🧪 EXPERIMENTAL / ALPHA — this is an independent prototype, not an official record. Data may be incomplete or wrong - always check the linked Hansard source before relying on it.
Hot Air

Tuesday, 25 March 2025

Customer and Product Data Bill

Part 2 Regulated data services
HansardID: 9b81b17e-b2b6-42b8-ad16-20e50b5096fa
Back to debates
šŸ—£ļø Speech Teanau Tuiono (Green Party — List Member)
Time unknown

Members, we now come to Part 2. This is a debate on clauses 14 to 35A, ā€œRegulated data servicesā€. The question is that Part 2 stand part.

šŸ—£ļø Speech Dr Carlos Cheung (National Party — Member for Mt Roskill)
Time unknown

I move, That debate on this question now close.

šŸ—£ļø Speech Teanau Tuiono (Green Party — List Member)
Time unknown

I call the Hon Scott Simpson—

Hon Peeni Henare: A bit of enthusiasm on that side of the Chamber!

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Yes, very enthusiastic colleagues. Just before we start the debate on this part, I thought it might be helpful to members of the committee if I just spend a minute or two setting out what Part 2 really does. Part 2 contains the core obligations on regulated parties. This is a core aspect of this legislation. That means that certain designated businesses that hold data—known as the ā€œdata holdersā€ā€”must provide data and perform actions in response to requests from customers and accredited third parties. These core obligations for data holders to provide data and perform actions form the basis of the bill’s regime and is, in the main, the way the bill addresses the reluctance by businesses that hold customer data, information, and product data tightly at the moment—how that is going to be addressed. These obligations have been carefully designed to include the necessary elements for the protection of customers and the success of the entire regime.

A key obligation is in clauseĀ 27, where data holders will be required to operate electronic systems that automatically respond to these requests, and the bill recognises that we have moved beyond paper—thank goodness!—and need to make the most of the technological advances that are now available to us and in the future.

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

This is an important part of the bill, because many of the debates internationally on these regimes have been about balancing the rights of consumers to privacy whilst also giving innovators the ability to use this data and create products which not only advance consumers’ rights but create new products in the market that we haven’t been able to have before. So this ability to refuse a request for data in circumstances is key to that.

In the General Data Protection Regulation, which is the EU way of approaching this problem, this was key to why they had to design out privacy provisions at the same time as creating the consumer data rights, because you can imagine a situation where consumers have a level of enthusiasm for disclosing data and using data that is not conducive with other privacy rights. So you want to be able to consider those at the same time.

I want to ask the Minister of Commerce and Consumer Affairs, particularly around clauseĀ 16(1)(ea)—this is now framed in a way that relates to clauseĀ 5(2) in the language of ā€œcontraventionā€. So if you’ve been involved in a contravention of any obligation under this Act in connection with the request, then this comes into play. Why I’m asking this is because should that be read—is it ā€œdeceptive conductā€? Are we calling it something else? Is it a contravention? Is the data holder who is envisioned in clauseĀ 16(1)(ea) somebody who we think would be liable for penalties, or is the data holder imagined in clauseĀ 16(1)(ea) just required to make the refusal, and there are no flow-on effects of that in the system? I ask this because it also leads on to questions about the remedies available for consumers or whether there should be any remedies available for consumers at all.

šŸ—£ļø Speech Helen White (Labour Party — Member for Mt Albert)
Time unknown

I’d like to ask about clauseĀ 16, and particularly the provisions that are new—forms of harm. I can see that clauseĀ 16 is talking about a data holder refusing a request for data in certain circumstances, and it clearly started with a position that there has to be a serious threat to life, health, safety of the individual, or public health or public safety. But the inclusion of paragraph (ba)—so it’s clauseĀ 16(1)(ba) and (bb)—really broadens that. They’re really interesting additions, because they’re about the risk of serious financial harm to people.

I wondered whether the Minister of Commerce and Consumer Affairs could elaborate on the inclusion of that, and the inclusion of the next paragraph, which is about the data holder reasonably believing that it’s likely that the request was made as a consequence of deception as well. I guess, in this particular time, it’s probably pretty hard to know whether something’s going to cause serious financial harm in the space of giving out data, and I wondered what the Minister’s thoughts were around what was reasonable in the circumstances there. I’d be grateful for an answer about this clauseĀ and any more elaboration beyond what I’ve raised which might be an issue in this clauseĀ in terms of the refusal to give such information up.

