🧪 EXPERIMENTAL / ALPHA — this is an independent prototype, not an official record. Data may be incomplete or wrong - always check the linked Hansard source before relying on it.
Hot Air

Tuesday, 25 March 2025

Customer and Product Data Bill

Part 3 Protections
HansardID: f358ba2d-3808-4eea-bf46-a203089e3970
Back to debates
šŸ—£ļø Speech Teanau Tuiono (Green Party — List Member)
Time unknown

Members, we now come to Part 3. Part 3 is the debate on clauses 36 to 53, ā€œProtectionsā€. The question is that Part 3 stand part.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

I just thought, again, it’s probably helpful to make some introductory remarks to this part. So Part 3 provides the important safeguards and protections which ensure that the regime is trusted by customers. It kind of follows on from the conversation we were having in the previous part. Some of these safeguards include the rules for authorisations by customers; identity verification, which is going to be important; record-keeping requirements; and the dispute resolution and customer complaints process that are key parts of this legislation. The rules for authorisation ensure that the customer’s data or actions on behalf of a customer can only be requested under the bill if the customer provides express approval.

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

I thank the Minister of Commerce and Consumer Affairs for that explanation. I’m asking him questions about clauses 36, 37, and 38. I’ve got seven questions about this. I hope we can have a bit of a back and forth dialogue on it.

My first question is about whether he considered any further provisions at the primary legislation level or whether he thinks this is for secondary legislation, or, indeed, whether he thinks the control for this is the accreditation of requesters and holders of data. My question is: how should the initial authorisation process ensure customer understanding and consent? It’s one thing for the legislation to require authorisation; it’s another thing for the regulations, or, indeed, the accreditation process for requesters to be asking about whether a customer actually consents and whether they actually understand that. In the tech context, we see a real range of practice. There is, in fact, probably no sort of best practice about consent and understanding in the context of this authorisation that we’re talking about at clauseĀ 36.

While the Minister considers that, my second question is more about clauses 37 and 38. It’s the same question about where this sits. Is it primary legislation, secondary legislation, or in the accreditation process around where safeguards should be in place to prevent the misuse of data after the initial authorisation? Many of these regimes around the world have come under fire because once the customer has authorised data sharing, the question for them is how they can ensure that their data is being used only for that intended purpose, or for the purpose that they thought they were consenting to—the purpose that they understood.

There are really good examples here. The example given at pageĀ 27 of the bill is about a customer authorising their electricity provider data holder to provide their details through an electricity usage company. So when you’re doing that, you might expect that they would use that specifically for the purpose of giving you the best electricity deal in the market, but they might also use that if they carry on their business as a comparer of electricity products to offer other products and information to other people, in an aggregate way. And so my question there is about the safeguards in place to prevent the misuse of data while also allowing those companies to build out really useful consumer-centric, helpful uses of that data.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

This is quite an important consideration about what amounts to authorisation, how it is collected, how it is obtained, and when it occurs. In general, authorisation is about the process of ensuring that the customer’s information, or actions on behalf of a customer, will only be disclosed or performed under the bill if the customer provides approval. So the approval is crucial. Authorisation is given if the customer, or secondary user, is reasonably informed—so, again, it’s that element of reasonableness—about the matter, about the authorisation, given expressly in the manner prescribed, and that’s set out in the clauses. When responding to a request from an accredited requester, ā€œThe data holder must check that the service is within the scope of the authorisation given by the customerā€. So there’s a protection there not to say, ā€œOh, yeah, it’s OK.ā€, and then that’s carte blanche for all information on all matters of everything. It’s quite fine, it’s quite finessed, and it’s quite focused.

A data holder and accredited requester must have systems in place to enable authorisation to be changed by the customer, so it’s not an authorisation in perpetuity. If the customer changes their mind or wants to do something differently or, maybe, in fact, engage with another entity, another fintech, then that opportunity has to be there. So an accredited requester must comply with their duties in respect of authorisation, and that’s part of the accreditation process for the entity. And, for example, here’s one for how they must ensure the customer or secondary user is reasonably informed: a person must not require a customer to authorise a regulated data service as a condition of providing some other good or service. So you can’t say, ā€œWell, you can have this, but only if you give us that.ā€ Again, I think that’s a good common-sense application. It comes back a little to the introductory comments I made, when we first started this committee stage, that one of the benefits we have in New Zealand of being a little slow to this legislative regime is that we have learnt some lessons from other jurisdictions where they haven’t quite got it right and we can pick up on their errors and take the good bits and not replicate the bad bits.

