Live data from Hacker News

JP Morgan fined by SEC for deleting email records

theregister.com

201–210 of 254 posts

Re: JP Morgan fined by SEC for deleting email records

#201

All enterprises have shitty IT. If you want this not to happen again, don't fine them, add a regulation. Regulations are literally the only thing that makes enterprises confirm that they've done something correctly. Only when an exec VP has their bonus or freedom threatened do they take shit seriously.

There are already regulations for data retention during attorney-related incidents.

> Only when an exec VP has their bonus or freedom threatened do they take shit seriously.

Isn't this a fine, and not a regulation?

Re: JP Morgan fined by SEC for deleting email records

#202
post #30

> to a project where the company aimed to delete from its systems any older communications and documents that were no longer required to be retained. Literally no reason to do this but for this precise goal.

you don't owe the information you are not required to keep IF you have deleted it.

if you still have it and delete it after you were asked to provide it, it will land you in jail.

this is IRS audit 101. I guess they have their own similar reasons.

Re: JP Morgan fined by SEC for deleting email records

#203

So the story is basically: 1. data that has to be retained for legal reasons can't be deleted by normal deletion processes 2. data that should be deleted didn't delete properly 3. to fix (2) they manually ran delete requests for times up to about the current date (back in 2018), relying on (1) to protect data 4. turns out somebody forgot to configure (1) for emails send to domains belonging to Chase (at that point th…

It seems like laws about how data gets handled are pretty much not real laws, due to there being almost no enforcement. So, most companies handle their data in a fairly careless way

It might be illogical for companies to invest more into their IT infrastructure if there isn't a good reason to do so. I mean, even massive customer data leaks go basically unpunished, so how do you justify the mitigation expenses at the board meeting when shareholders are already mad about the lack of growth last quarter?

Re: JP Morgan fined by SEC for deleting email records

#204
post #193

Earlier quoted context omitted.

The crime was identified, which is why JP Morgan was fined. Once a corporate entity is operating at a sufficient scale, it does not matter if the people inside willingly mess up. The organization is required to be run properly. The problem is that slaps on the wrist for failure do not suffice as environmental stressors for corporate evolution. As for what we can do, the possibilities are endless. We shape society how…

> crime was identified, which is why JP Morgan was fined The SEC is a civil agency. No crimes. > organization is required to be run properly It’s that easy? Just require good organization and you’ll get it by diktat? This entire thread seems to require a reading of Argentinian and modern Egyptian and Russian economic history.

Evidently you don't get well run organizations by simply having legislation, which is my point. We do not enforce that legislation appropriately.

I'm confused by your point regarding the SEC, how are they allowed to fine a company without legal basis? If my use of the word "crime" means something different to you, I mean "crime" as anything that breaks the law.

Re: JP Morgan fined by SEC for deleting email records

#205
post #40

Earlier quoted context omitted.

The SEC is not in the justice business. It is a puppet of the banks themselves. A $4M fine is NOTHING for a company netting $12.62B a QUARTER.

The $4M is a slap on the wrist, but if there's evidence that it was done on purpose, and the deleted data is evidence for a bigger case, they'd be in much bigger trouble still. But, innocent until proven guilty; if there's no indication of any missing evidence, it'll stay at the failure to retain data fine.

I think corporations of "too big to fail" stature should have different legal protections than what are offered to humans.

Innocent until proven guilty is not quite fair to apply to corporations that get bailed out by taxpayers when the policemen are driving bicycles trying to enforce the speed limit on a highway full of McLarens.

When a company has positioned itself to be a critical organ of society, it should be required to function properly. The rules of nature do not forgive a well meaning hare that didn't intend to be eaten by a lion.

Re: JP Morgan fined by SEC for deleting email records

#206

IANAL but in many countries the judge might draw adverse inference and effectively assume what was in that evidence. That wouldn't be in the deleters interest. https://en.m.wikipedia.org/wiki/Adverse_inference

I believe that can still happen. This was just a fine from the SEC, the legal consequences could come later.