šŸ—£ļø Speech Hon Peeni Henare (Labour Party — List Member)
Time unknown

Thank you, Mr Chair. Seeking your guidance too, Mr Chair: are we able to, in the Minister of Commerce and Consumer Affairs’ Amendment Paper, look towards his amendments at they pertain to Part 2?

CHAIRPERSON (Teanau Tuiono): We’re on Part 2.

Hon PEENI HENARE: Yeah, Part 2. So in this Amendment Paper, there are matters here that fall under the same clauses in Part 2. Just seeking your guidance.

CHAIRPERSON (Teanau Tuiono): Yeah, no, that’s fine.

Hon PEENI HENARE: Oh, perfect. Excellent. Thank you, Mr Chair. I read through those proposed changes from the Minister. I know that some of them are relatively straightforward. They seem like a systematic way of making sure there’s consistency in the bill.

There are, however, just a few things I think the committee would appreciate if the Minister could just explain a little bit why these amendments have come in. In particular, as I look towards the amendments that he’s proposing here, we’ve got here in clauseĀ 21—I know this sounds a little pedantic, but there’s a reason why these amendments have come in here. I want to make sure that, in order for us to look towards supporting the amendments that the Minister is proposing here, I hope that, more broadly speaking, the Minister might take a call to just explain through some of the more technical ones; not the ones where it is repeated in order for us to get consistency, but in particular some of the more detailed ones as described in his Amendment Paper.

The other one matter I want to raise with the Minister is looking towards the changes that are being made to clauseĀ 16. In that particular clause, as we look across the changes for subclauseĀ (1)(ba) and (bb), I’m looking at them, and I figure this fits under the mantle or under the banner of fraud more generally speaking. We’ve already traversed in Part 1 the definition of terms. But in this particular instance where it says, ā€œif the data holder reasonably believes that disclosure of the data would create a significant likelihood of serious financial harm to any person; orā€, and then in (bb) it states ā€œif the data holder reasonably believes that it is likely that the request was made (wholly or in part) as a consequence of deception;ā€, for me, this seems like, as my read of it—and, please, I ask the Minister to clarify if I’ve got this wrong—this is about a simple transaction where those who hold data, those who request that data, these are the grounds for which those who hold the data may continue to hold on to that data and not release it. That’s my reading of it.

I know it’s rather layman’s terms, but I wonder if the Minister wouldn’t mind taking a call just to make that very clear, as we’ve already touched on matters around deception and how it’s important to continue to maintain the integrity of the data that a person might give up and trust that somebody who’s holding that will continue to act in their best interests. If I think of recent cases of those who have been the sad victims of online fraud or online crimes and then have gone to banks and there’s been this whole merry-go-round, if you will, about what data can be released, who it can be released to, why didn’t certain parties do more to protect the victim in these instances, or at least withhold information where it looked like they may have been subject to fraudulent approaches by those who are requesting data or who have been able to access data. So I’ll leave those on the table for the Minister to consider.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you, Mr Chair. Again, several good questions from members of the committee. I want to just start this particular contribution by addressing the matter that Arena Williams raised relating to privacy. Of course, as I had explained when we were discussing the previous part, the Privacy Act applies. We have drafted this legislation in a way that gives the Privacy Act primacy in terms of protecting the privacy of customers, individuals, and I think that that regime is perfectly adequate for that.

But I want to just comment on the question of reasonableness, because throughout the legislation, there are several references to what’s reasonable behaviour, what’s reasonably expected, what’s reasonable access to information and data, and what’s reasonably not necessarily going to be available. I am relying, as many before me have done, on the very well-tested judicial interpretations of what’s reasonable and what’s not reasonable. It’s not for me to prejudge what that might look like, but I think that we can rely on our judiciary to interpret, should it be necessary, what reasonable looks like, and I’m very happy to let them do that.

In reference to the issue relating to refusing requests under clauseĀ 16(1)(ea), that was a fair question and one worthy of just exploring a little further. ClauseĀ 16(1)(ea) allows a data holder to refuse requests if the accredited person is in breach of the Act. Now, that may not involve any deception by the accredited requester or harm to the customer. Again, there is a protection there, and that particular clauseĀ doesn’t affect a customer’s ability to obtain redress if in fact there has been real harm.

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

I thank the Minister of Commerce and Consumer Affairs for that answer and that is helpful in thinking about how these contraventions work and how the other duties might sort of fit together with it. While I’m thinking about that, I want to ask him some other specific questions. I’ll take him to pageĀ 18; I’m on clauseĀ 21. The issue of how to deal with privacy when joint customers are involved has plagued the banks for many, many years; this is not a new issue. What do you do when you have a customer account of two people—perhaps it’s me and my husband—and then my husband rings up the bank and says, ā€œMy wife’s terrible, she’s down in Parliament giving a crazy speech. I want to lock her out of her bank account.ā€

Hon Scott Simpson: Surely not!

