On 7th of August 2020, the Conseil Constitutionnel (French Constitutional Court) made a decision concerning the constitutionality of a French law implementing safety measures against authors of terrorist offenses after their sentence. The law permitting to impose, through an act from the administration, various controls or interdiction to communicate with some people for authors of terrorist offenses after the end of their sanction.
Although the Conseil Constitutionnel estimated that such dispositions was disproportionate with regards to the objective, which prompted it to censor the text, it recognized that, since terrorism seriously disturbs public order through intimidation and terror, the fight against terrorism contributes to the objective of constitutional value consisting of preventing attacks on the public order. Thus it is not the nature but the intensity of the proposed measures which pushed the Conseil Constitutionnel to state this text not constitutional. By the way, the Conseil affirms that if the legislator submits it a law whose the measures are more proportionate to the goal, these, although Ex Ante and justified only by the existence of a risk, will be declared in conformity with the Constitution.
The Conseil Constitutionnel confirms here that the fight against terrorism financing is a "monumental goal" of Compliance Law.
On 31st of July 2020, the Commission de Régulation de l'Energie (CRE and French energy regulator) has examined the investment plan of the French electric network manager (RTE) as it does every year. This investment plan is an economic document but it also contains societal purposes, especially the adaptation of the electric network in order to integrate renewable energies.
The control by the CRE is not a financial control. The crucial operator (RTE) is free to decide the way it wants to manage its budget. The CRE just advices on the financial side by recommending for exemple to be more flexible in its financial strategies. The true CRE's control is about the investment plan's general orientations, the methodology of needs analysis and crucial operator's investment choices which must be aligned with those of the regulator.
Such a control leads to the emergence of an "investment doctrine" from the side of the crucial operator, mixing its own choices and the regulator's guidelines. Beyond this, the elaboration of the investment plan is the result of a true co-writing between the regulator and the firm which discuss together, exchanges points of view and methods. Such a method, expressing a kind of coregulation, could be used in other sectors.
The Financial Crimes Enforcement Network (FinCEN) is an organ, depending on the American Treasury, in charge of fighting against financial criminality and especially against money laundering and terrorism financing. For this, it has large control and sanction powers.
In August 2020, the FinCEN published a document untitled "Statement on Enforcement" which aimed to explicit its control and sanction methods. It reveals what firms risk in case of offense (from the simple warning letter to criminal pursuits passing through financial fines) and the different criteria on which FinCEN is based to use one sanction rather than another. Among these criteria, we find for examples the nature and the seriousness of committed violations or the firm's history but also the implementation of compliance program or the quality and the spread of the cooperation with FinCEN durning the investigation.
One of the objectives of the publication of such an information document is to obtain the cooperation of firms by creating a confidence relationship between the regulator and the regulated firm. However, it is very difficult to ask to the firms to cooperate and to furnish information if they can fear that this same information can be used later as proof against them by the FinCEN.
Another objective is to reinforce legal security and transparency. However, the FinCEN's declaration does not seem to commit it, because it is not presented as a chart but as a simple declaration. Indeed, the list of the possible sanctions and the criteria used by the FinCEN are far from being exhaustive and can be completed in concreto by the FinCEN without any justification.
The French Rail Regulator entrusts a public undertaking, RFF ("Réseau Ferré de France"), the management of the railway infrastructure. It must therefore enter into contracts with the railway undertakings to have rail transportation. European laws provide that these contracts must follow on the one hand, the specific legal provisions, and on the other hand the "network statement ". In addition, framework agreements determine the distribution of the allocation of capacity of the infrastructure between transport undertakings, schedules and prices. The regulator must give a reasoned opinion on these agreements. The notice is only optional, binding neither the State nor the parties. RFF ("Réseau Ferré de France") has developed a project of framework agreement and transmitted it to the autorité française de régulation des activités ferroviaires (ARAF) – (French Rail Regulator). It has chosen to open on 17 April a public consultation, with on its website the project of framework agreement, allowing any stakeholders to express themselves on the duration, pricing, transparency and confidentiality, and also the contractual balance of such an agreement. The consultation will be closed on 4 June and the autorité française de régulation des activités ferroviaires (ARAF) – (French Rail Regulator) will then deliver its opinion.
Season 2 Episode 3 of the British version of the series "Criminals" features the character of Danielle. Danielle is a mother which has decided to hunt down pedophiles on social networks in order to trap them and show to the world their acts. Danielle insists on the efficiency of her action with regard to the police and justice that she finds unproductive. In the episode, Danielle is accused of defamation by the police. While policemen try to explain to Danielle the importance of using a regular procedure and to respect the Rule of Law aiming to prove its accusations, she makes efficiency her only principle. According to her, her methods get results (on the contrary of those used by the police which respect procedures) and those she accuses to be pedophiles do not deserve defense rights.
We can learn three lessons from Danielle's story:
If Compliance Law is just a process of application of mechanical rules, then Rule of Law is not salient face to the principle of efficiency. But, if Compliance Law is defined by its "monumental goals" and that the respect of Rule of Law is erected in "monumental goal", then efficiency and Rule of Law become compatible and congruent.
The digital space must be disciplined by crucial digital firms supervised by public authorities, like in France or Germany for hate speeches and disinformation.
Compliance Law, and Law in general, must be pedagogue towards individuals as Danielle which do not understand why their behaviors are reproachable.
