All news

Reports

Autorité de Régulation des Activités Ferroviaires et Routières (French regulatory authority for rail and road activities)

Opinion n°2019-083 of 9th of December 2019

Full reference: ARAFER, Opinion n°2019-083 relatif aux projets de décrets approuvant les statuts de la société nationale SNCF, de la société SNCF Réseau, de la filiale mentionnée au 5° de l’article L. 2111-9 du code des transports et de la société SNCF Voyageurs, et portant diverses dispositions relatives à ces mêmes entités (related to the project of decrees approving the status of the national societies SNCF, SNCF réseau, of the subsidy mentionnes at the 5° of the article L. 2111-9 du code des transports and of SNCF Voyageurs, and carrying some dispositions related to this bodies), 9th of December 2019 Read the opinion (in French) Read the décret approuvant les status de la société nationale SNCF (in French) Read the opinion of 9th of May 2019 having preceded the one of 9th of December 2019

Glossary

Right to be forgotten

Watch the video explaining the "right to be forgotten". The "right to be forgotten" is a recent and specifically European invention. It was designed by the Court of Justice of the European Union in the Google Spain judgment of May 13, 2014, so that in this world without time, in which all information is eternally stored and available that is the digital world, the individual thus exposed can be protected against this new phenomenon, since forgetting no longer exists, by Law which by its power endows it with a "right to be forgotten". In this the term Right to be forgotten is more accurate. Because Law is made to protect human beings, the technological efficiency which created the digital world is limited by the new legal prerogative of the person to make unattainable information which concerns him when it takes on a "personal character". This was taken up by the community regulation of April 27, 2016, often called GDPR, transposed in the member states of the European Union no later than May 25, 2018. More than in the laws which have taken up the idea of ​​protection of persons in the handling of "data" by others, expressing more the concern to protect the consumer in a market economy, it is a question of directly protecting persons. in a technological world allowing blind obedience, Europe rejecting this model because the technique of the files left him a terrible memory because of the Second World War. However, Law is the memory of peoples and expresses the “spirit” of these (Savigny).

Videos

The French Council of State (Conseil d’État) confirms the wide and therefore severe application of the sanctions mechanism in the Compliance Law concerning the freezing of assets, by its decision of November 15, 2019, La Banque Postale v. ACPR

Watch the video explaining the content, meaning and scope of the decision made by the Conseil d'État (French Council of State) on November 15, 2019, La Banque Postale v. Autorité de contrôle prudentiel et de résolution (ACPR). The Autorité de contrôle prudentiel et de résolution – ACPR (French Authority of prudential control and resolution) pronounced a very high sanction, representing 7% of La Banque Postale's net annual result. The breach is constituted by the fact of not having prevented the use of the banking technique of the "money order" which was used to escape the freezing of the assets. The Conseil d'État recalls that by nature if the assets are frozen, it is not possible that anyone is able to dispose of these assets. However, by the use of "money orders", persons targeted by asset freezing decisions, tools used in connection with the fight against money laundering and the fight against terrorism, had been able to circulate money to from accounts managed by La Banque Postale, of which they were not customers. This case was not foreseen at the time when the Bank Postale was sanctioned by the ACPR for not having prevented such a use, the texts forcing it under its obligations of "conformity" to prevent this behavior of violation background gels on the part of his customers, but only that. This case of a use of a means by a person who is not a customer of the bank was not foreseen at the time when the alleged facts took place and the Bank claims not to be able to be punished since in the repressive matter it is necessary to respect the principle of non-retroactivity of the texts, – in this case texts later supplemented to aim at such an assumption -, the non-retroactivity being a major principle itself related to the principle of the legality of the offenses and the penalties. We are therefore in the hypothesis of a silence of the texts. What to decide? Can the Bank be condemned and so heavily or not by the ACPR? The Bank does not think so.  It acted against this sanction decision firstly because those who used these money orders were not its clients. It has strong reasons to avail itself of this fact, since subsequently the texts needed to be modified to aim not only the use of this technique of money order by those who have a count in the bank and also by those who act with cash through the bank without a count, that is to say without an account holder to look at. Because we are in criminal matters, the restrictive interpretation and non-retroactivity of the text should lead to follow the reasoning of the Bank. But the Conseil d'État does not because it considers that implicitly but necessarily even with this subsequent modification of the text, it had aimed that use before. By this way, the Conseil d'Étatuncil develops a very broad concept of the obligations of banks in their role in the fight against money laundering, and therefore a very repressive point of view, which permeates their "obligation of Compliance". Thus, when the bank also argues that it can not be sanctioned since for it this activity of money order is  deficit and that it did not cause harm to its customers even by assuming badly its obligations, theConseil d'État stresses that this is not a pertinent perspective since the Compliance obligations falls within the "overriding general interest of protection of public order and public security, to which the freezing of assets legislation responds". -   Read the  judgment of the Conseil d'État ( in French). 

Conferences

Legal theory of Risk Mapping, in “Risk Mapping, as Compliance Tool” (conference made in French)

Reference : Frison-Roche, M.-A., General presentation of the cycle of conferences on Les outils de la Compliance  (Compliance Tools) and  "Théorie générale de la cartographie des risques" (Legal Theory of Risk Mapping), conference made in French, in Département d'Economie de Sciences Po & Journal of Regulation & Compliance (JoRC),  La cartographie des risques, outil de la Compliance (Risk Mapping, as Compliance Tool), November 28th, 2019, Sciences Po, Paris.    Read the  General Presentation ot the cycle of conferences about the Compliance Tools   Read the General Presentation of the book written in English to be published   Read the General Presentation of the serie Régulations & Compliance in which the book will be published   Summary of the conference Risk mapping is both central to the obligations or practices of companies and little apprehended by the legal systems. It is not expressly referred to by the French legal system, except for the special national laws known as "Sapin 2" and "Vigilance". But if we are out of this field, because there is only a description and not a legal definition, even less a legal notion, we do not know what legal regime to apply to the action of mapping risks. It is therefore useful, indeed compelling, to define the legal concept of risk mapping. Starting from what is still the safest ground, namely these two special laws, to go towards less secure legal grounds, such as the doctrine of the authorities or the commitments of the companies, even the ISO certifications obtained in this matter. Through a few judicial decisions and legal reasoning, a legal notion of the action of mapping risks emerges. It is advisable to proceed in 5 steps (the working document follows another approach). The first, based directly on the two available laws, apprehends the action of mapping when it comes into execution of a special legal obligation. The decision rendered in 2019 by the French Commission des sanctions of the Agence Française Anticorruption (French Corruption Agency's Sanctions Commission) draws probate games as to the demonstration of the execution of the obligation and the probationary system can be extended. In the same way the decision of the French Conseil constitutionnel (Constitutional Council) in 2017 on the "Vigilance Act" shows that a mechanism referred to as a "modality" is legitimate with regard to the goal, which is, concerning this tool, the establishment of a responsibility for others. It is therefore the concern for the situation of others that can be targeted by the Law thanks to Compliance Tool, especially Risk Mapping. The second theme aims to map risks as a fact of good management for a company, while the enterprise is not constrained by a legal obligation. This fact is a paradox because the Regulatory Authority and the Judge may, where the conduct that was to be prevented occurs, for example a market abuse or an anti-competitive behavior, either qualify as an aggravating circumstance or as an attenuating circumstance. Consideration of the theory of incentives should lead to the adoption of the American solution, that is to say the qualification of an effective cartography as a mitigating fact. European case law is not yet fixed, especially in terms of Competition Law's compliance. The third theme is the mapping action carried out by an entity which, in doing so, exercises power over a third party. Because cartography is as much an obligation as a power, possibly on a third party. The Conseil d'État (French Council of State) in 2017 qualified risk mapping as an act of grievance, but doing so legitimately, since it was to prevent forest fires efficiently. This solution based on the teleology attached to Compliance Law can be transposed to other areas. Going further, one may consider transforming this action from de facto status to legal status on the part of the company, if it thus identifies risks for third parties. It would thus give third-party creditors the right to be in a position to measure the risks that weigh on them. Risk mapping would thus be part of a broader unilateral commitment by powerful companies, recognizing the existence of risks for third parties to enable them to know their nature and extent. If this responsibility Ex Ante (characteristic of Compliance Law) is fulfilled, then the Ex Post liability of the company could no longer be retained. This is the ongoing issue of the Johnson & Johnson trial (2019 American judgment), in terms of medical compliance. Because if one can argue that there exists through this kind of risk mapping that the posology a "subjective right to be worried about the risks related to the taking of the drug", the patient remains free in the use of it. The question of whether third-party education is included in the mapping, since the alert is already included in it, is an open question. For now, the answer is negative. Indeed and in a fifth time, appears the liberal definition of Compliance Law through the apprehension that the Law must make of the cartography of the risks. Beyond the rational act that any person has to control their risks for their own interest, by preventing the damaging effects of that from the crystallization of risk has in fact proved, it is a question of preserving an external interest for the preservation of which the Law must intervene because the subject of law, in particular the company will be less likely to be concerned. By the imprint of the law, risk mapping expresses the concern for an external interest, either of a system or of a third party. But this support in Ex Ante implies force (Sapin 2, Vigilance, financial market information obligation) or will (social responsibility, ethical commitment, adoption of non-financial standards) relates only to information, its constitution, its intelligibility and its hierarchy. Then it is the actors exposed to the risks, able to understand in Ex Ante the extent as far as they are concerned, either the entity itself, or the thirds, to choose to run them to no.     Consult the two sets of slides as basis of the conference:    Slides served as basis for the General Presentation of the cycle of conference on the Compliance Tools (in French)  Slides served as basis for the specific contribution "Théorie générale de la cartographie des risques / Legal Theory of Risk Mapping" (in French).   Read the working paper served as basis for the conference -

