Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

The Intersection of the Foreign Corrupt Practices Act and Data Privacy

By Junaid A. Zubairi, Joshua Nichols & Michael Waters on April 19, 2016
Email this postTweet this postLike this postShare this post on LinkedIn

On April 5, 2016, the Fraud Section of the Criminal Division of the Department of Justice (“DOJ”) released an Enforcement Plan and Guidance (the “Plan”) regarding the Foreign Corrupt Practices Act (“FCPA”). The Plan contains three components designed to enhance the DOJ’s ability to detect and prosecute violations of the FCPA:  (1) a substantial increase in law enforcement resources; (2) increased coordination with foreign jurisdictions; and (3) implementation of a pilot program (the “Pilot Program”) offering substantial cooperation credit to companies that meet certain specified standards for “(1) voluntary self-disclosure of criminality, (2) full cooperation, and (3) remediation.”

One of the enumerated requirements for companies to achieve “full cooperation” (and thus earn maximum cooperation credit) under the Pilot Program is that companies must effectuate “[d]islcosure of overseas documents, the location in which such documents were found, and who found the documents.” This requirement comes with an exception for situations in which “such disclosure is impossible due to foreign law, including but not limited to foreign data privacy laws.”  The requirement and exception are followed by a note stating that:

Where a company claims that disclosure is prohibited, the burden is on the company to establish the prohibition. Moreover, a company should work diligently to identify all available legal bases to provide such documents.

Thus, companies seeking to avail themselves of the cooperation credit offered under the Pilot Program may find themselves trying to strike a delicate balance between compliance with foreign data privacy laws, such as those in the European Union that restrict the transfer of personal data, and compliance with the DOJ’s “full cooperation” requirement.

On April 13, 2016, Andrew Weissman—Chief of the Fraud Section of the Criminal Division of the DOJ—provided further details on the DOJ’s approach to a situation in which a would-be cooperating company, under the Pilot Program, contends that it is prohibited from producing overseas documents.[1]  Weissman noted that the “Fraud Section is quite sophisticated in analysis of data privacy issues,” and that companies contending they are legally prohibited from producing all relevant overseas documents “can expect lots of factual and legal questions.”

With respect to factual questions, companies may be asked—among other things—whether the documents at issue are traditionally kept overseas, whether they are available on a server that can be accessed in the United States, and may also face questions about corporate structure (i.e., if the overseas documents are held by a subsidiary of a U.S. parent corporation, the parent corporation could potentially be deemed to have control over the documents). With respect to legal questions, companies may be asked—among other things—about the specific foreign data privacy law purported to prevent the company from providing overseas documents to the DOJ.  For instance, Weissman indicated that a company claiming a proscriptive interpretation of a foreign data privacy law will face pushback from the DOJ if other cooperating companies have found a way to provide overseas documents subject to that same law.

Finally, Weissman addressed the exact nature of the “burden” upon companies contending that they are prohibited from producing all relevant overseas documents, noting that it is not as high as “proof beyond a reasonable doubt” but that a granular definition of the precise burden is not necessary. Weissman noted that he views the Fraud Section as “a place that people can go and expect to have a rational, mature discussion with people in the DOJ and feel like they got a fair shake.”

In short, companies seeking to avail themselves of the Pilot Program will be expected to produce all relevant overseas documents. If a company believes that a foreign data privacy law prohibits them from doing so, then the company will bear the burden of convincing the DOJ of the prohibition.  While there is not a precise definition of that burden, companies can expect to face questions from, and engage in dialogue with, government attorneys who are well-versed in foreign data privacy laws and who have the benefit of knowing how other similarly situated companies have interpreted such laws.


[1] Weissman’s comments were reflective of his personal view of the relevant issues, and are not necessarily the views of the DOJ.

Photo of Junaid A. Zubairi Junaid A. Zubairi
Read more about Junaid A. ZubairiEmail
Photo of Joshua Nichols Joshua Nichols
Read more about Joshua NicholsEmail
Photo of Michael Waters Michael Waters

Michael J. Waters is a Shareholder and a member of the Litigation group at Vedder Price.  He has experience handling all phases of litigation, from emergency injunctions through trial and appeal, in a broad range of commercial litigation matters.  He has appeared and…

Michael J. Waters is a Shareholder and a member of the Litigation group at Vedder Price.  He has experience handling all phases of litigation, from emergency injunctions through trial and appeal, in a broad range of commercial litigation matters.  He has appeared and successfully argued in both state and federal appellate courts, and has participated in arbitrations before the American Arbitration Association and Financial Industry Regulatory Authority.  He has considerable experience in antitrust litigation, internet litigation and dispute resolution, mergers and acquisition litigation, banking and lending disputes, product liability litigation and handling disputes in the health care industry.

Read more about Michael WatersEmail
Show more Show less
  • Posted in:
    Government and Public Policy, Privacy and Cybersecurity
  • Blog:
    Media & Privacy Risk Report
  • Organization:
    Vedder Price PC
  • Article: View Original Source

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo