Opinion of the European Central Bank of 25 August 2022 on the establishment and operation of a Central Credit Register (CON/2022/28)
OPINION OF THE EUROPEAN CENTRAL BANK of 25 August 2022 on the establishment and operation of a Central Credit Register (CON/2022/28) Introduction and legal basis
On 29 July 2022 the European Central Bank (ECB) received a request from the Greek Ministry of Finance for an opinion on a draft law on the establishment and operation of a central credit register (hereinafter the ‘draft law’). The ECB’s competence to deliver an opinion is based on Articles 127(4) and 282(5) of the Treaty on the Functioning of the European Union and the third, fourth and sixth indents of Article 2(1) of Council Decision 98/415/EC , as the draft law relates to the Bank of Greece, the collection, compilation and distribution of monetary, financial, banking, payment systems and balance of payments statistics, and to rules applicable to financial institutions insofar as they materially influence the stability of financial institutions and markets. In accordance with the first sentence of Article 17.5 of the Rules of Procedure of the European Central Bank, the Governing Council has adopted this opinion.
1. Purpose of the draft law
1.1 The draft law establishes a central credit register (hereinafter the ‘Register’) as a national personal data filing system as defined in Article 4, point (6), of Regulation (EU) 2016/679 (hereinafter the ‘GDPR’). The Register will operate as an electronic database, be established, maintained and operated by the Bank of Greece, and record, at a granular level, inter alia, the payment history, type of collateral provided and any other information relating to any form of credit granted to natural and legal persons including guarantors (hereinafter ‘data subjects’) by credit and financial institutions that have their registered office in Greece and by branches of foreign credit and financial institutions operating in Greece. The exact scope of credit covered by the draft law, namely the relevant credit thresholds and the relevant creditors to be covered , will be specified in an act of the Governor of the Bank of Greece.
The Register will allow, among others: (a) the collection and extraction of (positive and negative) financial history data on natural and legal persons by creditors which hold and manage such data; (b) the production and provision of credit reports on data subjects; (c) the retention and processing of financial history data, in keeping with the applicable institutional framework for the protection of personal data and information security; (d) the provision of a single contact point from which data subjects can obtain credit reports; and (e) the provision of a single contact point to which data subjects can apply to have financial history data that is collected by third-party agencies updated or rectified, or generally to exercise their rights under the GDPR. 1.2 Objectives of the draft law The primary aim of establishing and operating the Register is to enhance the financing of the real economy by the Greek financial system and to safeguard financial stability by improving the quality of available information and thereby enabling a more rational assessment of the creditworthiness of potential borrowers and generally contributing to more informed decision-making in relation to credit granting . According to the explanatory note accompanying the proposal on the establishment of the Register submitted by Greece to the European Commission to obtain funding from the Recovery and Resilience Facility , the Register is also expected to increase available information regarding the credit history of potential debtors, have a positive impact on the quantity and quality of investment spending, encourage competition among financial institutions, result in a lower cost of capital for Greek borrowers, and greatly increase the ability of investors to price risk in the secondary market for non-performing loans (NPLs). This will increase NPL valuations, boost recovery rates and, thereby, help banks to resolve legacy NPL challenges faster and more efficiently in terms of use of capital. The explanatory note also states that the Register, since it is maintained and operated by the Bank of Greece, supports the Bank’s obligations and functions in supervising the financial sector and ensuring financial stability. 1.3 Information to be recorded with the Register The Bank of Greece may hold the following in the Register: (a) identification information and general information on the data subject; (b) financial history data relating to any credit application or credit agreement entered into by the data subject (including in its capacity as guarantor); (c) information linking data subjects that are parties to the same credit agreement or have provided a guarantee in connection
with the same credit agreement; and (d) any credit commentary or other analysis produced by the Bank of Greece in connection with a data subject. The credit information that the Bank of Greece may hold in the Register may be used for the production of general reports, analyses and statistics produced by the Bank of Greece and held in a form that prevents identification of the data subject. 1.4 Credit report Based on the aforementioned information and data recorded therewith, the Register will also produce, upon application, a credit report for all credit receivers. The exact contents of the report will be determined by an act of the Governor of the Bank of Greece and will vary depending on the recipient of the report and the purpose for which the report was requested. These purposes are listed in the draft law: (a) to verify information provided by the data subject in connection with a credit application to a creditor; (b) to assess the risks incurred by the creditor in granting credit to the data subject or accepting the data subject’s guarantee for the credit agreement; (c) to assess the risks attached to credit granted to the data subject or a change to the nature or term of the respective credit agreement or guarantee; (d) to monitor and assess failure to comply with the terms of a credit agreement relating to credit granted by the creditor to a data subject or to a guarantee provided by that data subject; (e) to evaluate a data subject’s application to a creditor for a debt payment plan; and (f) to analyse portfolios of credit agreements held by financial institutions. The report may not, however, assign a credit rating or a creditworthiness score for the credit receiver. 1.5 Role of the Bank of Greece The draft law requires the Bank of Greece to establish, maintain and operate the Register. The Bank of Greece is also responsible for its technical design and the implementation of its filing system, collecting and organising personal and other data from all sources, keeping them in a way that safeguards data integrity, confidentiality and availability, complying with data protection legislation and, in general, ensuring the seamless operation of the Register. The Bank of Greece is also appointed as the ‘controller’ within the meaning of the GDPR and Law No 4613/2019 , both of which apply to the processing of data by the Bank of Greece and third parties that receive the credit report produced by the Register. The Bank of Greece must also inform data subjects that their data have been shared with the Register, as required by the GDPR. 1.6 Information and data provided to the Register Where the relevant credit falls within the scope of the draft law, creditors must provide financial history data to the Register by giving the Register access to, and allow the electronic transmission from, their electronic systems covering a period of at least the past 12 months. The draft law requires creditors to transmit data (and update already provided data) on a monthly basis and to connect online to the Register within 12 months of the adoption of the act of the Governor of the Bank of Greece (see paragraph 1.9 below). The Bank of Greece may request creditors to provide additional data that may be used for financial analyses and the compilation of statistics produced by the Bank. The draft law defines ‘financial history data’ as all information on debts (whether due, repaid or outstanding) of natural and legal persons, including in particular: data identifying the debt; the type of debt and its basic terms; the real and contractual collateral for the debt; the payments made, the time of payment and the outstanding balance of the debt; debt payment plans; changes to the identity of the debtor; information on
any litigation between the debtor and creditors, on any administrative or enforcement measures taken, on any criminal proceedings for default where default is a criminal offence, as further specified in the draft law; and whether the data subject is unemployed or bankrupt or has been discharged and the debt has been written off. 1.7 Persons entitled to access the data held in the Register, and related purposes Under the draft law, the data held in the Register will only be accessible upon request to: the data subject, whose access will be restricted exclusively to data relating to them personally; any creditor to which credit is owed or to which an application for credit has been submitted and which has connected to the Register; the Personal Data Protection Authority for the purposes of verifying compliance with data protection legislation; and judicial and prosecutorial authorities for the purposes of dispensing justice and, in particular, preventing and combating money laundering and terrorism financing. Creditors may only use data to which the Register provides access for the sole purpose of managing credit risk and improving the quality of the credit information at their disposal on data subjects. Creditors which further process data received from the Register must be acting as ‘controllers’ within the meaning of the GDPR; and, for the purposes of the transmission of data to the Register, they must be regarded as processors and must conclude a contract for that purpose with the Bank of Greece in accordance with Article 28 of the GDPR. A similar contract must also be concluded between the Bank of Greece and Teiresias S.A., a privately owned and operated credit bureau that also processes and stores financial history data. Data subjects whose data are filed with the Register, have the rights provided for in the GDPR and may also challenge said data and the credit report produced by the Register on the basis of the said data, and request the Bank of Greece to correct inaccurate data. 1.8 Interoperability of the Register with other databases The draft law provides that the Register must complement and be fully harmonised and interoperable with the Public Debt Office, the Independent Credit Rating Authority, the Private Debt Monitoring Register (all of which will be established under separate legislation) and the existing system of Teiresias S.A.. For the purpose of cross-checking and corroborating identification information and general information held therein , the Register may have recourse to the IT systems of the Independent Authority for Public Revenue and of the General Commercial Registry, ERGANI and of any other public sector entity. In addition, the Register must also interoperate with GR-AnaCredit, the analytical credit dataset operated by the Bank of Greece in accordance with Regulation (EU) 2016/867 of the European Central Bank (ECB/2016/13) and Act 2677/19.05.2017 of the Governor of the Bank of Greece, which is used to collect information on loans granted by credit institutions to legal persons. In order to achieve its purposes, the Register may collaborate with similar central credit registries abroad. Furthermore, in order to be able to provide information in the context of producing financial analyses or statistical reports based on the data it holds, the Register must also interoperate and exchange information
