17 February 2011

Workplace safety: it's criminal

First corporate manslaughter conviction

A company has been convicted of the new offence of corporate manslaughter, arising out of an accident in 2008[1].
Before the Corporate Manslaughter and Corporate Homicide Act 2007 it was very difficult to prosecute for manslaughter arising out of industrial accidents. It was necessary to prove the personal guilt of an individual director. The new offence is committed if the way the company’s activities are managed or organised causes a death, amounting to gross negligence, to which senior management contributed. 
Cotswold Geotechnical (Holdings) Ltd ignored industry standards and left a junior geologist to work alone in a 3.5m deep trench. Sadly, Alex Wright was killed when the trench collapsed.
Originally, the managing director was also charged with manslaughter, but was unfit to stand trial, and the company was also charged with a health and safety offence. Was the corporate manslaughter offence is unnecessary in the circumstances? The company can expect a heavier fine than for the H&S offence[2], and has the public notoriety of being convicted for manslaughter[3] – perhaps that was the main reason for bringing in the offence, to convict companies of a “real” crime instead of what looked like a technical offence. Still no-one goes to jail.




[2] Sentencing guidelines for corporate manslaughter recommend a fine of over £500,000, that may be in millions; for health and safety offences causing death, of over £100,000. Fines cannot be recovered under insurance.
[3] Which is likely to include court-ordered publicity, eg on the company’s own website.

12 February 2011

A decent website?

Advertising code extended to all websites

The Code of Advertising Practice is being applied to all websites from 1 March. I blogged this week about the legal requirements for your website, but now it also has to follow the Code if it directly promotes products or services to consumers (including businesses) in the UK. That includes a Facebook page or LinkedIn company page.
You may think that all your promotional material is already legal, decent, honest and truthful, but do you hold documentary evidence to prove all claims that are likely to be regarded as objective? Is it clear that opinions are not intended to be objective claims?
For a start, very few law firm websites don’t claim to be a “leading” practice!
Some parts of the Code go beyond the content of advertisements: for instance products ordered must generally be delivered in 30 days, and the CAP duplicates and extends some parts of the Distance Selling Regulations, and brings in general obligations to treat customers fairly – and appears to apply them to business-to-business sales. Of course it does not have the force of law – its terms are enforced by the Committee of Advertising Practice through advertising industry sanctions, so it does not give customers direct contractual rights. But an adverse finding could be highly embarrassing. Remember, many complaints come from competitors!

07 February 2011

Name, rank and number

Company details you need on your stationery, websites and emails

Routine stuff, but I see many companies are still getting these wrong. Letterheads and invoices are usually right, but people fall down when it comes to email footers, websites and minor stationery items. Have you got them all right? As a reminder, download my easy guide as PDF.

05 February 2011

Companies House: all-electronic filing

Companies House has announced that all incorporations and filings of annual returns, accounts and the main company forms for the standard company types will be electronic-only by March 2013. That means the end of paper forms.

In most cases web filing is much easier, though it does make it harder to make sure that filings are right and properly authorised: a mistake by the person filling in the online form will not easily be picked up. You do have to struggle though the arcane director/secretary authority codes involving the first three letters of your eye colour and Dad's forename.


It can go wrong, though. A client acquired a company and moved the office, and was given an incorrect online filing code. We couldn't file the change of registered office or new directors. Companies House would only send the filing code out by post to the old registered office...


03 February 2011

Bribery Act delayed

The Government has delayed bringing the Bribery Act into force, until three months after it publishes its guidance. The guidance was due in January and the Act was to come into force in April. The guidance is to be made clearer and more comprehensive. It is important because it will clarify the steps businesses will have to have taken to show that they have "adequate procedures" to prevent bribery on their behalf. there is a fear that small businesses may be caught out because they will not have written manuals, processes and contracts.

01 February 2011

Insolvency and pension deficits: a Bonas for groups?

