Articles in the Journal of Regulation & Compliance (JoRC)

Articles in The Journal of Regulation & Compliance « JoRC »

📝 Definition of Proportionality and Definition of Compliance Law, in 🕴️ M.-A. Frison-Roche (ed.), 📘Compliance Monumental Goals

► Full Reference: M.-A. Frison-Roche, " Definition of Proportionality and Definition of  Compliance Law", in M.-A. Frison-Roche (ed.), Compliance Monumental Goals, series "Compliance & Regulation", Journal of Regulation & Compliance (JoRC) and Bruylant, 2023, p. - ► Article Summary: The use of Proportionality t always limit powers is only justified when it is about sanctions, but sanctions are only one tool among others in Compliance Law, intended moreover to have little place in this Ex Ante branch of Law. And returning to the very nature of Compliance Law, which relies on operators, private or public, because they are powerful, then using proportionality to limite powers is detrimental to Compliance Law.  However, nothing requires that. Compliance Law is not an exception that should be limited. On the contrary, it is a branch of Law which carries the greatest principles, aimed at protecting human beings and whose Normativity lies in its "Monumental Goals": detecting and preventing future major systemic crisis (financial, health and climate ones). However, literally the principle of Proportionality is: "no more powers than necessary, as many powers as necessary". The second part of the sentence is independent of the first: this must be used. Politics having fixed these Monumental Goals, the entity, in particular the company, must have, even tacitly, "all the necessary powers" to achieve them. For example, the power of vigilance, the power of audit, the power over third parties. Because they are necessary to fulfill the obligations that these "crucial operators" must perform as they are "in a position" to do so. So instead of limiting the powers, the Principe of Proportionality comes to support the powers, to legitimize them and to increase them, so that we have a chance that our future is not catastrophic, perhaps better. In this respect, Compliance Law, in its rich Definition, will itself have enriched the Principle of Proportionality. -   🚧read the Working Paper, with technical developments, references, and hypertext links. - 📘go to the general presentation of the book in which this article is published - ► read the presentations of the other Marie-Anne Frison-Roche's contributions in this book:  📝Compliance Monumental Goals, beating heart of Compliance Law,  📝 Role and Place of Companies in the Creation and Effectiveness of Compliance Law in Crisis,  📝 Assessment of Whistleblowing and the duty of Vigilance -

Articles in The Journal of Regulation & Compliance « JoRC »

📝Place and rôle of Companies in the Creation and Effectiveness of Compliance Law in Crisis, in 🕴️M.-A. Frison-Roche (ed.), 📘Compliance Monumental Goals

► Full Reference: M.-A. Frison-Roche, "Place and rôle of Companies in the Creation and Effectiveness of Compliance Law in situation of crisis", in M.-A. Frison-Roche (ed.), Compliance Monumental Goals, series "Compliance & Regulation", Journal of Regulation & Compliance (JoRC) and Bruylant, 2023, p. - ► Article Summary:  This article has a very topic: the place of private Companies, regarding the chapter's issue: "the ordeal of a crisis". The crisis constitutes a "test", that is to say, it brings evidence. Let us take it as such. Indeed, during the health crisis, Companies have helped the Public Authorities to resist the shock, to endure and to get out of the Crisis. They did so by force, but they also took initiatives in this direction. From this too, we must learn lessons for the next crisis that will come. It is possible that this has already started in the form of another global and systemic crisis: the environmental crisis. In view of what we have been able to observe and the evolution of the Law, of the standards adopted by the Authorities but also by the new case law, what can we expect from Companies in the face of this next Crisis, willingly and strength? -   🚧Read the bilingual Working Paper, with more developments, technical references, and hypertext links. - 📘go to the general presentation of the book, Compliance Monumental Goals, in which this article is published - ► read the presentations of the other Marie-Anne Frison-Roche's contributions in this book:  📝Compliance Monumental Goals, beating heart of Compliance Law,  📝Definition of Principe of Proportionality and Definition of Compliance Law, 📝 Assessment of Whistleblowing and the duty of Vigilance - .  

Articles in The Journal of Regulation & Compliance « JoRC »

📝Décrire, concevoir et corréler les outils de la Compliance, pour en faire un usage adéquat, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "Décrire, concevoir et corréler les outils de la Compliance, pour en faire un usage adéquat" ("Describing, conceiving and correlating Compliance Tools, in order to use them adequately"), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. Régulations & Compliance, Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp. 3-24. - 📝read the article (in French) - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation & Compliance): The article is the general introduction to the book on Compliance tools. In its first part it develops the overall problematic. In its second part, it presents each of the contributions, placed in the overall construction of the work. -

Articles in The Journal of Regulation & Compliance « JoRC »

📝Résoudre la contradiction entre “sanction” et “incitation” sous le feu du Droit de la Compliance, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "Résoudre la contradiction entre "sanction" et "incitation" sous le feu du Droit de la Compliance" ("Resolving the contradiction between "sanction" and "incentive" under the fire of Compliance Law"), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. "Régulations & Compliance", Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp. 89-98 - 📝read the article (in French) - 🚧read the bilingual Working Paper which is the basis of this article, with more developments, technical references and hyperlinks  - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation and Compliance): Compliance and Incentives appear at first glance to be totally opposite. For two major reasons. Firstly, because sanctions have a central place in Compliance Law and that the incentives suppose an absence of constraint on the operators. Secondly, because the incentives are linked to self-regulation and that Compliance Law assumes a strong presence of public authorities. Thus, one should choose: either Compliance or Incentives! Either the effectiveness of one or the effectiveness of the others; either the techniques of one, or the techniques of others; either the philosophy of one or the philosophy of the other. Resign oneself to the waste that such a necessary choice would imply. But to put the terms in this way amounts to thinking poorly about the situations and reducing the fields of the solutions they call for. If we take a rich definition of Compliance Law, we can on the contrary articulate Compliance and Incentives. From this perspective, sanctions can no longer become what blocks the use of incentives but, on the contrary, what constitutes them. Even more, the coupling between the Incentives and the requirements of Compliance Law must be strongly encouraged, as soon as the public authorities supervise in Ex Ante all the initiatives taken by the "crucial operators". This article deals with the first issue. Indeed, the so-called incentive theory targets mechanisms which do not directly resort to constraint. They would therefore have little place in Compliance Law. But it seems saturated with sanction procedures. We can even say that it seems to put them at the center, the public authorities presenting the number of sanctions as a sign of success, while the companies seem obsessed with their prospects, the two concerns ending in such a strange convergence that are the Convention Judiciaire d'Intérêt Public (non-prosecution agreement). The honest observer cannot help but be immediately uneasy. Indeed, it can only raise the definition of the sanction as a "constraint" triggered Ex Post, at the very heart of a Compliance Law which is presented as a set of Ex Ante mechanisms. Based on this contradiction in terms, should we give up the association and think that it would be wrong against the spirit to think of the sanction as an incentive? It is undoubtedly in this connection that one perceives most clearly the clash of two cultures, which do not communicate, while technically they apply to the same situations. Indeed, because Compliance was designed by Finance, everything is a tool for it. Therefore, the tendency to think of the sanction only as an incentive is very strong in Compliance Law, manifests itself continuously and will not stop (I). But whatever the reasons for conceiving it this way, the principles of the rule of law cannot disappear and if we do not want them to be erased, then they must be articulated (II). This is an essential game (II). This is why we can literally say that Compliance has set Criminal Law on fire by its conception, logical but closed in on itself, of sanctions as simple incentives. In order for Law to remain, however, we must hold a very firm definition of Compliance Law centered on its Monumental Goal, which is the protection of the person. -