(while preventing the identification of the data subject) with the databases and electronic systems of the public or the private sector or of credit rating agencies. 1.9 Secondary legislation to be adopted by the Bank of Greece The draft law authorises the Bank of Greece to adopt secondary legislation, in the form of an act of the Governor of the Bank of Greece, determining several aspects of the draft law, including the following: (a) credit thresholds falling within the scope of the draft law; (b) when and how often the Register accesses and extracts financial history data held by creditors; (c) the technical details and operating specifications of the Register and the method used to interconnect it with the agencies referred to in the draft law; (d) what an application for credit reports should contain, how it will be submitted to the Register and how data subjects may exercise their rights; (e) how the Register will process data; (f) for how long the Register is required to retain data, depending on the category of data and on whether or not the relevant debt has been repaid; (g) what credit reports will contain, depending on their recipient; (h) any other details conducive to or necessary for the operation of the Register. Moreover, the draft law authorises the Bank of Greece to adopt an operations regulation for the Register, detailing how creditors and data subjects interconnect and communicate with the Register, how information and data will be recorded to ensure that they are mapped and transmitted in an appropriate manner, the format in which information and details must be provided, and any other matter relating to the operational management of the Register.
2. General observations
2.1 The ECB notes that several important aspects of the Register are expected to be determined by means of secondary legislation to be adopted by the Bank of Greece. In that respect, the ECB should be consulted on such legislation before it is adopted. 2.2 The ECB in principle welcomes the establishment of the Register, insofar as it is envisaged to contribute to a comprehensive and efficient centralisation of granular credit data, which in turn should contribute to improving existing and developing new ESCB statistics since it provides important breakdowns and details not available from currently used data sources, such as information on the structure and risk patterns of credit granted by the financial sector. In addition, the Register should enable more informed assessments of credit risk by credit and financial institutions (both in terms of the initial decision to grant credit and in terms of ongoing assessments of existing exposures) and should therefore enhance the risk management capabilities of these institutions. In this sense, the data held in the Register are considered to constitute a useful tool for micro- and macroprudential supervision. The data to be held in on the Register, and access thereto, are also considered to be useful from a financial stability and macroprudential supervision perspective, as it would allow the monitoring and assessment of the build-up of and appetite for credit risk in the banking and financial system more generally, thereby helping to calibrate the use of macroprudential instruments. 2.3 However, the draft law does not contain any provision explicitly allowing the Bank of Greece, the ECB, or the European System of Central Banks (ESCB) to access data held in the Register. 2.4 Regarding microprudential supervision, the ECB understands that, subject to data protection requirements, the ECB may, in the exercise of its supervisory duties that relate to credit institutions,
require the Bank of Greece, as ‘national competent authority’ within the meaning of Article 2(2) of 10 11 Council Regulation (EU) No 1024/2013 , to request and pass on information held in the Register . This point is also relevant in the context of the macroprudential tasks conferred on the ECB under Council Regulation (EU) No 1024/2013 , which requires the ECB to take into account the specific situation of the financial system, economic situation and the economic cycle in the individual Member States or parts thereof . However, in view of the exhaustive list of persons granted access to the information held in the Register according to Article 6 of the draft law, any such access would be limited and granted on a case-by-case basis. Given the scope and the significance that the data to be held on the Register has for micro- and macroprudential supervision purposes and, therefore, for the tasks concerning policies relating to the prudential supervision of credit institutions and other financial institutions with the exception of insurance undertakings conferred on the ECB pursuant to Article 127(6) of the Treaty, the ECB would welcome the explicit inclusion of these purposes in the aims of the draft law and a provision in the draft law explicitly giving the Bank of Greece and the ECB access to the Register. 2.5 The consulting authority could also consider wider access rights to the Register, for example by other bodies and agencies of the Union that play a role in banking supervision, such as the European Systemic Risk Board, the European Banking Authority and other relevant bodies established at Union level, such as the European Stability Mechanism and the European Single Resolution Mechanism, as has been done by other Member States , and provided that the purposes for which the data can be shared with each specific body are clearly stipulated in the draft law and that the confidentiality of the said data is ensured. In that respect, the ECB notes that the draft law already provides that the Register may collaborate with similar central credit registries abroad in order to achieve its purposes. The ECB therefore notes that facilitating supervisory purposes could be usefully listed among the objectives of the Register, so that such wider access may be permitted. 2.6 Regarding the access of the ECB and the Bank of Greece to the data held in the Register for statistical and monetary policy (as distinct from supervisory) purposes, without an explicit legal basis in the draft law, such access would either be limited or completely impossible. Although the draft law does not explicitly list among the objectives of the Register that it would contribute to the tasks of the ESCB as laid down in Article 127 of the Treaty, the ECB considers that accessing the Register would be beneficial for, and materially support, the exercise of these tasks. Consideration should therefore be given to adding the contribution to the tasks of the ESCB to the objectives that the Register is
intended to serve and to further amending the draft law to explicitly include these purposes in the aims of the draft law and to ensure a clear legal basis establishing the said access rights, as has been done in other Member States , and taking into account the provisions of Council Regulation (EC) No 2533/98 . The ECB understands that such an explicit authorisation is necessary from a national law perspective to ensure that the Bank of Greece has a robust legal basis for disclosing data held in the Register to the ECB for the purposes of discharging its obligations under Regulation (EU) 2016/867 (ECB/2016/13) . Such a legal basis is required because the draft law prohibits the disclosure of information held in the Register unless such disclosure is explicitly provided for. This provision is without prejudice to the requirements of Article 10 of Regulation (EU) 2016/867 (ECB/2016/13), which regulates the use of credit data reported under that Regulation by the ECB and national central banks (NCBs). 2.7 In considering whether to grant access to the ECB and the Bank of Greece, as noted in paragraph 2.6 above, regard should be had to reducing and simplifying the reporting obligations of credit and financial institutions and avoiding the duplication of reporting requirements for credit-related data in line with the recitals of Regulation (EU) 2016/867 (ECB/2016/13), the recitals of which note that, with a view to ensuring efficient reporting and adequate interoperability with other existing or new reporting frameworks, NCBs should be allowed to collect the information to be transmitted to the ECB as a part of a broader national reporting framework and to extend the reporting of credit data beyond the scope outlined in Regulation (EU) 2016/867 (ECB/2016/13), for their own statutory purposes, in line with relevant national law . It is all the more important to avoid reporting redundancies given that the Register will, according to the draft law, ‘interoperate’ or ‘cooperate’, or ‘have recourse to’, several other public and private sector databases, some of which have not yet been established. 2.8 In considering whether to grant access to the ECB and the Bank of Greece as noted in paragraph 2.6 above, regard should be had to full compliance of the national framework with the objectives and requirements of Regulation (EU) 2016/867 (ECB/2016/13), including with legal requirements concerning feedback loops since further provisions on the scope and implementation of feedback loops by the NCBs may be laid down in separate legal acts to be adopted by the ECB, and NCBs may enter into Memoranda of Understanding regarding their respective cooperation in the feedback loops based on the applicable legal frameworks . 2.9 The recitals of Regulation (EU) 2016/867 (ECB/2016/13) also note that the framework for the collection of credit data under that Regulation should be set up with a view to ensuring interoperability
with central credit registers and other relevant credit data sets established by public sector entities, including databases on securities statistics as well as the ESCB Register of Institutions and Affiliates Dataset . The ECB understands that the Register will interoperate with GR-AnaCredit. In that respect and for reasons of legal certainty, it is suggested that the draft law or the secondary legislation to be adopted thereunder could more clearly incorporate the reporting obligations that have direct effect by reason of Regulation (EU) 2016/867 (ECB/2016/13) with the additional obligations imposed by the draft law on reporting agents that are covered by both frameworks. This would ensure full compliance of the draft law with the provisions of Regulation (EU) 2016/867 (ECB/2016/13). 2.10 The draft law does not contain any explicit provisions regarding sanctions to be imposed in cases of non-compliance of reporting agents with reporting obligations established in the draft law. The ECB understands that this may be one of the points regarding the Register that will be addressed in the secondary legislation that the Bank of Greece is authorised to adopt under the draft law. In that respect, the ECB wishes to draw the attention of the consulting authority to the sanctioning regime that applies in respect of a failure by reporting agents to comply with the ECB’s statistical reporting requirements, and which is referred to in Regulation (EU) 2016/867 (ECB/2016/13) , and to note that: (a) the sanctioning regime to be established for the Bank of Greece under national law should operate without prejudice to the ECB’s sanctioning regime under Union law; and (b) national law should ensure the compliance of both the ECB and the Bank of Greece with the non bis in idem principle, which is reflected in Article 2(1) of Regulation (EC) No 2157/1999 of the European Central Bank (ECB/1999/4) and whereby no legal action may be instituted twice in respect of the same cause of action. National law should therefore facilitate the provision of information and consultations between the ECB and the Bank of Greece before any decision to initiate an infringement procedure is taken by either . 2.11 Lastly, the ECB notes that the draft law does not explicitly state that the Register will be owned by the Bank of Greece. However, the ECB understands that the Bank of Greece will be the exclusive owner of the Register and would therefore welcome, for the sake of legal clarity, the inclusion of a provision in the draft law explicitly stating that the Bank of Greece is not only the sole operator but also the exclusive owner of the Register.
