2023-01-10
Added · Updated
The Central Bank of Jordan issued Instructions No. 13/2022, effective April 1, 2023, establishing operational controls for Credit Information Companies, Data Providers, and Credit Providers. The document mandates specific data retention periods, such as three years for payment delays and seven years for insolvency, while requiring weekly data updates from providers and daily updates for returned checks. It further imposes security protocols for database access, prohibits unauthorized disclosure of credit information, and requires Credit Information Companies to submit audited accounts and quarterly operational reports to the regulator.
In the Name of Allah, the Most Gracious, the Most Merciful
[Logo of the Central Bank of Jordan]
Number: 28/4847 Date: 27/5/1444 AH Corresponding to: 21/12/2022 AD
Instructions on Credit Information Companies' Operational Controls No. (13/2022) Issued pursuant to the provisions of Article (32/b) of the Temporary Credit Information Law No. (15) of 2010
Article (1): Scope of Application These Instructions are titled "Instructions on Credit Information Companies' Operational Controls" and apply to the following entities to the extent applicable to each, and shall be effective as of 1/4/2023: a. Credit Information Companies. b. Data Providers. c. Credit Providers.
Article (2): Definitions a. The following words and phrases shall have the meanings specified below wherever they appear in these Instructions, unless the context indicates otherwise:
b. The words and phrases contained in these Instructions shall have the meanings specified for them under the Law and the System, unless the context indicates otherwise.
Article (3): Retention of Credit Information and Any Information Related to the Customer's Credit Status in the Company's Database and Credit Report a. The following information and data shall appear in the credit report for the duration specified for each, as follows:
Article (4): Security and Protection of the Database Subject to what is stipulated in the System, the Company shall organize the access of Credit Providers to its database taking into account the following: a. Access to the Company's database shall be secure, using appropriate passwords that must be changed periodically. b. Periodic review of password controls for Company employees and Credit Providers. c. Periodic monitoring of credit report usage patterns to investigate any unusual usage. d. Retention of automated audit reports for all database access operations and modifications made to credit records.
Article (5): Credit Providers and Data Providers Subject to what is stated in Article (16) of the System, the following shall be observed: a. Before concluding agreements with Credit Providers, the Company must organize their access to any of the services it provides by exercising due diligence to verify the eligibility of the Credit Provider to obtain any of those services. b. The Company must re-verify the eligibility of the Credit Provider upon renewing the agreement concluded with them or if the Company has any reservations regarding the Credit Provider's use of credit reports, or whenever necessary. c. Data Providers must provide the Company with updated data on a weekly basis. d. Banks must provide the Company with data on returned checks on a daily basis. e. Data Providers must provide the Company with updated data on a daily basis if such data involves fundamental changes to the customer's credit information, including the following cases:
Article (6): Customer Rights In addition to what is stated in the Law and the System, the customer has the following rights: a. To know the entity that made the inquiry about their credit report within the last two years from the date of requesting the report. b. To submit an objection to the Company if their report contains incorrect information, or if the report is not updated, or if their credit report was inquired about without a legitimate purpose for the inquiry, and any other cases requiring objection.
Article (7): Objection to the Accuracy of Credit Information Subject to what is stated in Articles (17) and (18) of the System, the following shall be observed: a. The Company must prepare an approved policy outlining the procedures for handling objections submitted to it. b. An objection to the credit report itself is allowed only once. If the customer wishes to submit a second objection, they must request a new credit report before submitting the objection. c. If the Data Provider confirms the accuracy of the credit information subject to the objection, and the customer continues to object, the customer has the right to state their reasons for non-approval in a brief, written manner, which shall be saved in the customer's credit register. d. If it is determined that the inaccuracy of the information subject to the objection is due to the Company, the Company must provide the Central Bank with a report containing all details regarding this matter. e. The Company must inform the customer regarding the resolution of their objection. f. The Company must maintain a register of all objections submitted by customers regarding their credit information, the procedures taken regarding them, and the results thereof, for a period of not less than (5) years from the date of resolving the objection. g. The Data Provider is responsible for any error or inaccuracy in the information and data they provide to the Company.
Article (8): General Provisions a. The Company must comply with the following:
b. The Company must provide the Central Bank with the following:
[Signature] Governor Dr. Adel Al-Sharkas