{"id":3212,"date":"2016-03-31T19:36:57","date_gmt":"2016-03-31T19:36:57","guid":{"rendered":"http:\/\/jolt.richmond.edu\/?p=3212"},"modified":"2021-05-13T19:43:01","modified_gmt":"2021-05-13T23:43:01","slug":"addressing-employee-use-of-personal-clouds","status":"publish","type":"post","link":"https:\/\/blog.richmond.edu\/jolt\/2016\/03\/31\/addressing-employee-use-of-personal-clouds\/","title":{"rendered":"Addressing Employee Use of Personal Clouds"},"content":{"rendered":"<p>[et_pb_section admin_label=&#8221;section&#8221;]<br \/>\n\t\t\t[et_pb_row admin_label=&#8221;row&#8221;]<br \/>\n\t\t\t\t[et_pb_column type=&#8221;4_4&#8243;][et_pb_text admin_label=&#8221;Text&#8221;]<\/p>\n<p style=\"text-align: left\"><a href=\"http:\/\/jolt.richmond.edu\/files\/2017\/03\/Favro-Publication-Version.pdf\" rel=\"\">Favro Publication Version<\/a><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-128\" src=\"http:\/\/jolt.richmond.edu\/files\/2012\/05\/pdf_icon1.gif\" alt=\"pdf_icon\" width=\"16\" height=\"16\" \/><\/p>\n<p style=\"text-align: center\">Cite as: Philip Favro, Addressing Employee Use of Personal Clouds, 22 Rich. J.L. &amp; Tech. 6 (2016), http:\/\/jolt.richmond.edu\/v22i3\/article6.pdf.<\/p>\n<p style=\"text-align: center\">Philip Favro*<\/p>\n<p>&nbsp;<\/p>\n<p style=\"text-align: center\"><strong>I. INTRODUCTION<\/strong><\/p>\n<p>[1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cloud computing is one of the most useful innovations in the digital age.<a href=\"#_ftn1\" name=\"_ftnref1\">[1]<\/a> While much of the attention on recent advances has focused on smartphones, tablet computers, and wearable technology, the cloud is perhaps unrivaled in its utility for organizations.<a href=\"#_ftn2\" name=\"_ftnref2\">[2]<\/a> From simplified data storage to innovative software platforms, enterprise-grade cloud solutions provide cost-effective alternatives to acquiring expensive computer hardware and software.<a href=\"#_ftn3\" name=\"_ftnref3\">[3]<\/a> Enterprise clouds also offer a collaborative work environment for a mobile and widespread work force, enabling businesses to maximize worker productivity.<a href=\"#_ftn4\" name=\"_ftnref4\">[4]<\/a><\/p>\n<p>[2]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Organizations are not alone in reaping the benefits of cloud computing. Individuals have likewise discovered the value that cloud providers offer in their personal lives.<a href=\"#_ftn5\" name=\"_ftnref5\">[5]<\/a> With increased storage for digital photos, music, and other files, personal cloud providers help users avoid losing personal data when a computer hard drive inevitably fails.<a href=\"#_ftn6\" name=\"_ftnref6\">[6]<\/a> Furthermore, the transfer functionality afforded by personal clouds enables users to seamlessly move data between computers, smartphones, and other mobile devices.<a href=\"#_ftn7\" name=\"_ftnref7\">[7]<\/a><\/p>\n<p>[3]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 With such utility at their fingertips, it should come as no surprise that individuals use personal clouds to facilitate work responsibilities.<a href=\"#_ftn8\" name=\"_ftnref8\">[8]<\/a> Personal cloud providers like Dropbox, Box, and Google Drive can obviate clunky network storage options and simplify data sharing and teamwork among colleagues.<a href=\"#_ftn9\" name=\"_ftnref9\">[9]<\/a> While employees of many organizations\u00a0could benefit from such functionality, it is particularly advantageous to workers whose employers lag behind the technology curve.<a href=\"#_ftn10\" name=\"_ftnref10\">[10]<\/a><\/p>\n<p>[4]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 These and other features seem to make personal clouds an ideal tool for advancing business objectives within the corporate environment.<a href=\"#_ftn11\" name=\"_ftnref11\"><sup><sup>[11]<\/sup><\/sup><\/a> Appearances, however, can be deceiving. That is exactly the case with employee use of personal cloud applications in the workplace.<a href=\"#_ftn12\" name=\"_ftnref12\"><sup><sup>[12]<\/sup><\/sup><\/a> From information retention and information security to litigation readiness and cybersecurity, personal cloud use among employees implicates a range of troubles for organizations.<a href=\"#_ftn13\" name=\"_ftnref13\"><sup><sup>[13]<\/sup><\/sup><\/a> Indeed, the very aspects that make personal clouds so attractive\u2013cheap and unlimited storage, simplified transfers, and increased collaboration\u2013pose serious threats to the enterprise.<a href=\"#_ftn14\" name=\"_ftnref14\">[14]<\/a><\/p>\n<p>[5]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Nevertheless, companies in many instances have taken few, if any, actionable steps to address the proliferation of personal cloud use among their employees.<a href=\"#_ftn15\" name=\"_ftnref15\">[15]<\/a> Worse, some organizations have implemented \u201cbring your own cloud\u201d (BYOC) policies that officially sanction employee use of consumer-grade cloud applications in the workplace without sufficient corporate oversight.<a href=\"#_ftn16\" name=\"_ftnref16\">[16]<\/a> A BYOC policy that lacks proper measures to ensure compliance may very well result in a disastrous outcome for the enterprise.<a href=\"#_ftn17\" name=\"_ftnref17\">[17]<\/a><\/p>\n<p>[6]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In this article, I address these issues by surveying recent court cases that exemplify the information governance and litigation challenges arising from personal cloud use in the business enterprise. In particular, I discuss the problems with BYOC practices that expressly or implicitly enable employee use of personal clouds. I also spotlight some of the troubles that stealth use of personal clouds creates for organizations. I conclude by suggesting some practices that can help organizations ameliorate these problems.<\/p>\n<p style=\"text-align: center\"><strong>\u00a0<\/strong><strong>II. LAISSEZ-FAIRE TREATMENT OF PERSONAL CLOUD<br \/>\nUSE IN THE CORPORATE ENVIRONMENT<\/strong><\/p>\n<p>[7]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Employers are often directly responsible for the difficulties that have resulted from employee use of cloud applications.<a href=\"#_ftn18\" name=\"_ftnref18\">[18]<\/a> That employers are at fault does not stem from this being a new trend. Indeed, personal cloud providers have been around since the 2000s,<a href=\"#_ftn19\" name=\"_ftnref19\">[19]<\/a> with courts\u00a0examining the troubles associated with cloud computing beginning in 2011.<a href=\"#_ftn20\" name=\"_ftnref20\">[20]<\/a>Organizations previously overlooked the risks of this trend by authorizing their executives or employees to use personal cloud applications in the corporate ecosystem.<a href=\"#_ftn21\" name=\"_ftnref21\">[21]<\/a> In addition, they ignored the hazards associated with the stealth use of personal clouds.<a href=\"#_ftn22\" name=\"_ftnref22\">[22]<\/a> This Part examines cases that address these aspects of employee use of consumer clouds.