3. Conferral of a new task on the Bank of Greece
3.1 The draft law confers on the Bank of Greece the new task of establishing and operating a credit register as a centralised collection of granular credit and credit risk data. 3.2 The ECB underlines that a proposed conferral of new tasks on a national central bank (NCB) in the ESCB must be assessed against the prohibition on monetary financing laid down in Article 123(1) of the
Treaty. For the purposes of that prohibition, Article 1(1)(b)(ii) of Council Regulation (EC) No 3603/93 defines ‘other type of credit facility’, inter alia, as ‘any financing of the public sector’s obligations vis-à-vis third parties’. 3.3 Ensuring that Member States implement a sound budgetary policy is one of the key objectives of the monetary financing prohibition, which may not be circumvented . Therefore, the task of financing measures, which are normally the responsibility of the Member States, and which are financed from their budgetary sources rather than by the NCBs, must not be entrusted to NCBs. To decide what constitutes financing of the public sector’s obligations vis-à-vis third parties, which can be translated as the provision of central bank financing outside the scope of central bank tasks, it is necessary to carry out, on a case-bycase basis, an assessment of whether the task to be undertaken by an NCB is a central bank task or a government task, i.e. a task within the responsibilities of the Member States. 3.4 As part of its discretion in the exercise of its duty, on the basis of Article 271(d) of the Treaty and Article 35.6 of the Statute of the ESCB and of the European Central Bank (hereinafter the ‘Statute of the ESCB’), to ensure that NCBs honour the obligations laid down by the Treaty, the Governing Council has endorsed criteria for determining what may be seen as falling within the scope of a public sector obligation within the meaning of Article 1(1)(b)(ii) of Regulation (EC) No 3603/93 or, in other words, what constitutes a government task as follows: First, central bank tasks are in particular those tasks that are related to the tasks that have been conferred on the ECB and the NCBs by the Treaty and the Statute of the ESCB. These tasks are mainly defined in Article 127(2), (5) and (6) and Article 128(1) of the Treaty, as well as Article 22 and Article 25.1 of the Statute of the ESCB. Second, as Article 14.4 of the Statute of the ESCB allows NCBs to perform ‘other functions’, new tasks, i.e. tasks that are not related to tasks that have been conferred on the ECB and the NCBs, are not precluded per se. However, new tasks that are undertaken by an NCB and which are atypical of NCB tasks or which are clearly discharged on behalf of, and in the exclusive interest of the government or of other public sector entities should be considered government tasks. Third, an important criterion for qualifying a new task as atypical of an NCB task or as being clearly discharged on behalf of and in the exclusive interest of the government or other public sector entities is the impact of the task on the institutional, financial and personal independence of that NCB. In particular, the following aspects should be taken into account: (a) whether the performance of the new task creates conflicts of interest with existing central bank tasks, which are not adequately addressed, and does not necessarily complement those existing central bank tasks. If a conflict of interest arises between existing and new tasks, sufficient safeguards to mitigate that conflict should be in place. The complementarity between a new task and existing central bank tasks should not be interpreted broadly, so as to lead to the creation of an indefinite chain of ancillary tasks. Such complementarity should be examined in relation to the financing of those tasks;
(b) whether without new financial resources the performance of the new task is disproportionate to the NCB’s financial or organisational capacity, and may have a negative impact on the capacity to properly perform the existing central bank tasks; (c) whether the performance of the new task fits into the institutional set-up of the NCB in the light of central bank independence and accountability considerations; (d) whether the performance of the new task harbours substantial financial risks; (e) whether the performance of the new task exposes the members of the NCB decision-making bodies to political risks that are disproportionate and may also have an impact on their personal independence and, in particular, on the guarantee of term of office set out in Article 14.2 of the Statute of the ESCB. 3.5 Based on the criteria set out above, the following paragraphs assess whether the new task proposed to be conferred on the Bank of Greece under the draft law is in line with the prohibition of monetary financing. 3.6 Tasks related to the tasks conferred on the ECB and the NCBs by the Treaty and the Statute of the
ESCB
