Showing posts with label Compliance. Show all posts
Showing posts with label Compliance. Show all posts

26 February 2021

Ethics and new lawyers


How are bad apples getting into the barrel?


A solicitor, qualified in 2017, forged a decree absolute for a client's divorce, and got two clients to pay fees of around £1,600 each into her personal account instead of to her firm. 

What has happened to the intake of my profession? I am disturbed at a case like this one - a very junior solicitor abusing her position in blatant but, in terms of the gain involved, minor ways. Solicitors should have such a thorough grounding in ethics that no-one could be any doubt that doing these things was completely wrong. There may be some malicious individuals who train as lawyers in order to subvert the legal system, but surely they target clients in organised crime or look to pull off some large fraud? Why would you go through all the hard work stress and cost of qualifying only to throw it away? Are there really people passing all those exams who who have no moral commitment to their clients and are also too stupid to realise the inevitability of these petty offences being discovered, or the inevitable penalties?

Do students no longer get the moralistic grounding I got from my chain-smoking ethics lecturer, dismissing any departure from the highest standards as "very shoddy"?
 
Or is it that we are not looking after our young people well enough? Is there more to be done to protect mental health and make sure that those we trust to administer justice can cope with the pressures put on them?

18 August 2020

Solicitors' ethics: the client or the public?


How should lawyers deal with disreputable instructions?

The Solicitors Regulation Authority has published another warning about solicitors becoming involved in dubious investment schemes, after recent cases led to the closure of seven firms and other regulatory action. This rightly highlights the welcome change of attitude we solicitors have had to make. 

It used to be that we represented the client's interests without regard to any wider morality, so long as we were not knowingly participating in criminal conduct or misleading the court. Now, we are required to have broader ethical standards and to have a duty to the public. I'm glad about that. 

Lawyers are now expected to carry out some due diligence and assure themselves that their clients are behaving legally, rather than just accepting the assurances and half-truths clients my give them. The public may assume, rightly or wrongly, that because a solicitor is involved, the investment is legitimate or money is protected.

Professional ethics grew up in the admirable tradition that solicitors represent their clients fearlessly and independently, and that everyone is entitled to legal advice. Solicitors rightly represent people accused of crimes or wrongdoing without allowing personal feelings to cloud judgement, drawing the line at actual knowledge: if you don't know your client is guilty, you can and should represent him in court. But in transactional matters we need a more rigorous approach that avoids actually assisting in schemes that are suspicious or disreputable. The fearless and independent advice is then that the client should not do it. 

18 March 2020

Covid-19: suggestions for emergency law reform


Promoting fairness, spreading costs and avoiding a long tail of litigation


In my blog post of yesterday I described the existing law as it applies to business contracts during the coronavirus outbreak. I set out below some of the legal steps I think Government/Parliament should consider taking to stabilise the economy and markets and reduce unfair burden-sharing across the economy. It would normally be profoundly un-Conservative to interfere in private contracts, but in this case the circumstances were entirely unforeseen and the losses will be distributed in a way that is close to random, but with the effect falling particularly heavily on small businesses unable to pass costs back to their suppliers. Government attempts to help business with loans and other support are entirely welcome, but unless Government will contribute the entire cost to the economy, which is unlikely, it is important also to share the remaining burden across the economy as evenly and fairly as possible, and to preserve businesses and jobs so that they can resume after the crisis without a burden of debt or the threat of litigation. That needs to be done with very broad-brush temporary legal measures to complement targeted Government assistance.

English law currently makes no provision for short-term suspension of businesses or the temporary laying-off of workers. Businesses that do not perform contracts may be liable for unlimited claims for losses suffered by the other party.

My suggested steps are intended only to apply during the duration of the Covid-19 crisis. Ministers should take power to remove or suspend them when appropriate, with power to restore them if the virus returns. Inevitably they carry risks of further unfairness, fraud and abuse, but their short-term nature should mitigate that. Considerations of moral hazard (relieving those who did not prepare at the expense of those who did) hardly apply when the present situation was so unforeseeable.

All of my suggestions can be implemented by legislation alone, without of themselves requiring additional public expenditure, though for best effect they would be integrated with the financial measures already announced, or to be announced, by the Chancellor.

1.    For the duration of the crisis, businesses should be given power to “mothball” themselves, or individual sites or business activities within a company, without going to court or any other formality other than public notice. I would call this Suspension.

1.1. Suspension would have the same effect as Administration (Insolvency Act 1986 Part II) but the directors would remain in control and the process could be applied to an identifiable part of a business (such as a retail unit or a product line, with the employees, contracts and assets relating to that unit being deemed to be those of the unit in Suspension as if it were a separate company). Suspension would be permitted only if the directors consider the business to be uneconomic during the crisis and for the sole purpose of preserving the business during the crisis.

