Refine By
Clear all filter
About 91966 results for "*"
PRACTICE NOTES
Even with robust and effective internal complaints handling, it is likely that at some point, a law firm will experience escalation of a complaint to the Legal Ombudsman (LeO). This How-to-guide provides practical guidance on handling complaints referred to LeO. When are complaints referred to LeO? See Practice Note: Legal complaints handling—regulatory bodies—Legal Ombudsman for guidance about who can complain to LeO. Generally, a complainant can only go to LeO where they have used the firm’s internal complaints procedure by making a complaint either orally or in writing, and they: • are not satisfied with the final written response • have not received a final written response to their complaint from the firm within eight weeks For guidance on implementing and maintaining effective complaints handling procedures, see Practice Notes: How to implement and maintain effective complaints handling procedures—law firms and How to handle a complaint step by step—law firms. LeO has discretion to consider complaints which have not been directed to the firm, eg where there has been
PRACTICE NOTES
This Practice Note is intended for law firms. It explains how you can handle a complaint from receipt to resolution using the Legal Ombudman’s (LeO) Model Complaints Resolution Procedure (MCRP), while continuing to comply with relevant regulatory requirements. It is intended to support those responsible for managing complaints within your firm. The MCRP is a voluntary framework for handling complaints about legal services. It is intended to help firms deal with complaints fairly, consistently and as quickly as possible, with an emphasis on resolving concerns at the earliest appropriate opportunity. The MCRP does not replace the regulatory requirements applying to you. In particular, if you are a SRA-regulated, you must ensure that complaints are dealt with promptly, fairly and free of charge. For detailed guidance on the regulatory framework, see Practice Note: Complaints—law firms. For more information on the MCRP, including its five core features, timescales and issues to consider when deciding whether and how to adopt it, see Practice Note: The Model Complaints Resolution Procedure—law firms. For guidance
PRACTICE NOTES
This Practice Note is intended for private-sector commercial organisations in the UK. It provides guidance on handling data protection complaints under the UK GDPR. Data subjects have the right to complain to you if they believe you have handled their personal data in a way that breaches the UK GDPR. They also have the right to lodge a complaint with the ICO. The right to complain Data subjects have the right to make a complaint directly to your organisation if they believe you have handled their personal data in a way that breaches the UK GDPR. Data subjects are also entitled to lodge a complaint with the ICO and they can do so via a not-for-profit body, organisation or association. The ICO is required to investigate complaints to the extent appropriate and inform the complainant of the progress and outcome of the investigation within a reasonable period. Generally, the ICO will not deal with a request unless it has first been made to your organisation. Complaint or exercise of data subject right? You
PRACTICE NOTES
This Practice Note is intended for private sector commercial organisations in the UK. It provides practical guidance on how to handle data subject requests under the UK General Data Protection Regulation (UK GDPR). It explains some common features of all data subject requests and the issues that can arise when handling a data subject request. This Practice Note also considers compliance strategies to best equip your organisation to manage the process for dealing with data subject requests. Individuals have a number of rights in respect of their personal data under the UK GDPR: • a right of access • the rights to rectification, erasure and restriction of processing • a right of data portability • a right to object to processing For more guidance, see Practice Note: Rights of data subjects. A data subject can make a request to a data controller to exercise one or more of these rights at any time. They do not need to explain their reasons for making a request and there are strict time limits
PRACTICE NOTES
You should have processes whereby staff must report (usually to the nominated officer) knowledge or suspicion of: • money laundering, terrorist financing or proliferation financing • sanctions breaches • fraud • tax evasion • bribery and corruption • organised crime See further section: Mitigating the risk. The nominated officer is then under an obligation in certain circumstances to report that knowledge or suspicion to the National Crime Agency (NCA) through a suspicious activity report (SAR) (or, dependent on the nature of the report, to another agency through appropriate channels). The NCA allocates SARs to trained financial crime investigation officers for further investigation. Intelligence from SARs may then be disseminated by the NCA to other law enforcement or government agencies (LEAs), which may need further information. Where additional information is required by LEAs following a SAR, it will generally be obtained through enforcement action (usually a production order). This How-to guide provides guidance on handling financial crime investigations and considers related issues such as client confidentiality, legal professional privilege and whether a production
PRACTICE NOTES
This short ‘how to guide’ sets out the steps to be followed where a company has reason to believe that a person is a registrable person with significant control (PSC), a registrable relevant legal entity (RLE), or has knowledge of the identity of a PSC or RLE, but that person fails to provide the required information. This guide also sets out the statutory notices as provided for by the Companies Act 2006 (CA 2006) as well as the Companies House notifications and considers the use of the restrictions regime to encourage disclosures. For the purposes of this guide, a PSC is ‘non-responsive’ if they fail to provide the required information to a company for the purposes of keeping the central PSC register up to date. For more information on the PSC regime, see Practice Notes: PSC register—guidance for PSCs and RLEs and PSC register—the people with significant control regime. Key legal and operational background Since 6 April 2016, it has been necessary for a company (and certain other types of entity) to collect and record information
PRACTICE NOTES
