Last year, a divided 5th Circuit panel ruled that the SEC’s administrative law judge system, as currently operated, was unconstitutional. That’s a big deal in and of itself, but as Liz blogged at the time, some suggest that the decision could undermine not just the ALJ system, but a big chunk of the SEC’s rulemaking authority. In light of the stakes involved, it shouldn’t come as a big surprise that the SCOTUS granted the SEC’s petition for cert last week. This excerpt from SCOTUSBlog’s post on the case sets forth the issues to be addressed by the Court:
(1) Whether statutory provisions that empower the Securities and Exchange Commission to initiate and adjudicate administrative enforcement proceedings seeking civil penalties violate the Seventh Amendment; (2) whether statutory provisions that authorize the SEC to choose to enforce the securities laws through an agency adjudication instead of filing a district court action violate the nondelegation doctrine; and (3) whether Congress violated Article II by granting for-cause removal protection to administrative law judges in agencies whose heads enjoy for-cause removal protection.
The SEC has not fared well in the SCOTUS when it comes to challenges to its ALJ system – and unlike a lot of other issues, the Court’s skepticism toward the the agency’s use of ALJs has been bipartisan. In 2018, for example, Justice Kagan wrote the majority opinion in SEC v. Lucia, in which the Court by a 7-2 vote invalidated the SEC’s process for appointing ALJs. Earlier this year, she authored the Court’s unanimous opinion in SEC v. Cochran, which permitted defendants in ALJ proceedings to raise certain structural challenges to those proceedings in federal court, without having to first complete the administrative proceedings.
Stay tuned. Depending on how the SCOTUS rules on this case, there could be some pretty fundamental changes to how the SEC does business when it comes to enforcement – and perhaps rulemaking as well.
Earlier this week, a federal district court judge issued an unpublished opinion in a long-running clawbacks case. Even though the case doesn’t create formal precedent, it may affect decision-making as we all look to finalize Dodd-Frank clawback policies by December 1st of this year. Specifically, it emphasizes that it’s important to follow state law contract principles when you put a policy in place, if you want to be able to enforce the company’s rights under that policy down the road. Enforceability matters because under the new listing standards and SEC rule, companies aren’t required to merely adopt a clawback policy, they are also required to comply with the policy by recovering erroneously paid incentive compensation reasonably promptly – with delisting at stake.
In Monday’s case, the judge granted summary judgment in favor of Hertz’s former CEO, shutting down the company’s 2019 claim that he had breached the company’s clawback policy – as well as representations in his separation agreement – by creating a “tone at the top” that may have led to inappropriate accounting decisions. Although the former CEO settled with the SEC in 2020, he continued to fight reimbursing the company. Mike Melbinger blogged about this case at the “motion to dismiss” stage in 2021.
Hertz alleged that this was a case of misconduct that caused a restatement. It sought to claw back incentive-based compensation that was paid in prior years based on achievement of later-restated revenue, by way of the company clawback policy. It also sought to rescind golden parachute payments that it made to the former CEO under his separation agreement. Both the clawback policy and the separation agreement required a finding of gross negligence, fraud or willful misconduct.
The holding underscores that adopting a clawback policy is only one step in the process of recovering compensation – a point that Ron Mueller reiterated in yesterday’s webcast and has been preaching at our “Executive Compensation Conference” for many years. If there were doubts about whether to have executives agree in writing to be bound by company policies, this decision supports the notion that you do need a contractual basis for enforcement. And according to this opinion, simply incorporating a general policy into other agreements doesn’t work. Here’s an excerpt (citations omitted):
Hertz argues that the Clawback Policies were incorporated into “various other agreements” with Frissora and as such, are enforceable through this incorporation (“Incorporation Argument”). Specifically, Hertz argues that the following documents incorporate one or both Clawback Policies: (1) Frissora’s Employment Agreement, which Hertz argues incorporates both Clawback Policies because it states that the violation of a “material company policy” constitutes a defined cause to terminate Frissora’s employment; (2) the Separation Agreement, which Hertz argues incorporates the 2014 Clawback Policy by reference; and (3) Hertz’s “bylaws,” which Hertz argues incorporate both Clawback Policies because they “impose on [Frissora] and other senior executives the solemn duty of abiding by and enforcing company policies.” …
The Court agrees with Frissora that Hertz can only argue that the Clawback Policies are stand-alone contracts. Accordingly, if the Court finds that they are not enforceable contracts, then Hertz’s breach of contract claims under Counts I and II will fail.