1.2. During Suspension, no debts or contracts incurred before 16 March 2020 or accruing under existing obligations could be enforced by legal action or appointment of liquidators/administrators. Employment contracts could not be terminated but employees could be laid off at a specified rate – SSP rate, half pay, 75% or full pay, depending on Government subsidies. Government would undertake to pay all or a proportion of these wages costs, and could provide loans pending later claims. This could be extended to zero-hours workers and contractors engaged direct or through service companies. Alternatively, laid-off workers would be entitled to state benefits during lay-off as if unemployed, but without obligations to seek work.

1.3. Rents and interest payments and accruals could be arbitrarily reduced by 25% or 50% during the peak crisis period, sharing burdens with landlords and lenders, depending on how Government subsidies are to be targeted. Services provided to or by the busienss (other than utilities) could be suspended notwithstanding any long-term contracts, and no payments would be due for services not provided.

1.4. At the end of Suspension, the business would have to pay its suspended debts (but not cancelled interest, rent or taxes) no later than equal monthly instalments over six months.

1.5. Public service obligations could be imposed as conditions of Suspension, such as contributing to initiatives to provide essential products or services, or making staff available for volunteering, or a general obligation of directors to do everything possible to support public initiatives to fight the virus and keep the economy going.

2.    Alternatively, or as a separate initiative, employers should be given power to lay off employees on short notice for up to three months or the duration of the crisis, continuing to pay them (at reduced rate as above) with the benefit of state subsidies. Existing redundancy processes are too slow (for large businesses consultation and selection for redundancy plus notice period would exceed the likely duration of the crisis) and result in permanent dismissal. Anyone made redundant on or after 16 March 2020 and for the duration of the crisis should be automatically entitled to reinstated within six months unless the employer goes bust or can show that the job was redundant notwithstanding the crisis. This is what Virgin Atlantic is trying to achieve, but without a change in the law, its initiative would not survive challenge in the Employment Tribunal.

3.    All commercial rents and/or trading company interest rates in force between private parties at 16 March 2020 could be reduced by 25% for three months, purely as burden-sharing, on top of any reduction due to the base rate cut. Financial markets would need to be exempted in view of international implications and there might be a size threshold, though it would be a mistake to assume that only small businesses need relief.

4.    Covid-19 should be deemed a “force majeure” event for all contracts (other countries, eg China, have done this); the law would imply a term into every contract governed by UK law that if performance of the contract is rendered impossible, impractical or uneconomic by the coronavirus crisis (including by labour shortage or unavailability of supplies) the obligation is suspended, if capable of being performed later, or cancelled if time-critical, with any advance payments or expenses being refunded (as per section 2 of the Law Reform (Frustrated Contract) Act 1943), plus consumer deposits or prepayments being refundable in full. This would not apply to financial markets or insurance contracts but could apply to bank lending. This is intended to prevent the economy being overwhelmed by a tide of litigation attempting to shift costs to other parties and breach of contract claims for damages, including for loss of profit. Legislation akin to the Protection of Trading Interests Act 1980 could be used to prevent British companies being victims of such claims abroad or under contracts governed by foreign law.

5.    Compliance with Government recommendations on public health should be deemed compliance with a legal obligation for the purposes of all contracts and the law of torts, so that no-one can be sued for doing so and compliance, by the business or third parties, provides a lawful excuse for non-performance of obligations and enables insurance and benefits claims. No-one should be penalised for acting in accordance with Government advice, or because it is advice rather than the law.

6.    Legislation should say that exposure to coronavirus in the course of normal working should not in any circumstances be deemed a breach of health and safety laws by employers or negligence by the operators of business or premises. Otherwise businesses which should be staying open, perhaps in essential sectors such a heath supplies or food distribution, will close down because of the duties they have towards their own staff and the public, and will be reluctant to re-open as the danger reduces. We need to be explicit that businesses and individuals are allowed to take some risk in order to combat the virus and keep the economy going. Employers are reacting as if the call to work from home means that all workplaces must be closed, whether or not home working is possible. We do not want courts examining decisions with the benefit of hindsight, or businesses being burdened with litigation as they try to recover.

7.    Loans made under Government crisis initiatives should be exempted from prohibitions in other contracts and from calculation of financial covenants in bank lending documents. Otherwise acceptance of such emergency loans is likely to amount to a default under existing loans and result in lenders enforcing security, appointing administrators or increasing interest rates and fees to penal levels. There is a danger of lenders seeing receipt of crisis subsidies as an opportunity to recover pre-existing debt. It would be possible to suspend all financial covenants in loan agreements for a period to prevent defaults.

