Smart guide to mobile call recording for MiFID II

Similar documents
An overview of mobile call recording for businesses

Enterprise Mobility Management: completing the EMM story

Voice. The lost piece of the BYOD puzzle.

Should you be mixing business and pleasure? smart guide to the costs and risks of allowing business and personal calls on one phone

White Paper. The Impact of Payment Services Directive II (PSD2) on Authentication & Security

TeleWare Re:Call FAQ for Resellers

Voice. The lost piece of the BYOD puzzle.

ACCOUNTANCY TRANSFORMATIONAL CHANGE THROUGH UNIFIED COMMUNICATIONS

Thinking beyond data security: a comparison of the main mobile strategies

Accelerate GDPR compliance with the Microsoft Cloud

Adkin s Privacy Information Notice for Clients, Contractors, Suppliers and Business Contacts

NIPPON VALUE INVESTORS DATA PROTECTION POLICY

The GDPR Are you ready?

Kick-off Meeting DPIA Test phase

Privacy Statement. Your privacy and trust are important to us and this Privacy Statement ( Statement ) provides important information

Curatrix. How can Curatrix Communications help your business? Communications. Connecting your Business

Content. Privacy Policy

Data Management and Security in the GDPR Era

GDPR Compliance. Clauses

Disruptive Technologies Legal and Regulatory Aspects. 16 May 2017 Investment Summit - Swiss Gobal Enterprise

Compliance. Peter Oosthuizen Partner Service Team Leader

Public UBS MTF. MiFID II Identifier Management

Google Cloud & the General Data Protection Regulation (GDPR)

You can find a brief summary of this Privacy Policy in the chart below.

MOBIUS + ARKIVY the enterprise solution for MIFID2 record keeping

GDPR: A QUICK OVERVIEW

BUSINESS JUSTIFICATION. Name of the request: Securities Transaction Regulatory Reporting

The NIS Directive and Cybersecurity in

International Roaming Charges: Frequently Asked Questions

Use of Personal Mobile Phone Whilst on Duty

In Accountable IoT We Trust

Developing Issues in Breach Notification and Privacy Regulations: Risk Managers Are you having the right conversation with the C Suite?

NIS Standardisation ENISA view

The Apple Store, Coombe Lodge, Blagdon BS40 7RG,

Should you be mixing business and pleasure? smart guide to the costs and risks of allowing business and personal calls on one phone

Governing cyber security risk: It s time to take it seriously Seven principles for Boards and Investors

EU Data Protection Triple Threat for May of 2018 What Inside Counsel Needs to Know

Website and Marketing Privacy Policy

COUNCIL OF THE EUROPEAN UNION. Brussels, 24 May /13. Interinstitutional File: 2013/0027 (COD)

Transaction Reporting Service: EMIR

General Data Protection Regulation (GDPR)

Risk Outlook Anti money Laundering and Cybercrime. Steve Wilmott and George Hawkins

DATA PROTECTION AND PRIVACY POLICY

Cybersecurity Strategy of the Republic of Cyprus

Swedish bank overcomes regulatory hurdles and embraces the cloud to foster innovation

Do you handle EU residents personal data? The GDPR update is coming May 25, Are you ready?

Financial Services Solutions

Cyber Security and Cyber Fraud

VERITAS 2017 TRUTH IN CLOUD REPORT

PROTECT YOUR DATA, SAFEGUARD YOUR BUSINESS

BlackBerry WorkLife Persona. The Challenge. The Solution. Datasheet

POMONA EUROPE ADVISORS LIMITED

Clarity on Cyber Security. Media conference 29 May 2018

Regulating Cyber: the UK s plans for the NIS Directive

5-minute primer: MultiLine at work

EU data security and privacy trends

Securing Digital Transformation

Canada s Anti-Spam Law ( CASL ): It s the Law on July 1, 2014 questions for directors to ask

General Data Protection Regulation: Knowing your data. Title. Prepared by: Paul Barks, Managing Consultant

Planning BYoD Beyond Device Security. Report prepared by Utelize Communications Limited. A Utelize Insight Report 2017 Version.