The court went on to explain that the company’s clawback policies – which were set forth in board resolutions, incorporated into the company’s standards of business conduct, and described in public filings – were simply mechanisms by which Hertz would enter future contracts, and were not themselves enforceable contracts. The court also determined that the company’s general standards of business conduct weren’t enforceable contracts because (according to the court) they:
– Contained “only vague and aspirational language,”
– Had no yardstick by which to measure compliance with the standards,
– Stated that they were a “guide” not a “contract,” and
– Did not expressly have employees indicate that they would agree to be legally bound by the document.
There were some procedural & litigation strategy issues at play throughout all these findings, which also affected the court’s decision to reject the company’s attempt to rescind the payments under the separation agreement. And it’s possible Hertz will appeal. Nevertheless, this case shows that you need to keep basic contract principles in mind for company policies if you want to be able to enforce them. Also see question #1467 in our “Q&A Forum” on CompensationStandards.com, which discusses contractual interpretations of bylaws vs. policies.
We’ll be posting memos about this case in our “Clawbacks” Practice Area on CompensationStandards.com – and rest assured we’ll also be discussing the implications at our “20th Annual Executive Compensation Conference,” which is coming up virtually on September 22nd and, as always, follows our “Proxy Disclosure Conference” on September 20-21. Here are the agendas for that pair of conferences. If you haven’t already signed up, now is the time! You can register online (via the “virtual conferences” drop-down), call 800.737.1271, or email sales@ccrcorp.com.
It can be hard to keep track of what data in SEC filings needs to be tagged using inline XBRL. Fortunately, Vanderbilt Prof. Josh White recently flagged an Appendix to the SEC’s 2023 Semi-Annual Report to Congress on Machine Readable Data for Corporate Disclosures that provides an itemized list by filing type of which data must be tagged using inline XBRL. You may want to hang onto this one for your next form check.
In May, my wife and I traveled to Germany and Austria. It was our first trip abroad since the pandemic. The places and people were wonderful, and I really have to hand it to the Germans when it comes to a couple of things. First, they’re a lot better about confronting the dark parts of their history than we are, and second – on a much lighter note – if I ever became president, my first act would be to introduce legislation mandating Biergartens in every city.
Like I said, it was a great trip, but we were gone nearly three full weeks, so I eventually got very homesick. This Chuck Berry tune popped into my head as soon as we touched down on US soil and it captured how I felt at that moment better than anything I could say here.
We’ve been going through some challenging times as a nation, and it seems like we’re not real comfortable in our own skin just now. But a little time abroad does wonders for your perspective. My trip helped to remind me that, despite all our troubles, there’s a lot about this country that remains worth celebrating. Don’t take my word for it – just ask the Germans. So, let’s crank up our own volume & have a Glorious 4th! Our blogs will be back on Wednesday.
Based on a statement released yesterday by Gurbir Grewal, Director of the Division of Enforcement at the SEC, it appears that yesterday was the SEC’s “Insider Trading Day,” with the agency bringing charges against 13 defendants in four separate insider trading schemes. Grewal’s statement notes:
Public trust is essential to the fair and efficient operation of our markets. But when public company insiders take advantage of their status for personal gain, as we allege here, the investing public loses confidence that the markets work fairly and for them. Today’s actions reaffirm our commitment to leveraging all the tools at our disposal, including our data analytics initiatives, to investigate these abusive trading practices, hold accountable bad actors and ensure the integrity of our markets.
While I don’t believe that Insider Trading Day will gain traction as a national holiday (although I admit that it would be nice to have another holiday, even if it is dedicated to insider trading enforcement), the SEC was clearly seeking to make a statement by announcing all of these actions on the same day. For those charged with insider trading compliance, these cases provide a good demonstration of the many ways in which things can go awry when individuals are tempted to engage in illegal insider trading and tipping. For those who might be tempted to engage in this sort of conduct, the Insider Trading Day cases are a good reminder of the overwhelming legal peril that insider trading and tipping can put you in, including spending time in a correctional institution.
