Economic Law, Regulation and Compliance

Videos

The French Council of State (Conseil d’État) confirms the wide and therefore severe application of the sanctions mechanism in the Compliance Law concerning the freezing of assets, by its decision of November 15, 2019, La Banque Postale v. ACPR

Watch the video explaining the content, meaning and scope of the decision made by the Conseil d'État (French Council of State) on November 15, 2019, La Banque Postale v. Autorité de contrôle prudentiel et de résolution (ACPR). The Autorité de contrôle prudentiel et de résolution – ACPR (French Authority of prudential control and resolution) pronounced a very high sanction, representing 7% of La Banque Postale's net annual result. The breach is constituted by the fact of not having prevented the use of the banking technique of the "money order" which was used to escape the freezing of the assets. The Conseil d'État recalls that by nature if the assets are frozen, it is not possible that anyone is able to dispose of these assets. However, by the use of "money orders", persons targeted by asset freezing decisions, tools used in connection with the fight against money laundering and the fight against terrorism, had been able to circulate money to from accounts managed by La Banque Postale, of which they were not customers. This case was not foreseen at the time when the Bank Postale was sanctioned by the ACPR for not having prevented such a use, the texts forcing it under its obligations of "conformity" to prevent this behavior of violation background gels on the part of his customers, but only that. This case of a use of a means by a person who is not a customer of the bank was not foreseen at the time when the alleged facts took place and the Bank claims not to be able to be punished since in the repressive matter it is necessary to respect the principle of non-retroactivity of the texts, – in this case texts later supplemented to aim at such an assumption -, the non-retroactivity being a major principle itself related to the principle of the legality of the offenses and the penalties. We are therefore in the hypothesis of a silence of the texts. What to decide? Can the Bank be condemned and so heavily or not by the ACPR? The Bank does not think so.  It acted against this sanction decision firstly because those who used these money orders were not its clients. It has strong reasons to avail itself of this fact, since subsequently the texts needed to be modified to aim not only the use of this technique of money order by those who have a count in the bank and also by those who act with cash through the bank without a count, that is to say without an account holder to look at. Because we are in criminal matters, the restrictive interpretation and non-retroactivity of the text should lead to follow the reasoning of the Bank. But the Conseil d'État does not because it considers that implicitly but necessarily even with this subsequent modification of the text, it had aimed that use before. By this way, the Conseil d'Étatuncil develops a very broad concept of the obligations of banks in their role in the fight against money laundering, and therefore a very repressive point of view, which permeates their "obligation of Compliance". Thus, when the bank also argues that it can not be sanctioned since for it this activity of money order is  deficit and that it did not cause harm to its customers even by assuming badly its obligations, theConseil d'État stresses that this is not a pertinent perspective since the Compliance obligations falls within the "overriding general interest of protection of public order and public security, to which the freezing of assets legislation responds". -   Read the  judgment of the Conseil d'État ( in French). 

Conferences

Legal theory of Risk Mapping, in “Risk Mapping, as Compliance Tool” (conference made in French)

