Credit Provider Determination No. 2006-4 (Classes of credit providers)

Administered by Department of the Prime Minister and Cabinet

Legislation au F2006L02869 Not in force Legislative Instrument

Legislation content

 

 

 

 

 

 

 

Explanatory Statement

 

Credit Provider Determinations

 

     No. 2006 3 Assignees

     No. 2006 4 Classes of credit providers

 

 

August 2006

 

 

 

Explanatory Statement

1. Credit Provider Determinations

This explanatory statement has been drafted for the purpose of fulfilling the Office of the Privacy Commissioner’s obligations under section 26(1) of the Legislative Instruments Act 2003.

This explanatory statement refers to two determinations issued under section 11B(1)(b)(v)(B) of the Privacy Act 1988 (Cwlth) (the Privacy Act):

  • Credit Provider Determination No. 2006-03 (Assignees)
  • Credit Provider Determination No. 2006-04 (Classes of credit providers).

1.1  Authority for making the determinations

The authority for the Privacy Commissioner (the Commissioner) to make these credit provider determinations in respect of assignees and classes of credit providers rests in section 11B(1)(b)(v)(B) and section 28A(1)(d) of the Privacy Act.  Section 11B(1) states:

(1) For the purposes of this Act … a person is a credit provider if the person is:

(b) a corporation (other than an agency)

 (v) that

 (A) carries on a business or undertaking that involves the provision of loans (including the provision of loans by issuing credit cards); and

 (B) is included in a class of corporations determined by the Commissioner to be credit providers for the purposes of this Act.

Section 28A(1)(d) states that the Commissioner has the following function in respect of credit reporting:

(d) to make such determinations as the Commissioner is empowered to make under section 11B or Part IIIA.

1.2 Description of consultation

In February 2006, the Commissioner made short-term Assignees and Classes determinations to allow time for public consultation with stakeholders regarding the operation of the determinations.

In making the new Assignees and Classes determinations, the Commissioner has undertaken a review of the preceding Determinations. The review included issuing a public invitation for submissions to a consultation paper titled: 2006 Review of Credit Determinations Consultation Paper No. 1 – Assignees and Classes of Credit Provider[1] (the Consultation Paper).

The purpose of the consultation was to ascertain stakeholders’ views regarding the operation of the determinations, any new issues that may be relevant and the terms upon which any new determinations should be cast.

The Office of the Privacy Commissioner (OPC) received 12 written submissions from industry organisations, consumer organisations, debt collecting businesses, credit reporting agencies and regulators.

The OPC’s Report on the Review of the Credit Provider Determinations (Assignees and Classes of Credit Provider), August 2006[2] (the Report) provides an analysis of the submissions received, the OPC’s experience and the Commissioner’s review comments.  The Consultation Paper and the submissions are included as related documents in the Report.

2. Credit Provider Determination No. 2006-3 (Assignees)

2.1 Purpose and operation

The purpose of Credit Provider Determination No. 2006-3 (Assignees) (the Assignees Determination) is to determine that a corporation which acquires the rights of a credit provider with respect to the repayment of a loan (whether by assignment, subrogation or other means) shall, in relation to that loan, be regarded as the credit provider for the purposes of the Privacy Act.  A corporation deemed to be a credit provider by virtue of the Assignees Determination is regarded as the credit provider to whom the loan application was submitted, or who provided the loan.

The Assignees Determination affects those businesses that are not already credit providers by virtue of paragraphs (a) or (b)(iii) - (iv) of section 11B(1) of the Privacy Act.

Section 11B(1)(c) extends the operation of the Assignees Determination to assignees that are not a corporation and deems such persons to be credit providers.

This Determination continues the effect of Credit Provider Determination No. 2006-1 (Assignees) dated 22 February 2006 which lapses on 31 August 2006.  The new Assignees Determination is substantively the same as the previous five determinations concerning assignees issued over the past 11 years.

