Getting a default on your credit file feels frustrating, especially when you question whether it was listed correctly. But before accepting the default and moving on, it is worth understanding the rules that govern how these listings are created.
The Credit Reporting Privacy Code 2014 (the Code) sets mandatory standards for credit providers and credit reporting bodies. When these rules are not followed properly, it may provide grounds to challenge the listing.
Got a default on your credit file? Lodge it with Default Gone right here, or call us on (02) 5502 7025. $399 flat per consumer per default. We do not guarantee removal — outcomes depend on the facts of each case — but we will prepare and lodge the dispute properly.
What is the Credit Reporting Privacy Code 2014?
The Credit Reporting Privacy Code 2014 is a legally binding privacy code made under the Privacy Act 1988. It applies to all credit providers, credit reporting bodies and other entities that handle credit information in Australia.
The Code came into effect on 12 March 2014, replacing earlier privacy guidelines with mandatory rules. It sets specific requirements for:
- How credit information must be collected, used and disclosed
- What steps must be taken before listing defaults and other negative information
- How long different types of credit information can be kept
- When consumers must be notified about credit file changes
- What verification and accuracy checks are required
Unlike general privacy principles, the Code contains detailed procedural requirements. Credit providers cannot simply choose their own approach – they must follow the specific steps outlined in the Code.
Key sections relevant to defaults
Several sections of the Code directly affect how defaults are listed:
Section 21 covers the collection of credit information, including requirements to verify identity and confirm debt details before reporting.
Section 23 sets out disclosure rules, including when credit providers can share information with credit reporting bodies.
Sections 6-12 deal with accuracy, correction and access rights, requiring credit providers to have reasonable procedures to ensure information is accurate and up-to-date.
Schedule 1 contains specific notification requirements, including timeframes and content standards for default notices.
These sections work together to create a comprehensive framework that governs every step of the default listing process.
How the Code affects default listings
The Code establishes a multi-step process that credit providers must follow before listing a default. Each step has specific requirements, and missing or incorrectly completing any step may breach the Code.
Pre-listing requirements
Before a default can be listed, credit providers must:
Verify the debt exists and the amount is correct. This includes checking that the consumer actually entered into the credit arrangement, that the debt calculation is accurate, and that any payments or credits have been properly applied.
Confirm the consumer’s identity and address details. The Code requires reasonable steps to ensure the default will be listed against the correct person and that notifications will reach them.
Send proper default notices. The consumer must receive written notice that includes specific information about the debt, the consequences of non-payment, and their right to make a complaint.
Wait for the required response period. The Code sets minimum timeframes that must pass between sending notices and listing defaults.
Consider any response or dispute. If the consumer raises concerns about the debt during the notice period, these must be investigated before proceeding with the listing.
Ongoing obligations
Even after a default is listed, the Code creates ongoing obligations:
Accuracy monitoring: Credit providers must have systems to identify and correct inaccurate information.
Response to disputes: When consumers raise concerns about listed defaults, credit providers must investigate and respond within specific timeframes.
Updates and corrections: If circumstances change (such as payment of the debt), the credit file must be updated to reflect the current status.
Retention limits: Defaults can only be kept on credit files for five years from the date of first default, after which they must be removed.
Common Code breaches in default listings
Experience suggests several areas where credit providers may not fully comply with the Code requirements:
Insufficient verification
Some defaults appear to be listed without adequate verification of the underlying debt. This might include:
- Listing defaults for accounts opened through identity theft
- Recording incorrect amounts due to system errors or miscalculations
- Failing to apply payments or account for disputes before calculating the default amount
- Not confirming that the consumer actually received goods or services
Inadequate notification
The Code requires specific information to be included in default notices, sent to the correct address, with adequate time for response. Common issues include:
- Notices sent to old addresses without checking for updated contact details
- Missing required information about complaint rights or consequences
- Insufficient time between notice and listing
- Generic notices that do not contain specific debt details
Process shortcuts
Some credit providers may not follow the full process required by the Code:
- Listing defaults during active dispute processes
- Not properly investigating consumer responses to default notices
- Failing to consider hardship applications or payment arrangements
- Not maintaining adequate records of the steps taken
Identity and linking errors
The Code requires reasonable steps to ensure defaults are listed against the correct person:
- Defaults listed against people with similar names
- Errors in date of birth or address details
- Confusion between joint account holders
- Mixing up guarantor and borrower responsibilities
Your rights under the Code
The Credit Reporting Privacy Code 2014 creates specific rights for consumers dealing with defaults on their credit files.
