2006-03-02

Added · Updated

Rules Regulating the Work of Credit Inquiry and Rating Companies, Information Exchange, Central Bank Control, and Licensing Procedures

The Central Bank of Egypt establishes rules for credit inquiry and rating companies, requiring a minimum paid-up capital of five million Egyptian pounds and licensing for activities involving credit file creation and scoring. The document defines credit files, data providers, and users, while mandating that companies collect data from authorized sources such as banks and public registries. It imposes strict obligations on data security, confidentiality, and the retention of inquiry and complaint records for at least two years, alongside a five-year retention period for negative historical information. The regulations also outline consumer rights to access reports and dispute inaccuracies, and define the Central Bank's supervisory framework over these entities.

Central Bank of Egypt logo

Egypt

Central Bank of Egypt

Click to view thumbnail

Credit Inquiry and Rating Companies Rules for Exchanging Information and Data And the Central Bank's Control System over These Companies

Organizing Rules *

The Board of Directors of the Central Bank of Egypt approved these rules in its session held on January 17, 2006 *

The Board of Directors of the Central Bank of Egypt previously approved on August 30, 2005 the rules, procedures, and conditions for licensing credit inquiry and rating companies *

And the rules, procedures, and conditions for licensing them

Organizing Rules for Credit Inquiry and Rating Companies Rules for Exchanging Information and Data and the Central Bank's Control System over These Companies

Introduction

Credit inquiry and rating companies are Egyptian joint-stock companies whose sole purpose is to provide credit inquiry and rating services, with a paid-up capital of no less than five million pounds.

The Board of Directors of the Central Bank of Egypt licenses these companies to provide credit inquiry and rating services related to the indebtedness of bank customers, real estate financing companies, and financial leasing companies, and the indebtedness of applicants for credit facilities from suppliers of goods and services.

The Board of Directors of the Central Bank of Egypt determines by decision the rules, conditions, and procedures for licensing, the work system in these companies, and the Central Bank's control system over them. The Board of Directors of the Central Bank of Egypt also sets the rules governing the exchange of information and data with credit inquiry and rating companies.

Articles numbers 67 bis, 97, 99, 100, 101, 123, 124, and 135 of the Central Bank, Banking System, and Currency Law issued by Law No. 88 of 2003, amended by Law No. 93 of 2005, organized the legislative framework governing the licensing of credit inquiry and rating companies, the regulation of their work, the Central Bank's control system over them, and the rules for exchanging information and data between the Central Bank, banks, real estate financing companies, financial leasing companies, and credit inquiry and rating companies.

We present below the rules organizing the work of credit inquiry and rating companies, the rules for exchanging information and data, and the Central Bank's control system over these companies, which include three sections as follows:

From page 2 of 27

Section
First:Rules Organizing the Work of Credit Inquiry and Rating Companies
Second:Rules Organizing the Relationship Between the Company and Its Counterparties
-Relationship with Data Providers
-Relationship with Inquirers
-Relationship with Customers (Subjects)
-Relationship with Other Credit Inquiry and Rating Companies
Third:Rules Organizing the Company's Work
Fourth:Rules for Operating and Processing Information and Data

From page 3 of 27

Section
Second:Rules Organizing the Exchange of Information and Data
First:Contracts
Second:Provision of Information and Data
Third:Inquiry

From page 10 of 27

Section
Third:Central Bank Control System
Fourth:Procedures and Penalties Applied in Case of Violation

Article 17 - Attachments - Regulations of the Central Bank, Banking System, and Currency Law issued by Law No. 88 of 2003, amended by Law No. 93 of 2003, regarding credit inquiry and rating companies.

SubjectPage
Section Third Central Bank Control System20
Issued by decision of the Board of Directors of the Central Bank on August 30, 2005.23
  • Rules, conditions, and procedures for licensing credit inquiry and rating companies |

Section First Rules Organizing the Work of Credit Inquiry and Rating Companies

First: Definitions

The terms used in the Law and these Rules are defined as follows:

  • Credit Inquiry and Rating Company: An Egyptian joint-stock company with a paid-up capital of no less than five million pounds, licensed by the Board of Directors of the Central Bank of Egypt to conduct its activity as its nature involves forming credit files by collecting, processing, storing, and analyzing personal credit information related to the indebtedness of bank customers, real estate financing companies, financial leasing companies, and companies providing credit from suppliers of goods and services, in addition to providing other credit inquiry and rating services and issuing credit reports to inquirers without giving recommendations regarding the granting of credit.

  • Credit Images: The entities having access to personal credit information, any other information and data related to customers' repayment habits, which are provided to credit inquiry and rating companies in accordance with these Rules.

  • Subject: Natural persons (individuals) whose information and data are collected and stored in credit files at the company and are available for inquiry in accordance with these Rules.

  • Inquirer: Natural persons or legal entities who obtain credit reports and services provided by the company, in addition to customers whose information and data are concerned and who have credit files at the company, in accordance with these Rules.