<\/p>\n<p style=\"padding-left: 60px\"><strong>\u00a0<\/strong><strong>A. Corporate Approved BYOC Accounts<\/strong><\/p>\n<p>[8]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 In many instances, organizations have openly welcomed the use of personal clouds by their employees.<a href=\"#_ftn23\" name=\"_ftnref23\">[23]<\/a> Whether by policy or by practice, corporate IT departments have approved personal cloud use by expressly enabling its functionality.<a href=\"#_ftn24\" name=\"_ftnref24\">[24]<\/a> Nevertheless, that is often the extent of corporate oversight.<a href=\"#_ftn25\" name=\"_ftnref25\">[25]<\/a> Beyond requiring an employee to sign a perfunctory\u00a0non-disclosure agreement, little follow up effort is taken to prevent employees from transferring confidential information from company servers to a personal cloud.<a href=\"#_ftn26\" name=\"_ftnref26\">[26]<\/a><\/p>\n<p>[9]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Such corporate inaction can be challenging for cybersecurity initiatives, retention schedules, and preservation requirements in litigation. However, it can be especially problematic when an employee leaves the company with proprietary materials and begins working for an industry competitor.<a href=\"#_ftn27\" name=\"_ftnref27\">[27]<\/a> The <em>Selectica v. Novatus<\/em><a href=\"#_ftn28\" name=\"_ftnref28\">[28]<\/a> and <em>PrimePay v. Barnes<\/em><a href=\"#_ftn29\" name=\"_ftnref29\">[29]<\/a> decisions are particularly instructive on the need for organizations to abandon their laissez-faire attitude toward employee use of approved BYOC accounts.<\/p>\n<ol>\n<li><strong> <em>Selectica v. Novatus<\/em><\/strong><\/li>\n<\/ol>\n<p>[10]\u00a0\u00a0\u00a0\u00a0 In <em>Selectica<\/em>, plaintiff (Selectica) filed suit against defendant (Novatus), claiming Novatus misappropriated various trade secrets.<a href=\"#_ftn30\" name=\"_ftnref30\">[30]<\/a> In particular, Selectica alleged that four of its former sales personnel violated their respective non-disclosure agreements by sharing confidential pricing\u00a0information with Novatus, their new employer.<a href=\"#_ftn31\" name=\"_ftnref31\">[31]<\/a> Those agreements provided that the employees would maintain the confidentiality of Selectica\u2019s proprietary information and return all such materials to the company upon termination of their employment.<a href=\"#_ftn32\" name=\"_ftnref32\">[32]<\/a><\/p>\n<p>[11]\u00a0\u00a0\u00a0\u00a0 Despite those agreements, one of the employees (Holt) offered to share Selectica\u2019s pricing information to a member of Novatus\u2019 senior management team after joining Novatus.<a href=\"#_ftn33\" name=\"_ftnref33\">[33]<\/a> Holt still had access to that information along with other data belonging to Selectica because he maintained it with Box, a cloud storage provider.<a href=\"#_ftn34\" name=\"_ftnref34\">[34]<\/a> The Box account was not a stealth cloud drive concealed from Selectica.<a href=\"#_ftn35\" name=\"_ftnref35\">[35]<\/a><\/p>\n<p>[12]\u00a0\u00a0\u00a0\u00a0 Instead, Selectica expressly recommended and authorized Holt to store that data under a BYOC arrangement with Box: \u201cWhile employed by Selectica, [Holt] had a company laptop computer which, <em>on Selectica\u2019s recommendation<\/em>, was configured so that it automatically synced to his personal cloud storage account at Box.com. This meant that when Holt saved a file to the laptop, the system pushed a copy to his Box account.\u201d<a href=\"#_ftn36\" name=\"_ftnref36\">[36]<\/a> Despite having enabled the BYOC arrangement with Holt, Selectica apparently neglected to disable the Box account or remove any proprietary materials upon Holt\u2019s departure.<a href=\"#_ftn37\" name=\"_ftnref37\">[37]<\/a> As a result, Holt had full access to the pricing information when he joined Novatus.<a href=\"#_ftn38\" name=\"_ftnref38\">[38]<\/a><\/p>\n<p>[13]\u00a0\u00a0\u00a0\u00a0 <em>Selectica<\/em> demonstrates the folly of a lax approach to personal cloud use within the enterprise. While Selectica enabled the Box account for backup purposes, it took no action to protect Selectica\u2019s interest in the corporate information stored in that account. For example, Selectica did not obtain Holt\u2019s login credentials to the Box account.<a href=\"#_ftn39\" name=\"_ftnref39\">[39]<\/a> Nor does it appear that Selectica monitored Holt\u2019s use of the account while employed with the company.<a href=\"#_ftn40\" name=\"_ftnref40\">[40]<\/a> Selectica did not disable the Box account when Holt left the company.<a href=\"#_ftn41\" name=\"_ftnref41\">[41]<\/a> Furthermore, Selectica took no action to confirm that Holt had either returned or destroyed all proprietary company information before going to work for Novatus.<a href=\"#_ftn42\" name=\"_ftnref42\">[42]<\/a><\/p>\n<p>[14]\u00a0\u00a0\u00a0\u00a0 Any one of these steps\u2014and certainly a combination of them\u2014would likely have prevented the disclosure of Selectica\u2019s product pricing information to an industry competitor.<a href=\"#_ftn43\" name=\"_ftnref43\">[43]<\/a> <em>Selectica<\/em> exemplifies the need for corporate oversight of approved BYOC accounts if organizations are to prevent their trade secrets from falling into the hands of competitors.<\/p>\n<ol start=\"2\">\n<li><strong><em> PrimePay v. Barnes<\/em><\/strong><\/li>\n<\/ol>\n<p>[15]\u00a0\u00a0\u00a0\u00a0 Another exemplary decision on these issues is <em>PrimePay v. Barnes<\/em>.<a href=\"#_ftn44\" name=\"_ftnref44\">[44]<\/a> Like <em>Selectica<\/em>, <em>PrimePay<\/em> involves claims of trade secret misappropriation.<a href=\"#_ftn45\" name=\"_ftnref45\">[45]<\/a> In <em>PrimePay<\/em>, the plaintiff (PrimePay) sued one of its\u00a0former executives (Barnes) that established a competing business entity.<a href=\"#_ftn46\" name=\"_ftnref46\">[46]<\/a> PrimePay moved for a preliminary injunction against the operation of Barnes\u2019 business, arguing that Barnes took several categories of confidential PrimePay information and stored it with cloud service provider Dropbox, along with other locations.<a href=\"#_ftn47\" name=\"_ftnref47\">[47]<\/a> According to PrimePay, Barnes accessed the Dropbox-stored data to allegedly help start his competing company. He then allegedly destroyed those materials after the plaintiff warned him \u201cto preserve any PrimePay electronically stored information that he possessed.\u201d<a href=\"#_ftn48\" name=\"_ftnref48\">[48]<\/a><\/p>\n<p>[16]\u00a0\u00a0\u00a0\u00a0 In response to these arguments, Barnes asserted that he never absconded with PrimePay\u2019s proprietary data.<a href=\"#_ftn49\" name=\"_ftnref49\">[49]<\/a> Instead, Barnes explained that any PrimePay data in his Dropbox account was from work that he previously performed while at PrimePay.<a href=\"#_ftn50\" name=\"_ftnref50\">[50]<\/a> According to Barnes, that data was mostly deleted at the time he left the company.<a href=\"#_ftn51\" name=\"_ftnref51\">[51]<\/a> As for the origin of the Dropbox account, it was created far in advance of Barnes\u2019 departure from the company.