REQUIREMENT FOR MEMBERS TO SUBMIT A PERSONALLY IDENTIFIABLE INFORMATION (PII) FILE

Why you MUST protect your customer data

Incentives for IoT Security. White Paper. May Author: Dr. Cédric LEVY-BENCHETON, CEO

Important Information

European Directives and reglements for Information security

Aon Service Corporation Law Global Privacy Office. Aon Client Data Privacy Summary

Data Privacy in Your Own Backyard

NOTIFICATION FORM. Section 1 Market definition

NATIONAL CYBER SECURITY STRATEGY. - Version 2.0 -

Information Security in Corporation

Microsoft Office 365 TM & Zix Encryption

EY s data privacy service offering

Blue Alligator Company Privacy Notice (Last updated 21 May 2018)

Q&A for Citco Fund Services clients The General Data Protection Regulation ( GDPR )

Cloud versus direct with VNC Connect

A sustainable approach to property rationalisation and cost savings Sustainability---the new dynamic

What kind of information do you collect, when and how?

The Park Hotel Privacy Statement

ITU Asia-Pacific Centres of Excellence Training on Conformity and Interoperability. Session 2: Conformity Assessment Principles

This Policy has been prepared with due regard to the General Data Protection Regulation (EU Regulation 2016/679) ( GDPR ).

EU General Data Protection Regulation (GDPR) Achieving compliance

Plan a Pragmatic Approach to the new EU Data Privacy Regulation

Adelaide Fringe is committed to protecting the privacy of its artists, employees, prospective employees, venues and the general public.

ADMA Briefing Summary March

JT CLOUD PBX. Product Description. JT Cloud PBX Product Description

PS Mailing Services Ltd Data Protection Policy May 2018

EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS

Data Privacy and Cybersecurity

G DATA Whitepaper. The new EU General Data Protection Regulation - What businesses need to know

MDP On-boarding Application Form - Notes

Towards an integrated regulation platform in Luxembourg. Information Security Education Day th of april

Privacy Policy: Data & Information Security Policy Last revised: 9 May 2018

GENERAL DATA PROTECTION REGULATION (GDPR) CLIENT INFORMATION GENERAL DATA PROTECTION REGULATION CLIENT INFORMATION

Cybersecurity Considerations for GDPR

Cyber Security: Threat and Prevention

With BlackBerry, This Global Law Firm Works Smarter, Better, And More Securely

INNOVENT LEASING LIMITED. Privacy Notice

SCCE ECEI 2014 EU DATA PRIVACY COMPLIANCE FOR US DRIVEN PROJECTS. Monica Salgado JANINE REGAN CIPP/E

EBOOK The General Data Protection Regulation. What is it? Why was it created? How can organisations prepare for it?

ALGORITHMIC TRADING AND ORDER ROUTING SERVICES POLICY

Transcription:

Smart guide to mobile call recording for MiFID II

Contents smart summary 3 MiFID II what is it? 4 Does MiFID II apply to my firm? 5 The options to stay compliant 6 smart guide for mobile call recording for MiFID II 2

smart summary The upcoming Markets in Financial Instruments Directive (MiFID II) aims to provide stronger investor protection and transparency for clients. The implications of the Directive and the new Regulation (MiFIR) are wide ranging and will impact a large number of financial services firms across the UK. One of the introductions of MiFID II is the requirement for investment firms to record telephone conversations and electronic communications relating to own account and clients transactions. This includes telephone conversations that are intended to result in the conclusion of a transaction. Whilst the requirement to record mobile conversations is a new obligation for financial advisors and insurance brokers, mobile call recording is not, and as a result there are a plethora of solutions available. Whilst MiFID II regulations will come in effect in January 2017, establishing a call recording system can be complex and require careful consideration. To help you find the right solution, we will show you the benefits and limitations of each approach. smart guide for mobile call recording for MiFID II 3

MiFID II what is it? The original MiFID gave EU member states the discretion to decide if telephone conversations were required to be recorded. In 2011, the UK s financial regulator, then called FSA, enforced that all relevant mobile communications between traders had to be recorded, including SMS and voice. Exactly which firms are required to record mobile calls has been heavily debated in the UK, with some firms believing that they were exempt of the regulation all together. In addition, some firms argued that they were exempt from recording mobile calls as employees were using personal phones. MiFID II makes the requirement to record mobile conversations mandatory, regardless if the conversation is on a device provided by the firm or not. A brief history of MiFID In 2007, the European Securities and Markets Authority (ESMA) implemented the original MiFID to introduce competition across the EU. In light of the mis-selling scandals, the financial crash and technology advancements such as high frequency trading, ESMA are overhauling the Directive to provide more transparency for investors and regulators. On 20 October 2011, the European Commission published two proposals: the revised Markets in Financial Instruments Directive (MiFID II), along with Markets in Financial Investments Regulation (MiFIR). Both the Directive and Regulation aim to establish a safer and more transparent financial system by enhancing regulatory requirements, market transparency and investor protection. MiFID II rules will come into effect from 3 January 2017. smart guide for mobile call recording for MiFID II 4