  • Data Providers: Entities that provide a type of information or data.

  • Subject Data: Natural persons (individuals).

  • User: Legal entities contracted with the company that have a legitimate purpose.

It is prohibited for the company to deal with natural persons as inquirers regarding others, except for their right to inquire about their own information and data at the company in accordance with these Rules.

  • Credit File: The file contains personal and credit information and data related to customers that are collected, processed, and stored at the company, including:
    1. Data Provider: Including the name of the entity, the nature of its activity, and its address.
    2. Personal Data:
      • For natural persons: Including name, nationality, date and place of birth, identity documents, current place of residence, places of residence during the previous three years, profession and current place of work and its address, places of work during the previous three years, and the name of the spouse, in addition to any other data that serves the company's purposes.
      • For legal persons: Including name and legal form, commercial name and date thereof, address, main activity and subsidiary activities, information about the company's financial position, in addition to any other data that serves the company's purposes.
    3. Credit Data: Including the type of facility or product, currency type, due date, due installments, types of guarantees provided, in addition to any other data that serves the company's purposes.
    4. Payment Habits (Historical Data): Information reflecting customers' commitment to repay on specified dates, including:
      • Customers' failure to meet their obligations on due dates.
      • The customer's failure to meet their obligations, including delay, irregularity, returning checks and promissory notes without payment, stopping payment, default, issuance of judicial rulings, seizures, protests, and bankruptcy rulings.
      • These records must not be less than five years.
    5. Public Records Information: Information available in public records, including the Civil, Commercial, and Real Estate Registers and court records.
    6. Inquiries Made on the Credit File: Including the name and activity of the inquirer and the date of inquiry.

The credit file must not contain information or data related to political affiliation, membership in political parties and other public organizations, or those related to religious beliefs or health status.

  • Database: An electronic database containing credit files of customers, including some or all of the information and data available in the customer's credit file or a summary thereof.

  • Consent: Explicit written permission signed by the customer or their legal representative or agent, authorizing:

    • Inquiry about their personal information and data.
    • Sending their data to credit inquiry and rating companies. Consent is not required for entities subject to the provisions of Article 99 of the Law, namely banks, real estate financing companies, and financial leasing companies.
  • Credit Report: A report issued by the company in paper or electronic format.

  • Credit Scoring: The use of personal and credit information and data contained in the customer's credit file at the credit inquiry and rating company to reach a numerical evaluation of the customer according to statistical bases applied to all customers without distinction, for the purpose of determining the degree of risk associated with the customer's failure to meet future obligations.

  • Sources of Obtaining Information and Data: One or all of the following sources authorized by law or agreement to provide information and data to credit inquiry and rating companies, including:

    • Banks operating in Egypt.
    • The Central Credit Registration System at the Central Bank.
    • Entities supervising public records, namely the Civil, Commercial, and Real Estate Registers and court records.
    • Other entities having information and data that serve the company's purposes.
  • Legitimate Purpose: A legitimate purpose for inquiry and obtaining a credit report, including:

    • Reviewing or modifying terms.
    • Accepting a guarantee or any form of security.
    • Verifying the customer's regularity in meeting obligations.
    • Based on a judicial ruling or arbitral award.
    • Providing any form of credit upon the customer's request, increase, or renewal.
    • Determining the credit classification of the credit applicant or reviewing their credit position.
    • Based on consent signed by the customer or their legal representative or agent.
    • The purpose and scope of the agreement.

Second: Rules Organizing the Relationship Between the Credit Inquiry and Rating Company and Its Counterparties

The contractual relationship between the credit inquiry and rating company and data providers and inquirers, governed by the Law and the rules organizing the work of the credit inquiry and rating company, includes the following:

  • Confirmation of maintaining the confidentiality and protection of the accuracy of information and data.

The rules governing the relationship between the company and each of its counterparties are as follows:

Relationship Between the Company and Data Providers The contract concluded between them includes the company's commitment to maintain the confidentiality of information and data and use it for legitimate purposes in accordance with these Rules, and includes the data provider's commitment to the following:

  • The nature of the information and data to be collected and the categories targeted for collection.
  • Dates for sending information and data, how they are sent, and their security.
  • Rules regarding inquiry and obtaining credit reports.
  • Services provided in exchange for obtaining them and how they are paid.
  • Determination of the liability of the parties to the relationship regarding the accuracy of information and data.
  • Method of settling disputes arising from the execution or termination of the contract.

The company must:

  • Take necessary measures and precautions to secure the information and data provided to the company and verify their accuracy.
  • Obtain customer consent to send their information and data to the company.

Relationship Between the Company and Inquirers

  • The inquirer is committed to using the credit report for the purpose for which it was obtained and not for any other purpose.
  • Not to circulate the information and data contained in the credit report with third parties or enable third parties to access them, whether for consideration or without consideration.
  • Not to change or modify any clause of the credit report obtained from the company.
  • The inquirer may not assign their right to a third party or permit a third party to inquire.
  • The inquirer commits that the inquiry is made by authorized officials whom the company notifies by name.
  • The inquirer commits to maintaining the confidentiality of information and data and notifying the company of any changes in authorized inquirers or in case of terminating the work of one of them, and committing to maintaining the confidentiality of information and data.