<a href=\"#_ftn52\" name=\"_ftnref52\">[52]<\/a> Its purpose was not to steal proprietary data, Barnes argued, but to allow him to complete work for PrimePay when he was away from the office.<a href=\"#_ftn53\" name=\"_ftnref53\">[53]<\/a> Nor was this a stealth account; it was a company-approved BYOC:<\/p>\n<p style=\"padding-left: 30px\">Barnes created the Dropbox [account] . . . so that he could transfer and access files when he worked remotely on PrimePay matters if he was away from the office, on vacation or elsewhere and needed access to the PrimePay files, all with the knowledge and approval of [PrimePay owner] Chris Tobin.<a href=\"#_ftn54\" name=\"_ftnref54\">[54]<\/a><\/p>\n<p>[17]\u00a0\u00a0\u00a0\u00a0 Given that Barnes\u2019 Dropbox account was a company-approved BYOC account, and in light of other evidence suggesting Barnes did not access the Dropbox files or other proprietary PrimePay information after leaving his position with the company, the court did not find evidence of trade secret misappropriation.<a href=\"#_ftn55\" name=\"_ftnref55\">[55]<\/a> While the court ordered the destruction of PrimePay\u2019s remaining confidential information stored on the Dropbox, it refused to issue a preliminary injunction against the operation of Barnes\u2019 competing enterprise.<a href=\"#_ftn56\" name=\"_ftnref56\">[56]<\/a><\/p>\n<p>[18]\u00a0\u00a0\u00a0\u00a0 <em>PrimePay<\/em> reinforces the lesson from <em>Selectica<\/em> that a laissez-faire approach to personal clouds may lead to corporate disasters. Because PrimePay did not monitor or disable the Dropbox account, Barnes apparently left the company with a massive trove of proprietary company data. Even though the court accepted Barnes\u2019 explanation that he accessed little, if any, of that data after he left the company, PrimePay\u2019s evidence suggested otherwise.<a href=\"#_ftn57\" name=\"_ftnref57\">[57]<\/a> While PrimePay may never know how much of its information was used to start Barnes\u2019 competing enterprise, it is reasonably certain that a more robust compliance program would have quarantined the proprietary data before Barnes left the company.<a href=\"#_ftn58\" name=\"_ftnref58\">[58]<\/a> This may have obviated the legal expenses and opportunity costs of the litigation. Like <em>Selectica<\/em>, <em>PrimePay<\/em> ultimately teaches that organizations\u00a0should police approved BYOC environments to better safeguard proprietary corporate information.<\/p>\n<p style=\"padding-left: 60px\"><strong>\u00a0<\/strong><strong>B. \u00a0Stealth Use of Personal Clouds<\/strong><\/p>\n<p>[19]\u00a0\u00a0\u00a0\u00a0 Beyond the problem of a poorly monitored BYOC ecosystem stands the equally troubling scenario of stealth use of personal clouds.<a href=\"#_ftn59\" name=\"_ftnref59\">[59]<\/a> Such a scenario involves employees using their personal cloud accounts in connection with their work duties without express company approval.<a href=\"#_ftn60\" name=\"_ftnref60\">[60]<\/a> While some employees do so in good faith to facilitate their work, others clandestinely use their cloud accounts to sabotage the organization or to gain a competitive advantage over their former employers after leaving the company.<a href=\"#_ftn61\" name=\"_ftnref61\">[61]<\/a> A number of decisions demonstrate the problems with stealth\u2014or \u201cshadow\u201d\u2014use of personal clouds across the spectrum of corporate employees.<a href=\"#_ftn62\" name=\"_ftnref62\">[62]<\/a><\/p>\n<ol>\n<li><strong> Operations-Level Employee<\/strong><\/li>\n<\/ol>\n<p>[20]\u00a0\u00a0\u00a0\u00a0 Operations-level employees are often at the heart of stealth use of personal clouds. For example, in <em>Toyota Industrial Equipment Manufacturing v. Land<\/em>, a managerial level employee (Land) used Google Drive and other personal cloud applications to steal hundreds of critical\u00a0documents from his employer (Toyota) before going to work for an industry competitor.<a href=\"#_ftn63\" name=\"_ftnref63\">[63]<\/a> Those documents included technical specifications reflecting the proprietary design of certain industrial equipment, along with related pricing and financial information.<a href=\"#_ftn64\" name=\"_ftnref64\">[64]<\/a> While authorized to use that data during his employment, Land stored and kept shadow copies of these materials on his Google Drive account so they could be accessible after he left Toyota.<a href=\"#_ftn65\" name=\"_ftnref65\">[65]<\/a><\/p>\n<p>[21]\u00a0\u00a0\u00a0\u00a0 To facilitate the removal of Toyota\u2019s proprietary information, Land downloaded \u201cGoogleDriveSync.exe\u201d on his work computer.<a href=\"#_ftn66\" name=\"_ftnref66\"><sup><sup>[66]<\/sup><\/sup><\/a> Similar to the corporate-enabled Box account in <em>Selectica<\/em>, the GoogleDriveSync.exe program enabled Land to simultaneously save documents on his personal Google Drive account that he saved to his company-issued computer.<a href=\"#_ftn67\" name=\"_ftnref67\">[67]<\/a> On the eve of his departure from Toyota, Land placed approximately 800 \u201cfiles and folders\u201d on Google Drive.<a href=\"#_ftn68\" name=\"_ftnref68\">[68]<\/a> These actions\u2014Land removing and then retaining Toyota\u2019s proprietary information after his departure from the company in violation of his non-disclosure agreement\u2014resulted in an injunction preventing Land from working for Toyota\u2019s competitor.<a href=\"#_ftn69\" name=\"_ftnref69\">[69]<\/a><\/p>\n<p>[22]\u00a0\u00a0\u00a0\u00a0 Another case involving stealth cloud use by an operations-level employee is <em>RLI Insurance Company v. Banks<\/em>.<a href=\"#_ftn70\" name=\"_ftnref70\">[70]<\/a> In <em>RLI<\/em>, the employee (Banks) used a Norwegian cloud provider (Jottacloud)<a href=\"#_ftn71\" name=\"_ftnref71\">[71]<\/a> to upload \u201c757\u00a0customer claim files and other files containing proprietary information\u201d belonging to her employer (RLI).<a href=\"#_ftn72\" name=\"_ftnref72\">[72]<\/a> Banks initially tried to upload the files to her Dropbox account, but RLI\u2019s corporate network denied access to Dropbox.<a href=\"#_ftn73\" name=\"_ftnref73\">[73]<\/a> RLI had employed a web filtering software blocking employees from accessing more commonly used cloud providers, such as Dropbox.<a href=\"#_ftn74\" name=\"_ftnref74\">[74]<\/a> Undeterred, Banks researched \u201cDropbox alternatives\u201d that could evade RLI\u2019s filtering protocol, opened a Jottacloud account, and used that service to remove proprietary RLI data in violation of her employment agreement.<a href=\"#_ftn75\" name=\"_ftnref75\">[75]<\/a> RLI eventually discovered Banks\u2019 malfeasance, but only after offering her a severance package subsequent to her dismissal from the company.