🧪 EXPERIMENTAL / ALPHA — this is an independent prototype, not an official record. Data may be incomplete or wrong - always check the linked Hansard source before relying on it.
Hot Air

Tuesday, 25 March 2025

Customer and Product Data Bill

Part 1 Preliminary provisions (continued)
HansardID: 13b94a54-fa20-4cee-a7be-eeb79b2e1a26
Back to debates
🗣️ Speech Teanau Tuiono (Green Party — List Member)
Time unknown

Members, the House is in committee on the Customer and Product Data Bill. When we suspended for the lunch break, the committee was considering Part 1. This is the debate on clauses 3 to 13—“Preliminary provisions”—and Schedule 1. The question is that Part 1 stand part.

🗣️ Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

Thank you, Mr Chair. Before the House broke, we were having a very useful discussion with the Minister of Commerce and Consumer Affairs about the replacement provisions for derived data, which are set out in his Amendment Paper 254.

I want to ask him if he could give the members of the Economic Development, Science and Innovation Committee, who spent quite a long time agreeing in a cross-partisan way to the removal of derived data, some comfort that the new designated customer data provisions really are in the spirit of that cross-partisan agreement. There was agreement all around the table from the ACT Party to the Green Party that derived data, as it was framed in the bill, was not going to be workable, because we wanted the industry to hear from Government to go for it, to go for broke, to build out solutions, and to innovate.

So I want the Minister to step us through how the new provision will mean that industry still has all of the abilities and the empowering provisions in the legislation that they need to get things done and to not be hindered at all by the new provision. I’m thinking here particularly of the major accounting firms. The select committee had a really great submission from Xero about how derived data had just slowed things down in the Australian regime in a way that did not ultimately benefit consumers and certainly did not step out privacy rights.

A really useful part of the discussion was comparing how New Zealand’s privacy rights are really great. They’re a great framework for industry to work with. They’re a good principles basis for Government to also work with, and it means that we have an advantage here. We have an advantage of long-established law and well-understood principles about privacy that we can build from, rather than having to sort of build out two regimes as we go, and confuse the issue of transactional uses of data or the privacy protections that need to be in place for other sorts of uses.

So I’m keen on this idea, and Labour is still in principle supportive of this, but given that we are supportive of it but we’re also supportive of the whole select committee’s view that derived data had no place in this regime, can the Minister assure everyone that that commitment to cross-partisanship here is being honoured and that there won’t be an unnecessary slowing down of creating the useful products that derived data would have otherwise brought in?

I want to ask the Minister just to address the questions about how derived data came into the consultation. Many in the industry felt that it was late in the piece that it was introduced, especially when they’ve been engaging with the officials in good faith for a couple of years before the mention of that. It did really spook the horses; it felt like a new regime being built. So we want to know that this is not that by stealth.

🗣️ Speech Dr Lawrence Xu-Nan (Green Party — List Member)
Time unknown

Thank you, Mr Chair. I have a different line of questions for the Minister of Commerce and Consumer Affairs regarding clause 3 of Part 1 of the bill, which is under “Purpose”. I wanted to start with clause 3(1)(b) around “competition and innovation”. Now, going through the regulatory impact statement, we have seen a number of instances where the consultation was done with the Ministry of Business, Innovation and Employment (MBIE), which is understandable. However, what I couldn’t see—and this is a concern—is any consultation that was undertaken with the Ministry of Foreign Affairs and Trade (MFAT). Now, the reason I ask this question is, sure, there’s been a lot of information within the regulatory impact statement around what other countries are doing. We know, for example, the EU is particularly good when it comes to data protection, whereas the US is particularly bad at data protection. However, as we see through a number of our international trade deals—such as the Trans-Pacific Partnership Agreement (TPPA), the NZ-UK Free Trade Agreement, and the NZ-EU Free Trade Agreement (NZ-EU FTA)—each of them will contain a digital economy chapter which, then, pertains to how data can be held accountable within those.

The reason I mention that, in the context of this bill and particularly under the purpose clause, is—and we can go into further details later—around the fact that, for example, under the TPPA, there are specifically clauses about the ability for Governments to be able to challenge or to be able to create that competition under that particular trade agreement. Now, understanding we’re looking at the broader context of trade, in those kinds of cases, we have seen instances where big tech from the US has been able to use free-trade agreements (FTAs)—or particularly digital economy and trade parts of an FTA—as a tool of creating a monopoly or creating uncompetitive behaviour in certain marketplaces.