Does MiFID II apply to my firm? Unlike the current FCA regulations for mobile call recording, MiFID II stipulates that financial advisors and corporate broking firms have to record telephone conversations and electronic communications. This means thousands of businesses will have to begin recording conversations, text messages, emails and other data that are intended to end with a trade. It also means that an additional 300,000 people will need to have their mobile conversations recorded. If you don t already have a mobile call recording solution, this document outlines the different approaches to stay compliant. Even if you already have a mobile call recording solution, can it be scaled to meet the additional breadth of the types of conversations that need to be recorded? smart guide for mobile call recording for MiFID II 5

The options to stay compliant When the need for mobile call recording was introduced in 2011, there were a couple of options such as, mobile phones or adopting mobile call recording technology that routed conversations through a call recording server. The technology used two main approaches, either using an app or a SIM card to steer calls through a network based call recording solution. There s now a third solution, a hybrid that combines the best of an app based and network based solution. automatically divert calls to more than one phone in an emergency by routing calls by each DDI. DDI by DDI control can also enable organisations to move their staff in phases, floor by floor or department by department, minimising the risk of disruption. App based mobile call recording Some of the first solutions were apps created for BlackBerry mobile phones. Vendors have taken several approaches to record calls: Detecting a call is about to be made and steering it through the corporate telephone system or through a cloud based server to record calls. Creating a second call leg to a call recording platform, effectively conferencing the recorder. Utilise voice over IP technology which requires 3G or WiFi connection to make or receive calls. The benefits of app based mobile recording The advantage of app based solutions is that they are independent of the mobile network operator, so are able to record calls no matter what country the user is roaming in. The limitations of app based mobile call recording Many solutions are available on a variety of mobile operating systems, which reduces the challenge of finding a solution for organisations who have adopted a BYOD strategy. However, that s not always the case, older apps are tied into BlackBerry which isn t helpful for a mobile estate with different devices running different operating systems. smart guide for mobile call recording for MiFID II 6

The options to stay compliant App-based mobile call recording has usability challenges as well. There are either latency issues incurred while waiting for the call to be routed via the firm s telephone system or waiting for a second mobile call to be connected. The impact is that calls are either dropped, missed or parts of the conversation are not recorded. With solutions that route calls through the corporate telephone system there can be hidden costs. For example, additional telephone lines, to carry the additional mobile traffic and additional licenses for the corporate telephone system to record mobile calls. Network-based The network based solution is based on installing a new SIM card which automatically redirects calls to a recording server on the operator s network or the customer s onpremise infrastructure. The benefits of network-based mobile call recording The network based solution has been viewed as the best option by many firms. It dispels with many of the latency issues involved with an app based approach and provides a more reliable call recording service. Network based options provide an improved user experience as there is minimal delay in connecting the call. Additionally, modern solutions avoid the requirement for local infrastructure changes as calls are recorded in the cloud with recordings sent or downloaded. As the SIM card needs to be replaced, the personal SIM cannot be used. This means that users cannot have a personal mobile number on the same device, which often rules out BYOD strategies. Two numbers on one phone: smartnumbers mobile plus, the best of both worlds There are positives and negatives to both the app and network-based solutions. However, a new approach is now available: smartnumbers mobile plus. It provides the reliability and user experience of a network-based solution that records all business calls whilst being operator and network independent. This provides the benefit of a GSM mobile call recording service that records all business calls on personal phones whilst personal calls remain private. Every call made through the app is automatically recorded and sent securely to the compliant email server. For the first time, firms are able to consider BYOD without the risk of breaching market regulations and EU privacy laws. The limitations of network-based mobile call recording Network based solution are often dependent on installing a new SIM card to identify when a call is made or received. This ties the call recording solution to a specific mobile network operator. smart guide for mobile call recording for MiFID II 7

About Resilient This smart guide was created by Resilient, the company behind smartnumbers, a range of communications services that deliver mobility, continuity and compliance to public and private sector organisations. smartnumbers are trusted by 7 of the top 10 global investment banks, 50% of the UK s blue light services, and over 40,000 Ministry of Defence personnel. The services are available directly from Resilient and also from BT. This smart guide is not intended to be a source of legal advice, and should not be relied on as such. Phone 020 3379 9000 or visit www.resilientplc.com trusted communications mobility continuity compliance