significant portion of the discourse in this regard in the future, due to the ease of replication, transmission over the internet.
However, digital rights management tools have historically represented a double-edged sword in the media and entertainment industry. The success of subscription-based music services today may be attributable to the development of DRM tools in the industry, whereas death of the e-books industry may be attributed to DRM tools, which restrict dissemination on reading devices, printing capabilities. All stakeholders will inevitably be required to work in tandem, to flesh out the contours of content distribution over the internet in the long run. With the advent of new age technologies, we anticipate unprecedented levels of generation of copyrightable and transmissible content, which will necessitate amendment of overlapping laws.
While the Indian judiciary is yet to deliberate on the extent of the technological measures which may be implemented to protect any copyrighted works, or the manner of its circumvention, we may surmise a similar interpretation to the Court of Appeals of the Ninth Circuit, and may afford a similar right to Netflix, to protect itself against unauthorized dissemination of user account credentials.