Generally, it is noted that granular credit and credit risk data based on central credit registers are necessary for the development and production of new ESCB statistics, as well as to improve the quality of ESCB statistics. These new or improved statistics are, in turn, necessary for the performance of ESCB tasks. To assess whether the establishment and operation of a register holding such credit data is an ESCBrelated task, it is necessary to examine whether the purpose of that register is ESCB-related, i.e. whether the credit data are collected and analysed in order to support the performance of an ESCB-related task. Such an assessment needs to consider the legislator’s intention, as manifested in the provisions regarding the aims of the credit register as well as the access to and specific set-up of the register. While some provisions of the draft law seem to imply that the credit data held in the Register may be used by the Bank of Greece for statistical purposes , such purposes are not included in the wording of the draft law’s explicit provision on its primary aim and are not reflected in the rules governing access to the Register (see paragraphs 2.4 to 2.6 above). However, the draft law explicitly lists ‘safeguarding financial stability’ as one of the primary aims of the Register . Bank of Greece’s new task of establishing and operating the Register can thus be considered a task related to the ESCB’s contribution to the stability of the financial system under Article 127(5) of the Treaty. 3.7 Tasks which are atypical of central bank tasks Safeguarding financial stability is a task that is not atypical of a central bank. Moreover, the Bank of Greece already has a financial stability mandate . Consequently, the task of establishing and operating the
Register with the explicit primary aim of safeguarding financial stability is not an atypical task for the Bank of Greece. It is also noted that a number of Member States have established central credit registers and conferred the tasks involved in operating them upon NCBs, albeit for different purposes . Also, all Eurosystem NCBs are required to operate national granular credit datasets under Regulation (EU) 2016/867 (ECB/2016/13). 3.8 Tasks clearly discharged on behalf of and in the exclusive interest of the government The Bank of Greece is designated by the draft law as the sole operator of the Register . There is no indication that, in carrying out its task, the Bank of Greece would act exclusively in the interest of the government or another public entity. 3.9 Extent to which performance of the new task creates conflicts of interest with existing central bank
tasks
The performance of the new task of establishing and operating the Register is unlikely to give rise to any conflicts of interest in connection with the Bank of Greece’s existing central bank tasks. 3.10 Extent to which performance of the new task is disproportionate to the financial or organisational
capacity of the Bank of Greece
As previously noted by the ECB , Member States must not put their NCBs in a position where they have insufficient resources to carry out both their ESCB-related tasks and their national tasks, from an operational and financial perspective. In order to ensure that the Bank of Greece’s capacity to perform its ESCB-related tasks is not impaired, the Bank of Greece must, therefore, be able to avail itself of the necessary resources to carry out its responsibilities under the draft law. The draft law does not cover the costs/funding of the Bank of Greece’s new task and currently provides that access to financial history data shall be granted free of charge . However, the ECB understands that on condition that the draft provision is revised, the secondary legislation that the Bank of Greece is authorised to adopt under the draft law may contain provisions regarding such funding, e.g. in the form of fees to be levied on the reporting agents under the draft law which the secondary legislation will ultimately determine. The ECB also understands that the Bank of Greece has already taken the necessary measures to ensure that sufficient resources are available for establishing and operating the Register. 3.11 Extent to which performance of the new tasks fits into the institutional set-up of the Bank of Greece, in the light of central bank independence and accountability considerations Given the Bank of Greece’s existing financial stability mandate, the performance of the new tasks appears to fit into the Bank of Greece’s current institutional set-up. 3.12 Extent to which the performance of tasks harbours substantial financial risks The draft law does not contain any specific provisions on liability for the operation of the Register. Under the draft law the Bank of Greece will assume liability for processing personal data, under both the GDPR and national law. The Bank of Greece may also incur potential contractual or non-contractual liability vis-à-
vis the reporting agents or data subjects, stemming from the establishment of the Register, under national law. This potential liability does not appear to be disproportionate to the new tasks conferred on the Bank of Greece. 3.13 Extent to which the performance of the new task exposes members of the decision-making bodies of the Bank of Greece to disproportionate political risks and impacts on their personal independence The performance of the new task conferred under the draft law does not appear to expose the Bank of Greece’s decision-making bodies to any disproportionate political risk or have an impact on their personal independence. 3.14 Conclusion The ECB considers that the Bank of Greece’s new tasks relating to the Register qualify as central banking tasks and are therefore in line with the prohibition on monetary financing.
