Privacy (Credit Reporting) Code 2014 (Version 1.2)

Administered by Attorney-General's Department

Legislation au F2014L00459 Not in force Legislative Instrument

Legislation content

Explanatory Statement

Privacy (Credit Reporting) Code 2014 (Version 1.2)

Issued by the authority of the Information Commissioner

This explanatory statement fulfils the Information Commissioner’s obligations under s 26(1) of the Legislative Instruments Act 2003 (the LI Act) in relation to the lodgement for registration on the Federal Register of Legislative Instruments (FRLI) of the Privacy (Credit Reporting) Code 2014 (Version 1.2) (CR code v1.2).  

Authority for the registration on the FRLI of the CR code v1.2

A CR code is a written code of practice about credit reporting under s26N of the Privacy Act 1988 (Privacy Act). The CR code that is included on the Codes Register kept by the Information Commissioner under s26U of the Privacy Act is called the ‘registered CR code’. The Information Commissioner keeps the Codes Register electronically on the OAIC website. The registered CR code is a legislative instrument (s 26M(2) of the Privacy Act) and therefore must be registered on the FRLI as well as on the Codes Register.

The Information Commissioner is required by s 26S(4) of the Privacy Act to ensure that there is one, and only one, registered CR code on the Codes Register at all times after Part IIIB of the Privacy Act commences (ie 12 March 2014).

On 24 April 2014 the Information Commissioner approved a variation of the CR code included on the Codes Register on his own initiative. CR code v1.2 was included on the Codes Register at noon AEST on 24 April 2014, and the previous CR code was removed at the same time. Upon inclusion on the Codes Register, CR code v1.2 became the ‘registered CR code’.

Purpose and operation of the CR code v1.2

The primary purpose of the CR code v1.2 is to supplement the provisions of Part IIIA of the Privacy Act and the Privacy Regulation 2013. In accordance with s 26N of the Privacy Act, the CR code v1.2 performs the following functions:

  • sets out how one or more of the credit reporting provisions in Part IIIA of the Privacy Act are to be applied or complied with (s 26N(2)(a))
  • makes provision for, or in relation to, matters required or permitted by Part IIIA to be provided for by the registered CR code (s 26N(2)(b))
  • binds all credit reporting bodies (s 26N(2)(c))
  • specifies the credit providers that are bound by the CR code, or a way of determining which credit providers are bound (s 26N(2)(d)), and
  • specifies any other entities subject to Part IIIA of the Privacy Act that are bound by the CR code, or a way of determining which of those entities are bound (s 26N(2)(e)).

In addition, the CR code v1.2:

  • imposes additional requirements that are not contrary to, or inconsistent with the requirements of Part IIIA of the Privacy Act (s 26N(3)(a))
  • deals with the internal handling of complaints (s 26N(3)(b))
  • provides for the reporting to the Commissioner about complaints (s 26N(3)(c)), and
  • deals with any other relevant matters (s 26N(3)(d)).

The CR code v1.2 maintains all of the substantive provisions containing the obligations and rights in relation to organisations and individuals that were included in the original CR code (registered on the Codes Register between 22 January 2014 and 3 April 2014) and the first variation (registered on the Codes Register between 3 April 2014 and 24 April 2014).

The first varied CR code contained only one variation to the original CR code, namely the substitution of the numeral ‘5’ by the numeral ‘14’ in clause 8.1(b). The original CR code required a minimum grace period of 5 days before an overdue payment could be classified as overdue for the purposes of a credit provider (CP) disclosing repayment history information (RHI) to a credit reporting body (CRB). Under the variation, this grace period was extended to 14 days.

The CR code v1.2 contains some minor technical variations to the CR code that it replaces including the insertion of a repeal provision to properly effect repeals of the original CR code (titled the Credit Reporting Privacy Code (CR code)) and the first variation (titled the Credit Reporting Privacy Code (CR code) v1.1).

The CR code v1.2 also adds a few provisions usually included in legislative instruments, for example to name the instrument and to have a commencement provision.

The explanatory text on the front page of the original and first variation CR codes has been slightly amended for clarity and re-inserted under headings titled ‘Overview’ and ‘Reading the table’. A couple of additional definitions have been added under ‘Reading the table’ and the terms ‘current Code’ and ‘existing Code’ throughout the code have been replaced by the term ‘the pre-reform code’ to clarify which code those terms referred to. As well, a ’referencing’ provision has been inserted and the title of the code has been brought closer into line with best practice in legislative instrument naming. All these variations are minor in nature and aid referencing and reading the CR code.

Consultation

The Information Commissioner consulted with Australian Retail Credit Association (ARCA) the original CR code developer, in relation to these minor variations.

Apart from that consultation the Information Commissioner did not consider it necessary to undertake other consultation for the purposes of s 26T(3) of the Privacy Act and s 17 of the Legislative Instruments Act 2003 (LIA Act) because the effect of the proposed variations are minor in nature and do not affect the obligations or rights of individuals or organisations (see s 18 of the LIA Act).

The proposed variation was added to the OAIC’s Codes Register webpage on 22 April 2014 pursuant to s 26T(3)(a) of the Privacy Act.

Statement of compatibility with human rights

Prepared in accordance with Part 3 of the Human Rights (Parliamentary Scrutiny) Act 2011

CR code v1.2

The Privacy (Credit Reporting) Code 2014 (Version 1.2) (CR code v1.2) is compatible with the human rights and freedoms recognised or declared in the international instruments listed in s 3 of the Human Rights (Parliamentary Scrutiny) Act 2011.

