2026-04-21
Added · Updated
This law amends the definition of 'customer' to include potential customers, guarantors, and connected persons, and establishes detailed definitions for data recipients and data submitters within the Artemis data exchange mechanism. It replaces Article 28D to mandate the Central Bank of Cyprus's supervision of the Artemis system, granting it powers to inspect entities, require data corrections, and issue instructions regarding creditworthiness assessment and data processing. The amendment also expands the scope of data submitters to include the Registrar of Companies, the Insolvency Department, and the Director of the Department of Land and Surveys, while defining the rights of data recipients to access and use customer data for credit assessment purposes.
Get CBC alerts — same-day email on every new publication.
E.E. Part I(I) Law 84(I)/2026
No. 5087, 21.4.2026
The Law Amending the Law on the Business of Credit Institutions of 2026 is enacted with publication in the Official Gazette of the Republic of Cyprus in accordance with Article 52 of the Constitution.
Number 84(I) of 2026
LAW AMENDING THE LAWS ON THE BUSINESS OF CREDIT INSTITUTIONS OF 1997 TO 2025
Preamble. For the purposes of further harmonization with:
Official Journal of the E.U.: L 60, 28.2.2014, p. 34.
(a) Article 21 of the European Union Act titled 'Directive 2014/17/EU of the European Parliament and of the Council of 4 February 2014 on credit agreements for consumers relating to residential immovable property and amending Directives 2008/48/EC and 2013/36/EU and Regulation (EU) No 1093/2010'; and Official Journal of the E.U.: L 133, 22.5.2008, p. 66. (b) Article 8(1) and Article 9(1) of the European Union Act titled 'Directive 2008/48/EC of the European Parliament and of the Council of 23 April 2008 on credit agreements for consumers and repealing Council Directive 87/102/EEC',
The House of Representatives enacts as follows:
Short title.
66(I) of 1997
74(I) of 1999
94(I) of 2000
119(I) of 2003
4(I) of 2004
151(I) of 2004
231(I) of 2004
235(I) of 2004
20(I) of 2005
80(I) of 2008
100(I) of 2009
123(I) of 2009
27(I) of 2011
104(I) of 2011
107(I) of 2012
14(I) of 2013
87(I) of 2013
102(I) of 2013
141(I) of 2013
5(I) of 2015
26(I) of 2015
35(I) of 2015
71(I) of 2015
93(I) of 2015
109(I) of 2015
152(I) of 2015
168(I) of 2015
21(I) of 2016
5(I) of 2017
38(I) of 2017
169(I) of 2017
28(I) of 2018
89(I) of 2018
153(I) of 2018
80(I) of 2019
149(I) of 2019
21(I) of 2020
73(I) of 2020
28 (I) of 2021
94(I) of 2021
95(I) of 2021
162(I) of 2021
163(I) of 2021
61(I) of 2022
62(I) of 2022
162(I) of 2022
17(I) of 2023
59(I) of 2024
158(I) of 2024
14(I) of 2025.
Amendment of Article 2 of the principal Law.
2. Subsection (1) of Article 2 of the principal Law is amended as follows:
(a) By adding, in the appropriate alphabetical order, the following new terms and their definitions:
125(I) of 2018
26(I) of 2022.