By being granted credit provider status the assignee is able to conduct credit reporting, but only in relation to the assigned loan.  In particular, assignees may be able to, in accordance with Part IIIA of the Privacy Act and the Credit Reporting Code of Conduct (the Code), directly access an individual’s credit report, held by a credit reporting agency, for such purposes as: collecting a payment on the loan that is overdue; listing either an overdue payment or a serious credit infringement in relation to the loan; updating as paid an existing default listing in relation to the loan; and making corrections to information it, or the assignor, has previously reported in relation to that loan.

2.2 Background to the Assignees Determination

The term of the new Assignees Determination is five years.  A determination concerning assignees was first made in 1995, and then re-issued without substantive amendment in 1997, 2002, 2003 and February 2006.  The Determination issued in February 2006 was for six months until 31 August 2006.

The initial determination, made in 1993, followed representations from a mortgage insurer taking assignment of a loan upon the default of a borrower.  The mortgage insurer was concerned that as an assignee it would be able to conduct credit reporting in relation to such a loan as if it were the original credit provider.  Consultation was conducted by the OPC at the initial stage and subsequently prior to the making of the determination in 1997, during which no objections were raised by interested parties.  Prior to making the 2003 Determination, the then Commissioner observed that there were no problems encountered with the operation of the 1997 and 2002 Determinations but identified the issue of double listing as one that should be further considered upon review of that determination.

2.3 Public interest and other relevant considerations

The Consultation Paper sought to specifically address the issues of listing of statute-barred debts, double listings and poor record keeping by assignees.  Responses to these issues are summarised and analysed in the Report and are accompanied by the Commissioner’s comments.

In submissions responding to the Consultation Paper, consumer and industry organisations and industry participants have raised concerns that assignees accessing the credit reporting system may not be fully aware of their obligations in relation to these issues.  The Commissioner has outlined these obligations below and has also set out plans to deal with these issues in the Report.

Statute-barred debts

Under clause 2.8 of the Credit Reporting Code of Conduct a credit provider must not list a debt with a credit reporting agency where recovery of the debt by the credit provider is barred by the statute of limitations.  The provisions in State or Territory statutes of limitation vary but the period is usually six years.

Double listing

Double listing occurs when an assignee lists a payment default or serious credit infringement, which has already been listed, on an individual’s credit report. The practice of double-listing payment defaults or serious credit infringements upon assignment by assignees is not permitted by the Privacy Act and can result in an individual having the one default listed in the credit reporting system for longer than the periods allowed by section 18F of the Privacy Act.

Record keeping

Assignees should ensure that all relevant records relating to the loan they are assigned are accessible to them and are transferred with the loan.  Records in relation to a loan may consist of a notice given to the borrower at the commencement of the loan under section 18E(8)(c) of the Privacy Act[3] or the loan documentation itself.  The timely provision of a notice to the individual under section 18E(8)(c) permits credit reporting to be lawfully undertaken. 

Section 18G of the Privacy Act states that a credit provider must take steps to ensure that the personal information contained in a credit file or report is accurate, up-to-date, complete and not misleading.  If complete documentation for a loan is not available, a credit provider may be acting inappropriately in listing a default for the loan on an individual’s credit file.

3. Credit Provider Determination No. 2006-4 (Classes of credit providers)

3.1 Purpose and operation

The purpose of Credit Provider Determination No. 2006-4 (Classes of credit providers) (the Classes Determination) is to determine that a corporation belonging to the following classes is regarded as a credit provider for the purposes of section 11B(1)(b)(v)(B) of the Privacy Act:

  • a corporation where, in relation to a transaction, it is considering providing or has provided a loan in respect of the provision of goods or services on terms which allow the deferral of payment, in full or in part, for at least 7 days; or
  • a corporation engaged in the hiring, leasing or renting of goods, where, in relation to a transaction, no amount, or an amount less than the value of the goods, is paid as deposit for return of the goods, and the relevant arrangement is one of at least 7 days duration.

This Determination affects those businesses which are not already credit providers by virtue of paragraphs (a) or (b)(iii) - (iv) of section 11B(1) of the Privacy Act.

Section 11B(1)(c) extends the operation of this Determination to assignees that are not corporations and deems such persons credit providers.