šŸ—£ļø Speech Reuben Davidson (Labour Party — Member for Christchurch East)
Time unknown

Thank you, Mr Chair. Just circling back to one of the questions just raised and not quite yet addressed by the Minister of Commerce and Consumer Affairs—but I thank him for those most recent answers that really addressed the issues around the collection, the obtaining, and the changing of authorised data. But the question I have, specifically, is around the ending of that authorisation. So it says here in clauseĀ 37(a), ā€œthe expiry of the maximum period for an authorisation specified by the regulationsā€ā€”and my understanding is the regulations are yet to existā€”ā€œ(b) the occurrence of an event specified by the regulations (if any) (for example, when the customer closes an account with a data holder):ā€ and ā€œ(c) the time (if any) specified by the customer (or a secondary user on their behalf) when the authorisation is given:ā€.

So really the questions here are around—and I thank the Minister for his answers which made it clearer around the collection, the obtaining, and the changing, but often what we find is that people, especially in online contexts, find it very easy to opt into a system or a service but find opting out of that or knowing whether they’ve officially opted out of it quite difficult. So I really wanted to get an understanding around what those regulations will look exactly like and also to pick up on a point in the Minister’s answer around ensuring that companies, businesses, users of this legislation cannot compel somebody to provide greater access than necessary to their data or for a longer period than they would be comfortable.

Is there a similar consideration in place to ensure that there wouldn’t be the compulsion for individuals to remove access or data provision to one provider in order to proceed with another? So really making sure that people don’t have to withdraw a whole lot of information from one place to be able to engage in another. Just some clarity around some of those questions would be great, thank you.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Again, some good questions. The bill addresses the issues that the member has raised in a couple of ways. There will be a maximum length of time that an authorisation can last. Now, the detail of what that length of time might be will be in the regulations, because that will be potentially different from one sector to another, but the concept involves a finite endpoint. So it just means that once you’ve done it, there will be a point at which it has to be refreshed, that further consent has to be obtained, and so forth. So the circumstances when an authorisation ends—for example, when the customer closes an account—that brings to an end that relationship. But we want to make that very clear in the regulations.

Authorisations, of course, must also end at the time specified by the customer or secondary user once the authorisation is given. For example, a customer might only authorise data to be shared for, say, six months or eight months or whatever. It could be for a very finite period of time. And again, I’m envisaging a situation where, for instance, someone might be thinking about trying to obtain a mortgage. They want the information about all that for a set period of time, but maybe once they’ve got their mortgage, they no longer need that information. That would be an obvious and convenient time to bring that authorisation to a close.

There’s also an option—well, there’s also a requirement that authorisations may be ended at the time determined by the accredited requester as well. So that would be the actual fintech outfit. They might say, ā€œWell, we don’t need this any more. Time to turn it off. We’re finishing that authorisation.ā€

Again, the option for the secondary legislation through the regulations—I think that that’s where the detail will come. As the member may have heard me say earlier on, we’re expecting to see the regulations for banking before Christmas. Well, in fact, we want it to be before that, because we want to have it up and running by Christmas.

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

I thank the Minister of Commerce and Consumer Affairs for his really helpful answers there, and the expiry being different for different sectors makes sense but wasn’t something that was well understood or traversed, so that is a really helpful answer and means I don’t have to ask him a number of my questions.

But I do still have a question about what his expectations are for customers to remain informed about the ongoing use of their data, especially after the initial consent. So this is a question about how, you know, there’s nothing in the primary legislation which requires reconfirmation for subsequent actions, and that’s fine; that’s a policy choice that’s being made here. So how do customers remain confident in the use of the data if they’re not required to reconfirm it? What part of the system gives consumers confidence that once they have given an authorisation that the ongoing use of the data that they may well have signed up to is, you know, being monitored appropriately?

Another question about scope change, when the scope of an authorisation changes. So it is intended that the regulations will deal with having a customer who is able to change the scope of the authorisation that they’ve given, then modify that. But are the protections appropriate to ensure that the customer is aware of the ramifications of that change, so that they’re not going to have a part of their service turned off because they’ve turned off another part of their service?

My final questions are about withdrawal of consent at a later stage. The Minister has pointed to the regulations giving customers clear ability to do this but, again, you know, easily revoking consent for part or for a whole of a service that you are paying for should be quick, be easy, be painless, and match up with not only your privacy rights but then also your rights as a consumer. If you’re not getting the service you’re paying for, then you shouldn’t be paying for it.

The last question: penalties and consequences for companies that fail to confirm or adhere to authorisation scope when it changes? It’s not something that’s dealt with at the primary legislation. Is that because it needs to be different in sectors or is that a policy decision that is based on the accreditation scheme?

