Skip to main content
Promotional banner ad for the Penetration Testing Report Kit
Compliance Officers and Confidentiality: Five Myths That Lead to Career-Ending MistakesRegulatory Compliance
5 min readFor Compliance Officers

Compliance Officers and Confidentiality: Five Myths That Lead to Career-Ending Mistakes

The SEC's recent enforcement action against Benjamin Tesfaye, who profited $18,668 from insider trading using information from his compliance officer girlfriend, highlights a common misunderstanding about confidentiality. The case isn't unusual; people have traded on pillow talk since markets began. What's striking is that the source was a senior director of ethics and compliance who should have known better.

These failures don't occur because compliance officers are reckless. They happen because we've built myths about how confidentiality works. Let's dismantle them.

Myth 1: "I didn't name the company, so I didn't breach confidentiality"

Reality: Context is disclosure. In the Tesfaye case, his girlfriend never mentioned Calliditas Therapeutics by name. She simply told him that Asahi Kasei Corp. was acquiring another company and that a family member would recognize the target because he'd interviewed there. That was enough. While still on the phone, Tesfaye texted the family member, got a list of four companies, and deduced which one made strategic sense for Asahi.

The information you share doesn't need to be explicit to be material. If you provide enough context clues, industry sector, timing, geographic location, how it affects your role, you've given someone the pieces to complete the puzzle. The SEC's order noted that the girlfriend told Tesfaye she was "excited about what the acquisition might mean for her role and responsibilities." That emotional context was itself a data point.

Your obligation isn't to avoid naming names. It's to avoid creating a trail of breadcrumbs that leads to the same destination.

Myth 2: "My partner isn't in finance, so there's no insider trading risk"

Reality: Anyone with a brokerage account is a potential trading risk. The SEC order notes that Tesfaye had "education and knowledge of the pharmaceutical industry" and understood his partner handled sensitive corporate secrets. He didn't need a finance background to connect dots or execute trades. He needed curiosity and a smartphone.

The risk isn't limited to securities trading. Confidential M&A information can inform vendor negotiations, job searches, or conversations with friends who work in finance. Once information leaves your control, you can't govern how it cascades.

The practical standard: if you wouldn't say it to a journalist on background, don't say it at home. The SEC established that Tesfaye "owed a duty of trust or confidence" to his partner because they lived together, had been in a committed relationship for several years, and "routinely shared confidences relevant to their careers." That duty ran both ways, but it didn't create a legal safe harbor for disclosure.

Myth 3: "We have good boundaries, we work in separate rooms when we're remote"

Reality: Physical separation doesn't equal information security. The SEC order specifically mentions that Tesfaye and his girlfriend "had made arrangements to occupy separate workspaces when teleworking" because she expected him to maintain confidentiality and "it was very important to her that the trade secrets and confidential information of her employer be protected."

Those arrangements failed because boundaries are about what you say, not where you sit. You can have separate home offices with soundproofing and still compromise confidential information during dinner conversation or a phone call from the airport.

Effective boundaries require active discipline: not discussing specific deals, not naming counterparties, not sharing timelines, not expressing excitement about "big things happening" that invite follow-up questions. The controls are verbal and behavioral, not architectural.

Myth 4: "If I trust someone completely, I can share confidential information with them"

Reality: Trust is not a control. The SEC order emphasizes that Tesfaye and his girlfriend "routinely shared confidences relevant to their careers" and that he knew she handled sensitive corporate secrets. This established trust made the disclosure feel safe, but it didn't make it appropriate.

Your duty of confidentiality to your employer doesn't diminish because you trust the recipient. It's not a risk-based assessment where high-trust relationships justify more disclosure. The standard is binary: the information is either yours to share or it isn't.

The Tesfaye case demonstrates why. Even if his girlfriend trusted him completely and believed he would never trade on the information, she couldn't control what he did with contextual clues once she provided them. Trust describes a relationship; confidentiality describes a legal obligation. They're not interchangeable.

Myth 5: "I can vent about work stress without disclosing material information"

Reality: Emotional disclosure carries factual content. When Tesfaye's girlfriend told him there were "some very big things happening" and that she was "excited about what the acquisition might mean for her role," she was processing work stress and sharing her emotional state. She probably didn't think she was disclosing material nonpublic information.

But excitement about role expansion implies organizational change. "Very big things" signals materiality and urgency. Even without specifics, you're painting a picture. A sophisticated listener, and the SEC order notes Tesfaye had pharmaceutical industry knowledge, can infer deal type, timing, and strategic direction from your affect and phrasing.

If you need to process work stress, use a therapist, a peer compliance officer at another company, or your internal legal team. Don't use your spouse as an emotional outlet for matters involving material nonpublic information. The cost of that conversation, as this case shows, included $20,836 in disgorgement and interest, plus $18,668 in civil penalties for Tesfaye, and likely career consequences for the compliance officer.

What to Do Instead

First, establish a personal disclosure policy that's stricter than your employer's. If your organization allows discussing pending matters with immediate family, don't. Treat M&A activity, litigation strategy, regulatory investigations, and material operational changes as categories you simply don't discuss outside work, full stop.

Second, create substitution language for when partners ask about your day. "I'm working on a time-sensitive project" conveys stress without conveying content. "I can't talk about specifics, but I'm busy" sets a boundary without creating curiosity gaps that invite probing.

Third, recognize that compliance roles create asymmetric risk in personal relationships. Your partner may not intend to trade on information you share, but you've put them in an impossible position if they later want to make legitimate investment decisions. The cleanest approach is to avoid creating that conflict entirely.

The SEC's case against Tesfaye cost him roughly $39,500 and presumably cost his girlfriend her relationship and possibly her career. The disclosure that triggered it all was a phone call from an airport, excited, imprecise, seemingly harmless. That's how confidentiality breaches happen. Not through deliberate espionage, but through comfortable myths about what counts as disclosure and who counts as safe.

Promotional banner highlighting failures found in PCI audits and how to spot the gaps

You Might Also Like