ARENA WILLIAMS: ā€œSurely not!ā€, says the Hon Scott Simpson. It is a real issue that the banks have had to deal with for many, many years. This doesn’t necessarily step that out. It is a very, very difficult issue to deal with, one that there is actually also not very useful case law on because banks, when they get this wrong, are incentivised to settle this issue directly with consumers. So I would like the Minister to take us through how this is meant to work, especially in an open banking context and how we might give especially fintechs, small fintechs that are certainly not going to be in the habit of settling big matters on a one-on-one basis because they just do not have the teams to do that—how they are going to work through these difficult issues.

The other question I have for him is which provision in this part—or how are these several provisions in this part—is going to guarantee data portability? Data portability was something that was submitted on a lot in the Economic Development, Science and Innovation Committee. It is the thing that would give consumers a lot of control when they are not necessarily shopping around all of their other options. But in, say, a banking context, being able to switch banks easily is one of the things that the Government points to as a really important banking reform and something that will drive competition in the market.

This is a different approach to almost every other jurisdiction that has done this. Most other pieces of legislation have a section that is called ā€œdata portabilityā€ and it deals with all of the ways you might expect data portability to be enshrined in law. I want the Minister to explain how these sort of more open-ended provisions guarantee that New Zealanders will be able to always point to their rights to move their data around. Because it’s one thing to be able to request it, it’s one thing to be able to have a third party requesting it, but it’s another thing to make sure that these things aren’t being turned down because of, say, commercial sensitivity. As well, I’d like him to give us a sense of whether the agglomerated data that consumers’ data might be used for is also portable.

Just to round out, a third question here is: there are a number of trade-offs that have been made in this part about trust and security in the system. Once these regimes are introduced in every jurisdiction that that they have been introduced in, there have been instances of public pushback because trust in the system has been undermined in some way, whether it’s tech companies, social media companies with data breaches and scandals about data sharing—so these aren’t hacking or scams; these are situations where data is shared in a way which is agreed and where companies can point to sort of ambiguous laws to justify their actions. They’re not illegal, but they do offend consumers’ perceptions of trust in the system. How are we making sure that the rights of consumers to use their data in a free and open way are still going to stand up to a level of scrutiny in the system once this is introduced?

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you, Mr Chair. I want to just comment on this question of joint customers because it’s a very fair and reasonable question, and it’s a practical one as well. The member Arena Williams cited a situation where, maybe, a couple have a joint bank account. One wants access to the data, and one may not, for a variety of reasons, notwithstanding the quality of her speech making. So if she goes further through clauseĀ 21, particularly 21(2), it says, ā€œA data holder and an accredited requestor must deal with the joint customers in the manner prescribed by the regulations,ā€ and then it goes on to list a series of things including ā€œconnection withā€ and so forth. But the key words in that clause are ā€œin the manner prescribed by the regulationsā€.

Now, as I’ve mentioned specifically in relation to Part 1 when we were discussing it, the regulations have yet to be drawn up. So the first cab off the rank will be banking, and then we’ve indicated that the next sector to be regulated under this bill—or this Act, when it’s passed—will be electricity. Now, the manner with which joint customers or joint data holders are treated in those two sectors may be different. So as much as I would like at this early stage to give the member the precise detail relating to what those regulations will look at, sadly that has yet to come.

I’ve indicated we’ll have the banking one done—my timetable wants to have that up and running before Christmas—and then we’ll move on to the next one. So that’s the area there, but I would encourage the member to look through the rest of that clause as she goes through it.

I want to just go back to a matter that was raised relating to grounds to refuse. I’ve been advised that the Economic Development, Science and Innovation Committee heard from submitters about the changes that were needed to refuse requests and that that those requests would cause significant harm. Now, the obvious example of that is where it might be a scam, there would be obvious harm. Again, it’s a matter of practicality, of sensibleness, and, to a degree, of common sense. So that’s provided for in that particular part.

šŸ—£ļø Speech Sam Uffindell (National Party — Member for Tauranga)
Time unknown

I move, That debate on this question now close.