Customer Rights

  • The customer has the right to request a copy of their credit report.
  • The customer has the right to file a complaint objecting to the inaccuracy of the information and data contained in the report.
  • The complaint must be submitted on the form prepared for this purpose by the company, accompanied by any supporting documents.
  • The company must examine the complaint, and if it concerns the accuracy of information or data, it must preserve it for fifteen days from the date of receiving the report. If no complaint is submitted during this period, the information and data in the report are considered correct and fully approved by the customer unless the contrary is proven.
  • The company must examine the complaint and, if it is found that there is an error in the operation or processing by the company or sending it to the data provider, correct the information and data within a maximum period of ten days from the date of receiving the complaint, and notify the complainant thereof.

Third: Rules Organizing the Company's Work

  • The company is committed to drafting contracts with each data provider and inquirer, specifying the nature of the relationship between them and the liability of each contracting party, on forms prepared by the company for this purpose, while keeping copies of such contracts.
  • The chairman, board members, directors, and employees of the company are prohibited from accessing information and data available at the company except to the extent necessary to perform their work as inquirers. They are also prohibited from giving or disclosing any information or data about customers, their accounts, or transactions, or enabling third parties to access them, except in cases permitted by law. This prohibition applies to everyone who receives or accesses such information and data by virtue of their profession, job, or work, directly or indirectly.
  • The company must take necessary measures to verify compliance with these rules.
  • The company must publish its telephone and fax numbers, email address, activities, working hours, services provided, procedures for obtaining them, prescribed fees, and payment methods.
  • The company must indicate the Central Bank license number and date of issuance on all its correspondence and printed materials, including credit reports issued by it, as well as on its website.
  • The company must establish a unit to handle customer requests regarding their information and data within the Arab Republic of Egypt. Employees of this unit must be knowledgeable about customer rights and qualified to deal with them.
  • The company must issue credit reports on the prescribed model, attached with a detailed explanation of its contents.
  • The company is responsible for errors resulting from the operation and processing of information and data.
  • The company must keep a database of inquiry requests for no less than two years, including data on the date of inquiry, name of the inquirer, their activity, and number of inquiries. The credit report must indicate the number of inquiries made on the customer's file in the previous year.
  • The company must keep a database of complaints received for no less than two years, including measures taken to examine complaints, examination results, and statistical reports prepared regarding their number, type, and source.
  • The company must work to provide a suitable and secure means to provide credit inquiry and rating services and make credit reports available to inquirers in the governorates of the Republic.
  • The company must include negative historical information about customers in credit reports in accordance with these Rules, for a period of five years from the date these customers are discharged by any means, including the end of judicial proceedings by deletion or assignment, issuance of a judicial ruling, or payment.
  • The company must use the information and data stored at its disposal to develop systems and credit scoring models according to recognized systems in this field.
  • The company must provide suitable technological devices and means that enable it to create and operate systems and databases.
  • The company must take necessary measures to verify that the information and data it obtained are from reliable sources.
  • The company must take necessary measures to secure and protect information and data and maintain their confidentiality, including:
    • Appointing a Compliance Officer to monitor the company's compliance with the rules and procedures of work issued by the Board of Directors of the Central Bank regarding the work system, information exchange rules, and control system.
    • Establishing a physical security system for the information systems site.
    • Establishing an alternative emergency center for the company at a suitable distance from its main center to face potential disasters.
    • Adopting regular backup systems and plans for retrieving information and data in emergencies to ensure they are not exposed to loss or damage.
    • Establishing an emergency center to face hacking operations.
    • Setting policies and rules for company employees to authorize them to access and use databases and review these rules at regular periodic intervals.
    • Notifying the Central Bank of any hacking of its systems and what measures the company has taken to limit operational risks and the legal risks resulting therefrom.
    • Holding periodic meetings with groups of data providers and inquirers to introduce them to the company's activities and best practices in providing information and data and obtaining credit reports and any other services provided by the company.
    • Providing secure communication means to exchange information and data with providers and inquirers.
    • Providing a protection and security system for accessing the company's systems and databases, with a plan for identification/authentication and user passwords.
    • Contracts concluded with company employees must include a commitment to maintain the confidentiality of information and data.
    • Setting operational controls for employee access rights and database usage.

Fourth: Rules for Operating and Processing Data

  • The company must collect, match, and register the information and data provided by its providers.
  • The company must ensure the accuracy of information and data in case of violations regarding the provision of services to others or the health sector.

[RegAlert note: the English text above is a translation of the first 24,000 characters of a 100,504-character original (24% of the document). The remainder was not translated. The complete original-language text is stored with this document.]