If you are like me, you have spent a lot of time thinking about insider trading – you learn about it in school, you watch movies like Wall Street and The Wolf of Wall Street, you draft and review insider trading policies, you answer questions about when an individual can trade in compliance with an insider trading policy. If you tell someone at a cocktail party that you are a securities lawyer, they will probably ask you about insider trading, because that is what people often associate with the SEC and the securities laws. Despite all of this contemplation of insider trading over the years, when Insider Trading Day rolls around and the SEC announces a bunch of insider trading cases, I ask myself: “Why do they do it?”
Insider trading enforcement has long been a focus of the SEC. Over the years, in cases like Cady, Roberts and Texas Gulf Sulphur, the SEC sought to address the fundamentally unfair notion of trading on the basis of material nonpublic information, and the judge-made theories of insider trading emerged from the general antifraud provisions of the securities laws. As this SEC Historical Society piece notes, in the 1980s, when former SEC Chairman John Shad was asked about insider trading, he announced “we’re going to come down with hobnail boots.” Hobnail boots, for the uninitiated, are boots with nails inserted in the soles, so they would really hurt if some SEC Chairman attacks you with them. And with that statement, we got the great insider trading characters of our age in Ivan Boesky and Michael Milken, and of course the fictional Gordon Gecko from the movie Wall Street. It is not as if the SEC and criminal authorities ever went soft on insider trading after the 1980s – during my time at the SEC, insider trading always topped the list of Enforcement priorities and many cases were brought in the ensuing years.
So why, after we toil over an 8-page insider trading policy, conduct countless insider trading training programs and send periodic reminders about insider trading topics to employees and directors, do some people still choose to pilfer material nonpublic information and share it with their friends for profit? Obviously greed is the real motivator, but the one thing that I think is common in insider trading cases is that, for some reason, the individuals involved did not think that they would get caught.
I observe that there appears to be a common misconception among individuals charged with insider trading that their various efforts to hide their misconduct and their trading through faceless markets will somehow prevent detection. Unfortunately for them, nothing could be further from the truth. The SEC and the SROs dedicate substantial resources toward market surveillance, and inevitably they will detect trading anomalies and connections that allow them to investigate potential insider trading cases. With constant advances in data science and computing, these market surveillance efforts just get bigger and better, making the chances of conducting an undetected insider trading ring much smaller. Perhaps this is a point that we should all emphasize more in our insider trading training sessions, because I would hope that if people realized just how sophisticated the surveillance effort is, they might think twice about misappropriating the company’s material nonpublic information and trading or tipping.
I would be remiss if I let this week go by without encouraging you to sign up for our September conferences. As we approach July 4th, that always signals to me that the summer is passing by quickly and “back to school” time will be here in no time. As I have mentioned before, you will not want to miss the educational opportunities in September at our virtual conferences. Among the many topics that we plan to cover is “Insider Trading & Buybacks — What You Need to Do Now,” so you can hear the latest thinking on these very important issues.
Last week at the Financial Times Cyber Resilience Summit, SEC Enforcement Director Gurbir Grewal spoke on the topic of the SEC’s approach to cybersecurity issues, while not weighing in on the pending rulemaking activity for public companies and regulated entities. He shared five principles “that guide the work we are doing across the Enforcement Division to ensure that registrants take their cybersecurity and disclosure obligations seriously.” The five principles are:
1. “[W]hen there are cyber attacks on publicly traded companies and other market participants, we consider the investing public to also be potential victims of those incidents…So in addition to ensuring that market participants are doing their part to prevent and respond to cyber events, our goal is to prevent additional victimization by ensuring that investors receive timely and accurate required disclosures.”
2. “[F]irms need to have real policies that work in the real world, and then they need to actually implement them; having generic “check the box” cybersecurity policies simply doesn’t cut it.”
3. “[R]egistrants [must] regularly review and update all relevant cybersecurity policies to keep up with constantly evolving threats. What worked 12 months ago probably isn’t going to work today, or at a minimum may be less effective. And relatedly, registrants and the professionals that counsel them would be well-served by reviewing the Commission’s enforcement actions and public orders on these topics. They clearly outline what good compliance looks like and where and how registrants fall short with their cybersecurity obligations.”