<a href=\"#_ftn76\" name=\"_ftnref76\">[76]<\/a><\/p>\n<ol start=\"2\">\n<li><strong> Company Executives<\/strong><\/li>\n<\/ol>\n<p>[23]\u00a0\u00a0\u00a0\u00a0 Operations-level employees are not alone in their furtive use of personal clouds. Company executives can also be guilty of such conduct. Given the nature of access that executives often have to critical information, such conduct can be particularly problematic. The <em>Frisco <\/em><em>Medical Center v. Bledsoe<\/em><a href=\"#_ftn77\" name=\"_ftnref77\">[77]<\/a> and <em>De Simone v. VSL Pharmaceuticals<\/em><a href=\"#_ftn78\" name=\"_ftnref78\">[78]<\/a> cases are instructive in this particular scenario.<\/p>\n<p>[24]\u00a0\u00a0\u00a0\u00a0 In <em>Frisco Medical<\/em>, the chief operating officer (Bledsoe) for a Texas hospital (Frisco) used Dropbox to obtain several classes of proprietary and patient information before leaving Frisco for a new position elsewhere.<a href=\"#_ftn79\" name=\"_ftnref79\">[79]<\/a> More specifically, Bledsoe installed Dropbox on her work computer <em>after<\/em> she accepted her new position but<em> before<\/em> she resigned from Frisco.<a href=\"#_ftn80\" name=\"_ftnref80\">[80]<\/a> With Dropbox enabled, Bledsoe then transferred \u201cFrisco\u2019s confidential and proprietary information, trade secrets, peer review materials, and statutorily protected patient health information to her personal\u201d cloud account in violation of her employment agreements.<a href=\"#_ftn81\" name=\"_ftnref81\">[81]<\/a><\/p>\n<p>[25]\u00a0\u00a0\u00a0\u00a0 Frisco did not suspect that Bledsoe surreptitiously removed proprietary information from its computer network until she revealed in an exit interview that \u201cshe knew where too many bodies were buried.\u201d<a href=\"#_ftn82\" name=\"_ftnref82\">[82]<\/a> It was only then that Frisco began investigating Bledsoe\u2019s computer usage, discovered her use of Dropbox, and determined the extent of the information she had taken from the hospital.<a href=\"#_ftn83\" name=\"_ftnref83\">[83]<\/a><\/p>\n<p>[26]\u00a0\u00a0\u00a0\u00a0 In contrast to <em>Frisco Medical<\/em>, <em>De Simone v. VSL Pharmaceuticals<\/em> involved a chief executive officer (De Simone) who used Dropbox to\u00a0deprive his company (VSL) of corporate records.<a href=\"#_ftn84\" name=\"_ftnref84\">[84]<\/a> De Simone, who served as VSL\u2019s chief executive for more than a decade, became embroiled in a dispute with investors over who rightfully owned VSL\u2019s intellectual property related to the probiotic drug sold by the company.<a href=\"#_ftn85\" name=\"_ftnref85\">[85]<\/a> In connection with that dispute, De Simone transferred VSL\u2019s corporate records to his personal Dropbox account.<a href=\"#_ftn86\" name=\"_ftnref86\">[86]<\/a> He then wiped the corporate network in order to eliminate any trace of the records and rejected shareholder requests to access the information.<a href=\"#_ftn87\" name=\"_ftnref87\">[87]<\/a> After resigning his position as VSL\u2019s CEO a few months later, De Simone began working for a competitive enterprise that manufactured and sold a generic version of VSL\u2019s probiotic drug, taking the corporate records with him.<a href=\"#_ftn88\" name=\"_ftnref88\">[88]<\/a><\/p>\n<ol start=\"3\">\n<li><strong> Analysis of Cloud Jurisprudence<\/strong><\/li>\n<\/ol>\n<p>[27]\u00a0\u00a0\u00a0\u00a0 The cases discussed so far generally involve harm to employers that likely could have been obviated had the organizations taken safeguards to prevent or detect stealth use of personal clouds.<a href=\"#_ftn89\" name=\"_ftnref89\">[89]<\/a> Instead, like <em>Selectica<\/em>, the employers in <em>Toyota Industrial<\/em>, <em>RLI<\/em>, and <em>Frisco Medical <\/em>relied on non-disclosure and other employment agreements to protect their sensitive and proprietary information.<a href=\"#_ftn90\" name=\"_ftnref90\">[90]<\/a><\/p>\n<p>[28]\u00a0\u00a0\u00a0\u00a0 On the one hand, those agreements successfully enabled the aggrieved parties to obtain injunctions, summary judgment orders, and damages against the cloud-wielding tortfeasors.<a href=\"#_ftn91\" name=\"_ftnref91\">[91]<\/a> But at what cost? The employers incurred legal fees and costs for the investigations and court actions they undertook to address the theft of corporate information by their former employees. In addition to those expenses, the organizations sustained substantial opportunity costs. Personnel were likely redirected from business operations to ameliorate the harm caused by the loss of proprietary data. Moreover, industry competitors may have become acquainted with strategic plans, pricing information, design specifications, financial performance, and other proprietary data. All of this may have provided their competitors with an advantage in subsequent business dealings.<a href=\"#_ftn92\" name=\"_ftnref92\">[92]<\/a><\/p>\n<p>[29]\u00a0\u00a0\u00a0\u00a0 Simply put, the non-disclosure and employment agreements did nothing to stop the perpetrating employees from misappropriating company trade secrets.<a href=\"#_ftn93\" name=\"_ftnref93\">[93]<\/a> Beyond the agreements, the only employer that apparently took anything close to a preventative step was RLI, which used a blocking program to prevent personal cloud use.<a href=\"#_ftn94\" name=\"_ftnref94\">[94]<\/a> However, even that step proved inadequate as the employee easily circumvented the software filter by using a previously unknown cloud application.<a href=\"#_ftn95\" name=\"_ftnref95\">[95]<\/a><\/p>\n<p>[30]\u00a0\u00a0\u00a0\u00a0 Just as in <em>Prime Pay<\/em>, none of the employers appears to have established a process to detect the possible use of personal cloud applications. This is evident from <em>De Simone<\/em>, as the company did not know that its chief executive used Dropbox to steal its corporate records.<a href=\"#_ftn96\" name=\"_ftnref96\">[96]<\/a> That no such process was in place in <em>RLI<\/em> is confirmed by the company\u2019s initial offering of severance pay to Banks.<a href=\"#_ftn97\" name=\"_ftnref97\">[97]<\/a> The <em>Frisco<\/em> employer only began its search of Bledsoe\u2019s computer activity after she carelessly suggested she knew where the \u201cbodies were buried.\u201d<a href=\"#_ftn98\" name=\"_ftnref98\">[98]<\/a> In <em>Toyota Industrial<\/em>, no efforts were made either to examine Land\u2019s computer activity or to verify his next work destination after he tendered his resignation.<a href=\"#_ftn99\" name=\"_ftnref99\">[99]<\/a> Indeed, Toyota allowed Land to work for another two weeks at the company before his termination date.<a href=\"#_ftn100\" name=\"_ftnref100\">[100]<\/a><\/p>\n<p>[31]\u00a0\u00a0\u00a0\u00a0 With employees now regularly using consumer clouds in connection with their work responsibilities, organizations must be prepared to counteract their potential negative effects. As set forth in Part III, companies should develop proactive measures to address employee use of cloud applications and to mitigate any resulting harm.