Skip to main content Call us
Compliance & rights

Credit Reporting Privacy Code 2014: A Practical Guide for Consumers

The short version The Credit Reporting Privacy Code 2014 governs how credit providers and credit reporting bodies handle your personal credit information. It sets strict rules about what can be listed, how long information stays on file, and requires proper notification procedures before defaults are recorded.

Getting a default on your credit file can feel like punishment without warning, especially when the listing appears without proper notice or contains incorrect information.

The Credit Reporting Privacy Code 2014 is the main set of rules that governs how your credit information is collected, used, stored and disclosed in Australia. When credit providers or credit reporting bodies don’t follow these rules, it can give you grounds to challenge the listing.

Understanding your rights under the Privacy Code is particularly important if you’re dealing with a default that appeared without warning, contains wrong information, or was listed after you thought the matter was resolved.

Got a default on your credit file? Lodge it with Default Gone right here, or call us on (02) 5502 7025. $399 flat per consumer per default. We do not guarantee removal — outcomes depend on the facts of each case — but we will prepare and lodge the dispute properly.

What is the Credit Reporting Privacy Code 2014?

The Credit Reporting Privacy Code 2014 is a legally binding code made under the Privacy Act 1988. It applies to credit providers (banks, lenders, utilities, telecoms companies) and credit reporting bodies (Equifax, Experian, Illion) when they handle your credit information.

The Privacy Code covers:

  • What credit information can be collected and disclosed
  • How long different types of information can stay on your credit file
  • What steps must be followed before listing defaults or other negative information
  • Your rights to access, correct and complain about your credit information
  • Security requirements for handling credit data

Who must follow the Privacy Code?

The Privacy Code applies to:

  • Credit providers: Banks, credit unions, finance companies, buy-now-pay-later providers, utilities, telecoms companies, and any other organisation that provides credit
  • Credit reporting bodies: The three main credit reporting bodies in Australia (Equifax, Experian, Illion)
  • Mortgage insurers: Companies that provide lenders mortgage insurance
  • Trade insurers: Companies that provide credit insurance to businesses

Key protections under the Privacy Code

Default listing requirements

Before a default can be listed on your credit file, the Privacy Code requires credit providers to:

  1. Give proper notice: Send a written notice to your last known address at least 30 days before listing the default
  2. Specify the minimum amount: The overdue amount must be at least $150 (or a lower amount if specified in your credit contract)
  3. Allow reasonable time: Give you at least 30 days from the notice to pay or make arrangements
  4. Confirm the debt: The debt must be genuine, due and payable

Information retention periods

The Privacy Code sets maximum time limits for how long different types of information can stay on your credit file:

  • Defaults: 5 years from the date of default
  • Court judgements: 5 years from the date of judgement
  • Bankruptcy: 5 years from discharge (2 years for some older bankruptcies)
  • Credit applications: 5 years from the application date
  • Payment history: 2 years from the payment due date
  • Repayment history information: 2 years from when the account is closed

Accuracy and correction rights

Credit providers and credit reporting bodies must:

  • Take reasonable steps to ensure information is accurate and up-to-date
  • Investigate and respond to correction requests within 30 days
  • Notify you in writing of the outcome of any investigation
  • Correct information if it’s found to be inaccurate, out-of-date, incomplete or misleading

When defaults may breach the Privacy Code

A default listing may breach the Privacy Code if:

Insufficient or improper notice

  • No default notice was sent at all
  • The notice was sent to the wrong address
  • Less than 30 days’ notice was given
  • The notice didn’t contain the required information (amount owed, consequences of non-payment, contact details)

Amount threshold issues

  • The overdue amount was less than $150 (unless your contract specifies a lower amount)
  • The calculation includes fees or charges not permitted under your contract
  • Interest or charges were added after the due date without proper notice

Timing problems

  • The debt wasn’t genuinely overdue on the default date
  • You had made payment arrangements that weren’t honoured by the creditor
  • The account was in dispute when the default was listed
  • The default was listed while a hardship application was being considered

Factual errors

  • Wrong amount listed
  • Incorrect default date
  • Wrong account details
  • Listing against the wrong person (identity mix-up)

Joint account issues

For joint accounts, the Privacy Code requires that:

  • Both account holders must be notified separately
  • Defaults can only be listed against the person who was responsible for the debt
  • Each consumer’s credit file is their own, even in joint arrangements

What to check on your credit file

If you’re reviewing your credit file for potential Privacy Code breaches, check:

  • Default notice date: Was it at least 30 days before the default listing date?
  • Your address history: Was the notice sent to your correct address at the time?
  • Amount accuracy: Is the default amount correct and above the minimum threshold?
  • Account status: Was the account genuinely in default when listed?
  • Payment history: Do the records match your actual payment history?
  • Personal details: Are your name, date of birth and addresses correct?
  • Duplicate listings: Are there multiple entries for the same debt?
  • Time limits: Is any information older than the maximum retention period?

Privacy Code breaches and your options

If you believe a credit listing breaches the Privacy Code, you have several options:

Direct dispute with the credit provider

Start by contacting the credit provider directly. They must:

  • Acknowledge your complaint within 5 business days
  • Investigate and respond within 30 days
  • Provide reasons if they refuse to correct the information
  • Take reasonable steps to notify credit reporting bodies of any corrections

Dispute with the credit reporting body

You can also dispute directly with credit reporting bodies. They have similar investigation timeframes and must:

  • Investigate the accuracy of the information
  • Contact the credit provider if necessary
  • Update your file if the information is found to be incorrect
  • Provide you with a copy of your updated credit file

External review pathway

If you’re not satisfied with the outcome of direct disputes, there is an external review pathway available for privacy complaints. This pathway can consider whether the Privacy Code has been breached and order corrections or compensation where appropriate.

