LexGo

The financial outsourcing (r)evolution
28/02/2018

Luxembourg's well-known financial secrecy laws are changing. Bill n° 7024 amending inter alia Article 41 of the Financial Sector Act of 5 April 1993 (the "FSA") in this respect, initially gave rise to much discussion but was ultimately adopted. Barriers to several financial outsourcing transactions will officially disappear and the (IT) outsourcing landscape could undergo substantial changes. This newsflash takes a closer look at some of the most important changes which not only deal with the rules on professional secrecy but also clarify several organisational requirements to be complied with in outsourcing transactions.

 

Who is subject to the professional secrecy in the financial sector in Luxembourg?

Many individuals and entities in the financial sector are subject to a duty of professional secrecy, in particular:

  • natural and legal persons subject to prudential supervision by the Commission de Surveillance du Secteur Financier (the "CSSF") pursuant to the FSA;
  • natural and legal persons established in Luxembourg and subject to supervision by the European Central Bank (the "ECB") or a foreign supervisory authority for the exercise of an activity referred to in the FSA (new);
  • administrators, members of management bodies, directors, employees and other persons in the service of the abovementioned natural and legal persons.

A similar professional secrecy obligation has been foreseen for insurance companies and payment service providers in the respective laws regulating these activities.

For the sake of clarity it should be noted that investment funds are not subject to professional secrecy within the meaning of the FSA, but several of their service providers are, such as registrar agents and professional depositaries of financial instruments.

Persons to whom the information covered by professional secrecy may be disclosed

The distinction between outsourcing to intra-group and external entities that was initially made in bill no. 7024 has been abolished and replaced by a clear rule: the disclosure of the information covered by professional secrecy shall be possible where: (a) the sub-contractor is Luxembourg based and supervised itself; or (b) the client has agreed to the disclosure.

a) Supervised sub-contractor based in Luxembourg

Within the framework of a service agreement, the persons who are:

(i) established in Luxembourg;
(ii) supervised by the CSSF, the ECB or the Commissariat aux Assurances (the Luxembourg insurance regulator); and 
(iii) whose professional secrecy obligation is subject to criminal sanctions,

shall, following the adoption of bill no. 7024, be able to receive the information protected by a professional secrecy obligation.

b) Acceptance-based outsourcing

Under the CSSF's guidance to date (see inter alia Circular 12/552 prior to amendment by Circular 17/655), several financial institutions had already been entitled to outsource certain activities based on client consent. This consent-based exemption from professional secrecy obligations was not foreseen in the law, however, and thus gave rise to legal uncertainty. This uncertainty has fortunately been eliminated by new Article 41 of the FSA.

Henceforth, even entities that do not meet the abovementioned criteria may receive or access the information covered by professional secrecy obligations in the context of outsourced services if:

(i) the client has agreed, in accordance with the law or pursuant to a method of providing information agreed in between the parties, to: (a) the outsourcing of the relevant services, (b) the type of information that would potentially be disclosed in the context of such an outsourcing, and (c) the country in which the provider of the outsourced services is established; and
(ii) the relevant entity is subject to a professional secrecy obligation or is bound by a non-disclosure agreement.

While the initial version of the bill required the client's prior acceptance in writing, the final version offers some flexibility since financial institutions may – where there is no specific legal requirement – obtain the client’s acceptance pursuant to methods contractually agreed between the parties and, hence, implied acceptance could under circumstances be allowed.

Thus, the client’s acceptance within the meaning of the financial legislation does not appear to be the same as the data subject’s consent within the meaning of the data protection legislation (i.e. “any freely given, specific, informed and unambiguous indication of the data subject's wishes”). Nevertheless, it is of course possible that some types of outsourcing will require a more active consent in accordance with the data protection rules (e.g., transfers of data outside the EU/EEA that can have no other basis than consent).

How does the FSA revision impact the CSSF's prudential supervision of outsourcing?

The CSSF has amended Circular 12/552 to align it with new Article 41 of the FSA and adopted a new Circular 17/656 on key outsourcing principles. Both circulars now state that “financial sector customers should be informed or their consent obtained”. In other words, the CSSF does not impose in its guidance any consent requirement but has clarified at several occasions that the question as to whether consent must be obtained is to be assessed under Article 41 of the FSA. The latter being a provision subject to criminal law sanctions, the criminal courts have the last word on this.

It must be recalled that the CSSF prudential regulation implements the principles of sound governance and central administration that financial institutions should comply with. Whereas the focus of the FSA revision is with the outsourcing exception to the obligation of professional secrecy, it also has introduced a new set of outsourcing organisational requirements directly in the FSA itself. These requirements are inspired by the existing guidance framework governing insurance and payment institutions. Some of the new organisational requirements (e.g. the existence of a service contract or no delegation of responsibility) also appear to be inspired by the existing CSSF circulars on outsourcing, which still continue to apply alongside the FSA (for an overview, click here).

