Government bill · 20th Knesset · published as law 12 April 2016

חוק נתוני אשראי, התשע"ו-2016Law on Credit Data, 2016 · automatic translation · suggest a correction

Status: התקבלה בקריאה שלישית

Topics: Finance and consumer protection* · * from the Knesset's official law classification

Official summary of the law (Knesset)

The Credit Data Law, 2016 (hereinafter - the Law), was passed in second and third reading on 29 March 2016. The Law replaces the Credit Data Service Law, 2002 (hereinafter - the repealed Law), and establishes a new arrangement for the establishment and operation of a system for sharing credit data on individuals. The Law provides that the Bank of Israel will establish and operate a database that will include credit data on individuals indicating their ability to meet financial obligations and repay debts. This data on credit applicants is material for any credit provider in deciding whether to extend credit and on what terms. The Law changes the default rule that existed under the repealed Law regarding customer consent to be included in the database. Under the repealed Law, the collection of data on a customer was generally conditional on the customer's consent. As noted, the default rule has been changed, and the Law provides that information on customers will automatically pass to the database, unless a customer has requested the Bank of Israel not to collect information about them, or to collect it into the database but not transmit it to credit bureaus. The Law establishes the sources of information that will feed information into the database, distinguishing between information sources required to transmit information to the database and information sources permitted to do so. The information sources required to transmit information to the database include the Bank of Israel, the Execution Offices and the Official Receiver, banks, charge card issuers, the Postal Bank, and non-bank entities providing credit at a scope to be determined in regulations. Under the Law, credit bureaus, which are private entities that will have access to the database, will serve as the link between credit providers and the information in the database. The activity of credit bureaus will be subject to oversight and conditional upon obtaining a license from the Commissioner. Credit bureaus will be permitted to provide only the services permitted under the Law, or to provide additional services as part of another business, if the Governor has established this in rules. Under the Law, credit bureaus may operate a credit data service that includes the following services: 1. Preparing a credit report, which includes the customer's credit data for the last three years. A condition for providing a credit report is the customer's explicit consent for the credit bureau to transmit data about them to the credit provider. Only a credit provider included in the definition "credit data user" - a credit provider that transmits information to the database on all its customers and is not a low-risk credit provider - may receive a credit report. 2. Providing a credit indication, whereby the credit bureau gives its opinion on whether the credit request should be refused or approved. This is a service in which the loan provider is not exposed to the raw credit data, except for that published by law. The credit bureau receives the information, processes it, and responds to the credit provider with "yes" or "no". Any credit provider may receive such a service, and no customer approval is required for providing such a service, but only explicit advance notice to the customer is required. 3. Providing a data summary report to the customer or an authorized proxy for payment. Such a report includes all the information about the customer found in the database. A customer is entitled to receive it once a year even free of charge. The customer may choose to receive a regular data summary report including information for the last three years only, or to receive a full data summary report, relating to the last ten years. In addition to operating a credit data service, a credit bureau may provide services based on these services, including providing a credit provider or customer with a credit rating and advising them on certain matters specified in the Law. Finally, the Law establishes various provisions intended to ensure a high level of protection for privacy and information security when operating the database and the various services provided under this Law. For example, the Law limits the period information is kept in the database to ten years, with information being retained after three years for documentation purposes only. The Law also requires the Governor of the Bank of Israel to appoint a privacy protection officer, who will advise the database manager on privacy protection matters and advise the Commissioner on handling public complaints concerning privacy. The commencement of this Law is thirty months from the date of its publication in the Official Gazette, with the possibility of postponing the commencement date for additional periods not exceeding four years in total.