“Data Protection Commissioner” means the Data Protection Commissioner appointed under the provisions of Article 19 of the Law on the Protection of Natural Persons Regarding the Processing of Personal Data and on the Free Movement of Such Data; “data recipients” means— (a) licensed credit institutions (LCIs); (b) branches of credit institutions operating in the Republic under Article 10A; 169(I) of 2015 86(I) of 2018 129(I) of 2022 121(I) of 2024 86(I) of 2026. 122(I) of 2024 70(I) of 2025 85(I) of 2026. (c) managers or managers of credit facilities, as defined in these terms by Article 2 of the Law on the Sale of Credit Facilities and Related Matters or/and managers of credits as defined in this term by Article 2 of the Law on Managers of Credits and Buyers of Credits and Related Matters, as appropriate; 72(I) of 2016 67(I) of 2020 82(I) of 2026. (d) finance lease companies or finance lease service providers, as defined in these terms by Article 2 of the Finance Lease Law; 149(I) of 2017 30(I) of 2019 77(I) of 2021 49(I) of 2023 119(I) of 2024 80(I) of 2026. (e) lenders, as defined in this term by Article 2 of the Law on Credit Agreements for Consumers in Relation to Immovable Property Intended for Residence, including lenders from another Member State; 176(I) of 2012 40(I) of 2013 (f) credit institutions, as defined in this term by Article 2 of the Law on Consumer Credit Agreements, including credit institutions from another Member State; 50(I) of 2013 42(I) of 2017 120(I) of 2024 83(I) of 2026. (g) managers of securitised exposures, as defined in this term by Article 2 of the Securitisation Law; (h) any person who has the right to receive, access, process and/or use customer data in the ARTEMIS data exchange mechanism under Union law, under the conditions that may be determined; Official Journal of the E.U.: L 176, 27.6.2013, p. 1. “connected persons” means persons who form a group of connected customers, as defined in this term by Article 4(1)(39) of Regulation (EU) No 575/2013, including, in the case of a legal person, the beneficial owners; “data submitters” means— (a) licensed credit institutions (LCIs); (b) branches of credit institutions operating in the Republic under Article 10A; (c) buyers or buyers of credit facilities, as defined in these terms by Article 2 of the Law on the Sale of Credit Facilities and Related Matters or/and buyers of credits, as defined in this term by Article 2 of the Law on Managers of Credits and Buyers of Credits and Related Matters, as appropriate; (d) managers or managers of credit facilities, as defined in these terms by Article 2 of the Law on the Sale of Credit Facilities and Related Matters or/and managers of credits, as defined in this term by Article 2 of the Law on Managers of Credits and Buyers of Credits and Related Matters, as appropriate; (e) finance lease companies or finance lease service providers, as defined in these terms by Article 2 of the Finance Lease Law; (f) non-credit institutions, as
defined in this term by Article 2 of the Law on Credit Agreements for Consumers in Relation to Immovable Property Intended for Residence; (g) managers of securitised exposures, as defined in this term by Article 2 of the Securitisation Law; (h) any person who is required to submit customer data to the ARTEMIS data exchange mechanism under Union law, under the conditions that may be determined;
(b) by replacing the definitions of the terms 'potential customer', 'ARTEMIS data exchange mechanism', 'customer' and 'system or data exchange mechanism' with the following definitions, respectively:
“potential customer” means, for the purposes of the definition of the term 'customer', a natural or legal person, resident or non-resident in the Republic, who— (a) has submitted an application or in any other way requested the provision of a facility, and/or (b) intends to provide a guarantee and/or collateral as a guarantor and/or as a provider of collateral in the context of an existing or impending facility provision contract:
Provided that, a reference to 'facility' is interpreted in accordance with the definition of the term 'customer';
“ARTEMIS data exchange mechanism” means the system or data exchange mechanism operating within the Cypriot financial system;