Articles in The Journal of Regulation & Compliance « JoRC »

📝Compliance et incitations : un couple à propulser, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "Compliance et incitations: un couple à propulser " ("Compliance and incentives : a promising tandem"), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. "Régulations & Compliance", Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp. 123-130. - 📝read the article (in French) - 🚧read the bilingual Working Paper which is the basis of this article, with more developments, technical references and hypertext links - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation and Compliance): The theory of incentives targets the mechanisms which do not use directly constraint (except to present sanctions themselves as incentives) but which leads nevertheless to expected behaviors. To appreciate the links which must or must not be done between incentives and Compliance, we should proceed in two times.  First, the association appears natural between incentive mechanisms and "Compliance Law" since the later is defined in a dynamic way. Indeed, if it is defined placing its legal normativity in its "monumental goals", as the end of corruption, the detection of money laundering in order to underlying criminality disappears, or as the effective protection of environment or the concrete care of human beings, then what matters is not the means in themselves but the effective tension towards these "monumental goals". In this perspective, what was related to public policies led by States, because they are definitively not able to do it, the charge is internalized in the firms which are able to tend towards this goals: "crucial operators" because they have the geographical, technological, informational and financial means.  In this perspective, the internalization of public willingness provoking a split with the concept of State linked to a territory which deprives Politics of its constraint power, incentive mechanisms appear as the most efficient mean to reach these monumental goals. They appear as this "natural" mean both negatively and positively defined. Negatively in which they do not need in Ex Ante institutional localizable sources and sanction power in Ex Post: it is enough to substitute the interest to obligation. Positively, incentives relay through operators' strategies what was the so critical and joked form of public action: the "plan". The duration is thus injected thanks to Compliance mechanisms, as we can see it through the development of it in the care for environment ("plan climat") or through the educational mechanism, which could be conceived only in duration.   However, the opposition seems radical between Compliance Law and Incentives. And this because of three convictions often developed and that we have to overcome. First, the idea that in a general way, there would be a Law only if there is a mechanism of immediate constraint which is associated to the norm. As long as the incentive is not based on obligation, then it will be nothing… Secondly, and as if that were a kind of consolation …, Compliance would not be really Law either … We so often say that it is only about a methodology, a range of processes without sense, procedures to follow without trying to understand, process that algorithms integrate in a mechanic without end and without sense or that on the contrary, Compliance would be full of sense by Ethics and Morality, which are far from Law. While incentives talk to the human spirit which calculate, Compliance would be so a process through which machines will be connected to other machines, so an extra soul, where calculation has no place… Thirdly, solutions would be to be find in Competition Law because it can do without States, submit them and approach what is a-sectorial, especially finance and digital, the world being financialized and digitalized. The violence of Competition Law which comes in Ex Ante thanks to "Compliance sanctions" applying for example to essential infrastructures Law, by continuing to deny the salience of the duration and taking care of the "market power" would be also not compatible with a marriage with incentive mechanisms which rely on duration and power of those to which it is applied, converging towards goals, which are set by what Competition Law ignores: the project. This project which pretends to build the future is the one of politics and of companies, which use their deployed power in time to concretize it. It is without any doubt there that the future of Europe is.  To overcome this triple difficulty, it is thus necessary, in a second time, to modify our conception of Law, especially thanks to Compliance Law, in which this new branch is autonomous from Competition Law, and even sometimes opposed to it, in order to the insertion of incentive mechanisms permit to unknown or against Competition Law organizations to reach "monumental goals" which are imperative to take into consideration. For example, the taking into consideration of climate challenges or the building of a sovereign identity of the data. This is expressly set by European Commission which supervises such initiatives, supervision being what is articulated with Compliance, in a couple that go beyond Regulation, and replaces in Ex Ante Competition Law, salient branch for Ex Post. All the texts which are in the process of expressing it are based on this reformed couple: Compliance and Incentive. This couple supposes that we recognize as such the existence of companies as project carriers, project which is the creation of marketed wealth circulating on a market, which could be an industrial project specific to a geographical zone both economical and political. Regulation is deployed to go away from the notion of sector and to transform itself in supervision of crucial firms in the correspondance between the project and the action, what refers to the notion of "plan". In this, banking supervision is just the advanced bastion of all thematic, energetic, climatic and health plans, or more broadly industrial and technological that could by incentive be implemented, this conception of Compliance permitting to build zones which are not reduced to immediate market exchange. The incentive corresponds to the fact that Compliance Law relies on the power of the firm to reach its own political goals, for example fighting against disinformation in the digital space or obtaining a healthy environnement. This supposes that Compliance stops to be only conceived as a model of rules effectivity, for example of Competition Law, to be recognized as a substantial branch of Law. A branch which expresses political goals. A branch which is anchored in crucial firms whose it recognizes the autonomy with regards to markets. This makes it possible, in particular through the coupling with incentive mechanisms leading to long-term collaborative operations supervised by public authorities, not to be governed by simple Competition Law, inapt to bring projects to fruition. -

Articles in The Journal of Regulation & Compliance « JoRC »

