JP Morgan fined by SEC for deleting email records
theregister.com
theregister.com
1. data that has to be retained for legal reasons can't be deleted by normal deletion processes
2. data that should be deleted didn't delete properly
3. to fix (2) they manually ran delete requests for times up to about the current date (back in 2018), relying on (1) to protect data
4. turns out somebody forgot to configure (1) for emails send to domains belonging to Chase (at that point the merger was 18 years ago)
5. It took 1.5 years for anyone to notice.
To me it seems like number 5 is the biggest problem here. Mistakes happen, but had they noticed in time they likely would have had those messages in backups (if they don't, that's a much bigger problem). But they probably don't retain the backups for long, for the same reasons they delete old emails in the first place (legal discovery)
It might be illogical for companies to invest more into their IT infrastructure if there isn't a good reason to do so. I mean, even massive customer data leaks go basically unpunished, so how do you justify the mitigation expenses at the board meeting when shareholders are already mad about the lack of growth last quarter?
It turns out investigation and enforcement is disproportionately doled out to large corporations. Companies like Alphabet and Meta have multiple teams to make sure they are handling data correctly and yet there could still be things that fall through the cracks.
This regulatory attention on large companies is advantageous to startups though; until a startup gets big nobody really cares about its data handling compliance.
Any reference about this? If anything, the GDPR fines make me think the opposite.
On the other hand, big companies don't just deal with clearly defined responsibilities like GDPR; that's table stakes. They deal with random government investigations on data handling. If a company has multiple products, combining data from those multiple products could very well suddenly become antitrust concerns. What makes a particular data handling practice an antitrust concern? Companies don't really know in advance because it's purposefully vague and meant to be worked out by the courts.
Think FTC in the US or CMA in the UK.
I’m curious if any IT folks can comment on what they have seen? Do you actually have log records of all messages? Or do you have something like a snapshot of all accounts at a given time?
Anyway, all these business rules are (should be) documented in formal policies on data retention, litigation hold, privacy, etc. If a company were going through a working annual audit process for Sox or increasingly even routine annual financial audits (non-sox), policies would be examined for evidence that they are working with spot checks - e.g. auditor selects examples of qualifying events and asks for evidence that the given policy is in fact enabled/enforced technically. This may test retention as well as intention deletion (e.g. we should deliberately have no data beyond five years unless an exceptional circumstance warrants it).
[1] Fourth paragraph
For JPMorgan, sure. That missing evidence gets interpreted adversely against JPMorgan, which means those cases are basically won. The question is how many more will arise in the coming months, perhaps years, that find reasonable claim to damages arising out of evidence the defendant has conceded it can’t bring to its defense.
That wouldn't be in the deleters interest.
But, innocent until proven guilty; if there's no indication of any missing evidence, it'll stay at the failure to retain data fine.
Innocent until proven guilty is not quite fair to apply to corporations that get bailed out by taxpayers when the policemen are driving bicycles trying to enforce the speed limit on a highway full of McLarens.
When a company has positioned itself to be a critical organ of society, it should be required to function properly. The rules of nature do not forgive a well meaning hare that didn't intend to be eaten by a lion.
If its service is crucial and no other company can replace it, then there is a high risk that it makes use of its position by charging an arm and a leg for essential services.
I love this. Consider yourself quoted.
That would seem to be an indication of missing evidence
It doesn’t matter whether or not the above paragraph is reality, because masses perceive it as reality, and trust in public institutions continues to dive. If confidence isn’t restored soon, then things might start to destabilize
Nobody (who isn't a moron) is going to send an email about intentionally doing this, or talk about it with someone who wouldn't also be implicated if discovered. If you saw everything, kept careful notes, and decided to become a whistleblower, your career would be destroyed and your life might even be in danger.
That is proof of missing evidence.
This is ofcourse false. But given how little effort you made on this comment i assume nothing will change your mind:(
https://www.nytimes.com/2022/09/27/business/banks-fined-text...
Source? There is a revolving door, but it’s as much between industry and the SEC as it is between it and the rest of the public sector.
Well, honestly I am surprised at how extensive the commissioners' background is in public service and/or education.
If you need people people with experience in banking and finance, especially the legal and regulatory/compliance areas, where would you do your recruiting?
