Code Of Conduct
Member’s Obligations In Respect Of Information Obtained From Bureau
5.1 Each Member shall ensure that it does not make an enquiry requesting for a Credit Report from the Bureau unless such enquiry is made for a Relevant Purpose, in compliance with the Reciprocity Guidelines and in respect of a natural person who is –
5.1.1 a Customer of (or has applied for credit facilities from) such Member; or
5.1.2 a surety of a Customer of (or a surety of a party who has applied for credit facilities from) such Member, regardless of whether such Customer or party be a natural person, an unincorporated entity, a corporate entity or any other entity.
5.2 Each Member shall ensure that it retains adequate evidence to establish the existence of a Relevant Purpose in respect of each enquiry for a period of not less than seven (7) years from the date of the relevant enquiry (and it shall be adequate if the Member can establish in the case of automated operations that the relevant computer programme(s) required the relevant Individual to indicate that he or she was a Customer or surety or was applying for credit facilities before an enquiry was requested from the Bureau) and each Member shall ensure that all necessary precautions are taken to ensure that all Information provided to it by the Bureau is:
5.2.1 properly and accurately recorded and maintained;
5.2.2 protected against loss; and
5.2.3 protected against unauthorised access, use, modification or disclosure.
5.3 Each Member shall ensure that it:
5.3.1 shall only use Customer Information obtained from the Bureau for a Relevant Purpose and/or such other purposes as permitted by applicable law; and
5.3.2 discloses no Customer Information provided to it by the Bureau to any person or entity except that it may make such disclosure of the same as is authorised by the Act or applicable law or required in accordance with law.
5.4 Without prejudice to the generality of Clauses 5.1, 5.2 and 5.3, each Member shall take measures, including the following, to safeguard the security of Information provided to it by the Bureau:
5.4.1 establishment of controls and procedures to be applied when access is sought to Credit Reports to ensure that there are no unauthorized requests for Credit Reports;
5.4.2 maintenance of logs of all accesses, amendments and audit trails to the database of Information supplied by it to the Bureau and/or provided to it by the Bureau (including logs of all incidents involving proven or suspected breach(es) of security which contain particulars of the records affected and explanation(s) of the circumstance(s) and action(s) taken);
5.4.3 review, on a regular basis, of password and other controls over all personnel (whether or not employed by the Member) authorised to access the database of Information provided to it by the Bureau so as to prevent unauthorised access to the same;
5.4.4 review, on a regular basis, of patterns of usage of the applicable information systems, with a view to detecting and investigating any unusual or irregular patterns of access or use so as to deter unauthorized use of Information;
5.4.5 attendance by relevant personel (whether or not employed by the Member) at workshops organised by the Bureau relating to the Code and, in particular, good security practice for attendance by authorised representatives of Members;
5.4.6 development of operational guidelines and disciplinary and contractual procedures and penalties to be applied in relation to improper use of access authorities and/or improper use of Information by its personnel, authorised agents and/or persons authorised by the Member; and
5.4.7 development of operational guidelines to ensure adequate protection to minimise the risk of unauthorised entry into the database of Information provided to it by the Bureau or interception of communications made to and from such database.