“customer” means, for the purposes of the definitions of the terms 'data recipients', 'data submitters' and 'system or data exchange mechanism' and for the purposes of Articles 28D, 28E, paragraph (z) of subsection (2) of Article 29, and subsections (6) and (7) of Article 41, a natural or legal person who— (a) is a potential customer; or (b) has entered into a facility provision contract, and includes a debtor or borrower by operation of law; or (c) is a guarantor and/or provider of collateral of a person referred to in paragraph (b), and includes a debtor or borrower by operation of law in the capacity of guarantor and/or provider of collateral; or (d) is a connected person of any person referred to in paragraphs (a), (b) or (c). For the purposes of the definition of the term 'customer'— (a) the reference to 'facility' refers to, and includes— (i) a credit opening or credit agreement or credit or finance facility agreement including, among others, a loan, an overdraft limit, a credit card limit, a factoring agreement, a stock finance agreement, a finance lease agreement or any other financial facility, (ii) any of the facilities referred to in sub-paragraph (i), which has been purchased from and/or transferred to a buyer of credit facilities under the provisions of the Law on the Sale of Credit Facilities and Related Matters or/and to a buyer of credits under the provisions of the Law on Managers of Credits and Buyers of Credits and Related Matters, (iii) any of the facilities referred to in sub-paragraph (i), regardless of whether the relevant facility has been terminated and/or has ceased to be valid and/or any legal proceedings are pending in relation to it, (iv) any of the facilities referred to in sub-paragraph (i), which is undergoing restructuring, modification, rewriting, replacement or other change and/or assignment, reinstatement or other form of transfer; and (b) the definition includes, as appropriate, the customer of the person whose facilities and/or collateral and/or guarantees are managed by a manager of credit facilities under the provisions of the Law on the Sale of Credit Facilities and Related Matters or/and a manager of credits under the provisions of the Law on Managers of Credits and Buyers of Credits and Related Matters;
“system or data exchange mechanism” means a system or mechanism that meets all the following conditions:
(a) data recipients and data submitters, as appropriate, submit, store, use, provide, receive and/or access or process in any other way customer data in the system or mechanism, for the purpose of assessing the creditworthiness of customers for the most effective management of facilities and credit or/and other related risks, with the aim of ensuring financial stability in the Republic; (b) its operation aims at— (i) providing services for assessing the creditworthiness of customers including services for fully or partially automated as well as non-automated calibration of the creditworthiness of customers; and/or (ii) collecting, submitting, storing, processing by and/or transmitting and providing access to data recipients and data submitters, as appropriate, of data, elements and/or customer information, in each case for the purpose of assessing the creditworthiness of customers for the most effective management of facilities and credit or and other related risks, with the aim of ensuring financial stability in the Republic; and (c) it provides information, referred to in Article 28E and in the instructions issued under this Law, to the Central Bank for the purposes of exercising its powers arising from this Law, among others, for the calculation of the probability of default and loss given default, as well as for the purposes of fulfilling the obligations and duties of the Central Bank under any law and/or Union law;
Amendment of Article 2A of the principal Law.
3. Article 2A of the principal Law is amended by adding in subsection (1) immediately after the phrase 'subsection (2)' (first line) the phrase 'and the provisions of Article 28D'.
Amendment of the principal Law by replacing Article 28D.
4. The principal Law is amended by replacing Article 28D with the following Article:
Establishment and operation of the system or data exchange mechanism.
28D.-(1) Without prejudice to any other provision of this Law, this Law regulates the establishment and operation of the system or data exchange mechanism.
(2) The system or data exchange mechanism is established for the purpose of assessing the creditworthiness of customers, including fully or partially automated as well as non-automated calibration of the creditworthiness of customers, for the most effective management of facilities and credit or/and other related risks, with the aim of ensuring financial stability in the Republic. (3) The articles of this Law concerning the establishment and operation of the system or data exchange mechanism apply— (a) to the ARTEMIS data exchange mechanism; (b) to data recipients; and (c) to data submitters. (4) The Central Bank exercises the powers and duties provided for in this Law and monitors the activities of data recipients and data submitters, in order to assess their compliance with the requirements of this Law for the purposes of the ARTEMIS data exchange mechanism, as well as the instructions issued thereunder. (5) Data recipients and data submitters, when summoned by the Central Bank in the context of its supervisory activities, allow duly authorized officers of the Bank to enter their premises to inspect and/or supervise and/or investigate their work and activities in relation to the data received