Operation

The CR code v1.2 is a binding written code of practice about credit reporting. The purpose of the CR code v1.2 is to supplement the provisions of Part IIIA of the Privacy Act 1988 (Privacy Act) and the Privacy Regulation 2013.

Human rights implications

The CR code v1.2 engages Article 17 of the International Covenant on Civil and Political Rights (ICCPR). Article 17 provides that no one shall be subjected to arbitrary or unlawful interference with his or her privacy, family, home or correspondence, nor to unlawful attacks on his or her honour and reputation, and that everyone has the right to the protection of the law against such interference or attacks. 

The varied CR code has no implication for the prohibition against arbitrary interference with privacy because the variation from the original CR code does not reduce the privacy protections afforded to individuals by the original CR code.

Conclusion

The CR code v1.2 is compatible with human rights because the only amendment that has been made to the original CR code does not reduce the privacy protections afforded to individuals.  

 

Overview

The Privacy (Credit Reporting) Code 2014 (Version 1.2) was enacted to supplement the provisions of Part IIIA of the Privacy Act 1988, which deals with credit reporting. This legislative instrument was introduced to address gaps in the credit reporting practices and ensure that credit reporting bodies adhere to specific standards that protect the privacy of individuals. The Code is a binding written code of practice that sets out how credit reporting provisions are to be applied or complied with, making provision for matters required or permitted by Part IIIA to be provided for by the registered CR code, and binding all credit reporting bodies. The Privacy (Credit Reporting) Code 2014 (Version 1.2) was enacted by the Information Commissioner under section 26N of the Privacy Act 1988, with the policy objective of ensuring that credit reporting practices do not arbitrarily or unlawfully interfere with an individual's privacy, family, home or correspondence, and that individuals have the right to protection of the law against such interference or attacks.

Scope and Application

The Privacy (Credit Reporting) Code 2014 (Version 1.2) applies to credit reporting bodies and credit providers, binding them to specific practices regarding the handling of personal credit information. This includes any entity that collects, stores, uses, or discloses credit information, as well as those entities required to comply with Part IIIA of the Privacy Act 1988. The Code operates across the Commonwealth of Australia, impacting industries involved in credit reporting and the provision of credit services. The scope of the Code is national, applying uniformly regardless of state or territory boundaries. The Code includes minor technical variations from its predecessor, such as the extension of the grace period for overdue payments from five to fourteen days, but does not introduce significant changes to the obligations or rights of individuals or organisations. The Information Commissioner ensures the registered CR code is updated and compliant with the Privacy Act, reflecting the need for a consistent and legally binding framework governing credit reporting practices in Australia.

Key Provisions

The Privacy (Credit Reporting) Code 2014 (Version 1.2) (CR code v1.2) is a legislative instrument that supplements the Privacy Act 1988 and the Privacy Regulation 2013. Section 26N of the Privacy Act mandates that the CR code v1.2 sets out how the credit reporting provisions in Part IIIA of the Privacy Act are to be applied or complied with (s 26N(2)(a)), and makes provision for matters required or permitted by Part IIIA (s 26N(2)(b)). The CR code v1.2 binds all credit reporting bodies (s 26N(2)(c)) and specifies the credit providers that are subject to the code (s 26N(2)(d) and (e)). Additionally, the CR code v1.2 imposes additional requirements (s 26N(3)(a)), deals with internal complaints handling (s 26N(3)(b)), provides for reporting complaints to the Commissioner (s 26N(3)(c)), and addresses other relevant matters (s 26N(3)(d)). The CR code v1.2 imposes obligations on credit reporting bodies and credit providers to ensure compliance with the privacy principles outlined in the Privacy Act. Credit reporting bodies must adhere to the provisions set out in the CR code v1.2, which include handling personal information in a manner consistent with the privacy principles, ensuring the accuracy of credit information, and protecting the privacy of individuals whose information is reported. Credit providers are required to report credit information to credit reporting bodies in accordance with the CR code v1.2, ensuring that they provide accurate and timely information while maintaining the privacy of individuals. Failure to comply with the CR code v1.2 may result in civil or criminal penalties. Under the Privacy Act, non-compliance with the CR code v1.2 may lead to enforcement actions by the Office of the Australian Information Commissioner (OAIC), including the imposition of infringement notices with maximum penalties. For serious or repeated breaches, the OAIC may seek court orders or refer matters to the Australian Federal Police for criminal investigation. Additionally, individuals who suffer loss or damage due to a breach of the CR code v1.2 may have the right to seek redress through the courts. The CR code v1.2 maintains the substantive provisions of the original CR code, with minor technical variations. One significant change is the extension of the grace period for classifying overdue payments from 5 days to 14 days (clause 8.1(b)). This change was made to provide additional protections to consumers by giving them more time to settle overdue payments before they are reported as overdue. The CR code v1.2 also includes minor amendments to improve clarity and readability, such as the insertion of a repeal provision and the addition of definitions. These changes aim to ensure that the code is easily understood and implemented by credit reporting bodies and credit providers.

Legal classification tags

Area of Law
Privacy Law
Instrument
Code
Concepts
Definitions & Interpretation
Regulatory Standards
Reporting & Disclosure Obligations

Interactions

Authorises

All Versions

Sourced from the Federal Register of Legislation at 26 August 2026. For the latest information on Australian Government law please go to https://www.legislation.gov.au.