8.    Ministers should take powers to disapply intellectual property rights during the crisis if they restrict business responses to the crisis, eg by inhibiting UK copying and production of ventilators or other essential supplies normally sourced from overseas.

9.    The EU should suspend all State Aid restrictions during the crisis (at least outside the Eurozone) and disapply competition law to the extent that it inhibits businesses co-operating for the efficiency of the economy and the sourcing and distribution of goods during the crisis.

In the absence of steps such as these, businesses will take their own steps to protect themselves and (as they are required by law to do) their creditors and employees by making staff permanently redundant, disposing of assets (eg by not renewing leases) and/or going into insolvency, doing permanent damage to the economy and having knock-on effects for creditors and the wider economy. An overhang of litigation could stifle the economy for years to come. 

Stay safe.

26 February 2016

UK company fined at home for failing to prevent bribery overseas


A bung can cost more than a fistful of dollars


Last week Sweett Group PLC became the first company to be sentenced for the crime of failing to prevent bribery by an associated person (s7 Bribery Act 2010). One of its overseas subsidiaries paid bribes to secure a contract concerning an hotel in Abu Dhabi: Sweett Group is an AIM-listed construction consultant.

An English court imposed a fine of £1.4 million and a confiscation order of £851,000, plus costs. A number of lessons can be learned:



·     The Bribery Act has not gone away: the noise made by law firms when it came in has abated, but the Serious Fraud Office will prosecute British companies for failing to stop corruption overseas

·     Co-operating with the authorities will not always avoid prosecution – Sweett Group reported itself after it got media attention, but the SFO did not even offer a “plea bargain” deferred prosecution agreement

·     Penalties can be swingeing

·     Professional practices are not immune

·     UK companies must take precautions: demonstrable adequate procedures to avoid bribery, and an anti-bribery culture must exist before the problem arises.



03 August 2015

Insolvency and consumer credit businesses


A trap for administrators and a workload for the FCA


Consumer credit businesses used to be licensed by the OFT, in a fairly relaxed licensing regime. It included not only consumer credit lenders, but also businesses with a tangential involvement in credit such as credit brokers, debt collectors and debt advisers. Credit brokers include most businesses who introduce consumers to credit providers, such as motor, furniture and electrical retailers. Many large businesses held consumer credit licences for minor activities outside of their main businesses, such as employee loan schemes or other employee benefits.

The Financial Conduct Authority has now taken over regulation of consumer credit, with all the complexity of the financial services regime. Consumer credit businesses have become "authorised persons" (including those who have the transitional "interim permission"). That has many consequences, some of them possibly unforeseen. One of them is the application of the FSMA insolvency legislation to all consumer credit businesses.

A possible major trap is that an appointment of an administrator by the directors of a consumer credit authorised business, or of one that should be authorised, needs the prior consent of the FCA (section 362A FSMA 2000). The directors must obtain the consent of the FCA before filing a Notice of Intention to Appoint Administrators, or if there is no qualifying floating charge holder and therefore no need to file such a notice, the consent must be filed at the same time as the Notice of Appointment of Administrators. Failure to obtain the FCA’s consent renders the administrator's appointment invalid; but the case of Peter Lloyd Bootes and others v Ceart Risk Services Ltd holds that this is a curable defect, so the appointment will take effect when the consent is obtained and filed.  

If there is a qualifying floating charge holder, and it makes the appointment, no prior consent of the FCA is required. But all documents in relation to the administration issued to creditors must also be sent to the FCA, and similar requirements apply to other forms of insolvency.

This is yet another thing for insolvency practitioners to look out for before appointment, and a potential source of uncertainty in the validity of appointments. A search of the FCA register should probably be routine (and the separate specialist registers, including the consumer credit register), but even that is not complete protection: if the business should have been authorised, for instance because it introduced consumers to credit providers, the FCA's consent is still needed. Whether the FCA will give timely consents in respect of firms it has never heard of, or precautionary applications for consent, remains to be seen.


31 March 2014

Consumer credit licences all expire


If you haven't acted, your consumer credit activities are now illegal


All licences granted by the OFT under the Consumer Credit Act 1974 lapse at midnight tonight. That includes the group licence granted to all solicitors.
 
From tomorrow (1 April 2014), consumer credit businesses - including ancillary activities such as credit brokerage and debt collection - require authorisation by the Financial Conduct Authority. If you haven't already applied for interim authorisation, you will need to stop carrying on the regulated activity until you have gone through the application process - likely to take some months.
 