Reference : Frison-Roche, M.-A., General presentation of the cycle of conferences on Les outils de la Compliance  (Compliance Tools) and  "Théorie générale de la cartographie des risques" (Legal Theory of Risk Mapping), conference made in French, in Département d'Economie de Sciences Po & Journal of Regulation & Compliance (JoRC),  La cartographie des risques, outil de la Compliance (Risk Mapping, as Compliance Tool), November 28th, 2019, Sciences Po, Paris.    Read the  General Presentation ot the cycle of conferences about the Compliance Tools   Read the General Presentation of the book written in English to be published   Read the General Presentation of the serie Régulations & Compliance in which the book will be published   Summary of the conference Risk mapping is both central to the obligations or practices of companies and little apprehended by the legal systems. It is not expressly referred to by the French legal system, except for the special national laws known as "Sapin 2" and "Vigilance". But if we are out of this field, because there is only a description and not a legal definition, even less a legal notion, we do not know what legal regime to apply to the action of mapping risks. It is therefore useful, indeed compelling, to define the legal concept of risk mapping. Starting from what is still the safest ground, namely these two special laws, to go towards less secure legal grounds, such as the doctrine of the authorities or the commitments of the companies, even the ISO certifications obtained in this matter. Through a few judicial decisions and legal reasoning, a legal notion of the action of mapping risks emerges. It is advisable to proceed in 5 steps (the working document follows another approach). The first, based directly on the two available laws, apprehends the action of mapping when it comes into execution of a special legal obligation. The decision rendered in 2019 by the French Commission des sanctions of the Agence Française Anticorruption (French Corruption Agency's Sanctions Commission) draws probate games as to the demonstration of the execution of the obligation and the probationary system can be extended. In the same way the decision of the French Conseil constitutionnel (Constitutional Council) in 2017 on the "Vigilance Act" shows that a mechanism referred to as a "modality" is legitimate with regard to the goal, which is, concerning this tool, the establishment of a responsibility for others. It is therefore the concern for the situation of others that can be targeted by the Law thanks to Compliance Tool, especially Risk Mapping. The second theme aims to map risks as a fact of good management for a company, while the enterprise is not constrained by a legal obligation. This fact is a paradox because the Regulatory Authority and the Judge may, where the conduct that was to be prevented occurs, for example a market abuse or an anti-competitive behavior, either qualify as an aggravating circumstance or as an attenuating circumstance. Consideration of the theory of incentives should lead to the adoption of the American solution, that is to say the qualification of an effective cartography as a mitigating fact. European case law is not yet fixed, especially in terms of Competition Law's compliance. The third theme is the mapping action carried out by an entity which, in doing so, exercises power over a third party. Because cartography is as much an obligation as a power, possibly on a third party. The Conseil d'État (French Council of State) in 2017 qualified risk mapping as an act of grievance, but doing so legitimately, since it was to prevent forest fires efficiently. This solution based on the teleology attached to Compliance Law can be transposed to other areas. Going further, one may consider transforming this action from de facto status to legal status on the part of the company, if it thus identifies risks for third parties. It would thus give third-party creditors the right to be in a position to measure the risks that weigh on them. Risk mapping would thus be part of a broader unilateral commitment by powerful companies, recognizing the existence of risks for third parties to enable them to know their nature and extent. If this responsibility Ex Ante (characteristic of Compliance Law) is fulfilled, then the Ex Post liability of the company could no longer be retained. This is the ongoing issue of the Johnson & Johnson trial (2019 American judgment), in terms of medical compliance. Because if one can argue that there exists through this kind of risk mapping that the posology a "subjective right to be worried about the risks related to the taking of the drug", the patient remains free in the use of it. The question of whether third-party education is included in the mapping, since the alert is already included in it, is an open question. For now, the answer is negative. Indeed and in a fifth time, appears the liberal definition of Compliance Law through the apprehension that the Law must make of the cartography of the risks. Beyond the rational act that any person has to control their risks for their own interest, by preventing the damaging effects of that from the crystallization of risk has in fact proved, it is a question of preserving an external interest for the preservation of which the Law must intervene because the subject of law, in particular the company will be less likely to be concerned. By the imprint of the law, risk mapping expresses the concern for an external interest, either of a system or of a third party. But this support in Ex Ante implies force (Sapin 2, Vigilance, financial market information obligation) or will (social responsibility, ethical commitment, adoption of non-financial standards) relates only to information, its constitution, its intelligibility and its hierarchy. Then it is the actors exposed to the risks, able to understand in Ex Ante the extent as far as they are concerned, either the entity itself, or the thirds, to choose to run them to no.     Consult the two sets of slides as basis of the conference:    Slides served as basis for the General Presentation of the cycle of conference on the Compliance Tools (in French)  Slides served as basis for the specific contribution "Théorie générale de la cartographie des risques / Legal Theory of Risk Mapping" (in French).   Read the working paper served as basis for the conference -

Organisation of events

Co-organization of the conference “La cartographie des risques /Risk mapping”

