Customer and Product Data Bill
Members, the House is in committee on the Customer and Product Data Bill. When we suspended for the lunch break, the committee was considering Part 1. This is the debate on clauses 3 to 13ââPreliminary provisionsââand Schedule 1. The question is that Part 1 stand part.
Thank you, Mr Chair. Before the House broke, we were having a very useful discussion with the Minister of Commerce and Consumer Affairs about the replacement provisions for derived data, which are set out in his Amendment Paper 254.
I want to ask him if he could give the members of the Economic Development, Science and Innovation Committee, who spent quite a long time agreeing in a cross-partisan way to the removal of derived data, some comfort that the new designated customer data provisions really are in the spirit of that cross-partisan agreement. There was agreement all around the table from the ACT Party to the Green Party that derived data, as it was framed in the bill, was not going to be workable, because we wanted the industry to hear from Government to go for it, to go for broke, to build out solutions, and to innovate.
So I want the Minister to step us through how the new provision will mean that industry still has all of the abilities and the empowering provisions in the legislation that they need to get things done and to not be hindered at all by the new provision. Iâm thinking here particularly of the major accounting firms. The select committee had a really great submission from Xero about how derived data had just slowed things down in the Australian regime in a way that did not ultimately benefit consumers and certainly did not step out privacy rights.
A really useful part of the discussion was comparing how New Zealandâs privacy rights are really great. Theyâre a great framework for industry to work with. Theyâre a good principles basis for Government to also work with, and it means that we have an advantage here. We have an advantage of long-established law and well-understood principles about privacy that we can build from, rather than having to sort of build out two regimes as we go, and confuse the issue of transactional uses of data or the privacy protections that need to be in place for other sorts of uses.
So Iâm keen on this idea, and Labour is still in principle supportive of this, but given that we are supportive of it but weâre also supportive of the whole select committeeâs view that derived data had no place in this regime, can the Minister assure everyone that that commitment to cross-partisanship here is being honoured and that there wonât be an unnecessary slowing down of creating the useful products that derived data would have otherwise brought in?
I want to ask the Minister just to address the questions about how derived data came into the consultation. Many in the industry felt that it was late in the piece that it was introduced, especially when theyâve been engaging with the officials in good faith for a couple of years before the mention of that. It did really spook the horses; it felt like a new regime being built. So we want to know that this is not that by stealth.
Thank you, Mr Chair. I have a different line of questions for the Minister of Commerce and Consumer Affairs regarding clause 3 of Part 1 of the bill, which is under âPurposeâ. I wanted to start with clause 3(1)(b) around âcompetition and innovationâ. Now, going through the regulatory impact statement, we have seen a number of instances where the consultation was done with the Ministry of Business, Innovation and Employment (MBIE), which is understandable. However, what I couldnât seeâand this is a concernâis any consultation that was undertaken with the Ministry of Foreign Affairs and Trade (MFAT). Now, the reason I ask this question is, sure, thereâs been a lot of information within the regulatory impact statement around what other countries are doing. We know, for example, the EU is particularly good when it comes to data protection, whereas the US is particularly bad at data protection. However, as we see through a number of our international trade dealsâsuch as the Trans-Pacific Partnership Agreement (TPPA), the NZ-UK Free Trade Agreement, and the NZ-EU Free Trade Agreement (NZ-EU FTA)âeach of them will contain a digital economy chapter which, then, pertains to how data can be held accountable within those.
The reason I mention that, in the context of this bill and particularly under the purpose clause, isâand we can go into further details laterâaround the fact that, for example, under the TPPA, there are specifically clauses about the ability for Governments to be able to challenge or to be able to create that competition under that particular trade agreement. Now, understanding weâre looking at the broader context of trade, in those kinds of cases, we have seen instances where big tech from the US has been able to use free-trade agreements (FTAs)âor particularly digital economy and trade parts of an FTAâas a tool of creating a monopoly or creating uncompetitive behaviour in certain marketplaces.
One of the examples thatâs currently happening right now, although itâs not within our Aotearoa context, is the fact that Musk is currently suing the Indian Government for non-competitive behaviour, or for discriminatory behaviour, under certain trade agreements. So my first question is around whether the Minister has any clarity or clarification on whether MFAT has been consulted, in the context of this particular bill, specifically under the digital economy chapters.