<\/p>\n<p style=\"text-align: center\"><strong>III. PROACTIVE STEPS TO ADDRESS PERSONAL CLOUD USE<\/strong><\/p>\n<p>[32]\u00a0\u00a0\u00a0\u00a0 Despite the complexities that personal clouds now present for many organizations, they are not insurmountable. Enterprises can generally manage potential problems through a proactive, common sense\u00a0approach to information governance. In this Part, I discuss some of the key aspects of an information governance program that can help address the challenges associated with employee use of personal cloud applications.<\/p>\n<p>[33]\u00a0\u00a0\u00a0\u00a0 A prefatory step that organizations can take in this regard is to create a data map identifying the locations\u2014both on and off the corporate network\u2014where their information resides.<a href=\"#_ftn101\" name=\"_ftnref101\">[101]<\/a> While a data map is useful for both information retention and litigation purposes, it is essential for controlling ingress and egress to proprietary information\u2014precisely the data endangered by personal cloud applications.<a href=\"#_ftn102\" name=\"_ftnref102\">[102]<\/a> If a company cannot identify the precise areas where it has stored its trade secrets and other sensitive materials, it becomes difficult to establish that it used \u201creasonable steps\u201d to safeguard that information.<a href=\"#_ftn103\" name=\"_ftnref103\">[103]<\/a> In contrast, a current and accurate data map better enables organizations to reasonably account for proprietary records, along with other indispensable business information.<a href=\"#_ftn104\" name=\"_ftnref104\">[104]<\/a> Once the data map is in place, organizations can then proceed to develop policies that reasonably ensure the protection of corporate data.<a href=\"#_ftn105\" name=\"_ftnref105\">[105]<\/a><\/p>\n<p>[34]\u00a0\u00a0\u00a0\u00a0 Those policies should include actionable protocols that address employee use of personal cloud applications.<a href=\"#_ftn106\" name=\"_ftnref106\">[106]<\/a> Those protocols should clearly delineate whether personal clouds are permitted and if so, what constitutes an authorized BYOC account.<a href=\"#_ftn107\" name=\"_ftnref107\">[107]<\/a> Whether an enterprise chooses to ban the use of personal clouds or to adopt a BYOC-friendly environment, the policy should include audit and enforcement mechanisms to gauge policy observance.<a href=\"#_ftn108\" name=\"_ftnref108\">[108]<\/a> At a minimum, those mechanisms ought to include the right to monitor, access, and disable employee use of personal clouds.<a href=\"#_ftn109\" name=\"_ftnref109\">[109]<\/a> Related mechanisms will also be required for those organizations that proscribe BYOC use since employees\u00a0will likely circumvent such a policy.<a href=\"#_ftn110\" name=\"_ftnref110\">[110]<\/a> For example, blocking programs like the one used in <em>RLI<\/em>, while not foolproof, are a practicable first step to preventing some personal cloud use.<a href=\"#_ftn111\" name=\"_ftnref111\">[111]<\/a><\/p>\n<p>[35]\u00a0\u00a0\u00a0\u00a0 In a BYOC ecosystem, applicable protocols should additionally describe what company data can or cannot be transferred to the cloud.<a href=\"#_ftn112\" name=\"_ftnref112\">[112]<\/a> Organizations should also require the disclosure of user login credentials for approved cloud applications to ensure appropriate policy compliance.<a href=\"#_ftn113\" name=\"_ftnref113\">[113]<\/a> Upon an employee\u2019s termination, approved BYOC accounts should either be disabled or the company should verify that company data previously maintained in the account has been either returned or destroyed.<a href=\"#_ftn114\" name=\"_ftnref114\">[114]<\/a><\/p>\n<p>[36]\u00a0\u00a0\u00a0\u00a0 In like manner, non-BYOC organizations should consider examining terminated employees\u2019 computer activity and corporate devices to detect whether there was illicit use of personal clouds.<a href=\"#_ftn115\" name=\"_ftnref115\">[115]<\/a> However, such a step may not be practicable for many organizations that lack the\u00a0resources for a thorough review of every employee device. If a comprehensive sweep is cost prohibitive, organizations should consider conducting a review of those employees whose possible disclosure of corporate information carries the greatest risk to the enterprise.<a href=\"#_ftn116\" name=\"_ftnref116\">[116]<\/a> The extent to which a company carries out this step likely depends on the role of the terminated employees, their position in the company, and the nature of the information to which they were privy.<a href=\"#_ftn117\" name=\"_ftnref117\">[117]<\/a> Despite the expense of this procedure, such a step would likely have obviated much of the litigation that ensued in <em>Selectica<\/em>, <em>Novatus<\/em>, <em>Toyota Industrial<\/em>, <em>RLI<\/em>, and <em>Frisco Medical<\/em>.<\/p>\n<p style=\"text-align: center\"><strong>IV. CONCLUSION<\/strong><\/p>\n<p>[37]\u00a0\u00a0\u00a0\u00a0 The challenges with personal cloud applications need not be an intractable problem. Following industry best practices like those suggested in Part III should help organizations address many of the troubles associated with approved BYOC accounts. They should also mitigate the harm created by stealth cloud use that may go undetected. While certainly not an elixir, adopting these practices should help companies avoid many of the worst problems associated with personal cloud use in the enterprise.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"#_ftnref1\" name=\"_ftn1\"><\/a>*Consultant, Discovery and Information Governance, Driven, Inc.; J.D., Santa Clara University School of Law, 1999; B.A., Political Science, Brigham Young University, 1994.<\/p>\n<p>&nbsp;<\/p>\n<p>[1] <em>See<\/em> Joe McKendrick, <em>5 Benefits of Cloud Computing You Aren&#8217;t Likely to See in a Sales Brochure<\/em>, Forbes (July 21, 2013, 9:04 PM), http:\/\/www.forbes.com\/sites\/joemckendrick\/2013\/07\/21\/5-benefits-of-cloud-computing-you-arent-likely-to-see-in-a-sales-brochure\/#34a34b6e7d85, <em>archived at<\/em> http:\/\/perma.cc\/ET8N-JKG5.<\/p>\n<p><a href=\"#_ftnref2\" name=\"_ftn2\"><\/a>\u00a0[2] <em>See<\/em> Edwin Schouten, <em>5 Cloud Business Benefits<\/em>, Wired (Oct. 5, 2012), http:\/\/www.wired.com\/insights\/2012\/10\/5-cloud-business-benefits\/, <em>archived at<\/em> https:\/\/perma.cc\/7LJK-RP4M.<\/p>\n<p><a href=\"#_ftnref3\" name=\"_ftn3\"><\/a>\u00a0[3] <em>See<\/em> Jim Lynch, <em>What Are the Benefits and Drawbacks of Cloud Computing?<\/em>, TechSoup (Feb. 6, 2015), http:\/\/www.techsoup.org\/support\/articles-and-how-tos\/what-are-the-benefits-and-drawbacks-of-cloud-computing, <em>archived at <\/em>https:\/\/perma.cc\/9JYQ-AD93.<\/p>\n<p>[4] <em>See id<\/em>.<\/p>\n<p><a href=\"#_ftnref5\" name=\"_ftn5\">[5]<\/a> <em>See<\/em> Nicholas Lee, <em>Is Your Corporate Data Appearing on Personal Clouds?<\/em>, CloudTweaks (Sept. 9, 2015), http:\/\/cloudtweaks.com\/2015\/09\/is-your-corporate-data-appearing-on-personal-clouds\/, <em>archived at <\/em>https:\/\/perma.cc\/HD3C-VDDX.