The conferences cycle Les outils de la Compliance (The Compliance tools) taking place between November 2019 and June 2020 organized by The Journal of Regulation & Compliance and all the Partner Universities will start this year on the theme of "La cartographie des risques" (Risk Mapping) .    -   Conference – Debate (in French)  jeudi Thursday, November 28, 2019. 19h15 – 21h15 at the Economics Department of Sciences Po  28 rue des Saints-Pères 75007 Paris Amphithéâtre Simone Veil   Under the scientific coordination of Guillaume Sarrat de Tramezaigues, Executive Director fo the  Economics Department of Sciences po.   Risk Mapping is defined as a process of identifying, evaluating and prioritizing risks: it is an integral and fundamental part of an effective global strategy for managing these risks.  As a central tool for Compliance, this approach may not be radically new, but the Risk Mapping Technique is now renewed and sometimes compromised by the emergence of new Risks, often due to their new mutiform nature. Moreover, the primacy of the new pair of "Political Risks/Compliance Risks" tends to increase the vulnerability of organizations obliged by new legal provisions to draw up these maps, whereas these tools must also protect these organizations.  Before discussing it with the audience, the speakers will explain through their experience the place of this tool in Compliance, by looking at how Risk Mapping is articulated with the logic of value creation through risk-taking, inherent in entrepreneurial and political action. This good understanding is not only essential for the company, but also for the administrative and judicial authorities which control or sanction firms.   Especially with the interventions of: – Marie-Anne Frison-Roche, full professor of Regulatory Law and Compliance Law, Sciences Po – Jean-François Guillemin, former general secretary of the Bouygues Group – Lamia Liabes, Chief Operating Office, HSBC France – Guillaume Sarrat de Tramezaigues, executive Director fo the  Economics Department of Sciences po     Inscription : anouk.leguillou@mafr.fr -   This first event is more specifically   organized by the Economics Department of Sciences po. It opens the cycle of conferences organized by the Journal of Regulation & Compliance (JoRC) (see the partners of this cycle), whose general theme is Les outils de la Compliance (The Compliance tools). Read the General Presentation of the Conferences Cycles.   This manifestation will be the basis for a book.    Read the conditions for inscription, and conditions for access les conditions d'accès (in French). -  

Working papers

Anchor points of the risk mapping process in the legal system

  This Working Paper served as the basis for an intervention in the conference organized in the conference cycle organized by the Journal of Regulation & Compliance (JoRC) on the theme: Compliance Tools, in collaboration with many university partners: this first conference is organized in collaboration with the Sciences po Economics Department and is held on November 28, 2019 at Sciences po and deals with the more specific theme of Risk mapping. It also serves as the basis for the book edited by Marie-Anne Frison-Roche, Compliance Tools, which will be released in the Regulations & Compliance collection.   -    Is the consideration by Law of the Risk Mapping mechanism so new? At first glance yes, and one might even be surprised at this novelty, since this rational anticipation of risks should have been recognized for a long time. But this is perhaps due to the more general fact that Risk itself has only recently become an autonomous legal object in Economic Law, in particular because Risk does not have at all the same position in Competition Law and in Regulation Law (I) .. Its position is even opposed in the both, Risk becoming central in Regulation Law. Compliance Law being the extension of Regulatory Law, it is also built on the "concern" of Risk and the internalization of this consideration in enterprises therefore takes the form of mapping. A closer look maybe not,even  before the specific  French laws, called "Sapin 2" and "Vigilance" and beyond them, case law decisions giving a general scope to maps drawn up by operators, or increasing the obligation that 'they have to do it (II). In this, general and precise technical Law offers points of support for Compliance Law, strengthening it in its tools.  

Articles in The Journal of Regulation & Compliance « JoRC »

The Government itself collects personal data on social networks, without the consent of the parties concerned, but for a good cause: the fight against tax fraud. What should we think about it legally?

The Finance Bill has proposed to the Parliament to vote an article 57 whose title is: Possibilité pour les administrations fiscales et douanières de collecter et exploiter les données rendues publiques sur les sites internet des réseaux sociaux et des opérateurs de plateformes (translation: Possibility for the tax and customs administrations to collect and exploit the data made public on the websites of social networks and platform operators). Its content is as is in the text voted on in the National Assembly as follows: "(1) I. – On an experimental basis and for a period of three years, for the purposes of investigating the offenses mentioned in b and c of 1 of article 1728, in articles 1729, 1791, 1791 ter, in 3 °, 8 ° and 10 ° of article 1810 of the general tax code, as well as articles 411, 412, 414, 414-2 and 415 of the customs code, the tax administration and the customs administration and indirect rights may, each as far as it is concerned, collect and exploit by means of computerized and automated processing using no facial recognition system, freely accessible content published on the internet by the users of the online platform operators mentioned in 2 ° of I of article L. 111-7 of the consumer code. (2) The processing operations mentioned in the first paragraph are carried out by agents specially authorized for this purpose by the tax and customs authorities.   (3) When they are likely to contribute to the detection of the offenses mentioned in the first paragraph, the data collected are kept for a maximum period of one year from their collection and are destroyed at the end of this period. However, when used within the framework of criminal, tax or customs proceedings, this data may be kept until the end of the proceedings. (4) The other data are destroyed within a maximum period of thirty days from their collection. (5) The right of access to the information collected is exercised with the assignment service of the agents authorized to carry out the processing mentioned in the second paragraph under the conditions provided for by article 42 of law n ° 78-17 of January 6, 1978 relating to data processing, the files and freedoms. (6) The right to object, provided for in article 38 of the same law, does not apply to the processing operations mentioned in the second paragraph. (7) The terms of application of this I are set by decree of the Council of State. (8) II. – The experiment provided for in I is the subject of an evaluation, the results of which are forwarded to Parliament as well as to the National Commission for Data Protection at the latest six months before its end. "   This initiative provoked many comments, rather reserved, even after the explanations given by the Minister of Budget to the National Assembly. What to think of it legally? Because the situation is quite simple, that is why it is difficult: on the one hand, the State will collect personal information without the authorization of the persons concerned, which is contrary to the very object of the law of 1978 , which results in full disapproval; on the other hand, the administration obtains the information to prosecute tax and customs offenses, which materializes the general interest itself. So what about it? Read below.

