INTERNATIONAL CONFERENCE ON CREDIT BUREAU OPERATIONS Kyiv, Ukraine September 29, 2006 Credit Bureaus in the Region: legal and regulatory framework What.

Slides:



Advertisements
Similar presentations
Introduction to basic principles of Regulation (EC) 45/2001 Sophie Louveaux María Verónica Pérez Asinari.
Advertisements

Net Neutrality, What Else? Wim Nauwelaerts Partner Hunton & Williams.
2015 – a forward glance 17 February South Africa has a sophisticated credit bureau system
Transposition of Consumer Rights ERGEG Monitoring Report Christina Veigl-Guthann, ERGEG Task Force Chair.
Credit Reporting: What’s the role for the state? Fredes Montes Financial Infrastructure The World Bank.
1 PRIVACY ISSUES IN THE U.S. – CANADA CROSS BORDER BUSINESS CONTEXT Presented by: Anneli LeGault ACC Greater New York Chapter Compliance Seminar May 19,
XBRL AND BANKING SUPERVISION José María Roldán Director General of Regulation, Banco de España Chair, XBRL España Chair, Committee of European Banking.
A European View of Privacy Protection John Woulds Director of Operations UK Data Protection Commissioner National Conference on Privacy, Technology & Criminal.
Per Anders Eriksson
1 The importance of credit bureau and need of legal framework for it LITHUANIA.
IEKA - Albanian Institute of Authorized Chartered Auditors Towards application of new standards on accounting and auditing – Albanian challenge on implementing.
THE WORLD BANK World Bank Group Multilateral Investment Guarantee Agency 1 Investment Policy, Legal Framework, & Promotion Investment Facilitation Sector.
The Sixth Annual African Consumer Protection Dialogue Conference
Banks and the Privacy of Medical Information 8 th National HIPAA Summit March 8, 2004 Joy Pritts, JD Health Policy Institute Georgetown University
Limitations and Constraints on Marketing (1)
A Common Immigration Policy for Europe Principles, actions and tools June 2008.
The role of ERE in Costumer Protection Eduard Elezi Albanian Regulatory Authority ERE Conference “Albanian Energy Sector, Challenges and Regulation” Tirana,
Privacy Law for Network Administrators Steven Penney Faculty of Law University of New Brunswick.
18 th Annual Canadian IT Law Association Conference Insider View from the EU Expert Group on Cloud Computing Dr Sam De Silva Partner, Head of IT & Outsourcing.
EHRs and the European Union – current legislation and future directions. Dr Richard Fitton.
1 THE THIRD ENERGY PACKAGE – THE ENERGY COMMUNITY APPROACH Energy Community Secretariat 20 th Forum of the Croatian Energy Association and WEC National.
WORKSHOP, Nicosia 2-3rd July 2008 “Extension of SAFETY & QUALITY Common Requirements to the EMAC States” Item 3 : Regulatory Context Peter Stastny EUROCONTROL.
Data Protection Act AS Module Heathcote Ch. 12.
IBT - Electronic Commerce Privacy Concerns Victor H. Bouganim WCL, American University.
Europe's work in progress: quality of mHealth Pēteris Zilgalvis, J.D., Head of Unit, Health and Well-Being, DG CONNECT Voka Health Community 29 September.
POSTAL CONFERENCE 25 th – 27 th February 2015 Nairobi, Kenya By Yvonne UMUTONI Chairperson of EACO Working Group 9 (Quality of Service and Consumer Affairs)
European Commission Rita L’ABBATE Legal aspects linked to internal market DG Enterprise and Industry MARKET SURVEILLANCE COMMUNITY FRAMEWORK UNECE “MARS”
The Data Protection Act What Data is Held on Individuals? By institutions: –Criminal information, –Educational information; –Medical Information;
Presentation “Green Investment Schemes – greenhouse gas emissions quotas trading mechanisms in Ukraine according to the Kyoto Protocol to the Convention.
Directorate General for Energy and Transport European Commission Directorate General for Energy and Transport Regulation of electricity markets in the.
“Implementing Spectrum Trading” the recent consultation Presentation to SMAG Open Forum December 2002 Geoff Chapman Radiocommunications Agency.
