Customer and Product Data Bill
Members, we now come to Part 2. This is a debate on clauses 14 to 35A, āRegulated data servicesā. The question is that Part 2 stand part.
I move, That debate on this question now close.
I call the Hon Scott Simpsonā
Hon Peeni Henare: A bit of enthusiasm on that side of the Chamber!
Yes, very enthusiastic colleagues. Just before we start the debate on this part, I thought it might be helpful to members of the committee if I just spend a minute or two setting out what Part 2 really does. Part 2 contains the core obligations on regulated parties. This is a core aspect of this legislation. That means that certain designated businesses that hold dataāknown as the ādata holdersāāmust provide data and perform actions in response to requests from customers and accredited third parties. These core obligations for data holders to provide data and perform actions form the basis of the billās regime and is, in the main, the way the bill addresses the reluctance by businesses that hold customer data, information, and product data tightly at the momentāhow that is going to be addressed. These obligations have been carefully designed to include the necessary elements for the protection of customers and the success of the entire regime.
A key obligation is in clauseĀ 27, where data holders will be required to operate electronic systems that automatically respond to these requests, and the bill recognises that we have moved beyond paperāthank goodness!āand need to make the most of the technological advances that are now available to us and in the future.
This is an important part of the bill, because many of the debates internationally on these regimes have been about balancing the rights of consumers to privacy whilst also giving innovators the ability to use this data and create products which not only advance consumersā rights but create new products in the market that we havenāt been able to have before. So this ability to refuse a request for data in circumstances is key to that.
In the General Data Protection Regulation, which is the EU way of approaching this problem, this was key to why they had to design out privacy provisions at the same time as creating the consumer data rights, because you can imagine a situation where consumers have a level of enthusiasm for disclosing data and using data that is not conducive with other privacy rights. So you want to be able to consider those at the same time.
I want to ask the Minister of Commerce and Consumer Affairs, particularly around clauseĀ 16(1)(ea)āthis is now framed in a way that relates to clauseĀ 5(2) in the language of ācontraventionā. So if youāve been involved in a contravention of any obligation under this Act in connection with the request, then this comes into play. Why Iām asking this is because should that be readāis it ādeceptive conductā? Are we calling it something else? Is it a contravention? Is the data holder who is envisioned in clauseĀ 16(1)(ea) somebody who we think would be liable for penalties, or is the data holder imagined in clauseĀ 16(1)(ea) just required to make the refusal, and there are no flow-on effects of that in the system? I ask this because it also leads on to questions about the remedies available for consumers or whether there should be any remedies available for consumers at all.
Iād like to ask about clauseĀ 16, and particularly the provisions that are newāforms of harm. I can see that clauseĀ 16 is talking about a data holder refusing a request for data in certain circumstances, and it clearly started with a position that there has to be a serious threat to life, health, safety of the individual, or public health or public safety. But the inclusion of paragraph (ba)āso itās clauseĀ 16(1)(ba) and (bb)āreally broadens that. Theyāre really interesting additions, because theyāre about the risk of serious financial harm to people.
I wondered whether the Minister of Commerce and Consumer Affairs could elaborate on the inclusion of that, and the inclusion of the next paragraph, which is about the data holder reasonably believing that itās likely that the request was made as a consequence of deception as well. I guess, in this particular time, itās probably pretty hard to know whether somethingās going to cause serious financial harm in the space of giving out data, and I wondered what the Ministerās thoughts were around what was reasonable in the circumstances there. Iād be grateful for an answer about this clauseĀ and any more elaboration beyond what Iāve raised which might be an issue in this clauseĀ in terms of the refusal to give such information up.
Thank you, Mr Chair. Seeking your guidance too, Mr Chair: are we able to, in the Minister of Commerce and Consumer Affairsā Amendment Paper, look towards his amendments at they pertain to Part 2?
CHAIRPERSON (Teanau Tuiono): Weāre on Part 2.
Hon PEENI HENARE: Yeah, Part 2. So in this Amendment Paper, there are matters here that fall under the same clauses in Part 2. Just seeking your guidance.
CHAIRPERSON (Teanau Tuiono): Yeah, no, thatās fine.