📝Les droits subjectifs, outils premiers et naturels du Droit de la Compliance, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "Les droits subjectifs, outils premiers et naturels du Droit de la Compliance" ("Rights, primary and natural Compliance Tools"), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. "Régulations & Compliance", Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp. 301-323. - 📝read the article (in French) - 🚧read the bilingual Working Paper which is the basis of this article, with additional developments, technical references and hyperlinks - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of this article (done by the Journal of Regulation and Compliance): In the traditional conception of the architecture of the sectors regulated by Law, and in Compliance Law which extends the regulatory techniques, rights have little place. But this configuration no longer takes place; on the contrary, rights are at the center of Regulatory and Compliance systems, and will be more and more so. They are and will be the primary tools of Compliance Law because they constitute a very effective "tool" to ensure the entire functioning of a system whose goals are so difficult to achieve. Because every effort must be done to achieve these goals, the public authorities not only rely on the power of crucial operators, but also distribute prerogatives to people and organizations who, thus encouraged, activate the Compliance system and participate in the achievement of the "monumental goal". Rights can prove to be the most effective tools for actually achieving the goals set, so much so that they can be seen as "primary tools". But it is pertinent to have more pretension and to conceive rights as the most "natural" tools of Compliance Law. Indeed because all the Monumental Goals by which Compliance Law is defined can be expressed by the protection of persons, that is to say to the effectiveness of their prerogatives, by a mirror effect between rights. given as tools by Law by to persons and rights which constitute the very goal of all Compliance Law, in particular the protection of all human beings, even if they are in a situation of great weakness, rights becoming a "natural tool" of Compliance Law. We are only at the beginning of their deployment and it is undoubtedly on them that Digital space in which we now live would be regulated, so that we will not suffocated there and that it will constitute for people a civilized space. -

Articles in The Journal of Regulation & Compliance « JoRC »

📝Dresser des cartographies des risques comme obligation et le paradoxe des “risques de conformité”, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "Dresser des cartographies des risques comme obligation et le paradoxe des "risques de conformité"" ("Drawing up risk maps as an obligation and the paradoxe of the "compliance risks""), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. "Régulations & Compliance", Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp. 53-62. - 📝read the article (in French) - 🚧read the bilingual Working Paper which is the basis of this article, with additional developments, technical references and hyperlinks - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation & Compliance): There are few synthetic or theoretical studies on Risk Mapping even though it is in fact the Compliance central tool, perhaps because it is more a management tool than a legal one. Risk Mapping is often described but does not receive any other legal qualifications than being a "modality", suffering in this respect from an evil which affects the whole of Compliance, still little understood by Law, attention often so focused on the Ex Post (sanctions) while Compliance is by nature in the Ex Ante. Going from disarray to incomprehension, everyone can note the existence of "compliance risks" among the mapped risks, because if as so many affirm that it would be necessary to speak only of simple conformity as obedience, demonstrated in Ex Ante, to Law, how a sub-set of a tool would therefore have the same object as the set of Law that this tool serves … This aporia can only be resolved if Compliance Law is defined substantially by its "monumental goals" which exceed obedience to regulations. Consequently, Law taking up Risk Mapping, this mechanism may first appear as an ancillary obligation to the main obligation consisting in achieving "monumental goals". The ancillary obligation to draw up the maps is an obligation of result, while the main obligation to achieve the monumental goals is an obligation of means. These cartographies being very diverse and being only occasionally targeted by specific laws, it can also constitute only a legal fact or, through the play of various charters, a unilateral legal commitment. But it isnbecoming the basis of an autonomous legal obligation incumbent on enterprises in position to know certain risks, obligation referring to the existence of a subjective right tof knowing and measuring them ("right to be worried") which the third parties who are going to run them would hold, thus allowing them to choose to run them, or not.   -

Articles in The Journal of Regulation & Compliance « JoRC »

📝La formation : contenu et contenant de la Compliance, in 🕴️M.-A. Frison-Roche (ed.), 📕Les outils de la Compliance

► Full Reference: M.-A. Frison-Roche, "La formation : contenu et contenant de la Compliance" ("Training: content and container of Compliance"), in M.-A. Frison-Roche (ed.), Les outils de la Compliance, coll. "Régulations & Compliance", Journal of Regulation & Compliance (JoRC) and Dalloz, 2021, pp.. 227-244. - 📝read the article (in French) -   🚧read the bilingual Working Paper which is the basis of this article, with additional developments, technical references and hyperlinks - 📕read a general presentation of the book, Les outils de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation and Compliance): Firstly, as Training is a specific Compliance tool, it is supervised by Regulators. It becomes mandatory when it is contained in Compliance programs or sanction decisions. Since effectiveness and efficiency are legal requirements, what is the margin of companies to design them and how to measure the result? Secondly, as long as each Compliance tool includes, more and more, an educational dimension, we can take each of them to identify this perspective. So even condemnations and prescriptions are so many lessons, lessons given, lessons to be followed. The question is then to know who, in this so pedagogical Compliance Law, are the "teachers"? -

Articles in The Journal of Regulation & Compliance « JoRC »

When Facebook “Invite” Each Internet User to Act Against COVID-19 by Redirecting Him or Her Towards Public Information Center, Is It by Legal Obligation (Compliance) or by Corporate Social Responsibility? With Which Consequences?