Right to access and correction
You have the right to:
- Request a copy of your credit file from any credit reporting body
- Ask for corrections if information is inaccurate, incomplete or misleading
- Receive responses to correction requests within 30 days
- Have corrections made at no cost to you
For defaults specifically, this means you can challenge listings where the amount is wrong, the account details are incorrect, or the debt status has changed.
Right to proper notification
Before a default is listed, you must receive:
- Written notice of the intention to list the default
- Specific details about the debt including amount and account information
- Information about consequences of the listing
- Details of your right to make a complaint
- Reasonable time to respond before the listing is made
If you did not receive proper notice, or the notice was sent to the wrong address, this may breach the Code.
Right to have disputes considered
If you raise concerns about a proposed default listing, the credit provider must:
- Investigate your concerns before proceeding with the listing
- Consider any evidence or information you provide
- Respond to your dispute in writing
- Not list the default while a genuine dispute is being investigated
This right applies both before defaults are listed and after they appear on your credit file.
Right to complain
You can make complaints about potential Code breaches to:
- The credit provider directly
- The credit reporting body
- An external review pathway where appropriate
Credit providers must have accessible complaint procedures and respond to complaints within reasonable timeframes.
When Code breaches may support default disputes
Breaches of the Credit Reporting Privacy Code 2014 may provide grounds to challenge defaults, but each case depends on the specific facts and circumstances.
Verification failures
If a credit provider listed a default without properly verifying the debt, this may breach the Code’s accuracy requirements. Examples might include:
- Defaults for identity theft accounts where verification would have revealed the fraud
- Incorrect amounts due to calculation errors that proper verification would have caught
- Defaults listed despite active disputes that were not properly investigated
Notice defects
Where proper notice was not given before listing a default, this may breach the Code’s notification requirements:
- No notice sent at all
- Notice sent to wrong address without reasonable steps to find current details
- Notice missing required information about the debt or complaint rights
- Insufficient time between notice and listing
Process failures
Creditors who shortcut the required process may breach various Code provisions:
- Listing during active dispute resolution
- Not considering hardship applications before defaulting
- Failing to investigate consumer responses to default notices
- Not maintaining proper records of steps taken
Identity errors
Defaults listed against the wrong person may breach the Code’s accuracy and verification requirements:
- Wrong person due to similar names
- Errors in personal details like date of birth or address
- Confusion about joint account responsibilities
What to check if you suspect a Code breach
If you believe a default on your credit file may involve a breach of the Credit Reporting Privacy Code 2014, there are several things worth checking:
Documentation review
- Did you receive proper written notice before the default was listed?
- Were you given adequate time to respond to the notice?
- Did the notice contain all required information about the debt and your rights?
- Do you have records of any disputes or responses you made?
Account verification
- Is the default amount accurate according to your records?
- Have all payments and credits been properly applied?
- Was the account actually in your name and did you receive the goods/services?
- Are the personal details (name, address, date of birth) correct?
Process timeline
- Was the default listed during an active dispute process?
- Did the credit provider investigate any concerns you raised?
- Were you in a hardship arrangement or payment plan when the default was listed?
- Has the debt since been paid but the credit file not updated?
Record keeping
- Can the credit provider produce records showing they followed the required process?
- Do they have proof that notices were sent to the correct address?
- Can they demonstrate that verification steps were taken?
- Is there evidence of proper investigation of any disputes?
The difference between Code breaches and general disputes
Not every problem with a default listing constitutes a breach of the Credit Reporting Privacy Code 2014. Understanding the difference can help focus dispute efforts on the most relevant grounds.
Code breaches involve process failures
Code breaches typically involve failures to follow the specific procedures required by the legislation:
- Not sending required notices
- Using incorrect notification procedures
- Listing without proper verification
- Failing to investigate disputes
- Not maintaining required records
These are procedural violations that may support challenges regardless of whether the underlying debt exists.
General disputes often involve debt validity
Other types of default disputes may focus on:
- Whether the debt actually exists
- Disputes about goods or services quality
- Payment arrangement disagreements
- Hardship or financial difficulty issues
While these may also provide grounds to challenge defaults, they are typically evaluated under different legal frameworks such as consumer law or contract principles.
Why the distinction matters
Code breaches may be easier to identify and demonstrate because they involve clear procedural requirements. If a credit provider cannot show they followed the required process, this may support a challenge even where the underlying debt is valid.
General debt disputes often require more complex evaluation of the circumstances, evidence about the original transaction, and assessment of competing claims about what happened.
