Customer and Product Data Bill
Members, we now come to Part 3. Part 3 is the debate on clauses 36 to 53, āProtectionsā. The question is that Part 3 stand part.
I just thought, again, itās probably helpful to make some introductory remarks to this part. So Part 3 provides the important safeguards and protections which ensure that the regime is trusted by customers. It kind of follows on from the conversation we were having in the previous part. Some of these safeguards include the rules for authorisations by customers; identity verification, which is going to be important; record-keeping requirements; and the dispute resolution and customer complaints process that are key parts of this legislation. The rules for authorisation ensure that the customerās data or actions on behalf of a customer can only be requested under the bill if the customer provides express approval.
I thank the Minister of Commerce and Consumer Affairs for that explanation. Iām asking him questions about clauses 36, 37, and 38. Iāve got seven questions about this. I hope we can have a bit of a back and forth dialogue on it.
My first question is about whether he considered any further provisions at the primary legislation level or whether he thinks this is for secondary legislation, or, indeed, whether he thinks the control for this is the accreditation of requesters and holders of data. My question is: how should the initial authorisation process ensure customer understanding and consent? Itās one thing for the legislation to require authorisation; itās another thing for the regulations, or, indeed, the accreditation process for requesters to be asking about whether a customer actually consents and whether they actually understand that. In the tech context, we see a real range of practice. There is, in fact, probably no sort of best practice about consent and understanding in the context of this authorisation that weāre talking about at clauseĀ 36.
While the Minister considers that, my second question is more about clauses 37 and 38. Itās the same question about where this sits. Is it primary legislation, secondary legislation, or in the accreditation process around where safeguards should be in place to prevent the misuse of data after the initial authorisation? Many of these regimes around the world have come under fire because once the customer has authorised data sharing, the question for them is how they can ensure that their data is being used only for that intended purpose, or for the purpose that they thought they were consenting toāthe purpose that they understood.
There are really good examples here. The example given at pageĀ 27 of the bill is about a customer authorising their electricity provider data holder to provide their details through an electricity usage company. So when youāre doing that, you might expect that they would use that specifically for the purpose of giving you the best electricity deal in the market, but they might also use that if they carry on their business as a comparer of electricity products to offer other products and information to other people, in an aggregate way. And so my question there is about the safeguards in place to prevent the misuse of data while also allowing those companies to build out really useful consumer-centric, helpful uses of that data.
This is quite an important consideration about what amounts to authorisation, how it is collected, how it is obtained, and when it occurs. In general, authorisation is about the process of ensuring that the customerās information, or actions on behalf of a customer, will only be disclosed or performed under the bill if the customer provides approval. So the approval is crucial. Authorisation is given if the customer, or secondary user, is reasonably informedāso, again, itās that element of reasonablenessāabout the matter, about the authorisation, given expressly in the manner prescribed, and thatās set out in the clauses. When responding to a request from an accredited requester, āThe data holder must check that the service is within the scope of the authorisation given by the customerā. So thereās a protection there not to say, āOh, yeah, itās OK.ā, and then thatās carte blanche for all information on all matters of everything. Itās quite fine, itās quite finessed, and itās quite focused.
A data holder and accredited requester must have systems in place to enable authorisation to be changed by the customer, so itās not an authorisation in perpetuity. If the customer changes their mind or wants to do something differently or, maybe, in fact, engage with another entity, another fintech, then that opportunity has to be there. So an accredited requester must comply with their duties in respect of authorisation, and thatās part of the accreditation process for the entity. And, for example, hereās one for how they must ensure the customer or secondary user is reasonably informed: a person must not require a customer to authorise a regulated data service as a condition of providing some other good or service. So you canāt say, āWell, you can have this, but only if you give us that.ā Again, I think thatās a good common-sense application. It comes back a little to the introductory comments I made, when we first started this committee stage, that one of the benefits we have in New Zealand of being a little slow to this legislative regime is that we have learnt some lessons from other jurisdictions where they havenāt quite got it right and we can pick up on their errors and take the good bits and not replicate the bad bits.