automatic translation · suggest a correction

Hebrew original

חוק נתוני אשראי, התשע"ו-2016 (להלן - החוק), התקבל בקריאה השנייה ובקריאה השלישית ביום י"ט באדר ב' התשע"ו (29 במרס 2016). החוק מחליף את חוק שירות נתוני אשראי, התשס"ב-2002 (להלן – החוק הבטל), וקובע הסדר חדש להקמה ולפעילות של מערכת לשיתוף בנתוני אשראי של יחידים. החוק קובע שבנק ישראל יקים ויפעיל מאגר שיכלול נתוני אשראי על יחידים המעידים על היכולת שלהם לעמוד בהתחייבויות כספיות ובפירעון חובות. נתונים אלה על מבקשי האשראי, מהותיים לכל נותן אשראי לצורך קבלת ההחלטה אם לתת אשראי ובאיזה תנאים. החוק משנה את ברירת המחדל שהייתה בחוק הבטל לעניין הסכמת הלקוח להיכלל במאגר. לפי החוק הבטל , איסוף הנתונים על הלקוח היה מותנה, ככלל, בהסכמת הלקוח. כאמור, ברירת המחדל שונתה, והחוק קובע כי המידע על הלקוחות יעבור אוטומטית למאגר, אלא אם כן, לקוח ביקש מבנק ישראל שלא ייאסף עליו המידע, או שייאסף למאגר אך לא יימסר ללשכות האשראי. החוק קובע את מקורות המידע אשר יזרימו את המידע למאגר, כאשר קבועים מקורות מידע החייבים להעביר מידע למאגר ומקורות מידע שרשאים לעשות כן. מקורות המידע שחייבים להעביר מידע למאגר כוללים את בנק ישראל, לשכות ההוצאה לפועל וכונס הנכסים הראשי, בנקים, מנפיקי כרטיסי חיוב, בנק הדואר וגופים חוץ בנקאיים הנותנים אשראי בהיקף שיקבע בתקנות. לפי החוק, לשכות האשראי, שהן גופים פרטיים שיהיו בעלי גישה למאגר, יהיו הגורם המקשר בין נותני האשראי לבין המידע שבמאגר. פעילות לשכות האשראי תהיה נתונה לפיקוח ותותנה בקבלת רישיון מאת הממונה. לשכות האשראי יהיו רשאיות לתת את השירותים המותרים לפי החוק בלבד, או לתת שירותים נוספים במסגרת עיסוק אחר, אם הנגיד קבע זאת בכללים. לפי החוק, לשכות האשראי רשאיות להפעיל שירות נתוני אשראי הכולל את השירותים הבאים: 1. עריכת דוח אשראי, הכולל את נתוני האשראי לגבי הלקוח בשלוש השנים האחרונות. תנאי למתן דוח אשראי, הוא הסכמה מפורשת של הלקוח לכך שלשכת האשראי תמסור לנותן האשראי נתונים לגביו. רק נותן אשראי שנכלל בהגדרה "משתמש בנתוני אשראי", שהוא נותן אשראי המעביר מידע למאגר על כלל לקוחותיו ואינו נותן אשראי בסיכון נמוך, רשאי לקבל דוח אשראי. 2. מתן חיווי אשראי, שבמסגרתו לשכת האשראי מחווה את דעתה אם יש לסרב או להיענות לבקשת האשראי. מדובר בשירות בו נותן ההלוואה אינו נחשף לנתוני האשראי הגולמיים, למעט אלו המפורסמים על פי דין. לשכת האשראי מקבלת את המידע, מעבדת אותו ומשיבה לנותן האשראי ב"כן" או "לא". כל נותן אשראי רשאי לקבל שירות כאמור, ולא נדרש אישור של הלקוח למתן שירות כאמור, אלא נדרש רק יידוע הלקוח באופן מפורש ומראש. 3. מסירת דוח ריכוז נתונים ללקוח או למיופי כוח בתמורה. דוח כאמור כולל את כל המידע על הלקוח הנמצא במאגר. לקוח זכאי לקבלו פעם בשנה גם ללא תשלום. הלקוח יכול לבחור לקבל דוח ריכוז נתונים רגיל הכולל את המידע בשלוש השנים האחרונות בלבד או לקבל דוח ריכוז נתונים מלא, המתייחס לעשר השנים האחרונות. בנוסף להפעלת שירות נתוני אשראי, לשכת אשראי רשאית לתת שירותים המתבססים על שירותים אלה, ובכלל זה, לתת לנותן אשראי או ללקוח דירוג אשראי ולייעץ לו בנושאים מסוימים שמפורטים בחוק. לבסוף, החוק קובע הוראות שונות שנועדו להבטיח רמה גבוהה של הגנה על הפרטיות ועל בטחון המידע, בעת הפעלת המאגר והשירותים השונים שניתנים לפי חוק זה. כך למשל, החוק מגביל את משך הזמן שמידע נשמר במאגר לעשר שנים, כאשר לאחר שלוש שנים, המידע ישמר לצורכי תיעוד בלבד. כמו כן, נקבעה חובה של נגיד בנק ישראל למנות ממונה על הגנת הפרטיות, אשר ייעץ למנהל המאגר בעניין הגנת הפרטיות וייעץ לממונה בעניין בירור תלונות ציבור הנוגעות לפרטיות. תחילתו של חוק זה שלושים חודשים מיום פרסומו ברשומות כאשר ישנה אפשרות לדחות את מועד התחילה בתקופות נוספות שלא יעלו על ארבע שנים סך הכל.

Readings

Reservations, sections and other votes (6)

In order. Votes on reservations and individual sections are shown separately from the vote on the bill as a whole.

Source: bill page in the Knesset legislation database ↗

Law on Credit Data, 2016 · How the Knesset Votes