PRIVACY AMENDMENT (KEYSTART) REGULATIONS 2025
EXPLANATORY STATEMENT
Issued by authority of the Attorney-General
in compliance with section 15J of the Legislation Act 2003
Purpose and operation of the Instrument
The purpose of the Privacy Amendment (Keystart) Regulations 2025 (the Regulations) is to amend the Privacy Regulation 2013 (Privacy Regulation) to prescribe Keystart as an organisation under section 6F of the Privacy Act 1988 (Privacy Act). This will enable Keystart to participate in the credit reporting system, while also requiring Keystart to protect customers’ personal information, including credit reporting information.
The Privacy Act provides for the protection of the privacy of individuals. The Privacy Act contains 13 Australian Privacy Principles (APPs) which regulate the collection, use, disclosure and storage of individuals' personal information. The APPs apply to Commonwealth government agencies, private sector organisations with an annual turnover of over $3 million, and certain smaller organisations. One of the objects of the Privacy Act is to facilitate an efficient credit reporting system while ensuring the privacy of individuals is respected.
Subsection 100(1) of the Privacy Act provides that the Governor-General may make regulations, not inconsistent with the Privacy Act:
- prescribing matters required or permitted by the Privacy Act to be prescribed; or
- necessary or convenient to be prescribed for carrying out or giving effect to the Privacy Act.
Subsection 6F(1) of the Privacy Act provides that the Privacy Act applies in relation to a prescribed State or Territory authority as if the authority were an organisation. Before the Governor‑General makes regulations prescribing a State or Territory authority for the purposes of subsection 6F(1) of the Privacy Act, subsection 6F(3) provides that the Minister must be satisfied that the relevant State or Territory has requested that the authority be prescribed for those purposes and consult the Australian Information Commissioner about the desirability of regulating under the Privacy Act the collection, holding, use, correction and disclosure of personal information by the authority.
Background
Since 1989, Keystart has provided low-deposit home loans to Western Australians who may be unable to meet the deposit requirements of mainstream lenders. Historically, Keystart consisted of a group of companies regulated by the Corporations Act 2001 (Cth) and a trust, and was considered an organisation for the purposes of the Privacy Act. However, the Keystart Act 2024 (WA) establishes Keystart as a statutory corporation and government trading enterprise under its own enabling legislation, making it a State authority for the purposes of subsection 6C(3) of the Privacy Act. State authorities are specifically excluded from the operation of the Privacy Act, meaning Keystart would no longer be subject to the Privacy Act unless prescribed.
Prescription as an organisation would mean that Keystart would fall within the definition of a ‘credit provider’ under subsection 6G(1)(b) of the Privacy Act, as the provision of credit is a substantial part of Keystart’s business. Keystart requires access to personal information, including credit reporting information, for the purpose of assessing customers’ loan applications and their credit worthiness. The restrictions in Part IIIA of the Privacy Act on the collection, use and disclosure of consumer credit information to and by credit reporting bodies (CRBs) and credit providers mean Keystart would be unable to exchange credit information with CRBs, including default information and repayment history information, unless prescribed.
Prescription as an organisation would therefore mean Keystart would be able to participate in the credit reporting system and carry on its main business of issuing loans. Keystart would be bound to comply with the enhanced protections contained in Part IIIA of the Privacy Act that apply to credit providers, and bound to comply with the APPs (as modified by Division 3 of Part IIIA of the Privacy Act). Prescription would also provide a mechanism for the Office of the Australian Information Commissioner (OAIC) to exercise its regulatory functions in relation to Keystart, including the power to investigate any alleged interferences with individuals’ privacy, and provide affected individuals with legally enforceable complaint rights.
Impact and effect
The effect of the Regulations is to impose obligations on Keystart as an organisation under the Privacy Act. As an organisation that is a credit provider, Keystart will be permitted to disclose credit information about an individual to a CRB. The prescription will also permit CRBs to disclose credit reporting information, including repayment history information, to Keystart.
As an organisation that is a credit provider, Keystart will be required to handle information in accordance with the following legislation and legislative instrument:
- Schedule 1 of the Privacy Act, which contains the APPs, which regulate the collection, use, disclosure and storage of individuals' personal information (and which will apply as modified by Division 3 of Part IIIA of the Privacy Act);
- Part IIIA of the Privacy Act, which deals with the privacy of information relating to credit reporting (as supported by the Privacy Regulation); and
- the Privacy (Credit Reporting) Code 2024 (the CR Code).
Part IIIA of the Privacy Act regulates the handling of personal information about an individual’s activities in relation to consumer credit. Division 3 of Part IIIA of the Privacy Act outlines:
- the types of credit information that credit providers can disclose to a CRB to be included in an individual’s credit report; and
- the permitted purposes for which credit providers can use credit eligibility information about an individual.
The CR Code particularises the credit reporting obligations imposed by Part IIIA of the Privacy Act and the Regulations. It covers notification requirements, credit enquiries, financial hardship information, default information and publicly available information, credit bans, access and complaints.