Big cut in the threat of contribution notices

An important case for the insolvency world when dealing with pension scheme deficits: the Pensions Regulator has been knocked back in its demand for a substantial contribution (£20m claimed, £5m originally ordered) by way of a contribution notice against a parent company, following a pre-pack that resulted in the business being sold back to a member of the same group. In Re the Bonas Group Pension Scheme the Tribunal effectively held that a contribution notice can only be used to recover actual loss caused by the parent company’s conduct. Unless the pre-pack sale was at an undervalue (and since the subsidiary was insolvent and the parent had no other obligation to contribute to the scheme) the Pensions Regulator had no grounds for recovery of the scheme deficit from the parent by way of a contribution notice. This greatly reduces the threat of contribution notices is associated companies are allowed to go down with pension deficits, and  slashes the Pension Regulator’s bargaining power when negotiating contributions from groups.
Contribution notices can require a person connected to or associated with the employer to make a contribution to a scheme deficit. Financial support directions are not affected by the case, and there have been some legislative changes that could affect the result, but this is a big and unexpected reduction in the Pension Regulator's powers.

21 January 2011

Competition: bite the hand that feeds you

Would you have done the right thing?

RBS has been fined £28.59m by the OFT for supplying information on its pricing of loans to professional practices over a four-month period. Ouch!
A specialist team provided the information to Barclays. Barclays shopped them to the OFT, and by doing so escaped a fine and damaged its competitor. This is now the pattern – whistleblowers get off scot-free, so there is every incentive to be the first to rat.
Banks should know better, but smaller businesses are often not alive to competition issues. The occasional chat or bit of co-operation through a trade association seems only natural. Just think what might happen if your competitor goes to the OFT. Should you go first?
£28.59m! I wonder what the .59 was for.

18 January 2011

Why try to save money on legal fees?

Partner rates skyrocket at top firms despite economic gloom [1]




[1] The Lawyer 20 September 2010

"Magic circle partners are again charging as much as £725 per hour… five-year PQE associates now charge an average of £450-£550… US firms in London broke through the £600 barrier… some [City partners outside the magic circle] are now charging an all-time high of £640… national firms have… partners charging between £325 and £350 and five-year associates between £250 and £300." full article
Are those rates good value for money? Or is it worth saving money by finding the same levels of expertise at much lower rates?
Virtual law firms such as Excello Law can offer the experience of big firm partners at much lower rates – often half those of big firms with equivalent expertise. And law firms who bring in independent consultants like me only when needed can also be profitable at lower hourly rates.

12 January 2011

More stats – what do they mean?

Public deals up, private deals down

There were 34 public takeovers (listed and AIM) in 2010, compared to only 21 in 2009.[1] That may reflect the effect of surging stock markets, with companies looking to use the value of their paper to make acquisitions.
But if so, it hasn’t trickled down to unlisted companies. Q3 statistics show only 38 acquisitions of independent UK private companies over £1m.[2] That must be an under-estimate, but the level of activity is still paltry, and a decline on Q2.
Good news for everyone except insolvency practitioners: corporate insolvencies were down to 15,894 in 2010, a fall of 3,618 on 2010, with Q4 figures down 19% on Q4 2009 and down 6% on Q3.[3] Ever since the beginning of the recession people have been predicting a huge surge in insolvencies in three months’ time, but there is no evidence of it happening, or that it ever will. Corporates are limping out of the recession, slowly rebuilding their balance sheets, and lenders are waiting patiently for their customers to recover, taking the modest profits and leaving the equity holders waiting more patiently still. HMRC may be trying to claw back their time-to-pay arrangements, but there is little evidence that they are aggressively pushing companies under; now that they are ordinary unsecured creditors, they don’t get much out of a liquidation.








[1] Source: PLC
[2] Source: ONS

06 January 2011

Defamation and archives

Unacceptable publications: falsifying the record?