One of the examples that’s currently happening right now, although it’s not within our Aotearoa context, is the fact that Musk is currently suing the Indian Government for non-competitive behaviour, or for discriminatory behaviour, under certain trade agreements. So my first question is around whether the Minister has any clarity or clarification on whether MFAT has been consulted, in the context of this particular bill, specifically under the digital economy chapters.

Now, following on in the same vein, the question that you mentioned, Minister—and I think it’s a really important question to ask—is: it is my data, therefore I should be able to be able to use it in a way that I want to. However, that data sovereignty also is questionable under international trade deals and agreements, particularly from the perspective that in certain trade deals—and, again, I go back to the TPPA and the Comprehensive and Progressive Agreement for Trans-Pacific Partnership, which doesn’t exist, thankfully, under some of the newer ones like the NZ-EU FTA.

For example, in certain trade deals, we are not, under those trade deals, allowed to have that data being held onshore. In fact, there are certain trade agreements where we can’t even hold that data or have a copy of our own data onshore, because there’s no need for there to be an onshore presence. So, in this particular case, when the Minister is talking about onshore data and my data, what reassurances does the Minister have, from various consultations, that the data that we are holding under the requirement of this legislation, indeed, is allowed to be held onshore? Another example is the NZ-EU FTA, which, now, does allow us to hold a copy of that, but, again, there is no specific requirements for the original data centre to be held onshore.

The last question I have for the Minister is around clause 3(2)(c) in terms of “requiring certain safeguards, controls, standards, and functionality”, and I particularly want to hone in on the idea of third parties that are authorised, because, again, we have seen instances where, yes, although the data is being held by a particular company or a particular provider, but the data system itself—for example, let’s say Google or Meta, etc.—the data is not within the jurisdiction of those particular companies. So when we’re looking at creating safeguards, controls, and standards, does that mean that the liability is held within the companies themselves, or, originally, will some of those data collections or those kind of big tech elements ultimately be liable?

Again, in some of our trade agreements, there are certain clauses that mean that big tech companies are not liable for violation by a third party. So those are the three questions I have for the Minister: has there been consultation with MFAT in terms of consistency with our trade agreements? I know it’s quite a big concern in terms of the MBIE-MFAT interaction in this case. When we’re looking at my data, I can choose to use it in my way. What does data sovereignty in the context of this bill mean, and does that, again, come into conflict with some of the issues we see with our trade agreements? And, lastly, when we’re looking at third-party safeguards, controls, and standards, is this to do with the company that holds the data, and what happens if the companies themselves don’t hold the data but the data is being moved to a third-party provider—i.e., a big tech?

🗣️ Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you very much, Mr Chair. I want to just cover off on a couple of the questions that have been asked by members who have clearly been giving good and considered thought to this part of the bill.

I just want to go back to the derived data question that Arena Williams raised, because it is interesting. I want to make it very clear that my Amendment Paper actually doesn’t reintroduce derived data into the legislation. The Economic Development, Science and Innovation Committee made it very clear that for a variety of reasons it needed not to be included. But what the Amendment Paper does do is it clarifies the designated customer data as the specific types of data designated through the regulations. Now, what all that means is that the regulations contain the detail, not the legislation. The regulations have yet to be completely drafted, but they will be commenced and put into place before the legislation can be enlivened or switched on, if I can put it that way. We’re hoping to have that process for banking completed well before Christmas this year. So that’s the timetable plan on that. I’d also refer the member, if she wants to go into more detail on that—and I realise that sometimes the vocabulary and the language that is used around this sort of stuff is quite complicated and quite detailed, but the departmental report specifically relates to these issues and specifically paragraphs 73 to 77 of the departmental report refer.

There were also some questions about privacy rights. Well, of course, we have been careful to put into the legislation provisions that ensure that the Privacy Act is maintained and that, I think, provides the safeguards that the member will be looking for.

Lawrence Xu-Nan asked some questions around the role of the Ministry of Foreign Affairs and Trade—had they been consulted. What I can confirm is that the officials working on this bill have consulted very widely indeed and that no issues of the sort that he has questioned have arisen. So I take that to mean that, from an officials’ point of view, no matters have been brought to their attention.

But in making that point—because I think he raises an interesting question about trade agreements and the international scene and so forth—data doesn’t have geographic barriers. Data is data. What the barriers are are technical barriers. They are system barriers rather than lines on a map around the planet. So those are matters that we will have careful consideration of in terms of the regulations, and those will differ depending on which sector is being considered. The whole purpose of this legislation is to create the framework and then have separate regulatory constructs for each of the individual sectors that will then come under the purview of the legislation.

And, of course, in terms of third parties—well, a key feature of this legislation is the accreditation process and that will be watched and monitored very carefully.