This Determination continues the effect of Determination No. 2006-2 (Classes of credit providers) dated 14 February 2006 which lapses on 31 August 2006.  The new Classes Determination is substantively the same as the previous six determinations relating to classes of credit providers issued over the past 15 years.

By being granted credit provider status under the terms of the Classes Determination, a business falling within the class will be permitted to conduct credit reporting in relation to loan transactions that fall within the criteria of the determination in accordance with Part IIIA of the Privacy Act.  In accordance with Part IIIA of the Privacy Act and the Credit Reporting Code of Conduct, a credit provider may be able to directly access an individual customer’s credit report, held by a credit reporting agency for purposes including: assessing the loan application, collecting a payment on the loan that is overdue, listing either an overdue payment or a serious credit infringement in relation to the loan, updating as paid an existing default or serious credit infringement listing in relation to the loan, or making corrections to information they have previously reported in relation to the loan.

3.2 Background to the Classes Determination

The term of the new Classes Determination is five years.  A determination concerning classes of credit providers was made in 1991 then re-issued without substantive amendment in 1993, 1996, 2001, 2002, 2003 and February 2006.  The Determination issued in February 2006 was made for six months until 31 August 2006.

Prior to the making of the determination in relation to classes of credit providers in 2003, the OPC issued a consultation paper to stakeholders and sought comments on the operation of the determination. After considering the 18 submissions that were received, the then Commissioner issued a new Determination in 2003.  The background to that Determination stated that the increase in levels of credit activity did not show a corresponding increase in complaints; noted that there may be signs of emerging concerns such as a lack of credit providers’ understanding of their credit obligations; and the information did not warrant an amendment to the scope of the Determination.

3.3 Public interest and other relevant considerations

In their submissions to the Consultation Paper, consumer and industry organisations and industry participants have raised issues relating to compliance with the Privacy Act by some businesses covered by the Classes Determination.  The Commissioner has addressed this issue below and also sets out plans to deal with this issue in the Report.

Credit provider obligations

The obligations of credit providers are set out in Part IIIA of the Privacy Act and described in greater detail in the Credit Reporting Code of Conduct issued by the Commissioner.

These obligations include requirements for:

  • notifying the individual of the information items that will be disclosed to a credit reporting agency;
  • obtaining access to a credit report issued by a credit reporting agency;
  • issuing notices to an individual when credit is refused;
  • disclosing information about individuals to a credit reporting agency;
  • reporting overdue payments;
  • disclosing information to debt collection agents;
  • reporting serious credit infringements; and
  • disclosing information to other credit providers.

Credit providers also have obligations dealing with access and amendment rights of consumers, and ensuring that the information on a credit file is accurate, up-to-date, complete and not misleading. Credit providers must ensure that the file or report is protected through adequate security measures against loss, unauthorised access, use, modification, disclosure or other misuse.

Credit providers who are covered by the Classes Determination should ensure that they understand their obligations and can refer to the Credit Reporting Code of Conduct[4]for more details.

[1] Link to 2006 Review of Credit Determinations Consultation Paper No. 1 – Assignees and Classes of Credit Provider  on the OPC website at www.privacy.gov.au/act/credit/index.html#cpd

[2] The Report on the Review of the Credit Provider Determinations (Assignees and Classes of Credit Provider), August 2006 is available at www.privacy.gov.au/act/credit/index.html#cpd.

[3] Section 18E(8)(c) states that “a credit provider must not give to a credit reporting agency personal information relating to an individual if  the credit provider did not, at the time of, or before, acquiring the information, inform the individual that the information might be disclosed to a credit reporting agency”. 

[4] The Credit Reporting Code of Conduct is available at www.privacy.gov.au/community/credit/index.html#18.

