ASIC Credit (Breach Reporting—Prescribed Commonwealth Legislation) Instrument 2021/801

Administered by Department of the Treasury

Legislation au F2021L01364 Not in force Legislative Instrument

Legislation content

 

 

Explanatory Statement

 

ASIC Credit (Breach Reporting— Prescribed Commonwealth Legislation) Instrument 2021/801

This is the Explanatory Statement for ASIC Credit (Breach Reporting— Prescribed Commonwealth Legislation) Instrument 2021/801 (the instrument).

The Explanatory Statement is approved by the Australian Securities and Investments Commission (ASIC).

Summary

  1. The instrument provides temporary relief to limit the Commonwealth legislation in relation to which the breach reporting obligation in the National Consumer Credit Protection Act 2009 (the Credit Act) applies. The instrument provides relief for a period of three years.
  2. The relief is intended to be an interim measure to provide certainty to credit licensees ahead of legislative changes proposed to be made by the Government to give effect to the intended operation of the breach reporting obligation.

Purpose of the instrument

3.             On 10 December 2020, the Financial Sector Reform (Hayne Royal Commission Response) Act 2020 was passed (the FSR Act). The FSR Act introduced a breach reporting obligation for credit licensees into Division 5 of Part 2-2 of the Credit Act, which mirrors the breach reporting obligation in Part 7.6 of the Corporations Act 2001 (the Corporations Act). The obligation commences on 1 October 2021.

4.             Under the breach reporting obligation, credit licensees are required to report breaches or likely breaches (as well as investigations into breaches or likely breaches) of ‘core obligations that are significant. Core obligations are set out in subsection 50A(3) of the Credit Act and include the obligation in subsection 47(1)(d) of the Credit Act to comply with the credit legislation, so far as it relates to Commonwealth legislation that covers conduct relating to credit activities (but only in so far as it covers conduct relating to credit activities).

5.             On 6 September 2021, the Government announced its intention to make a number of technical amendments to give effect to the intended operation of the breach reporting reforms under the FSR Act. The proposed changes include an amendment to the Credit Act to limit the reporting of breaches of other Commonwealth laws relating to credit activities. The list of other Commonwealth laws in relation to which the Government proposes to retain the requirement to report relevant breaches under the breach reporting obligation in the Credit Act are:

(a)     Banking Act 1959;

(b)     Corporations Act 2001;

(c)     Financial Sector (Collection of Data) Act 2001;

(d)     Financial Sector (Shareholdings) Act 1998; and

(e)     Financial Sector (Transfer and Restructure) Act 1999.

6.             The proposed amendment is intended to provide a more consistent approach between the breach reporting obligations in the Credit Act and Corporations Act in relation to reporting of breaches of other Commonwealth legislation.  Specifically, it is intended to bring the core obligation in paragraph 50A(3)(c) of the Credit Act more closely into line with the corresponding core obligation in paragraph 912D(3)(c) of the Corporations Act, which is limited to the Commonwealth legislation specified in Regulation 7.6.02A of the Corporations Regulations 2001.

7.             The Government’s announcement foreshadowed that ASIC, following a targeted consultation, would consider providing temporary breach reporting relief for breaches under subsection 50A(1) of the Credit Act for any other Commonwealth legislation that covers conduct relating to credit activities. It also noted that this interim relief would be provided in light of the Government’s intention to make an amendment to the Credit Act to limit the breaches that are required to be reported under the breach reporting regime.

8.             Consistent with the Government’s stated policy intention, the instrument provides temporary relief to limit the Commonwealth legislation covered by the core obligation in paragraph 50A(3)(c) of the Credit Act to those listed in paragraph 5 above.

9.             The instrument provides certainty to credit licensees in relation to the application of the breach reporting obligation in the Credit Act in the interim period before the Government’s proposed legislative changes are made. It will avoid credit licensees being required to implement changes to business systems and processes to report breaches of Commonwealth legislation that are not intended to be caught by the obligation.  

10.         The instrument provides relief for a period of three years. This period will provide Parliament with the necessary time to consider the relevant legislative amendments and regulations.

 

Consultation

11.         ASIC consulted with a number of industry associations and consumer groups before making the instrument. None of the respondents to the consultation opposed the making of the instrument.

Operation of the instrument

12.         The instrument modifies the core obligation set out in paragraph 50A(3)(c) of the Credit Act to limit the scope of that obligation to the following Commonwealth legislation:

(a)     Banking Act 1959;

(b)     Corporations Act 2001;

(c)     Financial Sector (Collection of Data) Act 2001;

(d)     Financial Sector (Shareholdings) Act 1998; and

(e)     Financial Sector (Transfer and Restructure) Act 1999.

13.         As a result, breaches or likely breaches (or investigations into breaches or likely breaches) of Commonwealth legislation that are not specifically referred to in subsection 50A(3) of the Credit Act will not give rise to a ‘reportable situation’ under subsection 50A(1) and, unless any of the situations in subsection 50A(2) apply, will not trigger:

(a)     the obligation to lodge a report with ASIC under sections 50B and 50C;

(b)     the obligation to notify affected consumers under section 51A; and

(c)     the obligation to investigate the situation under section 51B.

14.         The instrument commences on the later of 1 October 2021 and the day after it is registered on the Federal Register of Legislation. This commencement date is intended to align with the commencement date of the breach reporting obligation in the Credit Act of 1 October 2021.