<\/p>\n<p>[6] <em>See<\/em> Zack Christenson, <em>Benefits of Cloud Computing<\/em>, American Consumer Institute (Sept. 30, 2013), http:\/\/www.theamericanconsumer.org\/2013\/09\/benefits-of-cloud-computing\/, <em>archived at<\/em> https:\/\/perma.cc\/9ATN-QEP2.<\/p>\n<p>[7] <em>See<\/em> Bill Kleyman, <em>What Personal Cloud Means for Consumers and Enterprises<\/em>, Data Center Knowledge (Sept. 10, 2013), http:\/\/www.datacenterknowledge.com\/archives\/2013\/09\/10\/what-personal-cloud-means-for-consumers-and-enterprises\/, <em>archived at <\/em>https:\/\/perma.cc\/RK2Z-VE6L.<\/p>\n<p>[8] <em>See<\/em> Louis Columbus, <em>How Enterprises Are Capitalizing on the Consumerization of IT<\/em>, Forbes (Mar. 24, 2014, 06:43 AM), http:\/\/www.forbes.com\/sites\/louiscolumbus\/2014\/03\/24\/how-enterprises-are-capitalizing-on-the-consumerization-of-it\/#1af595ef6160, <em>archived at<\/em> https:\/\/perma.cc\/38F9-KTQ6 (\u201c79% [of surveyed enterprises] report that file sharing and collaboration tools including Box, Egnyte, Google Apps, Microsoft Office 365, GroupLogic, ShareFile and others are pervasively used today. 49% are with IT approval and 30% are not.\u201d).<\/p>\n<p>[9] <em>See<\/em> Andrew Froehlich, <em>The Buck Stops at BYOC<\/em>, InformationWeek (Jan. 29, 2014, 12:00 PM), http:\/\/www.networkcomputing.com\/infrastructure\/buck-stops-byoc\/870595087, <em>archived at<\/em> https:\/\/perma.cc\/K7BV-HPPL (\u201cEmployees are comfortable using services such as DropBox, Google Apps, and Carbonite at home. Because of that comfort level, they naturally want to use those same tools in their business life.\u201d); Intermarine, L.L.C. v. Spliethoff Bevrachtingskantoor, B.V., No. 15-mc-80211-MEJ, 2015 U.S. Dist. LEXIS 112689, at *2 (N.D. Cal. Aug. 20, 2015) (\u201cDropbox provides a document storage and sharing service through which users can collectively save, share, and edit documents stored \u2018in the cloud.\u2019\u201d).<\/p>\n<p>[10] <em>See<\/em> Froehlich, <em>supra<\/em> note 9.<\/p>\n<p>[11] <em>See<\/em> <em>id.<\/em> (\u201cLack of IT management and control will quickly put an end to BYOC, even though it has the potential to provide real benefits.\u201d).<\/p>\n<p>[12] <em>See <\/em>Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *22\u201324, *29 (E.D. Tex. Nov. 30, 2015) (discussing defendants\u2019 extensive use of Dropbox to remove vast amounts of proprietary information belonging to plaintiff).<\/p>\n<p>[13] <em>See <\/em>Susan Miller, <em>New Risk on the Block: Bring Your Own Cloud<\/em>, GCN (May 23, 2013) https:\/\/gcn.com\/articles\/2013\/05\/23\/new-risk-bring-your-own-cloud.aspx, <em>archived at <\/em>https:\/\/perma.cc\/T7DM-3CD6.<\/p>\n<p>[14] <em>See <\/em>Robert L. Mitchell, <em>IT&#8217;s New Concern: The Personal Cloud<\/em>, ComputerWorld (May 20, 2013, 7:00 AM), http:\/\/www.computerworld.com\/article\/2497860\/consumerization\/it-s-new-concern&#8211;the-personal-cloud.html, <em>archived at <\/em>https:\/\/perma.cc\/XZN9-RSK8.<\/p>\n<p><a href=\"#_ftnref15\" name=\"_ftn15\">[15]<\/a> <em>See<\/em> discussion <em>infra<\/em> Part II.<\/p>\n<p>[16] <em>See<\/em> Froehlich, <em>supra<\/em> note 9.<\/p>\n<p>[17] <em>See id.<\/em> (\u201cBYOC presents a nightmare scenario because data can be copied, duplicated, and ultimately lost or stolen via the various cloud services.\u201d).<\/p>\n<p>[18] <em>See<\/em> Columbus, <em>supra<\/em> note 8.<\/p>\n<p>[19] <em>See <\/em>Victoria Barret, <em>Dropbox: The Inside Story of Tech\u2019s Hottest Startup<\/em>, Forbes (Oct. 18, 2011, 8:30 AM), http:\/\/www.forbes.com\/sites\/victoriabarret\/2011\/10\/18\/dropbox-the-inside-story-of-techs-hottest-startup\/4\/#1cace6c73a44, <em>archived at <\/em>http:\/\/perma.cc\/C9Q3-465F; Jonathan Strickland, <em>How Cloud Storage Works<\/em>, HowStuffWorks.com (Apr. 30, 2008), http:\/\/computer.howstuffworks.com\/cloud-computing\/cloud-storage2.htm, <em>archived at<\/em> https:\/\/perma.cc\/5JTG-UZS3 (Web-based e-mail providers like Yahoo! and Hotmail have been providing their users with a quasi-cloud computing environment through e-mail since the 1990s).<\/p>\n<p>[20] <em>See,<\/em> <em>e.g.<\/em>, Animators at Law, Inc. v. Capital Legal Solutions, L.L.C., 786 F. Supp. 2d 1114, 1117\u201318 (E.D. Va. 2011) (explaining that plaintiff\u2019s former employees accessed company files stored in a company Dropbox account through login credentials that plaintiff failed to disable after the employees left the company).<\/p>\n<p>[21] <em>See<\/em> Columbus, <em>supra<\/em> note 8.<\/p>\n<p>[22] <em>See<\/em> Boston Scientific Corp. v. Lee, No. 13-13156-DJC, 2014 U.S. Dist. LEXIS 66220, at *2, *4\u20137 (D. Mass. May 14, 2014) (enjoining defendant from using proprietary information that he had taken from his prior employer and which he stored both during and after his employment on Google Drive).<\/p>\n<p>[23] <em>See <\/em>Selectica, Inc. v. Novatus, Inc., No. 6:13-cv-1708-Orl-40TBS, 2015 U.S. Dist. LEXIS 30460, at *2 (M.D. Fla. Mar. 12, 2015).<\/p>\n<p>[24] <em>See<\/em> Columbus, <em>supra<\/em> note 8.<\/p>\n<p>[25] <em>See<\/em> Froehlich, <em>supra<\/em> note 9.<\/p>\n<p><a href=\"#_ftnref26\" name=\"_ftn26\">[26]<\/a> <em>See <\/em>Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *7\u20139 (observing that defendants\u2019 former employer began investigating the possibility that defendants took proprietary company data in violation of their non-disclosure agreements only after one of the defendants mentioned that \u201cshe knew where too many bodies were buried.\u201d).<\/p>\n<p>[27] <em>See <\/em>Toyota Indus. Equip. Mfg. v. Land, No. 1:14-cv-1049-JMS-TAB, 2014 U.S. Dist. LEXIS 99070, at *5\u20136, *9 (S.D. Ind. July 21, 2014) (explaining that defendant uploaded confidential information from his former employer to his Google Drive account before going to work for an industry competitor).<\/p>\n<p>[28] <em>See <\/em>Selectica, Inc. v. Novatus, Inc., No. 6:13-cv-1708-Orl-40TBS, 2015 U.S. Dist. LEXIS 30460 (M.D. Fla. Mar. 12, 2015).<\/p>\n<p>[29] <em>See <\/em>PrimePay, L.L.C. v. Barnes, No. 14-11838, 2015 U.S. Dist. LEXIS 65710 (E.D. Mich. May 20, 2015).<\/p>\n<p>[30] <em>See <\/em><em>Selectica, Inc.<\/em>, 2015 U.S. Dist. LEXIS 30460, at *4.<\/p>\n<p><a href=\"#_ftnref31\" name=\"_ftn31\">[31]<\/a> <em>See id.<\/em> at *2.<\/p>\n<p>[32] <em>See id. <\/em>at *1.<\/p>\n<p>[33] <em>See id.<\/em> at *3.<\/p>\n<p>[34] <em>See id<\/em>.<\/p>\n<p>[35] <em>See <\/em><em>Selectica, Inc.<\/em>, 2015 U.S. Dist. LEXIS 30460, at *2\u20133.<\/p>\n<p>[36] <em>Id.<\/em> at *2 (emphasis added).<\/p>\n<p>[37] <em>See id.<\/em> at *2.<\/p>\n<p>[38] <em>See id. <\/em>at *2\u20133.<\/p>\n<p><a href=\"#_ftnref39\" name=\"_ftn39\">[39]<\/a> <em>See id<\/em>. at *17.<\/p>\n<p>[40] <em>See<\/em> <em>Selectica, Inc.<\/em>, 2015 U.S. Dist LEXIS 30460, at *2\u20133.<\/p>\n<p>[41] <em>See id. <\/em><\/p>\n<p>[42] <em>See id.<\/em><\/p>\n<p>[43] <em>See<\/em> Tom Nolle, <em>Bring Your Own Cloud: The Movement Companies Can\u2019t and Shouldn\u2019t Stop<\/em>, TechTarget (Apr. 8, 2014), http:\/\/searchcloudapplications.techtarget.com\/feature\/Bring-your-own-cloud-The-movement-companies-cant-and-shouldnt-stop, <em>archived at <\/em>https:\/\/perma.cc\/C478-7NCG.<\/p>\n<p>[44] <em>See <\/em>PrimePay, L.L.C. v. Barnes, No. 14-11838, 2015 U.S. Dist. LEXIS 65710 (E.D. Mich. May 20, 2015).<\/p>\n<p>[45] <em>See id.<\/em> at *2.<\/p>\n<p>[46] <em>See id.<\/em> at *4\u20135.<\/p>\n<p>[47] <em>See id.<\/em> at *2, *9\u201311.<\/p>\n<p>[48] <em>Id.<\/em> at *8\u20139.<\/p>\n<p>[49] <em>See PrimePay, L.L.C.<\/em>, 2015 U.S. Dist. LEXIS 65710, at *3.<\/p>\n<p>[50] <em>See id.<\/em> at *11\u201313.<\/p>\n<p>[51] <em>See id.<\/em> at *12.<\/p>\n<p>[52] <em>See id.<\/em> at *11.<\/p>\n<p>[53] <em>See<\/em> <em>id.<\/em><\/p>\n<p><a href=\"#_ftnref54\" name=\"_ftn54\">[54]<\/a> <em>PrimePay, L.L.C.<\/em>, 2015 U.S. Dist. LEXIS 65710, at *11.<\/p>\n<p>[55] <em>See id.<\/em> at *64, 66.<\/p>\n<p>[56] <em>See id.<\/em> at *106\u201308.<\/p>\n<p>[57]<em> See id.<\/em> at *34\u201336, *100\u201301.<\/p>\n<p>[58] <em>See<\/em> Lee, <em>supra<\/em> note 5.<\/p>\n<p><a href=\"#_ftnref59\" name=\"_ftn59\">[59]<\/a> <em>See<\/em> Danny Palmer, <em>CIOs Worried Cloud Computing and Shadow IT Creating Security Risks<\/em>, Computing (July 27, 2015), http:\/\/www.computing.co.uk\/ctg\/news\/2419409\/cios-worried-cloud-computing-and-shadow-it-creating-security-risks, <em>archived at <\/em>https:\/\/perma.cc\/39AR-LJ4F.<\/p>\n<p>[60] <em>See<\/em> Thoran Rodrigues, <em>Cloud Computing and the Dangers of Shadow IT<\/em>, TechRepublic (Aug. 16, 2013, 12:48 PM), http:\/\/www.techrepublic.com\/blog\/the-enterprise-cloud\/cloud-computing-and-the-dangers-of-shadow-it\/, <em>archived at <\/em>https:\/\/perma.cc\/Y5BG-PEQZ.<\/p>\n<p>[61] <em>See,<\/em> <em>e.g.<\/em>, Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *3\u20134, *8\u20139 (E.D. Tex. Nov. 30, 2015); Toyota Indus. Equip. Mfg. v. Land, No. 1:14-cv-1049-JMS-TAB, 2014 U.S. Dist. LEXIS 99070, at *10, *13\u201314 (S.D. Ind. July 21, 2014).<\/p>\n<p><a href=\"#_ftnref62\" name=\"_ftn62\">[62]<\/a> <em>See<\/em> Rodrigues, <em>supra<\/em> note 60.<\/p>\n<p><a href=\"#_ftnref63\" name=\"_ftn63\">[63]<\/a> <em>See Toyota Indus. Equip. Mfg., Inc.<\/em>, 2014 U.S. Dist. LEXIS 99070, at *3\u20137.<\/p>\n<p>[64] <em>See id.<\/em> at *5.<\/p>\n<p>[65] <em>See id.<\/em> at *5\u20137.<\/p>\n<p>[66] <em>See id.<\/em> at *6\u20138.<\/p>\n<p>[67] <em>See id.<\/em> at *6\u20137.<\/p>\n<p>[68] <em>See Toyota Indus. Equip. Mfg., Inc.<\/em>, 2014 U.S. Dist. LEXIS 99070, at *8.<\/p>\n<p>[69] <em>See id<\/em>. at *15\u201316, *22.<\/p>\n<p><a href=\"#_ftnref70\" name=\"_ftn70\">[70]<\/a> <em>See<\/em> RLI Ins. Co. v. Banks, No. 1:14-CV-1108-TWT, 2015 U.S. Dist. LEXIS 9396, (N.D. Ga. Jan. 27, 2015).<\/p>\n<p><a href=\"#_ftnref71\" name=\"_ftn71\">[71]<\/a> <em>See id <\/em>at *2; <em>see<\/em> <em>generally<\/em> Jottacloud, https:\/\/www.jottacloud.com, <em>archived at<\/em> https:\/\/perma.cc\/7HQJ-AYFR (last visited Mar. 17, 2016) (\u201cJottacloud is a cloud storage service for individuals and companies that lets you backup, synchronize, store and share files from all your devices. The uploaded data is protected by one of the worlds [sic] strongest privacy laws, with all your data stored in Norway.\u201d).<\/p>\n<p>[72] <em>RLI Ins. Co.<\/em>, 2015 U.S. Dist. LEXIS 9396, at *2.<\/p>\n<p>[73] <em>See id.<\/em><\/p>\n<p>[74] <em>See id.<\/em> at *1\u20132.<\/p>\n<p>[75] <em>Id.<\/em> at *2.<\/p>\n<p>[76] <em>See<\/em> Verified Complaint for Damages and Emergency Injunctive Relief at 15\u201316, RLI Ins. Co. v. Banks, 2015 U.S. Dist. LEXIS 9396 (N.D. Ga. Jan. 27, 2015) (No. 1:14-CV-1108-TWT) (\u201cNot aware of Defendant\u2019s misappropriation of RLI\u2019s Customer Claim Files and Proprietary Information, RLI offered Defendant a severance package upon her termination. Defendant had not yet accepted the offer of a severance package when RLI discovered the misappropriation. Based on Defendant\u2019s misconduct, RLI revoked its offer of severance to Defendant by letter to Defendant.\u201d).<\/p>\n<p><a href=\"#_ftnref77\" name=\"_ftn77\">[77]<\/a> <em>See <\/em>Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915 (E.D. Tex. Nov. 30, 2015).<\/p>\n<p>[78] <em>See <\/em>De Simone v. VSL Pharm., Inc., No. TDC-15-1356, 2015 U.S. Dist. LEXIS 128209, at *2 (D. Md. Sept. 23, 2015).<\/p>\n<p>[79] <em>See Frisco Med. Ctr., L.L.P.<\/em>, 2015 U.S. Dist. LEXIS 159915, at *8.<\/p>\n<p>[80] <em>See id.<\/em> at *12.<\/p>\n<p>[81] <em>Id.<\/em> at *11.<\/p>\n<p>[82] <em>Id.<\/em> at *7.<\/p>\n<p>[83] <em>See id<\/em>. at *7\u20139.<\/p>\n<p><a href=\"#_ftnref84\" name=\"_ftn84\">[84]<\/a><em> See <\/em>De Simone v. VSL Pharm., Inc., No. TDC-15-1356, 2015 U.S. Dist. LEXIS 128209, at *48 (D. Md. Sept. 23, 2015).<\/p>\n<p>[85] <em>See id.<\/em> at *1\u20132.<\/p>\n<p>[86] <em>See id.<\/em> at *48\u201349.<\/p>\n<p>[87] <em>See id.<\/em> at *18.<\/p>\n<p>[88] <em>See id.<\/em> at *2.<\/p>\n<p>[89] <em>See<\/em> discussion <em>infra<\/em> Part III.<\/p>\n<p>[90] <em>See <\/em>Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *3 (E.D. Tex. Nov. 30, 2015); RLI Ins. Co. v. Banks, No. 1:14-CV-1108-TWT, 2015 U.S. Dist. LEXIS 9396, at *2, *6 (N.D. Ga. Jan. 27, 2015); Toyota Indus. Equip. Mfg. v. Land, No. 1:14-cv-1049-JMS-TAB, 2014 U.S. Dist. LEXIS 99070, at *4\u20136 (S.D. Ind. July 21, 2014).<\/p>\n<p><a href=\"#_ftnref91\" name=\"_ftn91\">[91]<\/a> <em>See Frisco Med. Ctr., L.L.P.<\/em>, 2015 U.S. Dist. LEXIS 159915, at *40\u201341 (granting Frisco summary judgment against Bledsoe on its trade secret claims); <em>Toyota Indus. Equip. Mfg., Inc.<\/em>, 2014 U.S. Dist. LEXIS 99070, at *21\u201322 (enjoining Land from working for his new employer).<\/p>\n<p>[92] <em>See<\/em> <em>Frisco Med. Ctr., L.L.P.<\/em>, 2015 U.S. Dist. LEXIS 159915, at *2 (stating that beyond the problems with industry competitors, such unauthorized disclosures could violate regulatory schemes such as the Health Insurance Portability and Accountability Act, or HIPAA).<\/p>\n<p><a href=\"#_ftnref93\" name=\"_ftn93\">[93]<\/a><em> See<\/em> David S. Levine, <em>School Boy\u2019s Tricks: Reasonable Cybersecurity and the Panic of Law Creation<\/em>, 72 Wash. &amp; Lee L. Rev. 323, 334\u201335 (2015) (observing that many companies prefer to litigate rather than protect their trade secrets).<\/p>\n<p>[94]<em> See RLI Ins. Co.<\/em>, 2015 U.S. Dist. LEXIS 9396, at *1\u20132.<\/p>\n<p>[95]<em> See id.<\/em> at *2.<\/p>\n<p><a href=\"#_ftnref96\" name=\"_ftn96\">[96]<\/a><em> See <\/em>De Simone v. VSL Pharm., Inc., No. TDC-15-1356, 2015 U.S. Dist. LEXIS 128209, at *48 (D. Md. Sept. 23, 2015).<\/p>\n<p>[97]<em> See <\/em>Verified Complaint for Damages and Emergency Injunctive Relief at 15\u201316, RLI Ins. Co. v. Banks, 2015 U.S. Dist. LEXIS 9396 (N.D. Ga. Jan. 27, 2015) (No. 1:14-CV-1108-TWT).<\/p>\n<p>[98] Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *7 (E.D. Tex. Nov. 30, 2015).<\/p>\n<p>[99]<em> See <\/em>Toyota Indus. Equip. Mfg. v. Land, No. 1:14-cv-1049-JMS-TAB, 2014 U.S. Dist. LEXIS 99070, at *6 (S.D. Ind. July 21, 2014).