Organisation of events

Co-organization of the conference “La cartographie des risques /Risk mapping”

The conferences cycle Les outils de la Compliance (The Compliance tools) taking place between November 2019 and June 2020 organized by The Journal of Regulation & Compliance and all the Partner Universities will start this year on the theme of "La cartographie des risques" (Risk Mapping) .    -   Conference – Debate (in French)  jeudi Thursday, November 28, 2019. 19h15 – 21h15 at the Economics Department of Sciences Po  28 rue des Saints-Pères 75007 Paris Amphithéâtre Simone Veil   Under the scientific coordination of Guillaume Sarrat de Tramezaigues, Executive Director fo the  Economics Department of Sciences po.   Risk Mapping is defined as a process of identifying, evaluating and prioritizing risks: it is an integral and fundamental part of an effective global strategy for managing these risks.  As a central tool for Compliance, this approach may not be radically new, but the Risk Mapping Technique is now renewed and sometimes compromised by the emergence of new Risks, often due to their new mutiform nature. Moreover, the primacy of the new pair of "Political Risks/Compliance Risks" tends to increase the vulnerability of organizations obliged by new legal provisions to draw up these maps, whereas these tools must also protect these organizations.  Before discussing it with the audience, the speakers will explain through their experience the place of this tool in Compliance, by looking at how Risk Mapping is articulated with the logic of value creation through risk-taking, inherent in entrepreneurial and political action. This good understanding is not only essential for the company, but also for the administrative and judicial authorities which control or sanction firms.   Especially with the interventions of: – Marie-Anne Frison-Roche, full professor of Regulatory Law and Compliance Law, Sciences Po – Jean-François Guillemin, former general secretary of the Bouygues Group – Lamia Liabes, Chief Operating Office, HSBC France – Guillaume Sarrat de Tramezaigues, executive Director fo the  Economics Department of Sciences po     Inscription : anouk.leguillou@mafr.fr -   This first event is more specifically   organized by the Economics Department of Sciences po. It opens the cycle of conferences organized by the Journal of Regulation & Compliance (JoRC) (see the partners of this cycle), whose general theme is Les outils de la Compliance (The Compliance tools). Read the General Presentation of the Conferences Cycles.   This manifestation will be the basis for a book.    Read the conditions for inscription, and conditions for access les conditions d'accès (in French). -  

Conferences

November 28, 2019. 1st event of the cycle “Les outils de la Compliance /Compliance tools”: “La cartographie des risques /Risk mapping” at Sciences Po