Hon PEENI HENARE: Oh, perfect. Excellent. Thank you, Mr Chair. I read through those proposed changes from the Minister. I know that some of them are relatively straightforward. They seem like a systematic way of making sure thereās consistency in the bill.
There are, however, just a few things I think the committee would appreciate if the Minister could just explain a little bit why these amendments have come in. In particular, as I look towards the amendments that heās proposing here, weāve got here in clauseĀ 21āI know this sounds a little pedantic, but thereās a reason why these amendments have come in here. I want to make sure that, in order for us to look towards supporting the amendments that the Minister is proposing here, I hope that, more broadly speaking, the Minister might take a call to just explain through some of the more technical ones; not the ones where it is repeated in order for us to get consistency, but in particular some of the more detailed ones as described in his Amendment Paper.
The other one matter I want to raise with the Minister is looking towards the changes that are being made to clauseĀ 16. In that particular clause, as we look across the changes for subclauseĀ (1)(ba) and (bb), Iām looking at them, and I figure this fits under the mantle or under the banner of fraud more generally speaking. Weāve already traversed in Part 1 the definition of terms. But in this particular instance where it says, āif the data holder reasonably believes that disclosure of the data would create a significant likelihood of serious financial harm to any person; orā, and then in (bb) it states āif the data holder reasonably believes that it is likely that the request was made (wholly or in part) as a consequence of deception;ā, for me, this seems like, as my read of itāand, please, I ask the Minister to clarify if Iāve got this wrongāthis is about a simple transaction where those who hold data, those who request that data, these are the grounds for which those who hold the data may continue to hold on to that data and not release it. Thatās my reading of it.
I know itās rather laymanās terms, but I wonder if the Minister wouldnāt mind taking a call just to make that very clear, as weāve already touched on matters around deception and how itās important to continue to maintain the integrity of the data that a person might give up and trust that somebody whoās holding that will continue to act in their best interests. If I think of recent cases of those who have been the sad victims of online fraud or online crimes and then have gone to banks and thereās been this whole merry-go-round, if you will, about what data can be released, who it can be released to, why didnāt certain parties do more to protect the victim in these instances, or at least withhold information where it looked like they may have been subject to fraudulent approaches by those who are requesting data or who have been able to access data. So Iāll leave those on the table for the Minister to consider.
Thank you, Mr Chair. Again, several good questions from members of the committee. I want to just start this particular contribution by addressing the matter that Arena Williams raised relating to privacy. Of course, as I had explained when we were discussing the previous part, the Privacy Act applies. We have drafted this legislation in a way that gives the Privacy Act primacy in terms of protecting the privacy of customers, individuals, and I think that that regime is perfectly adequate for that.
But I want to just comment on the question of reasonableness, because throughout the legislation, there are several references to whatās reasonable behaviour, whatās reasonably expected, whatās reasonable access to information and data, and whatās reasonably not necessarily going to be available. I am relying, as many before me have done, on the very well-tested judicial interpretations of whatās reasonable and whatās not reasonable. Itās not for me to prejudge what that might look like, but I think that we can rely on our judiciary to interpret, should it be necessary, what reasonable looks like, and Iām very happy to let them do that.
In reference to the issue relating to refusing requests under clauseĀ 16(1)(ea), that was a fair question and one worthy of just exploring a little further. ClauseĀ 16(1)(ea) allows a data holder to refuse requests if the accredited person is in breach of the Act. Now, that may not involve any deception by the accredited requester or harm to the customer. Again, there is a protection there, and that particular clauseĀ doesnāt affect a customerās ability to obtain redress if in fact there has been real harm.
I thank the Minister of Commerce and Consumer Affairs for that answer and that is helpful in thinking about how these contraventions work and how the other duties might sort of fit together with it. While Iām thinking about that, I want to ask him some other specific questions. Iāll take him to pageĀ 18; Iām on clauseĀ 21. The issue of how to deal with privacy when joint customers are involved has plagued the banks for many, many years; this is not a new issue. What do you do when you have a customer account of two peopleāperhaps itās me and my husbandāand then my husband rings up the bank and says, āMy wifeās terrible, sheās down in Parliament giving a crazy speech. I want to lock her out of her bank account.ā
Hon Scott Simpson: Surely not!
