Khoday v. Symantec Corp. was a consumer class action in the United States District Court for the District of Minnesota, filed on 24 January 2011, against Symantec Corp. and its online retailer Digital River, Inc. The plaintiffs alleged that the defendants sold a download add-on, called Extended Download Service or Norton Download Insurance, to buyers of downloadable Norton software while failing to disclose that the software could be re-downloaded without it.[4] Norton is one of the consumer brands of Gen Digital.[6] The court certified a nationwide class in 2014, denied summary judgment in 2015, and in 2016 approved a USD 60 million settlement.[4][5] The case did not decide what a Norton licence permitted; it matters to licence managers as a record of how access rights around a licence (re-download, serial key retrieval) were packaged and sold.
Background
According to the facts alleged in the complaint, as summarised by the court, Symantec sold Norton security software directly on its own websites and, earlier, through a platform run by Digital River. A licence to use the software ran for a year or more and allowed the software to be loaded or re-loaded on up to three computers while the licence was current.[1]
Purchasers received 60 days from the date of purchase to download the software. The shopping cart automatically included the add-on, and a customer who did not want it had to remove it before checkout. The text behind the “What’s this?” link on the retailer’s site said that the add-on would keep a backup of the software, and the customer’s serial key, available for one year.[1] The plaintiffs said free alternatives for re-downloading existed and were not disclosed at the point of sale. According to the later settlement report, the add-on cost between USD 4.99 and USD 16.99.[4]
The dispute
The amended complaint pleaded two claims against Symantec under California law, a claim against Digital River under Minnesota law, and declaratory judgment and unjust enrichment claims against both.[4] Symantec argued that the add-on carried a real benefit, namely a contractual right to download beyond 60 days that Symantec was not otherwise obliged to give, and that it made re-downloading easier. The plaintiffs answered that Symantec never intended to stop offering free downloads for a year, and that the pop-up text, scripted sales calls and pre-filled cart led buyers to believe they needed the add-on.[1] The court noted that after the complaint was filed Symantec stopped promoting and selling the add-on.[1]
Decision or outcome
On 12 March 2012 the court dismissed only the declaratory judgment claims, because the plaintiffs had more appropriate remedies, and otherwise let the case proceed. It found plausible allegations of fraudulent conduct, and that even true statements may have been misleading and created a duty to disclose.[1][4]
On 31 March 2014 the court certified a class of all persons in the United States who bought the add-on between 24 January 2005 and 10 March 2011.[2][4] On 27 April 2015 it denied Symantec’s motion for summary judgment, holding that genuine issues of fact remained about whether the defendants made misrepresentations or omissions on which the plaintiffs relied.[3] The report on the settlement records the court’s observation that the evidence suggested Symantec kept providing alternative re-download options throughout the period, and that representatives counselled some customers to use them.[4]
After a third mediation in April 2015 the parties agreed a USD 60 million settlement, funded equally by the two defendants. Approved claimants were to receive USD 50 for each add-on purchased in the class period, reduced pro rata if claims exceeded the fund, and any balance was to go to a digital rights non-profit and not revert to the defendants.[4] Direct notice went to about 14 million class members.[4] Without objection to the magistrate judge’s recommendation, the chief judge granted final approval on 21 April 2016, awarded one third of the fund as fees, and denied all objections.[5] The orders contain no finding that the defendants were liable.
Significance for software licensing and SAM practice
- Access rights can be unbundled. The dispute concerned whether re-download rights were part of what a customer already bought; the defendants’ own position was that the add-on gave a contractual right beyond 60 days.[1]
- Checkout design is part of the record. Pre-filled carts, link text and sales scripts were all treated as evidence of what customers were told.[1]
- Retailers share exposure. The court treated the vendor and its e-commerce operator as separate defendants under different state laws.[1]
Lessons learned
- Ancillary services sold alongside a licence are judged by what the point-of-sale text told buyers, not only by the licence terms. The 2012 order focused on the pop-up and retailer text rather than on the licence agreement.[1]
- A pre-selected add-on that the buyer must remove can be pleaded as deceptive if free alternatives are not disclosed. That allegation survived dismissal and summary judgment.[1][3]
- The vendor and its e-commerce operator were separately answerable for the checkout content. The claims against each rested on different state statutes.[1]
- Licence records should show which entitlements were in the base price and which were sold separately. Whether re-download and serial key retrieval were already included was the central factual question.[3]