Thank you, Mr Chair. Just circling back to one of the questions just raised and not quite yet addressed by the Minister of Commerce and Consumer Affairsābut I thank him for those most recent answers that really addressed the issues around the collection, the obtaining, and the changing of authorised data. But the question I have, specifically, is around the ending of that authorisation. So it says here in clauseĀ 37(a), āthe expiry of the maximum period for an authorisation specified by the regulationsāāand my understanding is the regulations are yet to existāā(b) the occurrence of an event specified by the regulations (if any) (for example, when the customer closes an account with a data holder):ā and ā(c) the time (if any) specified by the customer (or a secondary user on their behalf) when the authorisation is given:ā.
So really the questions here are aroundāand I thank the Minister for his answers which made it clearer around the collection, the obtaining, and the changing, but often what we find is that people, especially in online contexts, find it very easy to opt into a system or a service but find opting out of that or knowing whether theyāve officially opted out of it quite difficult. So I really wanted to get an understanding around what those regulations will look exactly like and also to pick up on a point in the Ministerās answer around ensuring that companies, businesses, users of this legislation cannot compel somebody to provide greater access than necessary to their data or for a longer period than they would be comfortable.
Is there a similar consideration in place to ensure that there wouldnāt be the compulsion for individuals to remove access or data provision to one provider in order to proceed with another? So really making sure that people donāt have to withdraw a whole lot of information from one place to be able to engage in another. Just some clarity around some of those questions would be great, thank you.
Again, some good questions. The bill addresses the issues that the member has raised in a couple of ways. There will be a maximum length of time that an authorisation can last. Now, the detail of what that length of time might be will be in the regulations, because that will be potentially different from one sector to another, but the concept involves a finite endpoint. So it just means that once youāve done it, there will be a point at which it has to be refreshed, that further consent has to be obtained, and so forth. So the circumstances when an authorisation endsāfor example, when the customer closes an accountāthat brings to an end that relationship. But we want to make that very clear in the regulations.
Authorisations, of course, must also end at the time specified by the customer or secondary user once the authorisation is given. For example, a customer might only authorise data to be shared for, say, six months or eight months or whatever. It could be for a very finite period of time. And again, Iām envisaging a situation where, for instance, someone might be thinking about trying to obtain a mortgage. They want the information about all that for a set period of time, but maybe once theyāve got their mortgage, they no longer need that information. That would be an obvious and convenient time to bring that authorisation to a close.
Thereās also an optionāwell, thereās also a requirement that authorisations may be ended at the time determined by the accredited requester as well. So that would be the actual fintech outfit. They might say, āWell, we donāt need this any more. Time to turn it off. Weāre finishing that authorisation.ā
Again, the option for the secondary legislation through the regulationsāI think that thatās where the detail will come. As the member may have heard me say earlier on, weāre expecting to see the regulations for banking before Christmas. Well, in fact, we want it to be before that, because we want to have it up and running by Christmas.
I thank the Minister of Commerce and Consumer Affairs for his really helpful answers there, and the expiry being different for different sectors makes sense but wasnāt something that was well understood or traversed, so that is a really helpful answer and means I donāt have to ask him a number of my questions.
But I do still have a question about what his expectations are for customers to remain informed about the ongoing use of their data, especially after the initial consent. So this is a question about how, you know, thereās nothing in the primary legislation which requires reconfirmation for subsequent actions, and thatās fine; thatās a policy choice thatās being made here. So how do customers remain confident in the use of the data if theyāre not required to reconfirm it? What part of the system gives consumers confidence that once they have given an authorisation that the ongoing use of the data that they may well have signed up to is, you know, being monitored appropriately?
Another question about scope change, when the scope of an authorisation changes. So it is intended that the regulations will deal with having a customer who is able to change the scope of the authorisation that theyāve given, then modify that. But are the protections appropriate to ensure that the customer is aware of the ramifications of that change, so that theyāre not going to have a part of their service turned off because theyāve turned off another part of their service?
My final questions are about withdrawal of consent at a later stage. The Minister has pointed to the regulations giving customers clear ability to do this but, again, you know, easily revoking consent for part or for a whole of a service that you are paying for should be quick, be easy, be painless, and match up with not only your privacy rights but then also your rights as a consumer. If youāre not getting the service youāre paying for, then you shouldnāt be paying for it.
The last question: penalties and consequences for companies that fail to confirm or adhere to authorisation scope when it changes? Itās not something thatās dealt with at the primary legislation. Is that because it needs to be different in sectors or is that a policy decision that is based on the accreditation scheme?