Without any request, on his or her newsfeed, those who surfs on the social network built by Facebook, has found on 23 of March 2020, in the morning, the following message : « X (prénom de l'internaute), agissez maintenant pour ralentir la propagation du coronavirus (COVID-19) Retrouvez les actualités des autorités sanitaires et institutions publiques, des conseils pour ralentir la propagation du coronavirus et des ressources pour vous et vos proches dans le Centre d’information sur le coronavirus (COVID-19)" ("X (user's name), act now to slow down the spread of the Coronavirus (COVID-19). Find the health authorities and public institutions' news, advices to slow down the spread of the Coronavirus for you and your entourage in the Information Center about Coronavirus (COVID-19) »). This corresponds to the more general declaration done the same day by Kang-Xing Jin, director of Health at Facebook, who declares : "In response to the coronavirus outbreak, Facebook is supporting the global public health community’s work to keep people safe and informed. Since the World Health Organization declared the coronavirus a public health emergency in January, we’ve taken steps to make sure everyone has access to accurate information, stop misinformation and harmful content, and support global health experts, local governments, businesses and communities.". Thanks, Facebook to indicate how to do ; by the way, thanks to having invited me to do it. By the way, is it really an « invitation » ? Since the expression is « act now ». Just miss the exclamation point, and the pointed finger of Uncle Sam for « war effort ». If in Law, we can consider « invitation », it would be not to the "invitation" that in the past Bank of France did to shareholders banks to refinance a bank which risks to be soon into difficulties that we could consider, invitation from which the invited cannot really escape. No, obviously no, it is just the same message that you and me can write on our Facebook pages to tell similar things about the same purpose ! But, Facebook would be, like you and me, editor of contents ? Questions and difficulties which encourage to proceed to the legal analysis to know under which title Facebook posted such a message. The first hypothesis is that this firm has acted spontaneously, following its « Corporate Social Responsibility » (I) If it is the right qualification, with regards to the content of the message, legal consequences are important because this firm, without generalizing to others, by the expression of its care of common good, shows, by transitivity, that it is an editor. The second hypothesis starts from the observation that Facebook is a « crucial digital operator ». In this perspective, the firm is constraint to Compliance Law (II). It is the reason why, it is constraint by specific obligations, that excludes the spontaneous message emission qualification. If it is the right qualification, with regards to the content of the message, legal consequences are also important and of a totally different nature. Indeed, the qualification leads to develop the relation between the obligation to fight against fake news and malicious websites towards those of redirecting towards public websites, benefiting for the operator of a reliability presumption. Read the developments below.

Articles in The Journal of Regulation & Compliance « JoRC »

The Government itself collects personal data on social networks, without the consent of the parties concerned, but for a good cause: the fight against tax fraud. What should we think about it legally?

The Finance Bill has proposed to the Parliament to vote an article 57 whose title is: Possibilité pour les administrations fiscales et douanières de collecter et exploiter les données rendues publiques sur les sites internet des réseaux sociaux et des opérateurs de plateformes (translation: Possibility for the tax and customs administrations to collect and exploit the data made public on the websites of social networks and platform operators). Its content is as is in the text voted on in the National Assembly as follows: "(1) I. – On an experimental basis and for a period of three years, for the purposes of investigating the offenses mentioned in b and c of 1 of article 1728, in articles 1729, 1791, 1791 ter, in 3 °, 8 ° and 10 ° of article 1810 of the general tax code, as well as articles 411, 412, 414, 414-2 and 415 of the customs code, the tax administration and the customs administration and indirect rights may, each as far as it is concerned, collect and exploit by means of computerized and automated processing using no facial recognition system, freely accessible content published on the internet by the users of the online platform operators mentioned in 2 ° of I of article L. 111-7 of the consumer code. (2) The processing operations mentioned in the first paragraph are carried out by agents specially authorized for this purpose by the tax and customs authorities.   (3) When they are likely to contribute to the detection of the offenses mentioned in the first paragraph, the data collected are kept for a maximum period of one year from their collection and are destroyed at the end of this period. However, when used within the framework of criminal, tax or customs proceedings, this data may be kept until the end of the proceedings. (4) The other data are destroyed within a maximum period of thirty days from their collection. (5) The right of access to the information collected is exercised with the assignment service of the agents authorized to carry out the processing mentioned in the second paragraph under the conditions provided for by article 42 of law n ° 78-17 of January 6, 1978 relating to data processing, the files and freedoms. (6) The right to object, provided for in article 38 of the same law, does not apply to the processing operations mentioned in the second paragraph. (7) The terms of application of this I are set by decree of the Council of State. (8) II. – The experiment provided for in I is the subject of an evaluation, the results of which are forwarded to Parliament as well as to the National Commission for Data Protection at the latest six months before its end. "   This initiative provoked many comments, rather reserved, even after the explanations given by the Minister of Budget to the National Assembly. What to think of it legally? Because the situation is quite simple, that is why it is difficult: on the one hand, the State will collect personal information without the authorization of the persons concerned, which is contrary to the very object of the law of 1978 , which results in full disapproval; on the other hand, the administration obtains the information to prosecute tax and customs offenses, which materializes the general interest itself. So what about it? Read below.

Articles in The Journal of Regulation & Compliance « JoRC »

probationary lesson of the decision of 4 July 2019 of the Sanctions Commission of the French Anti-Corruption Agency: the President of the Agency, a prosecuting body only bears the burden of allegation and the company must prove the execution of its Compliance obligation, presumed if it complies with the recommendations of the Agency

Compliance Law, like Regulatory Law, of which it is an extension, is an Ex Ante Law. It translates into a set of obligations that companies must perform to ensure that harmful behavior does not occur, such as bribery, money laundering, pollution, etc. This results in "structural" obligations, such as the establishment of a risk map, a third-party vigilance system, internal controls, the adoption of codes. The practical question that arises is whether to punish a company, it is necessary but it is sufficient that the company has not adopted these structural measures, or if it is also necessary that within it or through the persons whom it must be accountable (through the corporate officers and the employees, but also the suppliers, the sub-contractors, the financed operators, etc.) there were behaviors that Compliance Law prohibits, for example corruption, money laundering, pollution, safety-related accident, etc. The question is probative. Its practical stake is considerable. Because to obtain the conviction the prosecuting authority will have to demonstrate not only a failure in the structural device but also a behavioral failure. Si l'on considère que le Droit de la Compliance est à la fois sur l'Ex Ante et sur l'Ex Post, alors l'autorité de poursuite qui requiert une sanction doit démontrer qu'il y a un comportement reprochable (Ex Post) et qu'à cela correspond une défaillance structurelle (par exemple le compte bancaire anormal n'a pas été signalé) ; si l'on considère que le Droit de la Compliance est purement en Ex Ante, alors même s'il n'y a pas de comportement reprochable en Ex Post, la seule défaillance structurelle suffit pour que l'entreprise qui doit l'organiser en son sein soit sanctionné. If we consider that Compliance Law is both on the Ex Ante and the Ex Post, then the prosecuting authority that requires a sanction must show that there is a reprehensible behavior (Ex Post ) and that this corresponds to a structural failure (for example the abnormal bank account has not been reported); if we consider that Compliance Law is purely Ex Ante, then even if there is no reprehensible behavior in Ex Post, the only structural failure is enough for the company to be sanctioned, even if it does its best efforts, even if no prohibited behavior will have accured in Ex Post.   The second system, which is much more repressive and places a considerable burden on companies, even if there is no proven illicit behavior, is that of French Law, probably because of a tendency towards Ex Ante organization. .. Mais il faut garder mesure. Et cette mesure est probatoire. But we must keep measure. And this measure is probative. This is what the Commission des Sanctions of the Agence Française Anticorruption -AFA (French Anti-Corruption Agency's Sanctions Committee) has just said, in its decision of 4 July 2019, SAS S. et Madame C.,(written in French) contradicting the position of its director, who acted as the prosecuting authority. This is yet another general proof of the autonomy of the Sanctions Committee vis-à-vis to the Administrative Authority of which it is a part, and in relation to its director, who nevertheless governs it. But, jurisdictional model obliges, he has here the status of prosecuting authority, is subject to the regime of this one and not to the regime of head of the entity. Demonstration of the "functional autonomy" of the sanctioning bodies within the administrative regulatory and compliance authorities. Indeed, this important decision expresses with precision and reason the distribution of the "burden of the allegation" and the "burden of proof" on the prosecuting body and on the company pursued, as well as the role of presumption that the recommendations issued by the French Anti-corruption Authority can play. Read the analysis below.  