One problem we are having to grapple with increasingly in the internet age is that of archives. In the past, if a book contained illegal or defamatory material, you would supress its further publication, but it took too much effort to engage in book-burning, and libraries would probably retain their copies. No-one would attempt to get back all copies of last week's newspaper, or to fillet the publisher's archive. In the internet age we have semi-permanent, searchable, global access to almost anything, so the damage done continues long after publication of even the most ephemeral comment. How far is it acceptable to require filleting of archives to remove illegal or defamatory material? When does falsifying the record become worse than dissemination of the unacceptable material?

Where’s my Blackberry?

Data protection comes of age – is your law firm taking it seriously?

It’s hilarious, isn’t it? MI6 officer leaves his laptop in a cab. HMRC loses unencrypted data disk in the post. Building society employee’s computer is nicked from his home. Medical records found in car park. Council loses children database on memory stick. Only this week, sensitive Scottish court records discovered at recycling bank. There are so many of these stories, and we all enjoy a laugh at the incompetence of these large organisations in protecting our personal information. After all, this only applies to big, faceless institutions managing huge databases – doesn’t it?
Data protection law has been around for a long time, but it hasn’t been taken terribly seriously by anyone outside of large data centres – except as an excuse to not tell anyone anything: “can’t answer that – data protection”. We used to tell our clients not to worry unduly – make sure you register, but if you get anything wrong all you will get is a telling-off and guidance on how to do better next time.
But now data protection has come of age. Sit up and take notice. In November the Information Commissioner’s Office (ICO) levied its first fines, under stronger powers given it last year. Hertfordshire County Council was fined £100,000 for inadvertently sending child protection case papers by fax to the wrong number. Who hasn’t sent a fax or email to the wrong address? Yet the council should, apparently, have had procedures to stop this happening. What procedures, exactly?
The second fine was even more concerning for businesses. A private company, A4e, was fined £60,000 for the loss of a laptop, stolen from an employee’s house, containing unencrypted data on 24,000 people.
Data protection doesn’t only apply to big databases – the Hertfordshire case concerned only a handful of people, though the information was of the most sensitive kind. It doesn’t only apply to professional data processors; it can apply to any business. And good intentions aren’t enough: failure to have adequate security and procedures can lead to large fines, even with the intervention of errors or criminals. Keeping data on a PC inside a locked private house wasn’t good enough protection.
That led me to think about the attitude of the legal world. Solicitors take client confidentiality very seriously, in terms of their own conduct, but many have not translated that into action on data security or, for that matter, physical security. They think of it as a duty to the client, but not about the other data subjects who may be referred to in their files. Legal practices hold vast amounts of personal data, much of it of a highly sensitive nature. Deeds and will may be kept in a safe, but there is little or no security on paper files, which are stored openly, carried around on public transport and taken home. Many lawyers’ computer systems have no security on internal access to data beyond an access-level password. They have firewalls and virus protection. But usually no protection at all against unauthorised access or copying by legitimate users of the system, or anyone in possession of their passwords. Data is not segmented or internally password-protected.
Access to the servers from the internet is usually tightly controlled, but once in, there are no restrictions on access to client data. Unencrypted email is universally used for almost all communication, and unencrypted attachments are sent that could include large amounts of personal data. Worst of all is the approach to home and mobile working. Data may be freely transferred to work or personal laptops and mobile devices. Mobile devices with weak passwords or PIN numbers allow access to the entire system, or at least to email records.
Solicitors have always relied on their integrity and professional conduct to enforce confidentiality. Systems are devised to prevent casual disclosure of information, but they are not designed to withstand deliberate, criminal attack. Most solicitors would feel that there is not much chance that they will be victims of deliberate espionage or malicious attacks.