A regulator that regularly pulls exclusively from industry insiders should raise eyebrows. Now whether the SEC actually pulls the majority of hires from industry insiders, that's another question I can't readily answer. Don't have those figures.
A lot of people fail to realize how crucial financial institutions are for society. Everything we do has national currency as a middleman, and national currency is more under private control than under public.
$125M is a fee for stealing as much as you wish, since you have the power to print money. Need more assets? Just give out credit more loosely for a while. Then "accidentally" delete the records of what money went where, then get bailed out.
Commercial banks get to create and spend currency before its impact hits the wider market through inflation. In addition, the rate of creation has to continuously surpass debt repayment, otherwise there is a liquidity crisis. They have an immense privilege, and as such, should be held to much higher standards.
"Give me control over a nation's currency, and I care not who makes its laws."
If the violation of even the standards we have results in less than a month's worth of PROFIT for several years of wrongdoing, how are these rules or outcomes fair?
Basically a lot of that email was subject to litigation holds. If that litigation ends up depending on some email that Chase was supposed to retain but failed to, the judge is allowed to give a "spoliation inference" instruction to the jury - the jury can infer that the evidence would have been unfavorable to Chase.
The fact that this may have been due to incompetence rather than malice means this is less likely.
So, what you're saying is that if the actual evidence shows something worse than what the judge will assume it says, then you should 'accidentally' delete it.
I think there are plenty of cases of this happening.
I had been asked to analyze a machine’s event log to see what happened, and on a Teams meeting with a dozen people proceeded to right click the event log and mistakenly hit clear, unconsciously accepting the dialogue box.
That was embarrassing, but I was direct about it.
I always just pull the plug and image the disk since.
Look, I didn't mean to do the espionage thingy, especially in public ¯\_(ツ)_/¯
Had you immediately pulled the plug on the machine at that point, you would almost certainly have been able to recover the event log. Sure, it would have been many days effort, but probably better than failing to get evidence of a suspected evil do-er.
When you need to do any infrastructure change not to mention data manipulation it takes million signatures and meetings. Like 13 meetings to deal with one ex employee corporate cloud folder.
Unless they end up in court. Then somehow million things happen on their own in their benefit.
Dysfunctional organizations have (somebody-else-is-doing-it / im-doing-it) ratios that get way out of control. There's also (talking-about-doing-it / doing-it), where dysfunctional orgs lose the ability to experiment.
This is just corporate "The IT dept ate my homework."
It's a ridiculous excuse, "punished" with a trivial fine.
I had a customer that got accidentally sent confidential data to the wrong email address and it was backed up for multiple months. In the end we left it in there but they considered deleting all the backups that contained this email.
That is a good reason for having short lived backups and an archiving solution with retention policies emails.
It's exponentially expensive to eliminate the base-rate of a "whoops", and not everyone has NASA-level money to waste on IT.
They likely spend all of it on the million meetings full of people who wouldn't actually be executing the change, next to none of it on the team and infrastructure where the change will be made, and then fire the team who made the change.
We haven't figured out how to cure cancer in humans because we turn a blind eye to it when we create it ourselves.
> Take the number of vehicles in the field, A, multiply by the probable rate of failure, B, multiply by the average out-of-court settlement, C. A times B times C equals X. If X is less than the cost of a recall, we don't do one.
If you want to know why so much shady crap happens, part and parcel of that is when we fo catch malicious behavior, the fines are so small as to be cost of doing business.
The fines for these types of accidents should be starting with the letter B and ending with illions, lets see how often these types of mistakes happen in the future afterwards.
For example, I was working on a system that handles holdings and trading information at the fund level which covers AUM that starts with a T and ends in rillions. There was an SQL injection vulnerability with schema owner access. Luckily this was an internal app, but still there are trade desk devs who could accidentally paste a drop table statement with a name collison. Anyways, I brought all this up to the principal. I was told this isn't a real big deal because they have real-time backups. I asked if they ever tested the backups... no. Do they have procedures for restoring from backups... no. They go nuts if there's a 5 minute outage, so how long would it take to restore... no idea.
Trust me ignorance is very believable, even in regulated industries.
GP's point stands: they should be fined to a degree that it becomes clear to management that these "not uncommon" practices must become very uncommon.