Now, following on in the same vein, the question that you mentioned, Ministerâand I think itâs a really important question to askâis: it is my data, therefore I should be able to be able to use it in a way that I want to. However, that data sovereignty also is questionable under international trade deals and agreements, particularly from the perspective that in certain trade dealsâand, again, I go back to the TPPA and the Comprehensive and Progressive Agreement for Trans-Pacific Partnership, which doesnât exist, thankfully, under some of the newer ones like the NZ-EU FTA.
For example, in certain trade deals, we are not, under those trade deals, allowed to have that data being held onshore. In fact, there are certain trade agreements where we canât even hold that data or have a copy of our own data onshore, because thereâs no need for there to be an onshore presence. So, in this particular case, when the Minister is talking about onshore data and my data, what reassurances does the Minister have, from various consultations, that the data that we are holding under the requirement of this legislation, indeed, is allowed to be held onshore? Another example is the NZ-EU FTA, which, now, does allow us to hold a copy of that, but, again, there is no specific requirements for the original data centre to be held onshore.
The last question I have for the Minister is around clause 3(2)(c) in terms of ârequiring certain safeguards, controls, standards, and functionalityâ, and I particularly want to hone in on the idea of third parties that are authorised, because, again, we have seen instances where, yes, although the data is being held by a particular company or a particular provider, but the data system itselfâfor example, letâs say Google or Meta, etc.âthe data is not within the jurisdiction of those particular companies. So when weâre looking at creating safeguards, controls, and standards, does that mean that the liability is held within the companies themselves, or, originally, will some of those data collections or those kind of big tech elements ultimately be liable?
Again, in some of our trade agreements, there are certain clauses that mean that big tech companies are not liable for violation by a third party. So those are the three questions I have for the Minister: has there been consultation with MFAT in terms of consistency with our trade agreements? I know itâs quite a big concern in terms of the MBIE-MFAT interaction in this case. When weâre looking at my data, I can choose to use it in my way. What does data sovereignty in the context of this bill mean, and does that, again, come into conflict with some of the issues we see with our trade agreements? And, lastly, when weâre looking at third-party safeguards, controls, and standards, is this to do with the company that holds the data, and what happens if the companies themselves donât hold the data but the data is being moved to a third-party providerâi.e., a big tech?
Thank you very much, Mr Chair. I want to just cover off on a couple of the questions that have been asked by members who have clearly been giving good and considered thought to this part of the bill.
I just want to go back to the derived data question that Arena Williams raised, because it is interesting. I want to make it very clear that my Amendment Paper actually doesnât reintroduce derived data into the legislation. The Economic Development, Science and Innovation Committee made it very clear that for a variety of reasons it needed not to be included. But what the Amendment Paper does do is it clarifies the designated customer data as the specific types of data designated through the regulations. Now, what all that means is that the regulations contain the detail, not the legislation. The regulations have yet to be completely drafted, but they will be commenced and put into place before the legislation can be enlivened or switched on, if I can put it that way. Weâre hoping to have that process for banking completed well before Christmas this year. So thatâs the timetable plan on that. Iâd also refer the member, if she wants to go into more detail on thatâand I realise that sometimes the vocabulary and the language that is used around this sort of stuff is quite complicated and quite detailed, but the departmental report specifically relates to these issues and specifically paragraphs 73 to 77 of the departmental report refer.
There were also some questions about privacy rights. Well, of course, we have been careful to put into the legislation provisions that ensure that the Privacy Act is maintained and that, I think, provides the safeguards that the member will be looking for.
Lawrence Xu-Nan asked some questions around the role of the Ministry of Foreign Affairs and Tradeâhad they been consulted. What I can confirm is that the officials working on this bill have consulted very widely indeed and that no issues of the sort that he has questioned have arisen. So I take that to mean that, from an officialsâ point of view, no matters have been brought to their attention.
But in making that pointâbecause I think he raises an interesting question about trade agreements and the international scene and so forthâdata doesnât have geographic barriers. Data is data. What the barriers are are technical barriers. They are system barriers rather than lines on a map around the planet. So those are matters that we will have careful consideration of in terms of the regulations, and those will differ depending on which sector is being considered. The whole purpose of this legislation is to create the framework and then have separate regulatory constructs for each of the individual sectors that will then come under the purview of the legislation.
And, of course, in terms of third partiesâwell, a key feature of this legislation is the accreditation process and that will be watched and monitored very carefully.