šŸ—£ļø Speech Dr Carlos Cheung (National Party — Member for Mt Roskill)
Time unknown

I move, That debate on this question now close.

šŸ—£ļø Speech Helen White (Labour Party — Member for Mt Albert)
Time unknown

Thank you. I wanted to ask about the Privacy Act part of this, and the overlay between this bill and our own Privacy Act. My understanding is that when we were on the Economic Development, Science and Innovation Committee, the Australians had a very different system. That was because they didn’t really have the same Privacy Act overlay, and we’ve opted for a situation of very much relying on integrating this with the Privacy Act. So I can see that clauseĀ 52 and onwards is about those, and I wanted to give the Minister of Commerce and Consumer Affairs the opportunity to talk about the Privacy Act protections that are in place in New Zealand that might not be, in particular, in other countries. Thank you, Minister.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you. Again, I’ll work a little bit backwards. So Helen White’s question about privacy is a good one. So the bill complements existing protections provided under our Privacy Act—the 2020 legislation. The Privacy Act provides rights and obligations for personal information which apply across the entire economy—so not just in relation to this piece of legislation. They touch everything that we do in many respects. This bill only sets out the rules for providing certain customer and product data upon request, so it doesn’t relate to the actual data itself. It creates the framework for the data, rather than trying to prescribe detail or define the data. That is for another day. What it means, in effect, is that the Privacy Commissioner will continue to have investigation, guidance, enforcement, and redress powers over any breaches relating to personal information. So those powers, as the member will know, are quite strict and readily enforceable.

I want to just go back to the matter that was raised about how consent is given, because I’m not sure that I’d quite answered that as fully as I might have done. But the primary legislation provides the principles for how consent must be obtained—that’s specifically clauseĀ 36. Regulation and standards can provide further detail—that’s clauseĀ 36(1)(b). Existing industry standards in the banking sector, for instance, provide further requirements. Now, these could be adopted under the bill in the regulations. And clauseĀ 40 means that there must be compliance with the duties there stated and penalties apply for breaching authorisation provisions—clauseĀ 75. Those, as I’ve indicated previously, are fairly hefty.

The question relating to opting out is also significant. ClauseĀ 39 requires data holders and accredited requesters to provide systems for customers to end authorisation. So they have to be kind of proactive in terms of providing opt-out options. This is backed up with, again, some quite stiff penalties, should that clauseĀ be contravened. For those penalties in that clause, have a look at clauseĀ 75(1).

šŸ—£ļø Speech Arena Williams (Labour Party — Member for Manurewa)
Time unknown

Thank you, Mr Chair. I want to ask the Minister of Commerce and Consumer Affairs about deleted clauseĀ 47 and clauseĀ 50. These are unrelated to each other, but deleted clauseĀ 47 is about the publication of policies. Some of my questions to the Minister earlier and his very helpful answers fleshed out this issue where a lot of this is going to come down to individual arrangements between the fintech and its customer or the electricity competition provider and its customer.

This provision was originally designed to say, ā€œLook, these are arrangements that each customer is going to be able to enter into. We can have some faith that the market will work in a way where people know what they’re signing up for and agree to varying levels of risk and privacy.ā€ But this is gone now. So we’re then relying on industry standards, and that works quite well for banking where banking industry standards are quite well understood. Banks have very long had obligations that exist outside of this law, but in other areas of the law where they have to know their customers, they have to know about their financial circumstances, and they have to report on that in other ways, so publication of those policies might not have made sense in the banking sector.

But in something like where this might otherwise apply, in electricity, New Zealand doesn’t have the very, very, very long history that, say, an Australian jurisdiction has of consumer rights codes, law around consumer rights, and well-established case law around the rights of consumers and the electricity provisions, whether that is at the being-connected level or whether that is understanding the prices that they pay and regulation of the prices that they pay. So removing this clause seems to enable banks but hurts other consumers in other sectors, and I want the Minister to explain his thinking around this. Is the control simply the accreditation regime so that we’re then in those areas where there are not gold standards and where there are not well-established principles of using consumer data that we would simply only be having a few providers in the system, and those providers would have the very best privacy standards and the very best systems.

My question about clauseĀ 60 is—again, dispute resolution schemes in the industries that we’re talking about vary greatly. Banking dispute resolution schemes are great, very useful for consumers, and very accessible. In other industries where this might apply there, there are just not dispute resolution schemes like that. Is the intention here that every industry would be building out a suitable dispute resolution scheme, or is the intention to have dispute resolutions specifically for consumer data in those industries?