Both types of issues may support default challenges, but Code breaches provide a specific framework for evaluating whether correct procedures were followed.
How Default Gone helps
Default Gone helps Australians challenge unfair, incorrect or unlawfully listed defaults. We collect the relevant information, prepare the dispute, lodge it with the credit provider and/or credit reporting body, track the response and explain the outcome in plain English.
The standard Default Gone service is $399 per consumer, per default. There are no stage fees, no success fees and no surprise invoices. The fee covers the work performed, not a sought outcome.
Our automated compliance review examines defaults against the requirements of the Credit Reporting Privacy Code 2014 and other relevant standards. Where potential Code breaches are identified, these form part of the challenge strategy.
For more information about how the process works, see our pricing page or frequently asked questions section.
Related privacy law frameworks
The Credit Reporting Privacy Code 2014 operates alongside other privacy legislation that may also be relevant to default listings.
The Privacy Act 1988, particularly Part IIIA, establishes the broader framework for credit reporting privacy. The Code provides specific detail about how the general Privacy Act principles apply to credit information.
Understanding both the general Privacy Act requirements and the specific Code provisions can provide a comprehensive view of the legal framework governing default listings.
Getting started with a Code breach review
If you suspect your default may involve a breach of the Credit Reporting Privacy Code 2014, the first step is gathering relevant documentation and timeline information.
Our free credit scan can help identify defaults that may be worth reviewing, while our structured process examines each listing against applicable Code requirements.
Let’s challenge it properly.
$399 flat per consumer per default. We prepare your dispute under the Privacy Act 1988 framework, review the detail, and file it to the credit reporting body and the credit provider. We do not guarantee removal — outcomes depend on the facts of each case — but we will do every bit of work that fits.
Lodge your default · Call (02) 5502 7025 · See pricing · How it works
Disclaimer
Default Gone is not a law firm and does not provide legal or financial advice. We do not undertaking that a default or judgement will be removed. Outcomes depend on the facts, documents and response from the credit provider, credit reporting body or relevant legal pathway.
Frequently asked questions
What is the Credit Reporting Privacy Code 2014?
The Credit Reporting Privacy Code 2014 is a legally binding privacy code made under the Privacy Act 1988. It sets mandatory rules for how credit providers and credit reporting bodies must handle credit information, including specific requirements for listing defaults. The Code came into effect on 12 March 2014 and applies to all entities that deal with credit information in Australia.
How does the Code protect consumers from incorrect defaults?
The Code requires credit providers to follow specific verification, notification and accuracy procedures before listing defaults. This includes verifying debt details, sending proper written notices, allowing time for consumer response, and investigating any disputes raised. If these procedures are not followed correctly, it may provide grounds to challenge the default listing.
What should I do if I think my default breaches the Code?
Start by gathering any documentation about the default, including notices received, correspondence with the creditor, and your account records. Check whether you received proper written notice before the default was listed, whether the details are accurate, and whether any disputes were properly investigated. If you identify potential Code breaches, consider lodging a dispute with the credit provider.
Can old defaults still be challenged for Code breaches?
Yes, defaults can potentially be challenged for Code breaches regardless of their age, provided they are still within the five-year retention period. However, older defaults may involve different documentation and evidence challenges. The specific facts and available records will determine what grounds may be available for older listings.
What’s the difference between a Code breach and a general debt dispute?
Code breaches involve failures to follow the specific procedures required by the privacy legislation, such as not sending proper notices or inadequate verification. General debt disputes often focus on whether the debt actually exists or contract-related issues. Code breaches may be easier to demonstrate because they involve clear procedural requirements rather than complex factual disputes.
How long do credit providers have to respond to Code breach complaints?
Credit providers must respond to correction requests within 30 days under the Privacy Act framework. For general complaints, they must have accessible complaint procedures and respond within reasonable timeframes. If the initial response is unsatisfactory, there may be external review pathways available depending on the type of credit provider.
Do Code breaches automatically mean defaults will be removed?
No, Code breaches do not undertaking automatic removal of defaults. Each case depends on the specific facts, the severity of any procedural failures, and the response from the credit provider or credit reporting body. However, material breaches may provide strong grounds for challenging the listing and seeking correction or removal where appropriate.
Can I get compensation for Code breaches?
The Code primarily focuses on correction of inaccurate information rather than compensation. However, serious privacy breaches may potentially involve other legal pathways. The specific circumstances and impact of any breach would determine what options might be available. Default Gone focuses on the correction aspect rather than compensation claims.