2023-01-10

Added · Updated

Instructions on Credit Information Companies' Operational Controls No. 13/2022

The Central Bank of Jordan issued Instructions No. 13/2022, effective April 1, 2023, establishing operational controls for Credit Information Companies, Data Providers, and Credit Providers. The document mandates specific data retention periods, such as three years for payment delays and seven years for insolvency, while requiring weekly data updates from providers and daily updates for returned checks. It further imposes security protocols for database access, prohibits unauthorized disclosure of credit information, and requires Credit Information Companies to submit audited accounts and quarterly operational reports to the regulator.

Central Bank of Jordan logo

Jordan

Central Bank of Jordan

Click to view thumbnail

In the Name of Allah, the Most Gracious, the Most Merciful

[Logo of the Central Bank of Jordan]

Number: 28/4847 Date: 27/5/1444 AH Corresponding to: 21/12/2022 AD

Instructions on Credit Information Companies' Operational Controls No. (13/2022) Issued pursuant to the provisions of Article (32/b) of the Temporary Credit Information Law No. (15) of 2010

Article (1): Scope of Application These Instructions are titled "Instructions on Credit Information Companies' Operational Controls" and apply to the following entities to the extent applicable to each, and shall be effective as of 1/4/2023: a. Credit Information Companies. b. Data Providers. c. Credit Providers.

Article (2): Definitions a. The following words and phrases shall have the meanings specified below wherever they appear in these Instructions, unless the context indicates otherwise:

  • The Law: The Temporary Credit Information Law No. (15) of 2010.
  • The System: The Credit Information Companies System No. (36) of 2011.
  • The Central Bank: The Central Bank of Jordan.
  • The Company: The licensed Credit Information Company authorized to conduct the specified activities in accordance with the provisions of the Law and the System.
  • The Board: The Company's Board of Directors or its governing body.
  • Credit Register: The register compiled by the Company containing all credit information of the person, collected from multiple sources, upon which the credit report is based.
  • Returned Check: Any check drawn on any bank that is not honored due to insufficient or no funds, whether in Jordanian Dinar or foreign currencies.

b. The words and phrases contained in these Instructions shall have the meanings specified for them under the Law and the System, unless the context indicates otherwise.


Article (3): Retention of Credit Information and Any Information Related to the Customer's Credit Status in the Company's Database and Credit Report a. The following information and data shall appear in the credit report for the duration specified for each, as follows:

  1. Information related to inquiries about the customer, including the number of inquiries and the number of entities that made the inquiry: Two years from the date of the inquiry.
  2. Information related to the customer's failure to fulfill obligations on time, including delay and/or cessation of payment: (3) years from the date of settling each installment or the customer's discharge from it.
  3. Information related to settled debts: For the three years preceding the date of the inquiry, regarding the payment pattern.
  4. Information related to returned checks: (3) years from the date of settling the check or (5) years from the date of re-presenting the check if it was not settled, whichever is earlier.
  5. Information related to the content and result of objections submitted by the customer regarding any information in the credit report which were rejected by the data provider: (3) years from the date of ruling on the objection.
  6. Information related to debt write-offs: (5) years from the date of total or partial debt write-off or (3) years from the date of settling the debt or the customer's discharge from it in any manner, whichever is earlier.
  7. Information related to final judicial rulings concerning the customer's credit status: (5) years from the date of issuing the relevant rulings or (3) years from the date of settling the debt or the customer's discharge from it in any manner, whichever is earlier.
  8. Information related to the customer's insolvency/bankruptcy: (7) years from the date of the ruling declaring it. b. The Company shall retain credit information, including the information mentioned above, in its database for a period of (10) years from the date of termination of the contractual relationship between the customer and the credit provider. c. The Company shall maintain a register of all inquiries made on the customer's credit report, such that the register contains the date of each inquiry and the entity that made the inquiry. In the event that the inquiry revealed the non-availability of a report, the Company must retain a register containing the date of the inquiry, the information used in the inquiry about the customer, and the entity that made the inquiry.

Article (4): Security and Protection of the Database Subject to what is stipulated in the System, the Company shall organize the access of Credit Providers to its database taking into account the following: a. Access to the Company's database shall be secure, using appropriate passwords that must be changed periodically. b. Periodic review of password controls for Company employees and Credit Providers. c. Periodic monitoring of credit report usage patterns to investigate any unusual usage. d. Retention of automated audit reports for all database access operations and modifications made to credit records.