Why? Fining isn’t done for fetish, it’s done proportional to harm.
The article mentions twelve civil suits (four independent). JPMorgan will lose those. Any lawyer worth their salt, meanwhile, will be looking for claims which could reasonably involve the evidence which was deleted to file. In this way, the people actually harmed get compensated versus a government agency, which mitigates corruption concerns.
*for example, no more "the dog ate our homework" excuses.
All fines are subject to court supervision. This sentence makes no sense.
> cost of doing business this way must go up, way up
We want regulators thinking of the public, not randomly increasing the cost of business. This seems more motivated by hatred for a thriving industry than claims to specific damages. Regulators who pursue this path are rightfully overturned by courts for acting capriciously.
The wealth inequality gap is widening and it's due to pussyfooted enforcement on white collar crime and strategic negligence.
You can’t fine a business just to reduce inequality. Any jurisdiction that starts ruling that way fails basic definitions for rule of law. (This is in part what ruined Argentina.)
Also, in what universe would larger fines for banks decrease income inequality? The history of enforcement is capricious penalties increase incentives for cover-ups. If a record retention mistake means personal bankruptcy, you have zero incentive to correct mistakes. In practice, this leads to corruption among regulators, who are now the de facto commanders of private business.
> due to pussyfooted enforcement on white collar crime
Where is the crime here? The SEC investigated and found no wilful wrongdoing. Those twelve private plaintiffs are going to win judgements, as will everyone else who brings claims which could reasonably by covered by the missing records.
As for what we can do, the possibilities are endless. We shape society however we like, and that is the highest form of art humans engage in.
The SEC is a civil agency. No crimes.
> organization is required to be run properly
It’s that easy? Just require good organization and you’ll get it by diktat? This entire thread seems to require a reading of Argentinian and modern Egyptian and Russian economic history.
I'm confused by your point regarding the SEC, how are they allowed to fine a company without legal basis? If my use of the word "crime" means something different to you, I mean "crime" as anything that breaks the law.
There is a legal basis: retention requirements of the Securities Exchange Act of 1934.
From the SEC order: “As a result of the conduct described above, JPMorgan willfully violated Section 17(a) of the Exchange Act and Rule 17a-4(b)(4) thereunder, which require brokerdealers to preserve for at least three years originals of all communications received and copies of all communications sent relating to its business as such.”
Nobody argued as much.
> I mean "crime" as anything that breaks the law
This isn’t what “crime” means. Painting your house the wrong colour may be against code, but it isn’t a crime. Legally, the difference is starker, as nobody was shown to have done anything wrong here beyond the benefit of doubt.
This is what I was responding to. You seemed to be insinuating that I didn't understand that laws or rules are not sufficient deterrents.
> nobody was shown to have done anything wrong here beyond the benefit of doubt
I'm still confused as to how the SEC was able to fine someone for not committing any wrongdoing, exact definition of the word "crime" which I have clarified I used to mean "general rule breaking" aside.
Allowing "smart" individuals to play dumb to benefit themselves is not smart at all at a societal level.
Strategists at these companies examine the costs of failure or cheating, and simply see that it's worth it to cut corners or pile on risk. Just look at JP Morgans history in getting fined for market manipulation.
THIS.
I briefly worked for a major European bank. There was a system that was backed up on tape. The way they checked the backups was to visually look at the tape spool - before sending the tapes off to a mountain to be preserved.
One day, they needed something from a back up. Sure enough, the tapes were simply blank due a bug in the back up script.
Lol
Fines for this type of accident should be the permanent removal of the banking license.
What kind of company can you trust if evidence can be deleted "by accident" ?
part of their strength is their size.
There aren't any bank to take on their market ?
Individuals and companies won't stop having accounts or buying home or investmenting in equipment because 1 bank 'gracefully' shuts down. Another one will take on.
But risking a crash like Lehman Brothers, Wirecard (a journalist nearly got charged with market manipulation in Germany for covering what really happened in this firm), FTX,... is the real self sabotaging for a country.
"Too big to jail" is not a service for the common good. It's just protecting friends.
We need real investigations into how this bank is run, and how others are run as well. If this was genuinely just an IT incident, that's fine. But it raises questions obviously.
