Bank

Articles

Responding to an email with “serious anomalies”​,transferring personal data, blocks reimbursement by the bank: French Cour de cassation, July 1st 2020

Full reference: Frison-Roche, M.-A., Responding to an email with "serious anomalies"​,transferring personal data, blocks reimbursement by the bank: French Cour de cassation, July 1st 2020, Newsletter MAFR – Law, Compliance, Regulation, 10th of September 2020 Read by freely subscribing other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news "Phishing" is a kind of cyber criminality aiming to obtain, by sending fraudulent emails which look like to those sent by legitimate organisms, recipient's personal information in order to impersonate or steal him or her. As it is difficult to find the authors of "phishing" and to prove their intentionality in order to punish them directly, on mean to fight against "phishing" could be to entitle banks to secure their information network and, to accompany this obligation with a strong incentive, to convict them to reimburse the victims in case of robbery of their personal data.   In 2015, a client victime of this kind of fraud asked to his bank, the Crédit Mutuel, to reimburse him the amount stole, what the bank refused to do on the grounds that the client committed a fault, transferring its confidential information without checking the email, however grossly counterfeit. The Court of first instance gave reason to the client because although he committed this fault, he was in good faith. This judgment was broken by the Chambre commerciale de la Cour de cassation (French Judicial Supreme Court) by a decision of 1st of July 2020 which states that this serious negligence, exclusive of any consideration of good faith, justifies the absence of reimbursement by the bank. -   From this particular case, we can draw three lessons:  The Cour de Cassation states that good faith is not a salient criterion and that, as the bank must react when a banking account is objectively abnormal, the client must react face to an obviously abnormal email.  The Cour de Cassation describes the repartition of proof burden. Proof obligations are alternatively distributed between the bank and its client. First, the bank must secure its information network but, secondly, the client must take every reasonable measure to preserve its safety. It results from this that, if the email seems normal, phishing damages must be supported by the bank, and more generally of by the firm, while if the email is obviously abnormal, they must be supported by the client, but the burden to prove the abnormality of the email must be supported by the firm and not by the client.  Such a proof system shows that Compliance Law includes a pedagogic mission by educating each client in order to he or she would be able to distinguish among his or her emails, those which are normal and those which are obviously suspect. This pedagogic dimension, with the legal consequences associated to it, will not stop to spread.    -

Articles

Conflict of interests & “revolving doors”​:what the European Ombudsman said in May 2020, the European Banking Authority agreed in August.Three lessons

Full reference: Frison-Roche, M.-A., Conflict of interests & "revolving doors"​: what the European Ombudsman said in May 2020, the European Banking Authority agreed in August.Three lessons, Newsletter MAFR – Law, Compliance, Regulation, 7th of September 2020 Read by freely subscribing other news of the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news:  Supervision and regulation authorities' impartiality and independence are conditioned to the fact that their members do not have any conflict of interest with the sector that they supervise or regulate. Such an absence of conflict of interest is necessary to guarantee a climate of trust between the authority and operators. This supposes that regulation and supervision authority members do not cumulate functions of operator and of regulator/supervision during but also after their mandate in the regulation/supervision authority because the anticipation of a future hiring can influence present decisions.  On 2nd of August 2019, the executive director of the European Banking Authority (EBA) informed the authority of its willingness to become PDG of the Association des marchés financiers en Europe, lobby of the financial sector. EBA approved this perspective. However, "Change Finance", a civil coalition, sized the European Mediator explaining that such a professional reorientation created an inevitable conflict of interest. The European Mediator reacted on 7th of May 2020 through a recommendation saying that although EBA took preventive measures, theses measures are not sufficient with regard to the risks. In this recommendation, the European Mediator also made some general propositions to manage future conflicts of interest: The interdiction for senior managers to have positions able to create a conflict of interest for two years. The information of senior managers and candidates to senior managers positions of the actual rules. The implementation of internal procedures blocking access to confidential information to the member who notified its willingness to occupy later a position able to constitute a conflict of interest with its current position.  In a letter of 28th of August 2020, the president of EBA told to the European Mediator that he accepts these remarks and propositions.  In this particular case, we can draw three lessons: The difficult articulation between independence/impartiality (necessary for trust) and regulator/supervisor expertise. The European Mediator and the ABE are agree that the interdiction to get some positions must be limited in time. The necessity that everyone can anticipate rules correctly. The necessity to preserve legal security. 