This How-to guide provides high-level practical guidance on direct marketing, in particular how to comply with the UK General Data Protection Regulation (UK GDPR) and Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR 2003). More detailed guidance can be found in Practice Note: Direct marketing compliance. This How-to guide summarises key requirements relating to telephone marketing, postal marketing, email marketing and other electronic mail direct marketing. It also flags the need to screen against the Mailing Preference Service or Telephone Preference Service (TPS). This guide takes account of direct marketing guidance published by the Information Commission’s Office (ICO) on service messages, refer-a-friend campaigns, regulatory communications, market research including selling under the guise of research (sugging), tracking pixels, marketing lists, suppression lists and preference centres. It reflects the ICO’s: • Direct marketing guidance, and • Guidance on direct marketing using live calls and Guidance on direct marketing using electronic mail Understanding the law Any direct marketing activity that uses personal data is caught by the data protection regime, ie the UK
PRACTICE NOTES
Most people chat all day with family, friends, colleagues and clients; you converse without even pausing to think about it. In the work place, conversations have become a dying art, as email and instant messaging has taken over. But there are many occasions when you could cut through to the heart of an issue with a quick meeting when it might have taken days or weeks of circling around on email. This Practice Note looks at the art of conversation and offers some tips for having more effective and productive conversations. Practical techniques for better conversations Keep an open mind Do you always stop to think who you’re talking to and what you know about them? Often, you approach a situation with your blinkers on—replaying earlier scenarios with that person, with pre-set ideas on how it might play out, based on how it did previously. What would be more productive is to approach that person in a curious, open way—keen to hear what fresh new information they might have. It is tempting to roll your
PRACTICE NOTES
Under the Bribery Act 2010 (BA 2010) it is an offence to pay or receive a bribe. In addition, BA 2010 includes two offences designed to target commercial bribery: • an offence of bribing a foreign public official • a separate corporate offence of failure to prevent bribery The corporate offence can be committed by a commercial organisation where a bribe is paid by a person associated with it with the intention of obtaining or retaining business or business advantage for the organisation—see Practice Notes: The Bribery Act 2010—an introductory guide and Failure to prevent bribery—the offence. An organisation may also face criminal liability where the relevant offence is committed by a senior manager when acting within the actual or apparent scope of their authority. For further information, see subtopic: Corporate criminal liability—managing the risk. It is a defence to the corporate offence of failure to prevent bribery for the organisation to prove it had in place adequate procedures designed to prevent those who perform services for it from
PRACTICE NOTES
Corporate criminal liability attribution is the legal mechanism through which an organisation may be held criminally responsible for criminal conduct, and it can arise in a number of ways. The consequences of corporate criminal liability attribution can be significant and may include criminal investigations, prosecution, financial penalties, regulatory action and reputational damage. Over the years, there have been various developments and reforms to the law on corporate criminal liability attribution. It is therefore important for organisations to keep up with the changes and take steps to ensure their governance arrangements, compliance controls and reporting mechanisms are fit for purpose. This ‘How-to’ guide provides practical guidance for private sector commercial organisations in the UK on how to identify and assess corporate criminal liability risks. It should be read alongside ‘How-to’ guide: How to manage corporate criminal liability risks. Understanding corporate criminal liability Corporate criminal liability may arise in a number of ways, including through senior manager attribution, failure to prevent offences and other statutory mechanisms. Depending on the relevant liability mechanism,
PRACTICE NOTES
This Practice Note provides guidance on the regulatory requirement to conduct a firm-wide risk assessment (FWRA) as set out in the Money Laundering, Terrorist Financing and Transfer of Funds (Information on the Payer) Regulations 2017 (MLR 2017), SI 2017/692, as amended. The MLR 2017 do not prescribe any methodology and there is no single mandatory format. You should ensure you are thorough. Look at what you do and what you do not do. But no matter how thorough your FWRA or how appropriate your controls, some criminals may still succeed in exploiting your practice for criminal purposes. A comprehensive and documented FWRA, combined with written records of decisions made on individual clients and matters will enable you to justify your decisions and actions to law enforcement agencies and your supervisory authority. Do you have to conduct a risk assessment? If the MLR 2017 apply to your firm, you must take appropriate steps to identify and assess your firm’s money laundering, terrorist financing and proliferation financing
PRACTICE NOTES
Risk assessment is the foundation of any compliance programme. Fraud risk management is not straightforward. Commercial organisations need to consider fraud risk from two angles; (1) the risk of fraud being committed by or on behalf of the organisation, thereby committing the failure to prevent fraud offence, and (2) the risk of the organisation itself falling victim to fraud. However, the preventative measures you take are likely to be the same, or at least very similar, for both. You are unlikely to want to conduct two separate fraud risk assessments, or to issue and maintain two separate fraud prevention policies, for example. Therefore, this Practice Note and related Precedents cover both angles in one place, but you should bear in mind that they are not the same. What are the risks we are assessing? Risk assessing fraud is two pronged: Committing the failure to prevent fraud offence The risk of your organisation being a victim of fraud Your staff and people acting on your behalf committing fraud on behalf of your organisation and/or