Siemens Industry Software Inc v Telstra Corporation Limited is a 2020 decision of the Federal Court of Australia in which the developer of the NX and Solid Edge product lifecycle management software obtained an order for preliminary discovery against Telstra, an internet service provider. Siemens wanted to sue businesses that it believed were using cracked copies of its software, but the only identifier its in-product reporting had captured for 20 suspected users was an IP address that resolved to Telstra. Justice Burley ordered Telstra to disclose documents identifying the registered account holders for those IP addresses, limited how Siemens could use the information, and recorded Siemens’ undertaking not to pursue individuals who had not made commercial use of the software.[1]
Background
Siemens Industry Software Inc, a business unit of the Siemens Digital Industries division of Siemens AG, relied on evidence from its Senior Director and Head of License Compliance for Asia Pacific, Australia and New Zealand. According to that evidence, NX and Solid Edge are made up of numerous modules that are licensed individually. Examples of module prices, including the first year of maintenance, were $60,072, $12,569 and $41,602, and representative bundles of commonly purchased modules were priced at $337,514.45 for NX and $88,440.47 for Solid Edge. The court found that the software was likely to be used for business purposes and was of considerable commercial value.[1]
The automatic reporting function
Siemens embeds an “automatic reporting function” (ARF) in each of these products, which cannot be removed or switched off. When a computer running the software is connected to the internet, the ARF can collect data identifying the source of unlicensed use. The details of how it works were kept confidential under a suppression order.[1]
The judgment describes the main type of infringement Siemens was concerned about: software “cracked” or tampered with by a person, or more likely a company, licensed to use some but not all of the software, so that it can use every module without paying for them. Sometimes an ARF report is enough to identify the person responsible. In other cases it shows only a general domain, such as an ISP or webmail domain, and an IP address. If the IP address resolves to an ISP rather than a specific entity, the user is likely to be a subscriber of that ISP.[1]
The application
Siemens identified 20 potential infringing users who were Telstra subscribers, with the IP addresses and the dates and times of the suspected unlicensed use. When its solicitors asked Telstra for the subscriber details, Telstra replied that for privacy reasons a court order would be needed, and that it charged $18 to query one IP address. Siemens then applied under rule 7.22 of the Federal Court Rules 2011, which allows a prospective applicant to obtain discovery from a third party in order to ascertain the “description” (name and address) of a prospective respondent. Telstra neither consented nor opposed, and did not appear; the application was decided on the papers.[1]
Decision
A reasonable basis for a copyright claim
Siemens did not need to prove a prima facie case, but rule 7.22 is not available for speculative proceedings. The court found the threshold met. Siemens could rely on the statutory presumptions of ownership and subsistence of copyright based on the copyright notices on its packaging and media and on its United States copyright registration certificates for NX 5 to 12 and Solid Edge versions 1.0 to 9.[1]
On infringement, the court held that the ARF gave Siemens a logical basis to consider that, when an ARF report is generated, a material reproduction of the software has taken place without licence. It inferred that the purpose of gaining unauthorised access to the otherwise secure, unlicensed portions of the software was to run them without paying a licence fee, and noted that each time software is loaded onto a hard drive it is reproduced. Running cracked software would therefore be an unauthorised reproduction of a substantial part of the object code.[1]
The court was also satisfied that Siemens could not identify the users itself, having used its anti-piracy software and asked Telstra, and that Telstra was likely to hold documents that would identify them.[1]
Privacy safeguards
Because telecommunications and privacy law restrict what an ISP may disclose, the court followed the approach taken in earlier ISP discovery cases and limited the use of the information. The orders provide that:[1]
| Order or undertaking | Effect |
|---|---|
| Discovery | Telstra to give discovery within 14 days of documents identifying the registered account holders for the listed IP addresses at the listed times |
| Data retention carve-out | Telstra need not disclose information kept solely to comply with the mandatory data retention scheme (section 280(1B) of the Telecommunications Act 1997) |
| Costs | Siemens pays Telstra’s costs of compliance at $18 per IP address |
| Use restriction | Siemens may not disclose account holders’ names and addresses to third parties other than its agents, and may use them only to recover compensation for infringement: identifying end users, suing them, and negotiating with them |
| Undertaking | Siemens will not pursue any individual who has not made commercial use of the software |
| Undertaking | Siemens will send each identified prospective respondent a letter in a form approved by the court |
The approved letter
The approved letter, annexed to the orders as Schedule B, tells the recipient that Siemens has reason to believe that software was used on computers identified by listed MAC addresses at listed IP addresses, dates and times, and that the recipient is not licensed. It explains the Copyright Act provisions on authorising infringement and on damages, invites the recipient to a settlement conference, and proposes a resolution that may include compensation for past infringement, the purchase of all licences needed for Siemens software in the recipient’s possession or control, and an undertaking not to use or copy the software without authorisation. It also warns that any attempt to erase installed copies can be detected and that those copies may be needed as evidence.[1]
Significance for software licensing and SAM practice
The decision is a procedural step, not a finding of infringement against any business. It shows how in-product reporting connects to formal enforcement:
- Reporting reaches beyond the network boundary. The ARF reported MAC addresses and IP addresses from computers connected to the internet, and an ISP order converted the IP addresses into named account holders.[1]
- Partially licensed customers are a target group. The judgment records Siemens’ evidence that its main concern was licensees cracking the software to reach modules they had not licensed, rather than users with no licence at all.[1]
- Commercial use is the focus. Siemens undertook to pursue only commercial users, which matches the court’s observation that the software was likely to be used for business purposes.[1]
- The settlement terms are predictable. The approved letter sets out the elements Siemens would seek: compensation for past use, licences for every copy in the recipient’s control, and an undertaking for the future.[1]
Lessons learned
- Reporting functions can identify a business from outside. An embedded function that cannot be switched off supplied the IP addresses, dates and times on which the court relied to order disclosure by the ISP.[1]
- Cracking to unlock modules was treated as reproduction without licence. The court accepted that running cracked software reproduces a substantial part of its object code, which was enough to show that Siemens may have a right to relief.[1]
- A licence for some modules is not a licence for all of them. The scenario the judgment describes is a licensed customer using unlicensed modules, so entitlement checks need to be made at module level, not only at product level.[1]
- Expect a letter first. The orders limited Siemens to using the information to seek compensation, and required a court-approved letter inviting a settlement conference and warning against deleting installed copies.[1]