Flextronics International Ltd. v. Parametric Technology Corp. was a lawsuit in the United States District Court for the Northern District of California, filed on 3 January 2013, between electronics manufacturer Flextronics and its long-standing software supplier PTC. After PTC told Flextronics that “embedded technology” in its software had detected unauthorised copies, Flextronics sued PTC under federal and California computer-intrusion laws and sought a declaration that it had not infringed PTC’s copyright; PTC counterclaimed for copyright infringement and breach of contract.[2] Magistrate Judge Paul S. Grewal granted PTC a preliminary injunction that included an order not to interfere with PTC’s contractual audit right,[2] and later held that some of Flextronics’ claims about the monitoring technology were adequately pleaded.[4] The parties stipulated to dismissal of the case with prejudice in June 2014.[5]
Background
PTC had licensed software to Flextronics since 1998.[1] Under a 1998 customer agreement Flextronics licensed PTC’s Pro/ENGINEER software for use “on the Designated Computer or Designated Network by Users”, and PTC reserved “the right to audit Customer’s use of the Licensed Products during normal business hours on reasonable notice”. A 2005 agreement for additional software gave PTC an “Audit Right” with access to facilities, systems and staff, required Flextronics to reimburse the audit cost if unpaid licence fees were found, and included a “Reporting” clause requiring a certified installation or usage report within ten business days of a written request.[2]
PTC’s click-through agreement, accepted before installation, warned that PTC “utilizes data monitoring and scouring technologies to obtain and transmit to PTC data on users of illegal copies” and stated that users of unlicensed copies would pay PTC’s then-current list price for them. It also gave PTC a right to perform a “usage assessment”.[2]
The dispute
On 26 July 2012 PTC told Flextronics that it had found evidence of unauthorised versions of PTC software on Flextronics’ systems. Asked how it knew, PTC replied that its software contained “embedded technology that will initiate a push of information to a PTC server”, and that it initiated this process only “if and when a license file is altered”.[2]
Flextronics’ own counts changed over time. In September 2012, with 71% of machines scanned, it reported “11 ‘cracked’ versions found so far”; in October it reported nine unauthorised installations in its Asian sites; in December an internal spreadsheet listed 11 copies with invalid serial numbers such as 8888888 or 12345678, yet the company told PTC “we are coming up empty”; and its complaint alleged “at most one” infringing copy. In November 2012 it demanded that PTC “cease and desist” from accessing its systems and called the cracked copies “de minimis, at worst”.[2]
After the suit was filed, PTC invoked its audit and reporting rights. Flextronics’ uncertified January 2013 report showed 857 copies under a “corporate license”, 104 under a “non-corporate license” whose licence details could not be identified, and two “cracked keys”; a March 2013 scan found 128 machines in Asia with PTC software but no licence information. Flextronics, which operated in 60 countries, refused PTC’s demand for a simultaneous audit of all sites.[2]
Decision or outcome
Preliminary injunction (2013)
The court first allowed limited, reciprocal expedited discovery on PTC’s embedded technology and Flextronics’ internal audit, because it was “presented with two sets of test results, with no way of knowing which is correct”.[1]
On 16 September 2013 it granted PTC’s motion for a preliminary injunction in part. PTC was likely to succeed on copyright, because Flextronics had admitted some unauthorised copies and had not explained its “ever-shifting” counts; copying complete programs was not de minimis. PTC was also likely to succeed on contract, because Flextronics had not certified its usage report and “no audit whatsoever has yet occurred”. The court found a risk of irreparable harm because employees could easily delete evidence of cracked files, and noted that audit rights exist to let a vendor count infringing copies “before any spoliation can occur”. It declined to weigh Flextronics’ accusation that PTC came with unclean hands because of the phone-home technology.[2]
The injunction barred Flextronics from copying or using PTC software except as the contract or an express written licence allowed, required it to preserve copies, and ordered it not to interfere with “PTC’s right to a reasonable audit”. The court rejected PTC’s request for a compliance report within 30 days as disproportionate, and left it to the parties to agree what audit process was reasonable, noting Flextronics’ argument that a remote software asset management review would be effective.[2]
Flextronics’ claims about the monitoring (2014)
In January 2014 the court dismissed Flextronics’ claims under the Computer Fraud and Abuse Act (CFAA), the California Computer Data Access and Fraud Act (CDAFA), trespass and conversion, with leave to amend, because the complaint contained only conclusory allegations.[3] On the amended complaint, the court in May 2014 allowed the CFAA claim to proceed on the theory that PTC exceeded authorised access by using hidden technology to obtain information it was not entitled to, rejecting PTC’s argument that voluntary installation defeated the claim. Most CDAFA theories failed, because code within voluntarily installed software is not installed “without permission”, but a claim that PTC introduced a “computer contaminant” survived, as did trespass to chattels. The court noted that if the technology had obtained Flextronics’ consent to transmit the data, there would be no liability.[4]
Resolution
On 23 June 2014 PTC and Flextronics jointly stipulated that the action be dismissed with prejudice and without costs or attorneys’ fees,[5] and the court granted the stipulated dismissal on 24 June 2014.[6] No settlement terms were filed, and there was no ruling on the merits of either side’s claims.
Significance for software licensing and SAM practice
The rulings are district court decisions by a magistrate judge at preliminary stages. They are notable as a case in which the customer sued first, and for setting both sides of a telemetry-driven compliance dispute side by side:
- Audit rights have teeth. The court treated an unperformed audit right as a reason for injunctive relief, while leaving the audit’s scope to what is reasonable under the contract.[2]
- Unverified installations count against the customer. Copies with no identifiable licence were not treated as innocent while the customer failed to produce licensing records.[2]
- Monitoring is open to challenge. Hidden collection of data beyond what a customer agreed to can support claims under computer-intrusion law, depending on consent.[4]
A similar counterclaim against a vendor’s phone-home technology is described in Synopsys v. Ubiquiti. For current PTC terms, see PTC licensing.
Lessons learned
- Audit and reporting clauses can be enforced by injunction while a licence dispute is litigated. The court ordered Flextronics not to interfere with PTC’s right to a reasonable audit and found it had not certified its usage report.[2]
- An internal count of unlicensed copies that keeps changing undermines a customer’s credibility. The court relied on Flextronics’ “ever-shifting” figures in finding PTC likely to succeed.[2]
- Licensed software may report licence-tampering data to the vendor; read the click-through notices that say so. PTC’s click-through terms disclosed “data monitoring and scouring technologies”.[2]
- A customer can challenge hidden data collection, but the claim must plead specific facts about what was accessed and the harm. The first complaint was dismissed as conclusory; the amended one, with details of the data accessed and the harm, partly survived.[3][4]