ARENA WILLIAMS: āSurely not!ā, says the Hon Scott Simpson. It is a real issue that the banks have had to deal with for many, many years. This doesnāt necessarily step that out. It is a very, very difficult issue to deal with, one that there is actually also not very useful case law on because banks, when they get this wrong, are incentivised to settle this issue directly with consumers. So I would like the Minister to take us through how this is meant to work, especially in an open banking context and how we might give especially fintechs, small fintechs that are certainly not going to be in the habit of settling big matters on a one-on-one basis because they just do not have the teams to do thatāhow they are going to work through these difficult issues.
The other question I have for him is which provision in this partāor how are these several provisions in this partāis going to guarantee data portability? Data portability was something that was submitted on a lot in the Economic Development, Science and Innovation Committee. It is the thing that would give consumers a lot of control when they are not necessarily shopping around all of their other options. But in, say, a banking context, being able to switch banks easily is one of the things that the Government points to as a really important banking reform and something that will drive competition in the market.
This is a different approach to almost every other jurisdiction that has done this. Most other pieces of legislation have a section that is called ādata portabilityā and it deals with all of the ways you might expect data portability to be enshrined in law. I want the Minister to explain how these sort of more open-ended provisions guarantee that New Zealanders will be able to always point to their rights to move their data around. Because itās one thing to be able to request it, itās one thing to be able to have a third party requesting it, but itās another thing to make sure that these things arenāt being turned down because of, say, commercial sensitivity. As well, Iād like him to give us a sense of whether the agglomerated data that consumersā data might be used for is also portable.
Just to round out, a third question here is: there are a number of trade-offs that have been made in this part about trust and security in the system. Once these regimes are introduced in every jurisdiction that that they have been introduced in, there have been instances of public pushback because trust in the system has been undermined in some way, whether itās tech companies, social media companies with data breaches and scandals about data sharingāso these arenāt hacking or scams; these are situations where data is shared in a way which is agreed and where companies can point to sort of ambiguous laws to justify their actions. Theyāre not illegal, but they do offend consumersā perceptions of trust in the system. How are we making sure that the rights of consumers to use their data in a free and open way are still going to stand up to a level of scrutiny in the system once this is introduced?
Thank you, Mr Chair. I want to just comment on this question of joint customers because itās a very fair and reasonable question, and itās a practical one as well. The member Arena Williams cited a situation where, maybe, a couple have a joint bank account. One wants access to the data, and one may not, for a variety of reasons, notwithstanding the quality of her speech making. So if she goes further through clauseĀ 21, particularly 21(2), it says, āA data holder and an accredited requestor must deal with the joint customers in the manner prescribed by the regulations,ā and then it goes on to list a series of things including āconnection withā and so forth. But the key words in that clause are āin the manner prescribed by the regulationsā.
Now, as Iāve mentioned specifically in relation to Part 1 when we were discussing it, the regulations have yet to be drawn up. So the first cab off the rank will be banking, and then weāve indicated that the next sector to be regulated under this billāor this Act, when itās passedāwill be electricity. Now, the manner with which joint customers or joint data holders are treated in those two sectors may be different. So as much as I would like at this early stage to give the member the precise detail relating to what those regulations will look at, sadly that has yet to come.
Iāve indicated weāll have the banking one doneāmy timetable wants to have that up and running before Christmasāand then weāll move on to the next one. So thatās the area there, but I would encourage the member to look through the rest of that clause as she goes through it.
I want to just go back to a matter that was raised relating to grounds to refuse. Iāve been advised that the Economic Development, Science and Innovation Committee heard from submitters about the changes that were needed to refuse requests and that that those requests would cause significant harm. Now, the obvious example of that is where it might be a scam, there would be obvious harm. Again, itās a matter of practicality, of sensibleness, and, to a degree, of common sense. So thatās provided for in that particular part.
I move, That debate on this question now close.
Thank you. Thank you for the comment about the scams. It was what I had in mind, that weāre living in an age where also you often get that tension between a customer demanding information or demanding to be allowed the freedom to do something that, actually, the way the system is now picked up is extremely damaging in terms of those scams. Theyāre often their own worst enemy in those situations, and there is a balance needed between autonomy and that kind of harm happening.
