Under the Privacy Act 1988, credit providers and credit reporting bodies must destroy or de-identify credit information (credit providers) once it is no longer needed.
Credit eligibility information, pre-screening assessments and unsolicited credit information.
3 provisions of the Privacy Act 1988 apply to these records. Each one is set out below.
The terms
Conditions and exceptions Caution
From the provisions:
- Provider is not required by or under an Australian law, or a court/tribunal order, to retain the information
- Where retention is required by or under an Australian law or a court/tribunal order
- Entity no longer needs assessment for permitted purpose
- Entity not legally required to retain it
- Required by or under Australian law or court/tribunal order to retain
- Applies only where the body determined under subsection (1) that it could not have collected the information under section 20C
- Does not apply if the body is required by or under an Australian law, or a court/tribunal order, to retain the credit information (subsection (5))
The law
Other terms that apply to these records
This page covers credit information (credit providers) on their own. The same file is often caught by other laws as well, with different periods and start dates. See why a legal term is not a schedule.
3 records. 3 sets of rules. They don't agree.
One business file can hold all of these at once.
Now do that for every record your organisation holds, and redo it when the law changes. ScheduleOne has done that work, and keeps it current.
See ScheduleOne →