TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

United Kingdom - England & Wales Global Crisis Management Regulatory Guide Guide

Date posted:
09/10/2022
Last update:
09/10/2022

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

In the UK there are a several potential notifications required following a personal data breach, subject in some cases to threshold tests. The UK Information Commissioner's Office, ICO, should be notified unless a data breach is likely to result in harm as should any professional regulators for regulated businesses – subject to their rules. Data processors can also face a requirement to notify data controllers. It may be necessary to notify data subjects if there is a risk of harm. It can be advisable to notify Action Fraud in the UK of any cybercrime – who triage information for the Police. This is not mandatory.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

Following Brexit, the UK GDPR applies which is broadly a retained copy of the EU GDPR. The Data Protection Act 2018 also applies.

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

List: - HM Revenue & Customs: Police and Criminal Evidence Act 1984/Serious Organised Crime and Police Act 2005

  • The Financial Conduct Authority: Financial Services Act 2000

  • The Prudential Regulation Authority: Financial Services Act 2000

  • Information Commissioner’s Office: Data Protection Act 2018

  • The Serious Fraud Office: Criminal Justice Act 1987

  • The Competition and Markets Authority: Competition Act 1998

  • The Police: Police and Criminal Evidence Act 1984

  • Health and Safety Executive: Health and Safety at Work Act 1974

  • Environment Agency: Environment Act 1995

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

List: - A company may refuse the seizure of documents that are “privileged”.

  • There is usually little scope to refuse the seizure of documents on the grounds of confidentiality alone.

  • A company may refuse to allow the seizure of documents which are outside the scope of the investigation. Check the wording of the search warrant (or equivalent document), specifically any limitations, such as:

    • date ranges
    • custodians, and
    • subject matter.
  • Common practice is for any disputed documents to be placed in a sealed envelope so that arguments regarding privilege and/or scope may be addressed after the dawn raid.

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

List: - Workers have special legal protection when they report an alleged wrongdoing at work if it is a “qualifying disclosure”1. Whether or not a disclosure is protected also depends how and to whom the disclosure is made.

  • A “qualifying disclosure”2 is a disclosure of information which relates to one of six types of “relevant failure” (including criminal offences and civil wrongs) where the worker has a reasonable and genuine (albeit possibly wrong) belief that: (i) the information demonstrates a relevant failure; and (ii) disclosure is in the public interest.

Hide note

  1. S. 43A Employment Rights Act 1996.

  2. S. 43B Employment Rights Act 1996.

What legislative protection does that employee enjoy?

List: - Protection under the Employment Rights Act 1996

  • Workers have the right not to be subjected to any detriment on the ground of having made a protected disclosure. Claims can be made against the employer and/or against other workers individually.

  • Employees have an automatic unfair dismissal claim if the principal reason for their dismissal is that they made a protected disclosure.

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

The Bribery Act 2010 – this covers bribery of public officials and commercial bribery. The most significant offence for corporations is failing to prevent bribery. The only available defence for a corporate is if it can prove that it had “adequate procedures” in place to prevent the bribery that took place.

Does the legislation have extra-territorial effect?

Yes. It applies to persons with a close connection to the UK and companies that carry on or have a part of their business in the UK. Within that context, any acts of bribery that take place anywhere in the world with the intention of obtaining a business advantage for the company will constitute a breach of the Bribery Act and may be prosecuted in the UK.

What are the main enforcement bodies?

List: - The Serious Fraud Office investigates and prosecutes serious and/or complex fraud, bribery and corruption matters in England, Wales, and Northern Ireland.

  • The police and Crown Prosecution Service will investigate and prosecute all other types of fraud, bribery and corruption in these jurisdictions.

Internal investigations

Is there any duty to report the issue, for example to a regulator?

List: - When an issue arises, a company should consider its self-reporting obligations. These will vary, depending upon:

- the identity of the agency/agencies that regulate the company

- the nature of the issue

- the seriousness of the issue, and

- what is known about the issue at that time.
  • We set out below considerations relating to the key UK agencies:

The National Crime Agency

Regulated sectors under the Proceeds of Crime Act and Terrorism Act 2000; if there is a suspicion of money laundering, a Suspicious Activity Report should be made to the National Crime Agency. The report should be made immediately via the National Crime Agency’s website.

The Serious Fraud Office

There is no obligation to self-report fraud, bribery and/or corruption to the Serious Fraud Office. However, self-reporting may assist in persuading the Serious Fraud Office that a prosecution would not be in the public interest and a deferred prosecution agreement would be more appropriate.

HM Revenue & Customs

The Criminal Finances Act 2017 introduced the Corporate Criminal Offences (CCO) under which companies can be rendered criminally liable if persons associated with the company fail to prevent the facilitation of tax evasion. Self-reporting is voluntary. However, where it is discovered that this failure to prevent has occurred, self-reporting may be taken into account by prosecutors considering prosecution and may lead to the offer of a deferred prosecution agreement. If charged, self-reporting may be used as a part of the company's reasonable procedures defence and can be reflected in any penalties imposed.

The Office of Financial Sanctions Implementation

Relevant firms are legally obliged to report to the Office of Financial Sanctions Implementation (OFSI) as soon as practicable if they know or suspect that a breach of financial sanctions has occurred, that a person is a designated person, or that they hold frozen assets and that knowledge or suspicion came to the firm while conducting its business. Such a report may result in a reduction in penalty.

The Competition and Markets Authority

If the issue relates to a competition law infringement, self-reporting to the Competition and Markets Authority (CMA) should be considered. While there is no legal obligation to report, the CMA operates a leniency policy that can provide the first self-reporting company involved in a cartel with a reduction in a fine or even total immunity from a fine. The timing of any leniency application therefore can be critical. The cartel criminal offence only applies to individuals and not companies. However, the CMA can grant immunity from prosecution.

The Financial Conduct Authority

Firms authorised by the Financial Conduct Authority have self reporting obligations under the FCA Supervision Manual (SUP 15). These require a firm to notify the FCA if certain issues arise, including any involvement in fraudulent activity (including if the company is a victim of fraud), or an issue that could have a significant adverse impact on the company’s reputation and/or could result in serious detriment to its client.

Publicly Listed Companies

Firms whose shares are traded on a regulated market in the UK may have to make an announcement to the market. Such companies are required to disclose “inside information” (non-public information that would be likely to have a significant effect on the company’s share price if it were made public) to the market as soon as possible.

The Information Commissioner’s Office

See the section above on data breaches.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

List: - Documents generated as part of the investigation will generally not be disclosable if they are privileged. There are two relevant types of privilege under English law:

- Legal advice privilege protects all communications between a lawyer and client created in the context of seeking legal advice. Where the client is a company, the protection only applies to communications with the individuals authorised to seek legal advice on behalf of the company in relation to the investigation.

- Litigation privilege may protect documents/communications if they are: (i) created for the **dominant purpose of litigation**; (ii) that litigation is reasonably in contemplation at the time the document is created; and (iii) the litigation is adversarial in nature. Litigation privilege applies to communications between any employees of the company, third parties and/or legal advisors.
  • It is possible for privilege to be lost or waived unless arrangements are put in place to maintain privilege once it has been established.

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

Generally, advice given by an in-house lawyer regarding an investigation is confidential and privileged, if structured correctly. At the outset of an investigation, it is most likely that legal advice privilege will apply (see above). However, if litigation becomes likely as the investigation develops, then litigation privilege will also become likely to apply.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.