Questions & explanations
1. What is the private right of action under the California Consumer Privacy Act (CCPA)?
The private right of action under the CCPA allows consumers to sue businesses directly if their personal information is subject to a data breach due to the business's failure to maintain reasonable security. This right is limited to data breaches of certain categories of personal information, such as Social Security numbers, driver's license numbers, financial account numbers, medical information, or email addresses combined with passwords. Consumers can seek statutory damages between $100 and $750 per consumer per incident, or actual damages, whichever is greater. They must first give the business 30 days to cure the violation before filing a lawsuit. This right does not cover other CCPA violations, which are enforced by the California Attorney General.
2. What is the Anti-Kickback Statute (AKS) and how does it differ from the Stark Law?
The Anti-Kickback Statute (AKS) is a federal criminal law that prohibits offering, paying, soliciting, or receiving anything of value to induce or reward referrals of federal healthcare program business (like Medicare or Medicaid). The Stark Law (Physician Self-Referral Law) is a civil law that prohibits physicians from referring patients to entities with which they (or their family) have a financial relationship for designated health services. Key differences: AKS is intent-based (requires knowing and willful), while Stark is strict liability (no intent needed). AKS covers all referrals, Stark only covers specific services. Violations of AKS can lead to criminal penalties, while Stark violations result in civil fines and exclusion.
3. Compare the antitrust risks of sharing current pricing information versus sharing historical aggregated data.
Sharing current pricing information among competitors is highly risky because it can directly facilitate price coordination. If competitors know each other's current prices, they can easily match or undercut them, leading to collusion. In contrast, sharing historical aggregated data, such as average prices from six months ago, is much safer. Historical data is less likely to help competitors coordinate future prices because it is outdated. Aggregation also prevents identifying individual company strategies. However, even historical data can be risky if it is too recent or detailed. The key difference is that current data increases the chance of coordinated behavior, while historical aggregated data reduces that risk.
4. A doctor refers patients to a lab in which she owns shares. Is this automatically a Stark Law violation?
Not automatically; it depends on whether the lab provides designated health services (DHS) and whether an exception applies. The Stark Law prohibits a physician from referring Medicare patients to an entity for DHS if the physician (or an immediate family member) has a financial relationship with the entity. Ownership is a financial relationship. However, there are exceptions, such as the in-office ancillary services exception (if the lab is in the same office and the physician personally performs or supervises the tests) or the group practice exception. If no exception applies, the referral is illegal, even if the physician did not intend to violate the law. The lab cannot bill Medicare for those services.
5. How do countries cooperate on antitrust issues that affect international trade?
Countries cooperate through bilateral agreements and international organizations like the International Competition Network (ICN). For example, when a cartel operates in multiple countries, competition authorities share information and coordinate enforcement actions. They also try to harmonize their rules to reduce conflicts. The World Trade Organization (WTO) sometimes addresses competition issues, but it mainly focuses on trade. Cooperation helps prevent situations where a company is punished in one country but allowed in another. However, differences in laws and procedures can make cooperation difficult. The goal is to ensure that anticompetitive behavior does not undermine the benefits of free trade.
6. What is the Noerr-Pennington doctrine?
The Noerr-Pennington doctrine protects companies when they ask the government to take actions that might hurt their competitors. For example, a company can lobby a city council to pass a law that makes it harder for a rival to do business. Even if the law would reduce competition, the company is immune from antitrust lawsuits because it is exercising its right to petition the government. This protection applies to all kinds of government requests, like filing a lawsuit or applying for a permit. However, the protection is lost if the petition is a 'sham'—meaning the company doesn't really want government action, just to harm a competitor directly. The doctrine balances free speech with antitrust rules.
7. How does the indoor management rule differ from constructive notice?
Constructive notice assumes outsiders know the company's public documents, while the indoor management rule says outsiders do not need to check internal procedures. Constructive notice puts a burden on outsiders to read public filings. The indoor management rule protects outsiders from hidden internal problems. For example, if a company's articles require a board meeting to approve a loan, constructive notice says the outsider should know that rule. But the indoor management rule says the outsider can assume the meeting happened. So, one rule requires checking public documents, the other protects reliance on internal regularity. Together, they balance the company's and outsider's interests.
8. What is the right to erasure under the GDPR, and when can a person request it?
The right to erasure, also called the 'right to be forgotten,' allows individuals to request that a data controller delete their personal data without undue delay. This right applies in several situations: the data is no longer needed for the purpose it was collected; the individual withdraws consent and there is no other legal ground; the individual objects to processing based on legitimate interests and there are no overriding legitimate grounds; the data was unlawfully processed; or the data must be erased to comply with a legal obligation. However, the right is not absolute and may be limited if the data is needed for exercising freedom of expression, legal compliance, or public health.
9. How does antitrust treatment of sports leagues differ between the US and Europe?
In the US, professional sports leagues are often treated as single entities for antitrust purposes, meaning that the league itself is not considered a conspiracy among teams. This gives leagues more freedom to set rules. In Europe, leagues are more likely to be seen as associations of independent businesses, so their rules are subject to stricter antitrust scrutiny. For example, the European Court of Justice has ruled that FIFA's transfer rules can violate competition law. Also, European leagues often have open structures with promotion and relegation, which are considered more competitive. The US model allows more centralized control, while Europe emphasizes individual club autonomy.
10. What is the interaction between antitrust and international trade policy?
Antitrust and trade policy both aim to promote competition, but they work differently. Trade policy focuses on reducing barriers between countries, like tariffs and quotas, to allow foreign goods to compete. Antitrust focuses on preventing anticompetitive behavior within a market, like cartels or abuse of dominance. Sometimes, trade policy can conflict with antitrust. For example, if a country allows a domestic monopoly to protect it from foreign competition, that may harm consumers. Ideally, trade liberalization and antitrust enforcement work together to open markets and ensure fair competition. International cooperation is important to address cross-border anticompetitive practices.
11. A company suffers a data breach exposing customers' names and email addresses. Can customers sue under the CCPA private right of action?
No, because names and email addresses alone are not among the categories of personal information that trigger the private right of action. The CCPA private right of action applies only to breaches of specific data types: Social Security numbers, driver's license numbers, financial account numbers (with security codes), medical information, health insurance information, or email addresses combined with a password or security questions. If the breach exposed only names and email addresses without passwords, it does not qualify. Customers would have to rely on other laws or wait for the Attorney General to enforce. The business may still face regulatory action for failing to secure data.
12. What antitrust risks arise when competitors share information through trade associations?
When competitors share information through trade associations, they risk violating antitrust laws if the sharing leads to coordination on prices, output, or markets. Even if the information is not about future plans, sharing current or historical data can help competitors align their behavior. Trade associations must be careful to avoid discussions that reduce uncertainty about competitors' actions. For example, sharing detailed cost data or pricing strategies can be risky. To lower risk, associations should use an independent third party to collect and aggregate data, and avoid sharing individual company data. The key is that information sharing should not facilitate collusion.