There is no general permission for solicitors, so those engaged in consumer credit activities, including debt collection from consumers, now have to be dual-regulated by the FCA and the SRA (and pay two sets of fees for the privilege). Will consumers be any better off? No, of course not.


06 August 2013

Consumer credit gets the financial services treatment

The FCA takes over licensing in a whole new style

Any business providing credit to consumers, or introducing sources of credit, needs a consumer credit licence. The requirements and standards have increased gradually since licensing came in back in the 70’s. Back then, almost all applications were granted and hardly any licences were revoked. The OFT has never put much resource into the system and has taken a light-touch approach. That will all change when regulation moves to the financial services regulator, the FCA, in April 2014.[1]

The FCA is a far more demanding regulator. It is used to dealing with large institutions with full-time compliance officers, and the resources to apply detailed, complicated rules. The FCA has the resources to deal effectively with complaints and to make life miserable for those it suspects of transgressions, and it is not known for sympathy with small businesses struggling to comply. Apart from the largest consumer credit businesses, which are already FCA-regulated, consumer credit licence-holders may be in a for a shock.

Until now, the main sanction under consumer credit legislation was the threat that agreements might be unenforceable due to non-compliance. Although a whole industry grew up around this, not many defences based on technicalities were successful. The OFT was unlikely to take action unless the whole business model of the licence-holder was objectionable. The OFT’s expectations were set out in guidance notes, which did not have the force of law.

The FCA has said that it will act very differently. It is used to dealing with individual complaints and sanctioning businesses for isolated non-compliance, as well as looking carefully at the overall suitability of a business. It expects rigid compliance and self-reporting of breaches. Directors and those performing “controlled functions” will be subject to personal sanctions, as they are in other FCA-regulated businesses. The FCA will be translating the OFT’s guidance into enforceable rules. There will also be Principles of Business, High-level Standards and Conduct Standards – in other words, a whole new regulatory environment for businesses to learn and understand.

The FCA does promise some relaxation for lower-risk businesses. Giving deferred payment terms at no cost to buyers of goods and services or introducing them to sources of credit, hiring goods to consumers and not-for-profit debt advice all require licensing at present but are to be the subject of exemptions, and there is to be a new status as authorised representative of an authorised firm, allowing businesses to rely on the compliance of their consumer credit supplier.

All licence-holders have to apply for interim permission from the FCA, with applications stating in September, accompanied by payment of a £350 fee – likely to be the first of many. Full authorisation must be applied for by 2016, and aims to  ensure that regulated firms are well-run, recognise the risks they face and have appropriate strategies, systems and controls in place and the right people in important roles. Individuals who perform key “controlled functions” will be vetted and monitored.

Recommended first steps for licensed businesses are to check that your details are correct on the existing Consumer Credit Register and to sign up to FCA consumer credit emails. Any business contemplated consumer credit activities would do well to apply for an OFT licence before April, as otherwise it will be subject to the full rigours of FCA authorisation.




[1] Financial Services Act 2012 (Consumer Credit) Order 2013

28 May 2013

The Takeover Code and unquoted companies

A nasty surprise for the vanity PLC

Changes to the Takeover Code take effect in September. The Code regulates merger and takeover activity, largely between quoted companies. But many people (including many lawyers) do not realise that the Code also applies to some unquoted companies. Complying with it can be onerous: it involves a formal process and detailed documents, as well as large fees to the Takeover Panel. For small companies it is sometimes possible to get a waiver from the Panel with shareholder agreement, but that can be time-consuming and expensive. Otherwise, anyone contemplating buying or selling and unquoted PLC should be aware of the Code and the extra costs and delays it will involve.
Many companies think being a PLC gives them extra kudos. It can make the company seem bigger and more substantial than it is – in reality there may be only £12,500 of share capital paid up. A PLC may find it easier to get trade credit or to avoid needing personal guarantees from its shareholders. That status comes at an expense, because a number of Companies Act exemptions and relaxations do not apply to public companies, but it also brings the company within the scope of the Takeover Code. It applies to takeovers of all public companies (PLCs) whether or not their shares have been traded on a public market.
The Code also applies to a private company which has filed a prospectus, had its shares quoted on a market or had a dealing arrangement for its shares within the last 10 years. An unquoted PLC which has never had a share dealing arrangement can always escape the Code by re-registering as a private company, but any company that falls within the 10-year rule is within the Code for the full 10 year period.
What are the consequences if the Code’s application is missed? First and most likely, it will disrupt a transaction if the Code is raised part way through a deal. It gives minority shareholders in the target company extra rights, so they are the most likely to complain. Failing to comply with the Code is a serious disciplinary offence for parties or advisers in the financial services sector, and can also lead to unregulated companies or individuals being publicly reprimanded or banned from activity in the financial markets. A complaint could be made some time after a transaction. The extra rights conferred on minority shareholders may come as a surprise to a controlling majority, and the extra costs of acquisition could have an effect on potential sale price for the company.
Finally, there is that the dreaded Rule 9: anyone acquiring shares in a company subject to the Code which take him (with his associates) over 30% has to make a cash offer for all the remaining shares. That can come as an enormous shock!
Any unquoted company subject to the Code, and its major shareholders, should be aware of their Code obligations, and perhaps consider whether PLC status is worth it. Do not be caught out when a 29% shareholder buys another 2%, or when the quick and easy takeover deal gets bogged down in process and cost.

08 February 2012

Help! The bank has frozen my account!


Collateral damage from money-laundering legislation


I have seen this more than once: a client rings in a panic, having had his business bank account frozen by the bank. His bank won’t tell him why. They are suddenly completely uncooperative, and he is naturally livid. He wants to know how to get the account unfrozen, and if necessary to take immediate legal action. What should you do if it happens to you?

The reason is almost always that the bank has formed a suspicion that the account or the customer is involved in money-laundering (or terrorist financing). Once it forms that suspicion, the bank is obliged by law to block transactions; otherwise it risks committing an offence of converting or transferring criminal property under the Proceeds of Crime Act 2002 or facilitating the retention or control of terrorist property under the Terrorism Act 2000. [1] It also has to make a report to the Serious Organised Crime Agency (SOCA) explaining its suspicions.

You may be an entirely innocent party. The suspicion could relate to an investor, employee, customer or supplier. The concept of “proceeds of crime” is extremely wide, and can include, for instance, the benefit of tax evasion, or business cost savings arising from minor offences.

Suspicions can be triggered by the bank’s internal systems, far away from your relationship manager. All banks now operate back-office systems for flagging up and reporting unusual transactions. Your manager might know why something has happened, but it may still look suspicious to someone – or a computer – in head office.

What is more, the bank is prevented from telling you why it has done what it has done: it is an offence to “tip off” a person if that could prejudice an investigation following the report. The only way to avoid lying to you is for the bank to say nothing at all, so it just clams up. Of course this can be a nonsense: any criminal or terrorist, and most well-informed people, will know that if a bank or professional adviser suddenly refuses to act on instructions and won’t tell you why, it is probably because they have a made a money-laundering report.

SOCA can give consent to allow transactions to proceed, or if it doesn’t respond within seven working days, the freeze ends. But if SOCA refuses consent, the freeze is extended until 31 days from the date of refusal of consent. In that case, SOCA will usually have notified the police or other enforcement agencies. If they want further time to investigate, they will have to make an application to court.

The courts have consistently supported banks when they have relied on their duties under the money-laundering legislation, even if the customer is entirely innocent. [2] So the customer usually has no remedy, even if his business is left in ruins. A Mr Shah has been claiming losses of $330 million from HSBC which he alleges flowed from their blocking of transfers from his account.

To be protected, the bank just has to satisfy the court that it had a suspicion. The suspicion does not even have to be reasonable: if the bank has a suspicion, it must report and it must stop the transaction. The court has said that the bank must “think that there is a possibility, which is more than fanciful, that the relevant facts exist. A vague feeling of unease would not suffice. But the statute does not require the suspicion to be 'clear' or 'firmly grounded and targeted on specific facts' or even based on 'reasonable grounds'." [3]

Mr Shah tried a variety of different attacks on the bank’s position. He said that the bank’s suspicion was irrational; negligently self-induced; mistaken; and/or automatically generated by computer. He said that the bank was negligent, or breached its duty to give him relevant information about his affairs. The Court of Appeal dismissed all these claims apart from the last. It allowed the claim to go forward only in case Mr Shah could prove that the bank did not in fact have a suspicion at all; or he could prove loss from the bank’s failure to tell him what was going on, at a time when it was not protected by the “tipping off” requirement – perhaps because the investigation had ended. In a second visit to the Court of Appeal, the court even refused to order the bank to tell Mr Shah which employees had the suspicions and made the reports, on grounds that it was not relevant; public interest immunity could also apply.[4] Mr Shah’s lawyers made a third unsuccessful visit to the Court of Appeal [5] before the remains of his case came on for trial in December 2011. The trial is still going on, with a decision not expected for several months, but the legal principles are clear.