šŸ—£ļø Speech Ricardo MenĆ©ndez March (Green Party — List Member)
Time unknown

Thank you very much, Mr Chair. I’m wanting to unpack and ask some questions in relationship to clauseĀ 45 as well as clauseĀ 46 in Part 3, particularly in relationship to the infringement fees and a fine imposed by a court, both in relationship to the ā€œData holder must keep records about regulated data serviceā€ as well as the ā€œAccredited requestor must keep records about regulated data serviceā€ and, I guess, the consequences that are being put in this bill should those things not happen.

If we go to clauseĀ 45(5), what we’ll see is that it mirrors the amount laid out in clauseĀ 46(4) of an infringement fee of $20,000 or a fine imposed by a court not exceeding $50,000. I wanted to ask the Minister of Commerce and Consumer Affairs, in terms of the work that went into creating those two figures, how he believes that was the right amount to arrive to because if we have a static figure, and these are not proportionate to, say, for example, someone’s income or a profit made by a company that this person may be part of, we then create a situation where disproportionately wealthier individuals will be more easily able to pay that fine without that having a deterrence factor or huge adverse impacts in their life. Particularly, since those figures are static, I wanted to ask the Minister about whether he foresees that there needs to be some work around looking at these figures and adjusting them as inflationary pressures change things to ensure that these infringement fees and fines imposed by the court actually act as a deterrent factor, which is what I am assuming is the intent of these figures.

Again, the reason for that is that in other systems that we have, when we have infringement fees or fines imposed by a court that are static to act as a deterrent factor, what we end up seeing is that absurdly wealthy individuals get, effectively, a free pass because they’re able to afford these infringement fees. I know that none the less these are quite steep for the everyday person, but I’m assuming that some of the people that we may see being more likely to be at fault of not being able to keep records of regulated data services or holding records adequately when it comes to data, that they may be on that higher income, higher wealth bracket.

I’m curious to know whether the Minister did any work to model whether these figures need to be adjusted as time goes on, and how he arrived to the conclusion that you needed a $20,000 and $50,000 break for those two things.

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Thank you, Mr Chair. Ricardo MenĆ©ndez March asks a question about how the quantum was arrived at, and the short answer is that it was a comparison with other existing commercial and criminal penalties in similar regimes. So it’s in parallel and in line with others.

I want to just come back to a matter that Arena Williams raised about the removal of clauses 47 and 48, and she made reference to the New Zealand Banking Association, I think?

Arena Williams: The Financial Service Providers scheme, yes.

Hon SCOTT SIMPSON: Yes. So as a result of a submission made by the New Zealand Banking Association, officials decided, upon further reflection, that those policies in clauses 47 and 48 would add unnecessary compliance cost, especially for data holders. And for accredited requesters, they considered that the need for a policy could potentially be part of an accreditation criteria. So that was the reason that those have been taken out, because we think that those sorts of provisions are better placed within the accreditation criteria regime.

šŸ—£ļø Speech Reuben Davidson (Labour Party — Member for Christchurch East)
Time unknown

Thank you, Mr Chair. Just picking up on clauseĀ 51, around the complaints and regulated data services, I am just wanting to get a sense from the Minister of Commerce and Consumer Affairs around some of the penalties and some of the complaints but also some clarification around clauseĀ 51(2), where it says—and this does seem quite broad, so I’m wanting to get a bit of a sense of some clarification around how broad it is or what the restrictions are and what the discretion might be in this space. This is clauseĀ 51(2), which reads: ā€œThe regulations may disapply any requirement or restriction imposed under any other legislation in connection with a change to the rules of a scheme.ā€ It does seem particularly broad and it would be good just to get some clarification from the Minister on that.

It does go on, in subclauseĀ (4), to provide a little more definition of this, but it still feels that clauseĀ 51(2) reads quite broadly and quite openly, and it would be good to get some clarification from the Minister specifically on 51(2).

šŸ—£ļø Speech Hon Scott Simpson (National Party — Member for Coromandel)
Time unknown

Deliberately broad, because, as I’ve indicated several times now, the detail will be in the regulations and that detail will differ from sector to sector. The detail that may be in the regulations for banking may, by definition, be different to the regulations for electricity or indeed other sectors. Again, the legislation is the framework upon which the regulations for each sector will hang, and that’s the best answer I can give the member Reuben Davidson on this occasion at this point.

šŸ—£ļø Speech Teanau Tuiono (Green Party — List Member)
Time unknown

The question is that the Minister’s amendments to Part 3 set out on Amendment Paper 254 be agreed to.

Amendments agreed to.

Part 3 as amended agreed to.

Part 4 Regulatory and enforcement matters