13.07.2015 Views

A G E N D A 1. APOLOGIES FOR ABSENCE Ian Metcalfe 2 ...

A G E N D A 1. APOLOGIES FOR ABSENCE Ian Metcalfe 2 ...

A G E N D A 1. APOLOGIES FOR ABSENCE Ian Metcalfe 2 ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

whether any third parties (e.g. other regulators or litigants) are taking relevant action inrelation to the same breach.If Monitor considers that discretionary requirements are needed to ensure a breach not continue,it is likely that Monitor will impose a compliance requirement.In considering whether requirements are needed to deter further breaches by the provider,Monitor proposes to assess, amongst other relevant factors:Whether the provider knew, or should have known, that its actions would risk noncompliance;this may include evidence that the breach was genuinely accidental and thatthe provider has already taken steps to avoid non-compliance;How much the provider has gained, or is expected to gain, from the breach - relevantbenefits may include financial and other benefits such as reputational benefits; Whether the provider has taken steps that suggest the breach in question will not recur -this could be, for example, by:oooonotifying the breach to Monitor as soon as it was identified;voluntarily taking effective steps to ensure that the breach is remedied and to limitthe risk of further breaches taking place in future;cooperating generally with Monitor’s enquiries and requirements; ortaking action to compensate those affected.Whether the breach could represent part of a pattern of non-compliance, emerging orotherwise, such that Monitor considers that imposing requirements is necessary toincentivise compliance in the future; andWhether any third parties (e.g. other regulators or litigants) are taking relevant action inrelation to the same breach.Monitor is likely to impose a discretionary requirement if we are satisfied that it is needed to deterfuture breaches. A compliance requirement is likely to be appropriate if there are practical stepswhich Monitor could require of the provider in order to ensure that the breach not recur. Thegreater the risk of future breach, the greater the likelihood that Monitor will impose a variablemonetary penalty (whether instead of or in addition to other discretionary requirements) in orderto deter a recurrence.Page 20 of 50

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!