So what advice do I have for the innocent bank customer, without the resources of Mr Shah, to fund costs? Each case depends on its facts, but early litigation is not likely to be successful. In the short term, the best answer is usually to work with the bank to allay the suspicion and get the freezing lifted. If the client thinks he knows what has caused the suspicion, give the bank the evidence. Ask them to seek the permission of SOCA to proceed with the transaction, as a matter of urgency. Whilst pointing out the possibility of a claim may focus their minds and make them review their decisions, it is unlikely that there will be a successful claim if there is a genuine suspicion. Bank customers should perhaps be alive to these issues beforehand and try to head them off, for example by giving the bank an explanation in advance of transactions that may look suspicious. As Mr Shah is finding out, the cards are heavily stacked against the customer.



[1] It could also be that t has not completed its client due diligence under the Money Laundering Regulations 2007 or its ongoing monitoring has noticed a problem with it, which can oblige it to block bank account transactions under Regulation 11.

17 February 2011

Workplace safety: it's criminal

First corporate manslaughter conviction

A company has been convicted of the new offence of corporate manslaughter, arising out of an accident in 2008[1].
Before the Corporate Manslaughter and Corporate Homicide Act 2007 it was very difficult to prosecute for manslaughter arising out of industrial accidents. It was necessary to prove the personal guilt of an individual director. The new offence is committed if the way the company’s activities are managed or organised causes a death, amounting to gross negligence, to which senior management contributed. 
Cotswold Geotechnical (Holdings) Ltd ignored industry standards and left a junior geologist to work alone in a 3.5m deep trench. Sadly, Alex Wright was killed when the trench collapsed.
Originally, the managing director was also charged with manslaughter, but was unfit to stand trial, and the company was also charged with a health and safety offence. Was the corporate manslaughter offence is unnecessary in the circumstances? The company can expect a heavier fine than for the H&S offence[2], and has the public notoriety of being convicted for manslaughter[3] – perhaps that was the main reason for bringing in the offence, to convict companies of a “real” crime instead of what looked like a technical offence. Still no-one goes to jail.




[2] Sentencing guidelines for corporate manslaughter recommend a fine of over £500,000, that may be in millions; for health and safety offences causing death, of over £100,000. Fines cannot be recovered under insurance.
[3] Which is likely to include court-ordered publicity, eg on the company’s own website.

12 February 2011

A decent website?

Advertising code extended to all websites

The Code of Advertising Practice is being applied to all websites from 1 March. I blogged this week about the legal requirements for your website, but now it also has to follow the Code if it directly promotes products or services to consumers (including businesses) in the UK. That includes a Facebook page or LinkedIn company page.
You may think that all your promotional material is already legal, decent, honest and truthful, but do you hold documentary evidence to prove all claims that are likely to be regarded as objective? Is it clear that opinions are not intended to be objective claims?
For a start, very few law firm websites don’t claim to be a “leading” practice!
Some parts of the Code go beyond the content of advertisements: for instance products ordered must generally be delivered in 30 days, and the CAP duplicates and extends some parts of the Distance Selling Regulations, and brings in general obligations to treat customers fairly – and appears to apply them to business-to-business sales. Of course it does not have the force of law – its terms are enforced by the Committee of Advertising Practice through advertising industry sanctions, so it does not give customers direct contractual rights. But an adverse finding could be highly embarrassing. Remember, many complaints come from competitors!

07 February 2011

Name, rank and number

Company details you need on your stationery, websites and emails

Routine stuff, but I see many companies are still getting these wrong. Letterheads and invoices are usually right, but people fall down when it comes to email footers, websites and minor stationery items. Have you got them all right? As a reminder, download my easy guide as PDF.

05 February 2011

Companies House: all-electronic filing

Companies House has announced that all incorporations and filings of annual returns, accounts and the main company forms for the standard company types will be electronic-only by March 2013. That means the end of paper forms.

In most cases web filing is much easier, though it does make it harder to make sure that filings are right and properly authorised: a mistake by the person filling in the online form will not easily be picked up. You do have to struggle though the arcane director/secretary authority codes involving the first three letters of your eye colour and Dad's forename.


It can go wrong, though. A client acquired a company and moved the office, and was given an incorrect online filing code. We couldn't file the change of registered office or new directors. Companies House would only send the filing code out by post to the old registered office...


03 February 2011

Bribery Act delayed

The Government has delayed bringing the Bribery Act into force, until three months after it publishes its guidance. The guidance was due in January and the Act was to come into force in April. The guidance is to be made clearer and more comprehensive. It is important because it will clarify the steps businesses will have to have taken to show that they have "adequate procedures" to prevent bribery on their behalf. there is a fear that small businesses may be caught out because they will not have written manuals, processes and contracts.