Legislative instrument and primary legislation 

15.         The subject matter and policy implemented by this instrument is more appropriate for a legislative instrument rather than primary legislation because the matters contained in the instrument are:

(a)          a specific amendment designed to ensure that the application of primary legislation applies in a way consistent with the intended policy and enabling provisions in the primary legislation; and

(b)          made on an interim basis ahead of the Government making the necessary legislative changes in the primary legislation to give effect to the intended policy in the primary legislation.

Legislative authority

16.         The instrument is made under subsection 109(3) of the Credit Act.

17.         The instrument is a disallowable instrument under the Legislation Act 2003.

Statement of Compatibility with Human Rights 

18.         The Explanatory Statement for a disallowable legislative instrument must contain a Statement of Compatibility with Human Rights under subsection 9(1) of the Human Rights (Parliamentary Scrutiny) Act 2011. A Statement of Compatibility with Human Rights is in the Attachment.


Attachment

Statement of Compatibility with Human Rights

 

This Statement of Compatibility with Human Rights is prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.  

ASIC Credit (Breach Reporting— Prescribed Commonwealth Legislation) Instrument 2021/801

Overview

1. The instrument provides temporary relief to limit the Commonwealth legislation in relation to which the breach reporting obligation in the National Consumer Credit Protection Act 2009 applies.

Assessment of human rights implications

2. This instrument does not engage any of the applicable rights or freedoms.

Conclusion

3. This instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

 

Overview

The ASIC Credit (Breach Reporting—Prescribed Commonwealth Legislation) Instrument 2021/801 was introduced to provide temporary relief to credit licensees regarding the breach reporting obligation under the National Consumer Credit Protection Act 2009 (Credit Act). Enacted by the Australian Securities and Investments Commission (ASIC), this instrument aims to create clarity and certainty for credit licensees ahead of the legislative changes proposed by the Government. Specifically, the instrument limits the scope of Commonwealth legislation that credit licensees must report breaches of under the Credit Act, mirroring the breach reporting obligation in the Corporations Act 2001. The temporary relief is intended to prevent credit licensees from having to implement changes to their business systems and processes to report breaches of Commonwealth legislation that are not covered by the breach reporting regime. The instrument is designed to be an interim measure, providing relief for a period of three years until the Government enacts the necessary legislative amendments.

Scope and Application

The ASIC Credit (Breach Reporting—Prescribed Commonwealth Legislation) Instrument 2021/801 applies to credit licensees who are required to comply with the National Consumer Credit Protection Act 2009 (Credit Act). This instrument provides temporary relief to credit licensees by limiting the Commonwealth legislation in relation to which the breach reporting obligation applies. Specifically, the breach reporting obligation will apply to breaches of the Banking Act 1959, Corporations Act 2001, Financial Sector (Collection of Data) Act 2001, Financial Sector (Shareholdings) Act 1998, and Financial Sector (Transfer and Restructure) Act 1999. The instrument provides this relief for a period of three years, allowing credit licensees to avoid implementing changes to their business systems and processes to report breaches of Commonwealth legislation that are not intended to be caught by the obligation. The instrument commences on the later of 1 October 2021 and the day after it is registered on the Federal Register of Legislation. The instrument is made under subsection 109(3) of the Credit Act and is a disallowable instrument under the Legislation Act 2003. The instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Key Provisions

The main operative sections of the ASIC Credit (Breach Reporting—Prescribed Commonwealth Legislation) Instrument 2021/801 (the instrument) modify the 'core obligation' in paragraph 50A(3)(c) of the National Consumer Credit Protection Act 2009 (the Credit Act) to limit the scope of that obligation to specific Commonwealth legislation. Section 3 of the instrument specifies that the breach reporting obligation in the Credit Act will apply to breaches of the Banking Act 1959, the Corporations Act 2001, the Financial Sector (Collection of Data) Act 2001, the Financial Sector (Shareholdings) Act 1998, and the Financial Sector (Transfer and Restructure) Act 1999. This means that breaches or likely breaches of other Commonwealth legislation will not trigger the reporting, notification, or investigation obligations under the Credit Act unless specified exceptions apply. The instrument imposes specific obligations on credit licensees. Firstly, it requires credit licensees to report breaches or likely breaches of the specified Commonwealth legislation to the Australian Securities and Investments Commission (ASIC). This includes reporting investigations into such breaches. Secondly, credit licensees must notify affected consumers when required under the Credit Act. Thirdly, they are obligated to investigate situations that may involve breaches of the specified Commonwealth legislation. Failure to comply with the requirements set out in the instrument may result in civil or criminal consequences. While the instrument itself does not specify penalties, breaches of the Credit Act, which the instrument modifies, can lead to substantial penalties. For example, under section 1311 of the Credit Act, an individual who commits an offence against the Act can be subject to a penalty of up to 5,100 penalty units ($1,020,000) for a corporation and up to 510 penalty units ($102,000) for an individual. Additionally, section 1317 of the Credit Act provides that a person who contravenes certain sections of the Act is liable to a civil penalty of up to 5,100 penalty units ($1,020,000). The maximum penalties are subject to change in line with inflation adjustments and other legislative amendments. In summary, the instrument temporarily modifies the breach reporting obligations under the Credit Act to limit the scope of covered Commonwealth legislation. Credit licensees must adhere to specific reporting, notification, and investigation requirements for breaches of the specified legislation. Non-compliance can result in significant penalties, including fines and potential civil liability. The instrument provides interim relief until the Government enacts permanent legislative changes.

Legal classification tags

Area of Law
Consumer Law
Instrument
Legislative Instrument
Concepts
Definitions & Interpretation
Reporting & Disclosure Obligations
Regulatory Standards

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.