I wanted to ask you about a couple of the other sections we havenāt gone through at all. The issue over clauseĀ 22āitās a simple clause, where the data holder must provide to any personāI wondered how that would be effected with an individual, because itās very different giving data across to a company thatās set up for it. But how does somebody actually ask for their own information, and how specific do they have to be and how general could they be? Could they be asking for crazy amounts of information, and how repetitive could that be? Because that certainly becomes something that some particular personality types like to do. So I just wondered how practically that have been thought through.
I also wanted to ask about the issue that is in clauseĀ 24, about secondary users. There are some very interesting examples there of household data. Thereās the example, I think, of the electricity bill and trying to get the information around that, but youāve not just got the customer whoās paying the bill; youāve got a whole lot of other people within that household, as I understand it. So Iād invite and ask the Minister of Commerce and Consumer Affairs to explain to the general public what those sections are doing and how we have developed a system to perhaps cope with that situation of people in a broader group. Thank you, Minister.
Thank you, Mr Chair. The answer to the question in relation to clauseĀ 22, āData holder must provide product data to any personā, is actually detailed in the lines below that. The clause specifically says, āThis section applies ifā and then there are three provisions that I think would nicely limit the concerns that the member Helen White had.
So āThis section applies if (a) a person requests that a data holder provides data to the person; and (b) the data is designated product data; and (c) the request (i) is a valid requestāāso not an extreme request; a valid requestāāand (ii) is made using the system described in sectionĀ 27.ā So this is access to data provided by the accredited third party, so the consumer or the customer gives informed consent for that entity to gather the data from the data holder and then provide it back.
The member raises an interesting question about, maybe, information that might be available for your electricity usage. Iām envisaging a flatting situation where various flatmates might want to apportion appropriately the electricity usage amongst themselves. As a parent, I would have liked to have had that ability when my children were teenagers, but Iāve noticed that since theyāve become power bill - payers themselves, their use of electricity has changed appropriately.
I donāt know how that potential can exist, but I do know that there are some very smart operators out there who are probably, as we speak, trying to figure out ways that they can make that kind of application work in a way that is going to be meaningful and useful to electricity consumers and account holders. Iām very excited to wait and see what kind of options become available using their smarts.
Thank you, Mr Chair. I do so appreciate the Minister of Commerce and Consumer Affairsā willingness to engage on this part. I want to ask him a further question and itās about clauseĀ 34, on pageĀ 25āand hereās where I turn into a leery free-marketeer capitalist! You know, Minister, that I am very enthusiastic about this bill, and I want it to work very well, and I think that the industry have engaged deeply with the creation of these regulations over a really long period of time. So the creation of these new provisions where weāre possible giving officials further powers to draft regulations about the manner in which information is providedāthey give me pause. They give me pause in this particular frame of mind anyway.
What Iām asking you here, Minister, is about clauseĀ 34(c), āthe manner of notifying or making available the informationā could be read in two different ways. In an open banking scenario where youāve got an industry body like Payments NZ doing a stellar job of driving this from an industry perspective where they have a legacy relationship with the major banks but they are also working very hard to include smaller playersāvarying expense and a range of feedback and views on that in the industry, but all together they have really stepped up to the plate. You have industries leading that, and so the prescribed manner in which information is being provided here, one would assume would have a level of industry buy-ināthat that information being requested would not be used in a way that would benefit larger players as the expense of smaller players but would also turn out usable information.
What Iām getting at here is requiring small fintechs to give information in a way that lined up with the sort of information that the large banks hold would be unreasonable now, because the small players keep a range of different information on customers than the banks do. The banks have largeāvaryingly large but mostly very largeāinvestments into tech systems that record transactions on a per-second basis with a range of other information and algorithms to analyse that data. Small players donāt.
If you were using rules that were restrictive under this kind of provision, then you could perhaps have a market impact and an anti-competitive impact. Thatās one way to read it. Another way to read it might be there might be a bureaucratic overlay here, where Government is interested in a particular kind of data, a kind of presentation of data, that might not be industry-driven. So you need a balance between industry and Government setting this kind regulation, but that wasnāt what was envisioned first. It was envisioned in this overarching legislation that we would simply be talking about information, that there would be an information disclosure requirement, and then it would be up to secondary legislation, which, as we know, goes through fulsome consultation processes with industry where industry are consulted on the kind of information that they want, and that would be set out in the regulations.