It's not a matter of whether there's other banks that can take on the business. It's a matter of government intervention to that degree would rock confidence and cause a negative shockwave through the markets, which would most definitely affect you no matter how much or how little you have invested in the bank in question. New backers for loans made to the largest corporations and countries on earth, easily reaching billions if not trillions of dollars would need to be accounted for and reorganized. A primary source of funding for housing, infrastructure projects, etc. would be eliminated.
I think you fail to see how deeply entrenched the largest financial institutions in the world are with modern society. Our governments literally depend on them to function because of the complexities of globalization.
If the government revoked the license for a local lawn care company on the basis of a records retention mistake, I’m fairly sure they’d have a case for reversal in the courts. I get we’re technically minded, and so technical mistakes rank up with mortal sins, but let’s keep a sense of perspective.
Sure. My point is this has nothing to do with too big to fail.
Also, what is the impact of these records being deleted? If you have a claim that reasonably involves them, it is basically cashable due to the error. If nobody can show damages, it’s hard to argue this mistake had a wide impact.
Actually not whatever. But apparently some borders are quite thin.
I have never just deleted millions of emails and pieces of evidence in a listed company, especially one that falls under the SOX act (it implies some governance.)
Did they have the IT governance or not ?
I think this is more likely: https://www.sec.gov/news/press-release/2021-262
All emails and code changes are up for discovery and I don’t work with individual contributors directly so I’m not even sure how I would be able to give an instruction like this without many people wondering what was up.
In the early days sure, I could go ask X person to access things directly but after a couple hundred people it doesn’t work that way. Think about an org of hundreds of thousands with the most strict compliance rules in existence.
And doing something willful here would be jail time so why would someone already wealthy risk this? Even in a corrupt system people balance risk reward. A fine for the bank, fine, but life ruined forever stretches credulity given the limited upside.
So you think a few C-level execs went to 8,700 mail boxes and deleted 47 million messages to remove the EXACT evidence that was being subpoenaed?
I'm not saying that's what happened, I find the sequence of events described by JP Morgan believable. But the same process issues that allowed this to happen accidentally would allow it to happen maliciously.
Not a chance. NOTHING gets done at JPMorgan without a mountain-load of direction and a grip of meetings. This would have had to wipe out both the data and records of that direction. Because the layers of tape are so thick you can't travel floor to floor without an access card coding and used to log your time and that even these simple systems don't work all the time (which generates even more busy work, yay), it's a form of friction against any sort of "secret" dealings within the company. If your keycard/dev env/database access/wiki edits/etc are so chaotically managed, it's unlikely that you will leave 0 evidence behind. Note that there was enough information to reconstruct what happened, to some degree.
I would bet someone didn't communicate the arcane symbol column that meant "do not delete for legal reasons", in some SQL. It's that chaotic, which reinforces the paranoia about the legal consequences that are foisted on every employee, routinely. If you have a shoplifting conviction (a record that hasn't been purged), you aren't getting hired. Viewed from the inside, it's strangely dystopian, but far from subtle.
How did the bureaucracy let this happen if it's as big and bureaucratic as you claim? And there's other examples too.
Not to brag, but I skirted company policies at JPMC. I had been tasked with writing a solution for a specific process that integrated a freeform type of data. I didn't use customer data or even sensitive company information, but did cobble something together that worked as a prototype over 6 months, in addition to my application workload. Due to some unannounced hardware refresh, my laptop was to be wiped. I decided to mail a zipfile of the custom javascript code (all open source or hand-written), to myself. There was a proper application (OneDrive) to normally store this kind of data, but it wasn't on my machine...which was probably part of the reason some laptops were being nuked. So, against, company policy I "mishandled source code" and got a 2-week-long wrist-slap over it. Was this "letting employees use email to evade company policies", or is it simply something that happens because there's no practical way to prevent me from doing it and still maintain standard business operation? It's important to read between the lines sometimes.
Anything that requires participation of lower level employees, is different because they have to have explicit instructions and action plans to do anything...according to multiple policies and processes. If someone walked in and said "this is the SQL to use to delete this data for this JIRA ticket", it would be written down in a Confluence, JIRA, email, git, for starters. You would also have to have to account for the rollback as well, or it doesn't play.