01 February 2011

Insolvency and pension deficits: a Bonas for groups?

Big cut in the threat of contribution notices

An important case for the insolvency world when dealing with pension scheme deficits: the Pensions Regulator has been knocked back in its demand for a substantial contribution (£20m claimed, £5m originally ordered) by way of a contribution notice against a parent company, following a pre-pack that resulted in the business being sold back to a member of the same group. In Re the Bonas Group Pension Scheme the Tribunal effectively held that a contribution notice can only be used to recover actual loss caused by the parent company’s conduct. Unless the pre-pack sale was at an undervalue (and since the subsidiary was insolvent and the parent had no other obligation to contribute to the scheme) the Pensions Regulator had no grounds for recovery of the scheme deficit from the parent by way of a contribution notice. This greatly reduces the threat of contribution notices is associated companies are allowed to go down with pension deficits, and  slashes the Pension Regulator’s bargaining power when negotiating contributions from groups.
Contribution notices can require a person connected to or associated with the employer to make a contribution to a scheme deficit. Financial support directions are not affected by the case, and there have been some legislative changes that could affect the result, but this is a big and unexpected reduction in the Pension Regulator's powers.

21 January 2011

Competition: bite the hand that feeds you

Would you have done the right thing?

RBS has been fined £28.59m by the OFT for supplying information on its pricing of loans to professional practices over a four-month period. Ouch!
A specialist team provided the information to Barclays. Barclays shopped them to the OFT, and by doing so escaped a fine and damaged its competitor. This is now the pattern – whistleblowers get off scot-free, so there is every incentive to be the first to rat.
Banks should know better, but smaller businesses are often not alive to competition issues. The occasional chat or bit of co-operation through a trade association seems only natural. Just think what might happen if your competitor goes to the OFT. Should you go first?
£28.59m! I wonder what the .59 was for.

06 January 2011

Defamation and archives

Unacceptable publications: falsifying the record?

One problem we are having to grapple with increasingly in the internet age is that of archives. In the past, if a book contained illegal or defamatory material, you would supress its further publication, but it took too much effort to engage in book-burning, and libraries would probably retain their copies. No-one would attempt to get back all copies of last week's newspaper, or to fillet the publisher's archive. In the internet age we have semi-permanent, searchable, global access to almost anything, so the damage done continues long after publication of even the most ephemeral comment. How far is it acceptable to require filleting of archives to remove illegal or defamatory material? When does falsifying the record become worse than dissemination of the unacceptable material?

Where’s my Blackberry?

Data protection comes of age – is your law firm taking it seriously?

