Legal Doctrines that Convict CEOs
Ten doctrines, quotes, and court rulings — each one a mechanism by which U.S. law reaches past the corporation and holds the executive personally responsible. The cases are real. The prison sentences are real. The question is whether your organization has built the documented oversight that constitutes a defense.
10 Doctrines Prosecutors Use Against Executives
Click any card to pause. Use the speed controls to read at your own pace.
Across food, drug, environmental, securities, consumer-protection — and now data-security law — regulators are building tools to reach past the corporation and hold the executive personally.
United States v. Park (1975). A national grocery CEO was held criminally responsible for filthy warehouse conditions under the Responsible Corporate Officer (“Park”) doctrine — no personal involvement or knowledge required.
The oldest line in the executive playbook no longer protects the person at the top of the org chart.
United States v. DeCoster (upheld 8th Cir. 2016). After a salmonella outbreak traced to their egg operation, the owner and his son were each sentenced to prison. Their position of authority was enough.
The Supreme Court’s willful-blindness test (Global-Tech v. SEB, 2011): a high-probability suspicion plus deliberate steps to avoid confirming it equals knowledge.
United States v. Sullivan (conviction upheld by the Ninth Circuit, 2025). Uber’s Chief Security Officer concealed a data breach from the FTC while the agency was investigating. He was held criminally responsible — for the cover-up, not the hack.
An executive who designs the organization so bad news never reaches the corner office hasn’t built a defense — he’s built the evidence.
United States v. Huggins (Synthes/Norian, 2011). Executives pleaded guilty to misdemeanor misbranding of a bone cement the FDA had warned against; the president of Synthes North America got nine months — among the first executives actually imprisoned under the Park doctrine.
The FTC named CEOs personally in Drizly and InfoTrax — with obligations that travel to whatever company they run next — and banned the SpyFone CEO from his entire industry.
A willful false certification under Sarbanes-Oxley, and willful breaches of the DOJ’s new Data Security Program, each carry penalties of up to twenty years. Every one of these laws punishes the same thing hardest — willfulness, deliberate avoidance, looking away.
Across food, drug, environmental, securities, consumer-protection — and now data-security law — regulators are building tools to reach past the corporation and hold the executive personally.
United States v. Park (1975). A national grocery CEO was held criminally responsible for filthy warehouse conditions under the Responsible Corporate Officer (“Park”) doctrine — no personal involvement or knowledge required.
The oldest line in the executive playbook no longer protects the person at the top of the org chart.
United States v. DeCoster (upheld 8th Cir. 2016). After a salmonella outbreak traced to their egg operation, the owner and his son were each sentenced to prison. Their position of authority was enough.
The Supreme Court’s willful-blindness test (Global-Tech v. SEB, 2011): a high-probability suspicion plus deliberate steps to avoid confirming it equals knowledge.
United States v. Sullivan (conviction upheld by the Ninth Circuit, 2025). Uber’s Chief Security Officer concealed a data breach from the FTC while the agency was investigating. He was held criminally responsible — for the cover-up, not the hack.
An executive who designs the organization so bad news never reaches the corner office hasn’t built a defense — he’s built the evidence.
United States v. Huggins (Synthes/Norian, 2011). Executives pleaded guilty to misdemeanor misbranding of a bone cement the FDA had warned against; the president of Synthes North America got nine months — among the first executives actually imprisoned under the Park doctrine.
The FTC named CEOs personally in Drizly and InfoTrax — with obligations that travel to whatever company they run next — and banned the SpyFone CEO from his entire industry.
A willful false certification under Sarbanes-Oxley, and willful breaches of the DOJ’s new Data Security Program, each carry penalties of up to twenty years. Every one of these laws punishes the same thing hardest — willfulness, deliberate avoidance, looking away.
Cases and penalties are drawn from publicly reported matters. For general awareness only — not legal advice.