Article (5): Credit Providers and Data Providers Subject to what is stated in Article (16) of the System, the following shall be observed: a. Before concluding agreements with Credit Providers, the Company must organize their access to any of the services it provides by exercising due diligence to verify the eligibility of the Credit Provider to obtain any of those services. b. The Company must re-verify the eligibility of the Credit Provider upon renewing the agreement concluded with them or if the Company has any reservations regarding the Credit Provider's use of credit reports, or whenever necessary. c. Data Providers must provide the Company with updated data on a weekly basis. d. Banks must provide the Company with data on returned checks on a daily basis. e. Data Providers must provide the Company with updated data on a daily basis if such data involves fundamental changes to the customer's credit information, including the following cases:

  1. If the data is found to be inaccurate or incorrect.
  2. If the customer is found to be in a state of default.
  3. If the customer has fully settled their financial obligations.
  4. If the customer has obtained any new credit. f. Data Providers and Credit Providers must respect the customer rights stipulated in Article (6) of these Instructions, as well as the privacy of their data and protect it from any unauthorized use during the exchange, updating, or use of credit reports for any customers. g. Data Providers are prohibited from including credit information belonging to their customers under the name of the guarantor and providing any credit information pertaining to the guarantor without obtaining the guarantor's prior written consent. h. Credit Providers are prohibited from allowing third parties to view the information and data they obtain from the Company, whether by disclosing it, selling it, or transferring it. i. Credit Providers must be subject to the Central Bank's supervision before granting or renewing credit to any customer by inquiring about them through the Company. j. Credit Providers must not make any changes or modifications to any clause of the credit report issued by the Company. k. Credit Providers must retain the customer's access authorization for a period not less than the duration of the credit contract, unless there is a dispute or complaint regarding the relevant credit and/or the information appearing in the customer's credit report, in which case it shall be retained until the dispute is resolved or a final judicial ruling is issued.

Article (6): Customer Rights In addition to what is stated in the Law and the System, the customer has the following rights: a. To know the entity that made the inquiry about their credit report within the last two years from the date of requesting the report. b. To submit an objection to the Company if their report contains incorrect information, or if the report is not updated, or if their credit report was inquired about without a legitimate purpose for the inquiry, and any other cases requiring objection.


Article (7): Objection to the Accuracy of Credit Information Subject to what is stated in Articles (17) and (18) of the System, the following shall be observed: a. The Company must prepare an approved policy outlining the procedures for handling objections submitted to it. b. An objection to the credit report itself is allowed only once. If the customer wishes to submit a second objection, they must request a new credit report before submitting the objection. c. If the Data Provider confirms the accuracy of the credit information subject to the objection, and the customer continues to object, the customer has the right to state their reasons for non-approval in a brief, written manner, which shall be saved in the customer's credit register. d. If it is determined that the inaccuracy of the information subject to the objection is due to the Company, the Company must provide the Central Bank with a report containing all details regarding this matter. e. The Company must inform the customer regarding the resolution of their objection. f. The Company must maintain a register of all objections submitted by customers regarding their credit information, the procedures taken regarding them, and the results thereof, for a period of not less than (5) years from the date of resolving the objection. g. The Data Provider is responsible for any error or inaccuracy in the information and data they provide to the Company.

Article (8): General Provisions a. The Company must comply with the following:

  1. Submit audited final accounts certified by its statutory auditor to the Central Bank within a period not exceeding two months from the end of the financial year.
  2. Obtain prior approval from the Central Bank before opening any branches.
  3. Notify the Central Bank of any cyberattacks on their technical systems and the measures taken in response.
  4. Prepare a register including the names, activities, and addresses of Data Providers, as well as the contracts and agreements concluded with them.
  5. Establish a code of business ethics approved by the Board, which must include clear principles, policies, and controls for work behaviors and professional ethical conduct. The Company is responsible for taking all necessary steps to verify compliance by Board members, senior executive management, and all employees with this code, and must provide a copy to the Central Bank.

b. The Company must provide the Central Bank with the following:

  1. A quarterly report on its operations regarding the provision of information and customer inquiries, on both an individual and sectoral level for Credit Providers.
  2. An annual report on complaints and objections received by the Company.
  3. Any data or information requested by the Central Bank in the time and format specified.

[Signature] Governor Dr. Adel Al-Sharkas