Part 3
Protections
Record keeping
47Accredited requestor must keep records about regulated data service
An accredited requestor must keep records of the following matters in respect of any regulated data service relating to a customer that the accredited requestor requests:
- the request made for the service (including the time at which the request was made):
- the authorisation given by or on behalf of the customer, including—
- any limitations on the scope of the authorisation; and
- any modifications to the authorisation; and
- the time at which the authorisation was given; and
- the time (if any) at which the authorisation ended (if the accredited requestor is aware of that information):
- any limitations on the scope of the authorisation; and
- the information specified by the regulations (if any).
The records must be kept—
- for 5 years from the date of the request; and
- otherwise in the manner prescribed by the regulations (if any).
If a person ceases to be an accredited requestor, this section continues to apply with all necessary modifications as if it were still an accredited requestor.
An accredited requestor that contravenes this section commits an infringement offence and is liable to—
- an infringement fee of $20,000; or
- a fine imposed by a court not exceeding $50,000.