šŸ—£ļø Speech Helen White (Labour Party — Member for Mt Albert)
Time unknown

Thank you. Thank you for the comment about the scams. It was what I had in mind, that we’re living in an age where also you often get that tension between a customer demanding information or demanding to be allowed the freedom to do something that, actually, the way the system is now picked up is extremely damaging in terms of those scams. They’re often their own worst enemy in those situations, and there is a balance needed between autonomy and that kind of harm happening.

I wanted to ask you about a couple of the other sections we haven’t gone through at all. The issue over clauseĀ 22—it’s a simple clause, where the data holder must provide to any person—I wondered how that would be effected with an individual, because it’s very different giving data across to a company that’s set up for it. But how does somebody actually ask for their own information, and how specific do they have to be and how general could they be? Could they be asking for crazy amounts of information, and how repetitive could that be? Because that certainly becomes something that some particular personality types like to do. So I just wondered how practically that have been thought through.

I also wanted to ask about the issue that is in clauseĀ 24, about secondary users. There are some very interesting examples there of household data. There’s the example, I think, of the electricity bill and trying to get the information around that, but you’ve not just got the customer who’s paying the bill; you’ve got a whole lot of other people within that household, as I understand it. So I’d invite and ask the Minister of Commerce and Consumer Affairs to explain to the general public what those sections are doing and how we have developed a system to perhaps cope with that situation of people in a broader group. Thank you, Minister.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you, Mr Chair. The answer to the question in relation to clauseĀ 22, ā€œData holder must provide product data to any personā€, is actually detailed in the lines below that. The clause specifically says, ā€œThis section applies ifā€ and then there are three provisions that I think would nicely limit the concerns that the member Helen White had.

So ā€œThis section applies if (a) a person requests that a data holder provides data to the person; and (b) the data is designated product data; and (c) the request (i) is a valid requestā€ā€”so not an extreme request; a valid requestā€”ā€œand (ii) is made using the system described in sectionĀ 27.ā€ So this is access to data provided by the accredited third party, so the consumer or the customer gives informed consent for that entity to gather the data from the data holder and then provide it back.

The member raises an interesting question about, maybe, information that might be available for your electricity usage. I’m envisaging a flatting situation where various flatmates might want to apportion appropriately the electricity usage amongst themselves. As a parent, I would have liked to have had that ability when my children were teenagers, but I’ve noticed that since they’ve become power bill - payers themselves, their use of electricity has changed appropriately.

I don’t know how that potential can exist, but I do know that there are some very smart operators out there who are probably, as we speak, trying to figure out ways that they can make that kind of application work in a way that is going to be meaningful and useful to electricity consumers and account holders. I’m very excited to wait and see what kind of options become available using their smarts.

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

Thank you, Mr Chair. I do so appreciate the Minister of Commerce and Consumer Affairs’ willingness to engage on this part. I want to ask him a further question and it’s about clauseĀ 34, on pageĀ 25—and here’s where I turn into a leery free-marketeer capitalist! You know, Minister, that I am very enthusiastic about this bill, and I want it to work very well, and I think that the industry have engaged deeply with the creation of these regulations over a really long period of time. So the creation of these new provisions where we’re possible giving officials further powers to draft regulations about the manner in which information is provided—they give me pause. They give me pause in this particular frame of mind anyway.

What I’m asking you here, Minister, is about clauseĀ 34(c), ā€œthe manner of notifying or making available the informationā€ could be read in two different ways. In an open banking scenario where you’ve got an industry body like Payments NZ doing a stellar job of driving this from an industry perspective where they have a legacy relationship with the major banks but they are also working very hard to include smaller players—varying expense and a range of feedback and views on that in the industry, but all together they have really stepped up to the plate. You have industries leading that, and so the prescribed manner in which information is being provided here, one would assume would have a level of industry buy-in—that that information being requested would not be used in a way that would benefit larger players as the expense of smaller players but would also turn out usable information.

What I’m getting at here is requiring small fintechs to give information in a way that lined up with the sort of information that the large banks hold would be unreasonable now, because the small players keep a range of different information on customers than the banks do. The banks have large—varyingly large but mostly very large—investments into tech systems that record transactions on a per-second basis with a range of other information and algorithms to analyse that data. Small players don’t.

If you were using rules that were restrictive under this kind of provision, then you could perhaps have a market impact and an anti-competitive impact. That’s one way to read it. Another way to read it might be there might be a bureaucratic overlay here, where Government is interested in a particular kind of data, a kind of presentation of data, that might not be industry-driven. So you need a balance between industry and Government setting this kind regulation, but that wasn’t what was envisioned first. It was envisioned in this overarching legislation that we would simply be talking about information, that there would be an information disclosure requirement, and then it would be up to secondary legislation, which, as we know, goes through fulsome consultation processes with industry where industry are consulted on the kind of information that they want, and that would be set out in the regulations.