and/or submitted to the ARTEMIS data exchange mechanism and make available to them any books, documents or files and/or transmit to the Central Bank any information they deem necessary for the exercise of its supervisory activities under the provisions of this Law, as well as the instructions issued thereunder. (6) The authorized officers of the Central Bank may be assisted by duly qualified persons, who are named for this purpose by the Central Bank and who are subject to the same confidentiality obligations as the officers of the Central Bank. (7) In the event that incorrect or incomplete data is submitted to the ARTEMIS data exchange mechanism by a data submitter, the said person, after being notified in writing by the ARTEMIS data exchange mechanism, immediately proceeds to correct and resubmit the data or as soon as possible after obtaining sufficient evidence from their customer and in case of non-compliance, the Central Bank has the power to require correction of the elements in question:
Provided that, the correction procedure provided for in this subsection does not affect the exercise of the right to correction in accordance with the provisions of Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons Regarding the Processing of Personal Data and on the Free Movement of Such Data. (8)(a) Data recipients have the right to receive, access, use and/or process customer data from the ARTEMIS data exchange mechanism in accordance with the provisions of this Law and the instructions issued by the Central Bank thereunder, subject, in any case, to any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as appropriate. 70(I) of 1998 105(I) of 1999 163(I) of 2000 169(I) of 2003 254(I) of 2004 156(I) of 2005 52(I) of 2011 5(I) of 2019 12(I) of 2021 92(I) of 2022 172(I) of 2022 164(I) of 2023 1(I) of 2024 60(I) of 2024 58(I) of 2025. (b) Data recipients who grant loans on behalf of the Central Equal Burden Distribution Authority and/or grant loans in relation to which the Central Equal Burden Distribution Authority provides financial support or other grant or support in any case under the Law on the Central Equal Burden Distribution Authority (Establishment, Purposes, Powers and Other Related Matters), have the right to receive, access, use and/or process data of natural or legal persons from the ARTEMIS data exchange mechanism which they receive or request to receive a loan or financial support or other grant or support from the Central Equal Burden Distribution Authority, including data of any debtors and/or co-debtors and/or guarantors thereof and the said data recipients have the right to provide the aforementioned data to the Central Equal Burden Distribution Authority, provided that the relevant natural or legal person has given its consent for the provision of the aforementioned data of theirs to the Central Equal Burden Distribution Authority. (9) Data submitters submit customer data to the ARTEMIS data exchange mechanism in accordance with the provisions of this Law and the instructions issued by the Central Bank thereunder, subject, in any case, to any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as appropriate:
Provided that, persons provided for in paragraph (c) of the definition of the term 'data submitters' submit customer data to the ARTEMIS data exchange mechanism only to the extent that they do not proceed to submit the relevant customer data to the ARTEMIS data exchange mechanism on their behalf by the entities provided for in paragraph (d) of the definition of the term 'data submitters'. (10) For the purposes of the operation of the ARTEMIS data exchange mechanism, the following persons submit to the ARTEMIS data exchange mechanism elements determined by the Central Bank in instructions issued under this Law and comply with any other relevant regulation as provided for in the said instructions in relation to the aforementioned submission of elements and the ARTEMIS data exchange mechanism is obliged to process the said elements as provided for in this Law and the instructions issued by the Central Bank under this Law:
Chap. 113.
41(I) of 1994
15(I) of 1995
21(I) of 1997
82(I) of 1999
(a) the Registrar of Companies, as defined under the Companies Law, 149(I) of 1999 2(I) of 2000 135(I) of 2000 151(I) of 2000 76(I) of 2001 70(I) of 2003 167(I) of 2003 92(I) of 2004 24(I) of 2005 129(I) of 2005 130(I) of 2005 98(I) of 2006 124(I) of 2006 70(I) of 2007 71(I) of 2007 131(I) of 2007 186(I) of 2007 87(I) of 2008 41(I) of 2009 49(I) of 2009 99(I) of 2009 42(I) of 2010 60(I) of 2010 88(I) of 2010 53(I) of 2011 117(I) of 2011 145(I) of 2011 157(I) of 2011 198(I) of 2011 64(I) of 2012 98(I) of 2012 190(I) of 2012 203(I) of 2012 6(I) of 2013 90(I) of 2013 74(I) of 2014 75(I) of 2014 18(I) of 2015 62(I) of 2015 63(I) of 2015 89(I) of 2015 120(I) of 2015 40(I) of 2016 90(I) of 2016 97(I) of 2016 17(I) of 2017 33(I) of 2017 51(I) of 2017 37(I) of 2018 83(I) of 2018 149(I) of 2018 163(I) of 2019 38(I) of 2020 43(I) of 2020 191(I) of 2020 192(I) of 2020 43(I) of 2021 117(I) of 2021 150(I) of 2021 151(I) of 2021 87(I) of 2022 88(I) of 2022 96(I) of 2022 213(I) of 2022 80(I) of 2023 151(I) of 2023 18(I) of 2024 25(I) of 2024 26(I) of 2024 101(I) of 2024 138(I) of 2024 28(I) of 2025. 