I mean, I live this personally. When legal tells me to delete or retain something, I don't go get a law degree, and then insist that they let me have all the details to come to my own independent opinion about whether or not we need to delete or retain something. That is every bit as nonfunctional as when I tell them that the task they're asking for will take three weeks and they go get a programming degree and then come over and learn the exact environment we are working in so they can verify that we are telling them the correct estimate.
Part of the SEC’s process is peppering these people with pamphlets explaining how their testifying this happened is a $10+ million whistleblower payday.
The implementers and auditors themselves get bogged down by red tape and/or the game of telephone between various departments, leading to information and Acceptance Criterias falling between the cracks.
If you read the link in my previous comment, you'll see this isn't the first time they got fined for bad record keeping practices. In that instance, $125m.
It's kinda either/or. It's either possible that someone can get full admin privileges and deletes it off-the-record or they've got enough safeguards in place that the accidental deletion isn't possible either.
I don't think your argument works unless the article is wrong.
the thing we're discussing is deleting A LOT of records which INCLUDE the ones being subpoenaed, which is obviously easily possible, intentionally or otherwise
so, no stretch of the imagination required
0 - https://unlimitedhangout.com/2023/04/investigative-series/cr...
1 - https://trendingpoliticsnews.com/breaking-attorney-general-t...
2 - https://news.ycombinator.com/item?id=35959865
3 - https://www.cftc.gov/PressRoom/PressReleases/8260-20
4 - https://www.counterpunch.org/2020/09/22/3-count-felon-jpmorg...
Now there's a reliable source!
If you can point out anything specific in there that's provably wrong, I'd genuinely love to hear it.
While there are many statements one can confirm, such as "took up boxing", they are surrounding nuggets like this: "After being selected by a mix of powerful businessmen, many of whom shared connections to intelligence and/or organized crime", a statement which is so vague as to be highly suspicious.
And don't even get me started on the author feeling the need to point out that all these organized crime and banking folks are Jewish - what's the relevance? Only to double down on stereotypes - the other people in the story aren't called out for their ancestry or religion...
By only denouncing this Dangerous Anti-Semitism and ignoring the equally deplorable Anti-Italianism, you've outed yourself as an Anti-Italian Romanophobe whose opinions may be summarily dismissed. Checkmate.
If you read the article, you'll notice "Italian" occurring once, but not in relation to a specific person...
However, in the opening paragraphs of the "SuperMob" they're sure to mention which specific individuals are Jewish:
Crown Prince of the “Super Mob”
Henry Krinsky was born in 1896 in the city of Chicago. His father, a Jewish immigrant from Lithuania, worked as a sweatshop foreman and changed the family name to Crown when Henry was a child. After dropping out of school in the 8th grade, Crown started a steel business with his older brother, Sol Crown, in 1915, creating S.R. Crown & Company. A few years later, in 1919, another brother, Irving Crown, joined the company, which became Material Service Corporation (MSC), a sand, gravel, lime and coal business that was prominent in Chicago’s construction industry.
Henry Crown developed an early relationship with Jake Arvey, a notorious political fixer for the Democrats in Chicago who, like Crown, was the son of poor Jewish immigrants. Arvey had deep ties to the Chicago mob, including the circles around notorious gangster Al Capone
Now, I know also that you're saying I'm being overly sensitive, but I'm trying to point out (when I was asked to disprove the article) that these are signals that I think the article is not to be trusted on face value.
Making things out to be anti-semitic when they're not, such as happened to Corbyn, is a popular smear tactic. It's pretty disgusting though, and many Jewish people have pointed out that it's a very harmful and anti-semitic thing to do.
That ship has long sailed in the US. I don't see this behavior stopping in earnest until the greater populace stops giving any credibility to the claims due to repetitional damage. In fact right now they have become emboldened after the 2020 elections. Meanwhile there is a real rise in anti-semitism that is likely occurring among the far-right.
Change is starting to happen online in that every single thread i've been seeing on Reddit/HN that calls out Israel also tends to completely swat away the anti-Semitic claims thrown out when any criticism of Israel typically occurs. Whether this translates into real world changes remains to be seen but we are starting to see it in the voting patterns of Millennials and Gen-Z(them supporting comments made by "the Squad" and electing more reps that don't shy away). It very will likely be a generational shift as Israel continues to damage its reputation in the US due to its tactics.
