TerraLex Cross-Border Guide to Global Crisis Management Regulatory Guide

Welcome to the TerraLex global crisis management regulatory guide

When a crisis hits your organisation, you need to take action quickly. What practical steps can you and your team take to minimize the impact on your business? What are your reporting requirements in the relevant jurisdiction(s)? What legislation applies there?

Our guide provides you with the answers to these questions in relation to key jurisdictions and it supports your understanding of the relevant local legal framework. It also provides high level practical guidance for those crucial first 72 hours, together with contact details of the local TerraLex firm for when you need specialist advice.

A crisis, by its nature, is both serious and unexpected and your response and actions within the first 72 hours will most likely define its impact on your organisation.

It is therefore important to have in place robust procedures that, if followed, will help minimize the adverse consequences.

The crisis checklist below includes next steps which are common across all jurisdictions. Please refer to the chapter for the relevant jurisdiction for more detailed guidance on your obligations in that country.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

United States / North Carolina Global Crisis Management Regulatory Guide Guide

Date posted:
09/10/2022
Last update:
09/10/2022

Data breach

On discovering a data breach, which regulators or other government agencies should be notified?

List: - Once the extent of the incident is understood and the affected parties are identified, counsel will need to evaluate whether a data breach has occurred according to the legal framework of the states in which the affected customers reside. Unauthorized access to certain types of data by a third party may automatically trigger a notice obligation in some states, while other states require a risk of material harm to the affected party as a result of the unauthorized access. What is considered “personal information” or sensitive data in one state, such as name and physical address, may not be considered personal information in another state and give rise to a notice requirement.

  • Under North Carolina law, a security breach is defined as either: (1) unauthorized acquisition of unencrypted data containing personal information where illegal use of the personal information has occurred or there is a material risk of harm; or (2) unauthorized access and acquisition of encrypted data containing personal information and the encryption key. Once it is determined that a breach has occurred under the affected parties’ state law, each state law will also need to be examined to determine if notification to the affected party must be made as well as notice to that state attorney general or other government office. If a breach occurs in North Carolina, notifications must be sent to the North Carolina customers and to the North Carolina Attorney General.

  • All businesses should consider whether it is appropriate to notify local law enforcement or federal agencies such as the Federal Bureau of Investigation or U.S. Secret Service. Certain businesses may also have notification obligations to federal regulators, including the Securities and Exchange Commission and/or law enforcement. In the case of certain types of information, such as protected health information, a business may need to notify the Federal Trade Commission and/or the U.S. Department of Health and Human Services. Businesses may also have obligations under international laws including the European Union’s General Data Protection Regulation.

What legislation, relating to both criminal offences and civil wrongs, covers such a breach?

Data Breach notification is regulated in North Carolina pursuant to the Identity Theft Protection Act of 2005, codified at N.C. Gen. Stat. §§ 75-60.

"Dawn" raids

What agencies have the power to conduct dawn raids on private sector companies? What legislation gives those agencies the power to undertake those inspections?

In the very general definition of the term, the number of agencies that have the power and authority to conduct dawn raids is as plentiful as the number of agencies that exist. All law enforcement agencies including the FBI, Secret Service, and Interpol can petition a magistrate with evidence and allegations that establish probable cause and can be granted a search warrant to examine the contents of offices and seize relevant documents.

  • The legislation that empowers investigating agencies to conduct dawn raids include, among many others, the International Antitrust Enforcement Assistance Act, the Sherman Antitrust Act, the Clayton Antitrust Act, and the Federal Trade Commission Act (United States).

  • It is worth noting that in the United Sates enforcement agencies may elect not to conduct a dawn raid and can compel production of documents or information via a civil investigative demand or a subpoena.

On what bases, including privilege and/or confidentiality, may organisations refuse to permit the seizure of documents?

The issue of the search and seizure of privileged documents is as complex as the laws of competition themselves and vary widely from jurisdiction to jurisdiction. The United States allows great deference to materials protected by the attorney-client privilege and the attorney work product doctrine.

Whistleblowing

What are the circumstances under which an employee is entitled to protection when reporting an alleged wrongdoing?

If a publicly traded company or federal agency takes or threatens to take an adverse personnel action against an employee in retaliation for the disclosure of information by that employee, the entity can be sanctioned and financial remuneration can be awarded to the whistleblower. Further, the U.S. Supreme Court has held that whistleblower protection applies to employees of privately held contractors and subcontractors of public companies.1 Pursuant to Dodd-Frank, the whistleblower must voluntarily provide the SEC with original information that leads to the successful enforcement by the SEC in which the SEC obtains monetary sanctions totalling more than $1 million.

Hide note

  1. Lawson v FMR LLC, 571 U.S. 429

What legislative protection does that employee enjoy?