Then there was the ACS Law case, in September 2010. ACS, a small law firm, acted for copyright holders trying to sue P2P file sharers for copyright infringement. It got court orders against ISP’s forcing them to disclose lists of users with details of internet usage, allegedly including their access to pornography. BT, and possibly others, sent the data to ACS as unencrypted email attachments – Excel spreadsheets. You wouldn’t have done that – would you? Then the libertarians of the file-sharing community mounted an illegal denial-of-service attack on ACS’s website. In attempting to restore the site, ACS’s IT people accidentally allowed access to internal data, including their email archive – which was promptly stolen and distributed across the net. ACS could yet be fined up to £500,000 for this breach. Clearly that should not have happened. But it was a mistake, made by a technical person. How is a law firm supposed to supervise an IT specialist to make sure he never allows external access to data?
More worrying still, the unencrypted attachments were the main source of the data stolen. What could ACS have done to protect that information? It naturally archives its emails, even if deleted by its users. It also backs up the archive and everyone’s inboxes. So multiple copies of any attachment will be created, even if the user did not save the attachment – or correctly saved it with a password.
This is the heart of the problem for law firms. We deal in evidence. We are instinctively more worried about losing access to data than we are about others gaining access. People leave, and passwords get forgotten. We lawyers hate to throw anything away. We get sued if we can’t prove exactly what advice we gave to Mrs Jones on the phone in 2005, or we can’t explain why clause 24 was deleted in draft 3, or we forgot the family history told to us five years earlier. Professional standards such as Lexcel require us to ensure that other people in the firm have access to client information if the lawyer is absent for any reason. The drive to be efficient and keep costs down requires us to share information quickly.
Part of data protection is the deletion of data that is no longer required, but I have yet to meet a lawyer who thought that any document or record could be discarded. Try persuading them that they should be deleting all records of incoming emails from the other side in litigation because they contain personal data! It’s evidence in the case.
So what should we be doing? The ICO’s guidance is quite clear, and it does not match with what many lawyers have been doing. Review your security with an eye on protecting the privacy of all data subjects, not just your client. Make sure your data is secure even if someone steals your PCs or servers. Identify particularly sensitive items, either because of the nature of the information or the number of data subjects, and take particular precautions, including password-protecting individual documents and preventing their removal from the office, in hard copy or unencrypted electronic form. Ban anyone from working on computers outside the office unless all client data is stored on an encrypted drive with a strong password. Prevent anyone from transferring data to CD or memory stick without getting authorisation, to include checking the security of the data. Promote a culture of data security, including password security.
For now, this will still be an imperfect solution. We need to communicate with outside parties and to transfer data to them. Email encryption is still not widely accepted in the world at large, due to the need for both parties to operate the same system, so email traffic is likely to remain vulnerable in transmission. Make sure your records of incoming and outgoing emails are stored on encrypted drives and that your access passwords are strong, and not remembered by the user’s PC – which Outlook rather encourages. Check that your backups of data are as secure as the originals. If necessary, implement a password management system to securely record the passwords needed to access protected data.
I have done all this myself, now I am working at home, to give clients and data subjects the best protection possible against unauthorised access to my home PC, laptop or smartphone, my wireless network or my email communications. I tell my clients to anonymise bulk information they may send me about their employees or customers wherever possible, and to password protect the information. But no-one has yet shown me how to prevent the mis-keying of a fax number, the loss of a document in the post or accidentally attaching the wrong file to an email. At least by being seen to try, we should be protecting ourselves from the savage criticism that will flow from doing nothing.
I should say that nothing in this article relates in any way to any of the firms I work with – I have no cause for concern about any of them.