Articles

Why the decision of the French Constitutional Council of 7.08.2020 about authors of terrorist offences is so informative for Compliance & Criminal Law

Full reference: Frison-Roche, M.-A., Why the decision of the French Constitutional Council of 7.08.2020 about authors of terrorist offences is so informative for Compliance & Criminal Law, Newsletter MAFR – Law, Compliance, Regulation, 13th of August 2020 Read, by freely subscribing, the other news in the Newsletter MAFR – Law, Compliance, Regulation    Summary of the news On 7th of August 2020, the Conseil Constitutionnel (French Constitutional Court) made a decision concerning the constitutionality of a French law implementing safety measures against authors of terrorist offenses after their sentence. The law permitting to impose, through an act from the administration, various controls or interdiction to communicate with some people for authors of terrorist offenses after the end of their sanction.   Although the Conseil Constitutionnel estimated that such dispositions was disproportionate with regards to the objective, which prompted it to censor the text, it recognized that, since terrorism seriously disturbs public order through intimidation and terror, the fight against terrorism contributes to the objective of constitutional value consisting of preventing attacks on the public order. Thus it is not the nature but the intensity of the proposed measures which pushed the Conseil Constitutionnel to state this text not constitutional. By the way, the Conseil affirms that if the legislator submits it a law whose the measures are more proportionate to the goal, these, although Ex Ante and justified only by the existence of a risk, will be declared in conformity with the Constitution. The Conseil Constitutionnel confirms here that the fight against terrorism financing is a "monumental goal" of Compliance Law. 

Articles

Against money laundering, what time matters? Does it work, between ExAnte and ExPost? (BIL case)

Full reference: Frison-Roche, M.-A., Against money laundering, what time matters? Does it work, between ExAnte and ExPost? (BIL case), Newsletter MAFR – Law, Compliance, Regulation, 11th of August 2020 Read, by freely subscribing, the other news in the Newsletter MAFR – Law, Compliance, Regulation   Summary of the news The activity of money laundering is detrimental not only in itself but also because it permits the development and the sustainability of other criminal activities such as drug trafficking, weapon trafficking or human beings selling. Fighting against money laundering could permit to indirectly fight against these underlying activities, by the way very difficult to fight. Thus, the fight against money laundering has become a "monumental goal", which justifies the adoption of tools sometimes much more powerful than those used by classical criminal Law. For the sake of efficiency, the legal obligation to prevent money laundering is given to every body able to do it, as banks, real estate agents or gaming society, under the penalty of sanction.  On 10th of August 2020, the Luxembourgish financial market supervisor convicts the International Bank of Luxembourg to pay a fine of 4,5 millions of euros because of weaknesses detected in its process of fight against money laundering. However, when the sanction has been pronounced, the bank had already remedied the weaknesses identified. It is important to observe that what is important for Compliance Law, it is not that a non compliant behavior is punished but rather that the crucial firm modifies its behavior in order to being more efficient in the realization of the "monumental goal", only concern of the public authority. Thus, an Ex Post sanction against the crucial operator is not an end in itself and can be justified only if it permits to incite the crucial operator to act or rather to desincite to do anything. Compliance Law is an Ex Ante legal system.    To go further, read:  Frison-Roche, M.-A., Le couple Ex Ante – Ex Post, justificatif d'un droit spécifique et propre de la Régulation, 2006 (in French)

Videos

The French Council of State (Conseil d’État) confirms the wide and therefore severe application of the sanctions mechanism in the Compliance Law concerning the freezing of assets, by its decision of November 15, 2019, La Banque Postale v. ACPR