Details/operation
The Regulations are a legislative instrument for the purposes of the Legislation Act 2003.
The Regulations commence on the day after the instrument is registered on the Federal Register of Legislation.
Details of the Regulations are set out in Attachment A.
Consultation
The WA Department of Treasury and State Solicitor’s Office, Keystart and the OAIC were consulted and are supportive of the Regulations.
Impact analysis
The Office of Impact Analysis was consulted in relation to the Regulations and advised that a Regulatory Impact Statement is not required (OIA25-08821).
OTHER
The Regulations are compatible with the human rights and freedoms recognised or declared under section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011. A statement of compatibility with human rights for the Regulations is at Attachment B.
Attachment A
NOTES ON SECTIONS
Section 1 – Name
This section provides that the name of the instrument is the Privacy Amendment (Keystart) Regulations 2025 (the Regulations).
Section 2 – Commencement
This section provides that the instrument commences the day after the instrument is registered on the Federal Register of Legislation.
Section 3 – Authority
This section provides that the Regulations are made under the Privacy Act 1988 (the Privacy Act).
Section 4 – Schedules
This section is the formal enabling provision for the Schedule to the Regulations. This section enables the Privacy Regulation 2013 (Privacy Regulation) to be amended.
SCHEDULE 1 – Amendments
Privacy Regulation 2013
Item [1] – After subsection 8(1)
This item inserts a new heading for ‘Western Australia’. Under the Western Australia heading, new subsection 8(1A) specifies that for the purposes of subsection 6F(1) of the Privacy Act, the body known as Keystart established under the Keystart Act 2024 (WA) is prescribed.
Attachment B
Statement of Compatibility with Human Rights
Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011
Privacy Amendment (Keystart) Regulations 2025
The instrument is compatible with the human rights and freedoms recognised or declared in the international instruments listed in section 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.
Overview of the instrument
Under the Keystart Act 2024 (WA), Keystart is a body corporate with perpetual succession established for a public purpose under a state law, making it a State authority for the purposes of subsection 6C(3) of the Privacy Act 1988 (Privacy Act). By providing low-deposit home loans, Keystart facilitates home ownership, and assistance with housing, for persons in Western Australia, including persons in regional and rural areas, who may not be able to obtain financial assistance from non-government providers. In order to assess applicants’ loan applications, Keystart requires access to personal information, including credit reporting information.
The Privacy Amendment (Keystart) Regulations 2025 (the Regulations) prescribe Keystart as an organisation under section 6F of the Privacy Act. As an organisation that carries on a business, with a substantial part of that business being the provision of credit, Keystart would meet the definition of credit provider under subsection 6G(1)(b) of the Privacy Act.
Prescription as an organisation will therefore mean Keystart would be able to participate in the credit reporting system set out in Part IIIA of the Privacy Act and carry on its main business of issuing loans. Keystart would be bound to comply with the enhanced protections contained in Part IIIA that apply to credit providers, and bound to comply with the Australian Privacy Principles (APPs) (which will apply as modified by Division 3 of Part IIIA of the Privacy Act). Prescription would also provide a mechanism for the Office of the Australian Information Commissioner (OAIC) to exercise its functions in relation to Keystart, including the power to investigate interferences with privacy, and provide affected individuals with legally enforceable complaint rights.
Human rights implications
The Regulations engage the prohibition on interference with a person’s privacy, family and home in Article 17 of the International Covenant on Civil and Political Rights (ICCPR).
Article 17 of the ICCPR provides that no one shall be subjected to arbitrary or unlawful interference with their privacy, family, home or correspondence, nor to unlawful attacks on their honour and reputation. Article 17 of the ICCPR also provides that everyone has the right to the protection of the law against such interference or attacks.
The prohibitions in Article 17 have been given effect by the Privacy Act. By making Keystart subject to the Privacy Act, the human rights concerning privacy are engaged and supported.
The Privacy Act
The Privacy Act provides for the protection of personal information collected and held by Australian Government agencies and certain private sector organisations. It contains the APPs, which set out obligations for the collection, storage, use, disclosure, access to and correction of personal information.
One of the objects of the Privacy Act is to facilitate an efficient credit reporting system, while ensuring that the privacy of individuals is respected. Credit reporting laws are intended to balance an individual’s right to protect their personal information with the need to ensure credit providers:
- have sufficient information available to assist them to decide whether to provide an individual with credit, and
- can comply with their responsible lending obligations under the National Consumer Credit Protection Act 2009 (Cth).
To promote an individual’s right to privacy, Part IIIA of the Privacy Act regulates the handling of personal information about an individual’s activities in relation to consumer credit. Division 3 of Part IIIA outlines:
- the types of credit information that credit providers like Keystart can disclose to a credit reporting body (CRB), for the purpose of that information being included in an individual’s credit report, and
- the permitted purposes for which credit providers can use credit eligibility information about an individual.