The conferences cycle Les outils de la Compliance (The Compliance tools) taking place between November 2019 and June 2020 organized by The Journal of Regulation & Compliance and all the Partner Universities will start this year on the theme of "La cartographie des risques" (Risk Mapping) .    -   Conference – Debate (in French)  jeudi Thursday, November 28, 2019. 19h15 – 21h15 at the Economics Department of Sciences Po  28 rue des Saints-Pères 75007 Paris Amphithéâtre Simone Veil   Under the scientific coordination of Guillaume Sarrat de Tramezaigues, Executive Director fo the  Economics Department of Sciences po.   Risk Mapping is defined as a process of identifying, evaluating and prioritizing risks: it is an integral and fundamental part of an effective global strategy for managing these risks.  As a central tool for Compliance, this approach may not be radically new, but the Risk Mapping Technique is now renewed and sometimes compromised by the emergence of new Risks, often due to their new mutiform nature. Moreover, the primacy of the new pair of "Political Risks/Compliance Risks" tends to increase the vulnerability of organizations obliged by new legal provisions to draw up these maps, whereas these tools must also protect these organizations.  Before discussing it with the audience, the speakers will explain through their experience the place of this tool in Compliance, by looking at how Risk Mapping is articulated with the logic of value creation through risk-taking, inherent in entrepreneurial and political action. This good understanding is not only essential for the company, but also for the administrative and judicial authorities which control or sanction firms.   Especially with the interventions of: – Marie-Anne Frison-Roche, full professor of Regulatory Law and Compliance Law, Sciences Po – Jean-François Guillemin, former general secretary of the Bouygues Group – Lamia Liabes, Chief Operating Office, HSBC France – Guillaume Sarrat de Tramezaigues, executive Director fo the  Economics Department of Sciences po     Inscription : anouk.leguillou@mafr.fr -   This first event is more specifically   organized by the Economics Department of Sciences po. It opens the cycle of conferences organized by the Journal of Regulation & Compliance (JoRC) (see the partners of this cycle), whose general theme is Les outils de la Compliance (The Compliance tools). Read the General Presentation of the Conferences Cycles.   This manifestation will be the basis for a book.    Read the conditions for inscription, and conditions for access les conditions d'accès (in French). -  

Working papers

Anchor points of the risk mapping process in the legal system

  This Working Paper served as the basis for an intervention in the conference organized in the conference cycle organized by the Journal of Regulation & Compliance (JoRC) on the theme: Compliance Tools, in collaboration with many university partners: this first conference is organized in collaboration with the Sciences po Economics Department and is held on November 28, 2019 at Sciences po and deals with the more specific theme of Risk mapping. It also serves as the basis for the book edited by Marie-Anne Frison-Roche, Compliance Tools, which will be released in the Regulations & Compliance collection.   -    Is the consideration by Law of the Risk Mapping mechanism so new? At first glance yes, and one might even be surprised at this novelty, since this rational anticipation of risks should have been recognized for a long time. But this is perhaps due to the more general fact that Risk itself has only recently become an autonomous legal object in Economic Law, in particular because Risk does not have at all the same position in Competition Law and in Regulation Law (I) .. Its position is even opposed in the both, Risk becoming central in Regulation Law. Compliance Law being the extension of Regulatory Law, it is also built on the "concern" of Risk and the internalization of this consideration in enterprises therefore takes the form of mapping. A closer look maybe not,even  before the specific  French laws, called "Sapin 2" and "Vigilance" and beyond them, case law decisions giving a general scope to maps drawn up by operators, or increasing the obligation that 'they have to do it (II). In this, general and precise technical Law offers points of support for Compliance Law, strengthening it in its tools.  

Articles in The Journal of Regulation & Compliance « JoRC »

The Government itself collects personal data on social networks, without the consent of the parties concerned, but for a good cause: the fight against tax fraud. What should we think about it legally?