It’s hilarious, isn’t it? MI6 officer leaves his laptop in a cab. HMRC loses unencrypted data disk in the post. Building society employee’s computer is nicked from his home. Medical records found in car park. Council loses children database on memory stick. Only this week, sensitive Scottish court records discovered at recycling bank. There are so many of these stories, and we all enjoy a laugh at the incompetence of these large organisations in protecting our personal information. After all, this only applies to big, faceless institutions managing huge databases – doesn’t it?
Data protection law has been around for a long time, but it hasn’t been taken terribly seriously by anyone outside of large data centres – except as an excuse to not tell anyone anything: “can’t answer that – data protection”. We used to tell our clients not to worry unduly – make sure you register, but if you get anything wrong all you will get is a telling-off and guidance on how to do better next time.
But now data protection has come of age. Sit up and take notice. In November the Information Commissioner’s Office (ICO) levied its first fines, under stronger powers given it last year. Hertfordshire County Council was fined £100,000 for inadvertently sending child protection case papers by fax to the wrong number. Who hasn’t sent a fax or email to the wrong address? Yet the council should, apparently, have had procedures to stop this happening. What procedures, exactly?
The second fine was even more concerning for businesses. A private company, A4e, was fined £60,000 for the loss of a laptop, stolen from an employee’s house, containing unencrypted data on 24,000 people.
Data protection doesn’t only apply to big databases – the Hertfordshire case concerned only a handful of people, though the information was of the most sensitive kind. It doesn’t only apply to professional data processors; it can apply to any business. And good intentions aren’t enough: failure to have adequate security and procedures can lead to large fines, even with the intervention of errors or criminals. Keeping data on a PC inside a locked private house wasn’t good enough protection.
That led me to think about the attitude of the legal world. Solicitors take client confidentiality very seriously, in terms of their own conduct, but many have not translated that into action on data security or, for that matter, physical security. They think of it as a duty to the client, but not about the other data subjects who may be referred to in their files. Legal practices hold vast amounts of personal data, much of it of a highly sensitive nature. Deeds and will may be kept in a safe, but there is little or no security on paper files, which are stored openly, carried around on public transport and taken home. Many lawyers’ computer systems have no security on internal access to data beyond an access-level password. They have firewalls and virus protection. But usually no protection at all against unauthorised access or copying by legitimate users of the system, or anyone in possession of their passwords. Data is not segmented or internally password-protected.
Access to the servers from the internet is usually tightly controlled, but once in, there are no restrictions on access to client data. Unencrypted email is universally used for almost all communication, and unencrypted attachments are sent that could include large amounts of personal data. Worst of all is the approach to home and mobile working. Data may be freely transferred to work or personal laptops and mobile devices. Mobile devices with weak passwords or PIN numbers allow access to the entire system, or at least to email records.
Solicitors have always relied on their integrity and professional conduct to enforce confidentiality. Systems are devised to prevent casual disclosure of information, but they are not designed to withstand deliberate, criminal attack. Most solicitors would feel that there is not much chance that they will be victims of deliberate espionage or malicious attacks.
Then there was the ACS Law case, in September 2010. ACS, a small law firm, acted for copyright holders trying to sue P2P file sharers for copyright infringement. It got court orders against ISP’s forcing them to disclose lists of users with details of internet usage, allegedly including their access to pornography. BT, and possibly others, sent the data to ACS as unencrypted email attachments – Excel spreadsheets. You wouldn’t have done that – would you? Then the libertarians of the file-sharing community mounted an illegal denial-of-service attack on ACS’s website. In attempting to restore the site, ACS’s IT people accidentally allowed access to internal data, including their email archive – which was promptly stolen and distributed across the net. ACS could yet be fined up to £500,000 for this breach. Clearly that should not have happened. But it was a mistake, made by a technical person. How is a law firm supposed to supervise an IT specialist to make sure he never allows external access to data?
More worrying still, the unencrypted attachments were the main source of the data stolen. What could ACS have done to protect that information? It naturally archives its emails, even if deleted by its users. It also backs up the archive and everyone’s inboxes. So multiple copies of any attachment will be created, even if the user did not save the attachment – or correctly saved it with a password.
This is the heart of the problem for law firms. We deal in evidence. We are instinctively more worried about losing access to data than we are about others gaining access. People leave, and passwords get forgotten. We lawyers hate to throw anything away. We get sued if we can’t prove exactly what advice we gave to Mrs Jones on the phone in 2005, or we can’t explain why clause 24 was deleted in draft 3, or we forgot the family history told to us five years earlier. Professional standards such as Lexcel require us to ensure that other people in the firm have access to client information if the lawyer is absent for any reason. The drive to be efficient and keep costs down requires us to share information quickly.
Part of data protection is the deletion of data that is no longer required, but I have yet to meet a lawyer who thought that any document or record could be discarded. Try persuading them that they should be deleting all records of incoming emails from the other side in litigation because they contain personal data! It’s evidence in the case.
So what should we be doing? The ICO’s guidance is quite clear, and it does not match with what many lawyers have been doing. Review your security with an eye on protecting the privacy of all data subjects, not just your client. Make sure your data is secure even if someone steals your PCs or servers. Identify particularly sensitive items, either because of the nature of the information or the number of data subjects, and take particular precautions, including password-protecting individual documents and preventing their removal from the office, in hard copy or unencrypted electronic form. Ban anyone from working on computers outside the office unless all client data is stored on an encrypted drive with a strong password. Prevent anyone from transferring data to CD or memory stick without getting authorisation, to include checking the security of the data. Promote a culture of data security, including password security.
For now, this will still be an imperfect solution. We need to communicate with outside parties and to transfer data to them. Email encryption is still not widely accepted in the world at large, due to the need for both parties to operate the same system, so email traffic is likely to remain vulnerable in transmission. Make sure your records of incoming and outgoing emails are stored on encrypted drives and that your access passwords are strong, and not remembered by the user’s PC – which Outlook rather encourages. Check that your backups of data are as secure as the originals. If necessary, implement a password management system to securely record the passwords needed to access protected data.
I have done all this myself, now I am working at home, to give clients and data subjects the best protection possible against unauthorised access to my home PC, laptop or smartphone, my wireless network or my email communications. I tell my clients to anonymise bulk information they may send me about their employees or customers wherever possible, and to password protect the information. But no-one has yet shown me how to prevent the mis-keying of a fax number, the loss of a document in the post or accidentally attaching the wrong file to an email. At least by being seen to try, we should be protecting ourselves from the savage criticism that will flow from doing nothing.
I should say that nothing in this article relates in any way to any of the firms I work with – I have no cause for concern about any of them.