The article seemed pretty clear about where evidence was lacking; and is more densely packed with links than >95% of mainstream news articles.
Even if one were to completely dismiss everything fta that was even slightly suspect, you'd still have more insight into why JP Morgan might intentionally delete tens of millions of emails.
Forty-seven million emails. 47,000,000.
"Accidentally". Even if you could believe this - wow - even if you could take that at face value, the fine worth ~45 minutes or so of profit is still preposterous.
How many emails do you think JPM receives a year?
The problem is that most "reliable sources" aren't very reliable on the important topics - war, money, culture, etc.
E.g. Elizabeth Holmes got out on bail, but just recently went in to serve her sentence.
Not thankful for the downvoters although they probably thought I was cynical or something… but hey better have knowledge than points.
Well cynicism is definitely called for wrt bail, because it's regularly used for a very different purpose. It's normal for people accused of crimes to have to wait over a year for their trial in this country, and the courts often intentionally set bail so high that the accused can't possibly afford it. They are forced to choose between sitting in jail that whole time while their life evaporates, or they can plea guilty to a crime they may or may not have committed; the actual punishment is often less severe than being found innocent at trial. The prosecution can repeatedly push back the trial to keep the pressure on. Since healthcare access is almost always tied to employment, people plead guilty to crimes they didn't commit every day in this country so that their kids don't lose their access to healthcare. Just the sort of systemic, everyday corruption that we're supposed to pretend can't happen here.
And charging companies with fines is ridiculous IMO. There are always humans who made decisions ultimately. And charging companies (not them) is just a "get out of jail and enjoy Hawaii" card for them.
After they cheated, they probably had the promotions, money, golden parachutes, and left the company after bleeding it out and hurting it anyway. So why would you charge the company a second time ? Why not them ?
That's the point, they shouldn't be "reasonable" nor "appropriate" for an entity as large and with as many resources as JPM. Surely with the 300k employees they have and the literal infinite well of money they have, there's a few competent individuals working there to prevent these sort of "mistakes" from happening, and if not then they should either find some competent people, or cease to exist.
What's reasonable about charging them 4 million? It's not even a drop in the bucket, it's a singular molecule of water getting inserted into the bucket if we're talking about JPM.
Tell me, what exactly is reasonable or appropriate or fair about such a pittance of a fine for such blatant corruption? We're not talking about some random mom & pop shop, we're talking about the largest fucking bank in the States and arguably the entire world here. Someone in the thread already did some rough back-of-the-napkin math, this 4 million is a bit less than 20 minutes of income for them, in what universe is that a reasonable fine?
Instead they'll just have to have some 'extra' meetings with the regulator and report on their remediations later.
Nevertheless, one counter-intuitive policy which would end corporate control [1] (hence will never be implemented, again, no future for you) is supra-unitary taxation: effectively, tax rates above 100%, ensuring that the corporation has by default a lifetime (like a person they wish to be). Once the forever-in-debt corporation gets past a certain level of debt, it gets liquidated. Of course, corporations affected by this would have a certain scale (above $10 trillion, let's say) and a certain domain of activity (embedded AI, synthetic biology, nuclear fusion, asteroid mining, and similar).
[1] 2023, Claire Provost, Matt Kennard, Silent Coup. How Corporations Overthrew Democracy, Bloomsbury Academic, https://www.bloomsbury.com/uk/silent-coup-9781350270008
I'm sure you understand how that can happen.
Pay up.
So like the amount of money they earn on coffee break
Literally no reason to do this but for this precise goal.
if you still have it and delete it after you were asked to provide it, it will land you in jail.
this is IRS audit 101. I guess they have their own similar reasons.
EDIT: its amazing - not a mention of the fact that JPMorgan is under investigation for its relationship with Epstein ..
JMPC is no longer under investigation for Epstein - they paid a fine and that's that, sadly. Mr. Dimon doesn't want to testify again, because there's a high chance the Feds knew he was lying when he claimed in his first testimony that he had never heard of the guy and then claimed that he had no idea what Epstein was doing. Which if you follow the people involved, you know was a bold-faced lie. Yet JMPC will walk away unbothered, because they are untouchable.
Yes they are, JPMC is still being sued by the Virgin Islands government. They have a settlement that still needs to be approved with the victims.