Basically a lot of that email was subject to litigation holds. If that litigation ends up depending on some email that Chase was supposed to retain but failed to, the judge is allowed to give a "spoliation inference" instruction to the jury - the jury can infer that the evidence would have been unfavorable to Chase.

The fact that this may have been due to incompetence rather than malice means this is less likely.

Re: JP Morgan fined by SEC for deleting email records

#207
post #204

Earlier quoted context omitted.

> crime was identified, which is why JP Morgan was fined The SEC is a civil agency. No crimes. > organization is required to be run properly It’s that easy? Just require good organization and you’ll get it by diktat? This entire thread seems to require a reading of Argentinian and modern Egyptian and Russian economic history.

Evidently you don't get well run organizations by simply having legislation, which is my point. We do not enforce that legislation appropriately. I'm confused by your point regarding the SEC, how are they allowed to fine a company without legal basis? If my use of the word "crime" means something different to you, I mean "crime" as anything that breaks the law.

> you don't get well run organizations by simply having legislation, which is my point

Nobody argued as much.

> I mean "crime" as anything that breaks the law

This isn’t what “crime” means. Painting your house the wrong colour may be against code, but it isn’t a crime. Legally, the difference is starker, as nobody was shown to have done anything wrong here beyond the benefit of doubt.

Re: JP Morgan fined by SEC for deleting email records

#208

So the story is basically: 1. data that has to be retained for legal reasons can't be deleted by normal deletion processes 2. data that should be deleted didn't delete properly 3. to fix (2) they manually ran delete requests for times up to about the current date (back in 2018), relying on (1) to protect data 4. turns out somebody forgot to configure (1) for emails send to domains belonging to Chase (at that point th…

It seems like laws about how data gets handled are pretty much not real laws, due to there being almost no enforcement. So, most companies handle their data in a fairly careless way It might be illogical for companies to invest more into their IT infrastructure if there isn't a good reason to do so. I mean, even massive customer data leaks go basically unpunished, so how do you justify the mitigation expenses at the…

This would make for an interesting law review article

Re: JP Morgan fined by SEC for deleting email records

#209
post #204

Earlier quoted context omitted.

Evidently you don't get well run organizations by simply having legislation, which is my point. We do not enforce that legislation appropriately. I'm confused by your point regarding the SEC, how are they allowed to fine a company without legal basis? If my use of the word "crime" means something different to you, I mean "crime" as anything that breaks the law.

> you don't get well run organizations by simply having legislation, which is my point Nobody argued as much. > I mean "crime" as anything that breaks the law This isn’t what “crime” means. Painting your house the wrong colour may be against code, but it isn’t a crime. Legally, the difference is starker, as nobody was shown to have done anything wrong here beyond the benefit of doubt.

> Just require good organization and you’ll get it by diktat?

This is what I was responding to. You seemed to be insinuating that I didn't understand that laws or rules are not sufficient deterrents.

> nobody was shown to have done anything wrong here beyond the benefit of doubt

I'm still confused as to how the SEC was able to fine someone for not committing any wrongdoing, exact definition of the word "crime" which I have clarified I used to mean "general rule breaking" aside.

Re: JP Morgan fined by SEC for deleting email records

#210
post #209

Earlier quoted context omitted.

> you don't get well run organizations by simply having legislation, which is my point Nobody argued as much. > I mean "crime" as anything that breaks the law This isn’t what “crime” means. Painting your house the wrong colour may be against code, but it isn’t a crime. Legally, the difference is starker, as nobody was shown to have done anything wrong here beyond the benefit of doubt.

> Just require good organization and you’ll get it by diktat? This is what I was responding to. You seemed to be insinuating that I didn't understand that laws or rules are not sufficient deterrents. > nobody was shown to have done anything wrong here beyond the benefit of doubt I'm still confused as to how the SEC was able to fine someone for not committing any wrongdoing, exact definition of the word "crime" which…

Deleting records that are legally required to be retained is not “no wrongdoing”.
Post reply on HN