Authenticom v. CDK Global was an antitrust case brought in 2017 in the Western District of Wisconsin by Authenticom, a company that pulls dealer data out of the dealer management systems (DMS) that car dealers license, against the two largest DMS providers, CDK Global and The Reynolds and Reynolds Company. It is not a licence-audit case, but it turns on what a software licence lets a customer, and a customer’s agent, do with the system and its data, and on what a vendor may do to stop automated access. The district court granted Authenticom a preliminary injunction on 14 July 2017, and the Seventh Circuit set it aside on 6 November 2017.[1][2]
This article covers only those two decisions. Neither decided the merits, and both courts said so.[2]
Background
The district court described a DMS as the software package a dealer uses to manage everything from vehicle and parts inventory to service appointments and payroll. CDK and Reynolds supplied the DMS to roughly three-quarters of United States dealers, ran the servers that held each dealer’s data, and a dealer typically paid USD 8,000 to 10,000 a month for its DMS. The court found that the data belongs to the dealer.[1]
Dealers also use add-on applications from third-party vendors, typically 10 to 15 of them, and those applications need data from the DMS. Many dealers authorised the vendors to collect it directly or through a data integrator such as Authenticom. With the dealer’s consent, Authenticom logged in to the dealer’s DMS account with a user name and password the dealer supplied, captured the data by “screen scraping”, reformatted it and sent it to the vendor; the court recorded that a vendor typically paid it about USD 50 a month per dealer.[1]
The two vendors differed on access. The Seventh Circuit noted that Reynolds had always forbidden such data harvesting in its system licences, while CDK until 2015 placed no restrictions on third-party integrators, and then decided to move to a closed system.[2] Reynolds allowed third-party access only with its own approval, preferably through its Reynolds Certified Interface (RCI), and CDK’s equivalent was its 3PA programme.[1]
The dispute
The 2015 agreements. In February 2015 CDK and Reynolds signed three agreements: a Data Exchange Agreement under which CDK wound down its own integration subsidiaries’ unauthorised access to Reynolds systems, and two agreements giving each other’s applications access to their systems through their in-house interfaces. In the Data Exchange Agreement each also agreed not to assist anyone attempting to access or integrate with the other’s DMS.[1] The Seventh Circuit observed that nothing in the three agreements required either company to block third-party access to its own system.[2]
The claims. Authenticom sued in May 2017, arguing that the agreements, together with alleged statements by the defendants’ executives that they would shut third-party integrators out, amounted to a horizontal conspiracy in breach of section 1 of the Sherman Act, and that the defendants’ vendor contracts, which required vendors to use the in-house interfaces, were exclusive dealing.[1][2] The defendants said they closed access for security reasons and to protect their systems and work product.[1]
Prices and access terms. The district court recorded vendor evidence that the monthly price of integration through the defendants’ interfaces had risen sharply: for example, a vendor paid USD 247 per dealer per month for RCI in 2011 and would pay USD 893 by September 2017, and CDK’s 3PA price for another vendor went from about USD 160 in 2014 to USD 735 in July 2017. It also recorded that Reynolds’ standard RCI vendor contract prohibited the vendor from discussing RCI costs, and that CDK prevented vendors from showing 3PA charges as a line item on their bills.[1]
Decision or outcome
District court, 14 July 2017. The court found that Authenticom had shown at least a moderate chance of success on its Sherman Act claim and that it was at risk of going under, and it found the defendants’ security concerns unpersuasive because they already allowed many exceptions to their “no hostile integration” policies and no evidence showed that Authenticom had caused a breach. It granted a preliminary injunction.[1] As the Seventh Circuit later described it, the injunctions barred the defendants from blocking Authenticom’s use of log-in credentials from dealers it served on 1 May 2017, required each defendant to configure Authenticom-specific credentials, and set a USD 1 million bond.[2]
Seventh Circuit, 6 November 2017. The court of appeals set the injunction aside. It assumed, generously to Authenticom, that irreparable harm, inadequate remedy at law and some likelihood of success were shown, but held that the injunction went beyond the alleged violation: the proper preliminary remedy for an agreement in restraint of trade would be to bar the 2015 agreements, not to order the defendants into a new dealing arrangement with Authenticom, which was inconsistent with the Supreme Court’s decision in Verizon v. Trinko.[2] It said that nothing it wrote should be taken as presaging the outcome at trial, and urged the district court to expedite final judgment.[2]
Significance for software licensing and SAM practice
The case is a reminder that the licence a dealer signs, not only the law of data ownership, shapes who may touch a system. The Seventh Circuit treated the licence terms that forbid sharing credentials with, or scraping by, third parties as part of the commercial background of the dispute, while the district court stressed that the dealers’ data belonged to them.[1][2] For licence managers it shows how a change in a vendor’s access model, and the price of its official interface, can change what a licensed system costs to integrate with, without any change in the licence fee itself.
Because the appeal decided only the scope of interim relief, the case is not authority on whether the 2015 agreements were unlawful or on whether a vendor may block credential-based access.
Lessons learned
- Read the access and credential clauses. The licences at issue forbade third-party access, and the vendors used that to block automated log-ins; an integration built on a customer’s own credentials is only as safe as the licence allows.[2]
- Data ownership and system access are different rights. The district court found the data belonged to the dealer, yet the dealer still depended on the vendor’s system and rules to get it out.[1]
- Official interfaces can be repriced. The record shows integration fees through the vendors’ own interfaces rising several-fold in a few years, so seek a contractual export route and price protection for it.[1]
- Watch clauses that restrict disclosure of interface pricing. The record includes vendor contract terms that limited discussing or itemising interface charges, which makes comparison harder.[1]