Common Privacy Code compliance issues

Telecommunications defaults

Telco defaults often involve Privacy Code issues around:

Utility defaults

Utility companies sometimes breach the Privacy Code by:

Bank defaults

Major banks occasionally have Privacy Code compliance issues with:

How Default Gone helps

Default Gone helps Australians challenge unfair, incorrect or unlawfully listed defaults. We collect the relevant information, prepare the dispute, lodge it with the credit provider and/or credit reporting body, track the response and explain the outcome in plain English.

The standard Default Gone service is $399 per consumer, per default (limited launch pricing — normally $399). There are no stage fees, no success fees and no surprise invoices. The fee covers the work performed, not a sought outcome.

Our process includes reviewing potential Privacy Code breaches as part of every default dispute. This includes checking notification requirements, amount thresholds, timing issues, and factual accuracy against Privacy Code standards.

Next steps if you suspect a Privacy Code breach

If you think a default on your credit file may breach the Privacy Code:

  1. Get your credit file: Order a free credit report from all three credit reporting bodies
  2. Gather your records: Collect any notices, payment records, correspondence and account statements
  3. Check your address history: Confirm where you were living when the default notice should have been sent
  4. Review the timeline: Check whether proper notice periods were followed
  5. Document the issues: List any factual errors or procedural problems you’ve identified
  6. Consider your options: Decide whether to dispute directly or engage a credit dispute service

Got a default on your credit file? Lodge it with Default Gone right here, or call us on (02) 5502 7025. $399 flat per consumer per default. We do not guarantee removal — outcomes depend on the facts of each case — but we will prepare and lodge the dispute properly.

Before engaging any service, it’s worth reviewing what to check first to ensure you have the strongest possible case.

Remember that each default dispute has a flat fee structure regardless of the complexity of the Privacy Code issues involved.

Tired of being held back by a default?

Let’s challenge it properly.

$399 flat per consumer per default. We prepare your dispute under the Privacy Act 1988 framework, review the detail, and file it to the credit reporting body and the credit provider. We do not guarantee removal — outcomes depend on the facts of each case — but we will do every bit of work that fits.

Lodge your default · Call (02) 5502 7025 · See pricing · How it works


For brokers, dealers & finance professionals

Client stuck because of a default? Don’t lose the deal.

If a client’s finance application is held up by a default, you do not have to lose the client. Default Gone runs the entire dispute process — structured intake, document collection, lodgement and tracking. You keep the relationship. Our referral program shares the value with brokers, dealers, accountants and real estate agents who introduce clients we engage.

Apply to refer · Call (02) 5502 7025

Disclaimer

Default Gone is not a law firm and does not provide legal or financial advice. We do not undertaking that a default or judgement will be removed. Outcomes depend on the facts, documents and response from the credit provider, credit reporting body or relevant legal pathway.

Frequently asked questions

What happens if a credit provider breaches the Privacy Code?

If a credit provider breaches the Privacy Code, they may be required to correct or remove the incorrect information from your credit file. In serious cases, they may also face regulatory action or be required to pay compensation. The outcome depends on the specific breach and how it’s investigated.

Can I complain about Privacy Code breaches to the privacy regulator?

Yes, you can make a complaint to the privacy regulator about Privacy Code breaches. However, you generally need to try resolving the matter directly with the credit provider or credit reporting body first. The regulator can investigate systemic issues and take enforcement action where appropriate.

How long do I have to dispute a Privacy Code breach?

There’s no specific time limit for disputing Privacy Code breaches, but it’s best to act promptly once you become aware of an issue. Some external review pathways have time limits, and evidence may become harder to obtain over time.

Does the Privacy Code apply to business credit information?

The Privacy Code primarily applies to personal credit information. Business credit information is governed by different rules, though some Privacy Code principles may apply where personal guarantees are involved or where business information relates to individuals.

What’s the minimum amount for a default under the Privacy Code?

The Privacy Code sets a minimum threshold of $150 for default listings, unless your credit contract specifies a lower amount. This means defaults under $150 may breach the Privacy Code unless your original agreement allowed for lower amounts.

Can joint account holders dispute defaults separately?

Yes, each person named on a joint account can dispute defaults separately. Each consumer’s credit file is their own, and the Privacy Code requires that both joint account holders receive proper notification before defaults are listed.

What information must be included in a default notice?

Under the Privacy Code, a default notice must include the amount overdue, the consequences of non-payment, contact details for resolving the matter, and give at least 30 days to respond. Notices that don’t contain this information may breach the Privacy Code.

How do I prove a Privacy Code breach occurred?

To prove a Privacy Code breach, you typically need evidence such as your address history, payment records, correspondence with the creditor, and documentation of when notices were sent or received. Credit reporting bodies and credit providers must provide reasons for their decisions during dispute processes.

If you advise clients on credit-related matters, our broker referral program may be a fit.

Scroll to Top
Operated by Austech Online · ABN 82 307 630 720 Trading as Default Gone · ASIC business name search Office 903, 50 Clarence St, Sydney NSW 2000
Payments

Card payments — secured by Stripe

VISA AMEX Pay GooglePay link

Card payments are processed by Stripe, a PCI DSS Level 1 service provider — the highest level of certification a payment processor can hold. Default Gone never sees, stores, or transmits your card number; Stripe handles the entire card flow.

Powered by Stripe · PCI DSS Level 1