The Australian Information Commissioner, through the OAIC, is responsible for monitoring and enforcing compliance with the Privacy Act and can investigate complaints.
The Regulations
The Regulations promote an individual’s right to privacy because prescribing Keystart as an organisation would mean Keystart would be bound by the obligations in the Privacy Act. As an organisation, Keystart would also meet the definition of credit provider under subsection 6G(1)(b) of the Privacy Act. This would mean the range of additional privacy obligations that apply to credit providers contained in Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2024 (CR Code) would also apply to Keystart. These obligations relate to the transparency of information, additional notification requirements, the use and disclosure of information, ensuring the integrity and security of information, facilitating access to, and correction of, information and dealing with complaints regarding the handling of information.
Transparency of information
Obligations regarding the transparency of information require Keystart to:
- prepare a specific policy about its management of credit information and credit eligibility information, making the policy publicly available and taking reasonable steps to provide a copy of this policy on request (section 21B of the Privacy Act), and
- implement practices, procedures and systems to ensure Keystart meets its obligations under Part IIIA of the Privacy Act and the CR Code, and enable Keystart to deal with enquiries or complaints from individuals about its compliance (section 21B of the Privacy Act).
As a credit provider, Keystart’s notification obligations under APP 5 (notification of the collection of personal information) have been expanded to cover a range of additional matters specified in Part IIIA of the Privacy Act and the CR Code. In particular, additional notification requirements will be imposed on Keystart where it collects personal information about an individual that is likely to be disclosed to a CRB (section 21C of the Privacy Act).
Use and disclosure of credit related information
Generally speaking, a credit provider must not disclose credit information about an individual to a CRB (subsection 21D(1) of the Privacy Act). However, this prohibition on disclosure does not apply in the particular circumstances set out in subsection 21D(2). As an organisation that is a credit provider, Keystart may therefore only disclose credit information about an individual to a CRB in line with the requirements set out in section 21D, and must make a written note of that disclosure (subsection 21D(6)).
Keystart is also subject to specific obligations in relation to credit eligibility information disclosed to it by a CRB. Subsection 21G(1) of the Privacy Act prohibits a credit provider from using or disclosing the credit eligibility information that it holds. However, the prohibitions on use and disclosure do not apply in the circumstances set out in subsections 21G(2)-(3). Where Keystart uses or discloses credit eligibility information in those circumstances, it must make a written note of that use or disclosure (subsection 21G(6)).
Ensuring the integrity and security of credit related information
As a credit provider, Keystart must ensure the integrity and security of credit related information. In particular:
- Keystart must take reasonable steps to ensure the credit eligibility information it collects, uses and discloses is accurate, up-to-date and complete (section 21Q of the Privacy Act). APP 10 (quality of personal information) does not apply to Keystart in relation to its handling of credit eligibility information but does apply in relation to its handling of credit information generally (that is, information collected from the individual directly).
- Keystart must not disclose credit information or use/disclose credit eligibility information that is false or misleading in a material particular (section 21R of the Privacy Act).
- Keystart must take reasonable steps to protect credit eligibility information from misuse, interference, loss, unauthorised access, modification or disclosure (section 21S of the Privacy Act). These provisions also include requirements for Keystart to destroy or de-identify certain information that it holds in its records where it no longer needs this information for relevant purposes. APP 11 (security of personal information) does not apply to Keystart in relation to its handling of credit eligibility information but does apply in relation to its handling of credit information generally (that is, information collected from an individual directly).
The CR Code also imposes various record keeping obligations on credit providers in relation to their use or disclosure of credit information.
Access to, and correction of, credit related information
There are specific provisions in Part IIIA of the Privacy Act relating to the capacity of an individual to request access to their own credit eligibility information (section 21T) and to request correction of their own credit information (section 21V). Keystart is not permitted to charge for making such correction.
Specific obligations are also imposed on Keystart where it identifies that credit information or credit eligibility information it holds is inaccurate, out of date, incomplete, irrelevant or misleading on its own motion (section 21U of the Privacy Act).
These specific provisions alter the operation of the APPs with respect to credit related information held by Keystart.
Complaints regarding the handling of credit related information
There is a specific complaints-handling regime in Division 5 of Part IIIA of the Privacy Act that applies to certain complaints made to Keystart about its acts or practices that may be a breach of Part IIIA of the Privacy Act or the CR Code.
In accordance with the regime, Keystart is required to provide written acknowledgement of the complaint and how it will be handled, investigate the complaint, consult other parties as necessary and make a decision within 30 days unless the individual agrees to a longer period (section 23B of the Privacy Act).
By prescribing Keystart as an organisation, the Regulations promote an individual’s right to privacy by imposing obligations on Keystart to appropriately handle individuals’ personal information, including credit reporting information, and by providing individuals with legally enforceable complaint rights.
Conclusion
This instrument engages the protection against arbitrary interference with privacy. It is compatible with human rights because it promotes the protection of the right to privacy.