Day 16 of One Month to Better Investigations and Reporting

Day 16 of One Month to Better Investigations and Reporting

Prior to the Schrems decision by the European Court of Justice, US based law firms could rely on Safe Harbor to use and analyze information from investigations conducted in Europe. However the Schrems decision and subsequent EU privacy rulings and regulations have brought the entire issue around internal investigations into question. In a podcast interview with UK solicitor and data privacy expert Jonathan Armstrong about the decision, Armstrong noted that the decision puts real roadblocks in the path of a US company that could be investigating potential anti-corruption allegations in the UK or EU member country. The biggest issue would be around personal privacy and information. Unlike the US, work emails are covered by the privacy rights afforded to individuals and are not the property of the company. The same is true of other information. Under the Schrems decision, the ability of a US corporation to access that information and then take it back to the US under the safe harbor provision is no longer available. I asked Armstrong how a company might be able to move forward and internally investigate potential FCPA violations. Armstrong suggested that that the only way at this point was to obtain the consent of the person being investigated. However the obtaining of such consent raises a host of other problems. He said, “Can I really get consent in an internal investigation? Can I go along, speak to my Austrian agent and say, “Peter, I just need you to sign this form to transfer your data to the US”? Now, for consent to be valid the European legislation it has to be fully explained, it has to be honest, it can't be deceptive. I’ve got to say to him, “I want you to sign this form because I want to investigate you. I want to run a full FCPA investigation; you’re the prime suspect. I want to take a look at your emails and I have to inform you that by the way, you have the right not to consent and if you don’t consent there’s no way I can investigate you. Could you sign the form, please?”” As Armstrong went on to note, “What answer is he likely to give in an internal investigation and how would the US authorities feel if I go and tip off the main suspect that he’s under investigation?” With these two key components of any best practices compliance program, hotlines and internal investigations, seemingly now unavailable to CCOs or compliance practitioners for EU sourced information; I believe there will be additional pressure put on the compliance function. Obviously any US company with EU based operations will have to take steps immediately to ring fence such data originating in Europe. It may also mean that any inquiries will need to be headed by locally based compliance practitioners. Moreover, if you couple this ruling in the Schrems decision with the Yates Memo, you immediately see the issue involved for any company which is seeking cooperation credit because such company is required to turn over any and all information to the Department of Justice (DOJ) as soon as possible. But now, even if companies can still develop facts and data through internal investigations, in the manner suggested by Pirrotta in using local law firms, you might not be able to get the information back to the US to use. Worse yet, is the option laid out by Armstrong to obtain consent from an investigation target? Not only do I find it very improbable that anyone, European or otherwise, would give such a consent but in the unlikely event such consent is given, you have told the target, they are the target and other data sources might well begin to disappear. Armstrong put it starkly when he said, “you’re going to get no sympathy from the bribery prosecutors, bribery regulators if you mess this up. The SFO [Serious Fraud Office] have already lost the case, allegedly, on the way in which the US firm involved conducted the investigation. They will have, rightly I think, no sympathy at all for people whose investigations are themselves conducted unlawfully. It’s going to need a lot of careful thought to structure data transfers, even to structure interviews. How do you move those interview notes about, how do you look at emails, all of this stuff is going to be absolutely critical not only so that you don’t break data privacy data protection laws, but also tipping off witness, you know, interfering with the scene of an investigation, et cetera, et cetera. All of these things are critical.” How does the Schrems decision contribute to compliance at the tipping point? If you can use two of the key components in a best practices compliance program; based upon the DOJ/Securities and Exchange Commission (SEC) Ten Hallmarks of an Effective Compliance Program or another standard; it will put significant pressure on other parts of the program. A compliance program will have to be structured more rigorously to prevent FCPA violations through the use of internal controls and transaction monitoring tools. CCOs and compliance practitioners will also have to be more involved and have more visibility into the entire lifecycle of transactions so they can determine how to begin to move from even prevention to proscription of any FCPA violations. Just as the compliance world changed with the announcement of the Yates Memo, the DOJ Compliance Counsel and the VW emissions-testing scandal; the Schrems decision will change the need for a more robust compliance program going forward to help protect a company. Three Key Takeaways The Schrems decision significantly impacted US based internal investigations. Study the privacy laws of the country where you are performing your investigation. Informed consent is difficult to obtain but it may be critical for your investigation. Learn more about your ad choices. Visit megaphone.fm/adchoices