This opinion will be published on EUR-Lex.
Done at Frankfurt am Main, 25 August 2022.
[signed]
The President of the ECB
Christine LAGARDE
Fotnoter
- 1 Council Decision 98/415/EC of 29 June 1998 on the consultation of the European Central Bank by national authorities regarding draft legislative provisions (OJ L 189, 3.7.1998, p. 42). 2 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (OJ L 119 4.5.2016, p. 1). 3 The draft law defines ‘creditors’ as the legal persons to which data subjects owe credit that falls within the scope of the draft law but other than: entities listed as public sector agencies in article 51 of Law 1892/1990 (Government Gazette issue Α 101/1990, p. 101); local and regional municipal authorities and their enterprises/corporations; and utility undertakings to the extent that the Greek State holds, directly or indirectly, part of the share capital.
- The draft law contains a non-exhaustive/indicative list of creditors, that includes: i) credit institutions within the meaning of Article 3(1)(1) of Law 4261/2014 and Article 4(1) of Regulation (EU) No 575/2013 established in Greece; ii) branches in Greece of credit institutions established abroad; iii) credit institutions established in the EEA which trade in Greece pursuant to Article 39 of Law 4261/2014; iv) corporate credit providers within the meaning of Article 153(4) of Law 4261/2014; v) factoring companies within the meaning of Article 4(2) of Law 1905/1990 (Government Gazette A147/1990); vi) leasing companies within the meaning of Article 2(1)(a) of Law 1665/1986 (Government Gazette A 194/1986); vii) branches in Greece of financial institutions within the meaning of Article 3(1)(22) of Law 4261/2014 established abroad; viii) loan and credit debt management companies within the meaning of Article 1(1)(a)(aa) of Law 4354/2015 and branches within the meaning of Article 1(1)(a)(bb) of Law 4354/2015; ix) credit agencies within the meaning of Article 3(2) of Law 4438/2016; x) microfinance institutions within the meaning of Article 2(b) of Law 4701/2020; xi) payment institutions within the meaning of Article 4(4)(f) of Law 4537/2018, inasmuch as they provide credit; xii) e-money institutions within the meaning of Article 10(3) of Law 4021/2011, inasmuch as they provide credit; xiii) card issuing and management companies; and xiv) other financial institutions within the meaning of Article 4(1)(26) of Regulation (EU) No 575/2013. 4 See Article 1(3) of the draft law. 5 Available here: https://greece20.gov.gr/en/the-complete-plan/. 6 The Recovery and Resilience Facility was established by Regulation (EU) 2021/241 of the European Parliament and of the Council of 12 February 2021 (OJ L 57, 18.2.2021, p. 17–75).
- 7 Government Gazette A 78/2019.
- 8 ‘Identification information’ and ‘general information’ are defined in Article 2 of the draft law. 9 Regulation (EU) 2016/867 of the European Central Bank of 18 May 2016 on the collection of granular credit and credit risk data (ECB/2016/13) (OJ L 144, 1.6.2016, p. 44).