Watch the video explaining the content, meaning and scope of the decision made by the Conseil d'État (French Council of State) on November 15, 2019, La Banque Postale v. Autorité de contrôle prudentiel et de résolution (ACPR). The Autorité de contrôle prudentiel et de résolution – ACPR (French Authority of prudential control and resolution) pronounced a very high sanction, representing 7% of La Banque Postale's net annual result. The breach is constituted by the fact of not having prevented the use of the banking technique of the "money order" which was used to escape the freezing of the assets. The Conseil d'État recalls that by nature if the assets are frozen, it is not possible that anyone is able to dispose of these assets. However, by the use of "money orders", persons targeted by asset freezing decisions, tools used in connection with the fight against money laundering and the fight against terrorism, had been able to circulate money to from accounts managed by La Banque Postale, of which they were not customers. This case was not foreseen at the time when the Bank Postale was sanctioned by the ACPR for not having prevented such a use, the texts forcing it under its obligations of "conformity" to prevent this behavior of violation background gels on the part of his customers, but only that. This case of a use of a means by a person who is not a customer of the bank was not foreseen at the time when the alleged facts took place and the Bank claims not to be able to be punished since in the repressive matter it is necessary to respect the principle of non-retroactivity of the texts, – in this case texts later supplemented to aim at such an assumption -, the non-retroactivity being a major principle itself related to the principle of the legality of the offenses and the penalties. We are therefore in the hypothesis of a silence of the texts. What to decide? Can the Bank be condemned and so heavily or not by the ACPR? The Bank does not think so.  It acted against this sanction decision firstly because those who used these money orders were not its clients. It has strong reasons to avail itself of this fact, since subsequently the texts needed to be modified to aim not only the use of this technique of money order by those who have a count in the bank and also by those who act with cash through the bank without a count, that is to say without an account holder to look at. Because we are in criminal matters, the restrictive interpretation and non-retroactivity of the text should lead to follow the reasoning of the Bank. But the Conseil d'État does not because it considers that implicitly but necessarily even with this subsequent modification of the text, it had aimed that use before. By this way, the Conseil d'Étatuncil develops a very broad concept of the obligations of banks in their role in the fight against money laundering, and therefore a very repressive point of view, which permeates their "obligation of Compliance". Thus, when the bank also argues that it can not be sanctioned since for it this activity of money order is  deficit and that it did not cause harm to its customers even by assuming badly its obligations, theConseil d'État stresses that this is not a pertinent perspective since the Compliance obligations falls within the "overriding general interest of protection of public order and public security, to which the freezing of assets legislation responds". -   Read the  judgment of the Conseil d'État ( in French). 

Monographs

📝 Compliance et personnalité

► Full Reference : Frison-Roche, M.-A., Compliance et personnalité, in Recueil Dalloz, n°11/7812, avril 2019, pp. 604-606 -   ► Chronique English Summary: Compliance is often presented as a set of mechanical procedures, in which human beings are absent. It's the opposite. It is an Information Law, in its function of preventing systemic risks and a markets protection Law, which poses the requirement of knowing “truly” the person who is “relevant”, generalizing what Company or Competition Law had partially admitted. Even more, beyond systems, Compliance Law, insofar as it is a Protection Law, aims to protect human beings, directly or indirectly concerned, establishing them as legal persons, true final subjects of law of this new branch of Law. - 📝read the chronique (in French). - 🚧  read the bilingual Working paper, Compliance and Personality, basis of this chronique,    working paper including footnotes, technical references and hyperlink - 📖 read the other chroniques Chronique MAFR Droit de la Compliance -

Publication director

🏗️ direction of the collection: 📚Cours Dalloz – Série Droit privé

📚Publication of : 🕴️Stéphane PIÉDELIÈVRE, 📕Instruments de crédit et de paiement (Credit and Payment Instruments), 10th ed.

► Full Reference : S. Piédelièvre, Instruments de crédit et de paiement (Credit and Payment Instruments), 10th ed., 2018, Dalloz, “Cours Dalloz-Série Droit privé” Series, 450 p. - 📚See the entire collection in which the book is published. -

Articles in a legal collective publication

La société et l’entreprise

Articles in a legal collective publication

Compliance et confiance

Working papers

🚧 Compliance and Trust

Compliance. Trust. Two words that come more and more often than before at our readers' eyes or listeners' ears. And yet they do not seem to match well. They even seem to repel each other. Indeed, Compliance is the way in which Public Authorities trust certain private operators, not in themselves, but with their structural capacities to mechanically capture the information that these authorities need (I). This presupposes a vision of the world in which Companies are powerful and powerful alone but are not virtuous, while Public Authorities, such as the Public Prosecutor's Office or Regulators, are weak but virtuous alone. Such a conception of Compliance transforms companies into automata. Such a vision of the world has no future: only human beings can be trusted, whose fallibility must be accepted, as Compliance is then the expression of a relationship built on trust that is to be seen between non-mechanical operators, namely public Institutions and private Operators, who can both have in common concern for an interest which goes beyond them and which was formerly called the general interest (II). From this reality, no new doubt for private companies, but which explains the strange intimacy between the violent Compliance Law and the new spontaneous order of Corporate Social Responsibility, it is up to them to demonstrate this concern Cf others that it shares with the Public Authorities, except to fall in Compliance reduced to costly procedures, empty endless staked out of sanctions without control. It is thus for Companies to make this branch of Compliance Law emerging become what can be the best, when it is possible that it becomes what would be the worst.