I can certainly imagine industries where you would want to keep that very, very high level, where you wouldnāt want the regulator setting the sorts of calculations that providers were required to use. I want the Minister to explain where thatās come from, give the industry some certainty that that is, where possible, going to be industry led.
Just striking while the ironās hot. The member Arena Williams was referring to clauseĀ 34(c) at the bottom of pageĀ 25. The answer to her question is, actually, if she turns the page and looks at the guidance note that says, āsubpart 9 of Part 5 for provisions relating to the making of regulations and standards.ā So we arenāt at that part yet, but, with the indulgence of the Chair, I would point the member to looking towards the parts further into it.
There was the question I didnāt address relating to data portability. Thatās also worth just noting that data portability is actually fundamental to the bill. Although the bill uses different terminology, the bill ensures data portability by imposing obligations for data holders to transfer data to customers and accredited requesters. These transfers must be in standard formats and allow the data to be used effectively. This whole regime isnāt going to work if the data holders then provide, through a variety of different mechanisms, kind of disjointed data, blurred data, or data in a format that isnāt actually usable to the to the provider.
Just going back to clauseĀ 22, the product data that it refers to is the sort of thing like mortgage rates, for instance, that are currently publicly available. But in order to make comparisons, thatās quite a complicated process. People kind of draw up their own little grid and they have a look at this bank or that bank or this mortgage adviser and then try and come to that themselves. The concept, I think, thatās very exciting is the potential for a fintech to actually provide that kind of comparative service to a person seeking a mortgage. I think thatās an ideal and classic example of how this legislation can be used.
I move, That debate on this question now close.
Thank you. Iād like to ask a question about clauseĀ 35A, and Iād like to get your comments on thisāitās actually 35 as well as 35A, so weāll just put it in context there. Youāve got here a section that is about having to provide information, and if you donāt, then youāre going to be penalised and thereās going to be an infringement fee and a fine. Then, 35A has an exception to that, which is that you must not act if there are āreasonable grounds to believe that the authorisation or instruction is given under the threat of physical or mental harm.ā
Now, I appreciate the point that the Minister of Commerce and Consumer Affairs has made that some of that stuff about whatās reasonable is going to be resolved in the courts, but I wondered whether that standard would include things like domestic violence orders or whether people would be notifying, for example, the bank that there were issues around this, or what that kind of standard would be in that way, because I donāt knowāI simply donāt know where that line would be at the moment.
I can see that there is a good spirit in this part of the bill, because weāre trying to deal with anti-competitive processes, etc., and this sort of brings in a balancing of the sort of personal, in a way. So itās a personal circumstance that has been seen as a problem that should count against that kind of approach. So Iād be interested in that wider issue of why this particular exception is here, but also what practically that means for the general public. Thank you, Minister.
Thank you, Mr Chair. Well, the protection and proviso in clauseĀ 35 is deliberately inserted to ensure that coercion, threats, potential blackmailāall those sorts of things that we often choose to not look atāare included in here. So Iām very pleased that these two clauses are in the bill. The member will note that there are some quite specific and fairly weighty penalties should coercion or threats be signified or be brought to the attention of the data provider.
So, again, it comes back to a question of reasonableness. How much information does someone need to know before they think that the request is being made under coercion? I donāt have a specific answer to that. I donāt think thatās quantifiable. Thatās kind of a matter for individual data holders to determine. But what I do know is that for the various fintech companies that are going to be establishing these offers, these solutions, these tools, itās in their best interests to ensure that the people they are engaging with and the entities they are engaging with are legitimate, that they operate under best practice, and that they assume all the obligations of a responsible corporate citizen that go with any kind of tradingāwhether it relates to this particular bill or any interaction, commercial, social, or personal.
I move, That debate on this question now close.
Motion agreed to.
The question is that the Ministerās amendments to Part 2 set out on Amendment Paper 254 be agreed to.
Amendments agreed to.
Part 2 as amended agreed to.
Part 3 Protections