Hope the USVI gets all they are asking for and then some. The way Dimon testified it's so obvious he knew what was up - I mean, he worked with Jes Staley for nearly a decade, and promoted him to the head of JPMC's investment bank. There's no way in hell a guy in such a position who has a personal client transacting billions of dollars with former and current heads of state (including multiple former or future US Presidents), Fortune 50 CEOs, famous academics and also was convicted of sex trafficking in 2006 can hide that all from his boss. I don't believe that for a second.
When you pretend you have the legitimacy to run something as big as JP Morgan then you should not be allowed to screw up that much.
You earn that much money, you should demonstrate equal level of competency.
They should get jail time either way.
It was TD Ameritrade documents mostly it seems, but it was located close to a Citadel-owned building as well.
I assume this archiving rule just got applied too liberally. However, I doubt that will assuage the conspiracy theorists.
Unless the fines become existential or the c-suite goes straight to jail this won’t change.
If this vendor screwed up this badly, why can't we know their name?
> Only when an exec VP has their bonus or freedom threatened do they take shit seriously.
Isn't this a fine, and not a regulation?
Even if it was a genuine mistake, if anything legal came up, does a court need to accept that the evidence is gone and that the data was probably guilt-free? (getting some obstruction of justice vibes that I had in the US in 2019.......)
I wonder when democracy will arrive in America. Where people overpower concentrated wealth through overwhelming majority the way we did when we broke from England. Collectively voting to break up monopolies, tax the wealthy and imprison the corrupt.
I'm seeing ads on TV now for Vanguard and BlackRock, the companies perhaps most responsible for sending rents into the stratosphere and killing the dream of home ownership for millions of people. The American Dream.
"72 Hours Before JPMorgan Offered $290 Million to Make Epstein Claims Go Away, a Lawyer Disclosed that the Bank Had Withheld 1500 Documents" [0]
[0] https://wallstreetonparade.com/2023/06/72-hours-before-jpmor...
Edit - For those downvoting me: https://nymag.com/intelligencer/2023/06/new-documents-reveal...
When a law requires data to be retained for X time, risk-averse companies interpret this as an instruction to immediately delete said data as soon as time X passes, and use automated tools to this end. Sadly, these tools tend to be ad-hoc software written and maintained by internal teams, and thus about as buggy as you'd expect.
I've worked in such places, and - in addition to all the other issues - the continuous collective loss of corporate knowledge makes life pretty miserable.
Then he removed it and everyone else had it gone because of that.
Tech and their, deleted means we keep it forever but mark it as deleted, should take notice.
But, it is unfortunately absolutely realistic that companies are throwing away data the moment they can justify it. Ironically, it’s not the ones we’d like to forget about us most.
Data retention is a liability as much as it is an asset, and it’s challenging regardless.
If you’re a large enough company you will eventually come to be frustrated by whatever policies you have (either they’re too conservative or too liberal). And understandably when you’ve been caught being shady enough, even an honest deletion will look shady.
Of course they did! /s
It doesn't matter, anyone that even mentions it will eventually be relegated to the "her emails" camp and disregarded. Can never tell if i'm just getting older and taking more notice or the blatant corruption we seem to shrug off is actually growing (probably the prior).
Oopsie, that's too bad. Totally accidental though I swear.
But with a corporation all they can do is fine, so it just becomes a cost of business :(
Fines are not based ad hoc on how much you're able to pay. They're standard and the enforcer can't make you pay more - that would be terrible.
In socialist dictatorship like…check notes… Finland and Switzerland, they are. Those countries are indeed notorious for being terrible places to live… /s
(Well, I'm sure the multi-millionaires getting a €120k speeding tickets hated it: https://www.theguardian.com/world/2023/jun/06/finnish-busine...)
> Can you imagine a low wage earning getting away with stuff because they can't pay?
But somehow this is OK if that's rich people getting away with it…
(Sarcasm aside, nobody prevents the legislator to ad a floor to the fine, to avoid this exact issues, and unsurprisingly that's what the aforementioned countries do)
Lots of countries run fines exactly this way, and it's not terrible at all... Finland, Sweden, Germany, Switzerland, Denmark etc.
Kinda seems like you feel the concept of equality is unfair. Lol.