2019-06-10
Added · Updated
The Central Bank of Bosnia and Herzegovina establishes the Central Credit Register of Business Entities and Natural Persons to maintain a unified database of credit and other liabilities for financial system stability. Registered participants, including banks and microcredit organizations, are required to electronically submit detailed data on all liabilities for business entities and natural persons by the next working day. Access to this non-public data is restricted to the Central Bank, registered participants with written consent, and specific state authorities, with data retained for five years after account closure.
CENTRAL BANK OF BOSNIA AND HERZEGOVINA Number: UV-122-01-1-1612-3/19 NG Sarajevo, 10.06.2019.
Based on Article 2, paragraph (3), item i), Article 7, paragraph (1), items b), and Articles 59 and 70 of the Law on the Central Bank of Bosnia and Herzegovina ("Official Gazette of BiH", 1/97, 29/02, 13/03, 14/03, 9/05, 76/06 and 32/07) and Article 6, paragraph (1), items a) and d) of the Law on the Protection of Personal Data ("Official Gazette of BiH", 49/06, 76/11 and 89/11), the Administrative Board of the Central Bank of Bosnia and Herzegovina, at its 7th session held on 10.06.2019, adopts
Decision on the Central Credit Register of Business Entities and Natural Persons in Bosnia and Herzegovina
PART ONE – GENERAL PROVISIONS
Article 1. (Subject and Purpose of the Decision) (1) By this Decision, the Central Bank of Bosnia and Herzegovina (hereinafter: Central Bank) establishes the Central Credit Register of Business Entities and Natural Persons in Bosnia and Herzegovina (hereinafter: Central Credit Register) and determines its content, types of liabilities, method and deadlines for data submission, and conditions and methods for their use. (2) The purpose of establishing the Central Credit Register is to support the stability of the financial system of Bosnia and Herzegovina through the creation of a unified database of credit and other liabilities of business entities and natural persons.
Article 2. (Central Credit Register) (1) The Central Credit Register is established and maintained by the Central Bank. (2) The Central Credit Register is an electronic collection of data on credit and other liabilities of business entities and natural persons. (3) Data from the Central Credit Register are not public and may be made available for use only under the conditions and in the manner determined by this Decision.
Article 3. (Definitions of Terms) The individual terms used in this Decision have the following meanings: a) business entity is any entity to which a unique identification number has been assigned; b) natural person is any person who has a unique master number and a non-resident/foreign natural person who possesses an identification number assigned by the competent tax administration; c) participant in the register is any bank, microcredit organization, savings-credit organization, leasing company, factoring company, any other company under the jurisdiction of the competent entity agency for banking, an entity registered for the placement of financial funds that has voluntarily included itself in the Central Credit Register, as well as any other entity engaged in the purchase of receivables recorded in the Central Credit Register. d) liability is any recorded credit and other liability of a business entity or natural person that it has towards a participant in the register.
PART TWO – CONTENT OF THE CENTRAL CREDIT REGISTER
Article 4. (Content of the Central Credit Register for Business Entities) Participants in the register are obliged to submit the following data to the Central Credit Register for each liability of a business entity they manage:
Article 5. (Content of the Central Credit Register for Natural Persons) Participants in the register are obliged to submit the following data to the Central Credit Register for each liability of a natural person they manage:
PART THREE – METHOD AND DEADLINES FOR DATA SUBMISSION
Article 6. (Method and Deadlines for Data Submission) (1) Participants in the register are obliged to submit data from Articles 4 and 5 of this Decision to the Central Credit Register electronically, no later than the next working day from the date the data changes occurred, in the period from 08:00 to 16:00 hours. (2) For the purpose of paragraph (1) of this Article, a working day is considered a working day determined by the regulation of the Central Bank which establishes operational rules for giro clearing.
Article 7. (Responsibility for Submitted Data) (1) Participants in the register are responsible for the accuracy and timeliness of the submitted data, and the Central Bank is responsible for the identity of the submitted data with the data in the Central Credit Register and the administration of the register. (2) The Central Bank updates the data from Articles 4 and 5 of this Decision immediately upon their receipt, after which the updated data are available to data users. (3) In the event of the cessation of the existence of a participant in the register, it is obliged to send the data from Article 4, item 33, and Article 5, item 31, of this Decision, for all liabilities it submitted to the Central Credit Register, by recording all remaining active liabilities as closed in accordance with Article 4, item 32, and Article 5, item 30, of this Decision. Upon closure, liability data are submitted unchanged, i.e., in the form they were in at the moment of closure. (4) If a participant in the register does not act in accordance with paragraph (3) of this Article, the Central Bank will, within 60 days from the date of receipt of the act of the competent authority on the cessation of the existence of the participant in the register, or from the date of knowledge of the cessation of the existence of the participant in the register, make the appropriate changes in the Central Credit Register, so that the active liabilities that that participant in the register submitted to the Central Credit Register are closed. The reason for closure in this case will be indicator 5 – inactive participant in the register from Article 4, item 33, and Article 5, item 31, of this Decision. Other information about the liability will remain unchanged.
PART FOUR – CONDITIONS AND METHODS FOR USE OF DATA
Article 8. (Access to Data) (1) Access to data from the Central Credit Register can be obtained: a) by direct inspection via the internet and b) in the form of individual reports. (2) Search in the Central Credit Register can only be performed via the unique identification number of the business entity, the unique master number of the natural person, or the identification number of the non-resident/foreign natural person. (3) Exceptionally from paragraph (2) of this Article, if a business entity or natural person is recorded in the Central Credit Register under a unique identifier (a number consisting of thirteen ones) due to a lack of data on the identification number, or unique master number, in that case, the search is performed using the unique identifier and the name of the business entity, or the first and last name of the natural person.