- 10 Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63). 11 This understanding is based on Article 6(2) of Council Regulation (EU) No 1024/2013 of 15 October 2013 conferring specific tasks on the European Central Bank concerning policies relating to the prudential supervision of credit institutions (OJ L 287, 29.10.2013, p. 63) and Article 21 of Regulation (EU) No 468/2014 of 16 April 2014 of the European Central Bank establishing the framework for cooperation within the Single Supervisory Mechanism between the European Central Bank and national competent authorities and with national designated authorities (SSM Framework Regulation) (ECB/2014/17) (OJ L 141, 14.05.2014, p. 1). This understanding is also based on Article 55C of the Statute of the Bank of Greece but in that case, the Bank of Greece would only be able to share the information it has received on an aggregated basis. Prudential supervisionrelated information can also be shared with the ECB on the basis of Article 54 of Law No 4261/2014 (Government Gazette A 107/2014). 12 Article 5 of Council Regulation (EU) No 1024/2013. 13 See paragraph 3.2 of Opinion CON/2015/20. 14 See paragraph 2.2 of Opinion CON/2013/93.
- 15 See, e.g., paragraph 1.3 of Opinion CON/2021/24; paragraph 2.1 of Opinion CON/2013/93; paragraph 2.2 of Opinion CON/2014/57. 16 Council Regulation No (EC) 2533/98 of 23 November 1998 concerning the collection of statistical information by the European Central Bank (OJ L 318, 27.11.1998, p. 8). For example, article 8(1) Article 8(1) of Regulation (EC) No 2533/98 allows for the use of confidential statistical information by the ESCB “exclusively for the exercise of the tasks of the ESCB”, except in a number of defined circumstances. Moreover, paragraphs 4, 4a and 5 of Article 8 of the same regulation allow for the transmission of confidential statistical information within and outside the ESCB, subject to the fulfilment of a number of requirements and conditions. These latter provisions are particularly important when it comes to information collected by other NCBs in accordance with the AnaCredit Regulation (EU) 2016/867 to which the Bank of Greece may have access. 17 See also paragraph 2.3 of Opinion CON/2017/13. 18 See recital 15 of Regulation (EU) 2016/867 and paragraph 2.1 of Opinion CON/2017/33. 19 See recital 17 of Regulation (EU) 2016/867 (ECB/2016/13).
- 20 See recital 16 of Regulation (EU) 2016/867 (ECB/2016/13). 21 Article 18 of Regulation (EU) 2016/867. 22 Regulation (EC) No 2157/1999 of 23 September 1999 on the powers of the European Central Bank to impose sanctions (ECB/1999/4) (OJ L 264, 12.10.1999, p. 21). 23 See paragraph 3.5 of Opinion CON/2021/24.
- 24 Council Regulation (EC) No 3603/93 of 13 December 1993 specifying definitions for the application of the prohibitions referred to in Articles 104 and 104b(1) of the Treaty (OJ L 332, 31.12.1993, p. 1). 25 Article 123 of the Treaty also serves the objective of maintaining price stability and reinforces central bank independence.
- 26 For the relevance of the purpose in determining ESCB-related tasks, see paragraph 2.4.1 of CON/2021/29, paragraph 3.3.4.1 of CON/2016/54, and paragraph 3.2 of CON/2016/45. Regarding the purpose of a specific credit register, see CON/2013/29. Also compare Article 5.1 Statute of the ESCB: ‘In order to undertake the tasks of the ESCB, the ECB, assisted by the national central banks, shall collect the necessary statistical information ...’ 27 Article 3(5) of the draft law stipulates that credit information which the Bank of Greece may hold in the Register also encompasses analyses and statistics produced by the Bank; Article 4(3) of the draft law allows the Bank of Greece to request additional data from creditors so that they can be processed for the purpose of preparing financial analyses and statistical reports. 28 See Article 1(3) of the draft law. 29 Article 55A of the Statute of the Bank of Greece.
- 30 See, for example, Opinions CON/2016/57, CON/2021/2 and CON/2017/28 (Bulgaria); CON/2021/24 and CON/2011/20 (Belgium); CON/2019/2 and CON/2015/20 (Malta); CON/2017/33 (Austria); CON/2016/42 (Slovenia); CON/2014/57 (Portugal); CON/2013/93 and CON/2017/13 (Latvia); CON/2012/111 and CON/2012/74 (Ireland). 31 See also paragraph 2.11 above. 32 See, for example, paragraph 4.6.1 of Opinion CON/2018/21. 33 See Article 6(3) of the draft law.