🗣️ Speech Hon Peeni Henare (Labour Party — List Member)
Time unknown

Thank you, Mr Chair. I appreciate the Minister of Commerce and Consumer Affairs’ answers to these questions, and I want to pick up exactly where he left off with respect to the third-party matters. As I look at Part 1, clause 5(2), it says in there, “In this Act, a person is involved in a contravention if the person—”, and then it goes on to explain it.

I also recall the comments made by my colleague Arena Williams around the definition of theft—or deceit, was it? I think it was deceit—in the Interpretation, and it’s quite clear because it’s in the Crimes Act and it makes it quite clear. So I wonder, just to be very specific on this one, if a person is involved in a contravention—and, so it says there, “(a) has aided, abetted, counselled”, and we’ve talked about third parties—I wonder, then, if deceit is considered deceit and it’s quite clear in the Crimes Act, whether or not anybody is involved in a contravention, as described here, why that doesn’t fall under what would be considered deceit or, if you’re a third party, as it says there, has aided, abetted, or counselled. Just some clarification on that because this is to the point that we’ve made—and a number of speakers have since we’ve started the committee of the whole House on this bill—around the confidence that the public have on matters of their data.

Before I resume my seat—because that’s the very specific question I have for the Minister—I just want to acknowledge the Minister’s comment about how his data is his personal data. I know that a group called Te Kāhui Raraunga have done a lot of work on data sovereignty, so I’m heartened by those kinds of comments from the Minister to make sure that there is data sovereignty and that that kind of information that is owned by us, by people, by real people. Accepting the Minister’s definition that there aren’t any hardline boundaries on these matters; as he’s also stated, shop fronts, if you will, have changed in ways, shape, form, and nature. Once, you used to have to go to a bank; now, you can do it all online. You used to have to go to a shop; now you’re accessing it through different portals online, etc. So it’s really important to understand, while there might not be those geographic boundaries, if you will, that we do operate in a world, in a time, and in a space that isn’t defined, necessarily, by boundaries. But none the less, these functions of what would be seen as normal purchase, normal involvement in the economy, normal spaces of sharing our data still happens.

I just wanted to make that point but look forward to hearing from the Minister about that particular matter on the involvement in contravention, in particular with his statement around third parties.

🗣️ Speech Helen White (Labour Party — Member for Mt Albert)
Time unknown

Thank you, Mr Chair. I want to go to clause 4 and ask about the overview. What I noticed was, first of all, it’s a very unusual way of laying out a clause, and it seems a very effective way, actually. My understanding is that that’s an attempt at a kind of plain language that’s been adopted from the earlier iterations of the bill and kept because it’s seen as a way of people understanding their obligations very clearly. But it did lead me to ask some questions through it, which I’d just like to go through. I also wanted to go, really, to subclause (6) of that, which says that “This section is only a guide to the general scheme and effect of this Act.” So it’s in a place where we often have interpretations, etc. It doesn’t actually have effect. So I’d like the Minister of Commerce and Consumer Affairs’ comment on what place it has.

Then I’d like to just look at the clause itself in terms of what it’s doing. It’s talking about, in subclause (2), “Services relating to customer data are regulated as follows:”, and you’ve got “If … A person”, “Then …”, “However …”. There is a part of that when I get to “However”, where it says, “Certain protections apply, including duties to—confirm that the customer has authorised the request”. Now, this is that a person using this knows that they should be confirming that the customer has authorised the request. I wondered how long that would be that they had for that issue and then they need to check the identity of the persons who make the requests. Again, how would they do that? How would they check the identity? And how do they check that the customer has authorised the request? What’s driving “has to be made”? They also have to have a complaints process. My question there is: what would this look like, and where would they go to find those kinds of details which are sort of in line with this clause, very much practical ways of complying with the Act? Thank you, Minister.

🗣️ Speech Dr Lawrence Xu-Nan (Green Party — List Member)
Time unknown

Thank you, Minister, for your response. Just so I have absolute clarity, can I check with the Minister of Commerce and Consumer Affairs that the Ministry of Foreign Affairs and Trade has been consulted on this particular bill, in relation to the digital chapters of our trade agreements? That would be great.

Just to follow up from that, to give an example, let’s say we look at clause 11(1)(b)—or even indeed clause 11(4)—which talks about, “an overseas agency (B), in relation to any conduct by B in the course of carrying on business in New Zealand”. The issue and some of the challenges that we do see in terms of the way that our trade agreements work and how our data works in this context, is the fact that some of these—particularly when we’re looking at some of the big tech—do not need to have an onshore presence, which means that some of them are not considered as carrying on business in New Zealand, because our domestic law has no jurisdiction over them. This is one of the things which would then lead to—if any issues and complaints, it will go to a supranational court, where people who are judges of that would traditionally be trade, as opposed to data or digital—experts.