I can certainly imagine industries where you would want to keep that very, very high level, where you wouldn’t want the regulator setting the sorts of calculations that providers were required to use. I want the Minister to explain where that’s come from, give the industry some certainty that that is, where possible, going to be industry led.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Just striking while the iron’s hot. The member Arena Williams was referring to clauseĀ 34(c) at the bottom of pageĀ 25. The answer to her question is, actually, if she turns the page and looks at the guidance note that says, ā€œsubpart 9 of Part 5 for provisions relating to the making of regulations and standards.ā€ So we aren’t at that part yet, but, with the indulgence of the Chair, I would point the member to looking towards the parts further into it.

There was the question I didn’t address relating to data portability. That’s also worth just noting that data portability is actually fundamental to the bill. Although the bill uses different terminology, the bill ensures data portability by imposing obligations for data holders to transfer data to customers and accredited requesters. These transfers must be in standard formats and allow the data to be used effectively. This whole regime isn’t going to work if the data holders then provide, through a variety of different mechanisms, kind of disjointed data, blurred data, or data in a format that isn’t actually usable to the to the provider.

Just going back to clauseĀ 22, the product data that it refers to is the sort of thing like mortgage rates, for instance, that are currently publicly available. But in order to make comparisons, that’s quite a complicated process. People kind of draw up their own little grid and they have a look at this bank or that bank or this mortgage adviser and then try and come to that themselves. The concept, I think, that’s very exciting is the potential for a fintech to actually provide that kind of comparative service to a person seeking a mortgage. I think that’s an ideal and classic example of how this legislation can be used.

šŸ—£ļø Speech Dr Vanessa Weenink (National Party — Member for Banks Peninsula)
Time unknown

I move, That debate on this question now close.

šŸ—£ļø Speech Helen White (Labour Party — Member for Mt Albert)
Time unknown

Thank you. I’d like to ask a question about clauseĀ 35A, and I’d like to get your comments on this—it’s actually 35 as well as 35A, so we’ll just put it in context there. You’ve got here a section that is about having to provide information, and if you don’t, then you’re going to be penalised and there’s going to be an infringement fee and a fine. Then, 35A has an exception to that, which is that you must not act if there are ā€œreasonable grounds to believe that the authorisation or instruction is given under the threat of physical or mental harm.ā€

Now, I appreciate the point that the Minister of Commerce and Consumer Affairs has made that some of that stuff about what’s reasonable is going to be resolved in the courts, but I wondered whether that standard would include things like domestic violence orders or whether people would be notifying, for example, the bank that there were issues around this, or what that kind of standard would be in that way, because I don’t know—I simply don’t know where that line would be at the moment.

I can see that there is a good spirit in this part of the bill, because we’re trying to deal with anti-competitive processes, etc., and this sort of brings in a balancing of the sort of personal, in a way. So it’s a personal circumstance that has been seen as a problem that should count against that kind of approach. So I’d be interested in that wider issue of why this particular exception is here, but also what practically that means for the general public. Thank you, Minister.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you, Mr Chair. Well, the protection and proviso in clauseĀ 35 is deliberately inserted to ensure that coercion, threats, potential blackmail—all those sorts of things that we often choose to not look at—are included in here. So I’m very pleased that these two clauses are in the bill. The member will note that there are some quite specific and fairly weighty penalties should coercion or threats be signified or be brought to the attention of the data provider.

So, again, it comes back to a question of reasonableness. How much information does someone need to know before they think that the request is being made under coercion? I don’t have a specific answer to that. I don’t think that’s quantifiable. That’s kind of a matter for individual data holders to determine. But what I do know is that for the various fintech companies that are going to be establishing these offers, these solutions, these tools, it’s in their best interests to ensure that the people they are engaging with and the entities they are engaging with are legitimate, that they operate under best practice, and that they assume all the obligations of a responsible corporate citizen that go with any kind of trading—whether it relates to this particular bill or any interaction, commercial, social, or personal.

šŸ—£ļø Speech Tim Costley (National Party — Member for Ōtaki)
Time unknown

I move, That debate on this question now close.

Motion agreed to.

šŸ—£ļø Speech Teanau Tuiono (Green Party — List Member)
Time unknown

The question is that the Minister’s amendments to Part 2 set out on Amendment Paper 254 be agreed to.

Amendments agreed to.

Part 2 as amended agreed to.

Part 3 Protections