The Whistleblower Protection Act protects federal employees who report violations of various federal statutes. OSHA’s Whistleblower Protection Program enforces the whistleblower provisions of more than twenty whistleblower statutes protecting employees who report violations of various workplace safety and health laws, among others.2 The SEC pursuant to § 922 of Dodd-Frank, supports a whistleblower program that rewards individuals who provide the agency with “high-quality” tips that lead to successful enforcement actions. Whistleblowers are financially incentivized to report financial misconduct. The amount awarded to a successful enforcement by a whistleblower is required to be between 10% and 30% of the total monetary sanctions collected in the SEC’s action or any related action, such as in a criminal case.

Hide note

  1. https://www.whistleblowers.gov/

Anti-bribery and corruption

What are the main anti-corruption laws and regulations in your jurisdiction?

List: - The main anti-corruption law that U.S. companies and individuals must be concerned about is the Foreign Corrupt Practices Act (FCPA). This statute has been in place since 1977 and has been rigorously enforced over the past decade. Enforcement penalties and fines levied under the FCPA for 2018 will likely top $2 billion, so it is an important statute to be aware of for companies conducting international business.

  • Although the FCPA is the primary anti-corruption statute in the United States, many other countries have passed anti-corruption legislation in the last decade, and U.S. companies should be aware of any applicable statutes in the countries they do business in. Notably, the United Kingdom passed the U.K Bribery Act in 2011 and is beginning to enforce the statute more aggressively.

Does the legislation have extra-territorial effect?

List: - The FCPA has a very broad extraterritorial reach. The FCPA governs the conduct of “domestic concerns” and “issuers.” Domestic concerns are defined as “any individual who is a citizen, national, or resident of the United States, or any corporation, partnership, association, joint-stock company, business trust, unincorporated organization, or sole proprietorship that is organized under the laws of the United States or its states, territories, possessions, or commonwealths or that has its principal place of business in the United States.”3 A company is an “issuer” under the FCPA if it “has a class of securities listed on a national securities exchange in the United States, or any company with a class of securities quoted in the over-the-counter market in the United States and required to file periodic reports with SEC.”4 Thus, foreign companies can be, and often are, “issuers” for purposes of the FCPA.

  • In addition to applying to conduct occurring within the United States, all conduct by domestic concerns and issuers that uses any means of interstate commerce (including mail, phone lines, bank transfers, travel, etc.) that furthers a corrupt payment to a foreign official is also subject to FCPA jurisdiction. In practical terms, it is hard to imagine acts related to the bribery of a foreign official that are committed by a domestic concern or issuer that would not be subject to FCPA jurisdiction, even if the conduct did not occur on U.S. soil.

Hide note

  1. A Resource Guide to the Foreign Corrupt Practices Act, p.11. Available at www.justice.gov

  2. Id.

What are the main enforcement bodies?

The FCPA is jointly administered by the U.S. Department of Justice (DOJ) and the Securities and Exchange Commission (SEC). Both agencies have actively enforced the statute over the last decade.

Internal investigations

Is there any duty to report the issue, for example to a regulator?

List: - Generally, employers do not have a duty to report criminal conduct by their employees. However, every day federal and state prosecutors indict criminal conduct committed by or on behalf of corporations. Every Deputy Attorney General (“DAG”) since the late 1990’s has promulgated guidelines regarding the prosecution of corporations. In 2015, in a memorandum titled “Individual Accountability for Corporate Wrongdoing” released by then DAG, Sally Yates, the United States Department of Justice committed to prosecuting both culpable individuals and, when appropriate, the corporation on whose behalf they acted. In order for the corporation to receive credit for cooperation in reporting criminal conduct, the corporation must “provide to the [DOJ] all relevant facts about the individuals involved in corporate misconduct.” During a speech on November 29, 2018, DAG Rod Rosenstein announced changes to the DOJ policy concerning individual accountability in corporate cases. His focus now includes senior management and members of Boards of Directors.

  • Also, in many cases, for example in environmental-related matters, there is an obligation on companies to report illegal or unethical behavior to its regulators or face severe sanctions. This often requires an internal investigation by outside counsel.

What is the protection from disclosure for documents generated as part of the investigation (for example, privilege)?

There are a number of protections from disclosure available to various industries. For example, 12 CFR 261.20 strictly protects supervised financial institutions and financial institution supervisory agencies’ confidential supervisory information (CSI) from disclosure to third parties. In an internal inquiry related to a criminal investigation, the DOJ, pursuant to updates to various DAG memos, is prohibited from requiring the waiver of privileged material to achieve cooperation credit. However, this is a heavily nuanced and sometimes litigated issue. The DOJ’s position is that facts are not privileged; however there is an underlying question as to whether the attorney’s ability and work product in uncovering certain facts privileged.

Is the advice given by an in-house lawyer in relation to the investigation privileged and/or confidential?

This depends. Often, in-house counsel wears a number of hats during their work day. A corporate Board secretary may be a lawyer who provided legal advice but may also give non-legal advice related to furthering the cause of a business. Typically, a privilege holder who communicates with in-house counsel for the purpose of receiving legal advice can assert the privilege of an in-house counsel’s legal advice provided, of course, that the in-house counsel is a lawyer and is acting in his/her capacity as an attorney.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.