NEW ZEALAND CREDIT HEADER 3

The Supplier Data used to provide the “New Zealand - Credit Header 3” Dataset is supplied by Equifax New Zealand Information Services and Solutions Limited (“Equifax”) and includes consumer credit information about New Zealand Data Subjects. GBG is obliged under the terms of its agreement with Equifax to ensure that all End Users agree to comply with the following licensing provisions:

1. DEFINITIONS
1.1. In these Additional Terms, the following definitions shall apply, in addition to the definitions set out in the Agreement.
“End User Data” means any data provided to GBG by the End User for processing in accordance with the terms of the Agreement including where relevant any personal data.

2. USE OF THE DATASET
2.1. The End User acknowledges and accepts that:
a. GBG will provide the Supplier with the End User Data;
b. the Services rely on the information collected by the Supplier (including the End User Data);
c. the Supplier does not usually remove any information (including the End User Data) from its systems unless it considers that information to be inaccurate, out of date or incomplete; and
d. it is the Supplier’s decision whether to remove such information.
2.2. The End User further acknowledges that, given the nature of the Dataset, GBG recommends that the End User does not use the Supplier Data and Results as the sole basis for any business decision. The End User expressly accepts to use the Dataset at its own risks.
2.3. The Dataset is regulated by a Code under the Privacy Act 2020 called the Credit Reporting Privacy Code 2020 (the “Code”). The Code imposes particular obligations on Equifax as credit reporter when they provide consumer credit reporting services. Before the End User uses any consumer credit reporting service, it must inform the Data Subject it is enquiring of the purposes for which the Supplier collects, uses and discloses the End User Data. The Data Subject the End User is enquiring about must: a. authorise the End User to make an enquiry about them. This obligation does not apply if an exception under the Code applies to the End User; b. authorise the Supplier to list the information the End User provides about the Data Subject, use it for the Supplier’s credit reporting services, and supply it to the Supplier’s customers when they use the Supplier’s services. This obligation does not apply if an exception under the Code applies to the End User.
2.4. The End User confirms that it has and will maintain throughout the Agreement Term: a. written policies and procedures for its employees, agents and contractors to follow when they use the Services; b. controls over who uses the Services, including: i. the use of passwords and login details to access the Services; and ii. the ability to identify which of its users has accessed the Services each time they are used; c. information and training for its employees, agents and contractors on such policies, procedures and controls to ensure compliance with them; d. processes to monitor the use of the Services and regularly assess compliance with its internal policies, procedures and controls; e. procedures for taking appropriate action if it identifies any breaches of those policies, procedures or controls; and f. all other appropriate measures to safeguard the Services against unauthorised access.
2.5. The End User must: a. cooperate with the Supplier's reasonable requirements to monitor and review: i. the End User's use of the Services; ii. the End User's compliance with this Agreement; and iii. the effectiveness of the policies, procedures and controls maintained by the End User in connection with the use of the Services; b. upon request, provide the Supplier and GBG with evidence reasonably required to: i. verify the End User's compliance with this Agreement; and ii. substantiate any credit account information, credit default information, serious credit infringement information or credit non-compliance action information (as those terms are defined in the Code) disclosed by the End User to the Supplier.
2.6. The Dataset allows the End User to perform identity verification of the Data Subjects, where the express consent of the Data Subject being verified, has been obtained. The Dataset may be used in relation to customer due diligence and verification requirements generally, or specifically in relation to obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009. Each time the End User uses the Dataset the access will be logged. Each time the End User uses the Dataset, it must obtain the express consent of the Data Subject it is verifying. GBG and/or the Supplier may immediately suspend or withdraw the End User's access to, or use of, the Dataset without notice if, acting reasonably, GBG or the Supplier believes that the End User is not complying with these Additional Terms or the Code.

3. SERVICE LEVELS
3.1. Notwithstanding the Service Levels in the Agreement, the End User acknowledges and accepts that:
a. because the Supplier Data is supplied over communication links and other networks, the availability of any Supplier Data relies on the availability of those links and networks. GBG and the Supplier are not responsible if the links or the networks are unavailable at any time and do not guarantee the Supplier Data will be continuously available.
b. Equifax performs regular maintenance on their systems. The Supplier Data is usually available all day, every day, except between midnight to 2am (NZST). A daily outage window is reserved from 12.00am – 6.00am (NZST) to perform routine maintenance, when required, and Christmas Day and Good Friday are reserved for scheduled maintenance.

4. LIABILITY
4.1. The End User acknowledges that the Supplier Data comprises information obtained from third parties, public registers and other publicly available information sources. To the maximum extent permitted by applicable law, neither GBG nor the Supplier will be liable to the End User for the accuracy, completeness or currency of any Supplier Data obtained from such sources.