AVANTCORE Rechtsanwälte
Menu

No liability of the connection holder in case of security vulnerability

The holder of an internet connection is not liable for a copyright infringement committed via his connection, provided there is a possibility that unauthorized third parties have gained access to his internet connection via a security vulnerability in the WLAN router and have committed the infringing act.

The subject matter of the legal dispute was – as in most comparable proceedings – claims by the rights holder for damages and reimbursement of costs as a result of a copyright infringement that took place years agocopyright infringement through the use of an internet file-sharing platform. The connection holder refused to pay the amount of approximately €1000. He disputed having committed the legal infringement. In addition to him, his wife also used the internet connection, with each having their own PC at their disposal. Furthermore, it became known in 2012 that the router he was using at the time of the infringement had a security vulnerability, via which unauthorized third parties could easily gain access to the connection when the WPS function was enabled. The connection holder assumed that the WPS function was enabled on his router. The claimant rights holder disputed this.


Court decision

The Local Court (AG) Braunschweig dismissed the claim in full by judgment of 27.08.2014 (Az: 117 C 1049/14).

The court based its decision on the fact that there was already no factual presumption that the connection holder committed the legal infringement. In the context of the secondary burden of proof incumbent upon him, he put forward a factual situation that made it appear possible that unauthorized third parties had gained access to his internet connection via the security vulnerability in his router and had committed the infringing act. It did not help the rights holder to question whether the WPS function on the connection holder's router was enabled. It cannot be expected of the connection holder to still remember how the router was configured at least 4 years ago.

The court also considered it of little relevance that the security vulnerability only became publicly known 2 years after the legal infringement. This did not allow any conclusion to be drawn that criminal individuals with high IT competence had not discovered the vulnerability and exploited it for themselves much earlier.

The question of whether the wife was to be considered as a perpetrator ultimately became irrelevant.

Conclusion

Following the hitherto very one-sided case law of the Local Court (AG) Munich, which following the abolition of the floating jurisdiction can no longer be exclusively resorted to, this judgment is very much to be welcomed. Even according to the current case law of the Federal Court of Justice (BGH), the connection holder in comparable cases is not liable per se, in particular not if an alternative factual situation is put forward and appears possible. The Local Court (AG) Munich has frequently overlooked this in the past.

Last updated
10 September 2014
Author
AVANTCORE Rechtsanwälte

This is a translation of the German original. In case of discrepancies, the German version prevails.

All news
No liability of the connection holder in case | AVANTCORE