Working papers

Drawing up Risk Maps as an Obligation and the paradoxe of the “Compliance Risks”

This working paper has been the basis for the introduction in the presentation made in the conference organized by the Journal of Regulation & Compliance (JoRC) on the topic : Compliance Tools, in collaboration with many Universities partners.  This first conference has been organized with the Sciences po Economic Department on November 28, 2019 on Risks Mapping.    This working paper is articulated with a second working paper, being the basis of the first development of this conference, on the caractère nouveau ou non en Droit de l'obligation de cartographie des risques.   These two working papers are the basis for two articles published in the collective book, Compliance Tools, in the Series Regulations & Compliance. 

Articles

By Compliance, continental criminal justice mechanisms have come from inquisitorial procedure to adversarial system

Référence générale : Frison-Roche, M.-A., "La justice pénale est passée de l'inquisitoire à l'accusatoire" (By Compliance, Continental Criminal Justice Mechanisms have come from Inquisitorial Procedure to Adversarial System), Interview in French about the impact of the "conventions judiciaire d'intérêt public", the French equivalent of DPI, and Compliance Procedures in French Law, Lettre des juristes d'affaires, n°1416, October 14, 2019. Summary : In this interview and through the three questions asked, the answers show that we have gone from an inquisitorial system to an adversarial system, which is a  sort of Revolution especially in matter of proofw. The French legal system must be adapted, but also or, above all, this conception of Compliance efficiency is a mechanism without a judge. The expression of "deal of justice" is excessive, because precisely if there is a "deal", there is no a "judge" : the prosecutor was not a judge. These mechanisms are also handled by the administrative Independant Bodies of Regulation or Supervision, which act here as "prosecuting authorities", that is to say as prosecutor. They also "deal" the non-appearance of the judge, the opposite of "justice", in a classical conception which is the figure of the judge. It is true that in the case of the "convention judiciaire d'intérêt public" the French Law requires an approval by the judge of the CJIP: it is then that the stake moved. There is a change of culture: the prosecutor is in the center, the Regulator or the Supervisor are the "prosecuting authority" and it is as approval authority that the judge or the administrative Sanctions Committee intervenes. But later. When the essential are the proofs obtained in the first lapse of time. The firm or the person can be evaded by asserting his "right to the judge". This judge who seeks the truth while an authority to pursue wants something else: win. We must understand that.    Read the Interview (in French) and the answers to these three questions:  1. En quoi les mécanismes de justice négociée, relativement récents en France, bouleversent les concepts hexagonaux de l’ordre judiciaire ? /  How the negotiated justice mechanisms, relatively recent in France, upset the hexagonal concepts of the judiciary? 2. Les entreprises ont-elles véritablement le choix d’accepter ces « deals de justice » ? / Do companies really have the choice to accept these "deals of justice"? 3. En matière de lutte contre la corruption, les autorités de poursuite se comportent désormais comme des juges puisqu’ils exigent des engagements pour le futur. Quels sont les risques ? / In the fight against corruption, prosecution authorities now behave like judges since they demand commitments for the future. What are the risks ?