68(I) of 2020 211(I) of 2022. (b) the Insolvency Department, as defined under the Law on the Insolvency Department and Related Matters, and 141(I) of 2002 65(I) of 2003 76(I) of 2003 62(I) of 2004 13(I) of 2006 123(I) of 2007 92(I) of 2009 81(I) of 2010 44(I) of 2011 36(I) of 2013 174(I) of 2013 15(I) of 2015 16(I) of 2015 44(I) of 2015 166(I) of 2015 168(I) of 2017 9(I) of 2019 65(I) of 2019 86(I) of 2020 113(I) of 2020 145(I) of 2020 59(I) of 2021 149(I) of 2023 34(I) of 2024 76(I) of 2024 92(I) of 2025. (c) the Director of the Department of Land and Surveys and the Registrar, as defined under the Population Register Law. (11) The Central Bank may determine and/or specify in instructions issued under this Law the rights and obligations of data recipients and data submitters, the data received and submitted, as appropriate, as well as matters concerning the access and participation of data recipients and data submitters, including the terms and conditions of their access and participation and any other regulation as it deems appropriate, subject, in any case, to the provisions of this Law, the provisions of Regulation (EU) 2016/679, the Law on the Protection of Natural Persons Regarding the Processing of Personal Data and on the Free Movement of Such Data and the principle of data minimization, and subject, in any case, to any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as appropriate. (12) The Central Bank may further determine in instructions issued under this Law matters concerning the fully or partially automated as well as non-automated preparation of calibration of the creditworthiness of customers, including the creation of a creditworthiness calibration system, the process and manner of operation of preparing calibration of the creditworthiness of customers, the form of the creditworthiness
calibration report and the contents and characteristics of the said report, the categorization of customers on a creditworthiness rating scale and any other regulation in relation to the calibration of the creditworthiness of customers, as it deems appropriate and measures for the protection and safeguarding of the legitimate interests of customers in the context of preparing fully or partially automated as well as non-automated calibration of the creditworthiness of customers, subject, in any case, to the provisions of this Law, the provisions of Regulation (EU) 2016/679, the Law on the Protection of Natural Persons Regarding the Processing of Personal Data and on the Free Movement of Such Data and the principle of data minimization, and subject, in any case, to any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as appropriate.
Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data and the principle of data minimization.
(13)(a) The Central Bank shall inform the ARTEMIS data exchange mechanism in writing of the approvals granted for the purposes of access and submission of data to the ARTEMIS data exchange mechanism, provided that such approvals are provided for under the provisions of this Law, the directives issued thereunder, and any special provisions of the laws under which the operation of data recipients and submitters is regulated.
(b) Upon notification of the approvals provided for in sub-paragraph (a), the ARTEMIS data exchange mechanism shall, with immediate effect, permit the relevant access of data recipients or participation of data submitters to the ARTEMIS data exchange mechanism in accordance with such approval.
(14)(a) Transmission of data from the ARTEMIS data exchange mechanism to other systems or data exchange mechanisms or to other databases that operate and are used exclusively within the European Economic Area for the assessment of creditworthiness is permitted only in compliance with the provisions of Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, and after the applicant for the transmission has submitted to the Central Bank a documented report, which includes the findings of consultation with the relevant data recipients and/or data submitters, in relation to the transmission; if the Central Bank deems it necessary, it shall proceed with consultation itself.
(b) The Central Bank, having agreed with the reasons and the purpose of the requested transmission exclusively within the European Economic Area and having determined the data that may be transmitted from the ARTEMIS data exchange mechanism within the European Economic Area, shall take all actions arising from Regulation (EU) 2016/679 and the provisions of the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data in relation to the transmission.