In August 2020, Marriott International, online hotel room booking platform, has be sued before an English court by a consulting firm through a "class action" technic. The firm ask to Marriott International compensates the clients whose personal data jas been hacked while Marriott International which was in charge of this data, did not implement all it could to protect these data. According to the plaintiff firm, making the online platform responsible in Ex Ante of the clients' data security and constraint it to compensate injured clients in case of failure is a more important incentive for the firm to do its best to protect this data than a simple fine.
Many similar actions are ongoing, especially during English Courts where the practice of "class action" is more developed. The question is therefore to know whether it is interesting to encourage the development of this kind of process in France. Concretly, a substantial subjective right (here the right to have its data protected) exists only if it is accompanied by a procedural right to size the judge in order to he or she activates it. The right to ask for a compensation in case of violation of these Compliance obligations but also is therefore not only a strong incentive for firms but also a condition of effectivity of these same obligations, knowing that the effectivity is the major care of Compliance Law.
"Phishing" is a kind of cyber criminality aiming to obtain, by sending fraudulent emails which look like to those sent by legitimate organisms, recipient's personal information in order to impersonate or steal him or her. As it is difficult to find the authors of "phishing" and to prove their intentionality in order to punish them directly, on mean to fight against "phishing" could be to entitle banks to secure their information network and, to accompany this obligation with a strong incentive, to convict them to reimburse the victims in case of robbery of their personal data.
In 2015, a client victime of this kind of fraud asked to his bank, the Crédit Mutuel, to reimburse him the amount stole, what the bank refused to do on the grounds that the client committed a fault, transferring its confidential information without checking the email, however grossly counterfeit. The Court of first instance gave reason to the client because although he committed this fault, he was in good faith. This judgment was broken by the Chambre commerciale de la Cour de cassation (French Judicial Supreme Court) by a decision of 1st of July 2020 which states that this serious negligence, exclusive of any consideration of good faith, justifies the absence of reimbursement by the bank.
___
From this particular case, we can draw three lessons:
The Cour de Cassation states that good faith is not a salient criterion and that, as the bank must react when a banking account is objectively abnormal, the client must react face to an obviously abnormal email.
The Cour de Cassation describes the repartition of proof burden. Proof obligations are alternatively distributed between the bank and its client. First, the bank must secure its information network but, secondly, the client must take every reasonable measure to preserve its safety. It results from this that, if the email seems normal, phishing damages must be supported by the bank, and more generally of by the firm, while if the email is obviously abnormal, they must be supported by the client, but the burden to prove the abnormality of the email must be supported by the firm and not by the client.
Such a proof system shows that Compliance Law includes a pedagogic mission by educating each client in order to he or she would be able to distinguish among his or her emails, those which are normal and those which are obviously suspect. This pedagogic dimension, with the legal consequences associated to it, will not stop to spread.
The Journal of Regulation (JoR) was created in 2009 Marie-Anne Frison-Roche to study Regulation as a developing phenomenon.
Regulation can be defined as a set of mechanisms, rules, institutions, decisions and principles that allow certain sectors of the economy to grow and maintain equilibriums that they could not establish solely via their own economic strength.
Over the past years, 'common rules' to all the sectors impacted by Regulation (e.g., transports, energy, telecommunications, banking, finance, insurance, etc.) have appeared beyond the sectorial regulations that have been issued for the past decades, whose specificity were once justified by the great variety of sectorial technicalities that used to impregnate in return the sets of rules designed to regulate those sectors.
Neither economics nor political science - namely throughout the declining figure of the State - are sufficient to capture this common organisation and projection into the future that Regulation is, which we must understand to anticipate its evolution and act in accordingly.
The newly developed "Regulation Law" restores what is common to all of those sectors using a triangulated approach between Law, Economics and Politics. This is all the more important since Regulation already tends to dissociate itself from its founding notion of "sector", not only to be increasingly associated with the more inclusive one of "branch", but also to get more and more autonomous- that is, for instance, the case of the digital issues that cannot be reduced to a "sector" anymore, but that still needs to be regulated.
In order to follow, process, analyze and think about these issues, the Journal of Regulation (JoR),a mainly online-based bilingual publication (English-French), issues news reports, articles and thematic files.
The Journal of Regulation (JoR) issues a weekly newsletter to more than 10.000 people interested in Regulation throughout the world.
The Journal of Regulationregularly organizes public events. The last one, which is upcoming, is entitled 'Regulation, Supervision, Compliance'.
The Journal of Regulationissues its work in the RégulationsSeries, which are directed by Marie-Anne Frison-Roche and published by the Éditions Dalloz.
The Journal of Regulationoperates basing on different committees, particularly a Partners Committee including the main organisations, companies and law firms acting within the field of regulated sectors, and a Global Committee composed of the main Regulatory Authorities.
On June 27, 2012, the "Financial Securities Authority – FSA" of the United Kingdom sanctioned the Barclays Bank to have manipulated the Libor. By a chain reaction, on July 6, 2012, the German regulator, Bafin, opened an investigation into banks, with no doubt on Deutsche Bank, while the Japanese regulator, the "Securities Exchange Commission" in the United States, the Canadian competition office, in particular open all investigations since the 6 July concerning all banks within their competence on their statements. In addition, JP Morgan said that it was already the subject of a class action in this regard. The domino effect begins.