The Finance Bill has proposed to the Parliament to vote an article 57 whose title is: Possibilité pour les administrations fiscales et douanières de collecter et exploiter les données rendues publiques sur les sites internet des réseaux sociaux et des opérateurs de plateformes (translation: Possibility for the tax and customs administrations to collect and exploit the data made public on the websites of social networks and platform operators). Its content is as is in the text voted on in the National Assembly as follows: "(1) I. – On an experimental basis and for a period of three years, for the purposes of investigating the offenses mentioned in b and c of 1 of article 1728, in articles 1729, 1791, 1791 ter, in 3 °, 8 ° and 10 ° of article 1810 of the general tax code, as well as articles 411, 412, 414, 414-2 and 415 of the customs code, the tax administration and the customs administration and indirect rights may, each as far as it is concerned, collect and exploit by means of computerized and automated processing using no facial recognition system, freely accessible content published on the internet by the users of the online platform operators mentioned in 2 ° of I of article L. 111-7 of the consumer code. (2) The processing operations mentioned in the first paragraph are carried out by agents specially authorized for this purpose by the tax and customs authorities.   (3) When they are likely to contribute to the detection of the offenses mentioned in the first paragraph, the data collected are kept for a maximum period of one year from their collection and are destroyed at the end of this period. However, when used within the framework of criminal, tax or customs proceedings, this data may be kept until the end of the proceedings. (4) The other data are destroyed within a maximum period of thirty days from their collection. (5) The right of access to the information collected is exercised with the assignment service of the agents authorized to carry out the processing mentioned in the second paragraph under the conditions provided for by article 42 of law n ° 78-17 of January 6, 1978 relating to data processing, the files and freedoms. (6) The right to object, provided for in article 38 of the same law, does not apply to the processing operations mentioned in the second paragraph. (7) The terms of application of this I are set by decree of the Council of State. (8) II. – The experiment provided for in I is the subject of an evaluation, the results of which are forwarded to Parliament as well as to the National Commission for Data Protection at the latest six months before its end. "   This initiative provoked many comments, rather reserved, even after the explanations given by the Minister of Budget to the National Assembly. What to think of it legally? Because the situation is quite simple, that is why it is difficult: on the one hand, the State will collect personal information without the authorization of the persons concerned, which is contrary to the very object of the law of 1978 , which results in full disapproval; on the other hand, the administration obtains the information to prosecute tax and customs offenses, which materializes the general interest itself. So what about it? Read below.

Jurisprudence

European Court of Human Rights (ECHR)

Decision of 24th of October 2019, Carrefour France v. France

Full reference: CEDH, 24th of October 2019, Carrefour France v. France, n°21488/14 Read the decision (in French) Read the press release (in French)   Summary of the decision In this decision, the ECHR convicts Carrefour France to a civil fine for practices restricting competition committed by the company Carrefour hypermarkets France, dissolved and absorbed by its sole shareholder Carrefour France after the facts.  

Working papers

Drawing up Risk Maps as an Obligation and the paradoxe of the “Compliance Risks”

This working paper has been the basis for the introduction in the presentation made in the conference organized by the Journal of Regulation & Compliance (JoRC) on the topic : Compliance Tools, in collaboration with many Universities partners.  This first conference has been organized with the Sciences po Economic Department on November 28, 2019 on Risks Mapping.    This working paper is articulated with a second working paper, being the basis of the first development of this conference, on the caractère nouveau ou non en Droit de l'obligation de cartographie des risques.   These two working papers are the basis for two articles published in the collective book, Compliance Tools, in the Series Regulations & Compliance. 

Glossary

Subsidiarity (principle of)