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(1628)

Natural Disaster Expo Houston: Preparedness, Resilience, and Business-to-Government Networking

Natural Disaster Expo Houston: Preparedness, Resilience, and Business-to-Government Networking

In this episode, Tom Fox welcomes Jack Moss, CEO of Fortem International, about the Natural Disaster Expo series and the upcoming Houston event (October 14–15). Moss explains the expo evolved from a U...

18 Sep 16min

Michelle Tavares on Why Compliance Teams Need EB-5 on Their Radar

Michelle Tavares on Why Compliance Teams Need EB-5 on Their Radar

In this episode, Tom Fox welcomes Michelle Tavares, a former federal government forensic accountant and former USCIS EB-5 compliance officer who helped rewrite the EB-5 statute into the Reform and Int...

14 Sep 25min

9/11 Twenty-Five Years Later: Part 6: John Lee Dumas - “I Knew I Was Going to War”

9/11 Twenty-Five Years Later: Part 6: John Lee Dumas - “I Knew I Was Going to War”

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast series so that we never forget. ...

11 Sep 19min

9/11 Twenty-Five Years Later: Part 5: Scott Moritz – It Changed Overnight

9/11 Twenty-Five Years Later: Part 5: Scott Moritz – It Changed Overnight

Ed. Note: Five years ago, Tom Fox looked back on 9/11 in a 20-year retrospective. This week is the 25th anniversary of that event. We will be rerunning this award-winning podcast so we never forget. ...

10 Sep 23min

9/11 Twenty-Five Years Later: Part 4: Eric Feldman – A Wake Up Call

9/11 Twenty-Five Years Later: Part 4: Eric Feldman – A Wake Up Call

Ed. Note: Five years ago, Tom Fox looked back on 9/11 in a 20-year retrospective. This week is the 25th anniversary of that event. We will be rerunning this award-winning podcast so we never forget. ...

9 Sep 17min

9/11 Twenty-Five Years Later: Part 3: Alex Dill – Patriot Act: The AML Response to Terrorist Threats

9/11 Twenty-Five Years Later: Part 3: Alex Dill – Patriot Act: The AML Response to Terrorist Threats

Ed. Note: Five years ago, Tom Fox looked back on 9/11 in a 20-year retrospective. This week is the 25th anniversary of that event. We will be rerunning this award-winning podcast so we never forget. ...

8 Sep 19min

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

9/11 Twenty-Five Years Later: Part 2: Juan Zarate - The Treasury Department Responds

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

7 Sep 18min

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

9/11 Twenty-Five Years Later: Part 1: Gabe Hidalgo - Needing to Make a Difference

Ed. Note-Five years ago, I looked back on 9/11 in a 20 year retrospective. This week is the 25th anniversary of that event. I am rerunning this award winning podcast so that we never forget. On the ...

6 Sep 20min

Populärt inom Business & ekonomi

framgangspodden
varvet
rss-jossan-nina
rss-borsens-finest
svd-tech-brief
24fragor
avanzapodden
uppgang-och-fall
badfluence
rss-inga-dumma-fragor-om-pengar
lastbilspodden
fill-or-kill
rss-dagen-med-di
rikatillsammans-om-privatekonomi-rikedom-i-livet
rss-kort-lang-analyspodden-fran-di
rss-wallnor-pm
tabberaset
bilar-med-sladd
borsmorgon
kapitalet-en-podd-om-ekonomi