Who must comply with credit reporting obligations (Part IIIA Privacy Act)?
The applicability test for Comply with credit reporting obligations (Part IIIA Privacy Act) (OAIC), computed across 35 industries, 9 business structures and 6 size bands.
Short answer: Some businesses
Applies when the business has credit reporting activity or credit activity.
What the obligation is
Credit providers and CRBs must adhere to the CR Code on collection, use, disclosure, hardship and dispute resolution.
Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2014 govern handling of consumer credit information. Credit providers must give s 21D notices, observe permitted disclosures, treat repayment history information correctly, handle financial hardship requests under s 21D and the FHI regime (from 1 July 2022), and respond to corrections within statutory periods.
The applicability test
Applies when the business has credit reporting activity or credit activity.
How the regulator frames it: Credit providers, credit reporting bodies, mortgage insurers, and trade insurers within the regime.
What triggers it: Providing or receiving consumer credit information.
Jurisdiction: Commonwealth law, so the test is the same in every state and territory.
Which industries are in or out
Outcome across the 35 industries Rules Mate maps (2 of 35: yes; 33 of 35: no).
| Industry | Answer |
|---|---|
| Banks & ADIs | Yes |
| Credit licensees & mortgage brokers | Yes |
| No | 33 other industries |
Business structure and size
Structure does not change the answer in the 2 industries it can reach: for every structure the answer is "yes".
Size does not change the answer in the 2 industries it can reach: at every size band the answer is "yes".
Worked examples
Each line is one run of the Rules Mate applicability engine for a single business profile, with the reason the engine gives:
- Pty Ltd company in banks & adis with 6–19 employees, turnover $1M–$3M: applies. Authorised deposit-taking institution.
- Pty Ltd company in real estate agents with 6–19 employees, turnover $1M–$3M: does not apply. Requires credit reporting activity or credit activity.
Answers that bring it into scope
Starting from a small or large professional services company that does not otherwise meet the test, each of these single facts changes the engine's answer:
- The business holds an Australian credit licence (ACL): it then applies (ACL holder).
- The business provides credit to customers: it then applies (provides credit).
What you must do, and when
- When due
- Continuous; specific notification triggers per Part IIIA.
- Frequency
- Ongoing
- Evidence to keep
- CR Code compliance documentation, FHI procedures, notification templates, complaints register.
- Status
- Current
- Priority
- High
Penalty for not complying
Maximum penalty: Same penalty regime as broader Privacy Act; CR Code breaches additionally enforceable.
Audit or assurance level
Rules Mate has not yet classified the audit or assurance level for this obligation. Any audit, review or certification requirement is set by the regulator source listed below.
What usually applies alongside it
Across the 1,890 business profiles Rules Mate evaluates, these obligations apply to most of the businesses this one applies to, and are far more common among them than among businesses generally:
- Consumer Credit Hardship Notice (NCC ss 72-73): applies to 100% of the same businesses (17.5× the overall rate)
- Display comparison rate on credit product advertising: applies to 100% of the same businesses (17.5× the overall rate)
- Register security interests on the PPSR: applies to 100% of the same businesses (17.5× the overall rate)
- Comply with NCCP responsible lending obligations: applies to 100% of the same businesses (17.5× the overall rate)
- Respond to hardship notices within statutory timeframe: applies to 100% of the same businesses (17.5× the overall rate)
- Banking Code of Practice 2025: applies to 50% of the same businesses (17.5× the overall rate)
Where it sits in the corpus
Rules Mate tracks 20 published obligations tagged "privacy", 3 of them rated critical. For a professional services Pty Ltd company with 6–19 employees operating in every state, 4 of those apply outright. This obligation is rated high priority, and is an ongoing duty.
Regulator, legislation and tools
Regulated by Office of the Australian Information Commissioner.
OAIC: Privacy and freedom of information regulator. Administers the Privacy Act 1988, the Notifiable Data Breaches scheme, and the Australian Privacy Principles.
Privacy Act 1988: Federal privacy Act.
Free tools that help with this obligation:
Questions
- Who must comply with credit reporting obligations (Part IIIA Privacy Act)?
- Applies when the business has credit reporting activity or credit activity.
- Do sole traders need to comply with credit reporting obligations (Part IIIA Privacy Act)?
- Yes. Looking in the 2 industries it can reach and every size band, the engine's answer for a sole trader is: yes.
- Do businesses with 1–5 employees need to comply with credit reporting obligations (Part IIIA Privacy Act)?
- Yes (1–5 employees, turnover $100K–$1M).
- When is "Comply with credit reporting obligations (Part IIIA Privacy Act)" due?
- Continuous; specific notification triggers per Part IIIA.
Related
Sources
Computed by the Rules Mate applicability engine from the published obligation corpus; facts last checked 3 October 2026. Rules Mate is not a law firm and this is general information, not legal advice. Confirm your position with the regulator source or a qualified adviser before acting.