Articles in The Journal of Regulation & Compliance « JoRC »

THE TRANSFORMATION OF COMPETITION LAW INTO EX ANTE COMPLIANCE LAW: THE AMAZON CONSTRAINT AGREEMENT IMPOSED BY THE BUNDESKARTELLAMT ON 17 JULY 2019

Digital technology is not only a new world: it has transformed the world (see a demonstration in this sense, Frison-Roche, MA, The contribution of Compliance Law in Internet governance, report to the French Government, July 2019 ) .. Thus, one should not always put in the same basket even if the expression is euphonic "GAFAM". While some companies offer only intangible services, such as Facebook or Google, namely putting in contact, others have material activities. Amazon ensures the delivery of material objects, of which it provides storage for example, while Uber takes care of the transport of people. Admittedly, this company denies this meeting and ensures that it deals only with the connection, but Law has requalified its activity, which is indeed of a material nature. It is therefore difficult to find a unity in these companies, apart from the fact that they are American, that their power seems as sudden as it is unmatched, their global deployment and that they appear "indispensable" to billions of individuals. . Because many sellers consider that they can only reach potential buyers digitally, that the main market maker is Amazon, that the latter has enacted terms of sale that deprive these sellers numerous protections, the Germain Competition Authority, the Bundeskartellamt,  opened on November 28, 2018 an abuse of a dominant position against Amazon. The act taken by the Bundeskartellamt on July 17, 2019 with regard to Amazon and with the "Amazon agreement", in exchange for which the procedure initiated for a possible sanction of a possible abuse of a dominant position has stopped . Ex Post competition law is exchanged for a Compliance program that goes beyond the powers of a competition authority and the territorial scope of the latter. This does not pose a problem, since it is the “acceptance” that the company makes of it that gives rise to the binding effect and no longer the law which mandated the Competition Authority. This is an example of the remarkable transformation of Competition Law, which goes far beyond the digital issue. In 6 months, the lawsuit turns into an agreement. Which appears as a diktat of the Authority, bearing on the future, obliging in particular a different procedural behavior.   Read the analysis below.

Articles in The Journal of Regulation & Compliance « JoRC »

