International law firm attacks HMRC over privacy concerns

Image

Law firm Mishcon de Reya has filed a complaint with the Information Commissioners Office (ICO), citing concerns over the use of the common reporting standard (CRS) and beneficial ownership registers

The complaint, filed on behalf of an unnamed individual, alleges that when the individual’s information was shared with overseas tax authorities, it presented a clear risk of being hacked and would infringe on the individual’s rights to data protection.

The firm also argues that CRS goes beyond what is required under so-called ‘transparency laws’, threatening legitimate business owners.

In a statement, the law firm argued that: ‘Anyone owning a substantial interest in a private company based in Europe (or with a European subsidiary) will see their details published, regardless of where they are resident, the nature of the business or the nature of their involvement in that business.’

The release goes on to argue that: ‘the rights to privacy and data protection are fundamental rights. They are the cornerstone of the General Data Protection Regulation (GDPR) – which came into force in May 2018 – and emanate directly from European Convention on Human Rights and the EU's Charter of Fundamental Rights.

‘The transformational nature of the GDPR in defining the relationship between businesses and their customers is indicative of the strength of the fundamental rights to privacy and data protection. In order to be justified, any interference with these rights needs to have a clear legal basis, pursue a legitimate public interest (such as the fight against crime); and be proportionate, ie, limited to what is strictly necessary to achieve the objective pursued.’

Developed in 2014, CRS is an information standard for the automatic exchange of financial information, developed by the OECD and agreed by 97 countries. Based in part on the US Foreign Account Tax Compliance Act (FATCA), the standard has at times been criticised as creating privacy and data retention concerns. Although HMRC has admitted in the past that it shares data with tax authorities in other countries, its stated aim is to only do so when the action is lawful.

The leader of the action at Mishcon, partner Filippo Noseda, said: ‘After more than three years of assiduous campaigning on this issue and the publication of a comprehensive report by the Mishcon Academy, the time has come to take action.

‘There is a wealth of objective evidence supporting our proposition not least the comparisons made between the CRS and the Data Retention Directive – the latter of which was effectively declared illegal by the European Court of Justice in 2016.

‘In a democratic society, the rights to privacy and data protection are an essential safeguard to protect compliant citizens against potential abuses and must be treated with the appropriate seriousness by the authorities.’

Report by James Bunney

 

 

James Bunney

James Bunney, Accountancy magazine and Accountancy Daily...

View profile and articles

0
Be the first to vote

Rate this article

Related Articles
Subscribe