Overview

The Privacy Act 1988, enacted by the Parliament of Australia, addresses various privacy concerns, including the regulation of credit providers. The Privacy Commissioner, under section 11B(1)(b)(v)(B) and section 28A(1)(d) of the Privacy Act, has the authority to issue determinations that classify certain corporations as credit providers. In August 2006, the Office of the Privacy Commissioner issued two credit provider determinations, Credit Provider Determination No. 2006-3 (Assignees) and Credit Provider Determination No. 2006-4 (Classes of credit providers), to clarify the scope of credit providers and their responsibilities under the Privacy Act. These determinations aim to ensure that credit providers comply with their obligations, including the proper handling of credit reports and avoiding practices such as double listing and the listing of statute-barred debts. Public consultation was undertaken to gather stakeholder feedback, resulting in the determinations being designed to address identified issues and provide clarity to credit providers.

Scope and Application

The Privacy Commissioner’s Credit Provider Determinations No. 2006-3 (Assignees) and No. 2006-4 (Classes of credit providers) apply to corporations that acquire the rights of a credit provider in relation to the repayment of a loan or that are engaged in the hiring, leasing, or renting of goods with deferred payment terms, and subsequently perform credit reporting functions. These determinations are issued under the authority of sections 11B(1)(b)(v)(B) and 28A(1)(d) of the Privacy Act 1988 (Cwlth). They affect corporations that are not credit providers under paragraphs (a) or (b)(iii)-(iv) of section 11B(1) of the Privacy Act. The Assignees Determination also extends to non-corporate assignees, deeming them credit providers. These determinations facilitate the conduct of credit reporting by assignees and businesses within specified classes, in compliance with the Privacy Act and the Credit Reporting Code of Conduct. They do not include explicit exclusions or exemptions, but obligations for credit providers are detailed in the Credit Reporting Code of Conduct, including the necessity to maintain accurate and secure credit information. The determinations are subject to the review and potential amendment through subordinate instruments, reflecting ongoing consultation with stakeholders.

Key Provisions

The Credit Provider Determinations No. 2006-3 and No. 2006-4 establish specific conditions under which certain corporations and assignees are considered credit providers for the purposes of the Privacy Act 1988 (Cwlth). These determinations are pivotal in defining the scope of credit providers and their responsibilities in the credit reporting system. The Assignees Determination (No. 2006-3) stipulates that any corporation acquiring the rights of a credit provider concerning loan repayments is considered a credit provider for the purposes of the Privacy Act, provided the loan application was submitted to or the loan provided by the original credit provider. This applies to corporations that do not already fall under specific categories of credit providers as outlined in section 11B(1) of the Privacy Act. This determination allows assignees to conduct credit reporting only in relation to the assigned loan, including accessing credit reports for overdue payments, listing defaults, updating payment statuses, and making corrections. The Classes Determination (No. 2006-4) classifies certain corporations as credit providers if they provide loans allowing deferred payment for at least seven days or engage in hiring, leasing, or renting goods without a deposit for at least seven days. This determination extends to non-corporate assignees who are deemed credit providers, enabling them to conduct credit reporting under the Privacy Act and the Credit Reporting Code of Conduct. The Act imposes specific obligations on credit providers and assignees identified under these determinations. These include notifying individuals of the information that will be disclosed to credit reporting agencies, accessing credit reports, issuing notices of credit refusal, reporting overdue payments, disclosing information to debt collection agents, reporting serious credit infringements, and ensuring information is accurate, up-to-date, complete, and not misleading. Credit providers must also ensure that personal information is protected against unauthorized access and misuse. Assignees must be aware of their obligations to avoid issues such as double listing, listing of statute-barred debts, and maintaining proper record-keeping. Breaching the obligations outlined in the Privacy Act and the Credit Reporting Code of Conduct can lead to civil and criminal penalties. Under section 13G of the Privacy Act, a credit provider who contravenes the Act can face a civil penalty of up to $21,000 for a corporation and $4,200 for an individual. Additionally, under section 13H, a person who contravenes a provision of the Act can face a criminal penalty of up to $210,000 for a corporation and $42,000 for an individual. These penalties are intended to enforce compliance and protect consumers' privacy rights.

Legal classification tags

Area of Law
Privacy Law
Instrument
Regulation
Concepts
Definitions & Interpretation
Licensing & Registration
Reporting & Disclosure Obligations
Compliance Obligations
Prohibited Conduct

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.