<\/p>\n<p>[100]<em> See id.<\/em><\/p>\n<p><a href=\"#_ftnref101\" name=\"_ftn101\">[101]<\/a><em> See <\/em>David Wetmore &amp; Scott Clary, <em>To Map or Not to Map: Strategies for Classifying Sources of ESI<\/em>, Information Management (2009), http:\/\/content.arma.org\/IMM\/SeptOct2009\/to_map_or_not_to_map.aspx, <em>archived at <\/em>https:\/\/perma.cc\/CG8S-VACB.<\/p>\n<p>[102]<em> See <\/em>R. Mark Halligan, <em>Protecting U.S. Trade Secret Assets in the 21st Century<\/em>, 6 Landslide, No. 1, Sept.\u2013Oct. 2013, at 4, http:\/\/www.americanbar.org\/publications\/landslide\/2013-14\/september-october-2013\/protecting_us_trade_secret_assets_the_21st_century.html, <em>archived at<\/em> https:\/\/perma.cc\/FU3T-L4FW (urging companies to adopt \u201cmapping\u201d approaches to better safeguard trade secrets); <em>see also <\/em>Sterling Miller, <em>Ten Things: Trade Secrets and Protecting Your Company<\/em>, Corporate Law Advisory (Apr. 27, 2015), http:\/\/www.lexisnexis.com\/communities\/corporatecounselnewsletter\/b\/newsletter\/archive\/2015\/04\/27\/ten-things-trade-secrets-and-protecting-your-company.aspx, <em>archived at<\/em> https:\/\/perma.cc\/XH3L-WXRQ [hereinafter Miller] (\u201cYou need an inventory of all of the company\u2019s trade secrets . . . [a]n inventory helps you identify what steps are needed to keep those specific items confidential and protected and be clear with the business what items are not considered trade secrets . . .\u201d).<\/p>\n<p>[103] <em>See <\/em>Boston Scientific Corp. v. Lee, No. 13-13156-DJC, 2014 U.S. Dist. LEXIS 66220, at *10, *12\u201313 (D. Mass. May 14, 2014) (finding the employer used \u201creasonable means to protect its trade secrets\u201d despite contradictory evidence suggesting an employee openly used a personal Google Drive account to access and store confidential company information).<\/p>\n<p><a href=\"#_ftnref104\" name=\"_ftn104\">[104]<\/a><em> See <\/em>Halligan, <em>supra<\/em> note 102, at 4.<\/p>\n<p>[105] <em>See<\/em>, <em>e.g.<\/em>, Philip J. Favro, <em>Getting Serious: Why Companies Must Adopt Information Governance Measures to Prepare for the Upcoming Changes to the Federal Rules of Civil Procedure<\/em>, 20 Rich. J.L. &amp; Tech. 5, 25\u201335 (2014), http:\/\/jolt.richmond.edu\/v20i2\/article5.pdf, <em>archived at<\/em> https:\/\/perma.cc\/SZ3M-3MNP (explaining that a comprehensive information governance plan would take various factors into consideration. They would likely include the length of pertinent retention periods, the ability to preserve data for legal matters, applicable data protection laws, cybersecurity initiatives, and use policies for smartphones and other mobile devices).<\/p>\n<p>[106]<em> See<\/em> Philip Favro, <em>Do You Know Your BYOCs?<\/em>, Legal Tech. News (July 13, 2015), http:\/\/www.legaltechnews.com\/id=1202731897715?keywords=favro&amp;publication=Legal+Technology, <em>archived at <\/em>https:\/\/perma.cc\/QF6S-8KVW.<\/p>\n<p>[107] <em>See<\/em> Miller, <em>supra<\/em> note 102.<\/p>\n<p>[108] <em>See<\/em> Sophie Vanhegan, <em>Legal Guidance: Protecting Company Information in the Cloud-Era<\/em>, HRZone (Apr. 23, 2013), http:\/\/www.hrzone.com\/perform\/business\/legal-guidance-protecting-company-information-in-the-cloud-era, <em>archived at <\/em>https:\/\/perma.cc\/8MGT-3QZG.<\/p>\n<p>[109] <em>See id.<\/em> (observing that corporate policies must \u201callow company monitoring of employees\u2019 IT activity and work email accounts . . .\u201d).<\/p>\n<p><a href=\"#_ftnref110\" name=\"_ftn110\">[110]<\/a> <em>See id<\/em>. (\u201cEmployers may also wish to consider . . . implementing IT measures to prohibit uploading of documents onto web-based applications.\u201d); <em>see also<\/em> RLI Ins. Co. v. Banks, No. 1:14-CV-1108-TWT, 2015 U.S. Dist. LEXIS 9396, at *2 (N.D. Ga. Jan. 27, 2015).<\/p>\n<p>[111] <em>See, e.g.<\/em>,<em> RLI Ins. Co.<\/em>, 2015 U.S. Dist. LEXIS 9396, at *1\u20132.<\/p>\n<p>[112] <em>See<\/em> Vanhegan, <em>supra<\/em> note 108 (explaining that policies addressing personal cloud usage should \u201cexpressly prohibit the removal of company documents and information outside the company\u2019s systems.\u201d).<\/p>\n<p>[113] <em>See<\/em> Esther Schindler, <em>Protecting Corporate Data\u2026When an Employee Leaves<\/em>, Druva Blog (Oct. 13, 2014), http:\/\/www.druva.com\/blog\/protecting-corporate-data-employee-leaves\/, <em>archived at <\/em>https:\/\/perma.cc\/4GS5-QJ9H.<\/p>\n<p>[114] <em>See<\/em> Rachel Holdgrafer, <em>Fix Insider Threat with Data Loss Prevention<\/em>, Cloud Security Alliance (Dec. 10, 2015), https:\/\/blog.cloudsecurityalliance.org\/2015\/12\/10\/fix-insider-threat-with-data-loss-prevention\/, <em>archived at <\/em>https:\/\/perma.cc\/EU5U-2FZN.<\/p>\n<p>[115] <em>See<\/em> Miller, <em>supra<\/em> note 102 (\u201cDeparting employees constitute one of your biggest risks for trade-secret theft.\u201d).<\/p>\n<p><a href=\"#_ftnref116\" name=\"_ftn116\">[116]<\/a> <em>See<\/em> <em>id.<\/em><\/p>\n<p><a href=\"#_ftnref117\" name=\"_ftn117\"><\/a>\u00a0[117] <em>See id.<\/em>; <em>see also <\/em>Frisco Med. Ctr., L.L.P. v. Bledsoe, No. 4:12-CV-37; 4:15cv105, 2015 U.S. Dist. LEXIS 159915, at *5 (E.D. Tex. Nov. 30, 2015).[\/et_pb_text][\/et_pb_column]<br \/>\n\t\t\t[\/et_pb_row]<br \/>\n\t\t[\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[et_pb_section admin_label=&#8221;section&#8221;] [et_pb_row admin_label=&#8221;row&#8221;] [et_pb_column type=&#8221;4_4&#8243;][et_pb_text admin_label=&#8221;Text&#8221;] Favro Publication Version Cite as: Philip Favro, Addressing Employee Use of Personal Clouds, 22 Rich. J.L. &amp; Tech. 6 (2016), http:\/\/jolt.richmond.edu\/v22i3\/article6.pdf. Philip Favro* &nbsp; I. INTRODUCTION [1]\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Cloud computing is one of the most useful innovations in the digital age.[1] While much of the attention on recent advances [&hellip;]<\/p>\n","protected":false},"author":4287,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[1228],"tags":[],"class_list":["post-3212","post","type-post","status-publish","format-standard","hentry","category-articles"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/paMHOZ-PO","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3212","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/users\/4287"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/comments?post=3212"}],"version-history":[{"count":1,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3212\/revisions"}],"predecessor-version":[{"id":9258,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/posts\/3212\/revisions\/9258"}],"wp:attachment":[{"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/media?parent=3212"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/categories?post=3212"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.richmond.edu\/jolt\/wp-json\/wp\/v2\/tags?post=3212"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}