COMPLIANCE: COLLABORATE FULLY, A LITTLE, OR NOT AT ALL? DAIMLER’S CHOICE: NOT AT ALL

 It is often observed, even theorized, even advised and touted, that Compliance is a mechanism by which public authorities internalize political (eg environmental) concerns in big companies, which accept them, in Ex Ante, because they are rather in agreement with these "monumental goals" (eg saving the planet) and that this shared virtue is beneficial to their reputation. It is observed that this could be the most successful way in new configurations, such as digital. But, and the Compliance Mechanism has often been brought closer to the contractual mechanism, this is only relevant if both parties are willing to do so. This is technically true, for example for the Deferred Prosecution, which requires explicit consent. This is true in a more general sense that the company wants to choose itself how to structure its organization to achieve the goals politically pursued by the State. Conversely, the compliance mechanisms work if the State is willing to admit the economic logic of the global private players and / or, if there are possible breaches, not to pursue its investigations and close the file it has opened, at a price more or less high. But just say No. As in contractual matters, the first freedom is negative and depends on the ability to say No. The State can do it. But the company can do it too. And Daimler just said No. -   Publicly, including through an article in the Wall Street Journal of June 28, 2019. The company sets out in a warning to the market that it is the object of a requirement on the part of the German Motor Authority (Kraftfahrt-Bundesamt)  of an allegation of fraud, by the installation of a software, aimed at misleading instruments for measuring emissions of greenhouse gases on cars using diesel. It is therefore an environmental compliance mechanism that would have been intentionally countered. On this allegation, the Regulator both warns the company of what it considers to be a fact, ie compliance fraud, and attaches it to an immediate measure, namely the removal of the circulation of 42,000 vehicles sold or proposed by Daimler with such a device. And the firm answers : "No". -   Which is probably only beginning, since a No ends the dialogue of Ex Ante to project in the Ex Post sanction procedures, calls 6 observations:   1. No doubt Daimler, a German car manufacturing company, has it in mind in this allegation of fraud calculating pollution of its diesel cars what happened to his competitor Volkswagen: namely a multi-billion dollar fine, for lack of compliance in a similar hypothesis (so-called dieselgate). The strategic choice that is then made depends on education through the experience of the company, which benefits as such from a previous case that has had a very significant cost. Thus educated, the question is to measure the risk taken to refuse any cooperation, when the company can anticipate that it will still result in such an amount ….   2. In addition, we find the difficulty of the distinction of Ex Ante and Ex Post. Indeed, saying No will involve for the company a cost of confrontation with the Regulator, then the peripheral jurisdictions or review courts. But in Germany, the Government itself, concerning a bank threatened with compliance proceedings and almost summoned by the US regulator to pay "of its own free will" a transactional fine, felt that this was not normal, because it must be the judges who punish, after a contradictory procedure with due process and after established facts.    3.  However, this is only an allegation, of probable assertions, of what legally allows to continue, but which does not allow to condemn. The confusion between the burden of proof, which presupposes the obligation to prove the facts before being able to sanction, and the burden of the allegation, which only supposes to articulate plausibility before being able to prosecute, is very damaging, particularly if we are committed to the principles of Repressive Law, such as the presumption of innocence and the due process. This distinction between these two probationary charges is at the heart of the probatory system in the Compliance Law. Because Compliance Law always looks for more efficiency, tends to go from the first to the second, to give the Regulator more power, since businesses are so powerful ….   4. But the first question then arises: what is the nature no so much of the future measure to be feared, namely a sanction that could be taken later, against Daimler, if the breach is proven, or which will not be applied to the firm if the breach is not established; but what is the nature of the measure immediately taken, namely the return of 42,000 vehicles?   This may seem like an Ex Ante measurement. Indeed, the Compliance assumes non-polluting cars. The Regulator may have indications that these cars are polluting and that the manufacturer has not made the necessary arrangements for them to be less polluting (Compliance) or even organized so that this failure is not detected ( Compliance fraud).   This allegation suggests that there is a risk that thiese cars will polluting. They must immediately be removed from circulation for the quality of the environment. Here and now. The question of sanctions will arise after that, having its procedural apparatus of guarantees for the company that will be pursued. But see the situation on the side of the company: having to withdraw 42,000 vehicles from the market is a great damage and what is often called in Repressive Law a "security measure" taken while the evidence is not yet met could deserve a requalification in sanction. Jurisprudence is both abundant and nuanced on this issue of qualification.   5. So to withdraw these cars, it is for the company to admit that it is guilty, to increase itself the punishment. And if at this game, taken from the "cost-benefit", as much for the company immediately assert to the market that this requirement of Regulation is unfounded in Law, that the alleged facts are not exacts, and that all this the judges will decide. It is sure at all whether these statements by the company are true or false, but before a Tribunal no one thinks they are true prima facie, they are only allegations.  And before a Court, a Regulator appears to have to bear a burden of proof in so far as he has to defend the order he has issued, to prove the breach which he asserts exists, which justifies the exercise he made of his powers. The fact that he exercises his power for the general interest and impartially does not diminish this burden of proof.   6. By saying "No", Daimler wants to recover this classic Law, often set aside by Compliance Law, classic Law based on burden of proof, means of proof, and prohibition of punitive measures – except imminent and future imminente and very serious damages  – before 'behavior could be sanctioned following a sanction procedure. Admittedly, one would be tempted to make an analogy with the current situation of Boeing whose aircraft are grounded by the Regulator in that he considers that they do not meet the conditions of safety, which the aircraft manufacturer denies , Ex Ante measurement that resembles the retraction measure of the market that constitutes the recall request of cars here operated. But the analogy does not work on two points. Firstly, flight activity is a regulated activity that can only be exercised with the Ex Ante authorization of several Regulators, which is not the case for offering to sell cars or to drive with. This is where Regulatory Law and Compliance Law, which often come together, here stand out.Secundly, the very possibility that planes of which it is not excluded that they are not sure is enough, as a precaution, to prohibit their shift. Here (about the cars and the measure of the pollution by them), it is not the safety of the person that is at stake, and probably not even the overall goal of the environment, but the fraud with respect to the obligation to obey Compliance. Why force the withdrawal of 42,000 vehicles? If not to punish? In an exemplary way, to remind in advance and all that it costs not to obey the Compliance? And there, the company says: "I want a judge".   ​ -  

Articles in The Journal of Regulation & Compliance « JoRC »

On June 21, 2019, for the sole purpose of combating money laundering and terrorist financing, the FATF publishes a comprehensive system of supervision of ” =crypto-products” platforms