(15) The provisions of Article 29 shall apply, with due regard to proportionality, to any person who becomes aware of data and information from the ARTEMIS data exchange mechanism, and for the purposes of this Article, any reference to “API” constitutes a reference to the ARTEMIS data exchange mechanism, to data recipients, to data submitters, and any reference to “account” constitutes, for the purposes of this Article, a reference to “elements”:
It is understood that, in relation to buyers of credit facilities and managers of credit facilities, the provisions of Article 14A of the Law on the Sale of Credit Facilities and on Related Matters shall apply, and in relation to buyers of credits and managers of credits, the provisions of Article 28 of the Law on Managers of Credits and Buyers of Credits and on Related Matters shall apply.
(16) The Central Bank shall determine by directives issued under this Law the procedure for the imposition and/or revision of fees by the ARTEMIS data exchange mechanism and shall determine the amount and the method of determination thereof, as it deems appropriate.
(17) The Central Bank, before issuing directives under this Article and generally regarding the ARTEMIS data exchange mechanism in accordance with this Law, shall consult the Commissioner for the Protection of Personal Data on any matter concerning the processing of personal data and falling within its competence, based on Regulation (EU) 2016/679 and the provisions of the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data.
(18) Any processing of personal data by the ARTEMIS data exchange mechanism, data recipients, data submitters, and persons referred to in paragraph (10), under this Law and directives issued by the Central Bank under this Law, shall be carried out in compliance with the provisions of Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data.
(19) Without prejudice to the provisions of Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, the provision and/or exchange of data in accordance with the provisions of this Article and the directives issued by the Central Bank for the purposes thereof shall not constitute a breach of any obligation of confidentiality and professional secrecy provided for by this Law or any other law.
(20) Any information obtained from ARTEMIS, from data recipients, and from data submitters under this Law and directives issued by the Central Bank under this Law shall be confidential and may be used only for the purposes for which it was obtained and in compliance with the provisions of Regulation (EU) 2016/679 and the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, this Law, and the directives issued by the Central Bank under this Law.”
Amendment of the basic law by replacement of Article 28E.
“Powers of access, supervision and control of the ARTEMIS data exchange mechanism.
28E.-(1) Without prejudice to the provisions of paragraph 4 of Article 28D, the Central Bank has the competence to supervise the ARTEMIS data exchange mechanism to ensure its proper operation and proper management of the elements existing in its database.
(2) For the purposes of exercising its control, the Central Bank or any person authorized by it has the right of entry and access to all systems, elements, and functions of the ARTEMIS data exchange mechanism.
(3) Access to the data maintained in the ARTEMIS data exchange mechanism is provided by this Law to the Central Bank or to any person authorized by it.
(4) The Central Bank may require from the manager of the ARTEMIS data exchange mechanism, and in such a case the manager is obliged to provide to the Central Bank, access to files and documents and the production of reports for the purposes of the execution of the competences of the Central Bank, as well as for the purposes of fulfilling the obligations and duties of the Central Bank under any law and/or Union law.
(5) The Central Bank may require and receive under paragraph (4), among other things, information and reports on the total exposure and performance of a customer and their connected persons and statistical data for the creation of a statistical model for the calculation of the probability of default and the loss due to default.
(6) The information received by the Central Bank under this Article shall be kept confidential and used only for the purposes of this Law and the directives issued by the Central Bank for the purposes thereof:
It is understood that the Central Bank may publish statistical data received under this Article.
(7) The Central Bank has the power to require that all reasonable and cost-incurring expenses related to the exercise of its duties in the framework of the supervision and control of the ARTEMIS data exchange mechanism be paid to it.”
Amendment of the basic law by replacement of Article 28ST.
“Processing of personal data.
28ST. The processing of personal data for the purposes of this Law shall be carried out in accordance with Regulation (EU) 2016/679, the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data, and, where applicable, Regulation (EU) 2018/1725.”
Amendment of Article 29 of the basic law.
Amendment of Article 41 of the basic law.