4. “When a cyber incident does happen, the right information must be reported up the chain to those making disclosure decisions. If they don’t get the right information, it doesn’t matter how robust your disclosure policies are.”
5. “[W]e have zero tolerance for gamesmanship around the disclosure decision. Here, I am talking about those instances where folks are more concerned about reputational damage than about coming clean with shareholders and the customers whose data is at risk. Companies might, for example, stick their head in the sand, or work hard to persuade themselves that disclosure is not necessary based on their hyper technical readings of the rules, or by minimizing the cyber incident. Don’t do that. It doesn’t work for the customers whose data is at risk. It doesn’t work for the shareholders who are kept in the dark about material information. And it most certainly doesn’t work for the company, which will most likely face stiffer penalties once the breach gets out, as it invariably will, and if it turns out that the company violated its obligations.”
Grewal went on to note that, with respect to cybersecurity matters and more broadly, “firms that meaningfully cooperate with an SEC investigation, including by coming in to speak with us or self-reporting, receive real benefits, such as reduced penalties or even no penalties at all.”
In his speech last week at the Financial Times Cyber Resilience Summit, SEC Enforcement Director Gurbir Grewal made the point that companies must regularly review and update cybersecurity polices and keep abreast of the SEC’s enforcement actions in the area for insights into “what good compliance looks like.” If you are looking for resources to facilitate that regular review, check out the “Cybersecurity” Practice Area on TheCorporateCounsel.net. There is an incredible array of resources available in the Practice Area on cybersecurity and data privacy matters, including the latest coverage of SEC enforcement actions and SEC guidance, updates on the SEC’s rulemaking efforts, the latest thought leadership on corporate governance considerations, very helpful checklists and coverage of federal and state-level legislative and rulemaking developments.
If you do not have access to the Practice Areas and other resources available on TheCorporateCounsel.net, sign up today. During the first 100 days as an activated member, you may cancel for any reason and receive a full refund.
It is that time of year when the Supreme Court wraps up its term and issues a long list of decisions. While rulings on several high profile cases are expected very soon, the Court recently weighed in on perhaps the more mundane topic of whether a state can require a company, as a condition of doing business in the state, to consent to being sued there for any and all claims. As my colleagues at Morrison Foerster note in this alert, inMallory v. Norfolk Southern Railway Co., 599 U.S. __ (2023), the Court concluded that such a requirement is consistent with the Fourteenth Amendment’s due process clause, opening the door to a major increase in out-of-state corporations’ exposure to lawsuits if states seek such consents from businesses.
The case involved Pennsylvania’s long-arm statute, which authorizes Pennsylvania courts to exercise “general personal jurisdiction” over any corporation that is registered with the state (which is a requirement of doing business in the state). The MoFo alert notes:
In a fractured opinion, the Supreme Court vacated and remanded, ruling that Pennsylvania’s consent scheme does not violate the Due Process Clause. Although five Justices agreed that the state court ruling should be vacated and remanded, Justice Gorsuch wrote for a majority of the Court only for portions of his opinion. Justice Alito filed an opinion concurring in part and concurring in the judgment, and Justice Barrett filed a dissenting opinion for four Justices. Justice Jackson also filed a concurring opinion.
* * * *
Mallory represents a potentially vast increase in out-of-state corporations’ exposure to jurisdiction in unexpected places, often where jury verdicts are excessive. After the decision, states can now require companies to consent to personal jurisdiction as a condition of doing business there (even if another state has a greater interest in the underlying dispute). And while the Court’s opinion is fractured, it is clear that a majority of Justices agree that consent remains an independently sufficient ground for exercising general personal jurisdiction.
What remains unclear, however, is how many states will accept that invitation. As discussed in oral argument, laws like Pennsylvania’s may deter smaller businesses from operating in a particular state. States may conclude that those concerns outweigh any interest in providing a forum for suit. And even if states do enact such laws, a majority of the Court may view them as invalid, between the dissent’s due-process/federalism reasoning and Justice Alito’s dormant-Commerce-Clause analysis, which is likely to be tested in the next phase of this case.
I have to admit, it has been a while since I thought about the dormant Commerce Clause!