WhenToDeletePowered by ScheduleOneSearch the register
Privacy and customersCommonwealthDestruction / de-identification duty

Credit information (credit providers)

How long do credit information (credit providers) need to be kept in Australia?

DutyDestroy or de-identify
Clock startsNo longer needed
Applies toCredit providers and credit reporting bodies

General information, not legal advice or permission to destroy a record. Coverage may be incomplete or out of date. Check the official text, other applicable obligations and any investigations, disputes or legal holds before disposal. Get advice for your situation. Terms of use.

Under the Privacy Act 1988, credit providers and credit reporting bodies must destroy or de-identify credit information (credit providers) once it is no longer needed.

Credit eligibility information, pre-screening assessments and unsolicited credit information.

3 provisions of the Privacy Act 1988 apply to these records. Each one is set out below.

The terms

s 21S(2)Privacy Act 1988
Destroy or de-identify
the provider no longer needs the information for any purpose for which the information may be used or disclosed by the provider under this Division; and the provider is not required by or under an Australian law, or a court/tribunal order, to retain the information
s 20J(1)Privacy Act 1988
Destroy or de-identify
the entity no longer needs the assessment for any purpose for which it may be used or disclosed under section 20H; and the entity is not required by or under an Australian law, or a court/tribunal order, to retain the assessment
s 20D(4)Privacy Act 1988
Destroy or de-identify
If the credit reporting body determines that it could not have collected the credit information, the body must, as soon as practicable, destroy the information.

Conditions and exceptions Caution

From the provisions:

  • Provider is not required by or under an Australian law, or a court/tribunal order, to retain the information
  • Where retention is required by or under an Australian law or a court/tribunal order
  • Entity no longer needs assessment for permitted purpose
  • Entity not legally required to retain it
  • Required by or under Australian law or court/tribunal order to retain
  • Applies only where the body determined under subsection (1) that it could not have collected the information under section 20C
  • Does not apply if the body is required by or under an Australian law, or a court/tribunal order, to retain the credit information (subsection (5))

The law

Privacy Act 1988, s 21S(2) · Security of credit eligibility informationOfficial text ↗
the provider must take such steps as are reasonable in the circumstances to destroy the information or to ensure that the information is de‑identified
Text as at 4 June 2026
Privacy Act 1988, s 20J(1) · Destruction of pre‑screening assessmentOfficial text ↗
If an entity has possession or control of a pre‑screening assessment, the entity must destroy the assessment if: (a) the entity no longer needs the assessment for any purpose for which it may be used or disclosed under section 20H; and (b) the entity is not required by or under an Australian law, or a court/tribunal order, to retain the assessment.
Text as at 4 June 2026
Privacy Act 1988, s 20D(4) · Dealing with unsolicited credit informationOfficial text ↗
If the credit reporting body determines that it could not have collected the credit information, the body must, as soon as practicable, destroy the information.
Text as at 4 June 2026

Other terms that apply to these records

This page covers credit information (credit providers) on their own. The same file is often caught by other laws as well, with different periods and start dates. See why a legal term is not a schedule.

3 records. 3 sets of rules. They don't agree.

One business file can hold all of these at once.

Credit information (credit providers)DestroyPrivacy Act 1988, s 21S(2), s 20J(1), s 20D(4) · no longer needed
Personal information no longer neededDestroyPrivacy Act 1988, Schedule 1, APP 11.2, APP 4.3 · no longer needed for any permitted purpose
Customer due diligence (KYC) records7yAnti-Money Laundering and Counter-Terrorism Financing Act 2006, s 111(2), s 114(1), s 35F(2), s 35F(3) · the business relationship ends

Now do that for every record your organisation holds, and redo it when the law changes. ScheduleOne has done that work, and keeps it current.

See ScheduleOne →