31 December 2010

Discretionary dividends

Allocating dividends unequally across shares in a company

Gerry Jackson of Critchleys made an interesting blog post yesterday reminding us that paying dividends is almost always more tax-efficient for owner-managers than paying bonuses.
I commented about giving the directors a discretion to pay different dividends on separate classes of shares. We corporate lawyers often get asked by tax advisers to change the articles to do that. It allows the company to pay dividends otherwise than in proportion to shareholdings, either to maximise tax-efficiency or to reward contribution to the business – close to being disguised remuneration. But it has legal implications:
  • Directors have duties to act in the interests of the company and to treat shareholders fairly, which usually means equally, and the exercise of discretion in any other way could be criticised later or challenged in court.
  • It becomes difficult to value any particular block of shares, as the dividends attached to them vary depending on the exercise of the discretion. That difficulty could be exploited by HMRC in some circumstances: see (for instance) example 3 in the HMRC manual on "Securities with Artificially Enhanced Value". The value of the shares may go up and down depending on the history of dividend declarations, and there is no guarantee that the holder will get the same price per share as other shareholders when the company is sold.
  • HMRC may attempt to characterise dividends as disguised remuneration, depending on how the discretion is exercised.
  • HMRC may seek to attack discretionary dividends under the settlements legislation, especially when the beneficiary is the spouse, civil partner or minor child of the person not receiving the dividend: see the HMRC manual on this. 
  • The power to allocate dividends could be abused by directors. Even if the shareholders are directors, decisions could be made by a majority or if a director were absent. Except possibly in husband and wife companies, some protection is usually advisable, and I have some strategies to achieving that protection.
Two further points to add about taking remuneration as dividend. First, it may reduce the amount you can claim on dismissal, including following insolvency, or affect the amount of the pension contributions you can make. Second, remember that dividends have to be covered by distributable profits. My insolvency practitioner friends all have stories of unfortunates who continued to pay themselves by dividend as the company started to make losses, only to have the dividends reclaimed after the company went down.

30 December 2010

How can I sell my business?

The state of the mergers and acquisitions market
for private companies in the UK


As we enter 2011, is there hope on the horizon for entrepreneurs looking for an exit?
Not much, it seems. The national statistics and the mood amongst corporate finance professionals show the same gloomy picture for M&A activity. Q2 2010 saw only 47 UK acquisitions of independent UK companies over £1m  – perhaps one for every four law firms specialising in this work!
There is little doubt that the UK corporate sector is recovering from recession. In many sectors, notably those manufacturing for export, modest profitability and stability has returned . But that is not fuelling acquisition activity, and it remains very hard to sell your business.
The key to the problem is bank lending. UK banks continue to be extremely cautious, and are generally not willing to support expansion through acquisition, nor to provide leverage for private equity investment. That destroys the investment model for private equity – without a high level of debt, the investor cannot make the equity returns needed. Although the banks say their approval levels are at record highs, bank lending is focused on supporting existing customers and avoiding driving businesses under. The UK clearers have also had to take up lot of capacity from foreign banks withdrawing from the market, notably the Irish banks.
Almost all buyers need funding, and there are still no obvious alternatives to the banks. As most of the world has the same problems, there has been no influx of foreign lenders. In the old days the fall of sterling might have attracted them, but not now. Nor are foreign buyers flocking to the UK. Cash buyers should be able to pick up bargains, but those with cash are hoarding it, perhaps concerned about whether they will be able to raise finance for their own businesses over the next few years.
In the past, rising stock markets have led to booms in acquisitions by listed companies, but that isn’t happening either. The record sums being raised are going to bolster corporate balance sheets and reduce dependence on bank funding. There are some signs of personal or corporate cash balances being used to provide debt funding to corporates, cutting out the banks as middlemen, but not on the scale needed to make a difference.
Uncertainty and lack of business confidence make potential buyers or private lenders just as wary as the banks’ credit committees, so prices are driven down and even good businesses struggle to convince investors of their prospects. The uncertainty flowing from the public spending cuts is particularly destabilising.
In the SME market there is now a backlog of entrepreneurs looking to exit or retire, and few prospects for realising value. Most deals we are seeing are self-funded partial exits, with vendors handing over to a new generation of management for a deferred price paid out of the company’s cashflow. Inevitably that limits the price the seller can expect for his lifetime’s work, and leaves him with much of the risk while sacrificing the upside. The beneficiaries should be the next generation of management, who can gain ownership with little personal risk and good long-term prospects. We keep hoping for an improvement, driven by competition from outside the UK banks, but it isn’t here yet.
So for the time being there are bargains to be had, but few buyers with the resources to pick them up.

[1] Office for National Statistics Statistical Bulletin: Mergers and acquisitions involving UK companies 2nd Quarter 2010
[2] Eg CBI press release 18 November 2010 Demand improves for UK-made goods