Thank you, Mr Chair. I appreciate the Minister of Commerce and Consumer Affairsâ answers to these questions, and I want to pick up exactly where he left off with respect to the third-party matters. As I look at Part 1, clause 5(2), it says in there, âIn this Act, a person is involved in a contravention if the personââ, and then it goes on to explain it.
I also recall the comments made by my colleague Arena Williams around the definition of theftâor deceit, was it? I think it was deceitâin the Interpretation, and itâs quite clear because itâs in the Crimes Act and it makes it quite clear. So I wonder, just to be very specific on this one, if a person is involved in a contraventionâand, so it says there, â(a) has aided, abetted, counselledâ, and weâve talked about third partiesâI wonder, then, if deceit is considered deceit and itâs quite clear in the Crimes Act, whether or not anybody is involved in a contravention, as described here, why that doesnât fall under what would be considered deceit or, if youâre a third party, as it says there, has aided, abetted, or counselled. Just some clarification on that because this is to the point that weâve madeâand a number of speakers have since weâve started the committee of the whole House on this billâaround the confidence that the public have on matters of their data.
Before I resume my seatâbecause thatâs the very specific question I have for the MinisterâI just want to acknowledge the Ministerâs comment about how his data is his personal data. I know that a group called Te KÄhui Raraunga have done a lot of work on data sovereignty, so Iâm heartened by those kinds of comments from the Minister to make sure that there is data sovereignty and that that kind of information that is owned by us, by people, by real people. Accepting the Ministerâs definition that there arenât any hardline boundaries on these matters; as heâs also stated, shop fronts, if you will, have changed in ways, shape, form, and nature. Once, you used to have to go to a bank; now, you can do it all online. You used to have to go to a shop; now youâre accessing it through different portals online, etc. So itâs really important to understand, while there might not be those geographic boundaries, if you will, that we do operate in a world, in a time, and in a space that isnât defined, necessarily, by boundaries. But none the less, these functions of what would be seen as normal purchase, normal involvement in the economy, normal spaces of sharing our data still happens.
I just wanted to make that point but look forward to hearing from the Minister about that particular matter on the involvement in contravention, in particular with his statement around third parties.
Thank you, Mr Chair. I want to go to clause 4 and ask about the overview. What I noticed was, first of all, itâs a very unusual way of laying out a clause, and it seems a very effective way, actually. My understanding is that thatâs an attempt at a kind of plain language thatâs been adopted from the earlier iterations of the bill and kept because itâs seen as a way of people understanding their obligations very clearly. But it did lead me to ask some questions through it, which Iâd just like to go through. I also wanted to go, really, to subclause (6) of that, which says that âThis section is only a guide to the general scheme and effect of this Act.â So itâs in a place where we often have interpretations, etc. It doesnât actually have effect. So Iâd like the Minister of Commerce and Consumer Affairsâ comment on what place it has.
Then Iâd like to just look at the clause itself in terms of what itâs doing. Itâs talking about, in subclause (2), âServices relating to customer data are regulated as follows:â, and youâve got âIf ⌠A personâ, âThen âŚâ, âHowever âŚâ. There is a part of that when I get to âHoweverâ, where it says, âCertain protections apply, including duties toâconfirm that the customer has authorised the requestâ. Now, this is that a person using this knows that they should be confirming that the customer has authorised the request. I wondered how long that would be that they had for that issue and then they need to check the identity of the persons who make the requests. Again, how would they do that? How would they check the identity? And how do they check that the customer has authorised the request? Whatâs driving âhas to be madeâ? They also have to have a complaints process. My question there is: what would this look like, and where would they go to find those kinds of details which are sort of in line with this clause, very much practical ways of complying with the Act? Thank you, Minister.
Thank you, Minister, for your response. Just so I have absolute clarity, can I check with the Minister of Commerce and Consumer Affairs that the Ministry of Foreign Affairs and Trade has been consulted on this particular bill, in relation to the digital chapters of our trade agreements? That would be great.
Just to follow up from that, to give an example, letâs say we look at clause 11(1)(b)âor even indeed clause 11(4)âwhich talks about, âan overseas agency (B), in relation to any conduct by B in the course of carrying on business in New Zealandâ. The issue and some of the challenges that we do see in terms of the way that our trade agreements work and how our data works in this context, is the fact that some of theseâparticularly when weâre looking at some of the big techâdo not need to have an onshore presence, which means that some of them are not considered as carrying on business in New Zealand, because our domestic law has no jurisdiction over them. This is one of the things which would then lead toâif any issues and complaints, it will go to a supranational court, where people who are judges of that would traditionally be trade, as opposed to data or digitalâexperts.