Subsidiarity in the current sense is the idea that those closest to the action to be carried out must do so rather than the one who is far from it, because the latter is on the one hand less legitimate to do so and on the other hand less effective to do so. Subsidiarity is therefore a mechanism of both efficiency and legitimacy. In this respect, it constitutes both a political and a management principle: it is a principle of governance. It is also found in the form of a legal principle in European Union law, with a strong impact in Regulatory Law. Indeed, the principle of subsidiarity is a pillar of the European Union. Article 5 of the Treaty states that the power which enables public authorities to act legally by setting standards and by coercion is and remains with the Member States. But – and this is the very meaning of the Treaty which founded the Community, then the European Union – powers and objectives have been conferred on the European Union. In a first formulation, it was stated that within the "limits" of these "competences" and these "objectives", the European Union (as a legal person endowed with powers) and its institutions – in particular the Commission – can to act. The first meaning of the principle of subsidiarity is therefore that which one could say of a "sovereignty retained" by the Member States: everything that is not vested in the European Union is retained by the Member States. But we can see that as much as it is easy enough to define the "limits of competences", the line is less certain concerning the "objectives". Indeed, the "objectives" conferred on the Union are so broad that, depending on the interpretation given by the Court of Justice of the European Union (CJEU), there may not be much left of the principle of subsidiarity. This is why the text was completed, a principle indicating more of a method. Indeed, the Treaty firstly states that in certain matters the European Union has "exclusive competence". It is also exceptional, since it is vested in the Member States. This mainly concerns customs jurisdiction outside the Union, monetary jurisdiction outside the euro zone, competition law and common commercial policy. In this case, the European institutions exercise their full normative powers. When this transfer has not taken place, the European Union is no longer prima facie legitimate, that is to say its institutions cannot act since the Member States remain the legitimate authors of the standards. But if it turns out that the European Union is best placed to effectively achieve the desired objectives, even if there is no transfer of exclusive competence to the Union, then if the European institution can provide this proof that it is "better placed" to act effectively, it will be able to act. Completed, Article 5 of the Treaty now provides: By virtue of the principle of subsidiarity, in areas which do not fall within its exclusive competence, the Union intervenes only if, and to the extent that, the objectives of the action envisaged cannot be sufficiently achieved by the Member States, both at central, regional and local level, but may be better achieved, due to the dimensions or effects of the envisaged action, at the level of the Union. The end of Article 5 is above all methodological: the method of comparing the effectiveness of the action of a Member State – for example a law – and the action of a Union institution – for example a draft Regulation drawn up by the European Commission. When the two claim to be the most effective in achieving the Community objective – for example – energy security, then the question of the burden of proof arises. This is where the principle of subsidiarity takes all its power, which is above all proof: it is indeed for the European Union, in the above example the European Commission – to demonstrate that it is proved its project for an instrument (here an energy security regulation) which will be more effective in serving the objective, which the Member State could not achieve alone. A very heavy burden of proof for the Union and numerous objects of proof: the inability of the Member State to achieve this objective and the capacity of the Union to achieve it. If the Union provides this proof, then, even if there has not been a transfer of exclusive competence to its benefit, it will be able to act and lay down the principle that in Europe the normative power remains in the Member States. The legal principle of subsidiarity is essential in Regulatory Law. Indeed, because of its link with Politics, sectoral regulations are generally not transferred exclusively to the level of the European Union. This is why, strictly speaking, there are no "European regulators", but rather agencies which centralize information and its access. However and to take the most topical example, the need generated by the financial and banking situation in Europe justified the regulatory, supervisory and institutional mechanisms being brought to community level by the Banking Union, from 2010. But we do not find the same transfers, for example in energy, rail or telecommunications, which would undoubtedly contradict the legal principle of subsidiarity.

Glossary

Sector

The sector is the first historical reference for Regulation since, independently of the notion of market, it is a set of economic activities which have a technical object in common, for example the telephone, rail or banking. It is precisely because these objects have a particular technicality, for example conveying innovation or presenting a risk, or developing only in the long term, that definitive regulations are put in place, because there is a failure of market. The breakdown by sector seems to be obvious, for example the post office on the one hand, the telephone on the other hand, and the media on the third. But the evolution of technology means that if one takes into consideration the transmission of information first, these sectors become interchangeable. This is why the primary criterion of technicality that justifies recourse to the sector to define the contours of regulation, the construction of a regulator and its powers, necessarily evolves over time with the technical modifications of the objects in question. This is why, for example, we have chosen to segment the telecommunications sector into around twenty markets, while the minds of the possible merger of regulators of the container and content in telecommunications and the media or that we hesitate between 'interregulation and the merger between banking, finance and insurance, while the entry into the digital "era" would give the idea of ​​a new regulator, while it is difficult to say that the digital is a sector. The question then arises as to whether the "sector" is an outdated benchmark. Internet and digital can make it think so. The sector, if it is not an outdated concept, is at least for regulation a changing concept, for example in that it must give way to the concept of sector.