(a) By replacing paragraph (6) with the following paragraph:
“(6) Without prejudice to the generality of paragraphs (1) and (2) and any other provision of this Law and in compliance, in any case, with any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as applicable, the Central Bank may issue general or specific directives regarding the terms, conditions, competences, obligations, and procedures for the operation of the ARTEMIS data exchange mechanism and the use of data, the calibration of the creditworthiness of customers, the use by the Central Bank of the data for the exercise of its competences arising from this Law, as well as for the purposes of fulfilling the obligations and duties of the Central Bank under any law and/or Union law, and the terms, conditions, competences, obligations, and procedures for cooperation with other corresponding database arrangements or with data recipients and/or data submitters, in any case through the ARTEMIS data exchange mechanism:
It is understood that any directive issued based on this paragraph may provide for the exchange between data recipients and/or data submitters only of those data, elements, and information that are absolutely necessary for purposes related to the assessment of the creditworthiness of customers and the management of facilities and credit and/or other related risks with the aim of ensuring financial stability in the Republic, as well as for the use by the Central Bank of this information which is deemed necessary for the exercise of its competences arising from this Law, as well as for the purposes of fulfilling the obligations and duties of the Central Bank under any law and/or Union law:
It is further understood that the Central Bank, before issuing directives, shall consult the Commissioner for the Protection of Personal Data on any matter concerning the processing of personal data and falling within its competence, based on Regulation (EU) 2016/679 and the provisions of the Law on the Protection of Natural Persons with regard to the Processing of Personal Data and on the Free Movement of such Data.”;
and
(b) by amending paragraph (7) as follows:
(i) By adding immediately after the words “of the Central Bank” (second line) the phrase “, which shall comply, in any case, with any special provisions of the laws under which the operation of data recipients and data submitters is regulated, as applicable,”;
(ii) by replacing in paragraph (a) the word “are recorded” (first line) with the word “are submitted”; and
(iii) by adding immediately after paragraph (e) the following new paragraph:
“(st) any other matter provided to be regulated by directives issued by the Central Bank in accordance with the provisions of this Law.”.
Amendment of Article 42 of the basic law.
(a) By replacing paragraph (a) with the following paragraph:
“(a) In the event that the Central Bank, in the exercise of its control and supervisory powers over the ARTEMIS data exchange mechanism, data recipients, and data submitters under this Law and/or the directives issued thereunder, including the powers and competences of the Central Bank under Articles 28D and 28E and the powers and competences for entry and investigation under Article 28E, finds that any person-
(i) violates or fails to comply with any directive issued to the ARTEMIS data exchange mechanism and/or to data recipients and/or data submitters by the Central Bank or any provision of this Law; or
(ii) violates or fails to comply within a regular deadline or, in the absence thereof, within a reasonable time period, with any legally submitted or addressed request or notification by the Central Bank; or
(iii) in complying with any such directive, request, or notification by the Central Bank or with any provision of this Law or the directives issued thereunder, provides or demonstrates any misleading, inaccurate, or incomplete data or information, which it knew or ought to have known did not correspond to reality,
the Governor of the Central Bank, having previously summoned the person who has committed a violation or non-compliance of the above, including the manager of the ARTEMIS data exchange mechanism and/or the data recipient and/or the data submitter, as applicable, has the power to impose for each violation an administrative fine from one thousand (€1,000) to eighty thousand (€80,000) euros, depending on the severity of the violation, and, in the event that the violation continues, the Governor of the Central Bank has the additional power to impose an administrative fine, depending on the severity of the violation, from one hundred (€100) to eight thousand (€8,000) euros for each day of continuation of the violation.”;
(b) by amending paragraph (b) as follows:
(i) By replacing the phrase “of the systems or data exchange mechanisms under this Law or the directives issued thereunder, including the powers and competences for entry and investigation under Article 28E, finds that any system or data exchange mechanism, due to fault or negligence or omission or with knowledge of the members of the administrative body and/or senior administrative officer and/or the Director-” (second to sixth lines), with the phrase “of data recipients, data submitters, and the ARTEMIS data exchange mechanism under this Law or the directives issued thereunder, including the powers and competences for entry and investigation under Article 28E, finds that any of the above persons, due to fault or negligence or omission or with knowledge of the members of the administrative body and/or senior administrative officer and/or the director-”; and
(ii) by deleting in sub-paragraph (i) the phrase “to banks” (second line).
Read the rest free
Source: Central Bank of Cyprus — original document · Summary generated with machine assistance and reviewed before publication; the authoritative text is the regulator's original document. How RegAlert works
More like this from CBC
We email you every new CBC publication the day it's published.