Conclusion

By simplifying and extending the exceptions to the professional secrecy obligation in order to allow financial institutions to outsource operations in a more flexible manner, the revised FSA is more likely to reassure market players and to accommodate the different interests of all stakeholders concerned.

However, the conditions of the end clients' acceptance, which is a key concept for a valid exception to the professional secrecy, might still give rise to discussions.

Some restrictions to outsourcing activities have been lifted, but such activities nonetheless remain heavily regulated by means of CSSF circulars which lay down robust conditions in this respect. The new outsourcing regime is thus certainly not a revolution but rather an evolution compared to the prior regime.

Voir aussi : Nautadutilh Avocats Luxembourg SĂ rl ( Mr. Vincent Wellens ,  Mrs. JosĂ©e Weydert ,  Mr. Jad Nader )

Mr. Vincent Wellens Mr. Vincent Wellens
Partner
Vincent.Wellens@nautadutilh.com
Mrs. Josée Weydert Mrs. Josée Weydert
Managing Partner
josee.weydert@nautadutilh.com
Mr. Jad Nader Mr. Jad Nader
Local Partner
jad.nader@nautadutilh.com

Click here to see the ad(s)
Tous les articles Droit financier

Derniers articles Droit financier

Circular CSSF 21/769 – Teleworking in supervised entities
23/04/2021

On 9 April 2021, the CSSF published Circular CSSF 21/769 regarding governance and security requirements for Supervised Ent...

Circular CSSF 21/769 – Teleworking in supervised entities Read more

CSSF circular on governance and security requirements for teleworking
13/04/2021

On 9 April 2021, the Commission de Surveillance du Secteur Financier (the « CSSF »), the L...

CSSF circular on governance and security requirements for teleworking Read more

EU Recovery Prospectus: temporary fast-track to boost listed companies' COVID-19 recovery
09/04/2021

In addressing the severe economic impact of the COVID-19 pandemic, the European legislator amended the existing Prospectus...

EU Recovery Prospectus: temporary fast-track to boost listed companies' COVID-19 recovery Read more

Further specifications to the AML Law
07/04/2021

In order to perfect the transposition into Luxembourg law of the fourth EU AML Directive 2015/849, in line with GAFI recom...

Further specifications to the AML Law Read more

Derniers articles de Mr. Vincent Wellens

Regulatory changes in the audiovisual media sector
16/04/2021

The Act of 26 February 2021 and certain grand ducal regulations have transposed into Luxembourg law the Audiovisual Media ...

Read more

New bill brings Luxembourg to the forefront of distributed ledger technology
17/03/2021

On 22 January 2021 Parliament approved Bill 7637, which modified:  the Law of 5 April 1993 on the financial sec...

Read more

The Sky Is Not the Limit: Space Activities in Luxembourg
15/02/2021

At the end of 2020, Luxembourg adopted the Act of 15 December 2020 on space activities (loi du 15 décembre 2020 por...

Read more

Adoption of New Secondment Act
18/12/2020

On 9 December 2020, the Luxembourg Parliament adopted a new secondment act, the purpose of which is to transpose into nati...

Read more

Derniers articles de Mrs. Josée Weydert

New bill brings Luxembourg to the forefront of distributed ledger technology
17/03/2021

On 22 January 2021 Parliament approved Bill 7637, which modified:  the Law of 5 April 1993 on the financial sec...

Read more

New CSSF platform for submission of prospectuses and related documents
09/03/2021

Submissions of documents under the EU Prospectus Regulation (2017/1129, as amended) and the Law of 16 July 2019 on prospec...

Read more

Amendment to Insurance Contract Act in relation to Brexit
05/02/2021

The Act of 19 December 2020(1) implementing the Budget Act 2021 introduced into the Insurance Contract Act(2) a ...

Read more

New act on professional payment guarantees
15/07/2020

The law of 10 July 2020 on professional payment guarantees has just been published and will enter into force on 17 July 20...

Read more

Derniers articles de Mr. Jad Nader

Luxembourg Brexit Laws: 15 September 2019 final deadline for UK based managers to notify the CSSF
22/08/2019

On 8 April 2019, Luxembourg adopted two laws ("Brexit Laws") on measures to be taken in relation to the financia...

Read more

Luxembourg Banking & Finance Comparative Guide
10/04/2019

NautaDutilh Avocats Luxembourg is an exclusive contributor to The Legal 500 Banking & Finance 2nd Editi...

Read more

Luxembourg Brexit Bill for the Financial Sector
26/02/2019

On 31 January 2019, the Luxembourg finance minister introduced a bill (n° 7401) on measures to be taken in relation to...

Read more

What You Need to Know About Luxembourg's MiFID II Legislation
05/06/2018

The new act on markets in financial instruments (the “MiFID Act”), transposing Directive 2014/65/EU on markets...

Read more

LexGO Network