Using clause 11(1)(b) as a very tangible example, when we are looking at something like this, and letâs say, for example, in the context of privacy, is the Minister saying that, for anythingâbecause itâs our data, and we do have that data sovereigntyâthat the privacy of our data, that big tech, even as a third-party provider to some of the companies because they certain technology to store or to use or to process their data, are liable and held accountable under domestic legislation, as suggested in clause 11(1)(b)?
Mr Chair, thank you for an opportunity to ask the Minister of Commerce and Consumer Affairs about the deception provision, which has changed in this bill. Iâm nervous that we will not get an opportunity to deal with this definition before we move on to the penalties clauses. I acknowledge that the Minister has given an answer about that change, but the change that I am asking for here is that the criminal definition of deception include a failure to disclose information when there is a duty to disclose. So thatâs like a failure by omission that is well established in the criminal law but only applies when there are positive duties.
So my question to him was: are the provisions in this legislation being read as duties on the people who have roles as data providers and data users under this, and therefore there is a deception by omission provision in this law? Because that wasnât there before. That omissions element is new. The penalties werenât designed when there was an omissions element, when you could be penalised for not providing something or being silent on the issue or being reckless as to whether you were silent.
The reason Iâm pressing this point in that section is because it then goes to all of the ways we might do enforcement around it. No one in the select committee room wanted a penalties regime where small fintechs were being held to standards and penalties if they were reckless as to whether they were silent on it. Absolutely hold them to account if they have had a data breach where they did something to actively provide the data to the wrong personâabsolutely. Their security systems are designed for that; that is a really important part of this regime. But where there is an omission, thatâs another thing and I just want to make sure that the Minister is comfortable with that. If heâs comfortable with that, then can he give us that indication and then we can deal with it in the penalties provisions, about what has changed since then?
In the EU cases on thisâthe only jurisdictions that have had any significant litigation on this around the access to data where omissions are concernedâthe courts have had a lot of costly litigation on this and they have a mechanism for doing that. Itâs by lots of consumers joining up together, whether thatâs through class action lawsuits provisions or organisations bringing cases on their behalf. We donât have that, so if we were needing to develop that through court systems, that would need to be individuals, me and you who use our banking services and might be plugged in to an app or might be getting financial information about our own practices through one of the fintechs or needing to do that law development. So itâs just not really possible in New Zealand. So I just wanted to clarify how that deception rule might be tested if it is a bit fuzzy.
Look, I just sense that weâre getting a little bit repetitive. So I just want to make it very clear that there is a provision at clause 5(2) which defines a terminology, and that says âinvolved in a contraventionâ, and I draw membersâ attention to that. So, âIn this Act, a person is involved in a contravention if the personâ(a) has aided, abetted, counselled, or procured the contravention; or (b) has induced, whether by threats or promises or otherwise, the contravention; or (c) has been in any way, directly or indirectly, knowingly concerned in, or party to, the contravention; or (d) has conspired with others to effect the contravention.â So thatâs a very broad and wide catch-all. I think that that is adequate, but I understand that the member may wish to pursue that in another part of the bill when we get to it.
I want to just comment on the question that was raised relating to overseas persons. Clause 11(1)(b) provides that the bill applies to overseas persons âcarrying on business in New Zealandâ, and subclause (3) clarifies that the person need not have a place of business in New Zealand. So I think that covers that.
In a specific response to Lawrence Xu-Nanâs question about the Ministry of Foreign Affairs and Trade (MFAT), I maybe didnât make it as clear as I should have done in my previous response, but Iâm able to confirm that, absolutely, MFAT was consulted, and no issues were raised about New Zealandâs trade agreements.
Then just in terms of the issue that was raised about overview, this is a bill that is technical in nature. We recognise that; we understand that. So that wording around âoverviewâ attempts to help explain the framework. Itâs sort of the written equivalent of a flow chart, if I can put it that way. Yes, itâs an interesting technique, but I think, ultimately, a very helpful one.
I move, That debate on this question now close.
Motion agreed to.
The question is that the Ministerâs amendments to Part 1 set out on Amendment Paper 254 be agreed to.
Amendments agreed to.
Part 1 as amended agreed to.
Part 2 Regulated data services