Using clause 11(1)(b) as a very tangible example, when we are looking at something like this, and let’s say, for example, in the context of privacy, is the Minister saying that, for anything—because it’s our data, and we do have that data sovereignty—that the privacy of our data, that big tech, even as a third-party provider to some of the companies because they certain technology to store or to use or to process their data, are liable and held accountable under domestic legislation, as suggested in clause 11(1)(b)?

🗣️ Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

Mr Chair, thank you for an opportunity to ask the Minister of Commerce and Consumer Affairs about the deception provision, which has changed in this bill. I’m nervous that we will not get an opportunity to deal with this definition before we move on to the penalties clauses. I acknowledge that the Minister has given an answer about that change, but the change that I am asking for here is that the criminal definition of deception include a failure to disclose information when there is a duty to disclose. So that’s like a failure by omission that is well established in the criminal law but only applies when there are positive duties.

So my question to him was: are the provisions in this legislation being read as duties on the people who have roles as data providers and data users under this, and therefore there is a deception by omission provision in this law? Because that wasn’t there before. That omissions element is new. The penalties weren’t designed when there was an omissions element, when you could be penalised for not providing something or being silent on the issue or being reckless as to whether you were silent.

The reason I’m pressing this point in that section is because it then goes to all of the ways we might do enforcement around it. No one in the select committee room wanted a penalties regime where small fintechs were being held to standards and penalties if they were reckless as to whether they were silent on it. Absolutely hold them to account if they have had a data breach where they did something to actively provide the data to the wrong person—absolutely. Their security systems are designed for that; that is a really important part of this regime. But where there is an omission, that’s another thing and I just want to make sure that the Minister is comfortable with that. If he’s comfortable with that, then can he give us that indication and then we can deal with it in the penalties provisions, about what has changed since then?

In the EU cases on this—the only jurisdictions that have had any significant litigation on this around the access to data where omissions are concerned—the courts have had a lot of costly litigation on this and they have a mechanism for doing that. It’s by lots of consumers joining up together, whether that’s through class action lawsuits provisions or organisations bringing cases on their behalf. We don’t have that, so if we were needing to develop that through court systems, that would need to be individuals, me and you who use our banking services and might be plugged in to an app or might be getting financial information about our own practices through one of the fintechs or needing to do that law development. So it’s just not really possible in New Zealand. So I just wanted to clarify how that deception rule might be tested if it is a bit fuzzy.

🗣️ Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Look, I just sense that we’re getting a little bit repetitive. So I just want to make it very clear that there is a provision at clause 5(2) which defines a terminology, and that says “involved in a contravention”, and I draw members’ attention to that. So, “In this Act, a person is involved in a contravention if the person—(a) has aided, abetted, counselled, or procured the contravention; or (b) has induced, whether by threats or promises or otherwise, the contravention; or (c) has been in any way, directly or indirectly, knowingly concerned in, or party to, the contravention; or (d) has conspired with others to effect the contravention.” So that’s a very broad and wide catch-all. I think that that is adequate, but I understand that the member may wish to pursue that in another part of the bill when we get to it.

I want to just comment on the question that was raised relating to overseas persons. Clause 11(1)(b) provides that the bill applies to overseas persons “carrying on business in New Zealand”, and subclause (3) clarifies that the person need not have a place of business in New Zealand. So I think that covers that.

In a specific response to Lawrence Xu-Nan’s question about the Ministry of Foreign Affairs and Trade (MFAT), I maybe didn’t make it as clear as I should have done in my previous response, but I’m able to confirm that, absolutely, MFAT was consulted, and no issues were raised about New Zealand’s trade agreements.

Then just in terms of the issue that was raised about overview, this is a bill that is technical in nature. We recognise that; we understand that. So that wording around “overview” attempts to help explain the framework. It’s sort of the written equivalent of a flow chart, if I can put it that way. Yes, it’s an interesting technique, but I think, ultimately, a very helpful one.

🗣️ Speech Tim Costley (National Party — Member for Ōtaki)
Time unknown

I move, That debate on this question now close.

Motion agreed to.

🗣️ Speech Teanau Tuiono (Green Party — List Member)
Time unknown

The question is that the Minister’s amendments to Part 1 set out on Amendment Paper 254 be agreed to.

Amendments agreed to.

Part 1 as amended agreed to.

Part 2 Regulated data services