Sarbanes Oxley Europe: The EU Data Protection Directive vs. Sarbanes Oxley Whistleblower Protection

The Sarbanes-Oxley Act of 2002, adopted as areporting service for employees to use anonymously,
reaction to corporate scandals, has a significant impactand 2. A Data Protection control: Data subjects must
on European companies. The reason is simple:learn, rectify, erase or block incorrect data about them.
Hundreds of European-headquartered companies areThe problems
dually listed on two stock exchanges, one in EuropeOn 14 June 2005 the French Data Protection Authority
and the other in the United States. 470 non-USrefused to authorize the use of anonymous
companies are listed on the New York Stockwhistleblower hotlines. The French Authority's view
Exchange, with a combined market capitalization ofwas that such hotlines are "disproportionate to the
$3.8 trillion, 30 per cent of the total value ofobjectives sought and the risks of slanderous
capitalization of companies quoted on the exchange.denunciations and the stigmatization of employees
EU Data Protection DirectiveWhat is personal datawho were the subjects of an ethics alert."
(according to EU)? Personal data can be anyIn a similar decision a German labor court ruled that
information relating to an identified or identifiable naturalparts of an employee code of conduct inviting
person (directly or indirectly): Name, telephone number,employees to report misconduct to a whistleblowers
photos. Data specific to his physical, physiological,hotline breached German labor law.
mental, economic, cultural or social identity. What isEarly indications from the UK Information
processing of personal data? Any operationCommissioners Office (ICO) are that they would
performed upon personal data whether or not bydecline to follow the French and German approach. In
automatic means.contrast to the French and German decisions, the
Data Controllers must adhere to the following rules:ICO's view is that the appropriate use of such helpline
Data must be relevant and not excessive in relation toby organizations would not, in principle, raise data
the purpose for which they are processed. Data mustprotection concerns. However, where organizations
be accurate. Data controllers are required to providemisuse such anonymous hotlines for inappropriate
reasonable measures for data subjects to rectifyinformation gathering purposes there may be data
erase or block incorrect data about them. Theprotection implications.
directive prohibits transfer of personal information toRecommendations
countries outside the EU, which lack adequateCompanies that are publicly traded in the United States
protection of privacy.and also have operations in the European Union must
Sarbanes OxleySection 301. Public company auditbe very careful with the whistleblower provisions of
committees: Each audit committee shall establishthe U.S. Sarbanes-Oxley Act of 2002.
procedures for: (A) The receipt, retention, andFirst of all, before implementing Sarbanes Oxley hotline
treatment of complaints received by the issuerreporting services, companies need to ask for
regarding accounting, internal accounting controls, orpermission from the local Data Protection Authority.
auditing matters; and (B) The confidential, anonymousComplaints must be processed inside the European
submission by employees of the issuer of concernsUnion. Companies need to establish local investigation
regarding questionable accounting or auditing matters.procedures. The suspected person would be given the
The challengeopportunity to comment within two days. In the event
How a US company with offices throughout the EUthat the investigation shows that the allegations were
can comply with the notice and choice principles of EUunfounded, the data must be deleted within two days
Data Protection laws while simultaneously complyingof the case closure. If the allegations are determined to
with the whistle blower requirements under Sarbanesbe well-founded, then the file would be kept for one to
Oxley?five years after the case was closed (depending on
How can we have both: 1. A Sarbanes Oxley hotlinemanagement level).