Breaking news

no title

Conferences

The solutions offered by Compliance Law to fight effectively against mass counterfeiting

Generale Reference : Frison-Roche, M.-A., Les solutions offertes par le Droit de la Compliance pour lutter effectivement contre les contrefaçons de masse (The solutions offered by Compliance Law  to fight effectively against mass counterfeiting) , in Seminar of the Association des Praticiens du Droit Droit des Marques et des Modèles (APRAM), La contrefaçon de masse : va-t-on un jour réussi à y mettre un frein ? Quelques nouvelles pistes de réflexion (How to stop the mass Counterfeiting?, some new ideas), Paris, September 27, 2019.  Read the program of the Seminar. (in French) This conference is based on the report given to the French Government and published in July2019 : The contribution of Compliance Law to the Governance of Internet. It is also based on the new contribution to the new edition of the Grands Arrêts de la propriété intellectuelle : "Le maniement de la propriété intellectuelle comme outil de régulation et de compliance"(in French).  This publication is based on this Working Paper : The use of Intellectuel Property as a tool for Regulatory and Compliance Perspectives.      Summary : In this seminar devoted to new ways of reacting to "mass counterfeiting", the idea here is to start from the observation of an increase in the ineffectiveness of intellectual property rights – and thus of the I.P. Law. Law being a practical art, it is not a simple inconvenience, it is a central question. This can be remedied by improving the Ex Post legal process, but we can think of finding Ex Ante mechanisms. The Regulatory Law is Ex Ante, but digital world is not a sector, it is the world itself. A promising direction is therefore Compliance Law, in that it is both Ex Ante and non-sectoral. The contribution shows how Compliance Law is already useful, could be developed and how it could be applied so that these specific rights could be effectively protected in a digital world, where for the moment counterfactors have in fact the means to ignore them.   See the slides. (in French)  

Breaking news

BY BASIC TECHNOLOGY, MANY SITES BLOCKTHE INTERNET USERS THE POSSIBILITY TO SAY “NO”:THEY “CONSENT” TO TRANSFER THEIR PERSONAL DATA, WITHOUT OTHER TECHNOLGICAL CHOICES THAN THAT OF “ALL ACCEPT”. THE LINK BETWEEN “CONSENT” AND “FREE WILL” IS THEREFORE BROKEN

Experience shows that in the digital the legal technique of consent is not protective enough.   If only because a simplest technology neutralizes the link that should exist between the "consent" of the user and the "free will" of the latter: the consent of the user only protects the latter to the extent that this one can in Law and in fact to say "no.     I. THE EXPERIENCE    For example I found on my Facebook New an access to an unknown web site which puts online an article on "the rights of trees" … I go. In accordance with the European Regulation (GDPR) transposed into French legal system, the site informs that there is possibility for the user to accept or refuse the use of their personal data for the benefit of "partners". If they continue reading, the user is supposed to accept everything, but they can click to "customize". I click: there I find two options: "accept everything" or "reject everything". But the "reject all" option is disabled. It is only possible to click on the "accept all" option.   It is also possible, because the law obliges, to consult the list of the partners of this website: I click and find a list of unknown companies, with foreign denominations, which without doubt once will collect my personal data (and those of my contacts) , having their own head office outside the European Union. It is stated in a text, which can not be copied, that these "partners" can use my data without my consent and for purposes that they do not have to inform me. But, again, these things I can "refuse everything". Here again the "reject all" mention exists but the fonctionality is not active, while the mention "accept all" is an active fonctionality.   As I can not refuse (since it's disabled), and as 99% of Internet users have never clicked on the first two buttons, all their data has been fed into the data market that allows the targeting of products that spill out in the digital space, to their detriment and that of their contact. While believing to read a free article on the "right of the trees". At the end, I do not read this article, since I did not click on the only active buttons: "accept everything".   In more than 50% of cases, the "reject all" or "customize" options are only images but are not active. And data absorption is also about contacts. In exchange for a whimsical article about trees and their rights, or creams to be always young, or celebrities who change spouses, or about so-called tests to find what king or queen you should be if the all recognized all your merits, etc. Proposed on the digital news feed by unknown sites; in partnership with foreign companies that you will never reach. And mass-viewed by Internet users who are also told that "consent" is the proven solution for effective protection …. While these are just panels hastily built by new Potemkins …   II. WHAT TO DO ?    1. Not be satisfied with "consent" from the moment that it is a mechanism that may not be the expression of a free will: how could it be if the option "to refuse" is not active?   2. The link between will and consent must therefore be "presumed" only in a simple presumption and in a non-irrefutable way, because we must refuse to live in a dehumanized society, operating on "mechanical consents", to which the digital does not lead necessarily.   3. Entrust by the Compliance Law to the "crucial digital operators" (in the case of Facebook thanks to which these proposals for free reading are made on the thread of news of the Net surfers) the care to verify in Ex Ante the effectiveness of the link between Will and Consent: Here and concretely the possibility for the user to read while refusing the capture of all its data (for the benefit of operators who do not even have the concrete obligation to give the information of the use that will be made of these personal data).   -