Legal and institutional foundation of economic statistics Overview of international experience Regional Workshop for African Countries on Compilation of.
Copyright Atomic Dog Publishing, 2002 International Expansion Trade Barriers Trade Facilitators.
The EU AEO Programme in a global environment European Regional Forum “Partnership: Customs and Business”   May 2015, Astana, Kazakhstan.
African Centre for Statistics United Nations Economic Commission for Africa Systemic, Institutional and Infrastructural Challenges in CRVS in the African.
PROTECTION OF PERSONAL DATA. OECD GUIDELINES: BASIC PRINCIPLES OF NATIONAL APPLICATION Collection Limitation Principle There should be limits to the collection.
Data protection and compliance in context 19 November 2007 Stewart Room Partner.
PRESENTED AT THE STAKEHOLDERS FORUM ON QUALITY OF SERVICE AND CONSUMER EXPERIENCE LAICO REGENCY HOTEL Creating Space for Consumer Rights in.
An Introduction to the Privacy Act Privacy Act 1993 Promotes and protects individual privacy Is concerned with the privacy of information about people.
HIT Policy Committee NHIN Workgroup HIE Trust Framework: HIE Trust Framework: Essential Components for Trust April 21, 2010 David Lansky, Chair Farzad.
HIT Policy Committee Meeting Nationwide Health Information Network Governance June 25, 2010 Mary Jo Deering, PhD ONC, Office of Policy and Planning NHIN.
Connecting for Health Common Framework: the Model Contract for Health Information Exchange Gerry Hinkley com July 18, 2006 Davis Wright.
This presentation remains the property of XDS (PTY) Ltd and may not be altered, copied or distributed without written permission Regulatory and Legal Challenges.
Computer Laws Data Protection Act 1998 Computer Misuse Act 1990.
Access to Information: Bolivia Main Headline Goes Here Special Meeting of the Juridical and Political Affairs OAS December 13, 2010 Laura Neuman Access.
APEC Privacy Framework “The lack of consumer trust and confidence in the privacy and security of online transactions and information networks is one element.
Role of Credit Bureaus and Registries Session 1 – Asymmetries of information, regulatory frameworks, improving transparency and financial knowledge Serena.
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 27 – Environment Bilateral screening:
M O N T E N E G R O Negotiating Team for the Accession of Montenegro to the European Union Working Group for Chapter 6 – Company Law Bilateral screening:
Presented by Ms. Teki Akuetteh LLM (IT and Telecom Law) 16/07/2013Data Protection Act, 2012: A call for Action1.
Protection of Personal Information Act An Analysis on the impact.
ROMANIA NATIONAL NATURAL GAS REGULATORY AUTHORITY Public Service Obligations in Romanian Gas Sector Ligia Medrea General Manager – Authorizing, Licensing,
Agencija za zaštitu ličnih/osobnih podataka u Bosni i Hercegovini Агенција за заштиту личних података у Босни и Херцеговини Personal Data Protection Agency.
Accountability & Structured Privacy Management
Liberalisation and regulation in the telecommunication sector: Theory and empirical evidence Week 3 The European Regulatory Framework for the Telecommunication.
THE NEW GENERAL DATA PROTECTION REGULATION: A EUROPEAN OR A GLOBAL STANDARD? Bart van der Sloot Senior Researcher Tilburg Institute for Law, Technology,
Privacy principles Individual written policies
Data Protection: EU & International
September, Lev Razovskiy Director, International Affairs
INTERCONNECTION GUIDELINES
What is a Credit Bureau? A cooperative repository of information
General Data Protection Regulation
Data Protection Legislation
Legal Framework for Civil Registration, Vital Statistics
progress of the water reform in bulgaria
Healthcare Privacy: The Perspective of a Privacy Advocate
IAPP TRUSTe SYMPOSIUM 9-11 JUNE 2004
PRESENTATION OF MONTENEGRO
Outline Background: development of the Commission’s position
PRESENTATION OF MONTENEGRO
Presentation transcript:

INTERNATIONAL CONFERENCE ON CREDIT BUREAU OPERATIONS Kyiv, Ukraine September 29, 2006 Credit Bureaus in the Region: legal and regulatory framework What is the experience in the region with implementing credit bureau laws?

Table of Contents 1. European Experience a. Major issues 2. Regional Experience a. Kazakhstan, Russian, Ukraine 3. The 95/75 Rule - Success 4. Recommendations

EU-Directive 95/46 Parliaments throughout Europe, North American and elsewhere encourage information exchange as long as it does not violate a consumer’s basic right to privacy. Information flows: 1.reduce adverse economic selection effects, oligopolistic tendencies and credit rationing. 2.remove barriers between EU states in order to establish a single internal European market.

Legal Challenge Find the right balance between privacy and information exchange. Key Question: a) how much privacy legislation is required to protect the citizenry from unscrupulous users, which is the main function of regulation, and b) what is the cost of privacy legislation to the economy and to its citizens.

International Privacy Guidelines Consumer Rights To obtain Credit Report within reasonable time, at reasonable cost, & in a reasonable way. To obtain Credit Report within reasonable time, at reasonable cost, & in a reasonable way. To dispute data and have it corrected To dispute data and have it corrected To know the purpose for data collection To know the purpose for data collection To limit amount of data collected – religion, ethnic background, etc. To limit amount of data collected – religion, ethnic background, etc. To limit use and transfer To limit use and transfer To demand that data is accurate To demand that data is accurate To demand reasonable accountability of data processor, and apply remedies, when required To demand reasonable accountability of data processor, and apply remedies, when required      EU Dir. 95/46  

Data Protection Acts do not detail specific security measures that a Data Controller or Data Processor must have in place. Rather, they place an obligation on persons to have appropriate measures in place to prevent "unauthorised access to, or alteration, disclosure or destruction of, the data and against their accidental loss or destruction." Measures include: Access Control Encryption Anti-Virus Software Firewalls Automatic screen savers Logs and Audit trails Security Guidelines The Human Factor Remote Access Wireless networks Laptops Back-up systems Physical Security

Cost of Excessive Regulation In other words, There is a direct cost to the consumer and SMEs in terms of higher prices, higher interest rates and restricted access to credit when excessive privacy legislation (i.e., excessive regulation) interferes with the exchange of personal identification and credit history data.

Kazakhstan, Russia & Ukraine: a)No clear legal basis for data sharing b)Despite the fact that all banks indicated that they would share data, banks in fact reluctant to share data c)SME and consumer data fragmented; d)Regulatory “overreach”, as appeared in early drafts of the law, threatened a private CB’s operational viability e)Consumer rights not clearly protected in the law f)Conflicting legislation Legislative Context Before Law

a)Adopted in July 2004 – consistent with EU 95/46 b)100% private in a free market competitive system; c)Consumer consent required d)Data sharing of positive and negative data permissible; e)Single Regulatory Body; f)Open system – all sectors of economy participate g)Supervisory body will implement “MINIMUM REQUIREMENTS” for data regulation; h)If consumer “Opts-in” then bank mandated to transfer data to CB Kazakhstan Credit Bureau Law

Kazakhstan – Regulatory Framework State Agency for IT Solutions regulates data processing process Requirement for certification of equipment –To secure protection of data –Monitoring of data processing –Compliance with the requirements of data processing regulations Minimum regulatory requirements written into the law

Russian Credit Bureau Law Adopted in December 2004 Law is workable but should be simplified & amended – consent required E.g., 50% limitation for single owner Tries to define what types of data can be collected, i.e, Credit Cards – revolving lines of credit not specifically included in the law Regulations are quite extensive but also work Should be simplified

Ukrainian Credit Bureau Law Adopted on June 23, 2005 Substantially consistent with UE and American legislation Played a decisive role in laying the foundation for CB operation in Ukraine. Enables both data sharing and protection of the rights of subjects of credit histories.

Ukrainian CB Law Needs to be refined to facilitate data collection for CB database (e.g. public registries)Needs to be refined to facilitate data collection for CB database (e.g. public registries) Impracticality of certain provisions Impracticality of certain provisions Needs to be amended to avoid excessive regulatory burden of CB operations (inspections etc)Needs to be amended to avoid excessive regulatory burden of CB operations (inspections etc) Don’t duplicate oversight Don’t duplicate oversight May need to be transformed into a comprehensive CB lawMay need to be transformed into a comprehensive CB law Single legislation more workable Single legislation more workable

Ukrainian Regulations Licensing Licensing Registration Registration Inspection Inspection Others likely Others likely Make sure that Regulations are robust but not excessively detailed. Market’s participation with drafting regulations is an excellent decision by MinJus

Suggested Targets and Success Put in place the essential elements so that a credit reference bureau has passed from being merely established to a more advanced, mature and self-sufficient stage. Put in place the essential elements so that a credit reference bureau has passed from being merely established to a more advanced, mature and self-sufficient stage. Regulatory framework key Success may occur when the following is in place: –At least 95% of the financial sector has included “customer consent” clauses on credit application forms; and –75% of historical credit data in Ukraine has been collected in a single location and public record information accessible to a credit bureau; The 90/75 Rule

Recommendations Regulations must encourage data exchange, particularly since customer consent is necessary Regulations must encourage data exchange, particularly since customer consent is necessary Design a simple mechanism for tete-a-tete resolution of disputes using proven methodologies from other countries Design a simple mechanism for tete-a-tete resolution of disputes using proven methodologies from other countries Allow commercial issues to be negotiated and agreed upon between the data supplier and credit bureau Allow commercial issues to be negotiated and agreed upon between the data supplier and credit bureau Find balance between data flows and data security at the regulatory level. Find balance between data flows and data security at the regulatory level.

Thank you for your attention Questions Javier M. Piedra Senior Advisor USAID/ACTI Kiev, Ukraine September 29, 2006