In what it presents as a set of guidelines designed by a risk-driven approach, the FATF published on 21 June 2019 recommendating to fight the use of crypto-assets and cryptocurrency platforms for launderind money and financing terrorism. This fight against money laundering is (with the fight against corruption) often presented as the core of the Compliance Law. The FATF takes a large part of it. Even if this new branch of Law aims to crystallize other ambitions, such as the fight against tax fraud or climate change, or even the promotion of diversity or education and the preservation of democratie, the legislation of Compliance Law are mature in the matter of money laundering and the terrorism financing, as they are in the fight against corruption. The news comes then not from the new legal mechanisms but rather from the new technological tools that could allow the realization of the behaviors against which these obligations of compliance have been inserted in the legal system. It is then to these technologies that the law must adapt. This is the case with crypto-assets and cryptocurrency platforms. Because these are rapidly evolving technologies, with the exercise of written guidelines in 2019 to inform the meaning of the provisions adopted in 2018, the FATF is taking the opportunity to change the definition it provides of crypto-assets and cryptocurrencies. So that a too narrow definition by the texts does not allow the operators to escape the supervision (phenomenon of "hole in the racket" – loophole)..     -   In fact, in October 2018, the FATC (Financial Action Task Force) developed 15 principles applying to these platforms, to allow this intergovernmental organization to carry out its general mission to combat money laundering and the financing of terrorism. These June 2019 recommendations are to interpret them.   In this very important document, where it is expressly stated that it is a matter of fixing the obligations of those who propose crypto-assets and crypto-currencies, the notion of self-regulation is rejected. Il est writter : "Regarding VASP (virtual assets services providers) supervision, the Guidance makes clear that only competent authorities can act as VASP supervisory or monitoring bodies1souligné par nous, and not self-regulatory bodies. They should conduct risk-based supervision or monitoring, with adequate powers, including the power to conduct inspections, compel the production of information and impose sanctions. There is a specific focus on the importance of international co-operation between supervisors, given the cross-border nature of VASPs’ activities and provision of services." On the contrary, it is a matter of elaborating the control obligations that these service providers must exercise over products and their customers (Due Diligences), which must be supervised by public authorities.  In order to exercise this supervision and monitoring, the national authorities themselves must ensure that they work together : "As the Virtual Assets Services Providers (VASP) sector evolves, countries should consider examining the relationship between AML/CF (Anti-Money Laundering and Counter Terrorist Financint) measures for covered VA activities and other regulatory and supervisory measures (e.g., consumer protection, prudential safety and soundness, network IT security, tax, etc.), as the measures taken in other fields may affect the ML/TF risks. In this regard, countries should consider undertaking short- and longer-term policy work to develop comprehensive regulatory and supervisory frameworks for covered VA activities and VASPs (as well as other obliged entities operating in the VA space) as widespread adoption of VAs continues". After particularly interesting comparative law information on Italy, the Scandinavian countries and the United States, the report concludes: "International Co-operation is Key", because of the global nature of this activity.   Since the issue is not the global Regulation of these platforms and types of products, but only the possible modes of money laundering and terrorist financing to which they may give rise, the FATF recalls that neither crypto-products nor product suppliers are not referred to as such. As the guidance's title recalls, common to the 2018 document adopting the 15 principles and this interpretive document, these are "risk-based" rules. Thus, it is according to the situations that these – products and suppliers – that they may or may not present risks of laundering and financing of terrorism: depending on the type of transaction, the type of client, the type of country, etc. For example, from the moment that the transaction is anonymous, that is impossible to know the "beneficiary", or that it is transnational and instantaneous, which makes it difficult to supervise because of the heterogeneity of national supervisions little articulated between them. In reports that public supervisors must have with crypto-product suppliers, they must adjust according to the level of risk presented by them, higher or lower: "Adjusting the type of AML/CFT supervision or monitoring: supervisors should employ both offsite and onsite access to all relevant risk and compliance information.However, to the extent permitted by their regime, supervisors can determine the correct mix of offsite and onsite supervision or monitoring of Virtual Assets Services Providers (VASPs). Offsite supervision alone may not be appropriate in higher risk situations. However, where supervisory findings in previous examinations (either offsite or onsite) suggest a low risk for ML/TF, resources can be allocated to focus on higher risk VASPs. In that case, lower risk VASPs could be supervised offsite, for example through transaction analysis and questionnaires". This "adjustment" required does not prevent a very broad conception of the power of supervision. So, for nothing escapes the recommendations (and in particular the obligations that ensue for the suppliers of these products), the definition of the crypo-assets and crypo-currencies is this one: “Virtual asset” as a digital representation of value that can be digitally traded or transferred and can be used for payment or investment purposes. Virtual assets do not include digital representations of fiat currencies, securities, and other financial assets that are already covered elsewhere in the FATF Recommendations." And for the same reason of effectiveness is posited the principle of technological neutrality: "Whether a natural or legal person engaged in Virtual Assets (VA) activities is a Virtual Asset Services Provider (VASP) depends on how the person uses the VA and for whose benefit. As emphasized above, …  then they are a VASP, regardless of what technology they use to conduct the covered VA activities. Moreover, they are a VASP, whether they use a decentralized or centralized platform, smart contract, or some other mechanism.". The interpretative guidelines then formulate the obligations that these platforms have with regard to the supervisors they obey(question of the "jurisdiction", ratione loci ; ratione materiae): " The Guidance explains how these obligations should be fulfilled in a VA context and provides clarifications regarding the specific requirements applicable regarding the USD/EUR 1 000 threshold for virtual assets occasional transactions, above which VASPs must conduct customer due diligence (Recommendation 10); and the obligation to obtain, hold, and transmit required originator and beneficiary information, immediately and securely, when conducting VA transfers (Recommendation 16). As the guidance makes clear, relevant authorities should co-ordinate to ensure this can be done in a way that is compatible with national data protection and privacy rules. ". These platforms are not uniformly defined due to the diversity of their activities. Because it is their activity that makes them responsible for this or that regulator. For example from the Central Bank or the Financial Regulator: "For example, a number of online platforms that provide a mechanism for trading assets, including VAs offered and sold in ICOs, may meet the definition of an exchange and/or a security-related entity dealing in VAs that are “securities” under various jurisdictions’ national legal frameworks. Other jurisdictions may have a different approach which may include payment tokens. The relevant competent authorities in jurisdictions should therefore strive to apply a functional approach that takes into account the relevant facts and circumstances of the platform, assets, and activity involved, among other factors, in determining whether the entity meets the definition of an “exchange”2Underlined by us. or other obliged entity (such as a securities-related entity) under their national legal framework and whether an entity falls within a particular definition. In reaching a determination, countries and competent authorities should consider the activities and functions that the entity in question performs, regardless of the technology associated with the activity or used by the entity".   - Reading this very important document, it is possible to make 6 observations:  1. Interpretative documents are often more important than rules interpretated themselves. En these guidances, first and foremost, these are major obligations that are stated, not only for platforms but also for national laws, and well beyond the issue of money laundering. So, it is laid: "Countries should designate one or more authorities that have responsibility for licensing and/or registering VASPs. …  at a minimum, VASPs should be required to be licensed or registered in the jurisdiction(s) where they are created. ".This is a general prescription, involving a general regulation of these platform, which registered in a general way, will probably be supervised in a general way. Secondly, it is a series of binding measures that is required of the National legal systems, for example the possibility of seizing crypto-values. It shows that the soft Law illustrates the continuum of the texts, and allows their evolution. Here the evolution of the definition of the object itself: the definition of crypto-assets and crypto-currencies is widened, so that the techniques of money laundering and terrorist financing are always countered, without it being necessary to adopt new binding rules. We are beyond mere interpretation. And even more of the principle of restrictive interpretation, classically attached to the Repressive Law … 2. Fort the effectiveness of the Compliance Law, definition become extremely broad. Thus, to follow the FATF, the definititon off a financial institution is as follows: "“Financial institution” as any natural or legal person who conducts as a business one or more of several specified activities or operations for or on behalf of a customer". This is more the definition of a company in Competition Law3Plus loin, le texte donne une définition plus détaillée : "When determining whether a specific activity or entity falls within the scope of the definition and is therefore subject to regulation, countries should consider the wide range of various VA services or business models that exist in the VA ecosystem and, in particular, consider their functionality or the financial activities that they facilitate in the context of the covered VA activities (i.e., items (i) through (v) described in the VASP definition above). Further, countries should consider whether the activities involve a natural or legal person that conducts as a business the five functional activities described for or on behalf of another natural or legal person, both of which are essential elements to the definition and the latter of which implies a certain level of “custody” or “control” of the virtual asset, or “ability to actively facilitate the financial activity” on the part of the natural or legal person that conducts the business for a customer."….Why ? Because otherwise, an operator finds a status allowing him to escape the category and obligations listed. The principle of efficiency implies it. The principle of "legality", derived from criminal law, has hardly any existence. But this also corresponds to the general evolution of the financial world, in which one no longer stars from the organ (for example to be a"bank") but of activity, but from an activity or a fonction whose metamorphoses are so rapid that it is almost impossible to define them …. 3. In the same way, the definition of crypto-assets or crypto-currencies: "“Virtual asset” as a digital representation of value that can be digitally traded or transferred and can be used for payment or investment purposes. Virtual assets do not include digital representations of fiat currencies, securities, and other financial assets that are already covered elsewhere in the FATF Recommendations". This definition is purely operational because nothing can escape the FATF: all that is financial or monetary, whatever its form or support, its traditional form or a form that will be invented tomorrow, is within its competence and, through a such definition, is under national supervisors. In Compliance Law, and since everything is based on risk analysis, the idea is simple: nothing must escape obligations and supervision. 4. Platform apprehension is done by the criterion of activity, according to the "functional" method. Thus, its supervision, or even its regulation, and its obligations of compliance, will apply, depending on what it does, to the Financial Regulator (if it does ICO) or to others if it only uses tokens as an instrument of exchange. If it makes several uses, then it would fall under several Regulators (criterion ratione materiae). 5. The principle of "technological neutrality" is a classic principle in Telecommunications Law. Here we measure the interference between the principles of Telecommunications Law and Financial Law, which is logical because crypto-financial objects are born of digital technology. This neutrality allows both technological innovation to develop and supervision to be unhindered for not having foreseen an innovative technology appearing after the adoption of the legal text. Here again, the effectiveness of Compliance and risk management are served, without the innovation being thwarted, which is often opposed. 6. What is expected of national public authorities is a very wide "interregulation". This is both "positive". Indeed, this includes financial matters but also the security of networks, or the protection of consumers. It can be called equilibrium interregulation in that all goals converge. But this is also an "interregulation" that can be described as balance. Indeed, the FATF is concerned about the protection of personal data. However, it emphasizes that the effectiveness of the Compliance system must stop. But the protection of personal data is also a part of Compliance Law…. This is one of the major challenges in the future: the balance between security and the fight against global evils(here the fight against money laundering and terrorism) and the protection of the privacy of individuals, as both fall under Compliance, but both have opposite legal effects: one the transmission of information, and the other the secret of the information.  -    