I move, That debate on this question now close.
Thank you. I wanted to ask about the Privacy Act part of this, and the overlay between this bill and our own Privacy Act. My understanding is that when we were on the Economic Development, Science and Innovation Committee, the Australians had a very different system. That was because they didnāt really have the same Privacy Act overlay, and weāve opted for a situation of very much relying on integrating this with the Privacy Act. So I can see that clauseĀ 52 and onwards is about those, and I wanted to give the Minister of Commerce and Consumer Affairs the opportunity to talk about the Privacy Act protections that are in place in New Zealand that might not be, in particular, in other countries. Thank you, Minister.
Thank you. Again, Iāll work a little bit backwards. So Helen Whiteās question about privacy is a good one. So the bill complements existing protections provided under our Privacy Actāthe 2020 legislation. The Privacy Act provides rights and obligations for personal information which apply across the entire economyāso not just in relation to this piece of legislation. They touch everything that we do in many respects. This bill only sets out the rules for providing certain customer and product data upon request, so it doesnāt relate to the actual data itself. It creates the framework for the data, rather than trying to prescribe detail or define the data. That is for another day. What it means, in effect, is that the Privacy Commissioner will continue to have investigation, guidance, enforcement, and redress powers over any breaches relating to personal information. So those powers, as the member will know, are quite strict and readily enforceable.
I want to just go back to the matter that was raised about how consent is given, because Iām not sure that Iād quite answered that as fully as I might have done. But the primary legislation provides the principles for how consent must be obtainedāthatās specifically clauseĀ 36. Regulation and standards can provide further detailāthatās clauseĀ 36(1)(b). Existing industry standards in the banking sector, for instance, provide further requirements. Now, these could be adopted under the bill in the regulations. And clauseĀ 40 means that there must be compliance with the duties there stated and penalties apply for breaching authorisation provisionsāclauseĀ 75. Those, as Iāve indicated previously, are fairly hefty.
The question relating to opting out is also significant. ClauseĀ 39 requires data holders and accredited requesters to provide systems for customers to end authorisation. So they have to be kind of proactive in terms of providing opt-out options. This is backed up with, again, some quite stiff penalties, should that clauseĀ be contravened. For those penalties in that clause, have a look at clauseĀ 75(1).
Thank you, Mr Chair. I want to ask the Minister of Commerce and Consumer Affairs about deleted clauseĀ 47 and clauseĀ 50. These are unrelated to each other, but deleted clauseĀ 47 is about the publication of policies. Some of my questions to the Minister earlier and his very helpful answers fleshed out this issue where a lot of this is going to come down to individual arrangements between the fintech and its customer or the electricity competition provider and its customer.
This provision was originally designed to say, āLook, these are arrangements that each customer is going to be able to enter into. We can have some faith that the market will work in a way where people know what theyāre signing up for and agree to varying levels of risk and privacy.ā But this is gone now. So weāre then relying on industry standards, and that works quite well for banking where banking industry standards are quite well understood. Banks have very long had obligations that exist outside of this law, but in other areas of the law where they have to know their customers, they have to know about their financial circumstances, and they have to report on that in other ways, so publication of those policies might not have made sense in the banking sector.
But in something like where this might otherwise apply, in electricity, New Zealand doesnāt have the very, very, very long history that, say, an Australian jurisdiction has of consumer rights codes, law around consumer rights, and well-established case law around the rights of consumers and the electricity provisions, whether that is at the being-connected level or whether that is understanding the prices that they pay and regulation of the prices that they pay. So removing this clause seems to enable banks but hurts other consumers in other sectors, and I want the Minister to explain his thinking around this. Is the control simply the accreditation regime so that weāre then in those areas where there are not gold standards and where there are not well-established principles of using consumer data that we would simply only be having a few providers in the system, and those providers would have the very best privacy standards and the very best systems.
My question about clauseĀ 60 isāagain, dispute resolution schemes in the industries that weāre talking about vary greatly. Banking dispute resolution schemes are great, very useful for consumers, and very accessible. In other industries where this might apply there, there are just not dispute resolution schemes like that. Is the intention here that every industry would be building out a suitable dispute resolution scheme, or is the intention to have dispute resolutions specifically for consumer data in those industries?
