(1) A regulated entity contravenes this subsection if the entity:
(a) has actionable scam intelligence about an activity relating to, connected with, or using a regulated service of the entity; and
(b) fails to take reasonable steps within a reasonable time to identify the persons who were SPF consumers of that service at the time when the persons were or may have been impacted by the activity.
(2) Subsection (1) is a civil penalty provision.
Note: This means subsection (1) is a civil penalty provision of an SPF principle for the purposes of section 58FJ (about civil penalties).