Articles in The Journal of Regulation & Compliance « JoRC »

📝Un Droit substantiel de la Compliance, appuyé sur la tradition européenne humaniste, in 🕴️M.-A. Frison-Roche (ed.), 📕Pour une Europe de la Compliance

🌐 follow Marie-Anne Frison-Roche on LinkedIn 🌐 subscribe to the Newsletter MAFR Regulation, Compliance, Law - ► Full Reference: M.-A. Frison-Roche, "Un Droit substantiel de la Compliance, appuyé sur la tradition européenne humaniste" ("A substantive Compliance Law, based on the European humanist tradition"), in M.-A. Frison-Roche (ed.), Pour une Europe de la Compliance, series "Régulations & Compliance", Dalloz, 2019, pp. 13-35. - 📝read the article (in French) - 🚧read the bilingual Working Paper which is the basis of this article, with additional developments, technical references and hyperlinks - 📕read a general presentation of the book, Pour une Europe de la Compliance, in which this article is published - ► Summary of the article (done by the Journal of Regulation & Compliance): L'on présente souvent la Compliance comme un ensemble lourd, coûteux et incompréhensible de process, ensemble vide de sens, tandis que l'on ressent l'Europe comme un projet dont l'achèvement serait sans espoir ; alors mêler les deux … Et pourtant ! Pour que Compliance et Europe s'adossent l'une à l'autre dans une construction commune, il faut tout d'abord que l'Europe cesse d'être "en défense" n'appréhendant la Compliance que d'une façon "réactive", ne mettant son talent au mieux que pour la recopier au pire que pour la rejeter (I). L'Europe a d'autant plus de mal à faire autre chose que le Droit de la Compliance étant le prolongement du Droit de la Régulation, c'est secteur par secteur, but particulier par but particulier que le Droit de la Compliance lui apparaît, la seule unité étant la forme, procédure Ex Ante des obligations structurelles ou procédure Ex Post des sanctions. Dans ce vide de sens d'une Compliance qui ne serait qu'une méthode et rien de plus, l'Europe n'est alors qu'un réceptacle récalcitrant…. Mais si l'on voit au-delà des secteurs, comme y invite le Droit européen des données désormais fortement constitué sur le Droit de la Compliance pour protéger les données sensibles sans méconnaître le principe de circulation des données, données sensibles dont les données personnelles ne sont qu'une variété, l'on mesure que la référence au secteur s'efface. Un Droit substantiel de la Compliance peut alors se construire au regard des impératifs européens qui ont toujours été la protection de la personne (II). Se détachant de la régulation sectorielle, il apparaît alors plusieurs buts de compliance, appelant plusieurs formes de contrainte et plusieurs portées des mécanismes de Compliance. Si le but est la prévention de risque de catastrophes systémiques, comme le sont les défaillances bancaires, l'éclatement des bulles financières, la mise en circulation d'informations inexactes dévastatrices ou le développement de maladies contagieuses, alors le Droit de la Compliance doit se constituer sans frontière, le coeur en est la gestion des informations, leur recueil et leur transmission à ceux qui les manient au mieux au regard des risques car la protection du système global le requiert et l'Europe y prend sa part. Mais dans les autres cas, la protection de la personne ne requiert pas cela car elle ne croise pas l'hypothèse de contamination de système. Or, l'Europe a inventé la notion juridique de "personne", idée qui recouvre tout être humain, sa vie, sa liberté et ses secrets. L'action immédiate et la transparence n'y sont plus requises de la même façon. Il convient alors, comme l'a fait le Droit européen à propos des données, d'organiser à la fois la circulation et la garde des secrets, en déterminant celui qui est le mieux placé pour le faire. Le Droit de la Compliance pose que c'est toujours l'entreprise qui est la mieux placée pour le faire, mais soit pour ne pas utiliser l'information, soit pour transmettre l'information suivant les buts du Droit de la Compliance, soit sans interférence de l'Etat soit sous la tutelle de l'Etat et c'est toujours l'Autorité publique qui formule les buts. Plus encore, l'Europe peut prétendre qu'un marché n'est un espace vivable que s'il met en son centre l'être humain, qui n'est pas qu'un outil, cette conception humaniste permettant d'exiger des autres le respect de normes à propos desquelles l'Europe est exemplaire à travers ses entreprises et peut prétendre l'exiger à propos des entreprises qui entrent sur son espace, soit directement, soit à travers leurs produits.  -