Thank you very much, Mr Chair. Iām wanting to unpack and ask some questions in relationship to clauseĀ 45 as well as clauseĀ 46 in Part 3, particularly in relationship to the infringement fees and a fine imposed by a court, both in relationship to the āData holder must keep records about regulated data serviceā as well as the āAccredited requestor must keep records about regulated data serviceā and, I guess, the consequences that are being put in this bill should those things not happen.
If we go to clauseĀ 45(5), what weāll see is that it mirrors the amount laid out in clauseĀ 46(4) of an infringement fee of $20,000 or a fine imposed by a court not exceeding $50,000. I wanted to ask the Minister of Commerce and Consumer Affairs, in terms of the work that went into creating those two figures, how he believes that was the right amount to arrive to because if we have a static figure, and these are not proportionate to, say, for example, someoneās income or a profit made by a company that this person may be part of, we then create a situation where disproportionately wealthier individuals will be more easily able to pay that fine without that having a deterrence factor or huge adverse impacts in their life. Particularly, since those figures are static, I wanted to ask the Minister about whether he foresees that there needs to be some work around looking at these figures and adjusting them as inflationary pressures change things to ensure that these infringement fees and fines imposed by the court actually act as a deterrent factor, which is what I am assuming is the intent of these figures.
Again, the reason for that is that in other systems that we have, when we have infringement fees or fines imposed by a court that are static to act as a deterrent factor, what we end up seeing is that absurdly wealthy individuals get, effectively, a free pass because theyāre able to afford these infringement fees. I know that none the less these are quite steep for the everyday person, but Iām assuming that some of the people that we may see being more likely to be at fault of not being able to keep records of regulated data services or holding records adequately when it comes to data, that they may be on that higher income, higher wealth bracket.
Iām curious to know whether the Minister did any work to model whether these figures need to be adjusted as time goes on, and how he arrived to the conclusion that you needed a $20,000 and $50,000 break for those two things.
Thank you, Mr Chair. Ricardo MenĆ©ndez March asks a question about how the quantum was arrived at, and the short answer is that it was a comparison with other existing commercial and criminal penalties in similar regimes. So itās in parallel and in line with others.
I want to just come back to a matter that Arena Williams raised about the removal of clauses 47 and 48, and she made reference to the New Zealand Banking Association, I think?
Arena Williams: The Financial Service Providers scheme, yes.
Hon SCOTT SIMPSON: Yes. So as a result of a submission made by the New Zealand Banking Association, officials decided, upon further reflection, that those policies in clauses 47 and 48 would add unnecessary compliance cost, especially for data holders. And for accredited requesters, they considered that the need for a policy could potentially be part of an accreditation criteria. So that was the reason that those have been taken out, because we think that those sorts of provisions are better placed within the accreditation criteria regime.
Thank you, Mr Chair. Just picking up on clauseĀ 51, around the complaints and regulated data services, I am just wanting to get a sense from the Minister of Commerce and Consumer Affairs around some of the penalties and some of the complaints but also some clarification around clauseĀ 51(2), where it saysāand this does seem quite broad, so Iām wanting to get a bit of a sense of some clarification around how broad it is or what the restrictions are and what the discretion might be in this space. This is clauseĀ 51(2), which reads: āThe regulations may disapply any requirement or restriction imposed under any other legislation in connection with a change to the rules of a scheme.ā It does seem particularly broad and it would be good just to get some clarification from the Minister on that.
It does go on, in subclauseĀ (4), to provide a little more definition of this, but it still feels that clauseĀ 51(2) reads quite broadly and quite openly, and it would be good to get some clarification from the Minister specifically on 51(2).
Deliberately broad, because, as Iāve indicated several times now, the detail will be in the regulations and that detail will differ from sector to sector. The detail that may be in the regulations for banking may, by definition, be different to the regulations for electricity or indeed other sectors. Again, the legislation is the framework upon which the regulations for each sector will hang, and thatās the best answer I can give the member Reuben Davidson on this occasion at this point.
The question is that the Ministerās amendments to Part 3 set out on Amendment Paper 254 be agreed to.
Amendments agreed to.
Part 3 as amended agreed to.
Part 4 Regulatory and enforcement matters