Article 9. (Direct Inspection via the Internet) (1) Data users from the Central Credit Register who have the right to direct inspection of data via the internet are: a) the Central Bank, b) participants in the register, c) entity agencies for banking, courts, prosecutor's offices, public prosecutor's offices, internal affairs bodies, and police agencies. (2) The Central Bank accesses the Central Credit Register by direct inspection exclusively for the purpose of issuing an individual report based on an act from Article 10, paragraph (3) of this Decision. (3) Participants in the register can access data from the Central Credit Register by direct inspection only with the written consent of the business entity, or natural person. (4) The written consent of the business entity must be signed by an authorized person and certified with the seal of that business entity, while the written consent of the natural person must be signed by that natural person and must contain the number of their identification document and the name of the authority that issued it. (5) Bodies from paragraph (1), item c) of this Article, when accessing data from the Central Credit Register by direct inspection, are obliged to enter the purpose and legal basis for accessing the data in the designated field. (6) All data users from paragraph (1) of this Decision are obliged to provide the technical conditions necessary for access to the Central Credit Register themselves. (7) Each individual access to data from the Central Credit Register is recorded and is carried out exclusively using a valid certificate in the form of a USB key and password or using a valid certificate in the form of a smart card and password.
Article 10. (Access to Data in the Form of Individual Reports) (1) The Central Bank provides data from the Central Credit Register in the form of individual reports only based on a written request of authorities authorized by law for the performance of duties within their jurisdiction established by law. (2) The written request from paragraph (1) of this Article, addressed to the Central Bank, must contain the full name of the business entity, or full first and last name of the natural person for whom data is requested, the unique identification number or unique master number, the purpose and legal basis for obtaining and using the data, as well as the type of data requested. (3) If the request from paragraph (2) of this Article is complete and proper, the Governor of the Central Bank approves access to the requested data by their individual act. (4) Issuance of individual reports from the Central Credit Register can be performed by banks, microcredit organizations, savings-credit organizations, leasing companies, and factoring companies, and any other company under the jurisdiction of the competent entity agency for banking, based on a written request from a business entity or natural person addressed to the aforementioned participant in the register. The written request addressed to the participant in the register from this paragraph can relate to the submission of an individual report only for that business entity, or natural person who submitted the request. If a participant in the register from this paragraph issues individual reports from the Central Credit Register, it is obliged to notify the Central Bank of this. (5) The written request of the business entity must be signed by an authorized person and certified with the seal of that business entity, while the written request of the natural person must be signed by that natural person and must contain the number of their identification document and the name of the authority that issued it. (6) The written request from paragraph (5) of this Article is valid only for one access to data from the Central Credit Register.
Article 11. (Types of Reports) (1) Access to data from the Central Credit Register is possible through the following reports: a) Report on Current Liabilities of the Business Entity (BP1), b) Report on Closed Liabilities of Business Entities (BP2), c) Report on Current Liabilities of the Natural Person (BF1) and d) Report on Closed Liabilities of the Natural Person (BF2). (2) The reports from item b) and d) of paragraph (1) of this Article contain data on closed liabilities for the last five years, calculated from the date of actual repayment of the liability. (3) The Central Bank and entity agencies for banking have the right to access the register for the purpose of generating various statistical reports for their own needs, which do not contain individual data.
Article 12. (Types of Data in Reports) (1) All reports from Article 11, paragraph (1) of this Decision contain the date and time of creation of the report, the name of the business entity, or first and last name of the natural person, address, and unique identification number, or unique master number of the business entity, or natural person. (2) Depending on the type of liability, the reports from Article 11, paragraph (1) of this Decision may also contain other data listed in Articles 4 and 5 of this Decision.
Article 13. (Method of Use of Data) (1) Data users from Article 9, paragraph (1) of this Decision can use data from the Central Credit Register exclusively for the performance of duties within their jurisdiction and cannot further reproduce and distribute the received data. (2) Data users from Article 10, paragraph (4) of this Decision can issue individual reports from the Central Credit Register exclusively for the purpose prescribed by the aforementioned Article and paragraph.
Article 14. (Measures for the Protection of Personal Data and Retention Periods) (1) Personal data from Article 5 of this Decision, which banks submit to the Central Credit Register, the Central Bank collects and processes in accordance with the regulation governing the area of protection of personal data in Bosnia and Herzegovina. (2) The Central Bank implements organizational-technical measures for the protection of personal data submitted to the Central Credit Register, which include informing and training officials working on the processing of personal data, physical measures for the protection of work premises and equipment where personal data processing is performed, preventing unauthorized access to personal data, preventing unauthorized duplication, copying, transcription of personal data, and preventing destruction of personal data, which are detailed in the regulation of the Central Bank by which the protection of personal data in the Central Bank is established. (3) The Central Bank applies protection measures relating to personal data also to the data from Article 4 of this Decision. (4) The Central Bank retains data from Articles 4 and 5 of this Decision for five years, calculated from the actual date of closing the liability, and if it does not exist, from the last date of updating the closed liability, after which those data are deleted. (5) Information about access to data from the Central Credit Register is retained by the Central Bank for five years from the date of access to the register.
Article 15. (Notification on Processing of Personal Data) The Central Bank will, based on a written request of the holder of personal data whose personal data are collected and submitted
[RegAlert note: the English text above is a translation of the first 24,000 characters of a 27,324-character original (88% of the document). The remainder was not translated. The complete original-language text is stored with this document.]
More like this from CBBH
We email you every new CBBH publication the day it's published.